]>
git.pld-linux.org Git - packages/apache.git/log
Elan Ruusamäe [Tue, 22 Aug 2017 08:35:05 +0000 (11:35 +0300)]
up to 2.2.34 (released 2017-07-11)
https://www.apache.org/dist/httpd/Announcement2.2.html
Take note that Apache Web Server Project will provide no future release
of the 2.2.x series, although some security patches may be published
through December of 2017. These will be collected at the URL;
http://www.apache.org/dist/httpd/patches/apply_to_2.2.34/
Elan Ruusamäe [Tue, 11 Jul 2017 08:50:03 +0000 (11:50 +0300)]
apply_to_2.2.32 patches; fixes CVE-2017-3167 CVE-2017-3169 CVE-2017-7668 CVE-2017-7679
Elan Ruusamäe [Mon, 16 Jan 2017 16:54:26 +0000 (18:54 +0200)]
up to 2.2.32 (released 2017-01-13); CVE-2016-8743, CVE-2016-5387
http://www-eu.apache.org/dist//httpd/CHANGES_2.2.32
Elan Ruusamäe [Wed, 31 Aug 2016 08:05:59 +0000 (11:05 +0300)]
drop webserver(reqtimeout)
too much copy paste in
2bd52d6
no such "module" is documented in webapps package README and unlikely
any webapp to use such in deps
Elan Ruusamäe [Thu, 5 May 2016 13:40:22 +0000 (16:40 +0300)]
use >= for openssl dep
Elan Ruusamäe [Wed, 2 Mar 2016 14:21:15 +0000 (16:21 +0200)]
depend on openssl VERSION
openssl abi can change with each version
httpd.prefork: Syntax error on line 71 of /etc/httpd/apache.conf:
Syntax error on line 2 of /etc/httpd/conf.d/40_mod_ssl.conf:
Cannot load /etc/httpd/modules/mod_ssl.so into server:
/etc/httpd/modules/mod_ssl.so: undefined symbol: SSLv2_client_method
Elan Ruusamäe [Wed, 2 Mar 2016 14:17:17 +0000 (16:17 +0200)]
- openssl 1.0.2g rebuild
- release 3 (by relup.sh)
Arkadiusz Miśkiewicz [Fri, 18 Sep 2015 21:21:21 +0000 (23:21 +0200)]
- up to 2.2.31 (SECURITY fixes in 2.2.30)
Elan Ruusamäe [Tue, 7 Oct 2014 13:15:50 +0000 (16:15 +0300)]
add RESTART_DELAY parameter to sleep between stop and start
Elan Ruusamäe [Thu, 19 Feb 2015 10:56:31 +0000 (12:56 +0200)]
add webserver(headers) provide
Arkadiusz Miśkiewicz [Tue, 9 Dec 2014 15:28:45 +0000 (16:28 +0100)]
- up to 2.2.29; fixes from 2.2.26: CVE-2014-0098, CVE-2013-6438, CVE-2014-0118, CVE-2014-0231, CVE-2014-0226, CVE-2013-5704
Elan Ruusamäe [Thu, 30 Jan 2014 22:31:56 +0000 (00:31 +0200)]
include mod_authz_default in metapackage
Andrzej Zawadzki [Thu, 28 Nov 2013 15:35:40 +0000 (16:35 +0100)]
- up to 2.2.26
Arkadiusz Miśkiewicz [Fri, 15 Nov 2013 18:28:34 +0000 (19:28 +0100)]
- rel 9; better way of dealing with children at graceful reload
Arkadiusz Miśkiewicz [Fri, 7 Jun 2013 11:52:05 +0000 (13:52 +0200)]
- force new openssl version (to avoid runtime errors like undefined symbol: SRP_VBASE_free)
Arkadiusz Miśkiewicz [Sun, 14 Apr 2013 16:21:12 +0000 (18:21 +0200)]
- rel 8; that way works only for http dummy connection (won't work for https dummy)
Arkadiusz Miśkiewicz [Fri, 12 Apr 2013 15:51:27 +0000 (17:51 +0200)]
- rel 7; prevent apache from hanging too long in graceful restart
Arkadiusz Miśkiewicz [Thu, 11 Apr 2013 12:54:41 +0000 (14:54 +0200)]
- rel 6; backport fix optimizing loading config files with thousands of vhosts
Arkadiusz Miśkiewicz [Thu, 11 Apr 2013 10:02:13 +0000 (12:02 +0200)]
- don't even apply itk code when bcond off (to avoid problems with this unmaintained patch)
Arkadiusz Miśkiewicz [Wed, 10 Apr 2013 19:25:54 +0000 (21:25 +0200)]
- rel 5; grr hunk fix
Arkadiusz Miśkiewicz [Wed, 10 Apr 2013 19:10:40 +0000 (21:10 +0200)]
- rel 4; one missing hunk added
Arkadiusz Miśkiewicz [Wed, 10 Apr 2013 18:36:23 +0000 (20:36 +0200)]
- rel 3; in 2.2.24 the way internal dummy connection is done for SSL connection has changed which caused serious issues for me (like graceful restart taking minutes). Most likely sending TLS 1.0 fake dummy close is not interoperating nicely with openssl 1.0.1. Workaround that by backporting upstream fix for 39653 (aka use non-ssl internal dummy connection when possible).
Arkadiusz Miśkiewicz [Wed, 10 Apr 2013 07:41:57 +0000 (09:41 +0200)]
- seed some bytes of entropy instead of 0 bytes
Arkadiusz Miśkiewicz [Tue, 9 Apr 2013 16:08:32 +0000 (18:08 +0200)]
- rel 2; bugfixes for upstream 49058 and 39311 (prefork only)
Arkadiusz Miśkiewicz [Tue, 9 Apr 2013 13:58:23 +0000 (15:58 +0200)]
- backport fix for upstream bug 49058
Patryk Szczyglowski [Sat, 30 Mar 2013 20:04:40 +0000 (21:04 +0100)]
Disable compression on the SSL level (CRIME attack).
Elan Ruusamäe [Mon, 4 Mar 2013 15:48:19 +0000 (17:48 +0200)]
up to 2.2.24
Elan Ruusamäe [Sun, 25 Nov 2012 14:44:48 +0000 (16:44 +0200)]
- allow work without systemd-units
Arkadiusz Miśkiewicz [Sun, 25 Nov 2012 12:04:17 +0000 (13:04 +0100)]
- up to 2.2.23; fixes CVE-2012-0883, CVE-2012-2687
Jan Rękorajski [Tue, 17 Apr 2012 16:57:32 +0000 (16:57 +0000)]
- rel 7
- better systemd deps
Changed files:
apache.spec -> 1.643.2.3
Artur Frysiak [Thu, 29 Mar 2012 07:16:32 +0000 (07:16 +0000)]
- fix compilation with pcre 8.30
- rel. 6
Changed files:
apache.spec -> 1.643.2.2
cvs2git [Thu, 29 Mar 2012 07:15:21 +0000 (07:15 +0000)]
This commit was manufactured by cvs2git to create branch 'APACHE_2_2'.
Cherrypick from master 2012-03-29 07:15:21 UTC Artur Frysiak <artur@frysiak.net> '- fix for compilation with pcre 8.30':
pcre8.30.patch -> 1.1
Arkadiusz Miśkiewicz [Wed, 28 Mar 2012 12:15:39 +0000 (12:15 +0000)]
- rel 5
Changed files:
apache.spec -> 1.643.2.1
cvs2git [Fri, 17 Feb 2012 19:21:49 +0000 (19:21 +0000)]
This commit was manufactured by cvs2git to create branch 'APACHE_2_2'.
Sprout from master 2012-02-17 19:21:49 UTC Jan Rękorajski <baggins@pld-linux.org> '- rel 4'
Delete:
apache-mod_ssl-vhost.conf
apache-revert-bug-40463.patch
Jan Rękorajski [Fri, 17 Feb 2012 19:21:49 +0000 (19:21 +0000)]
- rel 4
- typo in macros
Changed files:
apache.spec -> 1.643
Jan Rękorajski [Fri, 17 Feb 2012 18:25:02 +0000 (18:25 +0000)]
- rel 3
- cleanup sysvinit/systemd hacks
Changed files:
apache.spec -> 1.642
Elan Ruusamäe [Thu, 9 Feb 2012 16:05:09 +0000 (16:05 +0000)]
- add note about %b and %B and suggest %O
Changed files:
apache-mod_log_config.conf -> 1.4
Jakub Bogusz [Wed, 1 Feb 2012 19:43:11 +0000 (19:43 +0000)]
- more verbose files in system-wide dirs
Changed files:
apache.spec -> 1.641
Artur Frysiak [Wed, 1 Feb 2012 16:04:39 +0000 (16:04 +0000)]
- systemd support
- rel. 2
Changed files:
apache.logrotate -> 1.16
apache.service -> 1.1
apache.spec -> 1.640
apache.sysconfig -> 1.18
Arkadiusz Miśkiewicz [Tue, 31 Jan 2012 21:24:43 +0000 (21:24 +0000)]
- up to 2.2.22; fixes CVE-2011-3368, CVE-2011-3607, CVE-2011-4317, CVE-2012-0021, CVE-2012-0031, CVE-2012-0053
Changed files:
apache.spec -> 1.639
Jan Rękorajski [Tue, 31 Jan 2012 11:50:25 +0000 (11:50 +0000)]
- release 5
Changed files:
apache.spec -> 1.638
Jan Rękorajski [Mon, 30 Jan 2012 20:35:06 +0000 (20:35 +0000)]
- rel 4
- added tmpfiles config for systemd
Changed files:
apache.spec -> 1.637
Jan Rękorajski [Mon, 30 Jan 2012 18:48:36 +0000 (18:48 +0000)]
- add systemd tmpfiles config
Changed files:
apache.tmpfiles -> 1.1
psz [Tue, 25 Oct 2011 09:40:41 +0000 (09:40 +0000)]
ServerTokens Full->Prod to hide specific Apache/Modules version information in both Server: header and generated messages.
Changed files:
apache-httpd.conf -> 1.58
hawk [Thu, 13 Oct 2011 18:35:20 +0000 (18:35 +0000)]
- release 3
Changed files:
apache.spec -> 1.636
lisu [Wed, 12 Oct 2011 07:34:09 +0000 (07:34 +0000)]
- rel 2
Changed files:
apache.spec -> 1.635
Jakub Bogusz [Sun, 18 Sep 2011 16:44:42 +0000 (16:44 +0000)]
- dropped db-devel, expat-devel BRs (apr dependencies, not apache itself)
- dropped gdbm-devel BR (seems no longer used)
Changed files:
apache.spec -> 1.634
lisu [Wed, 14 Sep 2011 12:56:20 +0000 (12:56 +0000)]
- obsoleted
Changed files:
apache-bug-51748.patch -> 1.2
lisu [Wed, 14 Sep 2011 12:52:53 +0000 (12:52 +0000)]
- updated to 2.2.21 by shadzik
- -bug-51748.patch is obsoleted
Changed files:
apache.spec -> 1.633
Arkadiusz Miśkiewicz [Sun, 4 Sep 2011 18:25:03 +0000 (18:25 +0000)]
- rel 2; fix for range fix regression; probably there will be 2.2.21 due to this
Changed files:
apache-bug-51748.patch -> 1.1
apache.spec -> 1.632
Arkadiusz Miśkiewicz [Wed, 31 Aug 2011 16:36:43 +0000 (16:36 +0000)]
- back to standard url
Changed files:
apache.spec -> 1.631
Elan Ruusamäe [Tue, 30 Aug 2011 10:37:32 +0000 (10:37 +0000)]
- allow older apr for ac
Changed files:
apache.spec -> 1.630
Arkadiusz Miśkiewicz [Tue, 30 Aug 2011 10:17:35 +0000 (10:17 +0000)]
- up to 2.2.20 (in process of being released); fixes CVE-2011-3192
Changed files:
apache.spec -> 1.629
byterange-no-merge.2.2.diff -> 1.2
Arkadiusz Miśkiewicz [Mon, 29 Aug 2011 12:22:44 +0000 (12:22 +0000)]
- rel 4; use currently available (unofficial) fix for latest 'Range' vuln.
Changed files:
apache.spec -> 1.628
byterange-no-merge.2.2.diff -> 1.1
Adam Gołębiowski [Sun, 21 Aug 2011 10:58:50 +0000 (10:58 +0000)]
- remove ssl_scache on startup, otherwise httpd may go into infinite loop
if there are db transaction logs laying around
Changed files:
apache.init -> 1.70
Elan Ruusamäe [Sat, 13 Aug 2011 19:27:46 +0000 (19:27 +0000)]
- Vary on User-Agent is insame, Vary on Accept-Encoding instead, also decaces old netscape4 "support" should go out too
Changed files:
apache-mod_deflate.conf -> 1.12
apache.spec -> 1.627
Tomasz Pala [Wed, 3 Aug 2011 22:42:16 +0000 (22:42 +0000)]
- do not checkconfig twice on restart, one time before stop is enough (skip
at start); do we need checkconfig during start at all? It's pointless with
proper config (normal situation, only makes start slower), and start itself
would fail on error (no real gain here). I'd go for checkconfig before
restart only for all services. RFC
Changed files:
apache.init -> 1.69
Tomasz Pala [Wed, 3 Aug 2011 22:08:10 +0000 (22:08 +0000)]
- ko mode was in affect...
Changed files:
apache.sysconfig -> 1.17
Tomasz Pala [Wed, 3 Aug 2011 22:03:47 +0000 (22:03 +0000)]
- fixed Id CVS keyword
Changed files:
apache.sysconfig -> 1.16
Tomasz Pala [Wed, 3 Aug 2011 21:41:48 +0000 (21:41 +0000)]
- missingok for vhosts.d/example.net.conf, non-interactive and not forced rm
Changed files:
apache.spec -> 1.626
Arkadiusz Miśkiewicz [Mon, 13 Jun 2011 06:34:57 +0000 (06:34 +0000)]
- release 2
Changed files:
apache.spec -> 1.625
Arkadiusz Miśkiewicz [Tue, 7 Jun 2011 09:09:37 +0000 (09:09 +0000)]
- no default encoding as it causes apache sends this encoding in every response headers thus breaking apps that don't use utf8 and rely on html charset info
Changed files:
apache-httpd.conf -> 1.57
Arkadiusz Miśkiewicz [Sun, 22 May 2011 17:57:15 +0000 (17:57 +0000)]
- up to 2.2.19; fixes ABI breakage introduced in .18
Changed files:
apache.spec -> 1.624
Arkadiusz Miśkiewicz [Mon, 16 May 2011 08:18:03 +0000 (08:18 +0000)]
- up to 2.2.18; fixes CVE-2011-0419; make it depend on apr 1.4.4 (security fixes)
Changed files:
apache-bug-41743.patch -> 1.2
apache-mpm-itk.patch -> 1.2
apache.spec -> 1.623
Elan Ruusamäe [Sun, 3 Apr 2011 13:22:25 +0000 (13:22 +0000)]
- default UTF-8 encoding
Changed files:
apache-httpd.conf -> 1.56
apache-mod_autoindex.conf -> 1.10
apache.spec -> 1.622
psz [Tue, 29 Mar 2011 13:47:19 +0000 (13:47 +0000)]
- added text/javascript to mod_deflate
Changed files:
apache-mod_deflate.conf -> 1.11
Elan Ruusamäe [Sat, 26 Mar 2011 19:54:13 +0000 (19:54 +0000)]
- use apu-1-config with exact db version in libs for build sanity
Changed files:
apache.spec -> 1.621
Elan Ruusamäe [Sat, 26 Mar 2011 17:03:45 +0000 (17:03 +0000)]
- add libtool --tag
Changed files:
libtool-tag.patch -> 1.1
Elan Ruusamäe [Sat, 26 Mar 2011 16:30:14 +0000 (16:30 +0000)]
- pass --tag to libtool to build with ccache
Changed files:
apache.spec -> 1.620
Jan Rękorajski [Thu, 10 Mar 2011 11:34:01 +0000 (11:34 +0000)]
- disable itk by default (last release 2009), try mod_ruid2
Changed files:
apache.spec -> 1.619
Jan Rękorajski [Thu, 10 Mar 2011 10:55:41 +0000 (10:55 +0000)]
- rel 9
Changed files:
apache.spec -> 1.618
Jan Rękorajski [Thu, 10 Mar 2011 10:51:17 +0000 (10:51 +0000)]
- typo
- install itk stuff
Changed files:
apache.spec -> 1.617
Jan Rękorajski [Thu, 10 Mar 2011 10:41:03 +0000 (10:41 +0000)]
- added ITK MPM
Changed files:
apache-mpm-itk.patch -> 1.1
apache.spec -> 1.616
Arkadiusz Miśkiewicz [Sun, 13 Feb 2011 18:53:04 +0000 (18:53 +0000)]
- rel 8; fix graceful restart for keepalive connections
Changed files:
apache-bug-41743.patch -> 1.1
apache.spec -> 1.615
Elan Ruusamäe [Wed, 2 Feb 2011 15:58:22 +0000 (15:58 +0000)]
- release 7
Changed files:
apache.spec -> 1.614
Elan Ruusamäe [Wed, 2 Feb 2011 15:55:52 +0000 (15:55 +0000)]
- rpmlint: W: unexpanded-macro dependency openssl >= %{openssl_version} %{openssl_version}
Changed files:
apache.spec -> 1.613
shadzik [Mon, 27 Dec 2010 19:05:06 +0000 (19:05 +0000)]
- rel 6, reverted back suexec_fcgi.patch
Changed files:
apache.spec -> 1.612
shadzik [Mon, 27 Dec 2010 09:45:03 +0000 (09:45 +0000)]
- reverted, seems to be right that way, but won't work for me...
Changed files:
apache-suexec_fcgi.patch -> 1.3
shadzik [Sun, 26 Dec 2010 19:55:55 +0000 (19:55 +0000)]
- rel 5
Changed files:
apache.spec -> 1.611
shadzik [Sun, 26 Dec 2010 19:55:45 +0000 (19:55 +0000)]
- typo!!
- this should only apply if the prog name is NOT suexec.fcgi
Changed files:
apache-suexec_fcgi.patch -> 1.2
shadzik [Sat, 13 Nov 2010 11:59:22 +0000 (11:59 +0000)]
- rel 4
Changed files:
apache.spec -> 1.610
Adam Gołębiowski [Sun, 31 Oct 2010 09:18:28 +0000 (09:18 +0000)]
- mod_dav += R: apr-util-dbm-db; release 3
Changed files:
apache.spec -> 1.609
Elan Ruusamäe [Thu, 21 Oct 2010 09:43:21 +0000 (09:43 +0000)]
- release 2
Changed files:
apache.spec -> 1.608
shadzik [Wed, 20 Oct 2010 12:02:48 +0000 (12:02 +0000)]
- upstream
Changed files:
apache-bug-40970.patch -> 1.6
shadzik [Wed, 20 Oct 2010 12:02:14 +0000 (12:02 +0000)]
- 2.2.17
Changed files:
apache.spec -> 1.607
Jakub Bogusz [Sun, 26 Sep 2010 11:15:55 +0000 (11:15 +0000)]
- pl fix
Changed files:
apache.spec -> 1.606
Jakub Bogusz [Sun, 26 Sep 2010 11:13:03 +0000 (11:13 +0000)]
- mod_case_filter,mod_case_filter_in descriptions
Changed files:
apache.spec -> 1.605
Arkadiusz Miśkiewicz [Sat, 25 Sep 2010 10:27:52 +0000 (10:27 +0000)]
- use upstream patch that adds -T for not doing some checks instead of dropping is_dir check in the code
Changed files:
apache-bug-40970.patch -> 1.5
apache.spec -> 1.604
apache.sysconfig -> 1.15
Elan Ruusamäe [Wed, 1 Sep 2010 10:53:46 +0000 (10:53 +0000)]
- revert wrong branch commit (update to 2.3.6, now tagged as DEVEL)
Changed files:
apache-apxs.patch -> 1.10
apache-paths.patch -> 1.3
apache.spec -> 1.603
httpd-2.0.45-encode.patch -> 1.5
httpd-2.0.46-sslmutex.patch -> 1.4
httpd-2.0.48-corelimit.patch -> 1.3
httpd-2.0.48-debuglog.patch -> 1.3
httpd-2.2.x-mod_ssl-sessioncaching.patch -> 1.4
Elan Ruusamäe [Wed, 1 Sep 2010 10:50:37 +0000 (10:50 +0000)]
- updated patches to 2.3.8, does not fully compile
Changed files:
apache-apxs.patch -> 1.9
apache-paths.patch -> 1.2
apache.spec -> 1.602
httpd-2.0.45-encode.patch -> 1.4
httpd-2.0.46-sslmutex.patch -> 1.3
httpd-2.0.48-corelimit.patch -> 1.2
httpd-2.0.48-debuglog.patch -> 1.2
httpd-2.2.x-mod_ssl-sessioncaching.patch -> 1.3
pawelz [Sat, 28 Aug 2010 22:13:07 +0000 (22:13 +0000)]
- authz for DocumentRoot
Changed files:
apache-example.net.conf -> 1.4
pawelz [Sat, 28 Aug 2010 22:10:01 +0000 (22:10 +0000)]
- DocumentRoot consistent with directories structure provided by apache package
Changed files:
apache-example.net.conf -> 1.3
shadzik [Tue, 3 Aug 2010 07:39:00 +0000 (07:39 +0000)]
- rel 1, builds
Changed files:
apache.spec -> 1.601
shadzik [Tue, 3 Aug 2010 07:37:23 +0000 (07:37 +0000)]
- 2.2.16
- rel 0.1
- fixes CVE-2010-1452 CVE-2010-2068
Changed files:
apache.spec -> 1.600
psz [Tue, 6 Jul 2010 08:18:18 +0000 (08:18 +0000)]
disable SSLv2
Changed files:
apache-mod_ssl.conf -> 1.20
apache.spec -> 1.599
Elan Ruusamäe [Tue, 11 May 2010 11:10:16 +0000 (11:10 +0000)]
- missing configtest on restart
Changed files:
apache.init -> 1.68
Tomasz Pala [Sat, 17 Apr 2010 15:14:14 +0000 (15:14 +0000)]
- please, man test
Changed files:
apache.init -> 1.67
Arkadiusz Miśkiewicz [Sat, 10 Apr 2010 20:47:14 +0000 (20:47 +0000)]
- release 3
Changed files:
apache.spec -> 1.598
aredridel [Tue, 23 Mar 2010 00:32:30 +0000 (00:32 +0000)]
- added mod_vhost_alias_docroot patch, making mod_vhost_alias actually
equivalent to multiple <VirtualHost>s
Changed files:
apache.spec -> 1.597
aredridel [Tue, 23 Mar 2010 00:31:52 +0000 (00:31 +0000)]
- added
Changed files:
apache-mod_vhost_alias_docroot.patch -> 1.1
This page took 0.089675 seconds and 4 git commands to generate.