Loading STATUS +10 −9 Original line number Diff line number Diff line Loading @@ -115,17 +115,18 @@ RELEASE SHOWSTOPPERS: *) Looping during check_headers() failure. Fix potential looping in new check_headers() due to new pattern of ap_die() from http header filter. Also, remove the bad headers explicitly. ap_die() from http header filter. Also, clear the previous headers and body explicitly. Trunk patch: https://svn.apache.org/r1773293 https://svn.apache.org/r1773293 https://svn.apache.org/r1773761 https://svn.apache.org/r1773779 https://svn.apache.org/r1773812 https://svn.apache.org/r1773861 https://svn.apache.org/r1773862 https://svn.apache.org/r1773865 2.4.x patch: trunk works +1: covener, jim -1: wrowe covener: This is not ideal but the looping/OOM is bad. jim: with the understanding that more work post release wrowe: *IIUC* If we are transmitting the discarded body to the client, and switching the code to 500, this isn't really a salvagable resolution. Two alternatives suggested to the list a few days ago. ylavic: how about r1773761? +1: ylavic *) Final CVE check Loading Loading
STATUS +10 −9 Original line number Diff line number Diff line Loading @@ -115,17 +115,18 @@ RELEASE SHOWSTOPPERS: *) Looping during check_headers() failure. Fix potential looping in new check_headers() due to new pattern of ap_die() from http header filter. Also, remove the bad headers explicitly. ap_die() from http header filter. Also, clear the previous headers and body explicitly. Trunk patch: https://svn.apache.org/r1773293 https://svn.apache.org/r1773293 https://svn.apache.org/r1773761 https://svn.apache.org/r1773779 https://svn.apache.org/r1773812 https://svn.apache.org/r1773861 https://svn.apache.org/r1773862 https://svn.apache.org/r1773865 2.4.x patch: trunk works +1: covener, jim -1: wrowe covener: This is not ideal but the looping/OOM is bad. jim: with the understanding that more work post release wrowe: *IIUC* If we are transmitting the discarded body to the client, and switching the code to 500, this isn't really a salvagable resolution. Two alternatives suggested to the list a few days ago. ylavic: how about r1773761? +1: ylavic *) Final CVE check Loading