Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-10-03 Thread Ondřej Surý
> So the actual item for the wishlist is to be able to specify a user (or more > than one) that are considered trusted. Suexec will then allow files > owned by either the target user, or by a trusted user, to be executed. Use chattr +i Ondrej. -- Ondřej Surý <[EMAIL PROTECTED]>

Bug#517126: closed by Ondřej Surý (Re: Bug#517126: apache2: PHP (5) support cannot be installed)

2009-02-25 Thread Ondřej Surý
he 1.x and php5 ;), and there has been(maybe still is) bug in the release notes. Ondrej > Axel > -BEGIN PGP SIGNATURE- > Version: GnuPG v1.4.9 (GNU/Linux) > Comment: Made with pgp4pine 1.76 > > iEYEARECAAYFAkmlqQcACgkQMiDYPOQNapFKFwCeI2ngQJ9O+Lqbxv18LNRjOMhJ > Y5

Bug#388805: RFP: please package mod_auth_xradius

2006-09-22 Thread Ondřej Surý
rvers. *Distributed Authentication Cache using apr_memcache. *Local Authentication Cache using DBM. *Uses standard HTTP Basic Authentication, unlike mod_auth_radius which uses cookies for sessions. Kind regards, -- Ondřej Surý <[EMAIL PROTECTED]>

Bug#397265: closed by Thom May <[EMAIL PROTECTED]> (LFS works fine)

2006-11-06 Thread Ondřej Surý
-1 which will be uploaded this evening if everything will be ok. Ondrej. -- Ondřej Surý <[EMAIL PROTECTED]>

Bug#397405: apache2-mpm-prefork: child seg-faults on access

2006-11-07 Thread Ondřej Surý
idea on how I can fix that? Try downgrading php4 to php4-4.4.4~4 and let us know if it helps. Ondrej. -- Ondřej Surý <[EMAIL PROTECTED]>

Bug#828236: Bug#844160: marked as done (apache2-dev should depend on libssl1.0-dev)

2016-11-13 Thread Ondřej Surý
nf->cid->serialNumber) != -1) && +ASN1_INTEGER *serial; + OCSP_id_get0_info(NULL, NULL, NULL, &serial, cinf->cid); +if ((i2a_ASN1_INTEGER(bio, serial) != -1) && ((n = BIO_read(bio, snum, sizeof snum - 1)) >

Bug#828236: Bug#844160: marked as done (apache2-dev should depend on libssl1.0-dev)

2016-11-13 Thread Ondřej Surý
On Mon, Nov 14, 2016, at 08:44, Ondřej Surý wrote: > On Mon, Nov 14, 2016, at 08:21, Adrian Bunk wrote: > > On Mon, Nov 14, 2016 at 05:03:45AM +0100, Ondřej Surý wrote: > > > > Looking at mod_ssl_openssl.h and the comment in #828330, > > > > I'd suggest t

Bug#828236: Bug#844160: marked as done (apache2-dev should depend on libssl1.0-dev)

2016-11-13 Thread Ondřej Surý
On Mon, Nov 14, 2016, at 08:21, Adrian Bunk wrote: > On Mon, Nov 14, 2016 at 05:03:45AM +0100, Ondřej Surý wrote: > > > Looking at mod_ssl_openssl.h and the comment in #828330, > > > I'd suggest the change below to add a dependency on libssl1.0-dev > > > to apa

Bug#851357: Regression: No longer supports ServerName containing underscore

2017-01-14 Thread Ondřej Surý
Hi Jonathan, while I agree that such changes should not happen within one Debian release and the maintainer might want to relax the rules for the package, the ServerName accepts a hostname as a parameter and a valid hostname cannot contain underscore. So the Apache is behaving correctly here n

Bug#851357: Regression: No longer supports ServerName containing underscore

2017-01-14 Thread Ondřej Surý
Stefan, JFTR underscores in domain names are allowed, just not for hostnames. SRV, TLSA and other RRs make use of them. O. On 14 January 2017 17:24:09 Stefan Fritsch wrote: On Saturday, 14 January 2017 12:33:55 CET Jonathan Vollebregt wrote: Actually that makes another point: according t

Re: Bug#852776: mariadb-server-10.1: init script doesn't specify it should be started prior to apache2 etc

2017-03-26 Thread Ondřej Surý
aken whether this would work if more packages has the '$database' defined. Ccing apache2 and postgresql maintainers on this one. Cheers, -- Ondřej Surý Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server Knot Resolver (https://www.knot-resolver.cz/) – secure, priv

Re: Bug#852776: mariadb-server-10.1: init script doesn't specify it should be started prior to apache2 etc

2017-03-28 Thread Ondřej Surý
heers, -- Ondřej Surý Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server Knot Resolver (https://www.knot-resolver.cz/) – secure, privacy-aware, fast DNS(SEC) resolver Vše pro chleba (https://vseprochleba.cz) – Mouky ze mlýna a potřeby pro pečení chleba všeho druhu On Sun, Mar 26, 2017, at

Re: Bug#877341: libapache2-mod-md: Doesn't seem to work at all: "AH02572: Failed to configure at least one certificate and key" (seems to require a patched version of mod_ssl / apache2)

2017-09-30 Thread Ondřej Surý
svinit (via /sbin/init) Versions of packages libapache2-mod-md depends on: ii apache2-bin [apache2-api-20120211] 2.4.27-6 ii libapr1 1.6.2-1 ii libaprutil1 1.6.0-2 ii libc6 2.24-17 ii libcurl3-gnutls 7.55.1-1 ii libjansson4 2.10-1 ii libssl1.1 1.1.0f-5 libapache2-mod-md recommends no packages. libapache2-mod-md suggests no packages. -- no debconf information -- Ondřej Surý

Problems with lbmethod_* modules requiring symbols from proxy

2018-07-25 Thread Ondřej Surý
nds” field, starting say at “20-“ prefix and increasing the number by 10 on each “Depends:” iteration. Unfortunately, I don’t have the time nor the perl-foo to do that. Anyway, I just wanted to warn the other maintainers before the 2.4.34 upload. Ondrej -- Ondřej Surý ond...@isc.org

Bug#978045: apache2-bin: Immediate exit with "AH00141: Could not initialize random number generator"

2020-12-26 Thread Ondřej Surý
I believe it’s a reasonable assumption that the kernel matches the Debian release. If anybody is running with old kernel or disables getrandom I would say they are on their own - also other stuff will break, not only apache2. Ondrej -- Ondřej Surý (He/Him) > On 27. 12. 2020, at 0:24, Ste

Bug#988029: apache2: Non-unique IDs being generated by mod_unique_id - Fix available

2021-05-03 Thread Ondřej Surý
thread, then use https://prng.di.unimi.it/ Ondrej -- Ondřej Surý (He/Him) > On 3. 5. 2021, at 23:33, Atle Solbakken wrote: > Package: apache2 > Version: 2.4.38-3+deb10u4 > Severity: normal > Tags: patch > > Hi > > The current version has a race condition in mod_unique_i

Bug#1021771: apache2: Accessing to type-map without .var suffix results 500 and apache2 exits

2022-10-14 Thread Ondřej Surý
certainly nice, it's not enough to see what might be the problem. And you can't expect other people do debug the Docker containers. Ondrej -- Ondřej Surý (He/Him) ond...@sury.org

Bug#1080079: apache2: Upgrade from Debian 11 to 12 seems to have enabled serve-cgi-bin.conf (security risk)

2024-08-30 Thread Ondřej Surý
bled serve-cgi-bin.conf? Ondrej -- Ondřej Surý (He/Him)

Bug#1080079: apache2: Upgrade from Debian 11 to 12 seems to have enabled serve-cgi-bin.conf (security risk)

2024-08-30 Thread Ondřej Surý
links. Ondrej -- Ondřej Surý (He/Him) > On 30. 8. 2024, at 16:52, Ralf Bergs wrote: > >  >> On 2024-08-30 12:58, Ondřej Surý wrote: >> your report is missing the information on **how** did you disabled >> serve-cgi-bin.conf? > Ah, sorry. > > I manually dele

Bug#578754: apache2-mpm-prefork: child exit signal Segmentation fault (11)

2010-04-22 Thread Ondřej Surý
t; #33922 0x0808b0a6 in ap_process_request (r=0x868cdc8) at > /tmp/buildd/apache2-2.2.9/modules/http/http_request.c:258 > #33923 0x080881d8 in ap_process_http_connection (c=0x8686d50) at > /tmp/buildd/apache2-2.2.9/modules/http/http_core.c:190 > #33924 0x080815f9 in ap_run_process_co

Bug#578754: apache2-mpm-prefork: child exit signal Segmentation fault (11)

2010-04-22 Thread Ondřej Surý
12 0xb724a490 in execute (op_array=0x864edb8) at >> /tmp/buildd/php5-5.2.6.dfsg.1/Zend/zend_vm_execute.h:92 >> #33913 0xb7224bd0 in zend_execute_scripts (type=8, retval=0x0, file_count=3) >> at /tmp/buildd/php5-5.2.6.dfsg.1/Zend/zend.c:1215 >&g

Re: [php-maint] Bug#619036: php5: Build-Depends uninstallable

2011-03-21 Thread Ondřej Surý
ding on db and if we can get somebody from apache2, ldap and subversion, we would have quite strong team. Ondrej -- Ondřej Surý -- To UNSUBSCRIBE, email to debian-apache-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archiv

Bug#621366: Still uses libdb4.8

2011-04-06 Thread Ondřej Surý
debian.org/?p=pkg-cyrus-imapd/cyrus-imapd-2.4.git;a=blob;f=debian/cyrus-upgrade-db;hb=HEAD Thanks, -- Ondřej Surý -- System Information: Debian Release: squeeze/sid APT prefers maverick-updates APT policy: (500, 'maverick-updates'), (500, 'maverick-security'), (500, '

Re: [php-maint] Bug#666820: php5: sourceful transition towards Apache 2.4

2012-04-06 Thread Ondřej Surý
2&searchon=sourcenames&exact=1&suite=all§ion=all > [3] > http://anonscm.debian.org/gitweb/?p=pkg-apache/apache2.git;a=blob;f=debian/PACKAGING;hb=next > [4] http://httpd.apache.org/docs/2.4/developer/new_api_2_4.html > [5] http://wiki.debian.org/Apache/PackagingFor24 > &g

Re: [php-maint] Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-08-14 Thread Ondřej Surý
h do not run PHP. Understood. > After your answer, I propose to send a brief summary to debian-release and > debian-devel, proposing reassign the bug to the release notes with the same > severity. Will you take care of that? O. -- Ondřej Surý -- To UNSUBSCRIBE, emai

Re: [php-maint] Bug#674089: Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-08-15 Thread Ondřej Surý
take care, that and PHP files intended to be interpreted are recognised as such (typically by adding MIME-Type or handler definitions in the webserver configuration). -- Ondřej Surý Wed, 15 Aug 2012 10:31:31 +0200 O. -- Ondřej Surý -- To UNSUBSCRIBE, email to debian-apache-requ...@lists

Re: Possible release note for systems running PHP through CGI.

2012-08-20 Thread Ondřej Surý
any other webserver included in Debian, but it might affect any application which relies on system MIME types to interpret PHP files. -- Ondřej Surý Wed, 15 Aug 2012 10:31:31 +0200 - Update the README.Debian to match current state. I will upload this change as part of 5.4.6-1 upload

Re: Possible release note for systems running PHP through CGI.

2012-08-20 Thread Ondřej Surý
, but I guess we now have to find a way how to cope with them and still make release team happy. I think the changes I have done are least intrusive, but again opinions may vary. O. -- Ondřej Surý -- To UNSUBSCRIBE, email to debian-apache-requ...@lists.debian.org with a subject of "uns

Re: Possible release note for systems running PHP through CGI.

2012-08-21 Thread Ondřej Surý
On Mon, Aug 20, 2012 at 8:12 PM, Stefan Fritsch wrote: > On Monday 20 August 2012, Ondřej Surý wrote: >> Ah, I see; it gets executed when there is no know handler or >> mime-type for second extension. >> >> E.g. index.php.jpeg works as expected (e.g. returning PHP sourc

Re: Possible release note for systems running PHP through CGI.

2012-08-21 Thread Ondřej Surý
ce for further information. O. -- Ondřej Surý -- To UNSUBSCRIBE, email to debian-apache-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/caljhhg_0smdoegerxyen1u0mxgpmyyt1gbvmqdmictt-u4e...@mail.gmail.com

Re: Possible release note for systems running PHP through CGI.

2012-08-21 Thread Ondřej Surý
On Tue, Aug 21, 2012 at 9:38 AM, Konstantin Khomoutov wrote: > On Tue, Aug 21, 2012 at 09:07:59AM +0200, Ondřej Surý wrote: > > [...] >>> Maybe add just a small paragraph that the configuration of the >>> extensions has changed and php users should read the NEWS

Re: Fwd: [php-maint] Updating php5 to 5.4.4-5 broke FastCGI setup on my machine

2012-10-08 Thread Ondřej Surý
In hindsight, maybe the mime.types change should have been > deferred until we ugrade to apache 2.4 and people have to adjust their > configs anyway. But I think it's too late now to go back. And leaving the > *.php.foo problem there for yet another release cycle would not have bee

Re: Fwd: [php-maint] Updating php5 to 5.4.4-5 broke FastCGI setup on my machine

2012-10-08 Thread Ondřej Surý
On Mon, Oct 8, 2012 at 9:51 PM, Christoph Anton Mitterer wrote: > On Mon, 2012-10-08 at 15:38 +0200, Ondřej Surý wrote: >> Just one last question which came to my mind. Would this all be fixed >> if we added non-magic type to mime-support (e.g. >> http://bugs.debian.org/6709

Re: Fwd: [php-maint] Updating php5 to 5.4.4-5 broke FastCGI setup on my machine

2012-10-26 Thread Ondřej Surý
t tests the non-magic mime-types as written down by sf in http://wiki.debian.org/Apache/WheezyMimeTypes), I think we can still change that before release. But now we at least need more test in php5-cgi.NEWS. O. -- Ondřej Surý -- To UNSUBSCRIBE, email to debian-apache-requ...@lists.debian

Bug#707071: dh_apache2 installs the dismod into postrm instead of prerm (which was common before Apache 2.4)

2013-05-07 Thread Ondřej Surý
Package: apache2-dev Version: 2.4.4-2 Severity: normal Hi, the apache2_invoke dismod should be installed in prerm, because the module file cease to exists between prerm and postrm. Thus if somebody/something restarts the apache2 before the removal process is complete, the apache2 process will f

Re: [php-maint] Apache 2.4 MediaWiki Debian tips

2013-05-09 Thread Ondřej Surý
Just don't use PHP 5.5 and Apache 2.4 from *experimental* yet, if you can't debug it, please. Ondřej Surý On 10. 5. 2013, at 4:36, jida...@jidanni.org wrote: > Yes so I decided to reinstall from scratch and now index.php is being > interpreted as plain text so I cannot figure

Bug#707024: Bug#661958: Reboot Apache2 2.4 transition

2013-05-13 Thread Ondřej Surý
regards, > Arno Töll > IRC: daemonkeeper on Freenode/OFTC > GnuPG Key-ID: 0x9D80F36D > -- Ondřej Surý -- To UNSUBSCRIBE, email to debian-apache-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://li

Bug#707024: Bug#661958: Reboot Apache2 2.4 transition

2013-05-16 Thread Ondřej Surý
On Thu, May 16, 2013 at 8:12 PM, Arno Töll wrote: > Hi, > > On 13.05.2013 10:51, Ondřej Surý wrote: >> I can ack that PHP 5.5 RC1 is prepared to enter the unstable. >> This will also trigger the libgd and php5.5 transitions. > > jcristau and me wondered if you want

Re: [php-maint] Bug#711454: libapache2-mod-php5: MPM prefork not found ... ==> ... Syntax error on line 9 of /etc/apache2/mods-enabled/php5.conf: Invalid command 'Order'

2013-06-06 Thread Ondřej Surý
the transition period from 2.2 to 2.4. That's also probably something which would be better places in dh helper to add replacement for ${apache2:Pre-Depends} which I would place into Pre-Depends:, so it can be dropped automatically when no longer needed. Ondřej Surý On 7. 6. 2013, at 0:45, Andreas

Re: Bug#717610: a second run of aptitude safe-upgrade clears it

2013-07-23 Thread Ondřej Surý
wrote: > > I get the same message. But then a second run of aptitude safe-upgrade > > gives no more error. Perhaps there is a bug too in aptitude? > > So it's ordering related ... but not a fault in apt/aptitude > > Anyway, the same problem appears in piuparts tests of > > debian-edu-config-gosa-netgroups > phpbb3 > > > Andreas > -- Ondřej Surý

Bug#717610: [php-maint] Bug#717610: a second run of aptitude safe-upgrade clears it

2013-07-23 Thread Ondřej Surý
On Tue, Jul 23, 2013 at 12:32 PM, Arno Töll wrote: > On 23.07.2013 12:29, Ondřej Surý wrote: > > Control: reassign -1 apache2 > > Control: retitle -1 apache2-maintscript-helper doesn't support dpkg > triggers > > Yep, thanks. That is it. Did you recently enable t

Bug#711925: apache2-doc's config file breaks apache itself

2013-07-25 Thread Ondřej Surý
> others who deliberately rm'ed all of /etc/apache2 because they think our > configuration sucks anyway. Arno, could you please rethink the idea of re-adding apache2.2-common with version Breaks: on all reverse depends (with versions from wheezy, the jessie can be handled by filling RC bugs case-by-case). O. -- Ondřej Surý

Bug#711925: apache2-doc's config file breaks apache itself

2013-07-25 Thread Ondřej Surý
On Thu, Jul 25, 2013 at 1:19 PM, Arno Töll wrote: > On 25.07.2013 13:16, Ondřej Surý wrote: > > could you please rethink the idea of re-adding apache2.2-common with > > version Breaks: on all reverse depends (with versions from wheezy, the > > jessie can be handled by fi

Bug#711925: apache2-doc's config file breaks apache itself

2013-07-25 Thread Ondřej Surý
On Thu, Jul 25, 2013 at 1:35 PM, Arno Töll wrote: > On 25.07.2013 13:25, Ondřej Surý wrote: > > Wouldn't > > > > Package: apache2 > > Replaces: apache2.2-common (<< 2.4.0) > > Breaks: apache2.2-common (<< 2.4.0) > > > > Solve the prob

Bug#716880: Solutions for the Apache upgrade hell

2014-07-14 Thread Ondřej Surý
modules in apache2.4 postinst and detect incompatible ABI in /usr/lib/apache2/modules/*.so files. 2. As a thought did you think about moving the modules under /usr/lib/apache2/20120211/ (e.g. similar to what PHP has). You still have time for that and it would make the transition easier in the futu

Fwd: Re: [php-maint] Bug#791902: libapache2-mod-php5.postinst: 291: [: !=: unexpected operator

2015-07-09 Thread Ondřej Surý
-- Ondřej Surý Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server - Original message - From: Ondřej Surý To: Andreas Beckmann , 791...@bugs.debian.org, debian-ap...@lists.debian.org Subject: Re: [php-maint] Bug#791902: libapache2-mod-php5.postinst: 291

Re: [php-maint] Bug#791902: libapache2-mod-php5.postinst: 291: [: !=: unexpected operator

2015-08-28 Thread Ondřej Surý
gt; > ___ > pkg-php-maint mailing list > pkg-php-ma...@lists.alioth.debian.org > http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-php-maint -- Ondřej Surý Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server

Re: [php-maint] Bug#799630: libapache2-mod-php5: changes apache MPM event if disabled

2015-09-23 Thread Ondřej Surý
.alioth.debian.org > http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-php-maint -- Ondřej Surý Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server

Bug#821956: make a2enmod work with perl 5.14 (Ubuntu Precise)

2016-04-20 Thread Ondřej Surý
Source: apache2 Version: 2.4.18-2 Severity: minor Tags: patch Hi Stephan and Arno, attached is a patch that makes a2enmod to run on Ubuntu Precise with perl 5.14 while hopefully not breaking anything else :). While looking into perl code, I felt as if millions of voices suddenly cried out in ter

Bug#823497: /usr/sbin/a2enmod: a2enmod: downgrade perl 5.16 requirements to allow Ubuntu backports

2016-05-05 Thread Ondřej Surý
Package: apache2 Version: 2.4.10-10+deb8u4 Severity: wishlist File: /usr/sbin/a2enmod Tags: patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, could you please apply attached patch to allow easier Ubuntu precise backports? Cheers, Ondrej - -- Package-specific info: - -- System Informat

Re: [php-maint] Bug#827446: libapache2-mod-php5: postinst script changes MPM back to prefork, even with updates

2016-06-16 Thread Ondřej Surý
with apache2_switch_mpm. Maybe apache2 maintainers can shed some light on it. Cheers, -- Ondřej Surý Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server Knot Resolver (https://www.knot-resolver.cz/) – secure, privacy-aware, fast DNS(SEC) resolver Vše pro chleba (https://vseprochleba.cz) – Potřeb