-*- coding: utf-8 -*-
Changes with Apache 2.5.0
- *) mod_proxy: Fix memory leak or possible corruption in ProxyBlock
- implementation. [Ruediger Pluem, Joe Orton]
+ *) htpasswd, htdbm: Add support for bcrypt algorithm (requires
+ apr-util 1.5 or higher). PR 49288. [Stefan Fritsch]
- *) mod_proxy: Check hostname from request URI against ProxyBlock list,
- not forward proxy, if ProxyRemote* is configured. [Joe Orton]
+ *) htpasswd, htdbm: Put full 48bit of entropy into salt, improve
+ error handling. Add some of htpasswd's improvements to htdbm,
+ e.g. warn if password is truncated by crypt(). [Stefan Fritsch]
- *) mod_proxy_connect: Avoid DNS lookup on hostname from request URI
- if ProxyRemote* is configured. PR 43697. [Joe Orton]
+ *) ab: add TLS1.1/TLS1.2 options to -f switch, and adapt output
+ to more accurately report the negotiated protocol. PR 53916.
+ [Nicolás Pernas Maradei <nico emutex com>, Kaspar Brand]
- *) mod_lbmethod_heartbeat, mod_heartmonitor: Respect DefaultRuntimeDir/
- DEFAULT_REL_RUNTIMEDIR for the heartbeat storage file. [Jeff Trawick]
+ *) mod_systemd: New module, for integration with systemd on Linux.
+ [Jan Kaluza <jkaluza redhat.com>]
- *) mpm_event: Don't count connections in lingering close state when
- calculating how many additional connections may be accepted.
- [Stefan Fritsch]
+ *) core: ErrorDocument now works for requests without a Host header.
+ PR 48357. [Jeff Trawick]
- *) mod_ssl: Add RFC 5878 support. [Ben Laurie]
+ *) --with-module: Fix failure to integrate them into some existing
+ module directories. PR 40097. [Jeff Trawick]
+
+ *) mod_headers: New params: %l for load averages, %i for an
+ idle percentage rating of httpd, and %b for a busy percentage
+ rating. [Jim Jagielski]
+
+ *) core: New functions to obtain load parameters: ap_get_sload()
+ and ap_get_loadavg(). [Jim Jagielski]
+
+ *) mod_cache_socache: New cache implementation backed by mod_socache
+ that replaces mod_mem_cache removed from httpd v2.2. [Graham
+ Leggett]
+
+ *) mod_auth_form: Support the expr parser in the
+ AuthFormLoginRequiredLocation, AuthFormLoginSuccessLocation and
+ AuthFormLogoutLocation directives. [Graham Leggett]
+
+ *) core: Add dirwalk_stat and pre_htaccess hooks, allowing mpm-itk
+ to be used without patches to httpd core. [Jeff Trawick]
+
+ *) mod_proxy: Allow for persistence of local changes (via the
+ balancer-manager) between graceful and normal restarts.
+ [Jim Jagielski]
+
+ *) mod_slotmem: New provider function, fgrab(), which forces an
+ allocation of a slot. [Jim Jagielski]
+
+ *) mod_proxy_balancer: The nonce is only derived from the UUID iff
+ not set via the 'nonce' balancer param. [Jim Jagielski]
+
+ *) mod_lua: Add LuaInputFilter/LuaOutputFilter for creating content
+ filters in Lua [Daniel Gruno]
+
+ *) core: Apply length limit when logging Status header values.
+ [Jeff Trawick, Chris Darroch]
+
+ *) mod_ssl: Match wildcard SSL certificate names in proxy mode.
+ PR 53006. [Joe Orton]
+
+ *) WinNT MPM: Store pid and generation for each thread in scoreboard
+ to allow tracking of threads from exiting children via mod_status
+ or other such mechanisms. [Jeff Trawick]
- *) mod_lua: Add new directive LuaAuthzProvider to allow implementing an
- authorization provider in lua. [Stefan Fritsch]
+ *) mod_ssl: Catch missing or mismatched client cert/key pairs with
+ SSLProxyMachineCertificateFile/Path directives. PR 52212.
+ [Keith Burdis <keith burdis.org>, Joe Orton]
- *) mod_lua: Add a few missing request_rec fields. Rename remote_ip to
- client_ip to match conn_rec. [Stefan Fritsch]
+ *) mod_lua: Allow scripts handled by the lua-script handler to return
+ a status code to the client (such as a 302 or a 500) [Daniel Gruno]
- *) mod_lua: Change prototype of vm_construct, to work around gcc bug which
- causes a segfault. PR 52779. [Dick Snippe <Dick Snippe tech omroep nl>]
+ *) mod_proxy_ajp: Fix crash in packet dump code when logging
+ with LogLevel trace7 or trace8. PR 53730. [Rainer Jung]
- *) mod_lua: Add the parsebody function for parsing POST data. PR 53064.
+ *) mod_cache: Wrong content type and character set when
+ mod_cache serves stale content because of a proxy error.
+ PR 53539. [Rainer Jung, Ruediger Pluem]
+
+ *) mod_lua: Decline handling 'lua-script' if the file doesn't exist,
+ rather than throwing an internal server error. [Daniel Gruno]
+
+ *) mod_lua: Add functions r:flush and r:sendfile as well as additional
+ request information to the request_rec structure. [Daniel Gruno]
+
+ *) mod_lua: Add a server scope for Lua states, which creates a pool of
+ states with managable minimum and maximum size. [Daniel Gruno]
+
+ *) core: Add post_perdir_config hook.
+ [Steinar Gunderson <sgunderson bigfoot.com>]
+
+ *) mod_lua: Add new directive, LuaMapHandler, for dynamically mapping
+ URIs to Lua scripts and functions using regular expressions.
[Daniel Gruno]
- *) mod_ssl: If exiting during initialization because of a fatal error,
- log a message to the main error log pointing to the appropriate
- virtual host error log. [Stefan Fritsch]
+ *) mod_lua: Add new directive LuaCodeCache for controlling in-memory
+ caching of lua scripts. [Daniel Gruno]
+
+ *) The following now respect DefaultRuntimeDir/DEFAULT_REL_RUNTIMEDIR:
+ - APIs: ap_log_pid(), ap_remove_pid, ap_read_pid()
+ - core: the scoreboard (ScoreBoardFile), pid file (PidFile), and
+ mutexes (Mutex)
+ - mod_lbmethod_heartbeat, mod_heartmonitor: heartbeat storage file
+ - mod_ldap: shared memory cache
+ - mod_socache_shmcb, mod_socache_dbm: shared memory or dbm for cache
+ [Jeff Trawick]
+
+ *) mod_ssl: Add RFC 5878 support. [Ben Laurie]
*) mod_ssl: Add support for TLS-SRP (Secure Remote Password key exchange
for TLS, RFC 5054). PR 51075. [Quinn Slack <sqs cs stanford edu>,
Christophe Renou, Peter Sylvester]
- *) mod_ssl: Add new directive SSLCompression to disable TLS-level
- compression. PR 53219. [Björn Jacke <bjoern j3e de>, Stefan Fritsch]
-
*) core: Make ap_regcomp() return AP_REG_ESPACE if out of memory. Make
ap_pregcomp() abort if out of memory. This raises the minimum PCRE
requirement to version 6.0. PR 53284. [Stefan Fritsch]
- *) apxs: Use LDFLAGS from config_vars.mk in addition to CFLAGS and CPPFLAGS.
- [Stefan Fritsch]
-
*) suexec: Add --enable-suexec-capabilites support on Linux, to use
setuid/setgid capability bits rather than a setuid root binary.
[Joe Orton]
to a file; configure --without-suexec-logfile --with-suexec-syslog.
[Joe Orton]
- *) mod_proxy_ajp: Reduce memory usage in case of many keep-alive requests on
- one connection. PR 52275. [Naohiro Ooiwa <naohiro ooiwa miraclelinux com>]
-
*) mod_ssl: Add support for TLS Next Protocol Negotiation. PR 52210.
[Matthew Steele <mdsteele google.com>]
Also set CC_FOR_BUILD to 'cc' when cross-compilation is detected.
PR 51257. [Guenter Knauf]
- *) core: Add the port number to the vhost's name in the scoreboard.
- [Stefan Fritsch]
-
*) core: In maintainer mode, replace apr_palloc with a version that
initializes the allocated memory with non-zero values, except if
AP_DEBUG_NO_ALLOC_POISON is defined. [Stefan Fritsch]
- *) mod_authnz_ldap: Don't try a potentially expensive nested groups
- search before exhausting all AuthLDAPGroupAttribute checks on the
- current group. PR52464 [Eric Covener]
-
*) mod_policy: Add a new testing module to help server administrators
enforce a configurable level of protocol compliance on their
servers and application servers behind theirs. [Graham Leggett]