httpd

Checkout Tools
  • last updated 4 hours ago
Constraints
Constraints: committers
 
Constraints: files
Constraints: dates

Changeset 979117 is being indexed.

hide win32 bins/sources until they exist
rebuild site
Prep 2.2.16

Propose backport

add test for RequireAll/RequireAny containers and AuthzMerging

  1. /test/framework/trunk/t/htdocs/authz_core
  2. /test/framework/trunk/t/htdocs/authz_core/a
    • ?
    /test/framework/trunk/t/modules/authz_core.t
  3. /test/framework/trunk/t/htdocs/authz_core/a/b
    • ?
    /test/framework/trunk/t/htdocs/authz_core/a/index.html
Updates.

The added path is canceled out by the next one,

but without it the sequence doesn't apply cleanly.

Fix typo.

Fix typo in CHANGES.

remove CHANGES entry of change reverted as part of r964156

Merge mod_dir fixups to avoid possible ordering issues noted by trawick

add proposal (this bug has caused quite some problems in Ubuntu 10.4)

expose subprocess_env on lua request object
r966869 required mmn bump

Applied accepted backport 164538.

Add backport proposal.

Cleaned up NetWare makefiles:

- removed obsolete -prefix compiler switch since already defined global for all files

- removed obsolete include paths

- changed include paths to use internal vars so hat apr/apr-util builds outside source tree

- removed trailing tabs and spaces, other minor cosmetic changes

  1. … 28 more files in changeset.
Removed obsolete include paths from NetWare makefiles.

  1. … 68 more files in changeset.
Use temp_pool not pool for a string that's a temp

Update documentation for AddOutputFilterByType move

Support multiple names in reimplemented AddOutputFilterByType

Move AddOutputFilterByType implementation from core to mod_filter.

Removed compiler switch -relax_pointers since no longer needed.

Removed compiler switch -relax_pointers since no longer needed.

fix revision in proposal

Roll on to 2.2.17-dev

Tag 2.2.16

Prepare for 2.2.16 release

CVE-2010-1452: Fix handling of missing path segments in the parsed URI structure.

If a specially crafted request was sent, it is possible to crash mod_dav or

mod_cache, as they accessed a field that is set to NULL by the URI parser,

assuming that it always put in a valid string.

PR: 49246

Submitted by: Mark Drayton

Patch by: Jeff Trawick

CVE-2010-1452: Fix handling of missing path segments in the parsed URI structure.

If a specially crafted request was sent, it is possible to crash mod_dav,

mod_cache or mod_session, as they accessed a field that is set to NULL

by the URI parser, assuming that it always put in a valid string.

PR: 49246

Submitted by: Mark Drayton

Patch by: Jeff Trawick