[NOTE that x.{odd}.z versions are strictly Alpha/Beta releases,
while x.{even}.z versions are Stable/GA releases.]
- 2.4.19 : In development.
+ 2.4.19 : In development. Jim to T&R March 21, 2015.
2.4.18 : Tagged on December 8, 2015. Released on December 14, 2015.
2.4.17 : Tagged on October 9, 2015. Released October 13, 2015.
2.4.16 : Tagged on July 9, 2015. Released July 15, 2015
PATCHES PROPOSED TO BACKPORT FROM TRUNK:
[ New proposals should be added at the end of the list ]
- *) mod_ssl: Free dhparams when getting DH params. This fixes issue when
- SSLCryptoDevice does not get unregistered because of non-zero refcount
- during the mod_ssl unload happening on httpd startup.
- trunk patch: http://svn.apache.org/r1720129
- http://svn.apache.org/r1723295
- http://svn.apache.org/r1733088
- http://svn.apache.org/r1733089
- 2.4.x patch: http://home.apache.org/~ylavic/patches/httpd-2.4.x-dh_leaks.patch
- +1: ylavic
- rpluem says: Can we get an updated 2.4.x proposal that includes r1723295?
- ylavic: done + CHANGES (votes reset)
-
*) mod_proxy_hcheck: Dynamic reverse proxy backend health check module
Trunk version of patch: <various>
Backport version for 2.4.x of patch:
the sizes of existing slotmems (slotmem_create/attach)?
jim: Yes, that is right (re: breakage)... this would be noted at
release.
-
- *) Use pre_connection hook in event.c to properly setup connection state
- of slave connections (eliminates hacks in mod_http2).
- Trunk patch:
- http://svn.apache.org/r1727603
- 2.4.x patch:
- Trunk version of patch works modulo CHANGES
- +1: icing, ylavic
-
- *) mod_proxy: Play/restore the TLS-SNI on new backend connections which
- had to be issued because the remote closed the previous/reusable one
- during idle (keep-alive) time.
- trunk patch: http://svn.apache.org/r1729826
- http://svn.apache.org/r1729847
- http://svn.apache.org/r1732986
- http://svn.apache.org/r1733056
- 2.4.x patch: http://home.apache.org/~ylavic/patches/httpd-2.4.x-mod_proxy-SNI_reuse-v2.patch
- +1: ylavic, icing
-
- * prefork: Fix crash in ap_mpm_pod_check call caused by NULL dereference of
- its parameter when starting httpd as single process (httpd -X).
- trunk patch: http://svn.apache.org/r1711479
- http://svn.apache.org/r1733064
- http://svn.apache.org/r1733068
- 2.4.x patch: http://home.apache.org/~ylavic/patches/httpd-2.4.x-prefork-ONE_PROCESS_POD.patch
- +1: ylavic, icing
-
- *) mod_ssl: When SSLVerify is disabled (NONE), don't force a renegotiation if
- the SSLVerifyDepth applied with the default/handshaken vhost differs from
- the one applicable with the finally selected vhost.
- trunk patch: http://svn.apache.org/r1684171
- 2.4.x patch: http://home.apache.org/~ylavic/patches/httpd-2.4.x-SSLVerify_NONE_no_reneg_Depth.patch
- +1: ylavic, icing
-
- *) core: Ensure that httpd exits with an error status when the MPM fails
- to run.
- trunk patch: http://svn.apache.org/r1629925
- http://svn.apache.org/r1629927
- http://svn.apache.org/r1629928
- http://svn.apache.org/r1733162
- http://svn.apache.org/r1733173
- 2.4.x patch: http://home.apache.org/~ylavic/patches/httpd-2.4.x-exit_with_error_on_mpm_failure.patch
+ ylavic: OK, this is just that persisted slotmems won't be reused on first
+ startup, not that the startup will fail (as I first thought).
+
+ *) core/util_script: relax alphanumeric filter of enviroment variable names
+ on Windows to allow '(' and ')' for passing PROGRAMFILES(X86) et.al.
+ unadulterated in 64 bit versions of Windows. PR 46751.
+ trunk patch: http://svn.apache.org/r1705217
+ 2.4.x patch: trunk patch works
+ +1: jailletc36
+ ylavic: As asked on dev@ (in reply to r1705217), what about CVE-2014-6271
+ (shellshock) with unix-like shells (or even maybe native windows
+ ones too)?
+
+ *) mod_ssl: Add "no_crl_for_cert_ok" flag to SSLCARevocationCheck directive
+ to opt-in previous behaviour (2.2) with CRLs verification when checking
+ certificate(s) with no corresponding CRL.
+ trunk patch: http://svn.apache.org/r1734561
+ http://svn.apache.org/r1734807
+ http://svn.apache.org/r1735159
+ http://svn.apache.org/r1735337
+ 2.4.x patch: trunk works (modulo CHANGES) or
+ http://home.apache.org/~ylavic/patches/httpd-2.4.x-no_crl_for_cert_ok.patch
+1: ylavic
-
+ *) mod_proxy_http2: add http2 proxy support in new, experimental module.
+ Includes backport of r1729208 to set ALPN protocols for ssl backend
+ connections.
+ Trunk version of patch: <various>
+ Backport version for 2.4.x of patch: https://www.eissing.org/proxy_http2_2.4v4.patch
+ +1: icing, ylavic
+ updated patch after review by cjaillet, merged 1735668,1735748 from trunk
+ updated patch with APLOGNOs by merging 1735931,1735935 from trunk
+ updated patch with APLOGNOs by merging 1735942 from trunk
+
+ *) CGIVar for controlling building of REQUEST_URI (and future uses)
+ As mentioned on dev@:
+ * This is intended to replace existing methods of configuring how various
+ CGI vars should be built over the long term, though only REQUEST_URI is
+ handled for now.
+ * If the mechanism should be usable by third-party modules for its own
+ concerns, a check for recognized-envvar can be removed from the command
+ processor and the rest of the code will let the third-party module do
+ the right thing since the rule for a var is a character string in a table,
+ not a separate core_dir_config flag with enumerated values.
+ Trunk patch: r1734947, 1735952
+ 2.4.x patch: https://emptyhammock.com/media/downloads/CGIVar-to-2.4.x.txt
+ +1: trawick, ylavic
+
+
PATCHES/ISSUES THAT ARE BEING WORKED
*) http: Don't remove the Content-Length of zero from a HEAD response if
make it nonblocking (by default)?
jim: Non-blocking seems the best way to handle...
- * mod_rewrite: PR58854: Revert r1726016 (rewrite looping issue) which was
- reverted in trunk in r1732896. The fix is bad and breaks old loop
- avoidance.
-
- +1 covener
PATCHES/ISSUES THAT ARE STALLED