]>
git.ipfire.org Git - thirdparty/apache/httpd.git/log
Rainer Jung [Thu, 1 Jan 2015 15:37:13 +0000 (15:37 +0000)]
Happy New Year 2015
Backport of r1648840 from trunk
resp. r1648845 from 2.4.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1648857 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Mon, 29 Dec 2014 20:26:09 +0000 (20:26 +0000)]
2.2.x-specific patch
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1648417 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Fri, 5 Dec 2014 22:13:34 +0000 (22:13 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1643448 13f79535 -47bb-0310-9956-
ffa450edef68
Jan Kaluža [Wed, 19 Nov 2014 07:32:50 +0000 (07:32 +0000)]
Vote for PR 44736 fix.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1640496 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 6 Nov 2014 14:41:51 +0000 (14:41 +0000)]
vote, promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1637124 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Thu, 6 Nov 2014 13:58:26 +0000 (13:58 +0000)]
Propose mod_deflate compilation fix wrt apr-1.2.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1637104 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Mon, 3 Nov 2014 17:45:02 +0000 (17:45 +0000)]
format
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1636403 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Mon, 3 Nov 2014 14:02:38 +0000 (14:02 +0000)]
propose reqtimeout fix, user followed up in PR
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1636355 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Wed, 29 Oct 2014 10:13:50 +0000 (10:13 +0000)]
Vote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1635090 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Wed, 29 Oct 2014 10:07:45 +0000 (10:07 +0000)]
Update PR 44736 proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1635084 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 18 Oct 2014 16:40:59 +0000 (16:40 +0000)]
Rebuild.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1632822 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 18 Oct 2014 16:40:00 +0000 (16:40 +0000)]
XML update.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1632821 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 18 Oct 2014 16:33:05 +0000 (16:33 +0000)]
XML update.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1632820 13f79535 -47bb-0310-9956-
ffa450edef68
Jan Kaluža [Tue, 14 Oct 2014 05:37:46 +0000 (05:37 +0000)]
Vote for mod_proxy-balancer_graceful.patch
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1631625 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Mon, 13 Oct 2014 19:29:19 +0000 (19:29 +0000)]
small comment only change to synch with later releases
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1631521 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Mon, 13 Oct 2014 19:25:20 +0000 (19:25 +0000)]
Merge r1631516 from trunk:
the hard-coded limit on LimitRequestLine has been gone since 2.1.x, see r819480
and r102840. PR57009
Submitted By: Ed Lu
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1631518 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Thu, 9 Oct 2014 16:11:28 +0000 (16:11 +0000)]
Votes.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1630528 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Thu, 9 Oct 2014 16:08:57 +0000 (16:08 +0000)]
Propose fix for PR 57067, fix misspelling and add PR 44736 reference.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1630524 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Thu, 9 Oct 2014 12:36:19 +0000 (12:36 +0000)]
Fix misspelling in changelog (including CHANGES for proposed patch).
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1630406 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Thu, 9 Oct 2014 12:29:48 +0000 (12:29 +0000)]
Propose.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1630402 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Thu, 9 Oct 2014 09:53:50 +0000 (09:53 +0000)]
fix line widths
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1630359 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Thu, 9 Oct 2014 09:25:41 +0000 (09:25 +0000)]
update transformations.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1630353 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Thu, 9 Oct 2014 09:24:43 +0000 (09:24 +0000)]
update for sync with English docs.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.gen.tr>
Reviewed by: Orhan Berent <berent belgeler.gen.tr>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1630352 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 20 Sep 2014 13:52:34 +0000 (13:52 +0000)]
Rebuild.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1626441 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 20 Sep 2014 13:51:26 +0000 (13:51 +0000)]
XML update.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1626440 13f79535 -47bb-0310-9956-
ffa450edef68
Vincent Deffontaines [Thu, 18 Sep 2014 19:42:12 +0000 (19:42 +0000)]
Fix previous commit - mutiple notes
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1626059 13f79535 -47bb-0310-9956-
ffa450edef68
Vincent Deffontaines [Thu, 18 Sep 2014 19:38:24 +0000 (19:38 +0000)]
[doc][2.2] Provide a note related to use of multiple Require directives on some setups
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1626056 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 13 Sep 2014 14:34:57 +0000 (14:34 +0000)]
Rebuil.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1624747 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 13 Sep 2014 14:34:03 +0000 (14:34 +0000)]
XML update.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1624745 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Wed, 3 Sep 2014 10:19:30 +0000 (10:19 +0000)]
Note release date
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1622211 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 31 Aug 2014 13:16:11 +0000 (13:16 +0000)]
Fix NetWare build: set NLM version with commandline option
instead of linker def file due to bug with mwldnlm linker
where patch version > 26 is ignored from def file.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1621588 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 30 Aug 2014 13:16:26 +0000 (13:16 +0000)]
Rebuild.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1621459 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 30 Aug 2014 13:15:42 +0000 (13:15 +0000)]
XML update.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1621458 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Wed, 27 Aug 2014 16:38:28 +0000 (16:38 +0000)]
Merge r1620932 from trunk:
Make up-to-date
Reviewed/backported by: jim
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620934 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 23 Aug 2014 19:54:35 +0000 (19:54 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620064 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Sat, 23 Aug 2014 11:37:07 +0000 (11:37 +0000)]
xforms
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620015 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Sat, 23 Aug 2014 11:35:27 +0000 (11:35 +0000)]
xforms
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620013 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Sat, 23 Aug 2014 11:34:05 +0000 (11:34 +0000)]
fix compat info for 2.2
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620012 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 23 Aug 2014 11:29:48 +0000 (11:29 +0000)]
Rebuild
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620010 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 23 Aug 2014 11:28:26 +0000 (11:28 +0000)]
XML update.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620009 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 23 Aug 2014 11:27:14 +0000 (11:27 +0000)]
Rebuild.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620008 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 23 Aug 2014 11:19:11 +0000 (11:19 +0000)]
XML update.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1620006 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Fri, 22 Aug 2014 20:31:28 +0000 (20:31 +0000)]
Revert r1602714 per http://httpd.apache.org/docs/2.2/howto/ssi.html#comment_2915
which included 2.4/ap_expr info and examples.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619923 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 15:58:38 +0000 (15:58 +0000)]
And we are at 2.2.30-dev
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619851 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 15:56:20 +0000 (15:56 +0000)]
Prepare to tag once again, at 2.2.29
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619849 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 14:54:06 +0000 (14:54 +0000)]
2.2.28 was tagged, this is .29 already
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619827 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 14:41:19 +0000 (14:41 +0000)]
Re-built all convmap, and picked up the missing new directive plus other bits
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619821 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 11:55:53 +0000 (11:55 +0000)]
And on to 2.2.29 maintenance
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619761 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 11:54:20 +0000 (11:54 +0000)]
Prepare to tag 2.2.28
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619759 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 11:43:36 +0000 (11:43 +0000)]
Resequence CHANGES chronologically and by severity
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619755 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 11:41:43 +0000 (11:41 +0000)]
core: Detect incomplete request and response bodies, log an error and
forward it to the underlying filters.
PR: 55475
Submitted by: Yann Ylavic
Reviewed by: ylavic, wrowe, rpluem
Backports: r1538776
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619754 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 22 Aug 2014 11:37:19 +0000 (11:37 +0000)]
mod_deflate: Handle Zlib header and validation bytes received in multiple
chunks.
PR: 46146, 55666
Submitted by: Yann Ylavic
Reviewed by: ylavic, wrowe, rpluem
Backports: r1572655, r1572663, r1572668, r1572669, r1572670, r1572671, r1573224, r1586745, r1587594, r1587639, r1590509, r1603156, r1604353
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619753 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Thu, 21 Aug 2014 17:33:48 +0000 (17:33 +0000)]
Merge r1610814, r1610686, r1610707 from trunk:
*) SECURITY: CVE-2013-5704 (cve.mitre.org)
core: HTTP trailers could be used to replace HTTP headers
late during request processing, potentially undoing or
otherwise confusing modules that examined or modified
request headers earlier. Adds "MergeTrailers" directive to restore
legacy behavior.
Submitted By: Edward Lu, Yann Ylavic, Joe Orton, Eric Covener
Committed By: covener
Reviewed By: covener, wrowe, rpluem
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619489 13f79535 -47bb-0310-9956-
ffa450edef68
Mike Rumph [Thu, 21 Aug 2014 15:35:43 +0000 (15:35 +0000)]
Comment on possible trailers CVE delay.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619446 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Thu, 21 Aug 2014 13:16:10 +0000 (13:16 +0000)]
mention quirk of the trailers CVE
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619385 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Thu, 21 Aug 2014 13:13:01 +0000 (13:13 +0000)]
fix comment
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1619384 13f79535 -47bb-0310-9956-
ffa450edef68
Ruediger Pluem [Thu, 14 Aug 2014 14:08:16 +0000 (14:08 +0000)]
* Vote and promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1617949 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Sat, 9 Aug 2014 18:15:54 +0000 (18:15 +0000)]
drop showstopper, lone report and no followup or recreate
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1617000 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 26 Jul 2014 18:51:05 +0000 (18:51 +0000)]
Rebuild
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1613704 13f79535 -47bb-0310-9956-
ffa450edef68
Lucien Gentis [Sat, 26 Jul 2014 18:50:17 +0000 (18:50 +0000)]
XML update.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1613703 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Sat, 26 Jul 2014 15:21:16 +0000 (15:21 +0000)]
add a showstopper Jeff might have found on users@
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1613655 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Thu, 24 Jul 2014 22:47:41 +0000 (22:47 +0000)]
Merge r1613318 from trunk:
two commenters were confused authnprovideralias
providing special config to authz providers
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1613320 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Fri, 18 Jul 2014 21:44:34 +0000 (21:44 +0000)]
Backported.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611818 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Fri, 18 Jul 2014 21:43:58 +0000 (21:43 +0000)]
fix latex build
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611817 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Fri, 18 Jul 2014 21:43:55 +0000 (21:43 +0000)]
Follow up to r1611813: add missing CHANGE
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611816 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Fri, 18 Jul 2014 21:38:38 +0000 (21:38 +0000)]
Merge r1572630, r1572611, r1572967, r1573229 from trunk:
Redo what was reverted in r1572627.
Don't reuse a SSL backend connection whose SNI differs. PR 55782.
This may happen when ProxyPreserveHost is on and the proxy-worker
handles connections to different Hosts.
Follows up r1572606.
MMN minor bump required by proxy_conn_rec change.
mod_proxy: follows up r1572630.
Don't reuse a SSL backend connection with no SNI for a request requiring SNI.
mod_proxy: Add comment and avoid ternary operator as condition (no functional change).
Submitted by: ylavic
Reviewed by: ylavic, rpluem, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611813 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Fri, 18 Jul 2014 21:24:10 +0000 (21:24 +0000)]
v4 for PR 46146.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611809 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Fri, 18 Jul 2014 21:03:41 +0000 (21:03 +0000)]
Merge r1572092 from trunk:
mod_deflate: fix decompression of files larger than 4GB. According to RFC1952,
Input SIZE (compLen) contains the size of the original input data modulo 2^32.
PR: 56062
Submitted by: Lukas Bezdicka
Reviewed by: ylavic, breser, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611806 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Fri, 18 Jul 2014 20:37:25 +0000 (20:37 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611796 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Fri, 18 Jul 2014 19:11:10 +0000 (19:11 +0000)]
mod_deflate proposal v3.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611771 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 18 Jul 2014 19:05:35 +0000 (19:05 +0000)]
That's the ticket
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611768 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Fri, 18 Jul 2014 18:49:43 +0000 (18:49 +0000)]
Fix mod_deflate proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611766 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 18 Jul 2014 15:33:11 +0000 (15:33 +0000)]
Vote up, two are promoted as accepted, defect identified in ylavic's patch
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611672 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Fri, 18 Jul 2014 11:35:24 +0000 (11:35 +0000)]
Update porposal -- Ruediger spotted the hand-merge error:
+ if (!apr_is_empty_table(rp->trailers_in)) {
+ apr_table_do(add_trailers, rp->trailers_out,
^
+ rp->trailers_in, NULL);
+ apr_table_clear(rp->trailers_in);
+ }
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611597 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Fri, 18 Jul 2014 11:30:09 +0000 (11:30 +0000)]
Fix typo.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611596 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Fri, 18 Jul 2014 01:00:08 +0000 (01:00 +0000)]
add patch/proposal for CVE-2013-5704 trailers thing
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611522 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Thu, 17 Jul 2014 22:45:50 +0000 (22:45 +0000)]
drop CVE-2014-0117 proposal, 2.2 not affected
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611499 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 17 Jul 2014 22:43:14 +0000 (22:43 +0000)]
And... vote some
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611497 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 17 Jul 2014 20:40:36 +0000 (20:40 +0000)]
Delete BOM, wrap before 80 col
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611468 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Thu, 17 Jul 2014 18:21:59 +0000 (18:21 +0000)]
Merge r1572896, r1572911, r1603156 from trunk:
mod_deflate:
Don't fail when asked to flush inflated data to the user-agent and that
coincides with the end of stream ("Zlib error flushing inflate buffer").
PR 56196.
Submitted By: [Christoph Fausak <christoph.fausak glueckkanja com>]
Committed By: ylavic
mod_deflate: follows up r1572896.
Be safe from successive or post end-of-stream flush buckets.
Add missing CHANGES entries for r1572655,
1572663 ,
1572668 -
1572671 ,
1573224 ,
1586745 ,
1587594 ,
1587639 ,
1590509 , r1572092, and r1572896,
1572911 .
Submitted by: ylavic
Reviewed/backported by: jim
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611428 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Thu, 17 Jul 2014 18:20:46 +0000 (18:20 +0000)]
Merge r1610501 from trunk:
*) SECURITY: CVE-2014-0118 (cve.mitre.org)
mod_deflate: The DEFLATE input filter (inflates request bodies) now
limits the length and compression ratio of inflated request bodies to avoid
denial of sevice via highly compressed bodies. See directives
DeflateInflateLimitRequestBody, DeflateInflateRatioLimit,
and DeflateInflateRatioBurst.
Thanks to Giancarlo Pellegrino and Davide Balzarotti for reporting the issue.
Submitted By: ylavic, covener
Reviewed By: jorton, covener, jim
Submitted by: covener
Reviewed/backported by: jim
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611426 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Thu, 17 Jul 2014 18:19:00 +0000 (18:19 +0000)]
promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611425 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Thu, 17 Jul 2014 18:18:43 +0000 (18:18 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611424 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Thu, 17 Jul 2014 17:45:03 +0000 (17:45 +0000)]
Withdrawal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611414 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Thu, 17 Jul 2014 11:36:51 +0000 (11:36 +0000)]
checks out for me
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611331 13f79535 -47bb-0310-9956-
ffa450edef68
Joe Orton [Thu, 17 Jul 2014 11:17:39 +0000 (11:17 +0000)]
CVE-2014-0117 does not seem to apply to 2.2.x, second set of eyeballs welcome.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611326 13f79535 -47bb-0310-9956-
ffa450edef68
Joe Orton [Thu, 17 Jul 2014 10:52:03 +0000 (10:52 +0000)]
Fooled by weird "svn merge" failing to fail... no this patch doesn't apply.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611319 13f79535 -47bb-0310-9956-
ffa450edef68
Joe Orton [Thu, 17 Jul 2014 10:47:09 +0000 (10:47 +0000)]
Vote, promote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611318 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Wed, 16 Jul 2014 21:19:48 +0000 (21:19 +0000)]
Correct CHANGES entry with attribution
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611195 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Wed, 16 Jul 2014 21:03:30 +0000 (21:03 +0000)]
Fix PR 56480: PROPFIND walker doesn't encode hrefs properly
Reverts r1529559 partially (specifically the dav_xml_escape_uri) bit.
Reverts r1531505 entirely.
* modules/dav/main/mod_dav.c
(dav_xml_escape_uri): Revert the piece of r1529559 that removes the URI
escaping from this function.
* modules/dav/main/props.c
(dav_do_prop_subreq): Escape the URI before doing a sub request with it.
This resolves some properties like getcontenttype from failing to be
returned for files that contain characters that require encoding in their
path.
* modules/dav/main/mod_dav.h
(dav_resource): Note the inconsistency in the documentation.
* modules/dav/fs/repos.c
(dav_fs_get_resource): Don't use the unparsed_uri to set the uri field of
the resource. This is the correct fix for the double encoding in mod_dav_fs
that led to the dav_xml_escape_uri() change and r1531505.
(dav_fs_walker, dav_fs_append_uri): Revert r1531505 changes.
Submitted by: breser
PR: 56480
Backports: r1602338
Reviewed by: breser, rpluem, ylavic
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611189 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Wed, 16 Jul 2014 20:56:51 +0000 (20:56 +0000)]
SECURITY: CVE-2014-0231
mod_cgid: Fix a denial of service against CGI scripts that do
not consume stdin that could lead to lingering HTTPD child processes
filling up the scoreboard and eventually hanging the server.
Submitted by: Rainer Jung, Eric Covener, Yann Ylavic
Backports: r1610509, r1535125
Reviewed by: covener, trawick, ylavic
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611185 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Wed, 16 Jul 2014 20:26:27 +0000 (20:26 +0000)]
Propose utf-8 service names for winnt
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1611179 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Wed, 16 Jul 2014 13:16:24 +0000 (13:16 +0000)]
Vote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1610995 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Wed, 16 Jul 2014 06:04:38 +0000 (06:04 +0000)]
Extend the scope of SSLSessionCacheTimeout to sessions
resumed by TLS session resumption (RFC 5077).
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1610914 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Wed, 16 Jul 2014 01:03:29 +0000 (01:03 +0000)]
get proposal CVE-2014-0117 on the books
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1610891 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Wed, 16 Jul 2014 00:37:07 +0000 (00:37 +0000)]
vote/promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1610888 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 15 Jul 2014 22:07:19 +0000 (22:07 +0000)]
Merge r1610207 from trunk resp. r1610340 from 2.4.x:
Forward local IP address as a custom request attribute
like we already do for the remote port.
Both were forgotten in the original AJP 13 spec
but are needed by the Servlet spec. Until now,
Tomcat simply returns for getLocalAddr() the same as
for getLocalName().
The next round of Tomcat releases will look for the
optional new request attribute.
See also Tomcat BZ 56661.
Submitted by: rjung
Reviewed by: trawick, ylavic
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1610867 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Tue, 15 Jul 2014 14:42:31 +0000 (14:42 +0000)]
Add comment about how to merge CHANGES entry wrt r1587201.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1610717 13f79535 -47bb-0310-9956-
ffa450edef68
Yann Ylavic [Tue, 15 Jul 2014 12:40:43 +0000 (12:40 +0000)]
Votes, 2.4.x patches references, and new proposal already backported to 2.4.8.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1610675 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Tue, 15 Jul 2014 11:08:34 +0000 (11:08 +0000)]
vote...
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@
1610650 13f79535 -47bb-0310-9956-
ffa450edef68