| Commit message (Collapse) | Author | Age | Files | Lines |
... | |
|
|
|
|
|
|
|
|
|
|
| |
WARNING: apache2 + apr 1.0 is BROKEN
I'm working on a small compat hack. But don't dream too much.
apache 2.0.x is not designed to work with apr 1.x.
Forgotten by: kuriyama
Notes:
svn path=/head/; revision=119575
|
|
|
|
|
|
|
| |
Pointy Hat Autumn Collection 2004 to: kuriyama
Notes:
svn path=/head/; revision=119564
|
|
|
|
|
|
|
|
| |
www/www).
It should help to keep consistancy in www-related ports.
Notes:
svn path=/head/; revision=119232
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Fix CAN-2004-0885:
* modules/ssl/ssl_engine_kernel.c (ssl_hook_Access): Ensure that a
correct cipher suite has been negotiated, else deny access.
* modules/ssl/ssl_engine_init.c (ssl_init_ctx_protocol): With OpenSSL
0.9.7, prevent session resumption during a renegotiation to force the
client to negotiate a new (and acceptable) cipher suite.
Credits: Hartmut Keil, Joe Orton
Notes:
svn path=/head/; revision=119190
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
- Use "PORTDOCS= #" and get rid of docs entry in plist.
- Support for FreeBSD 6 in apr
- Move of cache modules from THREADS to EXPERIMENTAL category and make
sure we enable THREADS modules (cgid only) when a threaded MPM is
selected.
- Resurect WITH_EXTRA_MODULES knob
- powerlogo.gif is now hosted by FreeBSD mirrors
- WITH_<category> is definitively no longer supported.
- Add Includes dir when installed via a package [1]
PR: ports/72309 [1]
Submitted by: Christian Kratzer <ck at cksoft dot de> [1]
Notes:
svn path=/head/; revision=118860
|
|
|
|
|
|
|
| |
Approved by: portmgr (krion)
Notes:
svn path=/head/; revision=118596
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
*) SECURITY: CAN-2004-0786 (cve.mitre.org)
Fix an input validation issue in apr-util which could be
triggered by malformed IPv6 literal addresses. [Joe Orton]
*) SECURITY: CAN-2004-0747 (cve.mitre.org)
Fix buffer overflow in expansion of environment variables in
configuration file parsing. [Andr<E9> Malo]
*) SECURITY: CAN-2004-0809 (cve.mitre.org)
mod_dav_fs: Fix a segfault in the handling of an indirect lock
refresh. PR 31183. [Joe Orton]
- Update documentation (finally!) and fix WITH_<CATEGORY>_MODULES
for special modules like LDAP or SSL [2]
Noticed by: nectar [1]
Requested by: Emile Heitor <imil at home dot imil dot net> [2]
Approved by: portmgr (marcus)
Notes:
svn path=/head/; revision=118182
|
|
|
|
|
|
|
| |
Discussed with: eik (long time ago)
Notes:
svn path=/head/; revision=118032
|
|
|
|
|
|
|
| |
restarting apache2 (to avoid an expected failure on restart)
Notes:
svn path=/head/; revision=117133
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* WITH_EXCEPTION_HOOK now exists
* Automatically add if WITH_DEBUG is set
* Update still-outdated-documentation
- Remove automatic debuf mode if DEBUG_FLAGS is set
Exception hook is very useful for debugging (upcoming www/mod_backtrace
and www/mod_whatkilledus modules)
Makefile.modules.3rd:
- Fix CONFIGURE_ARGS for dynamic module selection.
It's now fully usuable for apache13 ports
- Remove an useless WANT_APACHE check
- Move apxs detection at the beginning of the file, to use APXS_PREFIX
for apache major version detection [1]
The main advantage of this patch is to provide a nice way to
have multiple apache versions, without altering ${LOCALBASE}.
Submitted by: "ports/c0decafe.net" <ports at c0decafe dot net> [1]
Notes:
svn path=/head/; revision=116693
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* [SECURITY] mod_ssl: Fix potential input filter segfaults in
SPECULATIVE mode. (rollback handling for AP_MODE_SPECULATIVE)
"This issue has possible security implications; it's been assigned CVE
CAN-2004-0751 (cve.mitre.org)."
http://issues.apache.org/bugzilla/show_bug.cgi?id=30134
* [SECURITY] mod_ssl: Fix potential infinite loop.
(potential infinite loop in ssl_io_input_getline if connection is
aborted without inctx->rc being set.)
http://issues.apache.org/bugzilla/show_bug.cgi?id=27945
http://issues.apache.org/bugzilla/show_bug.cgi?id=29690
Obtained from: Apache CVS (httpd-2.0 HEAD)
Notes:
svn path=/head/; revision=116629
|
|
|
|
|
|
|
|
|
| |
- Allow access to /home if mod_userdir is loaded
- We don't need apache2libs.sh if apr is installed from ports.
- Add recent changes to UPGRADING
Notes:
svn path=/head/; revision=116513
|
|
|
|
|
|
|
| |
since 2.0.48
Notes:
svn path=/head/; revision=115584
|
|
|
|
|
|
|
| |
library.
Notes:
svn path=/head/; revision=115583
|
|
|
|
|
|
|
| |
Requested by, discussed with: lev
Notes:
svn path=/head/; revision=115479
|
|
|
|
|
|
|
| |
Noticed by: Roderick van Domburg <r.s.a.vandomburg@student.utwente.nl>
Notes:
svn path=/head/; revision=115261
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Makefile.modules:
- Export rewritten modules selection from Makefile.modules
to Makefile.modules.3rd
- Remove proxy support by default.
Makefile.modules.3rd:
- Add support for WANT_APACHE common13/common2 to share
code/functionalities between apache13 and apache2 server ports.
Rewrite of modules selection:
- WITH_MODULES and WITHOUT_MODULES are no more conflicting
WITHOUT_MODULES can be safely used internally to remove conflicting
modules
- Selection is based on modules categories to improve flexibility
- WITH_${category}[_MODULES]
- WITHOUT_${category}
- WITH_CUSTOM_${category}
- Support apache13, apache2{0,1}
This is EXPERIMENTAL. I'll test it IRL with www/apache13-ssl,
and it should be easily usuable in future bsd.apache.mk
Notes:
svn path=/head/; revision=115245
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
o Changes in httpd.conf
- mod_userdir:
. set Userdir if mod_userdir is loaded [1]
. Userdir is denied for users from /etc/ftpusers
- set more "secure" permissions.
By default, policy is to deny access to filesystem.
You HAVE to _ENABLE_ access to your filesystem in httpd.conf.
- Add an "Includes" directory to ${PREFIX}/etc/apache2/
to make configuration more flexible
${PREFIX}/etc/apache2/*.conf files are now automatically loaded.
o apache.sh
- be closer to apachectl, apache.sh need envvars [2]
It should restore subversion behavior.
Partially submitted by:
kuriyama [1],
Gregory (Grisha) Trubetskoy <grisha at apache dot org> [2]
Future changes are mostly written, they should be committed during the
week-end.
If you're interrested in changes, feel free contact me.
Notes:
svn path=/head/; revision=115092
|
|
|
|
| |
Notes:
svn path=/head/; revision=113544
|
|
|
|
|
|
|
| |
Obtained from: apr CVS
Notes:
svn path=/head/; revision=113537
|
|
|
|
|
|
|
|
|
|
| |
- Add WITHOUT_V4MAPPED knob and explicitly set --disable-v4-mapped
if WITHOUT_V4MAPPED or WITH_IPV6_V6ONLY
Also submitted by: Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp> [1]
Notes:
svn path=/head/; revision=113536
|
|
|
|
|
|
|
|
| |
It fixes problems when you deinstall a port with $PREFIX != $(apxs -q
prefix). Now plist is aware of real location of apache module.
Notes:
svn path=/head/; revision=113383
|
|
|
|
|
|
|
|
|
|
| |
when --enable-v4-mapped is used (default).
Use WITHOUT_IPV6 knob if you have problem with "HostnameLookup On" on
IPv4-only server(s).
I hope I can provide a real fix soon.
Notes:
svn path=/head/; revision=113285
|
|
|
|
|
|
|
|
|
| |
and share/nls/POSIX
Noticed by: thierry
Notes:
svn path=/head/; revision=112874
|
|
|
|
|
|
|
| |
- Add NOTICE file to respect Apache 2.0 license
Notes:
svn path=/head/; revision=112777
|
|
|
|
|
|
|
| |
looking like a reverse patching.
Notes:
svn path=/head/; revision=112683
|
|
|
|
|
|
|
|
|
|
|
| |
libtool14 (13/15).
PR: 67768
Submitted by: ade
Approved by: 4-exp bento runs (thanks, kris!)
Notes:
svn path=/head/; revision=112679
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Important changes:
*) SECURITY: CAN-2004-0493 (cve.mitre.org)
Close a denial of service vulnerability identified by Georgi
Guninski which could lead to memory exhaustion with certain
input data. [Jeff Trawick]
*) SECURITY: CAN-2004-0488 (cve.mitre.org)
mod_ssl: Fix a buffer overflow in the FakeBasicAuth code for a
(trusted) client certificate subject DN which exceeds 6K in length.
[Joe Orton]
Details can be found here:
http://www.apache.org/dist/httpd/CHANGES_2.0
- Use autoconf 2.59
- Add add SUEXEC_LOGFILE tunable to set suexec logfile [1]
- Silently ignore removal of libexec/apache2 directory
- Import latest version of apr_reslit.c from apr CVS which
adds timeout feature to apr_reslist_acquire().
This is required for future mod_logio-st.
- Add explicit dependency on libiconv (so nowwe support libiconv)
- Move Windows Update fix from MASTER_SITE_LOCAL to ports tree
- add WITH_EXPERIMENTAL_PATCHES knobs:
These patches are backports from apache CVS HEAD or apr CVS HEAD.
They have positive impacts on apache responsiveness but can be
instable
and are NOT currently supported by apache/apr teams.
* exp-http-ready.patch: add "httpready" support for ACCEPT_FILTER
(currently apache 2 only support "dataready")
* exp-apr-kqueue.patch: add support for kqueue in apr_poll().
This patch greatly improves apache network performance (up to
18% according to the author, on my test box, between 13% and 21%)
Test and feedback on -STABLE are welcome ;)
For more details, please see:
http://marc.theaimsgroup.com/?t=108650227500001&r=1&w=2
Submitted by: knu [1]
NOTE:
Please set MASTER_SITE_APACHE_HTTPD to closest mirrors.
you can easily find them from:
http://www.apache.org/dyn/closer.cgi/httpd/
Thanks :
Notes:
svn path=/head/; revision=112641
|
|
|
|
|
|
|
|
|
|
|
| |
CAN-2004-0493 - memory exhaustion denial of service
http://www.freebsd.org/ports/portaudit/81a8c9c2-c94f-11d8-8898-000d6111a684.html
Noticed by: eik
Obtained from: apache CVS
Notes:
svn path=/head/; revision=112522
|
|
|
|
| |
Notes:
svn path=/head/; revision=111131
|
|
|
|
|
|
|
|
| |
apachectl
- fix limits (missing eval)
Notes:
svn path=/head/; revision=111015
|
|
|
|
|
|
|
| |
Noticed by: Hutterer Robert <robert.hutterer@univie.ac.at>
Notes:
svn path=/head/; revision=110963
|
|
|
|
| |
Notes:
svn path=/head/; revision=110887
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
-2- add WITH_DEBUG knob (supports DEBUG_FLAGS)
-3- convert start script to RCng [1]
- add possibility to run limits(1) before apache starts
- apache2.sh reload = apachectl graceful
-4- Add threadpool MPM
-5- Adapt COMMENT to fit MPM.
-6- Bump PORTREVISION
PR: ports/66955 [1]
Submitted by: nork [1] (partially)
Requested by: ume [1]
Notes:
svn path=/head/; revision=110873
|
|
|
|
|
|
|
| |
Noticed by: kris
Notes:
svn path=/head/; revision=110652
|
|
|
|
| |
Notes:
svn path=/head/; revision=110327
|
|
|
|
| |
Notes:
svn path=/head/; revision=110323
|
|
|
|
|
|
|
|
| |
- Advertise ServerToken i.e.:
Apache/2.0.49 (FreeBSD) Server at satan.cultdeadsheep.org Port 80
Notes:
svn path=/head/; revision=110319
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* modules/ssl/ssl_engine_kernel.c (ssl_hook_UserCheck): Fix buffer
overflow in FakeBasicAuth code if client's subject DN exceeds 6K in
length (CVE CAN-2004-0488); switch to using apr-util base64 encoder
functions.
- ... and of course bump PORTREVISION.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0488
http://secunia.com/advisories/11534/
Reported by: Charles-Damien Orbello <tazma@cultdeadsheep.org>
Notes:
svn path=/head/; revision=110202
|
|
|
|
|
|
|
| |
Notice by: Fritz Heinrichmeyer <fritz.heinrichmeyer@fernuni-hagen.de>
Notes:
svn path=/head/; revision=109433
|
|
|
|
|
|
|
| |
It has been living out the tree for historical reason.
Notes:
svn path=/head/; revision=109429
|
|
|
|
|
|
|
| |
- use libtool 1.5.6
Notes:
svn path=/head/; revision=109425
|
|
|
|
|
|
|
| |
Per linimon's request correct {mis,ab}use of BROKEN.
Notes:
svn path=/head/; revision=109333
|
|
|
|
|
|
|
|
|
|
|
|
| |
- Cosmectic change in autogenerated plist (run apxs before the removal
of the module file, it can make apxs fail if you change module
name/shortname)
Forgotten by: me [1]
Reminded by: discussion with kris [1]
Notes:
svn path=/head/; revision=107350
|
|
|
|
|
|
|
|
|
| |
AP_INC and AP_LIB were added.
Reminded by: mod_vdbh port
Notes:
svn path=/head/; revision=107228
|
|
|
|
| |
Notes:
svn path=/head/; revision=107222
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
It can not be used with USE_APACHE knob.
Most important knobs:
WANT_APACHE= {13,2}
Apache version required. if undefined, both apache version
are allowed.
AP_FAST_BUILD
Do ${APXS} -c ${APXS} -i for you
AP_GENPLIST
Autogenerate a _SIMPLE_ plist:
See future commits to know how to use this file.
Notes:
svn path=/head/; revision=107217
|
|
|
|
|
|
|
|
|
|
|
|
| |
This shouldn't have been fixed, but I don't like setting UID and GID
variables.
so ${*} -> ${WWW*}
PR: 64032
Noticed by: Patrick Schoenfeld <schoenfeld@in-medias-res.com>
Notes:
svn path=/head/; revision=106411
|
|
|
|
|
|
|
|
|
|
| |
WITH_PTHREAD_LIBS and WITH_PTHREAD_CFLAGS are now working again
WARNING: This option is still NOT offically supported.
You can't flame me,but you still cansend me some backtrace ;-)
Notes:
svn path=/head/; revision=105348
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Full ChangeLogand announcement:
http://www.apache.org/dist/httpd/Announcement2.html
Port changes:
- buildconf patches improvement
- Fix typo [1]
PR: 64297 [1]
Submitted by: TSUMAI Yasuyuki <ral@ta-ko.jp> [1]
Notes:
svn path=/head/; revision=104730
|