<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-extended/lighttpd, branch scarthgap-5.0.9</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=scarthgap-5.0.9</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=scarthgap-5.0.9'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2024-03-01T09:28:51+00:00</updated>
<entry>
<title>lighttpd: upgrade 1.4.73 -&gt; 1.4.74</title>
<updated>2024-03-01T09:28:51+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2024-02-28T07:32:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=44aefa3d12b00a37ea445a9afd667ba721b387e6'/>
<id>urn:sha1:44aefa3d12b00a37ea445a9afd667ba721b387e6</id>
<content type='text'>
Changelog:
 http://www.lighttpd.net/2024/2/19/1.4.74/

(From OE-Core rev: 23e2aa465d3aa3fb4b61c53eb7b84249ed9b3c20)

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: upgrade 1.4.72 -&gt; 1.4.73</title>
<updated>2023-11-05T11:28:40+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2023-11-03T07:15:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=61859172cbc3eab191e4824de0524c523620326a'/>
<id>urn:sha1:61859172cbc3eab191e4824de0524c523620326a</id>
<content type='text'>
Changelog:
============
  * [core] add .mkv to mimetype.assign builtin defaults
  * [core] warn if out-of-range value for config short
  * [mod_openssl] set default curves for ossl &lt; 1.1.0
  * [mod_h2] parse HEADERS flags sooner
  * [mod_h2] check send window before defer frame rd
  * [mod_h2] send GOAWAY to excessive request flood
  * [mod_h2] h2_parse_headers_frame() adjust args
  * [mod_h2] h2_recv_headers() parse trailers earlier
  * [mod_h2] send GOAWAY to excessive request flood
  * [mod_h2] discard new streams after GOAWAY sent
  * [mod_h2] h2_discard_headers() to HPACK-decode hdrs
  * [core] parse entire server.http-parseopts list
  * [mod_wstunnel] Sec-WebSocket-Protocol only if req hdr
  * [mod_h2] disable h2proto if mod_h2 was not found
  * [core] omit dlopen trace for mod_h2, mod_deflate
  * [mod_h2] defer input parsing if large output queue
  * [mod_h2] defer frame handling if stream pend close
  * [mod_h2] detect and log HTTP/2 rapid reset attack
  * [core] honor MBEDTLS_USE_PSA_CRYPTO for hash,rand
  * [mod_mbedtls] honor MBEDTLS_USE_PSA_CRYPTO for rand
  * [core] comment out li_rand_bytes() (unused)
  * [mod_mbedtls] handle mbedtls 3.x partial write
  * [mod_h2] detect and log HTTP/2 rapid reset attack
  * [mod_h2] detect and log HTTP/2 rapid reset attack
  * [mod_openssl] warn if openssl version &lt; 3.0.0
  * [mod_openssl] include openssl/hmac.h for boringssl

(From OE-Core rev: 5a39ce6614c97e1f919133dc718cc44d197c974f)

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: modernize lighttpd.conf</title>
<updated>2023-10-23T09:49:19+00:00</updated>
<author>
<name>Glenn Strauss</name>
<email>gstrauss@gluelogic.com</email>
</author>
<published>2023-10-20T13:30:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=7cba02e8be91aed00f9d86ebb5488f89a29f6a45'/>
<id>urn:sha1:7cba02e8be91aed00f9d86ebb5488f89a29f6a45</id>
<content type='text'>
- remove obsolete modules
- replace mod_compress directives with mod_deflate
- do not enable debug.log-request-handling by default
  (should not be enabled *by default* on any production system,
   especially not an embedded system)
- update TLS syntax for modern recommended use
  (separate files for certificate+chain, and private key)
- remove incorrect comment about server.event-handler
  lighttpd defaults correctly to use kqueue on *BSD systems
- remove ancient config which disables range requests for PDF
  (cargo-culted config from ~15 years ago to address problem
   in then-popular PDF client)
- use recommend config file include syntax
  (more efficient and more deterministic include file ordering)

(From OE-Core rev: b52a12e66d2f9ed0751b63cea01e96890da15998)

Signed-off-by: Glenn Strauss &lt;gstrauss@gluelogic.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: update init script</title>
<updated>2023-10-23T09:49:19+00:00</updated>
<author>
<name>Glenn Strauss</name>
<email>gstrauss@gluelogic.com</email>
</author>
<published>2023-10-20T13:30:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=0d3c7e9630c975b78ddccc2a2fd0c61fde98a552'/>
<id>urn:sha1:0d3c7e9630c975b78ddccc2a2fd0c61fde98a552</id>
<content type='text'>
- add configtest option
- add configtest before starting, restart, reload, force-reload
- change reload,force-reload to use lighttpd graceful restart
  via kill signal USR1

(From OE-Core rev: 589450af505de6a00ba7d7a3b647a514d1d1282f)

Signed-off-by: Glenn Strauss &lt;gstrauss@gluelogic.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: upgrade 1.4.71 -&gt; 1.4.72</title>
<updated>2023-10-23T09:49:19+00:00</updated>
<author>
<name>Glenn Strauss</name>
<email>gstrauss@gluelogic.com</email>
</author>
<published>2023-10-20T13:30:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=74fe34f1c099256a71d175a563ee2b3ec7c0f722'/>
<id>urn:sha1:74fe34f1c099256a71d175a563ee2b3ec7c0f722</id>
<content type='text'>
(From OE-Core rev: 935d8d65488d5c08a84f7c43bb067c6660fec7a7)

Signed-off-by: Glenn Strauss &lt;gstrauss@gluelogic.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: upgrade 1.4.69 -&gt; 1.4.71</title>
<updated>2023-06-09T12:55:20+00:00</updated>
<author>
<name>Petr Gotthard</name>
<email>petr.gotthard@advantech.cz</email>
</author>
<published>2023-06-08T11:53:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=5be5b6ee21baa32e35fd9a9d1e093edfa32f1a7f'/>
<id>urn:sha1:5be5b6ee21baa32e35fd9a9d1e093edfa32f1a7f</id>
<content type='text'>
lighttpd 1.4.70 omits building separate (unused) modules for:
mod_access mod_alias mod_evhost mod_expire mod_fastcgi mod_indexfile
mod_redirect mod_rewrite mod_scgi mod_setenv mod_simple_vhost mod_staticfile
https://www.lighttpd.net/2023/5/10/1.4.70/

Therefore, the lighttpd-module-indexfile, lighttpd-module-staticfile and
lighttpd-module-access no longer exist and must be removed from
RDEPENDS and RRECOMMENDS.

lighttpd 1.4.71 split out the http/2 support into optional separate
module (mod_h2). By default the mod_h2 is not enabled.
https://www.lighttpd.net/2023/5/27/1.4.71/

(From OE-Core rev: ae40fb21a0f85ce02fc137c6e3cce2a90778d75f)

Signed-off-by: Petr Gotthard &lt;petr.gotthard@advantech.cz&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: upgrade 1.4.68 -&gt; 1.4.69</title>
<updated>2023-02-15T10:21:34+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2023-02-13T02:37:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=7edabcd0b52071bf3b75aac746505e423d42a29c'/>
<id>urn:sha1:7edabcd0b52071bf3b75aac746505e423d42a29c</id>
<content type='text'>
fix-missing-test.patch
removed since it's included in new verion.

(From OE-Core rev: b88ffd2c41d99099d444e9a05b6d1b84090160a0)

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: upgrade 1.4.67 -&gt; 1.4.68</title>
<updated>2023-02-09T09:57:24+00:00</updated>
<author>
<name>Alexander Kanavin</name>
<email>alex.kanavin@gmail.com</email>
</author>
<published>2023-02-08T07:21:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=7573d38c01099add660dc98acd20bfaa2c6caae2'/>
<id>urn:sha1:7573d38c01099add660dc98acd20bfaa2c6caae2</id>
<content type='text'>
Rename options where appropriate. pcre option supports pcre2 now, so convert to that.

(From OE-Core rev: 7da38c6bdce5692b1c0b24c7d7694123b5329588)

Signed-off-by: Alexander Kanavin &lt;alex@linutronix.de&gt;
Signed-off-by: Luca Ceresoli &lt;luca.ceresoli@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: upgrade 1.4.66 -&gt; 1.4.67</title>
<updated>2022-10-28T08:44:52+00:00</updated>
<author>
<name>wangmy</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2022-10-11T08:58:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=75c609f17fac86b90aafdc7900fc60e06dcc1bbf'/>
<id>urn:sha1:75c609f17fac86b90aafdc7900fc60e06dcc1bbf</id>
<content type='text'>
Changelog:
=============
  * Update comment about TCP_INFO on OpenBSD
  * [mod_ajp13] fix crash with bad response headers (fixes #3170)
  * [core] handle RDHUP when collecting chunked body
  * [core] tweak streaming request body to backends
  * [core] handle ENOSPC with pwritev() (#3171)
  * [core] manually calculate off_t max (fixes #3171)
  * [autoconf] force large file support (#3171)
  * [multiple] quiet coverity warnings using casts
  * [meson] add license keyword to project declaration

(From OE-Core rev: 7a399862bb2e1503fbffa18e7ec0767643f76132)

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>lighttpd: fix CVE-2022-41556</title>
<updated>2022-10-25T12:42:03+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2022-10-21T16:16:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=7deed5f7b1a8491f8706a460d333000eb1810778'/>
<id>urn:sha1:7deed5f7b1a8491f8706a460d333000eb1810778</id>
<content type='text'>
Backport the fix from upstream to fix this CVE.

(From OE-Core rev: 59f69125fb00dc8fd335f32fe6898e7a480141e4)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
</feed>
