]> git.ipfire.org Git - thirdparty/apache/httpd.git/log
thirdparty/apache/httpd.git
10 years agoFix misspelling in changelog (including CHANGES for proposed patch).
Yann Ylavic [Thu, 9 Oct 2014 12:36:19 +0000 (12:36 +0000)] 
Fix misspelling in changelog (including CHANGES for proposed patch).

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1630406 13f79535-47bb-0310-9956-ffa450edef68

10 years agoPropose.
Yann Ylavic [Thu, 9 Oct 2014 12:29:48 +0000 (12:29 +0000)] 
Propose.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1630402 13f79535-47bb-0310-9956-ffa450edef68

10 years agofix line widths
Nilgun Belma Buguner [Thu, 9 Oct 2014 09:53:50 +0000 (09:53 +0000)] 
fix line widths

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1630359 13f79535-47bb-0310-9956-ffa450edef68

10 years agoupdate transformations.
Nilgun Belma Buguner [Thu, 9 Oct 2014 09:25:41 +0000 (09:25 +0000)] 
update transformations.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1630353 13f79535-47bb-0310-9956-ffa450edef68

10 years agoupdate for sync with English docs.
Nilgun Belma Buguner [Thu, 9 Oct 2014 09:24:43 +0000 (09:24 +0000)] 
update for sync with English docs.

Translated by: Nilgün Belma Bugüner <nilgun belgeler.gen.tr>
Reviewed by:  Orhan Berent <berent belgeler.gen.tr>

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1630352 13f79535-47bb-0310-9956-ffa450edef68

10 years agoRebuild.
Lucien Gentis [Sat, 20 Sep 2014 13:52:34 +0000 (13:52 +0000)] 
Rebuild.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1626441 13f79535-47bb-0310-9956-ffa450edef68

10 years agoXML update.
Lucien Gentis [Sat, 20 Sep 2014 13:51:26 +0000 (13:51 +0000)] 
XML update.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1626440 13f79535-47bb-0310-9956-ffa450edef68

10 years agoFix previous commit - mutiple notes
Vincent Deffontaines [Thu, 18 Sep 2014 19:42:12 +0000 (19:42 +0000)] 
Fix previous commit - mutiple notes

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1626059 13f79535-47bb-0310-9956-ffa450edef68

10 years ago[doc][2.2] Provide a note related to use of multiple Require directives on some setups
Vincent Deffontaines [Thu, 18 Sep 2014 19:38:24 +0000 (19:38 +0000)] 
[doc][2.2] Provide a note related to use of multiple Require directives on some setups

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1626056 13f79535-47bb-0310-9956-ffa450edef68

10 years agoRebuil.
Lucien Gentis [Sat, 13 Sep 2014 14:34:57 +0000 (14:34 +0000)] 
Rebuil.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1624747 13f79535-47bb-0310-9956-ffa450edef68

10 years agoXML update.
Lucien Gentis [Sat, 13 Sep 2014 14:34:03 +0000 (14:34 +0000)] 
XML update.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1624745 13f79535-47bb-0310-9956-ffa450edef68

10 years agoNote release date
William A. Rowe Jr [Wed, 3 Sep 2014 10:19:30 +0000 (10:19 +0000)] 
Note release date

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1622211 13f79535-47bb-0310-9956-ffa450edef68

10 years agoFix NetWare build: set NLM version with commandline option
Guenter Knauf [Sun, 31 Aug 2014 13:16:11 +0000 (13:16 +0000)] 
Fix NetWare build: set NLM version with commandline option
instead of linker def file due to bug with mwldnlm linker
where patch version > 26 is ignored from def file.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1621588 13f79535-47bb-0310-9956-ffa450edef68

10 years agoRebuild.
Lucien Gentis [Sat, 30 Aug 2014 13:16:26 +0000 (13:16 +0000)] 
Rebuild.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1621459 13f79535-47bb-0310-9956-ffa450edef68

10 years agoXML update.
Lucien Gentis [Sat, 30 Aug 2014 13:15:42 +0000 (13:15 +0000)] 
XML update.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1621458 13f79535-47bb-0310-9956-ffa450edef68

10 years agoMerge r1620932 from trunk:
Jim Jagielski [Wed, 27 Aug 2014 16:38:28 +0000 (16:38 +0000)] 
Merge r1620932 from trunk:

Make up-to-date

Reviewed/backported by: jim

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620934 13f79535-47bb-0310-9956-ffa450edef68

10 years agoupdate transformation
André Malo [Sat, 23 Aug 2014 19:54:35 +0000 (19:54 +0000)] 
update transformation

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620064 13f79535-47bb-0310-9956-ffa450edef68

10 years agoxforms
Eric Covener [Sat, 23 Aug 2014 11:37:07 +0000 (11:37 +0000)] 
xforms

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620015 13f79535-47bb-0310-9956-ffa450edef68

10 years agoxforms
Eric Covener [Sat, 23 Aug 2014 11:35:27 +0000 (11:35 +0000)] 
xforms

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620013 13f79535-47bb-0310-9956-ffa450edef68

10 years agofix compat info for 2.2
Eric Covener [Sat, 23 Aug 2014 11:34:05 +0000 (11:34 +0000)] 
fix compat info for 2.2

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620012 13f79535-47bb-0310-9956-ffa450edef68

10 years agoRebuild
Lucien Gentis [Sat, 23 Aug 2014 11:29:48 +0000 (11:29 +0000)] 
Rebuild

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620010 13f79535-47bb-0310-9956-ffa450edef68

10 years agoXML update.
Lucien Gentis [Sat, 23 Aug 2014 11:28:26 +0000 (11:28 +0000)] 
XML update.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620009 13f79535-47bb-0310-9956-ffa450edef68

10 years agoRebuild.
Lucien Gentis [Sat, 23 Aug 2014 11:27:14 +0000 (11:27 +0000)] 
Rebuild.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620008 13f79535-47bb-0310-9956-ffa450edef68

10 years agoXML update.
Lucien Gentis [Sat, 23 Aug 2014 11:19:11 +0000 (11:19 +0000)] 
XML update.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1620006 13f79535-47bb-0310-9956-ffa450edef68

10 years agoRevert r1602714 per http://httpd.apache.org/docs/2.2/howto/ssi.html#comment_2915
Eric Covener [Fri, 22 Aug 2014 20:31:28 +0000 (20:31 +0000)] 
Revert r1602714 per http://httpd.apache.org/docs/2.2/howto/ssi.html#comment_2915
which included 2.4/ap_expr info and examples.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619923 13f79535-47bb-0310-9956-ffa450edef68

10 years agoAnd we are at 2.2.30-dev
William A. Rowe Jr [Fri, 22 Aug 2014 15:58:38 +0000 (15:58 +0000)] 
And we are at 2.2.30-dev

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619851 13f79535-47bb-0310-9956-ffa450edef68

10 years agoPrepare to tag once again, at 2.2.29
William A. Rowe Jr [Fri, 22 Aug 2014 15:56:20 +0000 (15:56 +0000)] 
Prepare to tag once again, at 2.2.29

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619849 13f79535-47bb-0310-9956-ffa450edef68

10 years ago2.2.28 was tagged, this is .29 already
William A. Rowe Jr [Fri, 22 Aug 2014 14:54:06 +0000 (14:54 +0000)] 
2.2.28 was tagged, this is .29 already

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619827 13f79535-47bb-0310-9956-ffa450edef68

10 years agoRe-built all convmap, and picked up the missing new directive plus other bits
William A. Rowe Jr [Fri, 22 Aug 2014 14:41:19 +0000 (14:41 +0000)] 
Re-built all convmap, and picked up the missing new directive plus other bits

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619821 13f79535-47bb-0310-9956-ffa450edef68

10 years agoAnd on to 2.2.29 maintenance
William A. Rowe Jr [Fri, 22 Aug 2014 11:55:53 +0000 (11:55 +0000)] 
And on to 2.2.29 maintenance

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619761 13f79535-47bb-0310-9956-ffa450edef68

10 years agoPrepare to tag 2.2.28
William A. Rowe Jr [Fri, 22 Aug 2014 11:54:20 +0000 (11:54 +0000)] 
Prepare to tag 2.2.28

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619759 13f79535-47bb-0310-9956-ffa450edef68

10 years agoResequence CHANGES chronologically and by severity
William A. Rowe Jr [Fri, 22 Aug 2014 11:43:36 +0000 (11:43 +0000)] 
Resequence CHANGES chronologically and by severity

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619755 13f79535-47bb-0310-9956-ffa450edef68

10 years agocore: Detect incomplete request and response bodies, log an error and
William A. Rowe Jr [Fri, 22 Aug 2014 11:41:43 +0000 (11:41 +0000)] 
core: Detect incomplete request and response bodies, log an error and
forward it to the underlying filters.

PR: 55475
Submitted by: Yann Ylavic
Reviewed by: ylavic, wrowe, rpluem
Backports: r1538776

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619754 13f79535-47bb-0310-9956-ffa450edef68

10 years agomod_deflate: Handle Zlib header and validation bytes received in multiple
William A. Rowe Jr [Fri, 22 Aug 2014 11:37:19 +0000 (11:37 +0000)] 
mod_deflate: Handle Zlib header and validation bytes received in multiple
chunks.

PR: 46146, 55666
Submitted by: Yann Ylavic
Reviewed by: ylavic, wrowe, rpluem
Backports: r1572655, r1572663, r1572668, r1572669, r1572670, r1572671, r1573224, r1586745, r1587594, r1587639, r1590509, r1603156, r1604353

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619753 13f79535-47bb-0310-9956-ffa450edef68

10 years agoMerge r1610814, r1610686, r1610707 from trunk:
Eric Covener [Thu, 21 Aug 2014 17:33:48 +0000 (17:33 +0000)] 
Merge r1610814, r1610686, r1610707 from trunk:

      *) SECURITY: CVE-2013-5704 (cve.mitre.org)
         core: HTTP trailers could be used to replace HTTP headers
         late during request processing, potentially undoing or
         otherwise confusing modules that examined or modified
         request headers earlier.  Adds "MergeTrailers" directive to restore
         legacy behavior.

    Submitted By: Edward Lu, Yann Ylavic, Joe Orton, Eric Covener
    Committed By: covener

Reviewed By:  covener, wrowe, rpluem

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619489 13f79535-47bb-0310-9956-ffa450edef68

10 years agoComment on possible trailers CVE delay.
Mike Rumph [Thu, 21 Aug 2014 15:35:43 +0000 (15:35 +0000)] 
Comment on possible trailers CVE delay.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619446 13f79535-47bb-0310-9956-ffa450edef68

10 years agomention quirk of the trailers CVE
Eric Covener [Thu, 21 Aug 2014 13:16:10 +0000 (13:16 +0000)] 
mention quirk of the trailers CVE

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619385 13f79535-47bb-0310-9956-ffa450edef68

10 years agofix comment
Eric Covener [Thu, 21 Aug 2014 13:13:01 +0000 (13:13 +0000)] 
fix comment

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1619384 13f79535-47bb-0310-9956-ffa450edef68

10 years ago* Vote and promote
Ruediger Pluem [Thu, 14 Aug 2014 14:08:16 +0000 (14:08 +0000)] 
* Vote and promote

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1617949 13f79535-47bb-0310-9956-ffa450edef68

10 years agodrop showstopper, lone report and no followup or recreate
Eric Covener [Sat, 9 Aug 2014 18:15:54 +0000 (18:15 +0000)] 
drop showstopper, lone report and no followup or recreate

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1617000 13f79535-47bb-0310-9956-ffa450edef68

11 years agoRebuild
Lucien Gentis [Sat, 26 Jul 2014 18:51:05 +0000 (18:51 +0000)] 
Rebuild

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1613704 13f79535-47bb-0310-9956-ffa450edef68

11 years agoXML update.
Lucien Gentis [Sat, 26 Jul 2014 18:50:17 +0000 (18:50 +0000)] 
XML update.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1613703 13f79535-47bb-0310-9956-ffa450edef68

11 years agoadd a showstopper Jeff might have found on users@
Eric Covener [Sat, 26 Jul 2014 15:21:16 +0000 (15:21 +0000)] 
add a showstopper Jeff might have found on users@

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1613655 13f79535-47bb-0310-9956-ffa450edef68

11 years agoMerge r1613318 from trunk:
Eric Covener [Thu, 24 Jul 2014 22:47:41 +0000 (22:47 +0000)] 
Merge r1613318 from trunk:

two commenters were confused authnprovideralias
providing special config to authz providers

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1613320 13f79535-47bb-0310-9956-ffa450edef68

11 years agoBackported.
Yann Ylavic [Fri, 18 Jul 2014 21:44:34 +0000 (21:44 +0000)] 
Backported.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611818 13f79535-47bb-0310-9956-ffa450edef68

11 years agofix latex build
André Malo [Fri, 18 Jul 2014 21:43:58 +0000 (21:43 +0000)] 
fix latex build

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611817 13f79535-47bb-0310-9956-ffa450edef68

11 years agoFollow up to r1611813: add missing CHANGE
Yann Ylavic [Fri, 18 Jul 2014 21:43:55 +0000 (21:43 +0000)] 
Follow up to r1611813: add missing CHANGE

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611816 13f79535-47bb-0310-9956-ffa450edef68

11 years agoMerge r1572630, r1572611, r1572967, r1573229 from trunk:
Yann Ylavic [Fri, 18 Jul 2014 21:38:38 +0000 (21:38 +0000)] 
Merge r1572630, r1572611, r1572967, r1573229 from trunk:

Redo what was reverted in r1572627.
Don't reuse a SSL backend connection whose SNI differs. PR 55782.
This may happen when ProxyPreserveHost is on and the proxy-worker
handles connections to different Hosts.

Follows up r1572606.
MMN minor bump required by proxy_conn_rec change.

mod_proxy: follows up r1572630.
Don't reuse a SSL backend connection with no SNI for a request requiring SNI.

mod_proxy: Add comment and avoid ternary operator as condition (no functional change).

Submitted by: ylavic
Reviewed by: ylavic, rpluem, wrowe

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611813 13f79535-47bb-0310-9956-ffa450edef68

11 years agov4 for PR 46146.
Yann Ylavic [Fri, 18 Jul 2014 21:24:10 +0000 (21:24 +0000)] 
v4 for PR 46146.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611809 13f79535-47bb-0310-9956-ffa450edef68

11 years agoMerge r1572092 from trunk:
Yann Ylavic [Fri, 18 Jul 2014 21:03:41 +0000 (21:03 +0000)] 
Merge r1572092 from trunk:

mod_deflate: fix decompression of files larger than 4GB. According to RFC1952,
Input SIZE (compLen) contains the size of the original input data modulo 2^32.

PR: 56062
Submitted by: Lukas Bezdicka
Reviewed by: ylavic, breser, wrowe

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611806 13f79535-47bb-0310-9956-ffa450edef68

11 years agoupdate transformation
André Malo [Fri, 18 Jul 2014 20:37:25 +0000 (20:37 +0000)] 
update transformation

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611796 13f79535-47bb-0310-9956-ffa450edef68

11 years agomod_deflate proposal v3.
Yann Ylavic [Fri, 18 Jul 2014 19:11:10 +0000 (19:11 +0000)] 
mod_deflate proposal v3.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611771 13f79535-47bb-0310-9956-ffa450edef68

11 years agoThat's the ticket
William A. Rowe Jr [Fri, 18 Jul 2014 19:05:35 +0000 (19:05 +0000)] 
That's the ticket

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611768 13f79535-47bb-0310-9956-ffa450edef68

11 years agoFix mod_deflate proposal.
Yann Ylavic [Fri, 18 Jul 2014 18:49:43 +0000 (18:49 +0000)] 
Fix mod_deflate proposal.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611766 13f79535-47bb-0310-9956-ffa450edef68

11 years agoVote up, two are promoted as accepted, defect identified in ylavic's patch
William A. Rowe Jr [Fri, 18 Jul 2014 15:33:11 +0000 (15:33 +0000)] 
Vote up, two are promoted as accepted, defect identified in ylavic's patch

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611672 13f79535-47bb-0310-9956-ffa450edef68

11 years agoUpdate porposal -- Ruediger spotted the hand-merge error:
Eric Covener [Fri, 18 Jul 2014 11:35:24 +0000 (11:35 +0000)] 
Update porposal -- Ruediger spotted the hand-merge error:

+                    if (!apr_is_empty_table(rp->trailers_in)) {
+                        apr_table_do(add_trailers, rp->trailers_out,
                                                    ^
+                                rp->trailers_in, NULL);
+                        apr_table_clear(rp->trailers_in);
+                    }

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611597 13f79535-47bb-0310-9956-ffa450edef68

11 years agoFix typo.
Rainer Jung [Fri, 18 Jul 2014 11:30:09 +0000 (11:30 +0000)] 
Fix typo.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611596 13f79535-47bb-0310-9956-ffa450edef68

11 years agoadd patch/proposal for CVE-2013-5704 trailers thing
Eric Covener [Fri, 18 Jul 2014 01:00:08 +0000 (01:00 +0000)] 
add patch/proposal for CVE-2013-5704 trailers thing

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611522 13f79535-47bb-0310-9956-ffa450edef68

11 years agodrop CVE-2014-0117 proposal, 2.2 not affected
Eric Covener [Thu, 17 Jul 2014 22:45:50 +0000 (22:45 +0000)] 
drop CVE-2014-0117 proposal, 2.2 not affected

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611499 13f79535-47bb-0310-9956-ffa450edef68

11 years agoAnd... vote some
William A. Rowe Jr [Thu, 17 Jul 2014 22:43:14 +0000 (22:43 +0000)] 
And... vote some

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611497 13f79535-47bb-0310-9956-ffa450edef68

11 years agoDelete BOM, wrap before 80 col
William A. Rowe Jr [Thu, 17 Jul 2014 20:40:36 +0000 (20:40 +0000)] 
Delete BOM, wrap before 80 col

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611468 13f79535-47bb-0310-9956-ffa450edef68

11 years agoMerge r1572896, r1572911, r1603156 from trunk:
Jim Jagielski [Thu, 17 Jul 2014 18:21:59 +0000 (18:21 +0000)] 
Merge r1572896, r1572911, r1603156 from trunk:

mod_deflate:
Don't fail when asked to flush inflated data to the user-agent and that
coincides with the end of stream ("Zlib error flushing inflate buffer").
PR 56196.

Submitted By: [Christoph Fausak <christoph.fausak glueckkanja com>]
Committed By: ylavic

mod_deflate: follows up r1572896.
Be safe from successive or post end-of-stream flush buckets.

Add missing CHANGES entries for r1572655,1572663,1572668-1572671,1573224,1586745,1587594,1587639,1590509, r1572092, and r1572896,1572911.
Submitted by: ylavic
Reviewed/backported by: jim

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611428 13f79535-47bb-0310-9956-ffa450edef68

11 years agoMerge r1610501 from trunk:
Jim Jagielski [Thu, 17 Jul 2014 18:20:46 +0000 (18:20 +0000)] 
Merge r1610501 from trunk:

  *) SECURITY: CVE-2014-0118 (cve.mitre.org)
     mod_deflate: The DEFLATE input filter (inflates request bodies) now
     limits the length and compression ratio of inflated request bodies to avoid
     denial of sevice via highly compressed bodies.  See directives
     DeflateInflateLimitRequestBody, DeflateInflateRatioLimit,
     and DeflateInflateRatioBurst.

Thanks to Giancarlo Pellegrino and Davide Balzarotti for reporting the issue.

Submitted By: ylavic, covener
Reviewed By: jorton, covener, jim

Submitted by: covener
Reviewed/backported by: jim

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611426 13f79535-47bb-0310-9956-ffa450edef68

11 years agopromote
Jim Jagielski [Thu, 17 Jul 2014 18:19:00 +0000 (18:19 +0000)] 
promote

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611425 13f79535-47bb-0310-9956-ffa450edef68

11 years agovote
Jim Jagielski [Thu, 17 Jul 2014 18:18:43 +0000 (18:18 +0000)] 
vote

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611424 13f79535-47bb-0310-9956-ffa450edef68

11 years agoWithdrawal.
Yann Ylavic [Thu, 17 Jul 2014 17:45:03 +0000 (17:45 +0000)] 
Withdrawal.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611414 13f79535-47bb-0310-9956-ffa450edef68

11 years agochecks out for me
Eric Covener [Thu, 17 Jul 2014 11:36:51 +0000 (11:36 +0000)] 
checks out for me

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611331 13f79535-47bb-0310-9956-ffa450edef68

11 years agoCVE-2014-0117 does not seem to apply to 2.2.x, second set of eyeballs welcome.
Joe Orton [Thu, 17 Jul 2014 11:17:39 +0000 (11:17 +0000)] 
CVE-2014-0117 does not seem to apply to 2.2.x, second set of eyeballs welcome.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611326 13f79535-47bb-0310-9956-ffa450edef68

11 years agoFooled by weird "svn merge" failing to fail... no this patch doesn't apply.
Joe Orton [Thu, 17 Jul 2014 10:52:03 +0000 (10:52 +0000)] 
Fooled by weird "svn merge" failing to fail... no this patch doesn't apply.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611319 13f79535-47bb-0310-9956-ffa450edef68

11 years agoVote, promote.
Joe Orton [Thu, 17 Jul 2014 10:47:09 +0000 (10:47 +0000)] 
Vote, promote.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611318 13f79535-47bb-0310-9956-ffa450edef68

11 years agoCorrect CHANGES entry with attribution
William A. Rowe Jr [Wed, 16 Jul 2014 21:19:48 +0000 (21:19 +0000)] 
Correct CHANGES entry with attribution

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611195 13f79535-47bb-0310-9956-ffa450edef68

11 years agoFix PR 56480: PROPFIND walker doesn't encode hrefs properly
William A. Rowe Jr [Wed, 16 Jul 2014 21:03:30 +0000 (21:03 +0000)] 
Fix PR 56480: PROPFIND walker doesn't encode hrefs properly

Reverts r1529559 partially (specifically the dav_xml_escape_uri) bit.
Reverts r1531505 entirely.

* modules/dav/main/mod_dav.c
  (dav_xml_escape_uri): Revert the piece of r1529559 that removes the URI
    escaping from this function.

* modules/dav/main/props.c
  (dav_do_prop_subreq): Escape the URI before doing a sub request with it.
    This resolves some properties like getcontenttype from failing to be
    returned for files that contain characters that require encoding in their
    path.

* modules/dav/main/mod_dav.h
  (dav_resource): Note the inconsistency in the documentation.

* modules/dav/fs/repos.c
  (dav_fs_get_resource): Don't use the unparsed_uri to set the uri field of
    the resource.  This is the correct fix for the double encoding in mod_dav_fs
    that led to the dav_xml_escape_uri() change and r1531505.
  (dav_fs_walker, dav_fs_append_uri): Revert r1531505 changes.

Submitted by: breser
PR: 56480
Backports: r1602338
Reviewed by: breser, rpluem, ylavic

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611189 13f79535-47bb-0310-9956-ffa450edef68

11 years agoSECURITY: CVE-2014-0231
William A. Rowe Jr [Wed, 16 Jul 2014 20:56:51 +0000 (20:56 +0000)] 
SECURITY: CVE-2014-0231

  mod_cgid: Fix a denial of service against CGI scripts that do
  not consume stdin that could lead to lingering HTTPD child processes
  filling up the scoreboard and eventually hanging the server.

Submitted by: Rainer Jung, Eric Covener, Yann Ylavic
Backports: r1610509, r1535125
Reviewed by: covener, trawick, ylavic

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611185 13f79535-47bb-0310-9956-ffa450edef68

11 years agoPropose utf-8 service names for winnt
William A. Rowe Jr [Wed, 16 Jul 2014 20:26:27 +0000 (20:26 +0000)] 
Propose utf-8 service names for winnt

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611179 13f79535-47bb-0310-9956-ffa450edef68

11 years agoVote.
Yann Ylavic [Wed, 16 Jul 2014 13:16:24 +0000 (13:16 +0000)] 
Vote.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610995 13f79535-47bb-0310-9956-ffa450edef68

11 years agoExtend the scope of SSLSessionCacheTimeout to sessions
Rainer Jung [Wed, 16 Jul 2014 06:04:38 +0000 (06:04 +0000)] 
Extend the scope of SSLSessionCacheTimeout to sessions
resumed by TLS session resumption (RFC 5077).

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610914 13f79535-47bb-0310-9956-ffa450edef68

11 years agoget proposal CVE-2014-0117 on the books
Eric Covener [Wed, 16 Jul 2014 01:03:29 +0000 (01:03 +0000)] 
get proposal CVE-2014-0117 on the books

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610891 13f79535-47bb-0310-9956-ffa450edef68

11 years agovote/promote
Eric Covener [Wed, 16 Jul 2014 00:37:07 +0000 (00:37 +0000)] 
vote/promote

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610888 13f79535-47bb-0310-9956-ffa450edef68

11 years agoMerge r1610207 from trunk resp. r1610340 from 2.4.x:
Rainer Jung [Tue, 15 Jul 2014 22:07:19 +0000 (22:07 +0000)] 
Merge r1610207 from trunk resp. r1610340 from 2.4.x:

Forward local IP address as a custom request attribute
like we already do for the remote port.

Both were forgotten in the original AJP 13 spec
but are needed by the Servlet spec. Until now,
Tomcat simply returns for getLocalAddr() the same as
for getLocalName().

The next round of Tomcat releases will look for the
optional new request attribute.

See also Tomcat BZ 56661.

Submitted by: rjung
Reviewed by: trawick, ylavic

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610867 13f79535-47bb-0310-9956-ffa450edef68

11 years agoAdd comment about how to merge CHANGES entry wrt r1587201.
Yann Ylavic [Tue, 15 Jul 2014 14:42:31 +0000 (14:42 +0000)] 
Add comment about how to merge CHANGES entry wrt r1587201.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610717 13f79535-47bb-0310-9956-ffa450edef68

11 years agoVotes, 2.4.x patches references, and new proposal already backported to 2.4.8.
Yann Ylavic [Tue, 15 Jul 2014 12:40:43 +0000 (12:40 +0000)] 
Votes, 2.4.x patches references, and new proposal already backported to 2.4.8.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610675 13f79535-47bb-0310-9956-ffa450edef68

11 years agovote...
Jeff Trawick [Tue, 15 Jul 2014 11:08:34 +0000 (11:08 +0000)] 
vote...

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610650 13f79535-47bb-0310-9956-ffa450edef68

11 years agoeasy vote, more tomorrow I hope...
Jeff Trawick [Tue, 15 Jul 2014 01:46:35 +0000 (01:46 +0000)] 
easy vote, more tomorrow I hope...

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610566 13f79535-47bb-0310-9956-ffa450edef68

11 years agopropose CVE-2014-0118 backport
Eric Covener [Mon, 14 Jul 2014 21:02:52 +0000 (21:02 +0000)] 
propose CVE-2014-0118 backport

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610527 13f79535-47bb-0310-9956-ffa450edef68

11 years agopropose CVE-2014-0231
Eric Covener [Mon, 14 Jul 2014 20:46:42 +0000 (20:46 +0000)] 
propose CVE-2014-0231

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610519 13f79535-47bb-0310-9956-ffa450edef68

11 years agoMerge 1610491 from trunk:
Joe Orton [Mon, 14 Jul 2014 20:34:32 +0000 (20:34 +0000)] 
Merge 1610491 from trunk:

SECURITY (CVE-2014-0226): Fix a race condition in scoreboard handling,
which could lead to a heap buffer overflow.  Thanks to Marek Kroemeke
working with HP's Zero Day Initiative for reporting this.

* include/scoreboard.h: Add ap_copy_scoreboard_worker.

* server/scoreboard.c (ap_copy_scoreboard_worker): New function.

* modules/generators/mod_status.c (status_handler): Use it.

Reviewed by: trawick, jorton, covener
Submitted by: jorton, trawick, covener

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610515 13f79535-47bb-0310-9956-ffa450edef68

11 years agoAdd 2.4.x rev to proposal.
Rainer Jung [Mon, 14 Jul 2014 06:10:50 +0000 (06:10 +0000)] 
Add 2.4.x rev to proposal.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610342 13f79535-47bb-0310-9956-ffa450edef68

11 years agoPropose.
Rainer Jung [Sun, 13 Jul 2014 22:51:57 +0000 (22:51 +0000)] 
Propose.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610316 13f79535-47bb-0310-9956-ffa450edef68

11 years agoPropose.
Rainer Jung [Sun, 13 Jul 2014 15:03:42 +0000 (15:03 +0000)] 
Propose.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610224 13f79535-47bb-0310-9956-ffa450edef68

11 years agoRebuild.
Lucien Gentis [Sun, 13 Jul 2014 12:21:08 +0000 (12:21 +0000)] 
Rebuild.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610177 13f79535-47bb-0310-9956-ffa450edef68

11 years agoUpdate.
Lucien Gentis [Sun, 13 Jul 2014 12:19:57 +0000 (12:19 +0000)] 
Update.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1610176 13f79535-47bb-0310-9956-ffa450edef68

11 years agoVote for 2 mod_deflate backports for 2.2.x
Ben Reser [Fri, 11 Jul 2014 03:56:30 +0000 (03:56 +0000)] 
Vote for 2 mod_deflate backports for 2.2.x

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1609621 13f79535-47bb-0310-9956-ffa450edef68

11 years agoAdd mod_deflate missing commits (present in 2.2.x patches).
Yann Ylavic [Wed, 9 Jul 2014 16:45:51 +0000 (16:45 +0000)] 
Add mod_deflate missing commits (present in 2.2.x patches).

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1609239 13f79535-47bb-0310-9956-ffa450edef68

11 years agoPropose mod_deflate fixes.
Yann Ylavic [Wed, 9 Jul 2014 16:40:23 +0000 (16:40 +0000)] 
Propose mod_deflate fixes.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1609233 13f79535-47bb-0310-9956-ffa450edef68

11 years agoVote and promote mod_dav fix.
Yann Ylavic [Wed, 9 Jul 2014 14:38:11 +0000 (14:38 +0000)] 
Vote and promote mod_dav fix.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1609180 13f79535-47bb-0310-9956-ffa450edef68

11 years ago* Vote
Ruediger Pluem [Wed, 9 Jul 2014 14:07:52 +0000 (14:07 +0000)] 
* Vote

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1609164 13f79535-47bb-0310-9956-ffa450edef68

11 years agoFix a typo and add my vote I accidentally left off the PR 56480 nomination.
Ben Reser [Wed, 9 Jul 2014 01:44:05 +0000 (01:44 +0000)] 
Fix a typo and add my vote I accidentally left off the PR 56480 nomination.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1608981 13f79535-47bb-0310-9956-ffa450edef68

11 years agoNominate the PR 56480 fix for 2.2.x backport.
Ben Reser [Wed, 9 Jul 2014 01:26:52 +0000 (01:26 +0000)] 
Nominate the PR 56480 fix for 2.2.x backport.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1608977 13f79535-47bb-0310-9956-ffa450edef68

11 years agobackport some consistency with trunks mod_cache:
Eric Covener [Tue, 8 Jul 2014 16:14:05 +0000 (16:14 +0000)] 
backport some consistency with trunks mod_cache:

   * mod_cache, mod_disk_cache: Try to use the key of a possible open but
     stale cache entry if there is one. This fixes problem when two different
     cache locks have been created for single stale cache entry leading to two
     requests sent to backend.
     PR 50317

   * Remove useless apr_file_remove() before renaming the cache entry in
     mod_disk_cache. This fixes small time-frame during which stale cache
     entry can be seen as not-cached.
     PR 50317

Subitted By: rpluem, jkaluza, ylavic
Reviewed By: ylavic, rpluem, jkaluza

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1608838 13f79535-47bb-0310-9956-ffa450edef68

11 years agoxforms
Eric Covener [Sun, 6 Jul 2014 21:58:08 +0000 (21:58 +0000)] 
xforms

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1608305 13f79535-47bb-0310-9956-ffa450edef68