Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
2.2.34_4 16 Apr 2018 10:44:31 |
brnrd |
www/mod_antiloris
www/mod_auth_imap2
www/mod_authn_sasl
www/mod_bw
www/mod_cband
www/mod_clamav
www/mod_extract_forwarded
www/mod_hosts_access
www/mod_log_config-st
www/mod_log_mysql
www/mod_log_sql2-dtc
www/mod_macro22
www/mod_musicindex
www/mod_ntlm2
www/mod_proxy_html
www/mod_remoteip
www/mod_spdy
www/mod_uid
www/mod_vhost_ldap
www/mod_whatkilledus
www/mod_xml2enc
2017-07-01 www/apache22: Upstream propose EoL of apache 2.2.x during the next 12
months |
2.2.34_4 21 Mar 2018 21:24:44 |
brnrd |
devel/apr1: Bump portrevision
- Repair my rookie mistake of earlier today
- Bump revision of dependent ports (again)
Reported by: antoine |
2.2.34_3 21 Mar 2018 19:50:35 |
brnrd |
devel/apr1: Fix runtime issues of dependent port
- iconv is in base in all supported FreeBSD versions
- Fix build with MariaDB 10.2 [2]
- Bump portrevision in dependencies
PR: 226705 [1], 226026 [2]
With hat: apache
Approved by: joneum (apache) |
2.2.34_2 11 Mar 2018 14:23:28 |
brnrd |
Mk/Uses/apache.mk: Migrate Mk/bsd.apache.mk to Uses
- Chase required changes in framework (bsd.sanity.mk, bsd.port.mk)
- Chase required changes in ports (version checks)
- Chase required changes in PHP ports (include bsd.apache.mk)
- exp-run by antoine, brnrd, joneum
PR: 223691 (exp-run)
Reviewed by: joneum (hat apache), mat (portmgr), antoine (portmgr)
Approved by: joneum (hat apache)
Approved by: portmgr
With hat: apache |
2.2.34_2 24 Feb 2018 10:33:54 |
brnrd |
www/apache22: Add upstream fix
- Upstream fixes no longer released as point versions
- Register BROKEN with various libssl providers |
2.2.34_1 19 Sep 2017 12:29:33 |
zi |
- Add backport of patch for CVE-2017-9798
- Bump PORTREVISION
Approved by: ports-secteam (with hat)
Security: 76b085e2-9d33-11e7-9260-000c292ee6b8 |
2.2.34 12 Jul 2017 19:26:14 |
brnrd |
www/apache22: Update to 2.2.34
- Security update to 2.2.34
MFH: 2017Q3
Security: 0c2db2aa-5584-11e7-9a7d-b499baebfeaf
Differential Revision: https://reviews.freebsd.org/D11285 |
2.2.32 09 Jun 2017 19:39:30 |
feld |
www/apache22: Update to 2.2.32
Does not build with OpenSSL 1.1.x or LibreSSL 2.5.x which is a known issue.
Changelog: http://www.apache.org/dist/httpd/CHANGES_2.2.32
PR: 219720
MFH: 2017Q2
Security: CVE-2016-8743 |
2.2.31_1 05 Nov 2016 18:01:37 |
sunpoet |
- Add LICENSE
Approved by: portmgr (blanket) |
2.2.31_1 28 Oct 2016 16:00:45 |
danfe |
- Remove trailing dot in COMMENT and/or reword it accordingly
- Prefer standard option descriptions, and trim one long line |
2.2.31_1 18 Jul 2016 20:42:41 |
ohauer |
- add lost condition to apply the extra patch
for reproducible build
MFH: 2016Q3 |
2.2.31_1 18 Jul 2016 20:26:26 |
ohauer |
- allow reproducible build
- set EXPIRATION_DATE to 2017-07-01 [1]
[1] Upstream propose EoL of apache 2.2.x during the next 12 months
See discussion on dev@apache list. |
2.2.31_1 18 Jul 2016 20:14:19 |
brnrd |
www/apache24: Fix httpoxy vulnerability (+2.2)
- Add upstream patch to www/apache24
- Add upstream patch to www/apache22
- Bump PORTREVISION
Approved by: feld (ports-secteam)
MFH: 2016Q3
Security: cf0b5668-4d1b-11e6-b2ec-b499baebfeaf
Security: CVE-2016-5387 |
2.2.31 05 Jul 2016 16:01:46 |
ohauer |
- s/USE_OPENSSL=yes/USES=ssl/ |
2.2.31 01 Apr 2016 14:33:58 |
mat |
Remove ${PORTSDIR}/ from dependencies, categories v, w, x, y, and z.
With hat: portmgr
Sponsored by: Absolight |
2.2.31 18 Jan 2016 19:36:58 |
ohauer |
- fix ab buid with OpenSSL from ports and SSL3 disabled [1]
(backport ab.c r1706008 from apache24)
- use new $opt-target
- improve kldstat check
- use new defined postexec, preunexec in pkg-plist
with hat apache@
PR: 206369
Submitted by: matthew@ [1] |
2.2.31 27 Sep 2015 10:44:39 |
ohauer |
- fix poudriere build on FreeBSD >= 10.x with OpenSSL from ports
I haven't found the exact culprit but it seems build in poudriere behaves
different.
Fix build in poudriere by inspecting MAKE_ENV, else WITH_OPENSSL_PORT is not
honored.
Noted by: Philip Jocks <pj @ netzkommune.de> |
2.2.31 17 Aug 2015 14:20:41 |
mat |
Remove UNIQUENAME and LATEST_LINK.
UNIQUENAME was never unique, it was only used by USE_LDCONFIG and now,
we won't have conflicts there.
Use PKGBASE instead of LATEST_LINK in PKGLATESTFILE, the *only* consumer
is pkg-devel, and it works just fine without LATEST_LINK as pkg-devel
has the correct PKGNAME anyway.
Now that UNIQUENAME is gone, OPTIONSFILE is too. (it's been called
OPTIONS_FILE now.)
Reviewed by: antoine, bapt
Exp-run by: antoine
Sponsored by: Absolight
Differential Revision: https://reviews.freebsd.org/D3336 |
2.2.31 03 Aug 2015 21:10:30 |
ohauer |
- re add libressl patches (lost by last cleanup commit)
- no version bump, libressl is not the default ssl
with hat: apache
PR: 202047
Submitted by: mcdouga9 _at_ egr.msu.edu
Patch Provided by: phil.stone _at_ gmx.com |
2.2.31 02 Aug 2015 19:39:10 |
ohauer |
- update to 2.2.31
- remove backports
- minor cleanups
- always rebuild configure script
- add patch for acinclude.m4 [1]
Changes with Apache 2.2.31 [2]
*) Correct win32 build issues for mod_proxy exports, OpenSSL 1.0.x headers.
[Yann Ylavic, Gregg Smith]
Changes with Apache 2.2.30 (not released)
*) SECURITY: CVE-2015-3183 (cve.mitre.org)
core: Fix chunk header parsing defect. (Only the first 15 lines of the commit message are shown above ) |
2.2.29_7 02 Aug 2015 15:03:20 |
tijl |
By default libtool replaces -export-symbols <file> with -retain-symbols-file
<file> on ELF systems, but this doesn't really do what -export-symbols is
meant to do. On GNU ELF systems it converts <file> to a simple version
script first and then uses -version-script instead of -retain-symbols-file.
Let USES=libtool patch libtool scripts to do this on all systems with GNU
ld(1).
Bump PORTREVISION on all ports where the build log contains -export-symbols.
audio/calf: This port builds a module that now exports only one function,
but it also builds a number of executables that link to this module and
expect to see other functions. Because it's already a bit dodgy to link to
a module (libtool warns about this) let the module continue to export only
one function and instead build an ordinary library from the same source that
the executables can link to. Fix a number of other issues in the same (Only the first 15 lines of the commit message are shown above ) |
2.2.29_6 20 Jul 2015 16:37:51 |
feld |
Backport patch for CVE and bump PORTREVISION
Approved by: pgollucci
MFH: 2015Q3
Security: CVE-2015-3183
Security: 29083f8e-2ca8-11e5-86ff-14dae9d210b8 |
2.2.29_5 02 Jun 2015 19:55:04 |
zi |
- Cleanup logjam patch (remove -rand call to openssl to fix build for libressl
users)
- Cleanup logjam patch (ensure perl can find/replace the correct bits when
re-rengerating)
- Bump PORTREVISION
With hat: ports-secteam |
2.2.29_4 31 May 2015 12:52:01 |
ohauer |
- use @sample for conf files
- backport ab from 2.4.x
- fix mode for suexec, cgi test files
- adopt http-ssl.conf.in from upstream trunk
- rebuild some patches |
2.2.29_3 21 May 2015 02:13:08 |
zi |
- Generate new DH params during build to mitigate Logjam attack
- Fix deprecated USE_AUTOTOOLS
- Bump PORTREVISION
With hat: ports-secteam
Obtained from: Winni Neessen |
2.2.29_2 14 May 2015 10:15:09 |
mat |
MASTER_SITES cleanup.
- Replace ${MASTER_SITE_FOO} with FOO.
- Merge MASTER_SITE_SUBDIR into MASTER_SITES when possible. (This means 99.9%
of the time.)
- Remove occurrences of MASTER_SITE_LOCAL when no subdirectory was present and
no hint of what it should be was present.
- Fix some logic.
- And generally, make things more simple and easy to understand.
While there, add magic values to the FESTIVAL, GENTOO, GIMP, GNUPG, QT and
SAMBA macros.
Also, replace some EXTRACT_SUFX occurences with USES=tar:*.
Checked by: make fetch-urlall-list
With hat: portmgr
Sponsored by: Absolight |
2.2.29_2 18 Apr 2015 09:47:30 |
tijl |
- Remove libtool hacks and patches that are now handled by USES=libtool
- Remove CONFIG_SHELL from CONFIGURE_ENV because bsd.port.mk handles that |
2.2.29_2 01 Mar 2015 17:41:43 |
feld |
Unbreak build with LibreSSL
PR: 196256 |
2.2.29_2 01 Dec 2014 22:50:42 |
ohauer |
- make QA script happy and RMDIR empty folder below $PORTDOCS
the script complans on them even PORTDOCS=* is set
- do not slence INSTALL commands |
2.2.29_2 14 Oct 2014 13:23:51 |
mat |
Remove a #define strtoul that is messing up with c++.
Differential Revision: https://reviews.freebsd.org/D945
Approved by: ohauer
Sponsored by: Absolight |
2.2.29_1 22 Sep 2014 18:50:19 |
ohauer |
apache24
- remove check if apr is build with threads
- bump PORTREVISION
- adopt new pkg-plist @dir
@with hat apache@ |
2.2.29 13 Sep 2014 19:24:23 |
tijl |
Remove unused LIBTOOLFILES |
2.2.29 03 Sep 2014 20:20:49 |
ohauer |
- update to 2.2.29
- use PTHREAD_LIBS/CFLAGS instead -pthread
Changes with Apache 2.2.29
http://www.apache.org/dist/httpd/CHANGES_2.2.29
*) Corrected docs/manual pages for new MergeTrailers directive and other
out of date documentation. [William Rowe]
Changes with Apache 2.2.28
*) SECURITY: CVE-2014-0118 (cve.mitre.org) [1]
mod_deflate: The DEFLATE input filter (inflates request bodies) now
limits the length and compression ratio of inflated request bodies to avoid
denial of service via highly compressed bodies. See directives (Only the first 15 lines of the commit message are shown above ) |
2.2.27_6 24 Jul 2014 20:22:09 |
ohauer |
- backport upstream security fixes
- fix build with SSL from ports [1]
SECURITY: CVE-2014-0118 (cve.mitre.org)
mod_deflate: The DEFLATE input filter (inflates request bodies) now
limits the length and compression ratio of inflated request bodies to
avoid denial of sevice via highly compressed bodies. See directives
DeflateInflateLimitRequestBody, DeflateInflateRatioLimit, and
DeflateInflateRatioBurst.
http://svn.apache.org/viewvc?view=revision&revision=1611426
SECURITY: CVE-2014-0226 (cve.mitre.org)
(Only the first 15 lines of the commit message are shown above ) |
2.2.27_5 13 Jul 2014 15:58:45 |
ohauer |
- reflect new preferred apache version |
2.2.27_4 08 Jul 2014 22:46:03 |
ohauer |
- fix strip command (use ${PREFIX} instead real path) |
2.2.27_4 08 Jul 2014 21:31:49 |
ohauer |
- strip files
- sort pkg-plist
- always install DOCS (remove Makefile hack)
- reflect modules.d in EXAMPLESDIR, next target
will be a new keyword for pkg-plist to handle
module installation.
- bump PORTREVISION
- add warning about default version change (2014-07-11)
(pkg-message, files/HEADS_UP) |
2.2.27_3 12 Jun 2014 09:17:33 |
tijl |
Bump PORTREVISION on everything that depends on devel/apr1 due to the
library version change.
Approved by: portmgr (implicit) |
2.2.27_2 04 Jun 2014 16:54:02 |
des |
Add CPE information.
With hat: ports-secteam |
2.2.27_2 30 May 2014 21:55:22 |
ohauer |
- /USE_AUTOTOOLS=libtool/USES=libtool/
with hat apache@ |
2.2.27_2 10 Apr 2014 20:57:36 |
ohauer |
- fix build against security/openssl on FreeBSD-10
in case port is build with tinderbox or poudriere.
openssl is registered as BUILD/RUN dependency not
as LIB dependency, therefore the check for openssl
fails since it will be installed in a later stage
by tinderbox / poudriere.
Thanks to Katsuya Higuchi who noted this issue on
the apache@ mailing list.
http://lists.freebsd.org/pipermail/freebsd-apache/2014-April/003490.html
MFH: 2014Q2
Submitted by: Katsuya Higuchi <higuchi@jt-sys.co.jp> |
2.2.27_1 08 Apr 2014 23:33:58 |
ohauer |
- fix build on FreeBSD-10+ with OpenSSL from ports
- bump PORTVERSION because of CVE-2014-0076 / CVE-2014-0160
Special Thanks to Philip Jocks for reporting and testing!
http://lists.freebsd.org/pipermail/freebsd-apache/2014-April/003483.html
with hat apache@ |
2.2.27 05 Apr 2014 22:03:24 |
ohauer |
- revert r350271 |
2.2.27 05 Apr 2014 21:52:11 |
ohauer |
- remove comment from patch |
2.2.27 27 Mar 2014 05:28:11 |
ohauer |
- update to version 2.2.27
- fix apache-mpm-peruser graceful reload [1]
Changes with Apache 2.2.27
*) SECURITY: CVE-2014-0098 (cve.mitre.org)
Clean up cookie logging with fewer redundant string parsing passes.
Log only cookies with a value assignment. Prevents segfaults when
logging truncated cookies.
[William Rowe, Ruediger Pluem, Jim Jagielski]
*) SECURITY: CVE-2013-6438 (cve.mitre.org)
mod_dav: Keep track of length of cdata properly when removing
leading spaces. Eliminates a potential denial of service from
specifically crafted DAV WRITE requests (Only the first 15 lines of the commit message are shown above ) |
2.2.26 16 Mar 2014 16:07:59 |
ohauer |
ports in cat www where MAINTAINER=ports
- USE_BZIP2 -> USES= tar:bzip2
- LICENSE=BSD -> BSD[n]CLAUSE |
2.2.26 21 Jan 2014 23:40:23 |
bapt |
Fix properties on pkg-plist |
2.2.26 24 Nov 2013 19:56:27 |
ohauer |
- update to 2.2.26
- add new directory for modules (APACHEETCDIR/modules.d)
New modules can be registered here with a simple
file that contains the LoadModule directives.
Additonal Maintaines can write instructions to the
conf file and keep pkg-message short.
As bonus the config file can be installed like every
other config file with a .sample extention so modules
are not disabled during pkg upgrades.
Module config files should begin with three digits
followed by '_' e.g. 100_php5.conf.
The load order can be controlled via the three digits. (Only the first 15 lines of the commit message are shown above ) |
2.2.25_1 05 Nov 2013 22:18:46 |
ohauer |
- do not silence directory creation
Submitted by: mandree |
2.2.25_1 05 Nov 2013 22:00:08 |
ohauer |
- backport upstream commit r1528718 into mod_dav [1].
This is needed because of a bug [2] due to an incorrect
implementation of RFC 4918.
The symptoms are a failure to copy a svn tree via DAV:
- fix package installation with old pkg tools (create empty
folders in pkg-plist even staging is enabled)
[1] http://svn.apache.org/viewvc?view=revision&revision=1528718
[2] https://issues.apache.org/bugzilla/show_bug.cgi?id=55306
PR: ports/183685
Submitted by: Pietro Cerutti <gahr@FreeBSD.org> |
2.2.25 27 Oct 2013 17:40:21 |
ohauer |
- support staging
- partitial adopt new ${opt}_ notation |
2.2.25 20 Sep 2013 23:36:54 |
bapt |
Add NO_STAGE all over the place in preparation for the staging support (cat:
www) |
2.2.25 14 Sep 2013 13:38:21 |
az |
- convert to the new perl5 framework
- convert USE_GMAKE to Uses
Approved by: portmgr (bapt@, blanket) |
2.2.25 07 Sep 2013 19:49:42 |
bsam |
Introduce variable ICONV_PREFIX at Mk/Uses/iconv.mk. The default for
pre 100043 is ${LOCALBASE} and /usr otherwise. Convert all ports to
new variable usage.
Approved by: portmgr (bapt, implicit) |
2.2.25 14 Aug 2013 22:35:54 |
ak |
- Remove MAKE_JOBS_SAFE variable
Approved by: portmgr (bdrewery) |
2.2.25 10 Jul 2013 19:01:44 |
ohauer |
- update to apache-2.2.25
- update vuxml with additional CVE-2013-1896 entry
Changes with Apache 2.2.25
http://www.apache.org/dist/httpd/CHANGES_2.2.25
*) SECURITY: CVE-2013-1896 (cve.mitre.org)
mod_dav: Sending a MERGE request against a URI handled by mod_dav_svn with
the source href (sent as part of the request body as XML) pointing to a
URI that is not configured for DAV will trigger a segfault. [Ben Reser
<ben reser.org>]
*) SECURITY: CVE-2013-1862 (cve.mitre.org)
mod_rewrite: Ensure that client data written to the RewriteLog is
escaped to prevent terminal escape sequences from entering the (Only the first 15 lines of the commit message are shown above ) |
2.2.24_1 06 Jul 2013 08:46:40 |
ohauer |
- add fix for CVE-2013-1862
- adjust vuxml |
2.2.24 27 Apr 2013 18:25:25 |
mva |
- Convert USE_ICONV=yes to USES=iconv
- Change USE_GNOME=pkgconfig|gnomehack to USES=pathfix|pkgconfig and
USE_GETTEXT=yes to USES=gettext while here |
2.2.24 26 Mar 2013 21:31:27 |
ohauer |
- prepare for apache24 |
2.2.24 05 Mar 2013 22:00:14 |
ohauer |
- disable new ab SSL extensions until a better way is found.
only builds with OpenSSL from ports are affected which is
not default, so no version bump.
Noted on the apache@ list by Jukka A. Ukkonen <jau@iki.fi>
and per PR by Arnis Rozentals <admin@liepajaport.lv>
PR: 176659 |
2.2.24 02 Mar 2013 19:31:50 |
ohauer |
- update to version 2.2.24
- move mpm itk patches to itk-mpm/files dir
- add sshd to REQUIRE line in the rc script to prevent boot
issues in case a SSL cert is password protected [1]
Changes with Apache 2.2.24
SECURITY: CVE-2012-3499 (cve.mitre.org) Various XSS flaws due to
unescaped hostnames and URIs HTML output in mod_info, mod_status,
mod_imagemap, mod_ldap, and mod_proxy_ftp. [Jim Jagielski, Stefan
Fritsch, Niels Heinen <heinenn google com>]
SECURITY: CVE-2012-4558 (cve.mitre.org)
XSS in mod_proxy_balancer manager interface. [Jim Jagielski,
Niels Heinen <heinenn google com>]
(Only the first 15 lines of the commit message are shown above ) |
2.2.23_4 09 Feb 2013 12:00:53 |
crees |
Various spelling corrections
PR: ports/175331
Submitted by: Christoph Mallon
Approved by: No objections within three weeks from any maintainer
While here, style and duplicate phrase fixes in bsdcflow pkg-descr
Submitted by: mi |
2.2.23_4 07 Feb 2013 12:37:48 |
gahr |
- Get rid of PTHREAD_CFLAGS and PTHREAD_LIBS (category: www)
Approved by: portmgr |
2.2.23_4 02 Jan 2013 02:12:17 |
ache |
Use
LockFile "/var/run/accept.lock"
instead of previous
LockFile "/var/log/accept.lock"
If system is crashed and rebooted, Apache refuses to start in case
/var/log/accept.lock.<pid> is found. That <pid> is almost always the same
due to minimum pid variance right after boot.
So use /var/run instead, which is cleaned on each boot. |
2.2.23_3 10 Dec 2012 19:11:12 |
mm |
Update PCRE to 8.32
Introduces the UTF-32 library pcre32
Bump PORTREVISION in dependent ports |
2.2.23_2 18 Nov 2012 18:48:29 |
hrs |
Fix a typo.
Spotted by: ume
Pointy hat to: hrs
Feature safe: yes |
2.2.23_1 18 Nov 2012 16:33:31 |
hrs |
Fix rc.d script to support systems before and after ${name}_fib is introduced
into rc.subr. Bump PORTREVISION.
Feature safe: yes |
2.2.23 02 Nov 2012 18:45:32 |
ohauer |
- update apache22 to version 2.22.23
- trim vuxml/Makefile header
with hat apache@
Feature safe: yes
Security: CVE-2012-2687 |
2.2.22_8 09 Sep 2012 17:01:30 |
ohauer |
- notice the users that old WITH/WITHOUT parameters are obsolete.
Point them to the wiki
Thanks to crees@ for this suggestion to
implement this direct in the port
PR: 171509 |
2.2.22_8 08 Sep 2012 16:35:31 |
ohauer |
- add a note about devel/apr1 and apache22 updates
- adjust DBD IGNORE message |
2.2.22_8 05 Sep 2012 07:40:26 |
ohauer |
- fix build on IPv4 only systems
Thanks to John Marshall to identify the issue! |
2.2.22_8 04 Sep 2012 21:17:07 |
ohauer |
- Simplify options with the removal of the last APR only related parameter [1]
- disallow IPv6 sockets to handle IPv4 requests per default. [2]
- move extra-patch-server__config.c
-> patch-server__config.c
https://issues.apache.org/bugzilla/show_bug.cgi?id=53823
- bump PORTREVISION
[1] Credits to Hajimu UMEMOTO (ume@) for finding the last APR related parameter
[2] http://httpd.apache.org/docs/2.2/bind.html
with hat apache@ |
2.2.22_7 02 Sep 2012 14:31:59 |
ohauer |
devel/apr1 [1]
- update APR to 1.4.6
- update APR-util to 1.4.1
- remove PKGNAMESUFFIX'es
www/apache-(event|itk|peruser|worker)-mpm
- adopt new Makefile header, adjust
PKGNAMESUFFIX in apache22 masterport
PKGNAME match now LATEST_LINK
www/apache22 [2]-[6]
- rewrite for options NG
- PORTNAME s|apache|apache22|
- remove APR APR-util specific otions,
will be checked now with help of apr/u-1-config (Only the first 15 lines of the commit message are shown above ) |
2.2.22_6 23 Aug 2012 04:49:37 |
ohauer |
- rewite apache port
- remove all apr/apu related parts (leftovers from bundled apr)
- remove invalid parts from Makefile.doc
- move MODULES to Makefile.options
- remove apache20 parts
- remove category handling
with hat apache@ |
2.2.22_6 13 Aug 2012 19:51:11 |
ohauer |
- rewrite bsd.apache.mk (prepare for options NG support)
keep full backward support until apache20 is removed from the tree
comment code to remove with MFC TODO:
- adjust apache20 and apache22 ports
changes are transparent for users (no PORTREVISION bump)
Users who are using special build instructions in make.conf, such as
- WITH_STATIC_MODULES= alias dir log_config mime rewrite setenvif vhost_alias
should convert the values to UPPERCASE
- WITH_STATIC_MODULES= ALIAS DIR LOG_CONFIG MIME REWRITE SETENVIF VHOST_ALIAS
At the moment code to support old lowercase style is in place, but
target to remove in favor for options NG.
with hat apache@ |
2.2.22_6 02 Aug 2012 03:17:26 |
wxs |
Document Apache 2.2.x insecure handling of LD_LIBRARY_PATH.
Add patch[1] to address problem to apache port.
[1]:
http://svn.apache.org/viewvc/httpd/httpd/trunk/support/envvars-std.in?view=log&pathrev=1296428
Approved by: apache@ (pgollucci@)
Obtained from: Apache SVN |
2.2.22_5 22 Jul 2012 21:13:35 |
ohauer |
apache22
- centralise OPTIONS in Makefile.options
- s/Enable// in OPTIONS
- rewrite Makefile.modules (last defined SLAVE_PORT_MPM port use now WITH_MPM
var)
- no REVISION bump, nothing changed in the logic / functionality
apache22-peruser-mpm
- use WITH_MPM instead SLAVE_PORT_MPM |
2.2.22_5 08 Jul 2012 21:32:23 |
ohauer |
- cleanup conflicts (remove no longer existent ports)
- remove explicit ABI version number from LIB_DEPENDS |
2.2.22_5 14 Feb 2012 12:44:23 |
mm |
Bump pcre library dependency due to 8.30 update
Add (vendor) patch for deprecated pcre_info() |
2.2.22_4 09 Feb 2012 02:49:55 |
pgollucci |
- use $SYSCTL
- use full path setfib
PR: ports/153264
Submitted by: Jeremy Chadwick <freebsd@jdc.parodius.com>
With Hat: apache@
Sponsored by: Apache Software Foundation (ASF) |
2.2.22_3 08 Feb 2012 22:49:54 |
pgollucci |
- Remove 0 length file breaking pkg
Reported by: glarkin |
2.2.22_2 08 Feb 2012 04:35:31 |
pgollucci |
- Convert to USERS/GROUPS [1]
- Resync proxy connect patch [2]
- Bump PORTREVISION since the proxy patch is unconditionally applied
which means we can remove that OPTION too
PR: ports/164698 [1], ports/164711 [2]
Submitted by: jgh@ [1], freebsd@nagilum.org [2]
With Hat: apache@
Sponsored by: RideCharge Inc. / TaxiMagic |
2.2.22 01 Feb 2012 18:56:08 |
jgh |
- Update to 2.2.22
Addresses:
* SECURITY: CVE-2011-3607 (cve.mitre.org)
Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP
Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif
module is enabled, allows local users to gain privileges via a .htaccess file
with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request
header, leading to a heap-based buffer overflow.
* SECURITY: CVE-2012-0021 (cve.mitre.org)
The log_cookie function in mod_log_config.c in the mod_log_config module in the
Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not
properly handle a %{}C format string, which allows remote attackers to cause a
denial of service (daemon crash) via a cookie that lacks both a name and a (Only the first 15 lines of the commit message are shown above ) |
2.2.21 23 Jan 2012 23:24:38 |
pgollucci |
- Restore inadvertently removed log renames from previous commit
Noticed by: sunpoet@
Pointy Hat: pgollucci@ |
2.2.21 18 Jan 2012 03:44:39 |
pgollucci |
- Pull r1227293 from httpd svn
Note, you have to actually uncomment the include for this to take affect
- No PORTREVISION bump since nothing changes by default
PR: ports/156987
Reported by: Adrian Dimcev <adimcev@carbonwind.net>
With Hat: apache@ |
2.2.21 14 Jan 2012 08:57:23 |
dougb |
In the rc.d scripts, change assignments to rcvar to use the
literal name_enable wherever possible, and ${name}_enable
when it's not, to prepare for the demise of set_rcvar().
In cases where I had to hand-edit unusual instances also
modify formatting slightly to be more uniform (and in
some cases, correct). This includes adding some $FreeBSD$
tags, and most importantly moving rcvar= to right after
name= so it's clear that one is derived from the other. |
2.2.21 23 Sep 2011 22:26:39 |
amdmi3 |
- Add LDFLAGS to CONFIGURE_ENV and MAKE_ENV (as it was done with LDFLAGS)
- Fix all ports that add {CPP,LD}FLAGS to *_ENV to modify flags instead
PR: 157936
Submitted by: myself
Exp-runs by: pav
Approved by: pav |
2.2.21 15 Sep 2011 05:00:28 |
ohauer |
- update to version 2.2.21
Addresses:
* SECURITY: CVE-2011-3348 (cve.mitre.org)
mod_proxy_ajp when combined with mod_proxy_balancer: Prevents
unrecognized HTTP methods from marking ajp: balancer members
in an error state, avoiding denial of service.
* SECURITY: CVE-2011-3192 (cve.mitre.org)
core: Further fixes to the handling of byte-range requests to use
less memory, to avoid denial of service. This patch includes fixes
to the patch introduced in release 2.2.20 for protocol compliance,
as well as the MaxRanges directive.
PR: ports/160743
Submitted by: Jason Helfman <jhelfman@experts-exchange.com> |
2.2.20_1 12 Sep 2011 23:17:33 |
gabor |
- Track dependencies after databases/gdbm update |
2.2.20 12 Sep 2011 13:46:59 |
gabor |
- Track dependencies after databases/gdbm update |
2.2.20 02 Sep 2011 06:18:02 |
ade |
Emergency upgrade to 2.2.20 - CVE-2011-3192. Any complaints, talk to me.
PR: 160381 |
2.2.19 29 Jun 2011 17:28:44 |
ohauer |
- Close a race condition that sometimes resulted in configure.in
patches being ignored |
2.2.19 22 May 2011 21:33:31 |
ohauer |
- update to httpd-2.2.19
Changes with Apache 2.2.19
*) Revert ABI breakage in 2.2.18 caused by the function signature change
of ap_unescape_url_keep2f(). This release restores the signature from
2.2.17 and prior, and introduces ap_unescape_url_keep2f_ex().
[Eric Covener]
commit with hat apache@ |
2.2.18 14 May 2011 21:53:21 |
ohauer |
- unbreak mpm-itk-20110321-01 patch
PR: ports/157041
Submitted by: zlopi.ru <zlopi.ru _at gmail.com> |
2.2.18 13 May 2011 23:02:38 |
ohauer |
- update to version 2.2.18
Changes:
http://www.apache.org/dist/httpd/CHANGES_2.2.18
Changes with Apache 2.2.18
*) Log an error for failures to read a chunk-size, and return 408 instead
413 when this is due to a read timeout. This change also fixes some cases
of two error documents being sent in the response for the same scenario.
[Eric Covener] PR49167
*) core: Only log a 408 if it is no keepalive timeout. PR 39785
[Ruediger Pluem, Mark Montague <markmont umich.edu>]
(Only the first 15 lines of the commit message are shown above ) |
2.2.17_2 18 Apr 2011 20:32:33 |
ohauer |
- fix Ports with version numbers going backwards for www/apache22-peruser-mpm
- by changing PORTREVISION= to ?=
Issue reported by erwin@ |
2.2.17_2 31 Mar 2011 17:00:37 |
ohauer |
- update Apache 2 ITK MPM patch to version 20110321-01 [1]
- add additional patch for mpm-itk [2]
- add mod_substitute to apache22 [3]
- add some documentation into the mpm-itk* patches
- bump portrevision
Changes:
[1] apache2.2-mpm-itk 2.2.17-01, released 2011-03-21:
* Fixed CVE-2011-1176: If NiceValue was set, the default with no
AssignUserID was to run as root:root instead of the default Apache user
and group, due to the configuration merger having an incorrect default
configuration.
* Rebase against Apache 2.2.17.
* Fix an issue where users can sometimes get spurious 403s on persistent
connections, if the .htaccess files are not world readable. (Only the first 15 lines of the commit message are shown above ) |
2.2.17_1 19 Mar 2011 12:38:54 |
miwi |
- Get Rid MD5 support |
2.2.17_1 07 Dec 2010 20:38:17 |
pgollucci |
- update conflicts |
2.2.17_1 04 Dec 2010 07:34:27 |
ade |
Sync to new bsd.autotools.mk |