3 *) Provide the NO_SUEXEC_FOR_AP_USER_N_GROUP macro for building
4 mod_fastcgi with the AP13 suexec behaviour (don't use suexec
5 if httpd's user and group match that needed for the application).
7 *) Prevent the use of all but the "auth" directives from being used
8 anywhere but in global scope. Prevent more than one instance
9 of the FastCgiWrapper directive.
11 *) Return NOT_FOUND (404) or FORBIDDEN (403) instead of
12 INTERNAL_SERVER_ERROR (500) when there are configuration issues
13 or the script does't exist. Suggested by Jeff Lawson [bovine@ud.com].
17 *) [*nix Security] - When FastCgiWrapper (FastCgiSuexec) was in use
18 and a vhost configured to use the same uid/gid as the main
19 server, mod_fastcgi would not bother using the wrapper (suexec)
20 because its effective uid/gid was already appropriate. This is
21 consistent with Apache's v1.3 mod_cgi behaviour. There are two
22 problems with this approach: 1) when FastCgWrapper is in use
23 mod_fastcgi's process manager keeps its root privileges (as its
24 real uid/gid) so it can terminate the applications its starts -
25 this privilege was being passed to applications when the use of
26 the wrapper was bypassed 2) wrappers are often employed to
27 perform functionality beyond setting the uid/gid - by not calling
28 the wrapper under certain circumstances, application invocation
29 environments were inconsistent. With this change, the wrapper is
30 always used (when enabled) under both Apache 1.3 and 2.
31 Reported by Michael Richards [michael@fastmail.ca].
33 *) [*nix/AP2] Use the vhost uid/gid instead of the server uid/gid
34 for dynamic application invocation when the FastCgiWrapper is in use.
35 Reported by Michael Richards [michael@fastmail.ca]
37 *) [*nix] Fix handling of FastCgiWrapper when passed a real path,
38 i.e. other than "on" or "off". Michael Richards [michael@fastmail.ca]
40 *) Eliminate the logging of "incomplete headers (0 bytes) received from
41 server" when a client aborts.
43 *) [WIN32] Fix a delay in handling large POSTs to named pipe based
44 servers. Philip Gladstone [philip@okena.com]
46 *) [*nix/AP2] Prevent the module from being initalized twice at startup
47 (resulting in confusing error messages to the log).
49 *) Eliminate the need for SetHandler or AddHandler with static or
50 external applications.
52 *) Limit PM requests to start a dynamic application
53 to 5sec to prevent endless spinning (this is a drop-dead
54 limit that should only occur if the socket/named_pipe directory
55 is removed out from under a running server).
57 *) [*nix] Change the default socket directory from /tmp/fcgi to:
59 Apache2 - RUNTIMEDIR/fastcgi
61 *) Add -user & -group args to FastCgiServer and FastCgiExternalServer
62 for use with wrappers (in lieu of finding the user/group associated
63 with a virtual host - under Apache2 this isn't accomodated).
65 *) [WIN32] Under Apache2, require v2.0.41 or later in order to pickup my
66 apr_proc_create() changes.
68 *) Log when invoking and restoring the restart backoff policy.
70 *) [WIN32] Prevent intermittent ReadFile() failures (properly initialize the
71 OVERLAPPED structure).
73 *) Eliminate need for dummy files for external servers under Apache2
75 *) Fix auth compatibility mode handling for access checker and authorizer
77 *) Fix HEAD request handling. Based on a patch by
78 Chris Lightfoot [chris@ex-parrot.com]
80 *) [*nix] When autoupdate is enabled touch the socket when restarting
81 the processes to prevent further requests.
82 Eckebrecht von Pappenheim [evp@heise.de]
84 *) Apache 2.0 support.
86 *) [WIN32] Don't read from a potentially closed named pipe.
87 Philip Gladstone [philip@okena.com]
89 *) Require the Apache version 1.3.6 or later to eliminate some signal
92 *) [WIN32] Use asyncronous io with named pipes instead of polled
93 nonblocking io. This should eliminate the last of the npipe issues.
95 *) Handle an application returning a complete and valid response without
96 having consumed all of the data sent to it.
98 *) Consume remaining client data (RESPONDERs only) if any.
100 *) Add support for backing off attempts to start applications that continuously
101 fail to start. Three new macros defined in mod_fastcgi.h control this
102 behaviour: MAX_FAILED_STARTS, RUNTIME_SUCCESS_INTERVAL, FAILED_STARTS_DELAY
104 *) [WIN32] Add (back) support for use of TerminateProcess() to accomodate
105 applications that do not (properly) support the shutdown event (this
106 feature was introduced in fcgi2 2.2.2 and improved in 2.2.4). The
107 new macro WIN32_SHUTDOWN_GRACEFUL_WAIT in mod_fastcgi.h conrols the
108 interval between signaling a proper shutdown and wacking the process(s)
109 with a TerminateProcess().
111 *) [WIN32] Don't set the OVERLAPPED_IO flag on NamedPipe listen HANDLEs -
112 setting it was just plain broken.
114 *) [WIN32] Fix the accept mutex - all applications were sharing one!?
116 *) Fix 'FastCgiConfig -autoUpdate'.
118 *) Fix 'FastCgiConfig -flush'.
120 *) Prevent silly maxProcesses and processSlack combinations.
121 Dmitry Dorofeev [dima@yasp.com]
123 *) Properly handle the killing of idle processes when one takes a long time
124 to exit once signaled down (or the config is funky).
125 Dmitry Dorofeev [dima@yasp.com]
127 *) Always kill the youngest instance of an application. Suggested by
128 Dmitry Dorofeev [dima@yasp.com]
132 *) Delay the logging of write errors to the pm to account for shutdown/restart.
134 *) (Win32) An assortment of fixes.
136 *) Fix some broken casts that were likely the cause of an assert.
138 *) Win32. Eliminate forward slashes from the named pipe path name.
139 Gerald Richter [richter@ecos.de]
141 *) SIGUSR2 is no longer blocked in the process manager and the fastcgi
142 applications it spawns. [ryans@amazon.com]
144 *) Added support for the -flush argument to FastCgiConfig.
145 Eric Sit [esit@alum.mit.edu]
147 *) Change the "which call to module_init() is this" check to a more
148 reliable approach. Doru Petrescu [pdoru@kappa.ro]
150 *) Close the old pipe file descriptor in apache main on USR1/HUP
151 (elimnates a small leak). James E. Jurach Jr. jjurach@fundsxpress.com
153 *) Fix a bug in fcgi_config_set_authoritative_slot(). Tetsuya Furukawa
154 [tetsuya@secom-sis.co.jp]
156 *) Eliminate the use of locks to assist in the clean shutdown of
157 applications. Instead, it is assumed that applications handle
158 termination signals properly (this is now embedded in the C
161 *) Fix Win32 process termination. Proper operation requires the use of
162 an updated application lib (termination is now signalled with an
163 Event and handled by specialized thread).
165 *) Docs cleanup. Andrew Benham [adsb@bigfoot.com]
167 *) Added code so if the last instance of a dynamic application died without
168 provocation, then don't restart it if singleThreshold > 0 (i.e. if the
169 configuration allows the last instance to be killed, then allow it to die).
170 Andrew Benham [adsb@bigfoot.com]
172 *) Fix the loadFactor calculation used to determine when dyanmic
173 applications could be killed off due to low demand [adsb@bigfoot.com].
175 *) Fix a deadlock condition that could occur with Win32 named
178 *) Fix a potential deadlock condition when FastCGI application
179 sent responses while still reading the client request (POST data).
183 *) Allow absolute pathnames in the -socket argument. Suggested by
184 Christian Jaeger [christian.jaeger@sl.ethz.ch].
186 *) Don't invoke suexec when the user/group for the fastcgi application
187 is the same as the apache main server. This is consistent with
188 apache's suexec handling. Suggested by Nikolaus Rath [Nikolaus@rath.org].
190 *) Reset the apache drop dead timer upon successful read or writes
191 to/from the client. This eliminates timeouts that were occuring
192 during the large file transfers to/from slow clients.
194 *) Support generic wrappers such as cgiwrap by eliminating dependencies
195 on Apache's SUEXEC, renaming the FastCgiSuexec directive
196 FastCgiWrapper and eliminating any checks regarding the target
197 application (this is the repsonibility of the wrapper).
199 *) Fix a nasty bug that occurred when a client aborted a POST request
200 before the connection to a dynamic FastCGI application was opened.
201 The application's lock file descriptor wasn't setup but was being
202 closed which resulted in FD0 being closed. Normally this is open to
203 /dev/null and should pose no problems except that because the FD
204 was available it was being returned by Apache's accept(). This
205 caused it to be registered for pool cleanup. mod_cgi though moves
206 the CGI stdin pipe to FD0 and thus it was getting waxed during pool
207 cleanup. Problem identified by checksum@163.net.
209 Changes with mod_fastcgi 2.2.8
211 *) Eliminate the concept of disabled applications. If a failure
212 occurs trying to setup an application (e.g. bind() error) its
213 tried repeatedly every init-start-delay seconds.
215 *) Tweak to Makefile.tmpl to support DSOs. Dave Hill [ddhill@zk3.dec.com]
217 Changes with mod_fastcgi 2.2.6
219 *) Shutdown the PM when Apache appears to have disappeared.
221 *) seteuid() tweak for HP-UX 11. Milton L. Hankins [mlh@swl.msd.ray.com]
223 *) (Win32) More dynamic fixes.
225 *) (Win32) Eliminate the per application named pipe mutex. Its now
226 per process to keep the lib happy (the use _FCGI_MUTEX_ should
227 removed from the lib). This allows pipe-based applications to
228 now handle multiple simoultanous requests (one per process).
230 *) Increase the number of open FDs we look to close when spawning apps.
232 *) Prevent an assert from popping unnecessarily.
234 *) (Win32) Add support for interpretter scripts.
236 *) (Win32) Fix named pipe handling (problems with large responses).
238 *) (Win32) Remove the "can exec" check.
240 Changes with mod_fastcgi 2.2.4
242 *) Beta WinNT support. David Allen [djallen@raleigh.ibm.com] and
243 Rob Saccoccio [robs@chelsea.net]
245 *) Remove request type restriction (GET and POST only) in order to support
246 Web DAV requests. Scott Robertson [sroberts@codeit.com]
248 *) Allow requests for URLs such as /server/some/other/qualifier to match a
249 FastCGI server defined as /server. This was done primarily for Java
250 Servlets, but is generically useful.
252 *) Change the comm between the PM and the request handlers from a regular
253 file to a pipe and an assortment of other dynamic fixes.
255 *) Log dynamic process termination scheduling and the resulting
256 process exit notification.
258 *) Change the default singleThreshhold from 10 to 0 to prevent the last dynamic
259 application process from being killed off due to low demand.
261 *) Clean up FastCGI application pathnames (e.g. remove duplicate slashes).
263 *) Fix bugs that prevented dynamic processes from being shutdown when
264 the load subsided. Lars Heete [heete@do.isst.fhg.de]
266 *) Prevent dynamic processes from being scheduled to be started before
267 the init-start-delay or restart-delay period expires. This prevents
268 the queuing of process start requests while an application which has
269 a long initialization period starts up.
271 *) When suexec is enabled, allow the process manager to become root again in
272 order to signal applications it spawned.
274 *) Change the "server started" log message level from INFO to WARN.
276 *) Fix dynamic server "Connection Refused" handling.
278 *) Fix demand-based dynamic process spawing (uses a more portable approach).
280 *) Add -idle-timeout arg to FastCgiServer, FastCgiExternalServer, and
281 FastCgiConfig. mod_fastcgi will now abort a connection if inactive for
282 longer than this period. It applies to the initiation of connections as
283 well (and thus is similar to appConnTimeout). Default is 30 seconds.
285 *) appConnTimeout is 0 by default now resulting in blocking connect()s. This
286 is more platform portable/predicable.
288 *) Leave STDOUT and STDERR open to the main server error_log. This should
289 eliminate a pile of protocol errors and having to track down 3rd party
290 libs writing to stderr inadvertantly. This doesn't mean these shouldn't
291 be fixed in the application to use the FastCGI I/O, it just allows these
292 applications to run when previously they'd crash and burn.
294 *) Add the pass-header arg to server directives.
296 *) Allow supplementary groups to be passed to spawned FastCGI applications (as
297 is done for CGI) - at least until PR2580 is resolved.
299 *) Initialize the default (empty) environment in a more socially acceptable
302 *) Miscellaneous doc improvements based on notes I've collected up over the
305 *) Fix a bug in the stderr handling introduced in 2.2.2. There were conditions
306 that resulted in not or improperly terminated strings.
308 *) Fix the call to setsockopt() to disable Nagle. [based on a bug report by
309 Johannes Plassmann <johannes.plassmann@pdb.siemens.de>]
311 Changes with mod_fastcgi 2.2.2
313 *) Added support for blocking connect()s by setting appConnTimeout to 0.
314 Non-blocking connect()s (the default) can be troublesome on some platforms.
315 Its expected that blocking connect()s will become the default (and
316 non-blocking connect()s will become optional) in the next release.
318 *) Dump a compile time error if the version of Apache is too old.
320 *) Wrap the SIGPIPE handler manipulation code such that it is only applicable
321 to Apache releases prior to 1.3.6.
323 *) Minor tweaks for RUSSIAN_APACHE. [Sergey Gershtein <sg@mplik.ru>]
327 Always restart a failed dynamic application if it is the last instance.
328 This means there once started there will always be at least one process
329 instance of a dynamic application.
331 Send PLEASE_START to the PM when a connect() results in an ECONNREFUSED.
332 ECONNREFUSED means the listen queue is full (or there isn't one). Asking
333 the PM to start (another) application instance may help empty it faster.
335 Change two sleep() calls to select() based snoozes because alarm() is in
336 effect and sleep() and alarm() don't always play nice together.
338 Fixed a couple of error messages.
340 *) Fix -listen-queue-depth arg on FastCgiConfig (dynamic). Previously it
341 was ignored and the default was always used.
343 *) Allow the -initial-env argument to be used to pass variables from the
344 Apache process environment to the FastCGI server (by specifying a
345 variable name without the "=" or a value). [suggested by
346 Martin Lichtin <lichtin@oanda.com>]
348 *) Cleanup some debug macros.
350 *) Improved script stderr handling. [based on suggestions by
351 David Birnbaum <davidb@chelsea.net>]
353 *) Added IRIX and FreeBSD to the list of supported platforms and other minor
354 updates to the INSTALL doc.
356 *) Changed the default listen-queue-depth (FCGI_DEFAULT_LISTEN_Q) from
357 5 to 100. Its still configurable with the -listen-queue-depth option.
358 This should help eliminate the FAQ - Why do I see "Connection Refused"
361 *) Fix a bug in FastCgiExternalServer that broke support for external servers
362 on other hosts. [Dave Neuer <dneuer@futuristics.net>]
364 Changes with mod_fastcgi 2.2.1
366 *) Updates to the INSTALL doc to describe building as a DSO.
368 *) If the FastCgiIpcDir directive was in use and "httpd -t" was issued while
369 Apache was running ("apachectl restart" does this), the contents of the
370 dynamic directory (dynamic sockets and the mbox) would be blown away
373 *) Add an extern declaration for ap_sys_siglist (its exposed but not in any
374 Apache header file) to prevent a compile error on systems without
377 *) During auth requests, the subprocess_env table was left holding variables
378 sent to the auth FastCGI server (including REMOTE_PASSWD!) which means they
379 were passed to other processing phases (such as CGI/FastCGI). The
380 subprocess_env is now restored to its pre-auth condition.
382 *) Added a FastCGI Authorizer Role compatibility mode which implements the
383 specification to the tee. Use -compat arg with any of the Auth server
384 directives. This is intended for new and existing FastCGI authorizer
385 applications that require compatibility with other server implementations.
387 *) Fix logging from the process manager. Previously, all calls to the
388 logging routines used NULL for the server_rec. This works fine in a dev
389 environment, but results in most of these messages being tossed by
390 log_error_core() because DEFAULT_LOGLEVEL is too low. Odd logic.
392 *) Always setup fr->header so that in the event the FastCGI server
393 doesn't get a valid FastCGI protocol header over the wire, we
394 can still print our error message to the log from do_work().
396 *) Fix a compile error in open_connection_to_fs() on systems with TCP_NODELAY
397 defined (Don Locrasto [locrasto@iceminer.com]).
399 Changes with mod_fastcgi 2.2.0
401 *) Serious rewrite of mod_fastcgi.html. An example conf will have
402 to wait until another time - I'm burned out on docs updates.
404 *) Add to the mod_fastcgi to the server version string.
406 *) SCO doesn't like the const in the arg to inet_addr() and
409 *) Use Apache's NET_SIZE_T to get the correct arg type for getsockopt().
411 *) Deleted redundant header files from fcgi.h.
413 *) Full path names are no longer required for directives which take
414 file names as arguments. Like other Apache directives you can
415 specify paths from server_root (don't start with a "/").
417 *) The fcgiKillMgr is gone. This intermediate process sat between
418 the Apache parent and the FastCGI Process Manager under Apache
419 1.2. The process manager tries to name itself fcgi_pm (it used
422 *) Authentication, Authorization, and Access phases are now
423 supported. I've bent the FastCgi spec a bit: as many of the standard
424 environment variables (that were easy) are sent (the spec says don't
425 send some by name), all headers (except Status) sent by the auth
426 FastCgi server are passed to subprocesses (CGI/FastCGI invocations)
427 as environment variables rather than just those prefixed by
428 "Variable-". Custom responses for auth failures aren't supported
429 (yet.. we'll see what the demand for this is like). In addition to
430 the FastCGI protocol defined environment variable "FCGI_ROLE" being
431 set to "AUTHORIZER" an environment variable "FCGI_APACHE_ROLE" is
432 set indicating which of the three phases is being processed. See
433 the docs for info on the new per-directory directives:
435 FastCgiAuthenticator, FastCgiAuthenticatorAuthoritative,
436 FastCgiAuthorizer, FastCgiAuthorizerAuthoritative,
437 FastCgiAccessChecker, FastCgiAccessCheckerAuthoritative
439 *) The code has been broken into logical chunks making figuring it
440 out much easier. All of the #defines a user may want to change are
441 now in mod_fastcgi.h.
443 *) All the logging has been converted to the "supported" Apache
444 logging routines, ap_log_error() and ap_log_rerror(). Log entries
445 for request specific errors should now be directed to the correct
446 server errorlog (if your running more than one). Some attempt has
447 been made at setting appropriate log levels (comments of course are
448 welcome) and printing errno info when its of value. All of log
449 messages now have "FastCGI" in them (nice for grep).
451 *) All of the calls to Apache routines have been updated to the ap_
452 convention, eliminating the need for the compat header.
454 *) By default we no longer flush every piece of data we get from the
455 FastCGI server to the client. This allows the FastCGI server to
456 release without having to wait for the client flush to complete.
457 The old behaviour can revived with the -flush argument to AppClass.
459 *) I renamed some of the directives for consistency (the old names
462 AppClass -> FastCgiServer,
463 FCGIConfig -> FastCgiConfig,
464 ExternalAppClass -> FastCgiExternalServer
466 *) Directive arguments are no longer case sensitive.
468 *) The module now uses hard_timeout() rather than soft_timeout. This
469 means that the module will longjump out of the request if the
470 drop-dead timeout expires (set with Apache's Timeout directive, the
471 default is 5min) or if the client closes the connection (SIGPIPE).
472 This is more typical for a Apache modules and I'm not convinced we
473 properly handle all of the error cases well enough to use
474 soft_timeout (I can think of one place we don't anyway). This means
475 your FastCGI application can see SIGPIPE.
477 *) SIGPIPE is now ignored by default in FastCGI servers spawned by
478 Apache. Without this the default behaviour is exit().
480 *) It should (I think) run now under DSO now.
482 *) The bug which prevented sending of binary data in 2.1b1 is fixed.
484 *) The broken -initial-env bug ins 2.1b1 is fixed.
486 *) Maybe some other stuff.
490 *** Well there's a big gap here. Maybe I'll go back and extract the CVS
491 commit notes and stick 'em in here.. when I get some free time. ;)
496 *** Originally from docs/README..
498 Apache[X1.03.01]/mod_fastcgi[02.00.05] 19970909 unsupported
499 From: Stanley Gambarin <stanleyg@cs.bu.edu>
501 *) Yet more changes to the source distribution. Separated out
502 the Tcl dynamic string and buffer libraries into separate files.
503 Did the same for the OS library, however, it is not really an
504 abstraction... more like a bunch of wrappers. Added to DEVNOTES
505 a note about the problem of Apache not allowing including header
508 Apache[X1.03.01]/mod_fastcgi[02.00.04] 19970908 unsupported
509 From: Stanley Gambarin <stanleyg@cs.bu.edu>
511 *) More changes to the installation scripts. Theoretically we
512 should be able to to use the same Makefile/installation script
513 for both Apache 1.2.x and 1.3.x. Need some sort of the abstraction
514 layer to use the same source code for both 1.2.x and 1.3.x sources.
516 Apache[X1.03.01]/mod_fastcgi[02.00.03] 19970905 unsupported
517 From: Stanley Gambarin <stanleyg@cs.bu.edu>
519 *) Created Makefile to compile the module into the archive library,
520 just like the proxy module. Also initial draft of the installation
521 script, which should work for both 1.2 and 1.3 sources of Apache.
523 Apache[01.02.04]/mod_fastcgi[02.00.02] 19970903 unsupported
524 From: Stanley Gambarin <stanleyg@cs.bu.edu>
526 *) More source reorg. Separated out some header files. Need much
527 more work on this. Updated the TODO file. Added fcgivers.h and
528 CHANGES file to track the history.
530 Apache[01.02.04]/mod_fastcgi[02.00.01] 19970902 unsupported
531 From: Stanley Gambarin <stanleyg@cs.bu.edu>
533 *) Source reorganization. This is done to provide a basis for later
534 functionality implementation. See TODO file for more information
535 of what possible future enhancements are possible/desired.
537 Apache[01.02.04]/mod_fastcgi[02.00.00] 19970902 unsupported
538 From: David MacKenzie <djm@va.pubnix.com>
540 *) Create the "dynamic" dir and "mbox" as the user specified in the
541 User and Group directives instead of as root. They are created with
542 restrictive permissions, and then the module checks to see whether the
543 user specified in the User and Group directives has read, write, and
544 execute permissions on them. Those permissions had been explicitly
545 denied by creating them as "root".
547 *) Some documentation was garbled or incomplete.
549 *) When a FastCGI application can't be execl'd, the code used a
550 value of errno that may have been stomped on by intervening system
551 calls. That happened on BSD/OS 2.1, where the error_log was
552 reporting errno=25 (NOTTY) instead of the correct errno=13 (EACCES).
553 An intervening stdio call was setting errno as a side-effect, which
554 it has the right to do.
556 *) Erroneous fprintf arguments, a missing return value, an unused
557 function, missing declarations, and other problems detected by gcc
560 *) Duplicated code to create the lock file name merged into a single
561 function, closing several memory leaks.
563 *) FCGIConfig -minProcesses didn't allow a value of 0, so the last
564 FCGI app in a given dynamic class would live forever, even if it
565 hadn't been requested for weeks.
567 *) The test for whether to keep looking for dynamic app victims to
568 kill was backwards, so no dynamic apps were ever selected as
571 *) The killInterval and updateInterval were being ignored; the
572 sigsuspend() forced recalculations only when a child died,
573 instead of at the intervals specified.
575 *) When a dynamic app couldn't be started, the program SEGV'd when
576 trying to free the ipcAddrPtr twice.
578 *) Remove the dead lock file and socket when cleaning up after a
579 server whose last child has been killed, so the FastCGIHandler
580 isn't fooled into thinking there is still a process serving
583 *) Make file locking robust in the presence of signals.
585 *) Rename some badly named variables.
587 *) Fix typos in many comments.
589 *) Fix some memory and file descriptor leaks.
591 *) Make the blocking kill of a server closer to working.
593 *) More fixes to calculations in dynamic application management.
596 *** Originally from docs/README.OMI..
598 What's New: Version 2.0b1, 16 Apr 1997
600 *) Implemented a mechanism by which FastCGI applications are started by
601 the web server on the first request and continue running. Also, a
602 heuristics have been implemented to allow for dynamic killing of the
603 running FastCGI apps. The configuration options are supplied via
604 the new FCGIConfig directive, that is described in the
607 *) When performing internal redirect, since the original request's body
608 has already been read, do not allow the redirected request to think
609 that is has one [body].
611 *) More conditional compilation for OS/2.
613 *) Fixed occassional "Assertion failed: len > 0, file mod_fastcgi.c"
615 *) Fixed "failed assertion `count >= 0 && count <= bufPtr->length'"
617 *) Added bflush() call after bwrite() in DrainReqOutBuf function to
618 force some output to be written in the period of inactivity. This
619 circumvents the Apache's buffering during the server-push.
621 *) Added a header-parser function placeholder for compatibility with an
624 *) Additional checks have been placed with regard to permissions of the
625 FastCGI processes. These include the existence of the file,
626 ExecCGI and IncludesNOEXEC checks, disallowing of nph- scripts, etc.
628 *) Implemented a restart cleanup, so that no parentlesses FastCGI
629 applications are left after Apache is restarted and/or terminated.
630 This was accomplished via two independent mechanisms, where the
631 first one prevents a start of the process manager on the first
632 reading of the configuration files. The second mechanism deals away
633 from Apache's implementation of fork() (via spawn_child()) and
634 implements its own forking, thus removing any dependencies on the
635 Apache to cleanup processes during termination phase.
637 *) Removed the definition of the Sigfunc, as Apache 2.0b10 defines it
638 itself in the file conf.h
640 What's New: Version 1.4.3, 15 Jan 1997
642 *) Fixed compilation warnings for various platforms, as well as
643 conditional compilation for OS/2.
645 What's New: Version 1.4.2, 12 Dec 1996
647 *) mod_fastcgi.c is ported to Apache 1.2b. Any further development
648 will proceed under this version of Apache web server.
650 *) As the result of porting, the "include virtual" construct of SSI
651 will now work correctly using either <Location> or <Directory>
654 What's New: Version 1.4.1, 4 Dec 1996
656 *) Checks have been removed from the ScanCGIHeaders that provided
657 for the presence of both Status and Location headers as being
658 an error. Contradictory to CGI/1.1 Internet Draft, both of
659 these headers are used by the current CGI applications.
661 What's New: Version 1.4, 22 Nov 1996
663 *) Added the -port option to AppClass, allowing TCP/IP communication.
664 Added the -socket option to AppClass, allowing Unix domain
665 communication via a configurable pathname.
667 *) Added the ExternalAppClass directive, allowing TCP/IP
668 communication with remote FastCGI applications.
670 *) The handler had its own code for generating HTTP response headers;
671 now it uses Apache's. This reduces the size of the module.
672 More importantly, it fixes the bug in which "include virtual"
673 sees the HTTP response headers.
675 *) The response header parser performed very little checking.
676 Now the parser enforces the guidelines in the CGI/1.1
677 Internet-Draft: Status and Location are mutually exclusive,
678 Location can only be a response to GET or HEAD,
679 CGI response headers can't be repeated, etc. (The CGI response
680 headers are the ones the handler interprets: Status, Location,
683 *) The response header parser used to miss CGI headers
684 with no whitespace after the colon, e.g. "Status:200 OK".
686 *) The response header parser sometimes interpreted the first line
687 of content as an RFC822 continuation line.
689 *) The handler implemented a nonstandard version of Location
690 which never used internal redirects. The handler
691 now attempts to implement Location as specified in the
692 CGI/1.1 Internet-Draft. The module documentation explains
695 *) Error log entries from the response header parser were
696 pretty uninformative; they are better now. If a header is
697 malformed, the log entry includes it. If the headers are
698 unterminated rather than malformed, the log entry says that,
699 and says how many bytes were received from the app.
701 *) When the application manager forked a new process, and that
702 process ran into trouble before executing the first instruction
703 of application code, the process used to exit with status =
704 errno. This made certain configuration problems (e.g. incorrect
705 file permissions when server parent is root) quite difficult
706 to pin down. Now the failing child process opens up the error log
707 and writes an informative entry before exiting.
709 *) The module now correctly handles a slash at the end of the
710 DocumentRoot directive. This was a one-line fix.
712 What's New: Version 1.3.3, 17 Oct 1996
714 *) The module now registers its request handler under the name
715 fastcgi-script in addition to the name application/x-httpd-fcgi.
716 This was a one-line addition to the module, but had quite
717 a large impact on the documentation and sample configuration.
719 What's New: Version 1.3.2, 27 Sept 1996
721 *) On some systems (SunOS, Linux?), fopen for append has a bug
722 that strikes when two processes append to the same file.
723 This bug causes the process manager to corrupt the error log.
724 Work around the bug by calling open, then fdopen. A patch
725 to Apache 1.1.1 is also required, as described in mod_fastcgi.html.
726 (Reported by Bob Ramstad.)
728 What's New: Version 1.3.1, 17 Sept 1996
730 *) On Linux and SunOS, the Apache default user_id (-1) is not a
731 legal value of uid_t, so cast it. (Reported by Bob Ramstad,
732 Scott Langley, others.)
734 *) On some systems (Linux, some Solaris?, Irix?), connect requires
735 write access to a Unix Domain socket, so provide it. (Reported
736 by Scott Langley, freeform@wired.com, others.)
738 *) If you hit a .fcg file, but there's no AppClass defined, the
739 error should be NOT_FOUND instead of SERVER_ERROR. (Reported
742 What's New: Version 1.3, 4 Sept 1996
744 *) Module sometimes busy-waited in FastCgiDoWork. Fixed.
746 *) Module violated the Apache buff abstraction.
747 Fixed. Might now work with SSL (not tested).
748 As part of the fix, eliminated support for
749 Apache 1.0x versions.
751 *) Module failed to chmod the Unix domain listening sockets
752 it created, so protections were set according to the current
755 *) Module forked too many process manager processes: One
756 per AppClass. When the Apache parent ran as root, these
757 process manager processes ran as root. New process
758 manager is a single process (only started if AppClass is
759 used) and runs with same privileges as other children.
760 The new process manager doesn't do any polling, so
761 there's less system overhead than before.
763 *) AppClass insisted on getting at least two arguments. Fixed.
765 *) Module used setjmp/longjmp, causing compiler warnings
766 on some platforms (e.g. Linux.) The module no longer
769 *) Module created listening sockets in /tmp, where they were
770 sometimes wiped out by cleanup scripts. Added FastCgiIpcDir
771 directive to give control over the location of listening
774 *) Module wrote error log entries without a timestamp. Fixed.
776 *) AppClass directive wrote error messages to stderr in addition
777 to returning a char * message to the Apache core. Fixed.
779 What's New: Version 1.2, 3 June 1996
781 *) Ported from Apache-1.0-based code to Apache-1.1b2 internals by
784 Add version string: APACHEVERSION macro to mod_fastcgi.c
786 *) chown FastCGI socket to user_id and setuid to user_id for app
789 *) Modify GetFromStream() by having it call an OS dependent
790 function GetStreamSize(FILE *) which uses FILE internal data member.
791 Linux users might need to modify GetStreamSize().
793 What's New: Version 1.1, 10 May 1996
795 *) If you specify a non-existent executable in the AppClass directive,
796 or if the file exists and it does not have execute permission you
797 get a constant stream of error messages telling you that "program
798 terminated due to a signal".
800 *) The mod_fastcgi module should use the standard Apache error logging
801 facility instead of writing to stderr.
803 Version 1.0, 30 April 1996