Re: Backports to consider for 1.6.4?

2018-08-29 Thread William A Rowe Jr
On Wed, Aug 29, 2018 at 10:30 PM, William A Rowe Jr 
wrote:

>
> Second;
> Are we comfortable adding a dependency on autoconf-archive?
> This macro below dates back to 2010. If we are not, I can
> revert this.
>

And note I'll need to tweak the buildcheck.sh if we choose to keep
the dependency, it already triggers a failure on our trunk/1.7 build
machines which will need the autoconf-archive package installed.
I can have this reverted from trunk/1.7 first thing tomorrow if the
consensus is negative.


Backports to consider for 1.6.4?

2018-08-29 Thread William A Rowe Jr
First;
Pull request #5 https://github.com/apache/apr/pull/5/files
corresponds to https://bz.apache.org/bugzilla/show_bug.cgi?id=61985
Yann and I are neutral on dodging (fd == -1), what do others think?
This would be a trivial one-line fix if we adopt it.

Second;
Are we comfortable adding a dependency on autoconf-archive?
This macro below dates back to 2010. If we are not, I can
revert this. In any case, I think it would be unwise to introduce
this before 1.7, we generally haven't changed our build prereqs
for a subversion rebuild.

On Wed, Aug 29, 2018 at 10:01 PM,  wrote:

> Author: wrowe
> Date: Thu Aug 30 03:01:53 2018
> New Revision: 1839628
>
> URL: http://svn.apache.org/viewvc?rev=1839628=rev
> Log:
> Submitted by: Hongxu Jia 
> https://patch-diff.githubusercontent.com/raw/apache/apr/pull/8.patch
>
> While cross-compiling, the tools/gen_test_char could not
> be executed at build time, use AX_PROG_CC_FOR_BUILD to
> build native tools/gen_test_char
>
> Support explicit libtool by variable assigning before buildcheck.sh,
> it is helpful for cross-compiling (such as libtool=aarch64-linux-libtool)
>
> Backports: r1839627
>
> Modified:
> apr/apr/branches/1.7.x/   (props changed)
> apr/apr/branches/1.7.x/Makefile.in
> apr/apr/branches/1.7.x/build/   (props changed)
> apr/apr/branches/1.7.x/build/buildcheck.sh
> apr/apr/branches/1.7.x/configure.in
>
> Propchange: apr/apr/branches/1.7.x/
> 
> --
> --- svn:mergeinfo (original)
> +++ svn:mergeinfo Thu Aug 30 03:01:53 2018
> @@ -1,4 +1,4 @@
>  /apr/apr/branches/1.4.x:1003369,1101301
> -/apr/apr/trunk:733052,739635,741862,741866-741867,741869,
> 741871,745763-745764,746310,747990,748080,748361,748371,
> 748565,74,748902,748988,749810,760443,767895,775683,
> 782838,783398,783958,784633,784773,788588,789050,793192-
> 793193,794118,794485,795267,799497,800627,809745,809854,
> 810472,811455,813063,821306,829490,831641,832904,835607,
> 888669,892028,892159,892435,892909,896382,896653,899905,
> 901088,902077,902090,908427,910419,910597,917819,917837-
> 917838,923311,923320,925965,929796,930508,931973,932585,
> 951771,960665,960671,979891,983618,989450,990435,1003338,
> 100,107,1055657,1072165,1078845,1081462,1081495,1083038,1083242,
> 1084662,1086695,1088023,1089031,1089129,1089438,1099348,1103310,1183683,
> 1183685-1183686,1183688,1183693,1183698,1213382,1235047,1236970,1237078,
> 1237507,1240472,1340286,1340288,1340470,1341193,1341196,1343233,1343243,
> 1367050,1368819,1370494,1372018,1372022,1372093,1372849,1376957,1384764,
> 1389077,1400200,1402868,1405985,1406690,1420106,
> 1420109,1425356,1428809,143
>  8940,1438957-1438959,1442903,1449568,1456418,1459994,
> 1460179-1460180,1460241,1460399,1460405,1462738,1462813,1470186,1470348,
> 1475509,1478905,1480067,1481262,1481265,1484271,1487796,1489517,1496407,
> 1502804,1510354,1516261,1523384,1523479,1523484,1523505,1523521,1523604,
> 1523613,1523615,1523844-1523845,1523853,1524014,1524031,1528797,1528809,
> 1529488,1529495,1529515,1529521,1529668,1530786,1530800,1530988,1531554,
> 1531768,1531884,1532022,1533104,1533111,1533979,1535027,1535157,1536744,
> 1538171,1539374,1539389,1539455,1539603,1541054,1541061,1541486,1541655,
> 1541666,1541744,1542601,1542779,1543033,1543056,1548575,1550907,1551650,
> 1551659,1558905,1559382,1559873,1559975,1561040,1561260,1561265,1561321,
> 1561347,1561356,1561361,1561394,1561555,1571894,1575509,1578420,1587045,
> 1587063,1587543,1587545,1588878,1588937,1589982,1593611,1593614-1593615,
> 1593680,1594684,1594708,1595549,1597797,1597803,1604590,1604596,1604598,
> 1605104,1610854,1611023,1611107,160,167,1611120,1611125,1611184,
> 1611193,
>  1611466,1611515,1611517,1625173,1626564,1634615,1642159,1648830,1664406,
> 1664447,1664451,1664471,1664769-1664770,1664775,1664904,1664911,1664958,
> 1666341,1666411,1666458,111,1667420-1667421,1667423,1667900-1667901,
> 1667903,1667914-1667916,1667962,1669077,1671292,1671329,1671356,1671386,
> 1671389,1671513-1671514,1671957,1672354,1672366,1672495,1672575,1675644,
> 1675656,1675668,1676013,1683521,1685929,1696140,1696767,1722547,1722557,
> 1726928,1727020,1727160,1727175,1727199,1728957,1732582,1733451,1733594,
> 1733694,1733706,1733708,1733775,1734816,1736552,1738791,1738925,1750374,
> 1755709,1755740,1755746,1755758,1755954,1761279,1762326,1774712,1774973,
> 1775069,1776994,1776998,1788334,1788337,1788929,1789947,1789998,1790045,
> 1790200,1790296,1790302-1790304,1790330-1790331,1790436,1790439,1790444,
> 1790446,1790488,1790521,1790523,1790569,1790632,1791598,1791718,1791728,
> 1792621-1792622,1792625,1792961,1792963,1797415,1798105,1805380,1808039,
> 1808836,1808910,1809649,1810452,1813286,1813330,1814239-18142
>  40,1814326,1814329,1814331,1816527,1816628,1817485,
> 1819857-1819858,1819860-1819861,1819934-1819935,1820080,1820755,1822357,
> 1827534,1832203,1832691,1832985,1834253,1834494,1834541,1836235,1839068,
> 

buildbot failure in on apr-x64-macosx-trunk

2018-08-29 Thread buildbot
The Buildbot has detected a new failure on builder apr-x64-macosx-trunk while 
building . Full details are available at:
https://ci.apache.org/builders/apr-x64-macosx-trunk/builds/153

Buildbot URL: https://ci.apache.org/

Buildslave for this Build: svn-x64-macosx-dgvrs

Build Reason: The AnyBranchScheduler scheduler named 'on-apr-commit' triggered 
this build
Build Source Stamp: [branch apr/apr/trunk] 1839627
Blamelist: wrowe

BUILD FAILED: failed Build

Sincerely,
 -The Buildbot





Re: Release schedule of APR-1.6.4?

2018-08-29 Thread Eric .
Yes, I'm looking for that Solaris patch.

On Wed, 29 Aug 2018 at 17:53, Nick Kew  wrote:

>
> > On 29 Aug 2018, at 09:25, Eric .  wrote:
> >
> > Hi all,
> >
> > May I have an idea approximately when APR-1.6.4 will be released?
> > Thank you very much.
>
> If you read this list, you know exactly the same as all of us.
> Are you running on Solaris and looking for that poll patch,
> or do you have some other interest?
>
> --
> Nick Kew
>


Re: 1.6 release?

2018-08-29 Thread Nick Kew


> On 29 Aug 2018, at 16:08, William Kimball Jr.  
> wrote:
> 
> Speaking of suggestions, may I please suggest closing a glaring security hole 
> in apr_dbd_mysql, per https://bz.apache.org/bugzilla/show_bug.cgi?id=62342? I 
> have provided diffs for 1.5 -- because my organization uses RHEL 7, which 
> uses APR 1.5 -- and 2.0 -- because someone on this list instructed me to do 
> so.  I'm happy to do the same for 1.6.

Thanks, that looks as if it makes sense.

Currently we're looking at an APR-1.6 release ASAP.  Not APR-UTIL, which is 
where
an apr_dbd patch applies, so this isn't of immediate concern.  But yes, it 
looks like
something we should patch for future releases.

-- 
Nick Kew

Re: 1.6 release?

2018-08-29 Thread William Kimball Jr.
Speaking of suggestions, may I please suggest closing a glaring security 
hole in apr_dbd_mysql, per 
https://bz.apache.org/bugzilla/show_bug.cgi?id=62342? I have provided 
diffs for 1.5 -- because my organization uses RHEL 7, which uses APR 1.5 
-- and 2.0 -- because someone on this list instructed me to do so.  I'm 
happy to do the same for 1.6.


We've been using this patch in production -- where every 
server-to-server connection must be encrypted -- for several months and 
it's working very well for us.



On 8/26/2018 10:18 PM, William A Rowe Jr wrote:
Let's take a few more days on this. We are getting more and more good 
suggestions as git merge requests to girhub.com/apache/app 
 that are worth a look.


On Fri, Aug 24, 2018, 08:17 Eric Covener > wrote:


Starting a new thread as potential RM's may be filtering bugzilla
emails.

There are a lot of reports of PR62644 from solaris users of httpd, can
anyone RM?

-- 
Eric Covener

cove...@gmail.com 


--
This message has been scanned for viruses and
dangerous content by *MailScanner* , and is
believed to be clean. 



--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.



Re: 1.6 release?

2018-08-29 Thread Nick Kew


> On 27 Aug 2018, at 04:18, William A Rowe Jr  wrote:
> 
> Let's take a few more days on this. We are getting more and more good 
> suggestions as git merge requests to girhub.com/apache/app that are worth a 
> look.

What do you envisage doing with those days?

The motivation for a release is to fix one problem, and without risk of
introducing any new problem:

> There are a lot of reports of PR62644 from solaris users of httpd, can
> anyone RM?

Reviewing activity since 1.6.last, I see nothing else whose risk/reward profile
cries out for a backport, unless it be some of the Windows stuff I'm in no
position to judge.  Are you right now reviewing that?

I also looked at your github link.  Among those I checked out I don't see 
anything
there that should be dealt with in a hurry (i.e. now) rather than at leisure in 
the
context of a minor-bugfix-release.

-- 
Nick Kew

Re: Release schedule of APR-1.6.4?

2018-08-29 Thread Nick Kew


> On 29 Aug 2018, at 09:25, Eric .  wrote:
> 
> Hi all,
> 
> May I have an idea approximately when APR-1.6.4 will be released?
> Thank you very much.

If you read this list, you know exactly the same as all of us.
Are you running on Solaris and looking for that poll patch,
or do you have some other interest?

-- 
Nick Kew


Release schedule of APR-1.6.4?

2018-08-29 Thread Eric .
Hi all,

May I have an idea approximately when APR-1.6.4 will be released?
Thank you very much.