Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
Please login to access the resource
SUSE:SLE-12-SP5:Update
squid.3919
squid.changes
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File squid.changes of Package squid.3919
------------------------------------------------------------------- Wed Dec 21 13:57:02 UTC 2016 - adam.majer@suse.de - SQUID-2016_11.patch: fixes incorrect processing of responses to If-None-Modified HTTP conditional request. This allowed responses containing private data to clients it should not have reached. (CVE-2016-10002, bnc#1016168) - nonce-replay.patch: fix nonce replay vulnerability in Digest authentication. (CVE-2014-9749, bsc#949942) ------------------------------------------------------------------- Fri Oct 14 11:40:46 UTC 2016 - adam.majer@suse.de - Fix misported SQUID-2015_2_port.patch which resulted in cascaded proxies not working with CONNECT resquests, ie. https (bnc#1003270) ------------------------------------------------------------------- Fri Jul 22 09:21:17 UTC 2016 - adam.majer@suse.de - squid-3-12982.patch: * Update forward_max_tries to permit 25 server paths With cloud sites becoming more popular more CDN servers are producing long lists of IPv6 and IPv4 addresses. If there are not enough paths selected the IPv4 ones may never be reached. - SQUID_2015_2_port.patch: * Improper Protection of Alternate Path (CVE-2015-5400, bsc#938715) * replaces squid:bsc_938715:CVE-2015-5400.patch - SQUID-2016_2_port.patch * Multiple DoS issues in HTTP Response processing (CVE-2016-2569, CVE-2016-2570, CVE-2016-2571, CVE-2016-2572, bsc#968392, bsc#968393, bsc#968394, bsc#968395) - SQUID_2016_2_fix_port.patch: * backport squid-3.5-13998.patch to address "side-effects" caused by original SQUID-2016_2 fixes. - SQUID_2016_3.patch: * fix buffer overrun issue in pinger ICMPv6 processing. (CVE-2016-3947, bsc#973782) - SQUID_2016_4_port.patch: * fix Denial of Service issue in HTTP Response processing. (CVE-2016-3948, bsc#973783) - SQUID-2016_5.patch: * fix buffer overflow in cachemgr.cgi (CVE-2016-4051, bnc#976553) - SQUID_2016_6.patch: * fix multiple issues in ESI processing. (CVE-2016-4052, CVE-2016-4053, CVE-2016-4054, bsc#976556) - SQUID_2016_7_port.patch: * fix cache poisoning issue in HTTP Request handling (CVE-2016-4553, bsc#979009) - SQUID-2016_8.patch: * fix header smuggling issue in HTTP Request processing (CVE-2016-4554, bsc#979010) - SQUID_2016_9_port.patch: * fix multiple Denial of Service issues in ESI Response processing. (CVE-2016-4555, CVE-2016-4556, bsc#979011, bsc#979008) - Not affected by: * CVE-2016-2390, bsc#967011 - Now requires automake/autoconf as Makefile.am is modified - rename squid:bsc_949942:CVE-2014-9749.patch to CVE-2014-9749-WIP.patch - update RELEASENOTES.html to 3.3.14 - fix all unit tests so they compile and run again - drop BR: on gpg-offline as source code verification is now done via source_validator OBS service - remove previously applied patches upstream in the 3.3.14 release. * SQUID-2015_1.patch * SQUID-2014_3.patch * SQUID-2014_4.patch - remove --enable-ntlm-fail-open option from configure, as it is not supported by Squid 3.3.x - squid.init: * wait that squid really dies when we kill it on upgrade instead of proclaiming its demise prematurely (bnc#963539) ------------------------------------------------------------------- Mon Dec 21 15:17:54 UTC 2015 - fstrba@suse.com - Added patch: * fix-external_acl-session-build.patch - bsc#959290: squid: external helper ext_session_acl is missing - Package the fixed built ext_session_acl ------------------------------------------------------------------- Thu Nov 19 12:05:11 UTC 2015 - fstrba@suse.com - Upgrade to squid-3.3.14 * Changes to squid-3.3.14 (01 May 2015): - Bug 4093: source-maintenance.sh errors and warnings due to wrong tools/options - ... and some documentation updates - ... and all fixes from squid 3.2.14 - Removed patches: * squid3-snmp-off-by-one.patch * squid:bsc_929493:CVE-2015-3455.patch - Fixed upstream - Changed patch: * squid:bsc_949942:CVE-2014-9749.patch - Backport changes from the 3.4 branch instead of using first fix that was already amended (bsc#955783) ------------------------------------------------------------------- Thu Nov 5 12:59:27 UTC 2015 - fstrba@suse.com - merge scriptlet changes from Factory - fix permissions for SLE12 * revert suid bit for pinger and basic_pam_auth add them to permissions file (commented) ------------------------------------------------------------------- Mon Oct 19 13:56:44 UTC 2015 - jkeil@suse.de - fix bsc#938715 * squid:bsc_938715:CVE-2015-5400.patch * VUL-1: CVE-2015-5400: squid,squid3: Improper Protection of Alternate Path ------------------------------------------------------------------- Mon Sep 14 15:15:52 UTC 2015 - jkeil@suse.de - Fix bsc#902197 * unsquid.pl was broken, patch provided by jreidinger@ ------------------------------------------------------------------- Tue Sep 1 16:43:16 UTC 2015 - jkeil@suse.de - fix bsc#929493 * squid3: Squid HTTP Proxy configured with client-first SSL bumping does not correctly validate server certificate * CVE-2015-3455 * squid:bsc_929493:CVE-2015-3455.patch ------------------------------------------------------------------- Thu Dec 11 18:04:55 UTC 2014 - jmatejek@suse.com - squid3-snmp-off-by-one.patch - fix off-by-one in snmp subsystem (CVE-2014-6270, bnc#895773) ------------------------------------------------------------------- Mon Sep 1 11:23:34 UTC 2014 - meissner@suse.com - Changes to squid-3.3.13 (28 Aug 2014): - Fix segmentation fault setting up server SSL connnection - HTTP/1.1: Ignore Range headers with unidentifiable byte-range values - Changes to squid-3.3.12 (09 Mar 2014): - Regression Bug 3769: client_netmask not evaluated since Comm redesign - Bug 4026: Fix SSL and adaptation_access handling of aborted connections - Bug 3969: Fix credentials caching for Digest authentication - Bug 3806: Caching responses with Vary header - Fix umask default on crash report generated email - Fix pthread library detection on FreeBSD 10 - Avoid assertions on Range requests that trigger Squid-generated errors. (bnc#867533 CVE-2014-0128) ------------------------------------------------------------------- Thu Aug 14 16:14:25 CEST 2014 - draht@suse.de - squid-cert_tool_use_bash_not_ksh.patch: /usr/sbin/cert_tool should use bash, not ksh. [bnc#891313] ------------------------------------------------------------------- Wed Dec 25 21:29:38 UTC 2013 - chris@computersalat.de - Changes to squid-3.3.11 (01 Dec 2013): * Regression Bug 3936: error-details.txt parse error with OpenSSL since 3.3.9 * Bug 3972: Segfault when getting the deny_info page ID after a reconfigure * Bug 3970: max_filedescriptors disabled due to missing setrlimit * Bug 3967: ipc/Kid.cc compilation failure: 'time' was not declared in this scope * Bug 3960: DEAD cache_peer are not revived * Bug 3956: xstrndup: tried to dup a NULL pointer * Bug 3906: Filedescriptor leaks in SNMP * Bug 3782: Digest authentication not obeying nonce_max_count * HTTP/1.1: Make header parser obey relaxed_header_parser * HTTP/1.1: Re-compute Range response content offset after an FTP response was adapted * SMP: Replace blocking sleep(3) and close UDS socket on failures * Windows: fix several compile errors - Changes to squid-3.3.10 (03 Nov 2013): * Bug 3929: request_header_add not working for tunnel requests * Bug 3923: cbdata and undefined behavior due to dynamic runtime enumeration * Bug 3918: Self Test Failures on Mac OS X 10.8 * Bug 3887: tcp_outgoing_tos not working for IPv6 * Bug 3836: Fix issues with automake 1.13+ and make check * Bug 3480: StoreEntry::kickProducer() segfaults in store_client::copy() * Fix pinning hierarchy log information * Fix close idle client connections associated with closed idle pinned connections. * Fix cbdata 'error: expression result unused' errors * Avoid "hot idle": A series of rapid select() calls with zero timeout. * Append Connection:close to OPTIONS requests when icap_persistent_connections is off * ntlm_fake_auth: pass DOMAIN data to Squid in original case * kerberos_ldap_group: fix LDAP string duplication * Use IPv6 localhost nameserver on DNS configuration errors * Add cache_miss_revalidate * ... and several portability improvements - modified patches: * squid-compiled_without_RPM_OPT_FLAGS.patch * squid-config.patch - fix build for SLE (libxml2-devel vs pkgconfig(libxml2)) - fix changed files * bindir/purge * bindir/squidclient ------------------------------------------------------------------- Sat Sep 28 17:56:52 UTC 2013 - chris@computersalat.de - Changes to squid-3.3.9 (11 Sep 2013): * Regression Bug 3077: off-by-one error in Digest header decoding * Bug 3895: fix acl_uses_indirect_client and cache_peer_access * Bug 3879: assertion failed ConnStateData::validatePinnedConnection * Bug 3863: myportname acl causes segmentation fault * Bug 3849: Duplicate certificate sent when using https_port * Bug 2287: Better fix for unsupported HTTP version handling * Bug 2112: Reload into If-None-Match * Fix several assert with side effects in ICAP/eCAP response handling * Fix myportname ACL on ICAP/eCAP transactions * Fix external ACL user:pass detail logging after adaptation * Fix SMP mgr:info report 'Largest file desc currently in use' * Improved compatibility with gcc 4.8, clang and icc * Show number of available filedescriptors when reserved FD changes * Sync with newest OpenSSL error codes * Register Http2-Settings header * ... and many Windows portability fixes - fix changelog ------------------------------------------------------------------- Thu Sep 5 11:43:22 UTC 2013 - chris@computersalat.de - fix build for Factory * rework fix-pod2man-check ------------------------------------------------------------------- Mon Sep 2 21:58:38 UTC 2013 - chris@computersalat.de - fix build for 1110 (SLES_11) * add configure --disable-strict-error-checking ------------------------------------------------------------------- Sun Sep 1 12:25:46 UTC 2013 - chris@computersalat.de - Changes to squid-3.3.8 (13 Jul 2013): * Bug 3869: assertion failed: MemBuf.cc:272: size < capacity * Improved handling of port values in Host: header validation - Changes to squid-3.3.7 (11 Jul 2013): * Bug 3297: Fix openSSL related build failures * Fix build on FreeBSD 9.x platform with clang * Protect against buffer overrun in DNS query generation - Changes to squid-3.3.6 (01 Jul 2013): * Bug 3854: pt1: compile errors on AIX * Bug 3802: Fix wrong check inside Format::Format::assemble * Bug 3762: remove bogus WARNING in cache.log * Bug 3717: assertion failed with dstdom_regex with IP based URL * Bug 1991: kqueue causes SSL to hang * Ask for SSL key password when started with -N but without sslpassword_program * Make sure %<tt includes all [failed] connection attempts * Support HTTP reply ACLs in icap_log and log_icap * Fix incorrect external_acl_type codes * Fix ICAP logging request headers and segmentation faults * ... and some documentation polish - Changes to squid-3.3.5 (20 May 2013): * Bug 3851: Delay Pool class 5 tag:levels displayed incorrectly in cache manager * Bug 3845: http_port tcpkeepalive= option fails parsing * Bug 3840: assertion failed 'sde' in UFS cache loading * Bug 3836: make check failures with automake-1.13 * Bug 3827: Remove AccessLogEntry::cache.authuser * Bug 3816 pt2: SSL_get_certificate call inside Ssl::verifySslCertificate crashes * Bug 3780: cachemgr.cgi: output problem in HTTP Header Statistics * Bug 3759: OpenSSL compilation error on stock Fedora17, RHEL, CentOS 6 systems * Bug 3744: squid terminated: FATAL: Bungled (null) line 3: sslproxy_cert_sign signTrusted all * Port from 2.6: external acl %ACL and %DATA tags * Update copyright on SN.png * ... and several minor memory leaks * ... and some documentation polish - Changes to squid-3.3.4 (27 Apr 2013): * Bug 3831: basic_ncsa_auth Blowfish and SHA support * Bug 3816: SSL_get_certificate call inside Ssl::verifySslCertificate crashes * Bug 3794: MacOS: workaround compiler errors and case-insensitivity * Bug 3781: Proxy Authentication not sent to cache_peer * Bug 3720 pt1: SourceLayout: shuffle fd_table definition into fde.h * Bug 3720 pt2: Add missing include in /dev/poll I/O module * Bug 3674: Improve compiler detection, better support warnings-as-errors on clang * Add support for TPROXY on BSD * Fix SSL Bump bypass for intercepted traffic * Fix memory leaks in ConnStateData pinning * Fix external_acl.cc "inBackground" assertion on queue overloads * CacheMgr: fix missing column separator in helper stats * OpenBSD: libpthreads requires OpenBSD 5.2 or later * ... and lots of documentation updates * ... and all changes from squid 3.2.10 - Changes to squid-3.3.3 (12 Mar 2013): * Bug 3720: Add missing include in /dev/poll I/O module (pt2) * ... and all changes from squid 3.2.9 - Changes to squid-3.3.2 (02 Mar 2013): * Bug 3781: Proxy Authentication not sent to cache_peer * Bug 3794: MacOS: workaround compiler errors * Bug 3720: Compile error in Solaris /OpenIndiana * ... and all changes from squid 3.2.8 - Changes to squid-3.3.1 (09 Feb 2013): * Bug 3726: build errors with --disable-ssl * Propigate pinned connection persistency and closures to the client. * Mimic SSL certificate Key Usage and Basic Constraints * Fix segmentation fault on missing squid.conf values * ext_sql_session_acl: Fix hex decoding on UID * ... and some code polish * ... and a lot of documentation polish * ... and all changes from squid 3.2.7 - rebase patches * config, nobuilddates, compiled_without_RPM_OPT_FLAGS ------------------------------------------------------------------- Sun Jul 28 12:44:37 UTC 2013 - bruno@ioda-net.ch - Changes to squid-3.2.13 (13 Jul 2013): * Bug 3869: assertion failed: MemBuf.cc:272: size < capacity * Improved handling of port values in Host: header validation - Changes to squid-3.2.12 (11 Jul 2013): * Protect against buffer overrun in DNS query generation * Avoid !closing assertions when helpers call comm_read during reconfigure. * Fix several minor memory leaks during reconfigure * Remove origin_tries limiter on forwarding and permit large max_forward_tries values ------------------------------------------------------------------- Thu Jul 25 10:19:05 UTC 2013 - tchvatal@suse.com - Add patch squid-fix-pod2man-check.patch solving building with new perl. ------------------------------------------------------------------- Tue Apr 30 11:42:06 UTC 2013 - bruno@ioda-net.ch - Changes for squid 3.2.11 release (29 April 2013) * Fix enter_suid/leave_suid build errors in ip/Intercept.cc * GNU Hurd: define MAP_NORESERVE as no-op when missing * Bug #3833: Option '-k' is not present in squidclient man page * Bug #3817: Memory leak in SSL cert validate for alt_name peer certs * Bug #3822: Locate LDAP and SASL headers in /usr/local/include for BSD support * Bug #3825: basic_ncsa_auth segfaulting with glibc-2.17 * Bug #3774: -k reconfigure drops rock * Bug #3565: Resuming postponed accept kills Squid * HTTP/1.1: partial support for no-cache and private controls with parameters * ssl_crtd: helpers dying during startup on ARM * Updated copyright for icons/SN.png squid-3.2-11813.patch * Revert r11810 - tools.h does not exist in 3.2 squid-3.2-11812.patch ------------------------------------------------------------------- Sun Mar 24 18:57:26 UTC 2013 - bruno@ioda-net.ch - Fixed squid.service - Removed commented patch lines ------------------------------------------------------------------- Fri Mar 15 10:31:02 UTC 2013 - bruno@ioda-net.ch - New revision for squid.service (using only sed) handle multiple cache_dir line Added sed as require - Packaging : fixed systemd squid.service * Rework on squid.service ExecStartPre line remove dependency on unfunctionnal wrapper * Fix bnc#802635 (creating cache struture fail on first call) * Fixed Type=forking and remove the use off -N (non daemon flag) * Fixed missing pid file * Structural : add all -k to end of Exec/Stop line * Ulimit : Added LimitNOFile=4096 ( same value as in /etc/sysconfig) but there's no way to decode dynamically /etc/sysconfig * Remove syslog.target ( no need anymore : advise from fcrozat ) * Clean up squid_cache_build.sh - Changes to squid-3.2.9 (12 Mar 2013): * Regression fix: Accept-Language header parse * Bug 3673: Silence 'Failed to select source' messages * Fix authentication headers sent on peer digest requests * Fix build error on Solaris, OpenIndiana, Omnios - Changes to squid-3.2.8 (02 Mar 2013): * Bug 3767: tcp_outgoing_tos/mark ACLs do not obey acl_uses_indirect_client * Bug 3763: diskd Error: no filename in shm buffer * Bug 3752: objects that cannot be cached in memory are not cached on disk * Bug 3753: Removes the domain from the cache_peer server pconn key * Bug 3749: IDENT lookup using wrong ports to identify the user * Bug 3723: tcp_outgoing_tos/mark broken for CONNECT requests * Bug 3686: cache_dir max-size default fails * Bug 3515: crash in FtpStateData::ftpTimeout * Bug 3329: Quieten orphan Comm::Connection messages * Make squid -z for cache_dir rock preserve the rock DB * Fixed several server connect problems * ... and some build issues on Solaris, OpenIndiana, MacOS X * ... and some documentation and debugs polishing ------------------------------------------------------------------- Wed Feb 20 23:24:06 UTC 2013 - e.istomin@edss.ee - Changes to squid-3.2.7 (01 Feb 2013): * Bug 3736: Floating point exception due to divide by zero * Bug 3735: raw-IPv6 domain URLs crash if IPv6-disabled * Bug 3732: Fix ConnOpener IPv6 awareness * Bug 3729: 32-bit overflow in parsing 64-bit configuration values * Bug 3728: Improve debug for cache_dir * Bug 3687: unhandled exception: c when using interception and peers * Bug 3678: external acl grace period causes acl lookup failures * Bug 3567: Memory leak handling malformed requests * Bug 3111: Mid-term fix for the forward.cc "err" assertion * Support OpenSSL NO_Compression optio * Fix IPv6 enabled pinger on split-stack or IPv6-disabled systems * Fix "address.GetPort() != 0" assertion for helpers * ... and several minor memory leaks * ... and some cache.log message polishing ------------------------------------------------------------------- Sun Jan 13 20:09:22 UTC 2013 - chris@computersalat.de - Changes to squid-3.2.6 (09 Jan 2013): fix for bnc#794954, CVE-2012-5643, SQUID:2012-1 - Regression Bug 3731: TOS setsockopt() requires int value - Regression Bug 3712: Rotating logs overwrites the previous log - Bug 3727: LLVM compile errors in kerberos_ldap_group - Bug 3650: Negotiate auth missing challenge token - Additional fixes for CVE-2012-5643 / SQUID:2012-1 * http://www.squid-cache.org/Advisories/SQUID-2012_1.txt * http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5643 - rebase nobuilddates, config patches ------------------------------------------------------------------- Sun Dec 30 14:56:38 UTC 2012 - chris@computersalat.de - Changes to squid-3.2.5 (10 Dec 2012): - Bug 3698: Add missing include of errno.h - Changes to squid-3.2.4 (03 Dec 2012): - Ported: urllogin ACL from squid 2.7 - Bug 3688: Lots of Orphan Comm:Connections to ICAP server - Bug 3677: Port un-pinning logic changes from squid 3.3 - Bug 3405: ssl_crtd crashes failing to remove certificate - ... and major bugs fixed in squid 3.1.22 - Fix accept_filter on Linux - Remove 'Bungled' warning on missing component directives - ... and many buffer and memory leak issues in the bundled helpers - ... and a small amount of code polishing - remove obsolete glibc-217 patch ------------------------------------------------------------------- Thu Nov 29 19:10:16 CET 2012 - sbrabec@suse.cz - Verify GPG signature. ------------------------------------------------------------------- Sat Nov 17 09:38:19 UTC 2012 - aj@suse.de - Fix build with glibc 2.17 (add patch squid-glibc217.patch). ------------------------------------------------------------------- Sun Oct 21 14:30:21 UTC 2012 - chris@computersalat.de - update to 3.2.3 (21 Oct 2012): - Regression: SMP crashes on startup with workers > 1 - Bug 3655: pinning failure breaks NTLM and Negotiate authentication - SMP: Allow a UFS cache_dir entry to coexist with a shared memory cache entry - HTTP/1.1: honour Cache-Control before Pragma:no-cache - HTTP/1.1: Cache-Control compliance upgrade - Remove obsoleted refresh_pattern ignore-no-cache option - Fix IPv6 enabled squidclient - ... and several compile fixes ------------------------------------------------------------------- Sat Oct 20 11:52:33 UTC 2012 - chris@computersalat.de - update to 3.2.2 (06 Oct 2012): - Regression: Make login=PASS send no credentials when none available - Regression: Handle dstdomain duplicates and overlapping names better - Bug 3661: Segmentation fault when using more than 1 worker - Bug 3660: ACLFilledChecklist::fd set with wrong fd for sslproxy_cert_error - Bug 3658: ERR_ZERO_SIZE_OBJECT propagates out even after successful retry - Bug 3648: polish String class files - Bug 3647: parsing hier_code acl fails - Bug 3626: forwarding loops on intercepted traffic - Bug 3616: retrieve client connection for ACL checks from the related HttpRequest object - Bug 3609: several RADIUS helper improvements - Bug 3605: memory leak in Negotiate authentication - Fix small memory leak in src ACL parse - Fix maximum_single_addr_tries upgrade - Fix chunked encoding on responses carrying a Content-Range header. - Do not reuse persistent connections for PUTs to avoid ERR_ZERO_SIZE_OBJECT - ... and several compile errors - fix deps * add missing Obsoletes/Provides for squid3 ------------------------------------------------------------------- Wed Aug 15 17:40:30 UTC 2012 - chris@computersalat.de - package rename from squid3 back to squid * old 'squid' (2.7STABLE9) now obsolete * only one "stable" squid available >= 3.2 ------------------------------------------------------------------- Wed Aug 15 11:46:11 UTC 2012 - chris@computersalat.de - update to 3.2.1 (15 Aug 2012): - Bug 3605: memory leak in peer selection - Bug 3478: better default handling without -DSTRICT_ORIGINAL_DST - ... and some documentation updates - rebase squid-config patch ------------------------------------------------------------------- Fri Aug 3 11:27:00 UTC 2012 - chris@computersalat.de - update to 3.2.0.19 (02 Aug 2012) - Regression Bug 3580: IDENT request makes squid crash - Regression Bug 3577: File Descriptors not properly closed - Regression Bug 3478: Allow peer selection and connection auth on intercepted traffic - Regression Fix: Restore memory caching ability - Bug 3556 Workaround: epoll assertion failed: comm.cc:1093: isOpen(fd) - Bug 3551: store_rebuild.cc:116: "store_errors == 0" assertion - Bug 3525: Do not resend nibbled PUTs and avoid "mustAutoConsume" assertion. - Avoid bogus "Disk space over limit" warnings when rebuidling dirty ufs index - Support custom headers in [request|reply]_header_* manglers - ... and much code polishing - remove upstream patches * 3.2-11611 - 3.2-11638 - rebase config, nobuilddates, compiled_without_RPM_OPT_FLAGS patches ------------------------------------------------------------------- Mon Jul 30 23:52:17 UTC 2012 - chris@computersalat.de - add upstream patches * 3.2-11631 - 3.2-11638 ------------------------------------------------------------------- Fri Jul 27 13:11:15 UTC 2012 - chris@computersalat.de - update to 3.2.0.18 (29 Jun 2012) - Bug 3576: ICY streams being Transfer-Encoding:chunked - Bug 3537: statistics histogram leaks memory - Bug 3526: digest authentication crash - Bug 3484: Docs: sslproxy_cert_error example flawed - Bug 3462: Delay Pools and ICAP - Bug 3405: ssl_crtd crashes failing to remove certificate - Bug 3380: Mac OSX compile errors with CMSG_SPACE - Bug 3258: Requests hang when Host forgery verify fails - Bug 3186: Digest auth caches failed state without revalidating - Bug 2976: ERR_INVALID_URL for transparently captured requests when reconfiguring - Bug 2885: AIX: check and set required compiler flags - Fix ssl_crtd compile issues with libsslutil - Fix build with GCC 4.7 (and probably other C++11 compilers). - Fix double-escape of %R on deny_info redirect responses - Support status 308 Permanent Redirect - Support for TLSv1.1 and TLSv1.2 options and methods - Support passing external_acl_type credentials on ICAP - Language Updates: fr, hy, pt_BR - ... and many compile issues on Windows - ... and some minor code polish for more info please see ChangeLog - remove obsolete swapdir, FSF patches - rebase config, nobuilddates patches - add upstream patches * 3.2-11611 - 3.2-11630 - add compiled_without_RPM_OPT_FLAGS patch * squid3 no-rpm-opt-flags <cmdline>:./cf_gen.cc ------------------------------------------------------------------- Tue Jun 12 10:22:46 UTC 2012 - chris@computersalat.de - update to 3.1.20 - Regression Bug 3545: FreeBSD dnsserver segfaults - Regression Bug 3504: clientside_tos fails to mark traffic - Bug 3539: CONNECT server connection not closed correctly on errors - Bug 3502: client timeout uses server-side read_timeout, not request_timeout - Bug 3466: Adaptation stuck on last single-byte body piece - Bug 3463: dnsserver fails to compile - Bug 3439: correct external_acl_type documented default for ipv4/ipv6 option - Bug 3390: Proxy auth data visible to scripts - Bug 3263: ssl_crtd: undefined references to squid_curtime - Bug 3233: Invalid URL accepted with url host is white spaces - Bug 3133: Memory leak handling requests for sites that don't exist - Bug 3074: Improper URL handling with empty path (RFC 3986) - Bug 3013: segmentation fault on shutdown commSetCloseOnExec at comm.cc:1889 - Regression: snmp/udp address directives not resolving hostname - Better helper-to-Squid buffer size management. - Support CoAP over HTTP (coap:// and coaps:// URLs) - Support for 3.2 error template codes - rebase config, swapdir patch ------------------------------------------------------------------- Fri Feb 17 16:01:23 UTC 2012 - chris@computersalat.de - some cleanup * rebase patches (p0), remove version from patch_names - add Source signature file - add FSF patch (incorrect-fsf-address) - add rpmlintrc file * macro-in-comment * no-manual-page-for-binary ------------------------------------------------------------------- Wed Feb 15 20:50:59 UTC 2012 - chris@computersalat.de - update to 3.1.19 - Regression Bug 3441: part 2: Prevent further cache size corruption of swap.state - Bug 3473: erase last uses of obsolete auth_user_hash_pointer - Bug 3470: GCC 4.7 - Bug 3442: assertion failed: external_acl.cc:908: ch->auth_user_request != NULL - Bug 3441: part 1: Minimize cache size corruption by malformed swap.state - Bug 3440: compile error in Adaptation - Bug 3420: Request body consumption races and !theConsumer exception - Bug 3370: external ACL sometimes skipping - Bug 3085: Crash when parsing esi:include - HTTP/1.1: do not add 110 and 111 Warnings to revalidated responses - Fix SSL library dependency fixes - remove obsolete upstream patches * squid-3.1-10415 - ..421 - add squid source signature file ------------------------------------------------------------------- Mon Jan 16 13:49:22 UTC 2012 - chris@computersalat.de - add upstream patches * 3.1-10419: Bug #3085: Crash when parsing esi:include * 3.1-10420: Bug #3473: erase last uses of obsolete auth_user_hash_pointer * 3.1-10421: Bug #3420: Request body consumption races and !theConsumer exception. ------------------------------------------------------------------- Wed Dec 21 12:12:09 UTC 2011 - chris@computersalat.de - fix for bnc#737905 * fix test EXPRESSION in post section ------------------------------------------------------------------- Mon Dec 12 12:47:50 UTC 2011 - chris@computersalat.de - add upstream patches * 3.1-10417: Polish: debug messages on swap.state rename failure * 3.1-10418: Bug #3442: assertion failed: external_acl.cc:908: ch->auth_user_request != NULL ------------------------------------------------------------------- Wed Dec 7 22:33:43 UTC 2011 - chris@computersalat.de - fix build * add upstream patches - 3.1-10415: Portability: SSL library dependency fixes - 3.1-10416: Bug #3440: compile error in Adaptation ------------------------------------------------------------------- Mon Dec 5 09:21:26 UTC 2011 - chris@computersalat.de - update to 3.1.18 - Regression: compile error in FTP - Changes to squid-3.1.17 (03 Dec 2011): - Bug 3432: Crash logging FTP errors - Bug 3428: Active FTP data channel accepted twice - Bug 3423: access violation in URL parser - Bug 3422: Buffer overflow in recv-announce - Bug 3412: External ACL Uses Invalid Cache Entry - Bug 3408: Wrong header length leads to EFAULTs when creating UFS swap.log.new - Bug 3398: persistent server connection closed after PUT/DELETE - Bug 3299: dnsserver: various undefined references - Bug 3077: '\' in url query strings cause Digest authentication to fail - Bug 2910: MemBuf may grow beyond max_capacity - Bug 2619: Excessive RAM growth due to unlimited adapted body data consumption - Bug 1243: Build overrides configured AR setting - Avoid crashes when processing bad X509 common names (CN). - Support %% in external ACL format - ... and several other compile error fixes - ... and several documentation fixes ------------------------------------------------------------------- Wed Nov 30 18:58:11 UTC 2011 - crrodriguez@opensuse.org - make coolo's bot reviewer happy ------------------------------------------------------------------- Wed Nov 30 18:11:27 UTC 2011 - crrodriguez@opensuse.org - Use service type "simple" ------------------------------------------------------------------- Mon Nov 28 20:18:40 UTC 2011 - crrodriguez@opensuse.org - Support systemd ------------------------------------------------------------------- Sun Nov 27 06:56:29 UTC 2011 - coolo@suse.com - add libtool as buildrequire to avoid implicit dependency ------------------------------------------------------------------- Sat Oct 15 14:00:35 UTC 2011 - chris@computersalat.de - update to 3.1.16 - Bug 3373: invalid URL in ERR_CACHE_ACCESS_DENIED - Bug 3368: Unhandled exceptions are not logged (workaround) - Bug 3326: miss_access incorrect default - Bug 3320: miss_access description confusing - Bug 3241: squid_kerb_auth cross compilation fix - Bug 3237: seq fault in free() from rfc1035RRDestroy - Bug 3190: Large HTTP POST stuck after early ICAP 400 error response - db_auth: display available DSN drivers on connect error - Updated OpenSSL 1.0.0 version checks - ... and several documentation fixes ------------------------------------------------------------------- Wed Oct 5 00:32:36 UTC 2011 - crrodriguez@opensuse.org - Build with -DOPENSSL_LOAD_CONF see OPENSSL_config(3) for detail ------------------------------------------------------------------- Tue Aug 30 15:44:50 UTC 2011 - chris@computersalat.de - update to 3.1.15 - Regression fix: vhost and defaultsite causing vport to be ignored - Regression Bug 3295: broken escaping in rfc1738_do_escape - Bug #3232: fails to compile with OpenSSL v1.0.0 - Bug #3222: cache_peer name is not logging on CONNECT - Bug #3131: fd_table[fd].closing() assert from ConnStateData::noteMoreBodySpaceAvailable() - Bug #3217: "!fd_table[fd].closing()" from ServerStateData::noteMoreBodySpaceAvailable - Bug #3213: https sites (CONNECT) not open when using NTLM - Bug #3114: Memory leak in SSL certificate verify code - Bug #3107: ncsa_auth DES silently truncates passwords to 8 bytes - Bug #2662: cf_gen failure when cross compiling - Bug #2655: passing wrong the username to the url_rewrite_program - Bug #2495: ignore whitespace prefix on config lines - Bug #2051: 'default' cache_peer option does not match documentation - Bug #1842: Optimize order of tests in peerWouldBePinged() and peerHTTPOkay() - Bug #1791: timestampsSet does not validate Date: if server sends very old date - Correct parsing of large Gopher indexes - Enable negative cacheing on unknown or -1 expiry timestamp - Remove hierarchy_stoplist default value - Migrate cf_gen tool from C-style to C++ - ... and several documentation and compiler warning fixes ------------------------------------------------------------------- Thu Aug 18 04:33:40 UTC 2011 - crrodriguez@opensuse.org - Disable "ident" lookups, obsolete and dangerous thing to have enabled these days. ------------------------------------------------------------------- Sun Jul 24 14:29:24 UTC 2011 - chris@computersalat.de - fix build for SLE_10 ------------------------------------------------------------------- Wed Jul 20 04:29:08 UTC 2011 - crrodriguez@opensuse.org - This is a long running network daemon, build with full RELRO - remove -fno-strict-aliasing, no longer needed. ------------------------------------------------------------------- Mon Jul 4 22:05:17 UTC 2011 - chris@computersalat.de - update to 3.1.14 - Regression Bug 3261: Could not create a DNS socket and exit - 3.1.13 - Regression Bug 3239: problems with myip/myport upgrade - Bug 3153: hung ICAP RESPMOD transactions - Update ssl_crtd to use 'OK' status inline with other helpers - remove obsolete upstream patches (10319,10320) ------------------------------------------------------------------- Mon Jun 27 13:42:53 UTC 2011 - chris@computersalat.de - add upstream patches o 10319, SourceFormat Enforcemen o 10320, Bug 3153: additional compile fixes ------------------------------------------------------------------- Sun Jun 19 18:37:40 UTC 2011 - chris@computersalat.de - update to 3.1.12.3 - Bug 3236: Port of %oa, %<lp and %<lp and %<la log format options - Bug 3214: unexpected read from ssl_crtd - Bug 3153: Prevent ICAP RESPMOD transactions getting stuck with the adapted body - Fix RADIUS helper resource leak - Fix segfault parsing digest auth realm - Fix segfault in parse_eol() - Fixed bypass of SSL certificate validation errors - Warn about myip/myport problems on interception proxies - Polish: display easily grepped config lines on -k parse - Fix squidclient -V option and allow non-HTTP protocols to be tested - rework patches o swapdir 3.1.10 -> 3.1.12.3 o nobuilddates 3.1.12 -> 3.1.12.3 - remove obsolete patches o 3.1.11-unused o 3.1.12-no-sslv2 ------------------------------------------------------------------- Thu Jun 2 14:33:36 UTC 2011 - chris@computersalat.de - update to 3.1.12.2 - Bug 3226: Tags from external ACLs do not correctly expire - Bug 3215: Malformed IPv6 DNS reverse lookup - Bug 3209: ssl-bumped requests forwarded unencrypted to the parent proxies/caches - Bug 3205: SSL-bump starts then hangs - Bug 3178: gcc-4.6 complains unused variables - Bug 3122: Unknown record type in WCCPv2 Packet (6) - Bug 2965 (partial): Compile errors on MinGW - Fix to only ssl-bump CONNECT requests if they are about to be tunneled - Fix cache manager display of -i/+i in regex ACL config display - Fix cache manager display of cache_peer options userhash and sourcehash - Fix URL re-writer loosing many transaction details - Fix always-true comparison in ICAP for some 32-bit platforms - Support for 'slow' group ACLs in ssl_bump access control - Support OpenSSL 1.0.0 built without SSLv2 - Support GCC 4.6 and binutils-gold - Add CSS id attribute to BODY tag of generated error pages. - Display WARNING and ERROR when max_filedescriptors has failed ------------------------------------------------------------------- Thu May 5 19:27:36 UTC 2011 - chris@computersalat.de - update to 3.1.12.1 - Port from 3.2: Dynamic SSL Certificate generation - Bug 3194: selinux may prevent ntlm_smb_lm_auth from using /tmp - Bug 3185: 3.1.11 fails to compile on OpenBSD 4.8 and 4.9 - Bug 3183: Invalid URL accepted with url host part of only '@' - Display ERROR in cache.log for invalid configured paths - Cache Manager: send User-Agent header from cachemgr.cgi - ... and many portability compile fixes for non-GCC systems. ------------------------------------------------------------------- Tue May 3 17:57:56 UTC 2011 - chris@computersalat.de - rework initscript o rename source to squid.init o ShouldStart winbind o setup cache_dir only if defined in squid.conf otherwise squid won't start, cause cache_dir is not set by default o new vars to squid.sysconfig default_opts '-sYD' -> '-sY' (-D obsolete) - remove author from spec - updated unused patch (idoenmez@novell.com) ------------------------------------------------------------------- Fri Apr 29 11:10:06 UTC 2011 - idoenmez@novell.com - Add squid-3.1.11-unused.patch: remove write only variables to fix compilation with gcc 4.6 ------------------------------------------------------------------- Thu Apr 21 16:05:07 UTC 2011 - chris@computersalat.de - mv RPM_BUILD_ROOT to {buildroot} - fdupes only on {buildroot}{_prefix} o no symlinks on config files ;) hence configs won't be overwritten on update ------------------------------------------------------------------- Tue Apr 12 13:11:40 UTC 2011 - chris@computersalat.de - rework config patch o 3.1.4 -> 3.1.12 - add some comments for patches - sort header TAGS ------------------------------------------------------------------- Mon Apr 11 03:03:01 UTC 2011 - crrodriguez@opensuse.org - Allow compile without SSLv2 o no-sslv2 patch - Supress build dates in binaries. o nobuilddates patch - Default cache storage type should be "aufs" in Linux o update config patch ------------------------------------------------------------------- Wed Apr 6 14:15:58 UTC 2011 - chris@computersalat.de - update to 3.1.12 (Bugs tracked by http://bugs.squid-cache.org/) - Regression fix: Use bigger buffer for server reads. - Regression fix: Add reply_header_replace directive for ability lost since 2.7 - Bug 3181: /dev/poll fails to build on Solaris with GCC 4.5.0 - Bug 3177: assertion failed: comm.cc:1583: "fd >= 0" - Bug 3175: IPv6 PTR lookup crashes on raw-IP URLs when IPv6 disabled - Bug 3173: Assertion bodyPipe!=NULL on SslBump CONNECT response writing failure - Bug 3164: Total memory info display 32-bit overflows - Bug 3155: Werror is hard-coded in libTrie build - Bug 3151: squid_kerb_auth: use autoconf LIBS instead of FLAGS for library linkage - Bug 2976: invalid URL on intercepted requests during reconfigure - Bug 2720: comment in same line as cache/mem_replacement_policy causes error - Bug 2621: Provide request headers to RESPMOD when using cache_peer. - Bug 2330: AuthUser objects are never unlocked - Prevent CONNECT request relaying to origin servers - squidclient HTTP/1.1 compliance updates (Pragma and User-Agent headers) - squidclient: send Cache Manager password using -w - eCAP: give full Request-URI to adapters - ... and several debug and error display cleanups ------------------------------------------------------------------- Sun Feb 13 17:03:55 UTC 2011 - chris@computersalat.de - update to 3.1.11 - Bug 3149: not caching eCAP adapted body - Bug 3144: redirector program blocks while reading STDIN - Bug 3140: memory leak in error page generation - Bug 3137: RADIUS auth helper does not send identifier to RADIUS server - Bug 3115: logging segfaults if access_log is set to a directory - Bug 2968: Show the Vary: headers information in cachemgr objects report - Bug 2959: remove SAMBAPREFIX dependency - Bug 2868: icc doesn't like string literal in assert checks - HTTP/1.1: Send 307 status on deny_info redirection - HTTP/1.1: Support POST/PUT with no body - HTTP/1.1: Allow persistent connections for Mozilla/3.0 User-Agents - Support RFC 5861 Cache-Control: stale-if-error option - Add ftp_eprt directive to disable EPRT extensions in FTP - Fix external_acl_type grace=0 to obey TTL - Fix IP/FQDN cache accounting to avoid idle caches on busy servers - Prevent pipeline_prefetch misconfigurations breaking NTLM/Negotiate auth - ... and some documentation updates and corrections - ... and some portability and stability fixes ------------------------------------------------------------------- Tue Jan 4 11:49:40 UTC 2011 - chris@computersalat.de - update to 3.1.10 - Bug 3121: memory leak in DigestAuth: AuthUser object is locked twice - Bug 3113: Consuming too much memory when uploading files - Bug 3110: 'reply_body_max_size none' does not work with x-forwarded-for - Bug 3096: Consuming too much memory when delaying traffic - Bug 3091: Bypassed ICAP errors are not counted as service failures - Bug 3090: Polish FTP login error handing - Bug 3068: cache_dir capacity and usage overflows - Bug 3028: Permit wbinfo_group.pl to authenticate Kerberos users with NT domain - Bug 427: HTTP Compliance: Support If-Match and If-None-Match requests - Fix memory leak in adaptation_access - Fix /dev/poll and poll() selection priority - Fix PREFIX/var/run creation during install - Fix cachemgr http_port config report display - Add upgrade help process for obsolete options - Accept RFC 2965 Set-Cookie2 / Cookie2 headers as 'known' - HTTP/1.1: entry is stale if request has max-age=0 - HTTP/1.1: do not forward TRACE with Max-Forwards: 0 after REQMOD - Toolchain update to support newer auto-tools - ... and updated error page translations - ... and updated documentation - ... and some code optimization/simplification polish - reworked swapdir patch ------------------------------------------------------------------- Fri Oct 29 23:57:39 UTC 2010 - chris@computersalat.de - update to 3.1.9 - Bug 3088: dnsserver is segfaulting - Bug 3084: IPv6 without Host: header in request causes connection to hang - Bug 3082: Typo in error message - Bug 3073: tunnelStateFree memory leak of host member - Bug 3058: errorSend and ICY leak MemBuf object - Bug 3057: 64-bit Solaris 9 Squid unable to determine peer IP and port - Bug 3056: comm.cc "!fd_table[fd].closing()" assertion crash when a helper dies - Bug 3053: cache version 1 LFS support detection broken - Bug 3051: integer display overflow - Bug 3040: Lower-case domain entries from hosts and resolv.conf files - Bug 3036: adaptation_access acls cannot see myportname - Bug 3023: url_rewrite_program silently fails to rewrite on broken URLs - Bug 2964: Prevent memory leaks when ICAP transactions fail - Bug 2808: getRoundRobinParent not handling weights correctly - Bug 2793: memory statistics sometimes display wrong - Bug 2356: Port from 2.7: Solaris /dev/poll event ports support - Bug 2311: crashes with ICAP RESPMOD for HTTP body size greater than 100kb - Ensure /var/cache or jail equivalent exists on install - HTTP/1.1: delete Warnings that have warning-date different from Date - HTTP/1.1: do not remove ETag header from partial responses - HTTP/1.1: make date parser stricter to better handle malformed Expires - HTTP/1.1: improve age calculation - HTTP/1.1: reply with a 504 error if required validation fails - HTTP/1.1: add appropriate Warnings if serving a stale hit - HTTP/1.1: support requests with Cache-Control: min-fresh - HTTP/1.1: do not cache replies to requests with Cache-Control: no-store - squidclient: Display IP(s) connected to in verbose (-v) display - Fixes several issues with ICAP persistent connections - Fixes small leaks in Netdb, DNS, ICAP, ICY, HTTPS - ... and some cosmetic polishing - removed obsolete patches o squid-beta-3.0-ia64 (upstream) o squid-beta-3.0-mem_node_64bit (not needed, Amos) o squid-3.1.4-openldap (not needed, Amos) - reworked swapdir patch o send upstream ------------------------------------------------------------------- Sun Sep 5 18:49:46 UTC 2010 - chris@computersalat.de - update to 3.1.8 - Bug 3033: incorrect information regarding TOS - Bug 3020: Segmentation fault: nameservers[vc->ns].vc = NULL - Bug 3005,2972: Locate LTDL headers correctly (again) - Bug 2872: leaking file descriptors - Bug 2583: pure virtual method called - Hardened DNS client against packet queue attacks - Hardened HTTP request-line parser - Several HTTP/1.1 support improvements - Improved cross-compile support - .. and several internal pointer safety fixes - remove obsolete patches o bug2972-real-fix.patch o squid-bootstrap.patch ------------------------------------------------------------------- Tue Aug 31 13:43:26 UTC 2010 - chris@computersalat.de - added bug2972-real-fix.patch o fix build for SLE_10 o but impossible to apply LDAP patch ------------------------------------------------------------------- Wed Aug 25 09:46:36 UTC 2010 - chris@computersalat.de - update to 3.1.7 - Regression Bug 3021: Large DNS reply causes crash - Regression Bug 3011: ICAP, HTTPS, cache_peer probe IPv4-only port fixes - Regression Bug 2997: visible_hostname directive no longer matches docs - Bug 3012: deprecate sslBump and support ssl-bump spelling in http_port - Bug 3006: handle IPV6_V6ONLY definition missing - Bug 3004: Solaris 9 SunStudio 12 build failure - Bug 3003: inconsistent concepts in documentation of cache_dir - Bug 3001: dnsserver link issues - HTTP/1.1: default keep-alive for 1.1 clients (bug 3016) - HTTP/1.1: Improved Range header field validation - HTTP/1.1: Forward multiple unknown Cache-Control directives - HTTP/1.1: Stop sending Proxy-Connection header - Fix 32-bit wrap in refresh_pattern min/max values - ... and several documentation corrections. ------------------------------------------------------------------- Tue Aug 10 11:07:29 UTC 2010 - chris@computersalat.de - update to 3.1.6 - Bug 2994, 2995: IPv4-only regressions - Bug 2991: Wrong parameters to fcntl() in commSetCloseOnExec() - Bug 2975: chunked requests not supported after regular ones - Fix: 32-bit overflow in reported bytes received from next hop - Fix Libtool build regressions - Limited split-stack IPv6 support. - squid_db_auth support MD5 encrypted passwords ------------------------------------------------------------------- Sun Jul 25 16:16:47 UTC 2010 - chris@computersalat.de - update to 3.1.5 - Bug 2967: raw-IPv6 address URL with append_domain broken - Bug 2950: HTTP responses with no Date, L-M or Expires can now be cached - Bug 2943: ICAP tokens not logged when using multiple access - Bug 2937: Fails to detect chunked encoding if not given in all lower case - Bug 2903: does not send indirect X-Client-Ip in ICAP respmod - Fix free memory corruption and off-by-one error when comparing SNMP OIDs - Port from 2.7: max_filedescriptor config option - Fix persistent_connection_after_error is meant to be on by default - ... and several build errors. ------------------------------------------------------------------- Wed Jun 9 11:51:33 UTC 2010 - chris@computersalat.de - fix build for SLE_10 o added bootstrap patch o fix permissions.secure for pam_auth - spec mods o build with --mandir o add BuildReq libcap-devel (TPROXY) ------------------------------------------------------------------- Tue Jun 8 20:54:20 UTC 2010 - chris@computersalat.de - new version 3.1.4 - Bug 2933: Verification of the max. port number for WCCP2 dynamic service - Bug 2924: RADIUS helper compile issues - Bug 2922: Fix assertion failed: HttpHeader.cc: "Headers[id].stat.aliveCount" - Bug 2919: tcp_outgoing_address ACLs not obeying acl_uses_indirect_client - Bug 2896: Fix assertion failed: comm.cc:2063: "!fd_table[fd].closing()" - Bug 2879: pt2: 3.0 regression in headers end finding - Bug 2877: pt2: only output zero-size warning on reverse-proxy requests - Bug 2876: FD_SETSIZE override not working on all linux distributions - Bug 2810: common log format generates 2 lines of syslog - Bug 2789: Optimize unlimited memory pools, and correctly handle limits over 2GB - Bug 2753: Fall back on IPv4 if IPv6 is not present - Bug 2697: Adaptation leaks and extra requests after reconfiguration - Bug 2633: Fix Ecap::HeaderRep::value(name) fails when there is no named header field - Change LDAP helpers to default to LDAP version 3 if available - Add Joomla and Salted Hash support to squid_db_auth helper - Fixed IpAddress port printing for ports higher than 9999 - Disable chunked memory pooling by default. - ... and several build errors. - reworked config patch with fuzz=0 - removed libxml2 patch - added swapdir patch - reworked ldap patch - adopt build_option storeio: (build all) o --enable-storeio=aufs,diskd,null,ufs -> --enable-storeio - adopt build_option ntlm-auth-helpers: SMB -> smb_lm o ntlm_auth -> ntlm_smb_lm_auth - enable parallel build - fix permissions file ------------------------------------------------------------------- Tue Mar 16 22:18:08 UTC 2010 - chris@computersalat.de - new version 3.0.STABLE25 - Bug 2845: Rework the http digest auth parser - Bug 2787: unknown/unexpected status code messages - Bug 2507: squid_ldap_group: Strip Domain name separated by + - Bug 2367: stale=true on digest requests with unknown nonce - ... and several other minor corrections ------------------------------------------------------------------- Tue Feb 16 09:33:33 UTC 2010 - chris@computersalat.de - new version 3.0.STABLE24 * Bug 2858: Segment violation in HTCP * Updated refresh pattern for dynamic pages - version 3.0.STABLE23 * Bug 2856: removing assert() required for 3.0 patch for SQUID-2010:1 * Regression Fix: Build error in Kerberos helper after library removal. - version 3.0.STABLE22 * Regression Fix: Make Squid abort on all config parse failures. * Bug 2787: Reduce unexpected http status to non-critical warnings. * Bug 2496: Downloading some variants in full before relaying * Bug 2452: Add upper limit to external_acl_type entries. * Removed optional kerberos/spnegohelp/ library due to licensing issues * Add client_ip_max_connections * Handle DNS header-only packets as invalid. - version 3.0.STABLE21 * Bug 2830: Clarify where NULL byte is in headers. * Bug 2778: Linking issues using SunCC * Bug 2395: FTP errors not displayed * Bug 2155: Assertion failures on malformed Content-Range response headers * Fix parsing and a few bugs in ACL time type * Fix RFC keep-alive compliance on intercepted replies * Improved security hardening on %nn parser * Replace several GCC-specific code snippets. ------------------------------------------------------------------- Mon Nov 9 20:40:30 UTC 2009 - chris@computersalat.de - new version 3.0.STABLE20 * Bug 2794: ESI parsing on FreeBSD * Bug 2791: assertion failed: MemBuf.cc:400: new_cap > (size_t) capacity * Bug 2779: Support GNU/kFreeBSD * Bug 2773: Segfault in RFC2069 Digest authantication * Bug 2768: squid_ldap_group argument parsing error * Bug 2761: Gopher and double HTTP response header * Bug 2735: Incomplete -fhuge-objects detection * Bug 2722: prevent CONNECT via http_port with accel * Bug 2624: Invalid response for IMS request * Bug 2510: digest_ldap_auth TLS support * Correct LINUX_CAPABILITY actions on non-Linux - removed old upstream patches o squid-3.0-9107.patch - squid-3.0-9124.patch ------------------------------------------------------------------- Wed Oct 7 23:58:37 CEST 2009 - chris@computersalat.de - added upstream patches o squid-3.0-9107.patch - squid-3.0-9124.patch ------------------------------------------------------------------- Mon Sep 14 13:37:55 UTC 2009 - chris@computersalat.de - new version 3.0.STABLE19 * Bug 2745: Invalid Response error on small reads * Bug 2739: DNS resolver option ndots can't be parsed from resolv.conf * Bug 2734: some compile errors on Solaris * Bug 2648: stateful helpers stuck in reserved if client disconnects while helper busy * Bug 2541: Hang in 100% CPU loop while extacting header details using a delimiter other than comma * Bug 2362: Remove support for deferred state in stateful helpers * Add 0.0.0.0 as a to_localhost address * Docs: Improve chroot directive documentation slightly * Fixup libxml2 include magics, was failing when a configure cache was used * ... and some minor testing improvements. - spec mods o adding group winbind, add squid to group winbind when using squid with samba-winbind for ntlm_auth squid needs read access to /var/lib/samba/winbindd_privileged group winbind is added if squid is installed before winbind ;) ------------------------------------------------------------------- Sat Sep 5 20:21:53 CEST 2009 - chris@computersalat.de - added upstream patches o b9097 - b9103 - rpmlint o added fdupes ------------------------------------------------------------------- Wed Sep 2 13:15:45 UTC 2009 - chris@computersalat.de - cleanup spec o removed #-------- ------------------------------------------------------------------- Tue Sep 1 10:04:02 CEST 2009 - coolo@novell.com - remove outdated patches ------------------------------------------------------------------- Mon Aug 31 10:30:54 CEST 2009 - coolo@novell.com - merge factory changes with buildservice ------------------------------------------------------------------- Sun Aug 30 20:03:46 UTC 2009 - aj@suse.de - Fix patch numbering for rpm 4.7. ------------------------------------------------------------------- Wed Aug 26 12:53:54 CEST 2009 - mls@suse.de - make patch0 usage consistent ------------------------------------------------------------------- Fri Aug 21 13:27:52 UTC 2009 - chris@computersalat.de - added upstream patches o b9095, b9096 ------------------------------------------------------------------- Sat Aug 15 16:26:30 CEST 2009 - chris@computersalat.de - added upstream patches o b9089 - b9094 o disabled b9089,b9090,b9092 cause can not patch inexistent file ------------------------------------------------------------------- Tue Aug 11 11:10:13 UTC 2009 - chris@computersalat.de - new version 3.0.STABLE18: * Bug 2728: regression: assertion failed: !eof * Bug 2732: reply_body_max_size smaller than error page loops infinitely until out of memory * Bug 2725: pconn failure if domain or client_address are unset * Bug 2648: reserved helpers not shut down after reconfigure/rotate * Bug 2462: make check should tell when cppunit is missing * Remove excess messages about headers < minimum size * Support Libtool 2.2.6 - Changes to squid-3.0.STABLE17 (27 Jul 2009): * Bug 2680 regression: Crash after rotate with no helpers running * Bug 2710: squid_kerb_auth non-terminated string * Bug 2679: strsep and strtoll detection failure * Bug 2674: Remove limit on HTTP headers read. * Bug 2659: String length overflows on append, leading to segfaults * Bug 2620: Invalid HTTP response codes causes segfault * Bug 2080: wbinfo_group.pl - false positive under certain conditions * Bug 1087: ESI processor not quoting attributes correctly. * Fix: issue with AUFS/UFS/DiskD writing objects to disk cache * Several small build issues with previous release. for full changes list, see: http://www.squid-cache.org/Versions/v3/3.0/squid-3.0.STABLE18-RELEASENOTES.html - removed squid-3.0.STABLE16-gcc_warn_kerb_auth.patch - removed changed, deprectated configure options o deprecated: --enable-poll o changed to default: --enable-htcp --enable-snmp ------------------------------------------------------------------- Sat Jul 25 19:27:34 CEST 2009 - chris@computersalat.de - spec mods * removed ^---------- * removed ^#--------- ------------------------------------------------------------------- Thu Jul 23 18:22:09 CEST 2009 - chris@computersalat.de - new version 3.0.STABLE16: * Bug 2672: cacheMemMaxSize 32-bit overflow during snmpwalk * Bug 2481: Don't set expires: now in generated error responses * Bug 2387: The calculation of the number of hash buckets correctly * Fix infinite loop in MSNT auth helper * Fix FD_SETSIZE on FreeBSD * Fix stripping NT domain in squid_ldap_group * Fix RADIUS auth helper build * Add Translate: and Unless-Modified-Since: headers to known list * Make fakeauth handle NTLMv2 better * Better Kerberos support detection * Several Widows port fixes - Changes to squid-3.0.STABLE16-RC1 (16 May 2009): * Bug 1148: Ported from 3.1: Chunked Transfer Encoding * Bug 2648: NTLM helpers not shutting down when deferred - Changes to squid-3.0.STABLE15 (06 May 2009): * Regression Bug 2635: Incorrect Max-Forwards header type * Bug 2652: 'Success' error on CONNECT requests * Bug 2625: IDENT receiving errors * Bug 2610: ipfilter support detection * Bug 2578: FTP download resume failure * Bug 2536: %H on HTTPS error pages * Bug 2491: assertion "age >= 0" * Bug 2276: too many NTLM helpers running * Endian system and compiler fixes provided by the NetBSD project * documentation fixes provided by the Debian project - Changes to squid-3.0.STABLE14 (11 Apr 2009): * Regression Fix: HTTP/0.9 in accelerator mode * Bug 1232: cache_dir parameter limited to only 63 entries * Bug 1868: support HTTP 207 status * Bug 2518: assertion failure on restart/reconfigure * Bug 2588: coredump in rDNS lookup * Bug 2595: Out of bounds memory write in squid_kerb_auth * Bug 2599: Idempotent start * Bug 2605: Prevent setsid() on helpers in daemon mode * Fix external_acl_type option parsing * Fix delay pools counters on FTP * Fix several issues with ident (some remain) * Fix performance issues with persistent connections * Fix performance issues with delay pools * Fix forwarding of OPTIONS requests * Add support for HTTP 1.1 Content-Disposition header * Add support for Windows 7, Windows Server 2008 R2 and later * ... and many small documentation updates for full changes list, see: http://www.squid-cache.org/Versions/v3/3.0/squid-3.0.STABLE16-RELEASENOTES.html - reworked gcc_warn_kerb_auth * was partially added - added after RELEASE patches * b9052 - b9067 for full changes list, see: http://www.squid-cache.org/Versions/v3/3.0/changesets/SQUID_3_0_STABLE16.html - some spec mods * removed {rel} ------------------------------------------------------------------- Wed Jun 10 16:54:49 CEST 2009 - ro@suse.de - strchr returns a const char* now, work around ------------------------------------------------------------------- Sun May 3 15:34:27 CEST 2009 - chris@computersalat.de - some spec fixes ------------------------------------------------------------------- Thu Feb 19 19:53:26 UTC 2009 - chris@computersalat.de - new version 3.0.STABLE13: * following patches removed from build * b8898.patch * b8900.patch * b8902.patch * b8904.patch * b8905.patch * b8906.patch * b8907.patch - some rpmlint fixes ------------------------------------------------------------------- Wed Feb 18 12:37:05 UTC 2009 - chris@computersalat.de - fixed failing fillup - fixed expansion error for SLES_9 - added KRB5_KTNAME to sysconfig file mods to init script - added README.kerberos ------------------------------------------------------------------- Wed Jan 28 16:40:00 CET 2009 - kssingvo@suse.de - update to squid-3.0.STABLE13 with these fixes: * ICAP filters break download resume * HTCP fails without icp_port * logformat '%tl' field not working as advertised * Policy: Change half_closed_clients default to off * Policy: Removed -V command line option, deprecated by 2.6 * filedescriptors being left unnecessary opened * fault passing ICAP filtered traffic to peers * Sefgaults in MemBuf::reset during idnsSendQuery * bad default in ACLChecklist * access.log request size tag * cache_peer forceddomainname=X option ... and few minor ones. For complete list see: http://www.squid-cache.org/Versions/v3/3.0/changesets/SQUID_3_0_STABLE12.html ------------------------------------------------------------------- Thu Nov 6 15:59:17 CET 2008 - kssingvo@suse.de - reworked on sysconfig files (bnc#439006) ------------------------------------------------------------------- Mon Oct 27 16:48:56 CET 2008 - kssingvo@suse.de - update to squid-3.0.STABLE10, fixes mainly: bad assert in forwarding Segfault on failed TCP DNS query DNS requests getting stuck in idns queue FTP PUT gives bad gateway ... and few minor ones. For complete list see: http://www.squid-cache.org/Versions/v3/3.0/changesets/SQUID_3_0_STABLE10.html - removed old patches, which were included upstream now - renamed sysconfig.squid to sysconfig.squid3 (bnc#439006) ------------------------------------------------------------------- Mon Oct 13 14:52:39 CEST 2008 - kssingvo@suse.de - reenabled linux-netfilter in configure as seems to work now again ------------------------------------------------------------------- Thu Oct 2 14:36:14 CEST 2008 - kssingvo@suse.de - added official patches: * assertion fix in forward.cc * bad links in ./configure due to website changes * define DEFAULT_CACHEMGR_CONFIG before its first use * don't strcmp Config.Log.store if it's NULL in storeLogOpen * workaround: When dns_error_message value is lost * ftp put gives bad gateway but put is correct * fix of a compilation error ------------------------------------------------------------------- Wed Sep 10 12:40:46 CEST 2008 - kssingvo@suse.de - new version 3.0.STABLE9: * Correct HTCP stats * fix: mgr:active_requests always returns "delay_pool 0" * fix: 3.0 must still wrap CARP properly * Improve display on fd debug output * Correct ICAP notes: *_postcache vector points not coded * fix: squid_ldap_group -h reports the old % codes for -f * Fix: Unsupported method in request may show raw binary data in log * Fix: cppunit tests broken by squid.h defines * fix: no_check.pl ntlm helper never sends challenge * Increase buffer in authenticateNegotiateStart / squid_kerb_auth * peer name not logged in access.log like expected, instead the ip address is logged * Fixed typo in squid.h which would prevent leak checking for arrays * COSS removal from 3.0 * Use safe functions in basic auth MSNT helper for full changes list, see: http://www.squid-cache.org/Versions/v3/3.0/changesets/SQUID_3_0_STABLE8.html - removed coss as disk storage method, as it became unstable now ------------------------------------------------------------------- Wed Aug 20 12:29:36 CEST 2008 - kssingvo@suse.de - fixed configure option: * change from "with-large-files" to "enable-large-files" * removed netfilters (kernel 2.4) option - fixed init script - added sysconfig as in squid ------------------------------------------------------------------- Tue Jul 22 16:08:26 CEST 2008 - kssingvo@suse.de - new version 3.0.STABLE8: * Support for cachemgr sub-actions * userhash peer selection method * sourcehash peer selection method * round-robin balancing fixes * acl documentation cleanup * cachemgr.cgi HTML output encoding * Regression: Log format size options * Correct the opening of PF device file. * ICAP accept mechanism * Regression: fakeauth_auth crashes * Boost error pages HTML standards. * Fixes several issues on 64-bit systems * Fixes several issues on older or stricter compilers * Linux-2.6.24/2.6.25 netfilter_ipv4.h __u32 workaround * Update Release Notes: 'all' ACL is built-in since 3.0.STABLE1 for full changes list, see: http://www.squid-cache.org/Versions/v3/3.0/changesets/SQUID_3_0_STABLE8.html - removed unneccesary compiler warning patch - added new patch for warnings in kerberos auth ------------------------------------------------------------------- Wed Jul 2 16:13:35 CEST 2008 - kssingvo@suse.de - update to version 3.0.STABLE7, which is mainly a bugfix version only: * important fix for ASN.1 DoS (no CVE) * spelling corrections * assertion on ESI page * in snmp reporting * (extra) whitespaces in logfile * added note that negative_ttl is a HTTP violation * Memory allocation problem in restoreCapabilities(), tools.cc * etc. for full change list see: http://www.squid-cache.org/Versions/v3/3.0/changesets/SQUID_3_0_STABLE7.html ------------------------------------------------------------------- Wed May 21 17:39:14 CEST 2008 - kssingvo@suse.de - update to version 3.0.STABLE5, which is mainly a bugfix version only: * fix in parsing cachemgr.conf * segfault in tunnelConnectTimeout() * segfault in MemBuf::append() * basic auth leaks memory * access_log syslog results in blanks syslog lines * umask support with porting from 2.6 * segfault in AuthDigestUserRequest::authUser * ntlm_auth helper resolves DC hostname to 0 ... and some minor bugfixes more - added cachemngr.conf.default to files ------------------------------------------------------------------- Mon May 19 19:39:48 CEST 2008 - kssingvo@suse.de - added "sharedscripts" to logrotate (bnc#388088) ------------------------------------------------------------------- Fri May 9 15:36:15 CEST 2008 - schwab@suse.de - Use autoreconf. ------------------------------------------------------------------- Tue Apr 29 17:39:40 CEST 2008 - kssingvo@suse.de - update to version 3.0.STABLE5, which is mainly a bugfix version only: * Bypassing 403 and 404 status to ICAP using icap_access - Failed * file uploads (RFC1867) fail with "error:double-CR" * Range tests failing. * crashes/restarts when ICAP enabled on respmod for HTTP body size greater than 100kb * Support for resolv.conf 'domain' option * Fix for incorrect default time/date log format * Fix: reentrant debugging crashes Squid * better handling of intercepted URI * better port for non-FQDN URI lookups * Improved logging, including incorrect timestamp format in earlier 3.0 releases * Support for profiling on x86 64-bit systems - removed upstream patches, which are now included in source tarball - removed own compiler warning patch (now upstream) ------------------------------------------------------------------- Thu Apr 17 12:07:17 CEST 2008 - kssingvo@suse.de - added official patches: * increase MAX_URL to 8192 * Honor 0x and 0 prefixes as numeric base indication when parsing squid.conf integer options. * Correct and simplify parsing of list headers * Fix processing of large reply headers * Removed execute bit from various non-executable source files * assertion failed: HttpHdrContRange.cc:100: "spec->length >= 0" * Fallback on transparent interception mode even if the connection didn't seem to be transparently intercepted * fix pt 2: DIRECT/<ip> mixed with DIRECT/ * Fallout from build-testing the new backports. - fixed a compiler warning, which got treated as an error ------------------------------------------------------------------- Mon Apr 7 18:46:46 CEST 2008 - kssingvo@suse.de - fix for unpackaged non-man pages (SLE9, SLE10 build failures) ------------------------------------------------------------------- Mon Apr 7 18:26:43 CEST 2008 - kssingvo@suse.de - update to version 3.0.STABLE2: * improved HTTP 1.1 support * Proxy-Authentication regression * Strip Domain from NTLM usernames for use in class 4 Delay Pools * compile error slipped into STABLE3 * ... and as usual Many bug fixes since STABLE 2. Please, have a look into included ChangeLog file for details. ------------------------------------------------------------------- Tue Mar 18 16:11:37 CET 2008 - kssingvo@suse.de - update to version 3.0.STABLE2: * Add myportname ACL for matching the accepting port name (see release notes) * Add include directive for squid.conf (see release notes) * Add ability to strip kerberos realm from usernames during Auth * License cleanup to comply with GPLv2 or later * Updated Error Pages and Translations * Updated configuration examples * Updated valgrind support for valgrind-3.3.0 * Improved support for Windows and MacOS X Leopard * Improved support for files larger than 2GB * Improved support for CARP arrays and WCCPv2 * Improved cachmgr, SNMP, and log reporting * ... and as usual Many bug fixes since STABLE 1 - removed unnecessary, official patches for STABLE1 ------------------------------------------------------------------- Wed Mar 12 13:39:43 CET 2008 - kssingvo@suse.de - added many official patches: * Squid Bugzilla #2250: double-freeing memory in http_port name= option code. * Optimisation cleanup of fake_auth * Fix Castings slipped out of back-ported patches from 3.1. * Update errors/list to match the actual list of error pages used * Added a CPPUNIT assertion to test whether a failed CPPUNIT test case properly * Several String fixes. * The connect(2) system call might return "connection ready" * Sort cache list in wccpv2 to ensure a consistent hash allocation across all serv * Squid Bugzilla #1978: fwdServerClose retries non-idempotent methods * Squid Bugzilla #2172: When user fails authentification Squid restarts * Squid Bugzilla #2186: NONE/- due to persistent connections * Squid Bugzilla #2189 fix: when dumping SNMP oids, do not overrun the result buffer. * Assert that checklist and request are set instead of segfaulting as in bug 2168 * Squid Bugzilla #1923 fix: Do not send hop-by-hop headers to the ICAP server. * Squid Bugzilla #1933 fix: Fixed memory pools configuration reporting. * Squid Bugzilla #2110 fix: When Squid is shutting down, disable persistent connections * Squid Bugzilla #2153: Use the cache_peer name in CARP hashing to support multiple peers on the same host * Add check for glob() and glob.h availability * make include support wildcards, and document the directive (copied from squid-2) * Use our own strwordtok instead of strtok_r. Not only is it portable, but also understands quoting and escaping * Squid Bugzilla #2180 (update) - include minor issues * include directive for squid.conf * More off_t related cleanups triggered by Squid Bugzilla #2164. * Squid Bugzilla #2164: assertion failed: stmem.cc:321: "candidate.offset >= 0" * Squid Bugzilla #2150: Connection hangs on automatic retry * Squid Bugzilla #2175: Update valgrind support for valgrind-3.3.0 * Random authenticaiton failures when using Digest authentication * digest auth related memory corruption * Allow informal errors on stderr when using -k parse * Squid Bugzilla #2063: Hide debugging messages before cache.log is opened * Squid Bugzilla #2018: dead_peer_timeout fails to declare peer dead * Squid Bugzilla #2114: cache memory accounting not working well * Fix some minor casting errors affecting cachemgr reporting when cache/mem >2GB * Squid Bugzilla #2231: Compile error in squid_kerb_auth under Mac OS X 10.5.2 * Squid Bugzilla #2101: Reuse pconns using LIFO * Squid Bugzilla #2159: WCCPv2 assertion failure on Mask assignment * Kill unused body_size variable * Kill obsolete phttpd/0.99.72 malformed HEAD response workaround. * License cleanup to comply with GPLv2 or later. * Sync store meta assignments with Squid-2. * Don't be so verbose about not yet implemented store meta data types * Accept some unknown store meta entries without throwing away the rest. * Patch to strip kerberos realm from username * Clean up of deferred reads and delay pools was not applied to comm_select_win32.cc * Fix missing default disk store type into QUICKSTART example. * Alter caching policy for Dynamic Objects. * Squid Bugzilla #2166 - Error compiling on Mac OS X 10.5 Leopard * Correct example IPs in tcp_outgoing_address config * Squid Bugzilla #2189 - wrong parameters used for memset - removed our patches, which are upstream included now - worked on BuildRequires: ------------------------------------------------------------------- Tue Jan 15 15:04:06 CET 2008 - kssingvo@suse.de - update to version 3.0.STABLE1: * Updated changelog for 3.0.STABLE1 release * MFC * Name the upcoming release 3.0.STABLE1 MFC * Remove references to myself and NLANR, add pointer to COPYRIGHT file * Change old info@ircache.net contact address to info@squid-cache.org * Fixed more compile errors after removal of snprintf.h * Fix compile errors after removal of snprintf.h * Removed the following debugging line, numerous copies of which used to appear * Set default formatting flags for the debugging stream to "fixed" with a * Delete now unused snprintf.h header file * removed lib/snprintf.c credits as it's no longer shipped with Squid * Kill GPL-incompatible (Apache) lib/snprintf.c source. * assertion failed: comm.cc:116: "ccb->active == false" * squid.conf, others overwrite -X * Wrap equation argument to debugs() properly. * Correct attribution of current MD5 changes. * Fix typo added during some patch. * Fix SegFault when NetDB asked to ping a zero-length domain/hostname * allow pending cache hits when delay pools not compiled in pack header entries on cache updates * Update to Squid MD5 syntax * Correct update of 304 headers * Make squid_db_auth reopen the database connection on each query by default * Updated MD5 credits (no longer RSA). Removed winbind credits (no longer shipped with Squid) * Drop the RSA licensed MD5 implementation, and use the one shipped with Squid instead * Change priority of proxy auth and extacl provided username in login=*:pass * Declare Squid 3 Windows support NOT STABLE. * Fix build failure caused by a typo. * Renamed "SQUID_ESI" to "USE_SQUID_ESI" at request of other developers * Change 'ESI' define to 'SQUID_ESI' * More fixes for recent MD5 mixups * Fix-fix for MD5. * fix GCC 4.3 warnings, part 1 * operator != declared outside of the HttpRequestMethod class results in * Returning -1 in the unreached portion of u_short GetService() code results in * partial fix: Allocate space for a NULL terminator of the helper * RFC 1157 - SNMP v1 Protocol is used by squid. * Enable squid to lookup /etc/services for named peer ports. * Re-fix libmd5 detection on configure * Solaris 10 appears to provide MD5 natively * Add some include-protection to IPInterception.cc * Extended the Squid -> Rewriter interface with key=value pairs * Close three possible buffer over/under-runs * Looks like 'dstdomain' and 'dstdomain_regex' ACLs were broken. * Spelling. * Code cleanup. * NetBIOS is now officially obsolete. * fix: Better handling of HTTP 206 Partial Content responses. * Added debugging while investigating * RFC bits omitted earlier. * RFC 3162 - updated RADIUS authentication protocol * Policy Change: Make all ACL a predefined default. * Add RFC 1902, 1905 - SNMP Protocols used by squid. * Close several unsafe control paths after fatalf() * Close several unsafe control paths after self_destruct() * fix: handle REQMOD HTTP responses without body * fix: SegFault in tunnelConnectTimeout error page generation. * Need to read clearer. We agreed on allow localnet->deny all. * Alter policy of ICP and HTCP access to default allow only local networks * autoconf 2.61 works. * Add notes about htcp_access effects on HTCP peers to config. * Update udp_(incoming|outgoing)_address option docs to reflect current state. * Respect DNS ttl=0 * Digest delays are no longer bound to any fixed unit of time. * digest_generation docs should reference compile option not internal macro. * 3.0RC1: Add stub ERR_ESI and ERR_ICAP_FAILURE documents to errors/Armenian * Likely fix for helper-related SEGV shortly after reconfigure * automake 1.10 also works.. * More >2GB fixes. BodyPipe::unproducedSize() method should also return an uint64_t - squid3 now obsoletes squid (= squid2) - renamed patches, removed unused patches - removed obsolete use of suse 8.0 version requirement - changed X-UnitedLinux-Should-XXX to Should-XXX in init script ------------------------------------------------------------------- Wed Dec 12 18:25:27 CET 2007 - kssingvo@suse.de - BuildRequires doesn't need openldap2 anymore. fixed. ------------------------------------------------------------------- Thu Nov 29 11:10:33 CET 2007 - kssingvo@suse.de - removed gcc-4.3 patch, now in upstream - added many upstream patches: * Fix typo added during some patch. * Fix SegFault when NetDB asked to ping a zero-length domain/hostname * Bug #2096: allow pending cache hits when delay pools not compiled in * pack header entries on cache updates * Update to Squid MD5 syntax * Correct update of 304 headers * Make squid_db_auth reopen the database connection on each query by default * Updated MD5 credits (no longer RSA). Removed winbind credits (no longer shipped with Squid) * Drop the RSA licensed MD5 implementation, and use the one shipped with Squid instead * Change priority of proxy auth and extacl provided username in login=*:pass * Declare Squid 3 Windows support NOT STABLE. * Fix build failure caused by a typo. * Renamed "SQUID_ESI" to "USE_SQUID_ESI" at request of other developers * Change 'ESI' define to 'SQUID_ESI' * More fixes for recent MD5 mixups * Fix-fix for MD5. * Bug #2123 fix, part 1: GCC 4.3 warnings * operator != declared outside of the HttpRequestMethod class results in * Returning -1 in the unreached portion of u_short GetService() code results in * Bug #2123 partial fix: Allocate space for a NULL terminator of the helper * RFC 1157 - SNMP v1 Protocol is used by squid. * Enable squid to lookup /etc/services for named peer ports. * Re-fix libmd5 detection on configure * Solaris 10 appears to provide MD5 natively * Add some include-protection to IPInterception.cc * Extended the Squid -> Rewriter interface with key=value pairs * Close three possible buffer over/under-runs * Looks like 'dstdomain' and 'dstdomain_regex' ACLs were broken. * Spelling. * Code cleanup. * NetBIOS is now officially obsolete. * Bug #2116 fix: Better handling of HTTP 206 Partial Content responses. * Added debugging while investigating bug #2116. * RFC bits omitted earlier. * RFC 3162 - updated RADIUS authentication protocol * Policy Change: Make all ACL a predefined default. * Add RFC 1902, 1905 - SNMP Protocols used by squid. * Close several unsafe control paths after fatalf() * Close several unsafe control paths after self_destruct() * Author:Rafael Martinez <rmartine@fdi.ucm.es> * Author: Rafael Martinez <rmartine@fdi.ucm.es> * Bug #2104 fix: handle REQMOD HTTP responses without body * Bug #2098 fix: SegFault in tunnelConnectTimeout error page generation. * Need to read clearer. We agreed on allow localnet->deny all. * Alter policy of ICP and HTCP access to default allow only local networks * autoconf 2.61 works. * Add notes about htcp_access effects on HTCP peers to config. * Update udp_(incoming|outgoing)_address option docs to reflect current state. * Bug #2100: Respect DNS ttl=0 * Digest delays are no longer bound to any fixed unit of time. * digest_generation docs should reference compile option not internal macro. * Bug #2094: 3.0RC1: Add stub ERR_ESI and ERR_ICAP_FAILURE documents to errors/Armenian * Likely fix for helper-related SEGV shortly after reconfigure * automake 1.10 also works.. * More >2GB fixes. BodyPipe::unproducedSize() method should also return an uint64_t ------------------------------------------------------------------- Tue Nov 20 12:30:45 CET 2007 - kssingvo@suse.de - added "squid-beta" to Conflicts: section - removed unneeded snprintf.c due to license issue (bugzilla#341246) - replace md5.c and md5.h by GPL version (bugzilla#341246) ------------------------------------------------------------------- Tue Nov 13 11:42:02 CET 2007 - kssingvo@suse.de - fixed gcc-4.3 "-Wall -Werror" issues ------------------------------------------------------------------- Thu Nov 8 10:00:27 CET 2007 - kssingvo@suse.de - initial try with RC1, based on squid-beta
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor