1 APACHE 2.0 STATUS: -*-text-*-
2 Last modified at [$Date: 2001/04/27 21:10:39 $]
6 2.0.17 : rolled April 17, 2001
7 2.0.16 : rolled April 4, 2001
8 2.0.15 : rolled March 21, 2001
9 2.0.14 : rolled March 7, 2001
10 2.0a9 : released December 12, 2000
11 2.0a8 : released November 20, 2000
12 2.0a7 : released October 8, 2000
13 2.0a6 : released August 18, 2000
14 2.0a5 : released August 4, 2000
15 2.0a4 : released June 7, 2000
16 2.0a3 : released April 28, 2000
17 2.0a2 : released March 31, 2000
18 2.0a1 : released March 10, 2000
20 DAEDALUS 2.0 PROBLEMS:
22 * mod_cgid and suexec have a problem co-existing. suexec sees a null
23 command string sometimes.
25 * core dump from 20010422
27 /usr/local/apache2b/corefiles/httpd.core.3
28 #0 0x806724c in check_hostalias (r=0x81fd03c) at vhost.c:891
29 #1 0x8067489 in ap_update_vhost_from_headers (r=0x81fd03c) at vhost.c:978
30 #2 0x806fa92 in ap_read_request (conn=0x81450fc) at protocol.c:946
31 #3 0x805a168 in ap_process_http_connection (c=0x81450fc) at http_core.c:274
32 #4 0x806bc60 in ap_run_process_connection (c=0x81450fc) at connection.c:82
33 #5 0x806be84 in ap_process_connection (c=0x81450fc) at connection.c:216
34 #6 0x805fbba in child_main (child_num_arg=65) at prefork.c:807
35 #7 0x805fd20 in make_child (s=0x80c64fc, slot=65) at prefork.c:880
36 #8 0x805ffec in perform_idle_server_maintenance () at prefork.c:1021
37 #9 0x80603d1 in ap_mpm_run (_pconf=0x80c600c, plog=0x80f300c, s=0x80c64fc) at prefork.c:1191
38 #10 0x80660cd in main (argc=1, argv=0xbfbffdac) at main.c:425
39 #11 0x8059bf9 in _start ()
41 The input data (received in one read from TCP layer):
43 GET /images/apache_sub.gif HTTP/1.1
45 Referer: http://search.apache.org/index.cgi
46 Accept-Language: en-us
47 Accept-Encoding: gzip, deflate
48 If-Modified-Since: Sat, 02 Dec 1995 21:26:28 GMT
49 If-None-Match: "29e60e-17c3-66972900"
50 User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)
52 Connection: Keep-Alive
54 * core dump from 20010418
56 /usr/local/apache2b/corefiles/httpd.core.2
57 #0 0x2813a3c8 in kill () from /usr/lib/libc.so.4
58 #1 0x2817609e in abort () from /usr/lib/libc.so.4
59 #2 0x8065299 in ap_log_assert (szExp=0x80aaa60 "total_bytes_left > 0 && tmplen > 0", szFile=0x80aa2aa "core.c", nLine=2555)
61 #3 0x8075227 in sendfile_it_all (c=0x81470fc, fd=0x814759c, hdtr=0xbfbff670, file_offset=1929216, file_bytes_left=261949,
62 total_bytes_left=261949, flags=0) at core.c:2555
63 #4 0x80761e2 in core_output_filter (f=0x814737c, b=0x814764c) at core.c:3172
64 #5 0x806d227 in ap_pass_brigade (next=0x814737c, bb=0x81e80fc) at util_filter.c:240
65 #6 0x805e696 in check_pipeline_flush (r=0x820803c) at http_request.c:388
66 #7 0x805e707 in ap_process_request (r=0x820803c) at http_request.c:432
67 #8 0x805a1a9 in ap_process_http_connection (c=0x81470fc) at http_core.c:280
68 #9 0x806bc60 in ap_run_process_connection (c=0x81470fc) at connection.c:82
69 #10 0x806be84 in ap_process_connection (c=0x81470fc) at connection.c:216
70 #11 0x805fbba in child_main (child_num_arg=272) at prefork.c:807
71 #12 0x805fd20 in make_child (s=0x80c64fc, slot=272) at prefork.c:880
72 #13 0x805ffec in perform_idle_server_maintenance () at prefork.c:1021
73 #14 0x80603d1 in ap_mpm_run (_pconf=0x80c600c, plog=0x80f300c, s=0x80c64fc) at prefork.c:1191
74 #15 0x80660cd in main (argc=1, argv=0xbfbffadc) at main.c:425
75 #16 0x8059bf9 in _start ()
77 The input data (received in one read from TCP layer):
79 GET /log4j/jakarta-log4j-1.1b2.zip HTTP/1.0
80 Via: 1.0 MDRPRXY01, 1.0 NS2
81 Connection: Keep-Alive
82 User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0)
83 Host: jakarta.apache.org
84 Accept: application/vnd.ms-excel, application/msword, application/vnd.ms-powerpoint, image/gif, image/x-xbitmap, image/jpeg,
86 Accept-Language: en-us,tscii;q=0.5
87 Referer: http://jakarta.apache.org/log4j/docs/download.html
88 Accept-Encoding: gzip, deflate
92 WARNING: ALWAYS check srclib/apr/STATUS and srclib/apr-util/STATUS
94 * threaded + cgid: "apachectl graceful" followed by "apachectl
95 restart" results in all processes but cgid going away; parent
96 died referencing other-child registration structures
98 * There is a bug in how we sort some hooks, at least the pre-config
99 hook. The first time we call the hooks, they are in the correct
100 order, but the second time, we don't sort them correctly. Currently,
101 the modules/http/config.m4 file has been renamed to
102 modules/http/config2.m4 to work around this problem, it should moved
103 back when this is fixed. rbb
105 * Root all file systems with <Directory /> for WIN32/OS2/NW permissions
106 Status: patch brought forward from 1.3.14
107 WIN32 and OS2 need review [William Rowe, Brian Harvard]
109 * Win32: Get Apache working on Windows 95/98. The following work
110 (at least) needs to be done:
111 - winnt MPM: Fix 95/98 code paths in the winnt MPM. There is some NT
112 specific code that is still not in NT only code paths
113 - IOL binds to APR sendfile, implemented with TransmitFile, which
114 is not available on 95/98.
115 - Document warning that OSR2 is required (for Crypt functions, in
118 * Win32: Test access logging with multiple threads. Will the
119 native file I/O calls serialize automagically like the
120 CRT calls or do we need to add region locking each time
124 * Win32: Complete the revamp the service environment and relocation
125 into the WinNT MPM. Changes ServerRoot service registry
126 parameter into ConfigArgs for multiple service startup parameters.
127 Problems to fix in the revamp: -k shutdown/restart are broken,
128 signals are not being acknowledged. Close window and shutdown
129 also seem out of sorts.
130 OtherBill is working on this and will finish over the weekend.
132 * We need a thread-safe resolver, at least on Unix.
133 Status: The best known candidate would be something from
135 Status: Greg asks, "why? doesn't gethostbyname_r() handle this?"
137 * The AddInputFilter and AddOutputFilter directives do not allow the
138 administrator to remove or reorder filters. Once a filter is added
139 in a container, it is present in any subcontainers. It can only be
140 added to the filter chain after any filters specified in enclosing
143 * remove the --disable-shared from the subdir config of APR(UTIL)
144 before the final release. (in fact, it might even be nice to
145 allow for Apache config/build against an already-installed
147 Note: we need to do a "make install" for APR(UTIL) so the shared
148 libraries can be installed properly. We could also use that
149 point to install include files (rather than have Apache
150 know everything that needs to be installed from the
151 sub-packages). The original impetus for doing the
152 disable-shared was because the shared lib wasn't getting
153 installed and a "make clean" in aprutil would make Apache
156 * users who want to install third-party modules into the Apache
157 source tree (for static linking) need to have autoconf and
158 libtool installed. This is because the module needs to have its
159 config.m4 incorporated into ./configure, which means "buildconf"
161 Note: This is in part because we have removed the "extra" directory.
162 In the Apache-2.0 repository, this directory had a config.m4
163 file that allowed people to add external modules by
164 specifying --with-module on the configure line.
166 * ap_vrprintf() needs to handle more than 4K
167 Status: Greg volunteers
169 * mod_dir should normally redirect ALL directory requests which do
170 not include a trailing slash on the URI. However, if a "notes"
171 flag is set (say, via BrowserMatch), this behavior will be
172 disabled for non-GET requests.
173 Status: Greg volunteers
174 MsgId: <20010227104646.E2297@lyra.org>
175 MsgId: <3A9C0097.9C83F07C@Golux.Com>
177 * Usability: Sanitize the MPM config directives. MaxClients in
178 the threaded MPM is totally misleading now as it has little to
179 do with limiting the number of clients (it limits the number
180 of child processes). Bill proposed nomenclature change to
181 something like "StartWorkers, MaxWorkers, etc." that could
182 apply to most all the MPMs (with some notable exceptions).
183 Bill would be happy with changing MaxClients to MaxServers
184 to make it agree with the operation of the StartServers
187 * A design problem with the scoreboard can cause the threaded
188 MPM to get in a state where it will no longer serve requests.
189 When MaxRequestsPerChild is hit, a threaded process will begin
190 allowing it's idle worker threads to exit. The child process
191 may have one (or a few) threads serving really long responses
192 over slow client connections, which will prevent the child
193 process from exiting. The problem is that the
194 perform_idle_server_maintenance code will NOT start a new
195 process to replace the dying child process until the dying child
196 has exited because the new child needs to use the old childs
197 space in the scoreboard. The scoreboard and
198 perform_idle_server_maintenance need to be redesigned.
199 Status: Several proposals discussed on new-httpd (April 16, 2001)
202 RELEASE NON-SHOWSTOPPERS BUT WOULD BE REAL NICE TO WRAP THESE UP:
204 * Performance: Get SINGLE_LISTENER_UNSERIALIZED_ACCEPT
205 optimization working again. Bill would like to see this
206 working for the threaded MPM, then prefork.
208 * mod_tls is very specific to OpenSSL. Make the API calls
209 more generic to support other encryption libraries.
211 * Performance & Debug: Eliminate most (and perhaps all) of the
212 malloc/calloc/frees in the bucket brigade code. Need some
213 light weight memory management functions that allow freeing
214 memory (putting it back into a memory pool) when it is no
215 longer needed. Enabling simple debugging features like guard
216 bands, double free detection, etc. would be cool but certainly
217 not a hard requirement.
219 * Eliminate unnecessary creation of pipes in mod_cgid
221 * the autoconf setup should be fixed to default to using the
222 "Apache" layout from config.layout, and each variable settable
223 in a layout should be overridable on the command line. Plus,
224 what we do right now just doesn't seem to fully fit into how autoconf
225 works, eg. AC_PREFIX_DEFAULT issues.
226 Message-ID: <Pine.BSF.4.20.0104031557420.20876-100000@alive.znep.com>
228 * mod_status ExtendedStatus SS (seconds since last request) is
229 bogus because of an uninitialized field in the scoreboard.
230 Status: Cliff is working on this
232 * All of our MPMs should use APR for threads/processes. This
233 will allow us to error out if a threaded MPM is chosen on a
234 platform that doesn't support threads.
236 * Combine log_child and piped_log_spawn. Clean up http_log.c.
239 * Document mod_file_cache.
241 * OS/2: Make mod_status work for spmt_os2 MPM.
243 * Win32: Win9x console window still won't play nice with the
244 close window, logoff and shutdown scenarios.
245 Status: OtherBill will move the patch forward from 1.3.15, once we
246 get our other Win9x issues solved.
248 * Win32: Add a simple hold console open patch (wait for close or
249 the ESC key, with a nice message) if the server died a bad
250 death (non-zero exit code) in console mode.
251 Status: OtherBill is bringing forward same ugly hack from 1.3.13
253 * Platforms that do not support fork (primarily Win32 and AS/400)
254 Architect start-up code that avoids initializing all the modules
255 in the parent process on platforms that do not support fork.
257 * Win32: Migrate the MPM over to use APR thread/process calls. This
258 would eliminate some code in the Win32 branch that essentially
259 duplicates what is in APR.
261 * There are still a number of places in the code where we are
262 losing error status (i.e. throwing away the error returned by a
263 system call and replacing it with a generic error code)
265 * Win32: Implement reliable piped logs on Windows
267 * Mass vhosting version of suEXEC.
269 * All DBMs suffer from confusion in support/dbmmanage (perl script) since
270 the dbmmanage employs the first-matched dbm format. This is not
271 necessarily the library that Apache was built with. Aught to
272 rewrite dbmmanage upon installation to bin/ with the proper library
273 for predictable mod_auth_db/dbm administration.
275 * use apu_dbm in mod_auth_dbm
276 Status: Greg +1 (low-priority volunteer)
279 Some additional items remaining:
280 - case_preserved_filename stuff
281 (use the new canonical name stuff?)
282 - find a new home for ap_text(_header)
283 - is it possible to remove the DAV: namespace stuff from util_xml?
285 * ap_core_translate() and its use by mod_mmap_static and mod_file_cache
286 are a bit wonky. The function should probably be exposed as a utility
287 function (such as ap_translate_url2fs() or ap_validate_fs_url() or
288 something). Another approach would be a new hook phase after
289 "translate" which would allow the module to munge what the
290 translation has decided to do.
291 Status: Greg +1 (volunteers), Ryan +1
293 * Explore use of a post-config hook for the code in http_main.c which
294 calls ap_fixup_virutal_hosts(), ap_fini_vhost_config(), and
295 ap_sort_hooks() [to reduce the logic in main()]
297 * read the config tree just once, and process N times (as necessary)
299 * (possibly) use UUIDs in mod_unique_id and/or mod_usertrack
301 * (possibly) port the bug fix for PR 6942 (segv when LoadModule is put
302 into a VirtualHost container) to 2.0.
304 * the LTFLAGS = -export-dynamic in the config.m4 is wrong. it is getting
305 added multiple times during the config process. The -export-dynamic
306 should probably move into build/special.mk (the make file used for
307 building Apache modules).
309 * shift stuff to mod_core.h
311 * APR-ize resolver stuff in mod_unique_id (Jeff volunteers)
313 * callers of ap_run_create_request() should check the return value
314 for failure (Doug volunteers)
316 PRs that have been suspended forever waiting for someone to
317 put them into 'the next release':
320 missing call to "setlocale();"
324 Additional status for XBitHack directive
328 Questionable performace of mod_dir() with negotiation
332 Mod_proxy doesn't allow change of error pages
336 Modified PATH environemnt variable is not passed, instead
341 Proxy doesn't deliver documents if not connected
345 proxy converts ~name to %7Ename when name starts with a dot (.)
349 mod_access syntax allows hosts that should be restricted
352 * PR#557: mod_auth-any
353 ~UserHome directories are not honored in absolute pathname
357 * PR#573: mod_log-any
358 More LogFormat directives
362 Proxy FTP Authentication Fails
365 * PR#623: mod_include
366 A smarter "Last Modified" value for SSI documents (see PR number 600)
370 Request of "Options SymLinksIfGroupMatch"
373 * PR#697: mod_include
374 A security tweak I've been using for a few years for SSI
378 Proxy doesn't do links right for OpenVMS files through ftp:
382 imap should read <MAP><AREA>*</MAP> too!
386 RLimitCPU and RLimitMEM don't apply to all children like they should
390 Uses cwd before filling it in, doesn't use syslog
394 it is useful to allow specifiction that root-owned symlinks
395 should always be followed
399 Controlling Access to Remote Proxies would be nice...
403 Adding authentication "on the fly" through the proxy module
406 * PR#1004: apache-api
407 request_config field in request_rec is moderately bogus
411 DoS attacks involving memory consumption
414 * PR#1050: mod_log-any
415 Logging of virtual server to error_log as well
419 ProxyRemote make a dead cycle.
422 * PR#1117: mod_auth-any
423 Using NIS passwd.byname dbm files with AuthDBMUserFile
427 suexec does not parse arguments to #exec cmd
430 * PR#1145: mod_include
431 Allow for Last-Modified: without resorting to XBitHack
435 insufficent AllowOverrides granularity for autoindexing
438 * PR#1158: apache-api
439 improvements to child spawning API
443 ``nph-'' not honored (no buffering) for ProxyRemote mapping
447 Apache cannot handle continuation line in headers
451 setlogin() is not called, causing problems with e.g. identd
455 regerror() exists, use it
458 * PR#1233: apache-api
459 there is no way to keep per-connection per-module state
463 Add frame-safe anchor attribute to mod_autoindex links
467 CGI scripts running as Apache user: security (suexec etc.)
471 Error messages could be easier to spot in cgi.log file for suexec.c
474 * PR#1287: mod_access
475 add allow,deny/deny,allow warning to mod_access
479 Need to know "hit-rate" on proxy cache
482 * PR#1358: mod_log-any
483 Selective url-encode of log fields (or maybe a pseudo
487 * PR#1383: mod_headers
488 I make mod_headers to modify request headers as well as
493 Proxy transfer logging
497 No HTTP_X_FORWARDED_FOR set...
501 ProxyRemote proxy requests fail authentication by firewall
504 * PR#1574: mod_autoindex
505 ReadmeName and HeaderName don't allow for server-parsed html.
508 * PR#1582: mod_rewrite
509 mod_rewrite forms REQUEST_URI different than mod_cgi does
512 * PR#1677: mod_headers
513 mod_headers should allow mod_log_config-style formats in
518 mod_proxy to support persistent conns?
521 * PR#1803: mod_include
522 patches to mod_include to allow for file tests
525 * PR#1809: mod_auth-any
526 Suggestion for improving authentication modules and core source
527 code, problem with 401 and ErrorDocument
530 * PR#1855: mod_autoindex
531 More Control over autoindex layout
535 listing of proxy cache content
539 Allow modules to set user:group for execution.
542 * PR#2024: apache-api
543 adding auth_why to conn_rec
546 * PR#2073: mod_log-any
547 pipelined connections are not logged correctly
550 * PR#2074: mod_rewrite
551 mod_rewrite doesn't pass Proxy Throughput on internal subrequests
555 HTTP Server Rebuild Line Needs Changing for the better
558 * PR#2138: mod_status
559 mod_status always displays 256 possible connection slots
562 * PR#2221: documentation
563 Make online documentation search link back to my installation
567 Can not POST to ErrorDocument - Apache/1.3b6
571 patterns in ProxyRemote
574 * PR#2343: mod_status
575 Status module averages are for entire uptime
579 suexec for general access of user content?
583 Proposal for TimeZone directive
587 /server-info doesn't check for the virtual host to list the info
591 problem specifying ndbm library for build ?with autoconfigure
595 A small addition to rotatelogs.c to improve program functionality.
599 AllowOverride FileInfo is too coarse
603 TimeOut applies to output of CGI scripts
606 * PR#2512: mod_access
607 <IfDenied> directive wanted
611 CGI's for general use still have to be run as another user
616 Cache file names in Proxy module
620 [PATCH] User/Group for <Directory> and <Location> i.e. not only
621 in global and <Virtual>.
625 mailto tags and bundling bug report script
628 * PR#2772: mod_log-any
633 Support for System Resource Controller
637 When will Apache support P3P? Any Plans?
641 Feedback/Comment on APACI
645 Inclusion of RPM spec file in CVS/distributions
649 Propose that Apache recommend $UNIQUE_ID for all "session id"
654 suggestion: power up your Include directive :)
658 cannot limit some HTTP methods
661 * PR#3026: mod_autoindex
662 No way to change ReadmeName/HeaderName suffixes.
665 * PR#3143: apache-api
666 No module specific data hook for per-connection data
670 Configuration file in Japanese
673 * PR#3191: mod_negotiation
674 no way to set global quality-of-source (qs) coneg values
678 * PR#3430: mod_negotiation
679 Enhancement: MultiViews, Multi-Language Documents
683 Accessing URL through proxy server corrupts data.
686 * PR#3594: os-windows
687 Please add an Apache icon to the systray instead of a DOS window
691 Some anonymous FTP URLs ask for authentication
694 * PR#3654: mod_autoindex
695 BORDER=0 makes Icons look nicer (FancyIndexing)
699 New ErrorDocumentMatch directive
702 * PR#4180: os-windows
703 Alternative for win95 users
707 Need to be able to override shebang line to make CGI scripts
712 "Files" and "FilesMatch" regexp does not recognize bang as
716 * PR#4448: mod_log-any
717 Please allow CGI env variables (QUERY_STRING, ...) to be logged
721 * PR#4459: mod_include
722 Suggestion for better handling of Last-modified headers
726 mod_cgi prevents handling of OPTIONS requests
729 * PR#4520: mod_autoindex
730 mod_autoindex does not generate Last-Modified response headers
733 * PR#4658: os-windows
734 The output of CGI scripts appears in the window that apache
738 * PR#5713: os-windows
739 [PATCH] install as service with domain account
743 AllowOverride should have a 'CheckNone' and 'AllowNone' argument
744 instead of only 'None'
748 MIME types for MNG and JNG files need adding to mime.types and
749 the mime.types and magic files
750 Status: Waiting for IANA types to be defined
752 Other bugs that need fixing:
754 * MaxRequestsPerChild measures connections, not requests.
755 Until someone has a better way, we'll probably just rename it
756 "MaxConnectionsPerChild".
758 * Regex containers don't work in an intutive way
759 Status: No one has come up with an efficient way to fix this
760 behavior. Dean has suggested getting rid of regex containers
763 * SIGSEGV on Linux (glibc 2.1.2) isn't caught properly by a
764 sigwaiting thread. We need to work around this, perhaps unless
765 there is hope soon for a fixed glibc.
767 * orig_ct in the byterange/multipart handling may not be
768 needed. Apache 1.3 just never stashed "multipart" into
769 r->content_type. We should probably follow suit since the
770 byterange stuff doesn't want the rest of the code to see the
771 multipart content-type; the other code should still think it is
772 dealing with the <orig_ct> stuff.
773 Status: Greg volunteers to investigate (esp. since he was most
774 likely the one to break it :-)
776 Other features that need writing:
778 * Finish infrastructure in core for async MPMs
781 * TODO in source -- just do an egrep on "TODO" and see what's there
783 Documentation that needs writing:
784 * Mod_status docs are needed.
786 * The concept of MPMs, especially if we ship more than one MPM for a
789 * New directives in the various MPMs and appropriate links from
790 obsolete directives in core.html to the MPM documentation.
792 * Revise manual/stopping.html and the last part of
793 manual/misc/perf-tuning.html to take account of the MPMs.
796 Status: Ben Laurie has written some hooks documentation
797 (apache-2.0/htdocs/hooks.html)
799 * Changes since 1.3.9 can be more easily seen in the commitlog file
800 dev.apache.org:/home/cvs/CVSROOT/commitlogs/apache-2.0
801 which includes some of Roy's comments when the changes were
802 committed in rough change-sets by purpose. Note that the commitlog
803 does not show the contents of new files until later.
807 * Jon Travis's <jtravis@covalent.net> patch to deal with thread-safe
808 issues with inet_ntoa. See message <20001201163220.A12827@covalent.net>
809 Status: This is being set aside until the IPv6 work is finished
810 so that we know exactly what is required.
812 * Martin Sojka <msojka@gmx.de>'s patch to add error reporting for failed
813 htpasswd actions due to a full /tmp volume (other programs may have
818 * Mike Abbott's <mja@trudge.engr.sgi.com> patches to improve
820 Status: These were written for 1.3, and are awaiting a port to
823 * Jim Winstead's <jimw@trainedmonkey.com> patch to add CookieDomain and
824 other small mod_usertrack features
826 * Dan Rench's <drench@xnet.com> patch to add allow the errmsg and timefmt
827 of SSI's to be modified in the config file. Patch is available in
832 * What do we do about mod_proxy?
834 * Which MPMs will be included with Apache 2.0?