mirror of
https://github.com/apache/httpd.git
synced 2025-08-15 23:27:39 +00:00

end-of-request time, and only update it after a round-trip with the LDAP server rather than every time we check back into the pool. git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1607960 13f79535-47bb-0310-9956-ffa450edef68
342 lines
14 KiB
Plaintext
342 lines
14 KiB
Plaintext
-*- coding: utf-8 -*-
|
|
Changes with Apache 2.5.0
|
|
|
|
*) mod_ldap: Be more conservative with the last-used time for
|
|
LDAPConnectionPoolTTL. PR54587 [Eric Covener]
|
|
|
|
*) mod_deflate: Don't fail when flushing inflated data to the user-agent
|
|
and that coincides with the end of stream ("Zlib error flushing inflate
|
|
buffer"). PR 56196. [Christoph Fausak <christoph fausak glueckkanja.com>]
|
|
|
|
*) mod_proxy: Don't limit the size of the connectable Unix Domain Socket
|
|
paths. [Christophe Jaillet, Yann Ylavic]
|
|
|
|
*) mod_ssl: dump SSL IO/state for the write side of the connection(s),
|
|
like reads (level TRACE4). [Yann Ylavic]
|
|
|
|
*) mod_proxy: Shutdown (eg. close notify) the backend connection before
|
|
closing. [Yann Ylavic]
|
|
|
|
*) mpm_event[opt]: Send the SSL close notify alert when the KeepAliveTimeout
|
|
expires. PR54998. [Yann Ylavic]
|
|
|
|
*) mod_ssl: Ensure that the SSL close notify alert is flushed to the client.
|
|
PR54998. [Tim Kosse <tim.kosse filezilla-project.org>, Yann Ylavic]
|
|
|
|
*) mod_log_config: Add GlobalLog to allow a globally defined log to
|
|
be inherited by virtual hosts that define a CustomLog.
|
|
[Edward Lu <Chaosed0 gmail.com>]
|
|
|
|
*) MPMs: Support SO_REUSEPORT to create multiple duplicated listener
|
|
records for scalability. [Yingqi Lu <yingqi.lu@intel.com>,
|
|
Jeff Trawick, Jim Jagielski]
|
|
|
|
*) mod_proxy_html: support automatic detection of doctype and processing
|
|
of FPIs. PR56285 [Micha Lenk <micha lenk info>, Nick Kew]
|
|
|
|
*) mod_proxy_html: skip documents shorter than 4 bytes
|
|
PR 56286 [Micha Lenk <micha lenk info>]
|
|
|
|
*) mod_proxy_fdpass: Fix computation of the size of 'struct sockaddr_un'
|
|
when passed to 'connect()'.
|
|
[Graham Dumpleton <grahamd apache org>]
|
|
|
|
*) core: Add ap_mpm_resume_suspended() API to allow a suspended connection
|
|
to resume. PR56333
|
|
[Artem <artemciy gmail.com>, Edward Lu <Chaosed0 gmail.com>]
|
|
|
|
*) core: Add ap_mpm_register_socket_callback_timeout() API. [Eric Covener]
|
|
|
|
*) mod_proxy_wstunnel: Honor ProxyWebsocketIdleTimeout in asynchronous
|
|
processing mode. [Eric Covener]
|
|
|
|
*) mod_authnz_ldap: Fail explicitly when the filter is too long. Remove
|
|
unnecessary apr_pstrdup() and strlen(). [Graham Leggett]
|
|
|
|
*) Add the ldap-search option to mod_authnz_ldap, allowing authorization
|
|
to be based on arbitrary expressions that do not include the username.
|
|
[Graham Leggett]
|
|
|
|
*) Add the ldap function to the expression API, allowing LDAP filters and
|
|
distinguished names based on expressions to be escaped correctly to
|
|
guard against LDAP injection. [Graham Leggett]
|
|
|
|
*) Add module mod_ssl_ct, which provides an implementation of Certificate
|
|
Transparency (RFC 6962) for httpd. [Jeff Trawick]
|
|
|
|
*) mod_proxy: Preserve original request headers even if they differ
|
|
from the ones to be forwarded to the backend. PR 45387.
|
|
[Yann Ylavic]
|
|
|
|
*) mod_proxy: When ping/pong is configured for a worker, don't send or
|
|
forward "100 Continue" (interim) response to the client if it does
|
|
not expect one. [Yann Ylavic]
|
|
|
|
*) mod_remoteip: Prevent an external proxy from presenting an internal
|
|
proxy. PR 55962. [Mike Rumph]
|
|
|
|
*) mod_ssl: Add hooks to allow other modules to perform processing at
|
|
several stages of initialization and connection handling. See
|
|
mod_ssl_openssl.h. [Jeff Trawick]
|
|
|
|
*) mod_proxy_wstunnel: Avoid sending error responses down an upgraded
|
|
websockets connection as it is being close down. [Eric Covener]
|
|
|
|
*) mod_proxy_wstunnel: Allow the administrator to cap the amount
|
|
of time a synchronous websockets connection stays idle with
|
|
ProxyWebsocketIdleTimeout. [Eric Covener]
|
|
|
|
*) mod_proxy_wstunnel: Change to opt-in for asynchronous support, adding
|
|
directives ProxyWebsocketAsync and ProxyWebsocketAsyncDelay.
|
|
[Eric Covener]
|
|
|
|
*) mod_proxy_wstunnel: Stop leaking websockets backend connections under
|
|
event MPM (trunk-only). [Eric Covener]
|
|
|
|
*) mod_proxy_http: Add detach_backend hook (potentially usable
|
|
in other proxy scheme handlers). [Jeff Trawick]
|
|
|
|
*) mod_deflate: Add DeflateAlterETag to control how the ETag
|
|
is modified. The 'NoChange' parameter mimics 2.2.x behavior.
|
|
PR 45023, PR 39727. [Eric Covener]
|
|
|
|
*) mod_rewrite: Add 'BNF' (backreferences-no-plus) flag to RewriteRule to
|
|
allow spaces in backreferences to be encoded as %20 instead of '+'.
|
|
[Eric Covener]
|
|
|
|
*) mod_rewrite: Support an optional list of characters to escape in the
|
|
argument for the 'B' (escape backreferences) flag. [Eric Covener]
|
|
|
|
*) mod_ssl: Add SSLOCSPUseRequestNonce directive to control whether or not
|
|
OCSP requests should use a nonce to be checked against the responder's
|
|
one. PR 56233. [ Yann Ylavic ]
|
|
|
|
*) mod_dir: Default to 2.2-like behavior and skip execution when method is
|
|
neither GET nor POST, such as for DAV requests. PR 54914. [Chris Darroch]
|
|
|
|
*) mod_rewrite: Rename the handler that does per-directory internal
|
|
redirects to "rewrite-redirect-handler" from "redirect-handler" so
|
|
it is less ambiguous and less likely to be reused. [Eric Covener]
|
|
|
|
*) mod_rewrite: Protect against looping with the [N] flag by enforcing a
|
|
default limit of 10000 iterations, and allowing each rule to change its
|
|
limit. [Eric Covener]
|
|
|
|
*) mod_ssl: Fix config merging of SSLOCSPEnable and SSLOCSPOverrideResponder.
|
|
[Jeff Trawick]
|
|
|
|
*) Add HttpContentLengthHeadZero and HttpExpectStrict directives.
|
|
[Yehuda Sadeh <yehuda inktank com>, Justin Erenkrantz]
|
|
|
|
*) mod_ssl: Add -t -DDUMP_CA_CERTS option which dumps the filenames of all
|
|
configured SSL CA certificates to stdout the same way as DUMP_CERTS does.
|
|
[Jan Kaluza]
|
|
|
|
*) mod_ssl: Don't flush when an EOS is received. Prepares mod_ssl
|
|
to support write completion. [Graham Leggett]
|
|
|
|
*) core: Add parse_errorlog_arg callback to ap_errorlog_provider
|
|
to allow providers to check the ErrorLog argument. [Jan Kaluza]
|
|
|
|
*) mod_cgid: Use the servers Timeout for each read from a CGI script,
|
|
allow override with new CGIDRequestTimeout directive. PR43494
|
|
[Eric Covener, Toshikuni Fukaya <toshikuni-fukaya cybozu co jp>]
|
|
|
|
*) core: ensure any abnormal exit is reported to stderr if it's a tty.
|
|
PR 55670 [Nick Kew]
|
|
|
|
*) mod_lua: Let the Inter-VM get/set functions work with a global
|
|
shared memory pool instead of a per-process pool. [Daniel Gruno]
|
|
|
|
*) ldap: Support ldaps when using the Microsoft LDAP SDK.
|
|
PR 54626. [Jean-Frederic Clere]
|
|
|
|
*) mod_proxy: Add ap_connection_reusable() for checking if a connection
|
|
is reusable as of this point in processing. [Jeff Trawick]
|
|
|
|
*) mod_authnz_ldap: Change default value of AuthLDAPMaxSubGroupDepth to 0
|
|
to avoid performance problems when subgroups aren't in use. [Eric Covener]
|
|
|
|
*) mod_syslog: New module implementing syslog ap_error_log provider.
|
|
Previously, this code was part of core, now it's in separate module.
|
|
[Jan Kaluza]
|
|
|
|
*) core: Add ap_errorlog_provider to make ErrorLog logging modular. Move
|
|
syslog support from core to new mod_syslog. [Jan Kaluza]
|
|
|
|
*) mod_status, mod_echo: Fix the display of client addresses.
|
|
They were truncated to 31 characters which is not enough for IPv6 addresses.
|
|
PR 54848 [Bernhard Schmidt <berni birkenwald de>]
|
|
|
|
*) core: Add ap_log_data(), ap_log_rdata(), etc. for logging buffers.
|
|
[Jeff Trawick]
|
|
|
|
*) mod_unique_id: Use output of the PRNG rather than IP address and
|
|
pid, avoiding sleep() call and possible DNS issues at startup,
|
|
plus improving randomness for IPv6-only hosts.
|
|
[Jan Kaluza <jkaluza redhat.com>]
|
|
|
|
*) mod_authnz_ldap: Support primitive LDAP servers that do not accept
|
|
filters, such as "SDBM-backed LDAP" on z/OS, by allowing a special
|
|
filter "none" to be specified in AuthLDAPURL. [Eric Covener]
|
|
|
|
*) mod_file_cache: mod_file_cache should be able to serve files that
|
|
haven't had a Content-Type set via e.g. mod_mime. [Eric Covener]
|
|
|
|
*) core: merge AllowEncodedSlashes from the base configuration into
|
|
virtual hosts. [Eric Covener]
|
|
|
|
*) AIX: Install DSO's with "cp" instead of "install" in instdso.sh
|
|
[Eric Covener]
|
|
|
|
*) mod_ldap: Don't keep retrying if a new LDAP connection times out.
|
|
[Eric Covener]
|
|
|
|
*) mod_deflate: permit compilation of mod_deflate against a zlib that has
|
|
been configured with -D Z_PREFIX, which redefines the token "deflate".
|
|
[Eric Covener]
|
|
|
|
*) mod_auth_digest: Use the secret when generating nonces in all cases and
|
|
not only when AuthName is used in .htaccess files (this change may cause
|
|
problems if used with round robin load balancers). Don't regenerate the
|
|
secret on graceful restarts. PR 54637 [Stefan Fritsch]
|
|
|
|
*) core: Remove apr_brigade_flatten(), buffering and duplicated code
|
|
from the HTTP_IN filter, parse chunks in a single pass with zero copy.
|
|
Reduce memory usage by 48 bytes per request. [Graham Leggett]
|
|
|
|
*) core: Stop the HTTP_IN filter from attempting to write error buckets
|
|
to the output filters, which is bogus in the proxy case. Create a
|
|
clean mapping from APR codes to HTTP status codes, and use it where
|
|
needed. [Graham Leggett]
|
|
|
|
*) mod_proxy: Ensure network errors detected by the proxy are returned as
|
|
504 Gateway Timout as opposed to 502 Bad Gateway, in order to be
|
|
compliant with RFC2616 14.9.4 Cache Revalidation and Reload Controls.
|
|
|
|
*) mod_dav: mod_dav overrides dav_fs response on PUT failure. PR 35981
|
|
[Basant Kumar Kukreja <basant.kukreja sun.com>, Alejandro Alvarez
|
|
<alejandro.alvarez.ayllon cern.ch>]
|
|
|
|
*) mod_ldap: LDAP connections used for authentication were not respecting
|
|
LDAPConnectionPoolTimeout. PR 54587
|
|
|
|
*) core: ap_rgetline_core now pulls from r->proto_input_filters.
|
|
|
|
*) mod_proxy_html: process parsed comments immediately.
|
|
Fixes bug where parsed comments may be lost. [Nick Kew]
|
|
|
|
*) mod_proxy_html: introduce doctype for HTML 5 [Nick Kew]
|
|
|
|
*) mod_proxy_html: fix typo-bug processing "strict" vs "transitional"
|
|
HTML/XHTML [Nick Kew]
|
|
|
|
*) core: Add option to add valgrind support. Use it to reduce false positive
|
|
warnings in mod_ssl. [Stefan Fritsch]
|
|
|
|
*) mod_authn_file, mod_authn_dbd, mod_authn_dbm, mod_authn_socache:
|
|
Cache the result of the most recent password hash verification for every
|
|
keep-alive connection. This saves some expensive calculations.
|
|
[Stefan Fritsch]
|
|
|
|
*) http: Remove support for Request-Range header sent by Navigator 2-3 and
|
|
MSIE 3. [Stefan Fritsch]
|
|
|
|
*) core, http: Extend HttpProtocol with an option to enforce stricter HTTP
|
|
conformance or to only log the found problems. [Stefan Fritsch]
|
|
|
|
*) core: Correctly parse an IPv6 literal host specification in an absolute
|
|
URL in the request line. [Stefan Fritsch]
|
|
|
|
*) EventOpt MPM
|
|
|
|
*) core: Add LogLevelOverride directive that allows to override the
|
|
loglevel for clients from certain IPs. This also works for things
|
|
like the SSL handshake where <If> LogLevel ... </If> is evaluated
|
|
too late. [Stefan Fritsch]
|
|
|
|
*) core: Add new directive Warning to issue warnings from a configuration
|
|
file. Both Warning and Error now generate a timestamped log message.
|
|
[Fabien Coelho]
|
|
|
|
*) ap_expr: Add SERVER_PROTOCOL_VERSION, ..._MAJOR, and ..._MINOR
|
|
variables. [Stefan Fritsch]
|
|
|
|
*) core: New directive RegisterHttpMethod for registering non-standard
|
|
HTTP methods. [Stefan Fritsch]
|
|
|
|
*) core: New directive HttpProtocol which allows to disable HTTP/0.9
|
|
support. [Stefan Fritsch]
|
|
|
|
*) mod_allowhandlers: New module to forbid specific handlers for specific
|
|
directories. [Stefan Fritsch]
|
|
|
|
*) mod_systemd: New module, for integration with systemd on Linux.
|
|
[Jan Kaluza <jkaluza redhat.com>]
|
|
|
|
*) WinNT MPM: Store pid and generation for each thread in scoreboard
|
|
to allow tracking of threads from exiting children via mod_status
|
|
or other such mechanisms. [Jeff Trawick]
|
|
|
|
*) The following now respect DefaultRuntimeDir/DEFAULT_REL_RUNTIMEDIR:
|
|
- APIs: ap_log_pid(), ap_remove_pid, ap_read_pid()
|
|
- core: the scoreboard (ScoreBoardFile), pid file (PidFile), and
|
|
mutexes (Mutex)
|
|
- mod_cache: thundering herd lock directory
|
|
- mod_lbmethod_heartbeat, mod_heartmonitor: heartbeat storage file
|
|
- mod_ldap: shared memory cache
|
|
- mod_socache_shmcb, mod_socache_dbm: shared memory or dbm for cache
|
|
[Jeff Trawick]
|
|
|
|
*) suexec: Add --enable-suexec-capabilites support on Linux, to use
|
|
setuid/setgid capability bits rather than a setuid root binary.
|
|
[Joe Orton]
|
|
|
|
*) suexec: Add support for logging to syslog as an alternative to logging
|
|
to a file; configure --without-suexec-logfile --with-suexec-syslog.
|
|
[Joe Orton]
|
|
|
|
*) mod_ssl: Add support for TLS Next Protocol Negotiation. PR 52210.
|
|
[Matthew Steele <mdsteele google.com>]
|
|
|
|
*) cross-compile: allow to provide CC_FOR_BUILD so that gen_test_char will
|
|
be compiled by the build compiler instead of the host compiler.
|
|
Also set CC_FOR_BUILD to 'cc' when cross-compilation is detected.
|
|
PR 51257. [Guenter Knauf]
|
|
|
|
*) core: In maintainer mode, replace apr_palloc with a version that
|
|
initializes the allocated memory with non-zero values, except if
|
|
AP_DEBUG_NO_ALLOC_POISON is defined. [Stefan Fritsch]
|
|
|
|
*) mod_policy: Add a new testing module to help server administrators
|
|
enforce a configurable level of protocol compliance on their
|
|
servers and application servers behind theirs. [Graham Leggett]
|
|
|
|
*) mod_firehose: Add a new debugging module able to record traffic
|
|
passing through the server in such a way that connections and/or
|
|
requests be reconstructed and replayed. [Graham Leggett]
|
|
|
|
*) mod_noloris
|
|
|
|
*) APREQ
|
|
|
|
*) Simple MPM
|
|
|
|
*) mod_serf
|
|
|
|
[Apache 2.5.0-dev includes those bug fixes and changes with the
|
|
Apache 2.4.xx tree as documented below, except as noted.]
|
|
|
|
Changes with Apache 2.4.x and later:
|
|
|
|
*) http://svn.apache.org/viewvc/httpd/httpd/branches/2.4.x/CHANGES?view=markup
|
|
|
|
Changes with Apache 2.2.x and later:
|
|
|
|
*) http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/CHANGES?view=markup
|
|
|
|
Changes with Apache 2.0.x and later:
|
|
|
|
*) http://svn.apache.org/viewvc/httpd/httpd/branches/2.0.x/CHANGES?view=markup
|
|
|