summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* nginx-1.9.15-RELEASErelease-1.9.15Maxim Dounin2016-04-191-0/+55
|
* HTTP/2: send the output queue after emitting WINDOW_UPDATE.Valentin Bartenev2016-04-191-0/+10
| | | | | | | | The WINDOW_UPDATE frame could be left in the output queue for an indefinite period of time resulting in the request timeout. This might happen if reading of the body was triggered by an event unrelated to client connection, e.g. by the limit_req timer.
* HTTP/2: skip data frames in case of internal errors.Valentin Bartenev2016-04-191-0/+2
| | | | | | This prevents possible processing of such frames and triggering rb->post_handler if an error occurred during r->request_body initialization.
* HTTP/2: don't send WINDOW_UPDATE for an empty request body.Valentin Bartenev2016-04-191-12/+13
| | | | | | | Particularly this prevents sending WINDOW_UPDATE with zero delta which can result in PROTOCOL_ERROR. Also removed surplus setting of no_flow_control to 0.
* Thread pools: memory barriers in task completion notifications.Maxim Dounin2016-04-191-0/+4
| | | | | | | | | | The ngx_thread_pool_done object isn't volatile, and at least some compilers assume that it is permitted to reorder modifications of volatile and non-volatile objects. Added appropriate ngx_memory_barrier() calls to make sure all modifications will happen before the lock is released. Reported by Mindaugas Rasiukevicius, http://mailman.nginx.org/pipermail/nginx-devel/2016-April/008160.html.
* HTTP/2: write logs when refusing streams with data.Maxim Dounin2016-04-181-0/+4
| | | | | | Refusing streams is known to be incorrectly handled at least by IE, Edge and Safari. Make sure to provide appropriate logging to simplify fixing this in the affected browsers.
* HTTP/2: send WINDOW_UPDATE instead of RST_STREAM with NO_ERROR.Valentin Bartenev2016-04-141-0/+22
| | | | | | | | | | | | | | | | | After the 92464ebace8e change, it has been discovered that not all clients follow the RFC and handle RST_STREAM with NO_ERROR properly. Notably, Chrome currently interprets it as INTERNAL_ERROR and discards the response. As a workaround, instead of RST_STREAM the maximum stream window update will be sent, which will let client to send up to 2 GB of a request body data before getting stuck on flow control. All the received data will be silently discarded. See for details: http://mailman.nginx.org/pipermail/nginx-devel/2016-April/008143.html https://bugs.chromium.org/p/chromium/issues/detail?id=603182
* HTTP/2: refuse streams with data until SETTINGS is acknowledged.Valentin Bartenev2016-04-142-1/+8
| | | | | | | | | A client is allowed to send requests before receiving and acknowledging the SETTINGS frame. Such a client having a wrong idea about the stream's could send the request body that nginx isn't ready to process. The previous behavior was to send RST_STREAM with FLOW_CONTROL_ERROR in such case, but it didn't allow retrying requests that have been rejected.
* HTTP/2: deduplicated some code in ngx_http_v2_state_headers().Valentin Bartenev2016-04-141-18/+13
| | | | No functional changes.
* FastCGI: skip special bufs in buffered request body chain.Valentin Bartenev2016-04-111-0/+5
| | | | | | | | | | | This prevents forming empty records out of such buffers. Particularly it fixes double end-of-stream records with chunked transfer encoding, or when HTTP/2 is used and the END_STREAM flag has been sent without data. In both cases there is an empty buffer at the end of the request body chain with the "last_buf" flag set. The canonical libfcgi, as well as php implementation, tolerates such records, while the HHVM parser is more strict and drops the connection (ticket #950).
* Fixed NGX_CONF_TAKE1/NGX_CONF_FLAG misuse (as in e444e8f6538b).Ruslan Ermilov2016-04-121-1/+1
|
* Fixed typos.Alessandro Ghedini2016-04-111-2/+2
|
* Removed redundant "u" format specifier.Ruslan Ermilov2016-04-085-6/+6
| | | | It is implied for "x" and "X".
* Simplified ngx_unix_recv() and ngx_readv_chain().Ruslan Ermilov2016-04-082-6/+2
| | | | This makes ngx_unix_recv() and ngx_udp_unix_recv() differ minimally.
* Merged implementations of ngx_unix_recv().Valentin Bartenev2016-04-081-59/+11
| | | | | There's no real need in two separate implementations, with and without kqueue support.
* Fixed small inconsistency in handling EOF among receive functions.Valentin Bartenev2016-04-082-42/+41
| | | | Now all functions always drop the ready flag in this case.
* Merged implementations of ngx_udp_unix_recv().Valentin Bartenev2016-04-081-47/+4
| | | | | There's no real need in two separate implementations, with and without kqueue support.
* Fixed spelling.Josh Soref2016-04-076-10/+10
|
* Version bump.Ruslan Ermilov2016-04-071-2/+2
|
* release-1.9.14 tagMaxim Dounin2016-04-051-0/+1
|
* nginx-1.9.14-RELEASErelease-1.9.14Maxim Dounin2016-04-051-0/+58
|
* Compatibility with FreeBSD 2.2.9.Maxim Dounin2016-04-011-2/+3
| | | | | | | | | | | Added (RTLD_NOW | RTLD_GLOBAL) to dlopen() test. There is no RTLD_GLOBAL on FreeBSD 2.2.9. Added uint32_t test, with fallback to u_int32_t, similar to uint64_t one. Added fallback to u_int32_t in in_addr_t test. With these changes it is now possible to compile nginx on FreeBSD 2.2.9 with only few minor warnings (assuming -Wno-error).
* Configure: improved multiple types handling in auto/types/typedef.Maxim Dounin2016-04-011-1/+5
|
* Configure: fixed autotest source code logging.Maxim Dounin2016-04-012-6/+9
| | | | | | Fixed a regression introduced in rev. 434548349838 that prevented auto/types/sizeof and auto/types/typedef properly reporting autotest source code to autoconf.err in case of test failure.
* HTTP/2: support for unbuffered upload of request body.Valentin Bartenev2016-04-013-3/+138
|
* HTTP/2: rewritten handling of request body.Valentin Bartenev2016-04-014-258/+238
| | | | | | | | | | | | | There are two improvements: 1. Support for request body filters; 2. Receiving of request body is started only after the ngx_http_read_client_request_body() call. The last one fixes the problem when the client_max_body_size value might not be respected from the right location if the location was changed either during the process of receiving body or after the whole body had been received.
* HTTP/2: sending RST_STREAM with NO_ERROR to discard request body.Valentin Bartenev2016-04-012-14/+25
| | | | | | | | | | | | | | RFC 7540 states that "A server can send a complete response prior to the client sending an entire request if the response does not depend on any portion of the request that has not been sent and received. When this is true, a server MAY request that the client abort transmission of a request without error by sending a RST_STREAM with an error code of NO_ERROR after sending a complete response (i.e., a frame with the END_STREAM flag)." This should prevent a client from blocking on the stream window, since it isn't maintained for closed streams. Currently, quite big initial stream windows are used, so such blocking is very unlikly, but that will be changed in the further patches.
* Core: removed incorrect GCC 2.7 check.Maxim Dounin2016-04-011-5/+0
| | | | | | | | It was broken since introduction (__GNU__ instead of __GNUC__) and did nothing. Moreover, GCC 2.7 is happy with the normal version of the code. Reported by Joel Cunningham, http://mailman.nginx.org/pipermail/nginx-devel/2016-March/007964.html.
* Trailing space fix.Maxim Dounin2016-04-011-1/+1
|
* SSL: SSLeay_version() is deprecated in OpenSSL 1.1.0.Maxim Dounin2016-03-312-3/+13
| | | | | | | | SSLeay_version() and SSLeay() are no longer available if OPENSSL_API_COMPAT is set to 0x10100000L. Switched to using OpenSSL_version() instead. Additionally, we now compare version strings instead of version numbers, and this correctly works for LibreSSL as well.
* SSL: X509 was made opaque in OpenSSL 1.1.0.Sergey Kandaurov2016-03-311-0/+4
| | | | | To increment reference counters we now use newly introduced X509_up_ref() function.
* SSL: EVP_MD_CTX was made opaque in OpenSSL 1.1.0.Sergey Kandaurov2016-03-311-9/+12
|
* SSL: RSA_generate_key() is deprecated in OpenSSL 1.1.0.Maxim Dounin2016-03-314-4/+4
| | | | OpenSSL removed support for all 40 and 56 bit ciphers.
* SSL: initialization changes for OpenSSL 1.1.0.Maxim Dounin2016-03-312-1/+13
| | | | | | | | | | | | | | OPENSSL_config() deprecated in OpenSSL 1.1.0. Additionally, SSL_library_init(), SSL_load_error_strings() and OpenSSL_add_all_algorithms() are no longer available if OPENSSL_API_COMPAT is set to 0x10100000L. The OPENSSL_init_ssl() function is now used instead with appropriate arguments to trigger the same behaviour. The configure test changed to use SSL_CTX_set_options(). Deinitialization now happens automatically in OPENSSL_cleanup() called via atexit(3), so we no longer call EVP_cleanup() and ENGINE_cleanup() directly.
* SSL: get_session callback changed in OpenSSL 1.1.0.Maxim Dounin2016-03-311-4/+11
|
* SSL: guarded error codes not present in OpenSSL 1.1.0.Maxim Dounin2016-03-311-1/+4
|
* SSL: reasonable version for LibreSSL.Maxim Dounin2016-03-312-3/+9
| | | | | | | | | | LibreSSL defines OPENSSL_VERSION_NUMBER to 0x20000000L, but uses an old API derived from OpenSSL at the time LibreSSL forked. As a result, every version check we use to test for new API elements in newer OpenSSL versions requires an explicit check for LibreSSL. To reduce clutter, redefine OPENSSL_VERSION_NUMBER to 0x1000107fL if LibreSSL is used. The same is done by FreeBSD port of LibreSSL.
* Removed the prototype mysql module.Ruslan Ermilov2016-03-318-773/+3
|
* Fixed ngx_os_signal_process() prototype.Ruslan Ermilov2016-03-315-8/+8
|
* Fixed ngx_pid_t formatting in ngx_sprintf() and logging.Sergey Kandaurov2016-03-313-8/+8
|
* Fixed format specifiers in ngx_sprintf().Sergey Kandaurov2016-03-312-3/+3
|
* Fixed logging.Sergey Kandaurov2016-03-3139-66/+67
|
* Events: fixed logging.Sergey Kandaurov2016-03-312-12/+19
|
* Fixed logging with variable field width.Sergey Kandaurov2016-03-316-10/+11
|
* Fixed logging in close error handling.Sergey Kandaurov2016-03-312-2/+2
|
* Fixed mistranslated phrase.Ruslan Ermilov2016-03-301-1/+1
|
* Events: fixed test building with eventport on OS X.Ruslan Ermilov2016-03-301-1/+1
| | | | Broken in d17f0584006f (1.9.13).
* Style.Ruslan Ermilov2016-03-3043-215/+215
|
* Version bump.Ruslan Ermilov2016-03-301-2/+2
|
* release-1.9.13 tagMaxim Dounin2016-03-291-0/+1
|