summaryrefslogtreecommitdiff
path: root/www/squid27 (follow)
Commit message (Collapse)AuthorAgeFilesLines
* - Update transparent patch.Florent Thoumie2005-06-302-4/+4
| | | | | PR: ports/82838 Submitted by: maintainer
* Update the chroot vendor patch to version 2, cfJean-Yves Lefort2005-06-292-4/+4
| | | | | | | http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE10-chroot PR: ports/82739 Submitted by: maintainer
* - Integrate the following vendor patches as published onMichael Johnson2005-06-283-16/+38
| | | | | | | | | | | | | | | | | | | | <http://www.squid-cache.org/Versions/v2/2.5/bugs/>: + double content-length often harmless (squid bug #1305) + update spanish error pages + squid internal icons were served with slightly incorrect headers (squid bug #1275) + squid -k fails in combination with chroot (squid bug #1307) + core dump with --enable-ipf-transparent if access to NAT device is denied (squid bug #1313) + http_accel_single_host incompatible with redirection (squid bug #1314) + squid -k reconfigure caused data corruption when a cache_dir type had been changed (squid bug #1308) + SNMP getnext failed if the given OID was outside the squid MIB (squid bug #1317) PR: ports/82703 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* - Read cachemgr.conf rather than cachemgr.conf.defaultJean-Yves Lefort2005-05-222-12/+6
| | | | | | | - Add a missing %SUBDIR% in MASTER_SITES PR: ports/81319 Submitted by: maintainer
* - Update Squid to 2.5.STABLE10Pav Lucistnik2005-05-195-85/+28
| | | | | PR: ports/81213 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* - update distinfo for the updated syslog patchVolker Stolz2005-04-272-31/+2
| | | | | | | | - remove local patch that is now incorporated into the corresponding vendor patch (with slightly different wording) PR: ports/80367 Submitted by: maintainer
* - Update distinfo for the 2GB patch, this includes a fix forYen-Ming Lee2005-04-211-1/+1
| | | | | | | | | | squid bugs #1283, 1287 and 1288 (assertion failed in store_client.c:343). (already committed) - Bump portrevision as a datapoint for this bugfix. PR: 80163 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* - according web page, the patch file is rerolled at 2005-04-20 14:59 againYen-Ming Lee2005-04-201-2/+2
| | | | | | http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-2GB Noticed by: kris
* - the patch is repacked at 2005-04-18 00:57, after maintainer submit PR 80028Yen-Ming Lee2005-04-181-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - diff is listed below: --- /tmp/squid-2.5.STABLE9-2GB.patch Mon Apr 4 17:09:16 2005 +++ /usr/ports/distfiles/squid2.5/squid-2.5.STABLE9-2GB.patch Mon Apr 18 08:57:57 2005 @@ -3000,7 +3000,7 @@ } /* there are some things we cannot do yet */ Index: squid/src/protos.h -diff -c squid/src/protos.h:1.420.2.28 squid/src/protos.h:1.420.2.32 +diff -c squid/src/protos.h:1.420.2.28 squid/src/protos.h:1.420.2.30 *** squid/src/protos.h:1.420.2.28 Fri Mar 18 17:01:52 2005 --- squid/src/protos.h Sat Mar 26 10:36:01 2005 *************** @@ -3455,9 +3455,9 @@ + #endif /* SQUID_H */ Index: squid/src/ssl.c -diff -c squid/src/ssl.c:1.118.2.9 squid/src/ssl.c:1.118.2.10 +diff -c squid/src/ssl.c:1.118.2.9 squid/src/ssl.c:1.118.2.11 *** squid/src/ssl.c:1.118.2.9 Mon Mar 21 12:39:29 2005 ---- squid/src/ssl.c Fri Mar 25 19:50:53 2005 +--- squid/src/ssl.c Sun Apr 17 18:54:30 2005 *************** *** 46,52 **** int len; @@ -3482,7 +3482,7 @@ kb_incr(&statCounter.server.all.kbytes_out, len); kb_incr(&statCounter.server.other.kbytes_out, len); + /* increment total object size */ -+ if (sslState->size_ptr) ++ if (sslState->size_ptr && sslState->client.fd != -1) + #if SIZEOF_SQUID_OFF_T <= 4 + if (*sslState->size_ptr < 0x7FFF0000) + #endif Noticed by: many people ...
* Integrate the following vendor patches as published onYen-Ming Lee2005-04-183-2/+62
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | <http://www.squid-cache.org/Versions/v2/2.5/bugs/>: - Correct several minor aufs issues (squid bug #671) - Basic authentification fails when login+password totalled to more than 64 characters (squid bug #1171) - Fix an assertion that could occur when traffic other than HTTPS was tunneled through squid via the CONNECT method (squid bug #1269) - Make the --disable-hostname-check configuration option actually work (squid bug #1270) - Fix aufs warning about open filedescriptors when the cache was shut down (squid bug #671) - Allow squid to process requests for files larger than 2GB in size (squid bug #437) Introduce a new OPTION "WITH_SQUID_LARGEFILE", default to off to match squid's default behaviour. Rebuild squid with -DWITH_SQUID_LARGEFILE or run 'make config' and select this new option. - Add two new cachemgr actions: "pending_objects" and "client_objects" - Make external acls that require authentication request new credentials after access had been denied (squid bug #1278) - Make squid use "daemon" instead of "local4" as syslog facility (squid bug #1227) PR: 80028 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* - Chase checksum of the updated pid_t patchMichael Johnson2005-03-152-3/+3
| | | | | PR: ports/78897 Submitted by: maintainer
* - Integrate the following vendor patches as published onMichael Johnson2005-03-132-11/+47
| | | | | | | | | | | | | | | | | | | | | | | <http://www.squid-cache.org/Versions/v2/2.5/bugs/>: + Handle odd data formats (squid bug #321) + reload_into_ims fails to revalidate negatively cached entries (squid bug #1159) + Clarify delay_access function (squid bug #1245) + Check several squid.conf directives for int overflows (squid bug #1247) + Use memset(3) instead of bzero(3) (squid bug #1256) + Fix compile warnings due to pid_t not being an int (squid bug #1257) + Fix incorrect use of ctype functions (squid bug #1259) + Defer digest fetch if the peer is not allowed to be used (squid bug #1262) + Extend relaxed_header_parser to work around "excess data from" errors from many major web servers (squid bug #1265) - Enable IPFilter based transparent proxying on all FreeBSD versions where IPFilter headers are part of the base system (i.e. RELENG_4 < 4.7-RELEASE, RELENG_5 and 6-CURRENT). Create a new OPTION WITH_SQUID_IPFILTER for this purpose. Thanks to sem@ for keeping track of this issue! PR: ports/78780 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* Integrate the following vendor patches as published onPav Lucistnik2005-03-082-1/+13
| | | | | | | | | | | | - correct a race condition related to the Set-Cookie header - correct the FTP parser with regards to the EPLF format (squid bug #1252) - correct FTP listing output when the URL was requested without a trailing slash (squid bug #1253) - make ACL configuration errors fatal (squid bug #1255) PR: ports/78446 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* - Update to 2.5.STABLE9Pav Lucistnik2005-02-262-20/+5
| | | | | PR: ports/78079 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* * Vendor patches:Pav Lucistnik2005-02-202-1/+14
| | | | | | | | | | | | - fix some cross-platform build format warnings - allow high characters in generated FTP and Gopher directory listings (squid bug #1220) - cleanup generation of FTP URLs - relax the newly introduced strict HTTP parser slightly to work around some more malformed HTTP responses (squid bug #1242) PR: ports/77779 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* - Update to 2.5-STABLE8Sergey Matveychuk2005-02-133-224/+7
| | | | | | | | | - Integrate a vendor patch from: http://www.squid-cache.org/Versions/v2/2.5/bugs/ it fixes a major problem regarding the handling of invalid DNS responses PR: ports/77423 Submitted by: maintainer
* - Update header_parsing.patchPav Lucistnik2005-02-103-36/+3
| | | | | PR: ports/77360 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* Integrate the following vendor patch as published onJacques Vidrine2005-02-082-2/+20
| | | | | | | | | | | | | | | | | <http://www.squid-cache.org/Versions/v2/2.5/bugs/>: - Address HTTP protocol mismatch related to oversized reply headers and enhance cache.log on reply header parsing failures (squid bug #1216) - correct the search request generated by the LDAP authentication helper - fix a race within the NTLM authentication mechanism (squid bug #1127) - fix handling of failed PUT/POST requests (squid bug #1224) - fix problems with persistent server connections after failed PUT/POST requests (squid bug #1122) - improve handling of forged WCCP packets (squid bug #1225) PR: ports/76967 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer) Security: http://vuxml.freebsd.org/bfda39de-7467-11d9-9e1e-c296ac722cb3.html
* - Fix fetching.Sergey Matveychuk2005-02-012-3/+3
| | | | | | | | * The response_splitting patch has been updated to correct a problem with cache digests. PR: ports/76889 Submitted by: maintainer
* - Integrate a vendor patch against a buffer overflow in the WCCP handling,Sergey Matveychuk2005-01-292-2/+5
| | | | | | | | see <http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow> and <http://www.squid-cache.org/Advisories/SQUID-2005_3.txt>. PR: ports/76827 Submitted by: maintainer
* Sync follow-XFF with the latest vendor patch.Kirill Ponomarev2005-01-291-5/+5
| | | | | PR: ports/76801 Submitted by: maintainer
* - Integrate vendor patches as published onSergey Matveychuk2005-01-264-42/+213
| | | | | | | | | | | | | | | | | | | | | <http://www.squid-cache.org/Versions/v2/2.5/bugs/>: + Reject malformed HTTP requests and responses that conflict with the HTTP specifications This issue is qualified as a security issue by the vendor. + PURGE is allowed to delete internal objects (squid bug #1112) + Disable Path-MTU discovery on intercepted requests (squid bug #1154) (VuXML vid=b4d94fa0-6e38-11d9-9e1e-c296ac722cb3) - Clean up and correct package list generation. Now installed files and directories are visible via PLIST_FILES and PLIST_DIRS. - Don't claim that squid related files or directories are still present after deinstallation when in fact they are not. - Add "-g" to CFLAGS when WITH_SQUID_STACKTRACES is defined to make this option actually useful. PR: ports/76628 Submitted by: maintainer
* [Maintainer/security] www/squid: protect against HTTP resonse splitEdwin Groothuis2005-01-222-2/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | attack and other patches Integrate vendor patches as published on <http://www.squid-cache.org/Versions/v2/2.5/bugs/>: - FTP data connection fails on some FTP servers when requesting a directory without a trailing slash (squid bug #1194) - Icons fail to load on non-anonymous FTP when using the short_icons_url configuration directive (squid bug #1203) - Strengthen squid against HTTP response splitting cache pollution attacks (squid bug #1200), classified as security issue by the vendor Proposed VuXML information, entry date left to be filled in: (Note: I added only a publically accessible link to the Sanctum, Inc. whitepaper, the squid bug tracker contains a deep link to the PDF itself; if we are allowed to publish it, it could instead be used as reference because Sanctum, Inc. wants you to register with them before you get access to their whitepapers.) PR: ports/76550 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de>
* [Maintainer/Security] www/squid: integrate vendor patchesEdwin Groothuis2005-01-192-2/+11
| | | | | | | | | | | | | | Integrate vendor patches as published on <http://www.squid-cache.org/Versions/v2/2.5/bugs/>: - Sanity check usernames in squid_ldap_auth (squid bug #1187), classified as minor security issue by the vendor, see below for VuXML information - FQDN names truncated on compressed DNS responses (squid bug #1136) - Internal DNS memory leak on malformed responses (squid bug #1197) PR: ports/76364 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de>
* - Integrate vendor patches as published onSimon L. B. Nielsen2005-01-122-4/+20
| | | | | | | | | | | | | | | | | | | | | | | <http://www.squid-cache.org/Versions/v2/2.5/bugs/> for the following issues: + Prevent a possible denial of service attack via WCCP messages (squid bug #1190), classified as security issue by the vendor + Fix a buffer overflow in the Gopher to HTML conversion routine (squid bug #1189), classified as security issue by the vendor + Fix a null pointer access and plug memory leaks in the fake_auth NTLM helper (squid bug #1183) (this helper app is not installed by default by the port) + Stop closing open filedescriptors beyond stdin, stdout and stderr on startup (squid bug #1177) - Unbreak the port on NO_NIS systems (thanks to "Alexander <freebsd AT nagilum.de>" for reporting this) - Document the two security issues in VuXML. PR: ports/76173 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer) Approved by: erwin (mentor)
* Patch was rerolled because of some bug fixes.Kirill Ponomarev2004-12-291-2/+2
| | | | Approved by: maintainer
* Handle empty ACL definitions properly.Kirill Ponomarev2004-12-232-2/+5
| | | | | PR: ports/75403 Submitted by: maintainer
* Integrate the following vendor patches as published onSergey Matveychuk2004-12-082-2/+11
| | | | | | | | | | | | | | | http://www.squid-cache.org/Versions/v2/2.5/bugs/: - a malformed hostname can cause squid to return random data as error messages, possibly leaking internal information from former requests (squid bug #1143). (This is classified as a minor security issue by the squid developers, so maintainer cc'ed security-team@. See VuXML entry.) - the "httpd_accel_port 0" directive does not work on its own (squid bug #1121) - fix crashes occuring when using cachemgr's "vm_objects" operation (squid bug #1149) PR: ports/74859 Submitted by: maintainer
* - fix shutting down of helper applications on reconfigure orKirill Ponomarev2004-11-142-2/+8
| | | | | | | | | logrotation (squid bug #1118) - properly close the client TCP connection when a malformed blank HTTP response was received from the server (squid bug #1116) PR: ports/73913 Submitted by: maintainer
* - Integrate the following vendor patches:Sergei Kolobov2004-10-272-2/+8
| | | | | | | | | | | - document the LDAP helpers' -v option - correct the implementation of the req_header and resp_header acls (the original implementation submitted in squid bug #961 was faulty) See <http://www.squid-cache.org/Versions/v2/2.5/bugs/> for further details. - Bump PORTREVISION PR: ports/73154 Submitted by: Thomas-Martin Seck (maintainer)
* - Integrate a vendor patch that prevents squid from consuming 100%Sergei Kolobov2004-10-183-15/+20
| | | | | | | | | | | | CPU for half closed PUT/POST requests (squid bugs #354, 1096). See <http://www.squid-cache.org/Versions/v2/2.5/bugs/> for further details. - Adapt the follow_xff patch to changes in some of squid's data structures and unbreak the WITH_SQUID_FOLLOW_XFF option. - Bump PORTREVISION. PR: ports/72840 Submitted by: Thomas-Martin Seck (maintainer)
* - Update to 2.5-STABLE7; this release fixes a security issue regardingSergei Kolobov2004-10-135-103/+26
| | | | | | | | | | | | | the SNMP module - Remove a patch that is now part of the distribution - Miscellaneuous small fixes: + in squid.sh, make stop_command poll for the squid processes' exit in the rcNG case too; this eliminates the need to do this in restart_command + make the information regarding rcNG'ness in pkg-install easier to read + install unstripped binaries if WITH_SQUID_STACKTRACES is defined PR: ports/72581 Submitted by: Thomas-Martin Seck (maintainer)
* - Unbreak fetching squid again:Sergei Kolobov2004-10-112-3/+3
| | | | | | | | | | | The recently updated client_db_gc patch has been reissued again; according to squid CVS to "finetune the client db garbage collection interval". Update distinfo accordingly and bump PORTREVISION. PR: ports/72461 [1], ports/72463 [2] Submitted by: Sunpoet Po-Chuan Hsieh <sunpoet@sunpoet.net> [1], Thomas-Martin Seck (maintainer) [2] Approved by: portsmgr (krion)
* - Unbreak fetching:Sergei Kolobov2004-10-072-2/+2
| | | | | | | | | | The client_db_gc patch contained a wrong debugging information and was thus reissued by the vendor. Update distinfo accordingly and bump PORTREVISION. PR: ports/72387 Submitted by: Thomas-Martin Seck (maintainer) Approved by: portsmgr (krion)
* Implement vendor patches for the following issues:Sergey Matveychuk2004-09-025-72/+93
| | | | | | | | | | | | | | | | | | - try to prevent crashes of the digest helper (squid bug #1031) - correct parsing of the acl_time directive when multiple time specifications are given (squid bug #1060) - correct "cachemgr config" output for http_header_* directives (squid bug #1056) - recognize the Content-Disposition header to be able to specify http_header_access directives using it (squid bug #961) See <http://www.squid-cache.org/Versions/v2/2.5/bugs/> for further information. Reimplement the rcNG support. See UPDATING for details. PR: ports/71260 Submitted by: maintainer
* Integrate vendor patches for the following issues:Sergey Matveychuk2004-08-282-2/+11
| | | | | | | | | | | | | | | - close a memory leak when NTLM authentication without challenge reuse is used (squid bug #994) - close a temporary memory leak when NTLM challenge response reuse is enabled (squid bug #910) - when performing log rotation with 'squid -k rotate' do not crash if a swap state file or a cache directory is unwriteable (squid bug #1053) See <http://www.squid-cache.org/Versions/v2/2.5/bugs/> for further information. PR: ports/71082 Submitted by: maintainer
* Fix grammatical and whitespace errors in squid.conf.default.Kirill Ponomarev2004-08-213-14/+20
| | | | | | | | | | | | Set supplementary group membership correctly when running squid as a non-root user and do not ignore the squid_group setting when starting squid as root (squid bug #1021) Enable the external_acl helper protocol to handle newlines in the embedded data (squid bug #1038) PR: ports/70767 Submitted by: maintainer
* * Integrate a vendor patch for a possible DOS against the NTLMSergey Matveychuk2004-08-202-2/+5
| | | | | | | | authentication helpers, see squid bug #1045. * Bump PORTREVISION. PR: ports/70707 Submitted by: maintainer
* The ldap_helpers patch has been updated again; see squid bugKirill Ponomarev2004-08-111-2/+2
| | | | | | | #1032 for details. PR: ports/70312 Submitted by: maintainer
* Integrate new vendor patches:Kirill Ponomarev2004-08-072-2/+8
| | | | | | | | | | | - fix a problem in the heap policy code that could cause memory corruption when a {cache,memory}_replacement_policy other than the default "lru" was used (squid bug #1009) - correct quoting of unknown % escape codes when generating error pages (squid bug #1030) PR: ports/70110 Submitted by: maintainer
* [Maintainer] www/squid: chase re-issued patch, unbreak fetchingEdwin Groothuis2004-07-292-3/+3
| | | | | | | | | | The concurrent_dns_lookups patch was reissued, update distinfo accordingly. See <http://www.squid-cache.org/bugs/show_bug.cgi?id=852> for further information. PR: ports/69764 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de>
* - integrate a new version of the LDAP update patch, theKirill Ponomarev2004-07-282-8/+8
| | | | | | | | | | | problems with the previous version are hopefully fixed (squid bug #1018) - integrate a new NTLM authentication patch to address a problem with truncating NTLM authentication blobs (squid bug #1016) - remove two patches which were withdrawn (see squid bugs #910 and 994) PR: ports/69719 Submitted by: maintainer
* Fix a bug that disallowed explicit unsetting of the squid_flags variable.Ying-Chieh Liao2004-07-281-1/+1
| | | | | PR: 69670 Submitted by: maintainer
* - Tweaks to RC scriptPav Lucistnik2004-07-252-12/+47
| | | | | | | | | - Fix dynamic plist generation to not include files that happen to be in target directories. This prevents their removal on deinstallation or upgrade. PR: ports/69552, ports/69266 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* Remove ldap_helpers.patchSergey Matveychuk2004-07-241-2/+0
| | | | | PR: ports/69487 (partially) Submitted by: maintainer
* Remove squid-2.5.STABLE6-ldap_helpers.patch until it is fixed.Oliver Eikemeier2004-07-231-1/+0
| | | | | | | | | | | cf <http://www.squid-cache.org/bugs/show_bug.cgi?id=1018> Do not bump PORTREVISION, since a) ldap is not in the default configuration b) we hope to have that fixed soon PR: 69465 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
* The ldap_helpers patch has been rerolled (a missing returnKirill Ponomarev2004-07-222-3/+3
| | | | | | | statement was inserted). PR: ports/69408 Submitted by: maintainer
* Integrate the following vendor patches as published onKirill Ponomarev2004-07-192-9/+55
| | | | | | | | | | | | | | | | | | | | | | http://www.squid-cache.org/Versions/v2/2.5/bugs/: - fix a memory leak in client_db (squid bug #833) - add delay pools information to cachemgr's active_requests page - make basic authentication operate case insensitive by default, case sensitive operation can be enabled via squid.conf - log if cache files cannot be created for some reason - make sure that a HTTP HEAD request does not return stale data - correctly log partial hits as TCP_MISS instead of TCP_HIT - fix memory leaks within the NTLM authentication helper - handle the request_header_max_size directive correctly - avoid creating a large number of queued DNS lookups for the same domain in case of DNS problems - update LDAP helper PR: ports/69307 Submitted by: maintainer
* Update to 2.5-STABLE6Kirill Ponomarev2004-07-142-113/+42
| | | | | PR: ports/69060 Submitted by: maintainer
* Fix the patch that simulates the autotools bootstrap for theKirill Ponomarev2004-06-284-86/+24
| | | | | | | | | | | | | | | follow-xff-patchset (thanks to Michael Ranner for spotting the problem and testing the fix). While at it, wordsmith the comments in the patch. Use the official patch for the NTLM auth helper vulnerability, see <http://www.squid-cache.org/Versions/v2/2.5/bugs/> for details. Build install the SMB basic authentication helpers by default PR: ports/68448 Submitted by: maintainer