You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@httpd.apache.org by "William A. Rowe Jr." <wr...@rowe-clan.net> on 2014/03/13 21:55:47 UTC

[VOTE] Release httpd 2.2.27 as GA?

The pre-release candidate Apache httpd 2.2.27 can be found in;

	http://httpd.apache.org/dev/dist/

  +/-1
  [  ]  Release 2.2.27 (apr 1.5.0, apr-util 1.5.3)

Please take note of APR minor version bump from 1.4.8 to 1.5.0.

Votes please - up, down or sideways... vote to conclude 21:00 GMT
Sunday.  TIA!

Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by Yann Ylavic <yl...@gmail.com>.
On Thu, Mar 13, 2014 at 9:55 PM, William A. Rowe Jr.
<wr...@rowe-clan.net> wrote:
>
> The pre-release candidate Apache httpd 2.2.27 can be found in;
>
>         http://httpd.apache.org/dev/dist/
>
>   +/-1
>   [ +1]  Release 2.2.27 (apr 1.5.0, apr-util 1.5.3)

Debian 6.0 (squeeze) + libssl-0.9.8o-4squeeze14
Debian 7.0 (wheezy) + libssl-1.0.1e-2+deb7u4
No test framework regression with event/worker/prefork.

Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by "William A. Rowe Jr." <wm...@gmail.com>.
Yes... it appears to have been intermediary caches that threw me... the 2.4
and 2.2 new vulnerabilities are now in sync on the site.

Thanks for confirming, Joe.
On Mar 26, 2014 5:25 PM, "Joe Schaefer" <jo...@yahoo.com> wrote:

> What is the specific issue Bill- afaict everything looks fine to me.
>
>
>
> > On Wednesday, March 26, 2014 6:17 PM, William A. Rowe Jr. <
> wrowe@rowe-clan.net> wrote:
> > > On Mon, 17 Mar 2014 05:40:19 -0500
> > "William A. Rowe Jr." <wm...@gmail.com> wrote:
> >
> >>  I've been running behind too... But expect to have all my platforms
> >>  checked out Monday.  Since there are no negative votes we'll keep
> >>  this open a bit longer.
> >
> > Apologies for the delay, this has been pushed to the live site.
> >
> > Many thanks to rjung for the apr fixes already in 1.5.x branch which had
> > confounded me (I noted the changes discussed here, and didn't look over
> > for his earlier fixes).
> >
> > I cannot figure out what is going on with my attempt to refresh the
> > http://httpd.apache.org/security/vulnerabilities_22.html page with the
> > two new CVE's... if anyone can cast light on this, I'd much appreciate
> > the guidance.
> >
>

Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by Joe Schaefer <jo...@yahoo.com>.
What is the specific issue Bill- afaict everything looks fine to me.



> On Wednesday, March 26, 2014 6:17 PM, William A. Rowe Jr. <wr...@rowe-clan.net> wrote:
> > On Mon, 17 Mar 2014 05:40:19 -0500
> "William A. Rowe Jr." <wm...@gmail.com> wrote:
> 
>>  I've been running behind too... But expect to have all my platforms
>>  checked out Monday.  Since there are no negative votes we'll keep
>>  this open a bit longer.
> 
> Apologies for the delay, this has been pushed to the live site.
> 
> Many thanks to rjung for the apr fixes already in 1.5.x branch which had
> confounded me (I noted the changes discussed here, and didn't look over
> for his earlier fixes).  
> 
> I cannot figure out what is going on with my attempt to refresh the
> http://httpd.apache.org/security/vulnerabilities_22.html page with the
> two new CVE's... if anyone can cast light on this, I'd much appreciate
> the guidance.
> 

Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by "William A. Rowe Jr." <wr...@rowe-clan.net>.
On Mon, 17 Mar 2014 05:40:19 -0500
"William A. Rowe Jr." <wm...@gmail.com> wrote:

> I've been running behind too... But expect to have all my platforms
> checked out Monday.  Since there are no negative votes we'll keep
> this open a bit longer.

Apologies for the delay, this has been pushed to the live site.

Many thanks to rjung for the apr fixes already in 1.5.x branch which had
confounded me (I noted the changes discussed here, and didn't look over
for his earlier fixes).  

I cannot figure out what is going on with my attempt to refresh the
http://httpd.apache.org/security/vulnerabilities_22.html page with the
two new CVE's... if anyone can cast light on this, I'd much appreciate
the guidance.

RE: [VOTE] Release httpd 2.2.27 as GA?

Posted by "William A. Rowe Jr." <wm...@gmail.com>.
I've been running behind too... But expect to have all my platforms checked
out Monday.  Since there are no negative votes we'll keep this open a bit
longer.
On Mar 17, 2014 5:00 AM, "Plüm, Rüdiger, Vodafone Group" <
ruediger.pluem@vodafone.com> wrote:

> I try to find a slot to vote on 2.2.x later today, but I guess it will be
> in the evening my local time (GMT+1).
>
> Regards
>
> Rüdiger
>
> > -----Original Message-----
> > From: Eric Covener [mailto:covener@gmail.com]
> > Sent: Sonntag, 16. März 2014 18:21
> > To: Apache HTTP Server Development List
> > Subject: Re: [VOTE] Release httpd 2.2.27 as GA?
> >
> > On Thu, Mar 13, 2014 at 4:55 PM, William A. Rowe Jr.
> > <wr...@rowe-clan.net> wrote:
> > >
> > > The pre-release candidate Apache httpd 2.2.27 can be found in;
> > >
> > >         http://httpd.apache.org/dev/dist/
> > >
> > >   +/-1
> > >   [  ]  Release 2.2.27 (apr 1.5.0, apr-util 1.5.3)
> > >
> > > Please take note of APR minor version bump from 1.4.8 to 1.5.0.
> > >
> >
> > +1 AIX/xlc/PPC64 100% tests pass (minor autoconf tweaks for ssl as
> > discussed in 2.4 results)
>

Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by Ruediger Pluem <rp...@apache.org>.

Rainer Jung wrote:
> On 17.03.2014 20:15, William A. Rowe Jr. wrote:
>> On Mon, 17 Mar 2014 13:25:32 +0100
>> Rainer Jung <ra...@kippdata.de> wrote:
>>
>>> On 17.03.2014 10:59, Plüm, Rüdiger, Vodafone Group wrote:
>>>> I try to find a slot to vote on 2.2.x later today, but I guess it
>>>> will be in the evening my local time (GMT+1).
>>>
>>> Same here, some builds and tests still running, currently looks OK.
>>>
>>> One minor nag: out of tree build found another problem in addition to
>>> the known one for bundled APR 1.5.0. When building httpd 2.2.27, the
>>> bundled libtool has version 1.5.26 which does not create the "tools"
>>> directory before trying to write tools/.libs/gen_test_char.o
>>>
>>> httpd 2.4.9 contains libtool 2.4.2, which does not exhibit that
>>> problem.
>>>
>>> So we should also add
>>>
>>> 	$(APR_MKDIR) tools
>>>
>>> to the apr Makefile to avoid that pitfall. I'll fix that later in apr
>>> svn. Basically the breakage of out of tree build for APR 1.5.0 was
>>> known (r1541744), this is just a new detail.
>>
>> Agreed that's the fix, and there has been chatter about putting out
>> 1.5.1 one of these days.  I don't think this is enough to warrant
>> dumping the release, but I was afraid something odd might happen by
>> picking up 1.5.0 over 1.4.8.  That said - I think 1.5.0 was still the
>> right call for the time being.
>>
>> Anyone doing out of tree builds aught to be able to read the output
>> of make >build.log 2>&1, and work that out.  And most who build out
>> of tree I expect also build apr, apr-util individually.
>>
>> The casual user who would be bit by this bug is undoubtedly grabbing
>> the tarball and just building the entire stack in-tree, so I'm not
>> worried to much.
> 
> +1 to that.

+1

Regards

Rüdiger


Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by Rainer Jung <ra...@kippdata.de>.
On 17.03.2014 20:15, William A. Rowe Jr. wrote:
> On Mon, 17 Mar 2014 13:25:32 +0100
> Rainer Jung <ra...@kippdata.de> wrote:
> 
>> On 17.03.2014 10:59, Plüm, Rüdiger, Vodafone Group wrote:
>>> I try to find a slot to vote on 2.2.x later today, but I guess it
>>> will be in the evening my local time (GMT+1).
>>
>> Same here, some builds and tests still running, currently looks OK.
>>
>> One minor nag: out of tree build found another problem in addition to
>> the known one for bundled APR 1.5.0. When building httpd 2.2.27, the
>> bundled libtool has version 1.5.26 which does not create the "tools"
>> directory before trying to write tools/.libs/gen_test_char.o
>>
>> httpd 2.4.9 contains libtool 2.4.2, which does not exhibit that
>> problem.
>>
>> So we should also add
>>
>> 	$(APR_MKDIR) tools
>>
>> to the apr Makefile to avoid that pitfall. I'll fix that later in apr
>> svn. Basically the breakage of out of tree build for APR 1.5.0 was
>> known (r1541744), this is just a new detail.
> 
> Agreed that's the fix, and there has been chatter about putting out
> 1.5.1 one of these days.  I don't think this is enough to warrant
> dumping the release, but I was afraid something odd might happen by
> picking up 1.5.0 over 1.4.8.  That said - I think 1.5.0 was still the
> right call for the time being.
> 
> Anyone doing out of tree builds aught to be able to read the output
> of make >build.log 2>&1, and work that out.  And most who build out
> of tree I expect also build apr, apr-util individually.
> 
> The casual user who would be bit by this bug is undoubtedly grabbing
> the tarball and just building the entire stack in-tree, so I'm not
> worried to much.

+1 to that.

Rainer


Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by "William A. Rowe Jr." <wr...@rowe-clan.net>.
On Mon, 17 Mar 2014 13:25:32 +0100
Rainer Jung <ra...@kippdata.de> wrote:

> On 17.03.2014 10:59, Plüm, Rüdiger, Vodafone Group wrote:
> > I try to find a slot to vote on 2.2.x later today, but I guess it
> > will be in the evening my local time (GMT+1).
> 
> Same here, some builds and tests still running, currently looks OK.
> 
> One minor nag: out of tree build found another problem in addition to
> the known one for bundled APR 1.5.0. When building httpd 2.2.27, the
> bundled libtool has version 1.5.26 which does not create the "tools"
> directory before trying to write tools/.libs/gen_test_char.o
> 
> httpd 2.4.9 contains libtool 2.4.2, which does not exhibit that
> problem.
> 
> So we should also add
> 
> 	$(APR_MKDIR) tools
> 
> to the apr Makefile to avoid that pitfall. I'll fix that later in apr
> svn. Basically the breakage of out of tree build for APR 1.5.0 was
> known (r1541744), this is just a new detail.

Agreed that's the fix, and there has been chatter about putting out
1.5.1 one of these days.  I don't think this is enough to warrant
dumping the release, but I was afraid something odd might happen by
picking up 1.5.0 over 1.4.8.  That said - I think 1.5.0 was still the
right call for the time being.

Anyone doing out of tree builds aught to be able to read the output
of make >build.log 2>&1, and work that out.  And most who build out
of tree I expect also build apr, apr-util individually.

The casual user who would be bit by this bug is undoubtedly grabbing
the tarball and just building the entire stack in-tree, so I'm not
worried to much.


Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by Rainer Jung <ra...@kippdata.de>.
On 17.03.2014 10:59, Plüm, Rüdiger, Vodafone Group wrote:
> I try to find a slot to vote on 2.2.x later today, but I guess it will be in the evening my local time (GMT+1).

Same here, some builds and tests still running, currently looks OK.

One minor nag: out of tree build found another problem in addition to
the known one for bundled APR 1.5.0. When building httpd 2.2.27, the
bundled libtool has version 1.5.26 which does not create the "tools"
directory before trying to write tools/.libs/gen_test_char.o

httpd 2.4.9 contains libtool 2.4.2, which does not exhibit that problem.

So we should also add

	$(APR_MKDIR) tools

to the apr Makefile to avoid that pitfall. I'll fix that later in apr
svn. Basically the breakage of out of tree build for APR 1.5.0 was known
(r1541744), this is just a new detail.

Regards,

Rainer


RE: [VOTE] Release httpd 2.2.27 as GA?

Posted by Plüm, Rüdiger, Vodafone Group <ru...@vodafone.com>.
I try to find a slot to vote on 2.2.x later today, but I guess it will be in the evening my local time (GMT+1).

Regards

Rüdiger

> -----Original Message-----
> From: Eric Covener [mailto:covener@gmail.com]
> Sent: Sonntag, 16. März 2014 18:21
> To: Apache HTTP Server Development List
> Subject: Re: [VOTE] Release httpd 2.2.27 as GA?
> 
> On Thu, Mar 13, 2014 at 4:55 PM, William A. Rowe Jr.
> <wr...@rowe-clan.net> wrote:
> >
> > The pre-release candidate Apache httpd 2.2.27 can be found in;
> >
> >         http://httpd.apache.org/dev/dist/
> >
> >   +/-1
> >   [  ]  Release 2.2.27 (apr 1.5.0, apr-util 1.5.3)
> >
> > Please take note of APR minor version bump from 1.4.8 to 1.5.0.
> >
> 
> +1 AIX/xlc/PPC64 100% tests pass (minor autoconf tweaks for ssl as
> discussed in 2.4 results)

Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by Eric Covener <co...@gmail.com>.
On Thu, Mar 13, 2014 at 4:55 PM, William A. Rowe Jr.
<wr...@rowe-clan.net> wrote:
>
> The pre-release candidate Apache httpd 2.2.27 can be found in;
>
>         http://httpd.apache.org/dev/dist/
>
>   +/-1
>   [  ]  Release 2.2.27 (apr 1.5.0, apr-util 1.5.3)
>
> Please take note of APR minor version bump from 1.4.8 to 1.5.0.
>

+1 AIX/xlc/PPC64 100% tests pass (minor autoconf tweaks for ssl as
discussed in 2.4 results)

Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by olli hauer <oh...@gmx.de>.
On 2014-03-13 21:55, William A. Rowe Jr. wrote:
> 
> The pre-release candidate Apache httpd 2.2.27 can be found in;
> 
> 	http://httpd.apache.org/dev/dist/
> 
>   +/-1
>   [  ]  Release 2.2.27 (apr 1.5.0, apr-util 1.5.3)
> 
> Please take note of APR minor version bump from 1.4.8 to 1.5.0.
> 
> Votes please - up, down or sideways... vote to conclude 21:00 GMT
> Sunday.  TIA!
> 

Hi,

is there already a known release / announcement date for 2.2.27?


-- 
Regards,
olli

RE: [VOTE] Release httpd 2.2.27 as GA?

Posted by Plüm, Rüdiger, Vodafone Group <ru...@vodafone.com>.

> -----Original Message-----
> From: Ruediger Pluem [mailto:rpluem@apache.org]
> Sent: Montag, 17. März 2014 21:10
> To: dev@httpd.apache.org
> Subject: Re: [VOTE] Release httpd 2.2.27 as GA?
> 
> 
> 
> William A. Rowe Jr. wrote:
> >
> > The pre-release candidate Apache httpd 2.2.27 can be found in;
> >
> > 	http://httpd.apache.org/dev/dist/
> >
> >   +/-1
> >   [ +1 ]  Release 2.2.27 (apr 1.5.0, apr-util 1.5.3)
> 
> Test on Centos 6.5 64 Bit.


Prefork, Event, Worker MPM. No regression with Perl test suite. checksums and signatures fine.

Regards

Rüdiger


Re: [VOTE] Release httpd 2.2.27 as GA?

Posted by Ruediger Pluem <rp...@apache.org>.

William A. Rowe Jr. wrote:
> 
> The pre-release candidate Apache httpd 2.2.27 can be found in;
> 
> 	http://httpd.apache.org/dev/dist/
> 
>   +/-1
>   [ +1 ]  Release 2.2.27 (apr 1.5.0, apr-util 1.5.3)

Test on Centos 6.5 64 Bit.

Regards

Rüdiger