<feed xmlns='http://www.w3.org/2005/Atom'>
<title>pkgsrc/www/apache2, branch pkgsrc_2004Q4</title>
<subtitle>[no description]</subtitle>
<id>https://git.osdyson.ru/mirror/pkgsrc/atom?h=pkgsrc_2004Q4</id>
<link rel='self' href='https://git.osdyson.ru/mirror/pkgsrc/atom?h=pkgsrc_2004Q4'/>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/'/>
<updated>2005-02-10T15:22:24Z</updated>
<entry>
<title>Pullup ticket 277 - requested by Matthias Scheler</title>
<updated>2005-02-10T15:22:24Z</updated>
<author>
<name>salo</name>
<email>salo</email>
</author>
<published>2005-02-10T15:22:24Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=7f807dbed5cae012324e0a3a0aab72ef5ddd913b'/>
<id>urn:sha1:7f807dbed5cae012324e0a3a0aab72ef5ddd913b</id>
<content type='text'>
security fix for apache2

Revisions pulled up:
- pkgsrc/devel/apr/Makefile           1.31
- pkgsrc/devel/apr/distinfo           1.11
- pkgsrc/www/apache2/Makefile         1.66 (merged by hand)
- pkgsrc/www/apache2/Makefile.common  1.13
- pkgsrc/www/apache2/PLIST            1.27
- pkgsrc/www/apache2/distinfo         1.36 (merged by hand)
- pkgsrc/www/apache2/patches/patch-aa 1.14
- pkgsrc/www/apache2/patches/patch-as removed
- pkgsrc/www/apache2/patches/patch-at removed

   Module Name:	pkgsrc
   Committed By:	tron
   Date:		Wed Feb  9 14:52:12 UTC 2005

   Modified Files:
   	pkgsrc/devel/apr: Makefile distinfo

   Log Message:
   Update "apr" package to version 0.9.6.2.0.53. Changes since
   version 0.9.5.2.0.52:
   - Add apr_threadattr_stacksize_set() for overriding the default
     stack size for threads created by apr_thread_create().
   - Add an RPM spec file.
   - Add a build script to create a solaris package.
---
   Module Name:	pkgsrc
   Committed By:	tron
   Date:		Wed Feb  9 14:57:52 UTC 2005

   Modified Files:
   	pkgsrc/www/apache2: Makefile Makefile.common PLIST distinfo
   	pkgsrc/www/apache2/patches: patch-aa
   Removed Files:
   	pkgsrc/www/apache2/patches: patch-as patch-at

   Log Message:
   Update "apache2" package to version 2.0.53. Changes since version 2.0.52:
   - Fix --with-apr=/usr and/or --with-apr-util=/usr.  Bug report 29740.
     [Max Bowsher &lt;maxb ukf.net&gt;]
   - mod_proxy: Fix ProxyRemoteMatch directive.  Bug report 33170.
     [Rici Lake &lt;rici ricilake.net&gt;]
   - mod_proxy: Respect errors reported by pre_connection hooks.
     [Jeff Trawick]
   - --with-module can now take more than one module to be statically
     linked: --with-module=&lt;modtype&gt;:&lt;modfile&gt;,&lt;modtype&gt;:&lt;modfile&gt;,...
     If the &lt;modtype&gt;-subdirectory doesn't exist it will be created and
     populated with a standard Makefile.in.  [Erik Abele]
   - Fix the RPM spec file so that an RPM build now works. An RPM
     build now requires system installations of APR and APR-util.
     Remove some arbitrary moving around of binaries - the RPM now
     maps to the ASF build of httpd.
     [Graham Leggett]
   - mod_dumpio, an I/O logging/dumping module, added to the
     modules/expermimental subdirectory.  [Jim Jagielski]
   - mod_auth_ldap: Handle the inconsistent way in which the MS LDAP
     library handles special characters.  Bug report 24437.
     [Jess Holle]
   - Win32 MPM: Correct typo in debugging output.  [William Rowe]
   - conf: Remove AddDefaultCharset from the default configuration because
     setting a site-wide default does more harm than good.
     Bug report 23421. [Roy Fielding]
   - Add charset to example CGI scripts.  [Roy Fielding]
   - mod_ssl: fail quickly if SSL connection is aborted rather than
     making many doomed ap_pass_brigade calls.
     Bug report 32699.  [Joe Orton]
   - Remove compiled-in upper limit on LimitRequestFieldSize.
     [Bill Stoddard]
   - Start keeping track of time-taken-to-process-request again for
     mod_status if ExtendedStatus is enabled. [Jim Jagielski]
   - mod_proxy: Handle client-aborted connections correctly.
     Bug report 32443.  [Janne Hietamäki, Joe Orton]
   - Fix handling of files &gt;2Gb on all platforms (or builds) where
     apr_off_t is larger than apr_size_t.
     Bug report 28898.  [Joe Orton]
   - mod_include: Fix bug which could truncate variable expansions
     of N*64 characters by one byte.  Bug report 32985.  [Joe Orton]
   - Correct handling of certain bucket types in ap_save_brigade, fixing
     possible segfaults in mod_cgi with #include virtual.
     Bug report 31247.  [Joe Orton]
   - Allow for the use of --with-module=foo:bar where the ./modules/foo
     directory is local only. Assumes, of course, that the required
     files are in ./modules/foo, but makes it easier to statically
     build/log "external" modules.  [Jim Jagielski]
   - Util_ldap: Implemented the util_ldap_cache_getuserdn() API so that
     ldap authorization only modules have access to the util_ldap
     user cache without having to require ldap authentication as well.
     Bug report 31898.  [Jari Ahonen jah progress.com, Brad Nicholes]
   - mod_auth_ldap: Added the directive "Requires ldap-attribute" that
     allows the module to only authorize a user if the attribute value
     specified matches the value of the user object. Bug report 31913
     [Ryan Morgan &lt;rmorgan pobox.com&gt;]
   - SECURITY: CAN-2004-0942 (cve.mitre.org)
     Fix for memory consumption DoS in handling of MIME folded request
     headers.  [Joe Orton]
   - SECURITY: CAN-2004-0885 (cve.mitre.org)
     mod_ssl: Fix a bug which allowed an SSLCipherSuite setting to be
     bypassed during an SSL renegotiation.  Bug report 31505.
     [Hartmut Keil &lt;Hartmut.Keil adnovum.ch&gt;, Joe Orton]
   - mod_ssl: Fail at startup rather than segfault at runtime if a
     client cert is configured with an encrypted private key.
     Bug report 24030.  [Joe Orton]
   - apxs: fix handling of -Wc/-Wl and "-o mod_foo.so".
     Bug report 31448 [Joe Orton]
   - mod_ldap: Fix format strings to use %APR_PID_T_FMT instead of %d.
     [Jeff Trawick]
   - mod_cache: CacheDisable will only disable the URLs it was meant to
     disable, not all caching. Bug report 31128.
     [Edward Rudd &lt;eddie omegaware.com&gt;, Paul Querna]
   - mod_cache: Try to correctly follow RFC 2616 13.3 on validating stale
     cache responses.  [Justin Erenkrantz]
   - mod_rewrite: Handle per-location rules when r-&gt;filename is unset.
     Previously this would segfault or simply not match as expected,
     depending on the platform.  [Jeff Trawick]
   - mod_rewrite: Fix 0 bytes write into random memory position.
     Bug report 31036. [André Malo]
   - mod_disk_cache: Do not store aborted content.  Bug report 21492.
     [Rüdiger Plüm &lt;r.pluem t-online.de&gt;]
   - mod_disk_cache: Correctly store cached content type.
     Bug report 30278.
     [Rüdiger Plüm &lt;r.pluem t-online.de&gt;]
   - mod_ldap: prevent the possiblity of an infinite loop in the LDAP
     statistics display. Bug report 29216. [Graham Leggett]
   - mod_ldap: fix a bogus error message to tell the user which file
     is causing a potential problem with the LDAP shared memory cache.
     Bug report 31431 [Graham Leggett]
   - mod_disk_cache: Do not store hop-by-hop headers.  [Justin Erenkrantz]
   - Fix the re-linking issue when purging elements from the LDAP cache
     Bug report 24801.  [Jess Holle &lt;jessh ptc.com&gt;]
   - mod_disk_cache: Fix races in saving responses.  [Justin Erenkrantz]
   - Fix Expires handling in mod_cache.  [Justin Erenkrantz]
   - Alter mod_expires to run at a different filter priority to allow
     proper Expires storage by mod_cache.  [Justin Erenkrantz]
</content>
</entry>
<entry>
<title>- Bump to nb5 to specifically address a new apache vuln:</title>
<updated>2004-12-18T08:42:12Z</updated>
<author>
<name>adrianp</name>
<email>adrianp</email>
</author>
<published>2004-12-18T08:42:12Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=c4a0095bbf3ad8336eaecccc125aa4541ab2a3f9'/>
<id>urn:sha1:c4a0095bbf3ad8336eaecccc125aa4541ab2a3f9</id>
<content type='text'>
  http://issues.apache.org/bugzilla/show_bug.cgi?id=31505
  http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0885
- Changes backported from apache CVS HEAD:
  http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_kernel.c?r1=1.110&amp;r2=1.111
  http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_init.c?r1=1.128&amp;r2=1.129
</content>
</entry>
<entry>
<title>Classes must be appended to SUBST_CLASSES.</title>
<updated>2004-12-07T22:25:50Z</updated>
<author>
<name>seb</name>
<email>seb</email>
</author>
<published>2004-12-07T22:25:50Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=ab045bfb27fc017d5188a8b7f7e0f2d09f9151a9'/>
<id>urn:sha1:ab045bfb27fc017d5188a8b7f7e0f2d09f9151a9</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Modify the apxs(8) script to use ${APR_LIBTOOL} as the libtool to</title>
<updated>2004-11-30T23:21:43Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2004-11-30T23:21:43Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=7d15665dcfa3b003ba962b47cbc100f9ae6ebd0b'/>
<id>urn:sha1:7d15665dcfa3b003ba962b47cbc100f9ae6ebd0b</id>
<content type='text'>
build modules if APR_LIBTOOL is defined in the environment.  Force
the use of the libtool wrapper by module packages by setting APR_LIBTOOL
in apache2/buildlink3.mk.  Bump the PKGREVISION.
</content>
</entry>
<entry>
<title>Pass DL_* flags to the compiler when linking httpd since it dlopens</title>
<updated>2004-11-26T23:07:58Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2004-11-26T23:07:58Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=dd2a88784a74303693e032a861cd551eba06095e'/>
<id>urn:sha1:dd2a88784a74303693e032a861cd551eba06095e</id>
<content type='text'>
shared modules.  Bump the PKGREVISION.
</content>
</entry>
<entry>
<title>There are additional headers installed if APACHE_MPM == "worker".</title>
<updated>2004-11-24T07:39:50Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2004-11-24T07:39:50Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=67db05106cd8b1141e0409285bba3ea54d8bc438'/>
<id>urn:sha1:67db05106cd8b1141e0409285bba3ea54d8bc438</id>
<content type='text'>
Handle this with the usual PLIST_SUBST magic.
</content>
</entry>
<entry>
<title>buildlink3.mk files should be included outside of the multiple inclusion</title>
<updated>2004-11-23T20:17:55Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2004-11-23T20:17:55Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=ba91829d8fc7f969c6d5816ef87cbcd088652ac2'/>
<id>urn:sha1:ba91829d8fc7f969c6d5816ef87cbcd088652ac2</id>
<content type='text'>
protected region (see mk/buildlink3/bsd.buildlink.mk).
</content>
</entry>
<entry>
<title>We don't need to check for APR_USE_* or generate our own _APR_OPTIONS</title>
<updated>2004-11-23T00:37:04Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2004-11-23T00:37:04Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=d5dee196c6fda133277eb6c9fed9d08d2df89953'/>
<id>urn:sha1:d5dee196c6fda133277eb6c9fed9d08d2df89953</id>
<content type='text'>
variable since the apr/buildlink3.mk file does the right thing for us
already; we simply need to include it and check the value of
PKG_OPTIONS.apr.
</content>
</entry>
<entry>
<title>* Create APACHE_MPM variable that can be either "prefork" or "worker"</title>
<updated>2004-11-22T22:52:53Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2004-11-22T22:52:53Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=6609a89cf1bfe1fb8e6d1aac64c657a5c8e080f6'/>
<id>urn:sha1:6609a89cf1bfe1fb8e6d1aac64c657a5c8e080f6</id>
<content type='text'>
  (defaulting to "prefork") that chooses the multi-processing model
  for apache to handle requests.  "Prefork" is the method used by
  Apache-1.3, which is non-threaded.  "Worker" uses threads to handle
  requests.

* Fix libtool usage in this package.  Apache uses libtool, but is
  hardcoded to use the libtool installed by devel/apr.  Patch the
  generated makefile fragment to use a local libtool instead, and
  allow the usual libtool wrapper to take its place.
</content>
</entry>
<entry>
<title>Convert to use bsd.options.mk: APACHE_SUEXEC is now the "suexec" option.</title>
<updated>2004-11-22T20:25:26Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2004-11-22T20:25:26Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=540d01b3c223ba923509daeb26463c09b44bcc3e'/>
<id>urn:sha1:540d01b3c223ba923509daeb26463c09b44bcc3e</id>
<content type='text'>
</content>
</entry>
</feed>
