From dev-return-91356-archive-asf-public=cust-asf.ponee.io@httpd.apache.org Fri Mar 9 04:38:34 2018 Return-Path: X-Original-To: archive-asf-public@cust-asf.ponee.io Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by mx-eu-01.ponee.io (Postfix) with SMTP id A16D818064C for ; Fri, 9 Mar 2018 04:38:33 +0100 (CET) Received: (qmail 95573 invoked by uid 500); 9 Mar 2018 03:38:31 -0000 Mailing-List: contact dev-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: dev@httpd.apache.org list-help: list-unsubscribe: List-Post: List-Id: Delivered-To: mailing list dev@httpd.apache.org Received: (qmail 95563 invoked by uid 99); 9 Mar 2018 03:38:31 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd2-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 09 Mar 2018 03:38:31 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd2-us-west.apache.org (ASF Mail Server at spamd2-us-west.apache.org) with ESMTP id 59C8B1A1898 for ; Fri, 9 Mar 2018 03:38:31 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd2-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 1.979 X-Spam-Level: * X-Spam-Status: No, score=1.979 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=2, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=disabled Authentication-Results: spamd2-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=rowe-clan-net.20150623.gappssmtp.com Received: from mx1-lw-eu.apache.org ([10.40.0.8]) by localhost (spamd2-us-west.apache.org [10.40.0.9]) (amavisd-new, port 10024) with ESMTP id PDCdHSJZQYCZ for ; Fri, 9 Mar 2018 03:38:26 +0000 (UTC) Received: from mail-oi0-f42.google.com (mail-oi0-f42.google.com [209.85.218.42]) by mx1-lw-eu.apache.org (ASF Mail Server at mx1-lw-eu.apache.org) with ESMTPS id 1C7C55F2A9 for ; Fri, 9 Mar 2018 03:38:26 +0000 (UTC) Received: by mail-oi0-f42.google.com with SMTP id c83so6065016oib.1 for ; Thu, 08 Mar 2018 19:38:26 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rowe-clan-net.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=ntLKTsBH43dUt5/jHXAYNgTYnZSJmRfmlTgXifsWQtM=; b=ZmpmmqdaXMBalbp9DONweIXe3XcPZluAJsPoSJ5DLPMhL5LrSfdfatkI6W89MgE1RO TomIwAzBrqAf7UR7f2mva4SMBBGCSJWU7XPgctu+LJ7J2szW4V7Omqyc4ejhkG5EtjF2 lw0aOT0G+QDWtD47nkQu/JNUnCxDx/le1aaM3MjiAIiUAsnfppJekULaofe8ho/8htN6 s97b5xEXnHB11SFQ614GPM9X5phBR8XlNfuZf2MbHFWBwHp2KKqrSK4/Zjk7SGHmNUiR W7X8m+R/W85f+MLi7bFyWX6X/uIsH4FcJ1JUUbdcrufD4XQm/CflIU6nkzdxxyDs20RZ H3Mg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=ntLKTsBH43dUt5/jHXAYNgTYnZSJmRfmlTgXifsWQtM=; b=BwkTujvkT3uMiJ2ujv0Bss/4maC2ApeLYxH7obt/JARtjPug+/4QJw4DOyIjQpBnmX uFEpsDgs/NRXo4VwqoLn+JvB47p0ebpcrM5bavY3v8Z+6CpFBY7hkaoi2BNASD2xmr6a Ww9QibHlbzB0TYf6Ni6WasJ20oBaHEhc02kSGI5wxZq8IzvYkpiDC7Xfjg/9WO9kl5cP y18hdwaR9If5bggeLJMXrqcq8wy0awtKV26HY/CDKAvI5BrKDJ/BA8+t0oCQMVL9Ijkt MHlQ5EqWxjAtgm8v2D9VFl6CLkKZJ8qwGTciraNgqzfnTWeLFgjGyQ84agN68uJ7rau6 c/Mw== X-Gm-Message-State: AElRT7HeIUHeQBbArQcncIxuMKvXUxX1mwzAm+gCnouBHLBhGcbGUzIi gWQSakqp03wbAsY1rBIv+MiYtv/0U/5A6HlVU6BNqA== X-Google-Smtp-Source: AG47ELthdC7nYFmqqAOKM4jPX/nWOr/a/m8mQf5WkQ6j+k/o/jOkixnx8OlSTALBJ296A8xYbbKRN2vaHTbV2WC2Zq0= X-Received: by 10.202.97.139 with SMTP id v133mr1902846oib.129.1520566704358; Thu, 08 Mar 2018 19:38:24 -0800 (PST) MIME-Version: 1.0 Received: by 10.157.46.236 with HTTP; Thu, 8 Mar 2018 19:38:23 -0800 (PST) Received: by 10.157.46.236 with HTTP; Thu, 8 Mar 2018 19:38:23 -0800 (PST) In-Reply-To: References: <20180308220021.D7DE83A00E7@svn01-us-west.apache.org> From: William A Rowe Jr Date: Thu, 8 Mar 2018 21:38:23 -0600 Message-ID: Subject: Re: svn commit: r1826279 - /httpd/httpd/branches/2.4.x/STATUS To: httpd Content-Type: multipart/alternative; boundary="001a113d6358458bcb0566f286c6" --001a113d6358458bcb0566f286c6 Content-Type: text/plain; charset="UTF-8" Doesn't our crazy old unquoted ErrorDocument directive have this issue too? On Mar 8, 2018 16:05, "Yann Ylavic" wrote: > On Thu, Mar 8, 2018 at 11:00 PM, wrote: > > > > *) mod_access_compat, mod_authz_host: Prevent access control > misconfiguration > > due to interpretation of #comments in Require host or Allow/Deny > directives. > > trunk patch: http://svn.apache.org/r1667676 > > http://svn.apache.org/r1826207 > > 2.4.x patch: trunk works, svn merge -c 1667676,1826207 > ^/httpd/httpd/trunk . > > - +1: jorton, jim, > > + +1: jorton, jim, ylavic > > This one possibly/later could be addressed at > ap_getword_conf[_nocomment)() level, many/most directives should stop > on #comments no? > --001a113d6358458bcb0566f286c6 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Doesn't our crazy old unquoted ErrorDocument directiv= e have this issue too?

On Mar 8, 2018 16:05, "Yann Ylavic" <ylavic.dev@gmail.com> wrote:
On Thu, Mar 8, 2018 at 11:00 PM,= =C2=A0 <ylavic@apache.org> w= rote:
>
>=C2=A0 =C2=A0 *) mod_access_compat, mod_authz_host: Prevent access cont= rol misconfiguration
>=C2=A0 =C2=A0 =C2=A0 =C2=A0due to interpretation of #comments in Requir= e host or Allow/Deny directives.
>=C2=A0 =C2=A0 =C2=A0 =C2=A0trunk patch: http://svn.apache.org/r166= 7676
>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 <= a href=3D"http://svn.apache.org/r1826207" rel=3D"noreferrer" target=3D"_bla= nk">http://svn.apache.org/r1826207
>=C2=A0 =C2=A0 =C2=A0 =C2=A02.4.x patch: trunk works, svn merge -c 16676= 76,1826207 ^/httpd/httpd/trunk .
> -=C2=A0 =C2=A0 =C2=A0+1: jorton,=C2=A0 jim,
> +=C2=A0 =C2=A0 =C2=A0+1: jorton, jim, ylavic

This one possibly/later could be addressed at
ap_getword_conf[_nocomment)() level, many/most directives should stop
on #comments no?
--001a113d6358458bcb0566f286c6--