Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

lighttpd-mod_cml-1.4.20-3.7.1 RPM for i586

From OpenSuSE 11.2 updates for i586

Name: lighttpd-mod_cml Distribution: openSUSE 11.2
Version: 1.4.20 Vendor: openSUSE
Release: 3.7.1 Build date: Wed Feb 3 17:43:12 2010
Group: Productivity/Networking/Web/Servers Build host: build20
Size: 29788 Source RPM: lighttpd-1.4.20-3.7.1.src.rpm
Packager: http://bugs.opensuse.org
Url: http://www.lighttpd.net/
Summary: CML (Cache Meta Language) module for Lighttpd
CML is a Meta language to describe the dependencies of a page at one
side and building a page from its fragments on the oth er side using
LUA.

CML (Cache Meta Language) wants to solves several problems:

* dynamic content needs caching to perform

* checking if the content is dirty inside of the application is
   usually more expensive than sending out the cached data

* a dynamic page is usually fragmented and the fragments have
   different livetimes

* the different fragements can be cached independently



Authors:
--------
    Jan Kneschke <jan@kneschke.de>

Provides

Requires

License

BSD3c

Changelog

* Mon Feb 01 2010 mrueckert@suse.de
  - added fix-slow-request-dos-in-1.4.x.patch:
    fix a bug that makes lighttpd allocate too much memory
    for handling a request.  (bnc#573948) CVE-2010-0295
* Mon Nov 24 2008 mrueckert@suse.de
  - as we build inside the obs now replace the opensuse_bs
    conditional with a conditional based on _repository.
* Thu Oct 02 2008 mrueckert@suse.de
  - update to 1.4.20 (bnc#429764, bnc#374761)
    * Fix #285 again: read error after SSL_shutdown (thx
      marton.illes@balabit.com) and clear the error queue before some
      other calls (CVE-2008-1531)
    * Fix mod_magnet: enable "request.method" and "request.protocol"
      in lighty.env (#1308)
    * Fix segfault for appending matched parts if there was no regex
      matching (just give empty strings) (#1601)
    * Use data_response_init in mod_fastcgi x-sendfile handling for
      response.headers, fix a small "memleak" (#1628)
    * Don't send empty Server headers (#1620)
    * Fix conditional interpretation of core options
    * Enable escaping of % and $ in redirect/rewrite; only two cases
      changed their behaviour: "%%" => "%", "$$" => "$"
    * Fix accesslog port (should be port from the connection, not the
      "server.port") (#1618)
    * Fix mod_fastcgi prefix matching: match the prefix always
      against url, not the absolute filepath (regardless of check-local)
    * Overwrite Content-Type header in mod_dirlisting instead of
      inserting (#1614), patch by Henrik Holst
    * Handle EINTR in mod_cgi during write() (#1640)
    * Allow all http status codes by default; disable body only for
      204,205 and 304; generate error pages for 4xx and 5xx (#1639)
    * Fix mod_magnet to set con->mode = p->id if it generates
      content, so returning 4xx/5xx doesn't append an error page
    * Do not rely on PATH_MAX (POSIX does not require it) (#580)
    * Disable logging to access.log if filename is an empty string
    * Implement a clean way to open /dev/null and use it to close
      stdin/out/err in the needed places (#624)
    * merge spawn-fcgi changes from trunk (from @2191)
    * let spawn-fcgi propagate exit code from spawned fcgi application
    * close connection after redirect in trigger_b4_dl (thx icy)
    * close connection in mod_magnet if returned status code
    * fix bug with IPv6 in mod_evasive (#1579)
    * fix scgi HTTP/1.* status parsing (#1638), found by
      met@uberstats.com
    * fixed typo in mod_accesslog (#1699)
    * replaced buffer_{append,copy}_string with the _len variant
      where possible (#1732) (thx crypt)
    * case insensitive match for secdownload md5 token (#1710)
    * Handle only HEAD, GET and POST in mod_dirlisting (same as in
      staticfile) (#1687)
    * fixed mod_secdownload problem with unsigned time_t (#1688)
    * Use filedescriptor 0 for mod_scgi spawn socket, redirect STDERR
      to /dev/null (#1716)
    * fixed round-robin balancing in mod_proxy (#1715)
    * fixed EINTR handling for waitpid in mod_fastcgi
    * mod_{fast,s}cgi: overwrite environment variables (#1722)
    * inserted many con->mode checks; they should prevent two modules
      to handle the same request if they shouldn't (#631)
    * fixed url encoding to encode more characters (#266)
    * allow digits in [s]cgi env vars (#1712)
    * fixed dropping last character of evhost pattern (#161)
    * print helpful error message on conditionals in global
      block (#1550)
    * decode url before matching in mod_rewrite (#1720)
    * fixed conditional patching of ldap filter (#1564)
    * Match headers case insensitive in response (removing of
      X-{Sendfile,LIGHTTPD-*}, catching Date/Server)
    * fixed bug with case-insensitive filenames in mod_userdir
      (#1589), spotted by "anders1"
    * fixed format string bugs in mod_accesslog for SYSLOG
    * replaced fprintf with log_error_write in fastcgi debug
    * fixed mem leak in ssi expression parser (#1753), thx Take5k
    * hide some ssl errors per default, enable them with
      debug.log-ssl-noise (#397)
    * fix segfault for stat_cache(fam) calls with relative path
      (without '/', can be triggered by x-sendfile) (#1750)
    * fix splitting of auth-ldap filter
    * workaround ldap connection leak if a ldap connection failed
      (restarting ldap)
    * fix auth.backend.ldap.bind-dn/pw problems (only read from
      global context for temporary ldap reconnects, thx ruskie)
    * fix memleak in request header parsing (#1774, thx qhy)
    * fix mod_rewrite memleak/endless loop detection
      (#1775, thx phy - again!)
    * use decoded url for matching in mod_redirect (#1720)
  - removed lighttpd-1.4.x_ssl_dos.patch: included in version update
  - removed lighttpd-1.4.16_testsuite.patch:
    the path to the php-cgi binariy can now be configured with export
    of the variable PHP. adapt lightytest.sh accordingly.
  - added a logrotate script provided by Carsten Hoeger (bnc#430565)
* Fri May 16 2008 mrueckert@suse.de
  - added lighttpd-1.4.x_ssl_dos.patch: (bnc#374761)
    properly clear ssl errors before proceeding to the next connection
    (CVE-2008-1531)
* Tue Mar 11 2008 mrueckert@suse.de
  - update to 1.4.19: (bnc#366526, bnc#364517, bnc#368670)
    * added support for If-Range: <date> (#1346)
    * added support for matching $HTTP["scheme"] in configs
    * fixed initgroups() called after chroot (#1384)
    * fixed case-sensitive check for Auth-Method (#1456)
    * execute fcgi app without /bin/sh if used as argument to
      spawn-fcgi (#1428)
    * fixed a bug that made /-prefixed extensions being handled also
      when matching the end of the uri in fcgi,scgi and proxy modules
      (#1489)
    * print error if X-LIGHTTPD-send-file cannot be done; reset
      header Content-Length for send-file. Patches by Stefan Buehler
    * prevent crash in certain php-fcgi configurations (#841)
    * add IdleServers and Scoreboard directives in ?auto mode for
      mod_status (#1507)
    * open log immediately after daemonizing, fixes SIGPIPEs on
      startup  (#165)
    * HTTPS env var should be "on" when using mod_extforward and the
      X-Forwarded-Proto header is set. (#1499)
    * generate ETag and Last-Modified headers for mod_ssi based on
      newest modified include (#1491)
    * support letterhomes in mod_userdir (#1473)
    * support chained proxies in mod_extforward (#1528)
    * fixed bogus "cgi died ?" if we kill the CGI process on shutdown
    * fixed ECONNRESET handling in network-openssl
    * fixed handling of EAGAIN in network-linux-sendfile (#657)
    * reset conditional cache (#1164)
    * create directories in mod_compress (was broken with
      alias/userdir) (#1027)
    * fixed out of range access in fd array (#1562, #372)
      (CVE-2008-0983)
    * mod_compress should check if the request is already handled,
      e.g. by fastcgi (#1565)
    * remove broken workaround for buggy Opera version with
      ssl/chunked encoding (#285)
    * generate etag/last-modified header for on-the-fly-compressed
      files (#1171)
    * req-method OPTIONS: do not insert default response if request
      was denied, do not deny OPTIONS by default (#1324)
    * fixed memory leak on windows (#1347)
    * fixed building outside of the src dir (#1349)
    * fixed including of stdint.h/inttypes.h in etag.c (#1413)
    * do not add Accept-Ranges header if range-request is disabled
      (#1449)
    * log the ip of failed auth tries in error.log (enhancement
      [#1544])
    * fixed RoundRobin in mod_proxy (#516)
    * check for symlinks after successful pathinfo matching (#1574)
    * fixed mod-proxy.t to run with a builddir outside of the src dir
    * do not suppress content on "307 Temporary Redirect" (#1412)
    * fixed Content-Length header if response body gets removed in
      connections.c (#1412, part 2)
    * do not generate a "Content-Length: 0" header for HEAD requests,
      added test too
    * remove compress cache file if compression or write failed
      (#1150)
    * fixed body handling of status 300 requests
    * spawn-fcgi: only try to connect to unix socket (not tcp) before
      spawning (#1575)
    * fix sending source of cgi script instead of 500 error if fork
      fails (CVE-2008-1111)
    * fix min-procs handling in mod_scgi.c, just set to max-procs
      (patch from #623)
    * fix sending "408 - Timeout" instead of "410 - Gone" for
      timedout urls in mod_secdownload (#1440)
    * workaround #1587: require userdir.path to be set to enable
      mod_userdir (empty string allowed) (CVE-2008-1270)
    * make configure checks for --with-pcre, --with-zlib and
    - -with-bzip2 failing if the headers aren't found
    * fixed handling of waitpid() == EINTR mod_ssi on solaris
* Mon Oct 08 2007 mrueckert@suse.de
  - use distro lua on 10.3 or newer
* Sun Sep 09 2007 mrueckert@suse.de
  - update to 1.4.18 (#307749)
    * fixed compile error on IRIX 6.5.x on prctl() (#1333)
    * fixed forwarding a SIGINT and SIGHUP when using max-workers
      (#902)
    * fixed FastCGI header overrun in mod_fastcgi
      (reported by mattias@secweb.se)
    * fixed hanging redirects with keep-alive due to missing
      "Content-Length: 0" headers
    * fixed crashing when using undefined environment variables in
      the config
    * fixed compilation of mod_mysql_vhost on irix (#1341)
* Wed Aug 29 2007 mrueckert@suse.de
  - update to 1.4.17
    * added dir-listing.set-footer in mod_dirlisting (#1277)
    * added sending UID and PID for SIGTERM and SIGINT to the logs
    * fixed hardcoded font-sizes in mod_dirlisting (#1267)
    * fixed different ETag length on 32/64 platforms (#1279)
    * fixed compression of files < 128 bytes by disabling compression
    * (#1241)
    * fixed mysql server reconnects (#518)
    * fixed disabled keep-alive for dynamic content with HTTP/1.0
    * (#1166)
    * fixed crash on mixed EOL sequences in mod_cgi
    * fixed key compare (#1287)
    * fixed invalid char in header values (#1286)
    * fixed invalid "304 Not Modified" on broken timestamps
    * fixed endless loop on shrinked files with sendfile() on BSD
      (#1289)
    * fixed counter overrun in ?auto in mod_status (#909)
    * fixed too aggresive caching of nested conditionals (#41)
    * fixed possible overflow in unix-socket path checks on BSD
      (#713)
    * fixed extra Content-Length header on 1xx, 204 and 304 (#1002)
    * fixed handling of duplicate If-Modified-Since to return 304
    * fixed extracting status code from NPH scripts (#1125)
    * fixed prctl() usage (#1310)
    * removed config-check if passwd files exist (#1188)
    * fixed crash when etags are disabled but the client sends one
      (#1322)
    * fixed crash when freeing the config in mod_alias
    * fixed server.error-handler-404 breakage from 1.4.16 (#1270)
    * fixed entering 404-handler from dynamic content (#948)
    * added more debug infos for FAM based stat-cache
    * use more LSB like paths in the sample config (#1242)
* Thu Aug 23 2007 mrueckert@suse.de
  - split the firewall files for http and https similar to apache
    (#247748)
* Mon Aug 20 2007 mrueckert@suse.de
  - updated lighttpd-1.4.10_testsuite.patch
    new name lighttpd-1.4.16_testsuite.patch:
    - omit upstreamed snippet
* Wed Jul 25 2007 mrueckert@suse.de
  - update to 1.4.16
    * added static-file.etags, etag.use-inode, etag.use-mtime,
      etag.use-size to customize the generation of ETags for static
      files. (#1209) (patch by <Yusufg@gmail.com>)
    * fixed typecast of NULL on execl() (#1235)
      (patch by F. Denis)
    * fixed circumventing url.access-deny by trailing slash (#1230)
    * fixed crash on duplicate headers with trailing WS (#1232)
    * fixed accepting more connections then requested (#1216)
    * fixed mem-leak in mod_auth (reported by Stefan Esser)
    * fixed crash with md5-sess and cnonce not set in mod_auth
      (reported by Stefan Esser)
    * fixed missing check for base64 encoded string in mod_auth and
      Basic auth (reported by Stefan Esser)
    * fixed possible crash in Auth-Digest header parser on trailing
      WS in mod_auth (reported by Stefan Esser)
    * fixed check on stale errno values, which broke handling of
      broken fastcgi applications. (#1245)
    * fixed crash on 32bit archs when debug-msgs are printed in
      mod_scgi, mod_fastcgi and mod_webdav (#1263)
  - removed lighttpd-1.4.x_mod_status_orig_uri.patch:
    included upstream
* Fri May 25 2007 mrueckert@suse.de
  - added lighttpd-1.4.x_mod_status_orig_uri.patch:
    show the original request uri in the mod_status output
* Mon May 14 2007 mrueckert@suse.de
  - synced spec with the -snapshot rpms
* Thu Apr 19 2007 mrueckert@suse.de
  - added /var/lib/lighttpd/sockets/
* Mon Apr 16 2007 mrueckert@suse.de
  - update to 1.4.15:
    * fixed broken Set-Cookie headers
  - additional changes from 1.4.14: (includes fixes for bnc:#246945)
    * fix crash if gethostbyaddr() failed on redirect [1718]
    * properly handle 206 responses generated by *cgi scripts.
      (#755) [1716]
    * added HTTPS=on to the environment of cgi scripts (#861) [1684]
    * fix handling of 303 (#1045) [1678]
    * made the configure check for lua more portable [1677]
    * added mod_extforward module [1665]
    * references to the fam stat cache engine should be conditional
      (#1039) [1664]
    * fix http 500 errors (colin.stephen/at/o2.com) #1041 [1663]
    * prevent wrong pidfile unlinking on graceful restart
      (Chris Webb) [1656]
    * ignore empty packets from STDERR stream. #998
    * fix a crash for files with an mtime of 0 reported by cubiq on
      irc [1519] CVE-2007-1870
    * allow empty passwords with ldap (Jörg Sonnenberger) [1516]
    * mod_scgi.c segfault fix #964 [1501]
    * Added round-robin support to mod_fastcgi [1500]
    * Handle DragonFlyBSD the same way as Freebsd
      (Jörg Sonnenberger) [1492,1676]
    * added now and weeks support to mod_expire. #943
    * fix cpu hog in certain requests [1473] CVE-2007-1869
    * fix for handling hostnames with trailing dot [1406]
    * fixed header-injection via server.tag (#1106)
    * disabled caching of files without a content-type to solve the
      aggressive caching of FF
    * remove trailing white-spaces from HTTP-requests before parsing
      (#1098)
    * fixed accesslog.use-syslog in a conditional and the caching of
      the accesslog for files (fixes #1064)
    * fixed various crashes at startup on broken accesslog.format
      strings (#1000)
    * fixed handling of %% in accesslog.format
    * fixed conditional dir-listing.exclude (#930)
    * reduced default PATH_MAX to 255 (#826)
    * ECONNABORTED is not known on cygwin (#863)
    * fixed crash on url.redirect and url.rewrite if %0 is used in
      a global context (#800)
    * fixed possible crash in debug-message in mod_extforward
    * fixed compilation of mod_extforward on glibc < 2.3.4
    * fixed include of empty in the configfiles (#1076)
    * send SIGUSR1 to fastcgi children before SIGTERM. libfcgi
      wants SIGUSR1. (#737)
    * fixed missing AUTH_TYPE entry in the fastcgi environment.
      (#889)
    * fixed compilation in network_writev.c on MacOS X 10.3.9 (#903)
    * added kill-signal as another setting for fastcgi backends. See
      the wiki for more.
  - fixed the default config: (#254820)
    it broke when module configs used variables
  - added zlib-devel and libbz2-devel to the buildrequires for 10.3+
  - added proper conditionals for older distros
  - added optional mod_geoip module. (only build on the buildservice)
  - added mod_magnet config file
* Mon Mar 26 2007 rguenther@suse.de
  - Add gdbm-devel BuildRequires
* Sat Dec 02 2006 mrueckert@suse.de
  - fixed building on sles9
* Thu Oct 19 2006 mrueckert@suse.de
  - Factory has 5.1.1. so allow building against plain lua-devel
* Tue Oct 10 2006 mrueckert@suse.de
  - update to 1.4.13:
  - removed lighttpd-1.4.9.patch: fixed it upstream finally.
    * added initgroups in spawn-fcgi (#871)
    * added apr1 support htpasswd in mod-auth (#870)
    * added lighty.stat() to mod_magnet
    * fixed segfault in splitted CRLF CRLF sequences
      (introduced in 1.4.12) (#876)
    * fixed compilation of LOCK support in mod-webdav
    * fixed fragments in request-URLs (#869)
    * fixed pkg-config check for lua5.1 on debian
    * fixed Content-Length = 0 on HEAD requests without
      a known Content-Length (#119)
    * fixed mkdir() forcing 0700 (#884)
    * fixed writev() on FreeBSD 4.x and older (#875)
    * removed warning about a 404-error-handler
      returned 404
    * backported and fixed the buildsystem changes for
      webdav locks
    * fixed plugin loading so we can finally load lua
      extensions in mod_magnet scripts
    * fixed large uploads if xattr is enabled
  - buildrequire lua51
* Mon Sep 25 2006 mrueckert@suse.de
  - lighttpd.sysconfig/lighttpd.init:
    added LIGHTTPD_UMASK with a default value of "077" to make sure
    we have a sane umask. mod_webdav now honors the umask when
    creating new files.
* Sat Sep 23 2006 mrueckert@suse.de
  - update to 1.4.12:
    o added experimental LOCK support for webdav
    o added Content-Range support for PUT in webdav
    o added support for += on empty arrays in config-files
    o added ssl.cipher-list and ssl.use-sslv2
    o added $HTTP["querystring"] conditional
    o added mod_magnet as long-term replacement for mod_cml
    o added work-around for a Opera Bug with SSL + Chunked-Encoding
    o changed --print-config to print to stdout instead of stderr
    o changed no longer use 0600 for new files with webdav. umask is
      honored. Make sure you have set a proper umask.
    o fixed upload hangs with SSL
    o fixed connection drops with SSL (aka bad retry)
    o fixed path traversal with \ on cygwin
    o fixed mem-leak in mod_flv_streaming
    o fixed required trailing newline in configfiles (#142)
    o fixed quoting the autoconf files (#466)
    o fixed empty Host: + $HTTP["host"] handling (#458)
    o fixed handling of If-Modified-Since if ETag is not set
    o fixed default-shell if SHELL is not set (#441)
    o fixed appending and assigning of env.* vars
    o fixed empty FCGI_STDERR packets
    o fixed conditional server.allow-http-11
    o fixed handling of follow-symlink + lstat()
    o fixed SIGHUP handling if max-workers is used
    o fixed "Software caused connection abort" messages on FreeBSD
  - additional changes from 1.4.11:
    o added ability to specify which ip address spawn-fci listens on
      (agkr@pobox.com)
    o added mod_flv_streaming to streaming Flash Movies efficiently
    o fixed handling of error codes returned by mod_dav_svn behing a
      mod_proxy
    o fixed error-messages in mod_auth and mod_fastcgi
    o fixed re-enabling overloaded local fastcgi backends
    o fixed handling of deleted files in linux-sendfile
    o fixed compilation on BSD and MacOSX
    o fixed $SERVER["socket"] on a already bound socket
    o fixed local source retrieval on windows
      (secunia)
    o fixed hanging cgi if remote side is dieing while reading
      from the pipe (sandy@meebo.com)
* Thu Jul 20 2006 olh@suse.de
  - remove unused neon from buildrequires

Files

/etc/lighttpd/conf.d/cml.conf
/usr/lib/lighttpd/mod_cml.so
/usr/share/doc/packages/lighttpd-mod_cml
/usr/share/doc/packages/lighttpd-mod_cml/cml.txt


Generated by rpm2html 1.8.1

Fabrice Bellet, Mon Jun 10 05:29:09 2013