Last commit made on 2016-06-02
Get this branch:
git clone -b ubuntu/wily-security https://git.launchpad.net/ubuntu/+source/nginx
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information


Recent commits

451904e... by Thomas Ward on 2016-06-01

Import patches-unapplied version 1.9.3-1ubuntu1.2 to ubuntu/wily-security

Imported using git-ubuntu import.

Changelog parent: 6c9bc88ef224d54e36fb75720b4bb9351ea5dd70

New changelog entries:
  * SECURITY UPDATE: Null pointer dereference while writing client request
    body (LP: #1587577)
    - debian/patches/cve-2016-4450.patch: Upstream patch to address issue.
    - CVE-2016-4450

6c9bc88... by Marc Deslauriers on 2016-02-03

Import patches-unapplied version 1.9.3-1ubuntu1.1 to ubuntu/wily-security

Imported using git-ubuntu import.

Changelog parent: 92ee203cd6cc51c8551649420bb6c572f688fe02

New changelog entries:
  * SECURITY UPDATE: multiple resolver security issues (LP: #1538165)
    - debian/patches/CVE-2016-074x-1.patch: fix possible segmentation fault
      on DNS format error.
    - debian/patches/CVE-2016-074x-2.patch: fix crashes in timeout handler.
    - debian/patches/CVE-2016-074x-3.patch: fixed CNAME processing for
      several requests.
    - debian/patches/CVE-2016-074x-4.patch: change the
      ngx_resolver_create_*_query() arguments.
    - debian/patches/CVE-2016-074x-5.patch: fix use-after-free memory
      accesses with CNAME.
    - debian/patches/CVE-2016-074x-6.patch: limited CNAME recursion.
    - CVE-2016-0742
    - CVE-2016-0743
    - CVE-2016-0744

92ee203... by Thomas Ward on 2015-07-22

Import patches-unapplied version 1.9.3-1ubuntu1 to ubuntu/wily-proposed

Imported using git-ubuntu import.

Changelog parent: 3556730aa419a7ac8455a93cf16c99746a55fafc

New changelog entries:
  * Merge from Debian. Remaining changes: (LP: #1476811)
    - debian/patches/ubuntu-branding.patch: add Ubuntu branding (refreshed)
    - d/{control,rules,nginx-core.*}: add new binary package for main,
      nginx-core, which contains only source-tarball-included modules
      and no third-party modules.
    - debian/tests/control: add nginx-core test.
    - debian/control: drop luajit from Build-Depends as it is in universe.
    - debian/apport/source_nginx.py: Add apport hooks for additional bug
      information gathering.
    - debian/nginx-common.install: Add install rule for apport hooks.

3556730... by ctrochalakis on 2015-07-14

Import patches-unapplied version 1.9.3-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: b640c24540634ab74e91242fef01bb1f1e4f12bc

New changelog entries:
  [ Christos Trochalakis]
  * New upstream Release. (Closes: #789924)
  * debian/control:
    + Remove XS-Testsuite header, it is now automatically added when
      `debian/tests/control` is present.
  * debian/modules/nginx-lua:
    + Update nginx-lua to v0.9.16 and drop our backported patches.
  * debian/conf/*:
    + Add REQUEST_SCHEME to fcgi, wsgi and scgi configs (sync with upstream).

b640c24... by ctrochalakis on 2015-06-22

Import patches-unapplied version 1.9.2-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 9db1698ec3d60e85fc69413ac2170c0f14316e9c

New changelog entries:
  [ Michael Lustfield ]
  * debian/nginx-common.nginx.init:
    + Init script now returns the proper exit status. (Closes: #788573)
    + Cleaned up the init script to have consistent naming/structure.
  [ Christos Trochalakis ]
  * New upstream Release.
  * debian/rules:
    + Add stream module to nginx-full & nginx-extras.
    + Add thread pool support to nginx-full & nginx-extras.
  * debian/modules/nginx-lua:
    + Backport upstream's 9531e5e7 fixing build failure when thread pool
      support is enabled.

9db1698... by ctrochalakis on 2015-06-12

Import patches-unapplied version 1.9.1-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 7a8a9a90a6413fc5fd37dba447c5ec792cfcbfa6

New changelog entries:
  [ Michael Lustfield ]
  * debian/conf/nginx.conf:
    + Switch worker_processes to auto. (Closes: #781711)
  * debian/conf/sites-available/default:
    + Add comment about disabling gzip in HTTPS. (Closes: #773332)
    + Add comment about checking ssl_ciphers. (Closes: #765782)
  * debian/modules/*:
    + Updated nginx-auth-pam 1.3 -> 1.4. (Closes: #777120)
    + Updated nginx-echo v0.56 -> v0.57.
    + Updated nginx-lua v0.9.13 -> v0.9.15.
    + Updated nginx-cache-purge 2.1 -> 2.3.
    + Updated ngx-fancyindex v0.3.4 -> v0.3.5.
  * debian/nginx-common.NEWS:
    + Document potential issues with newer versions on i386.
  * debian/nginx-common.{dirs,install}, debian/vim/*:
    + Installing vim syntax highlighting from package. (Closes: #771609)
      Thanks Emmanuel Bouthenot for building this patch.
  * debian/nginx-common.nginx.upstart:
    + Created file to support upstart jobs. (Closes: #745483)
      Thanks Cameron Norman for building this file.
  * debian/rules:
    + Add hardening flags with dpkg-buildflags. (Closes: #747025, #781703)
      Thanks Thomas Ward.
    + Supply custom DEB_BUILD_MAINT_OPTIONS for debian_ldflags generation.
      Thanks Thomas Ward.
    + Added back missing module gunzip. (Closes: #782065)
      Thanks Peter Wu for the initial patch.
  * debian/modules/nginx-lua/*:
    + Updated module version. (Closes: #762494)
  * debian/ngx-conf/*
    + Added configuration utility, not shipped yet. (Closes: #652108)
  * debian/nginx-common.manpages:
    + Replaced man page with upstream maintained version. (Closes: #781345)
  * debian/nginx-common.install:
    + Changed debian/index.html -> html/index.html. This installs the package
      maintained version of this file as opposed to our out of date version.
  [ Christos Trochalakis ]
  * New upstream release. Switching to mainline version. (Closes: #777677)
  * debian/nginx-common.manpages:
    + Build & ship manpages with binary packages.
  * debian/rules:
    + Adjust configure flags for limit_zone module (renamed to limit_conn).
  * debian/modules/nginx-lua:
    + Backport upstream's f4e1311 fixing build failure with mainline nginx.
  * debian/control:
    + Depend on libgd-dev now that jessie is released.

7a8a9a9... by ctrochalakis on 2014-11-30

Import patches-unapplied version 1.6.2-5 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 76a9d567e1d72024c4f009df8cf5ff8c8f2d5481

New changelog entries:
  [ Christos Trochalakis ]
  * debian/conf/nginx.conf:
    + Drop SSLv3 protocol (POODLE), and prefer server ciphers
      by default. (Closes: #767456)
  * debian/copyright:
    + Add copyright for ngx_http_substitutions_filter_module.
  * debian/nginx-common.{preinst,postinst,postrm}:
    + Remove /etc/nginx/naxsi-ui.conf conffile. (Closes: #768233)
  * debian/README.Debian:
    + Add a list of important changes since wheezy.

76a9d56... by ctrochalakis on 2014-10-19

Import patches-unapplied version 1.6.2-4 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 4f4fcce289cd2c689d65830b5f9ad55bb1ce61af

New changelog entries:
  [ Christos Trochalakis ]
  * debian/modules/nginx-development-kit:
    + Upgrade v0.2.17-7-g24202b4 -> v0.2.19
  * debian/modules/nginx-echo:
    + Upgrade v0.51 -> v0.56
  * debian/modules/nginx-upload-progress:
    + Upgrade v0.9.0-0-ga788dea -> 0.9.1
  * debian/modules/ngx-fancy-index:
    + Upgrade v0.3.3 -> v0.3.4
  * debian/copyright:
    + Rewrite copyright file fixing various issues.
  * debian/nginx-common.nginx.logrotate:
    + Switch postrotate to the initscript's rotate command.

4f4fcce... by ctrochalakis on 2014-10-16

Import patches-unapplied version 1.6.2-3 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 687e59f75e2fd84e9afc509fffd34b6ea368691e

New changelog entries:
  [ Christos Trochalakis ]
  * Change the default document root to /var/www/html according to debian
    policy (Closes: #730382)
  * Provide a new, debian specific, default landing page.
  * debian/nginx-common.nginx.service:
    + Graceful stopping of nginx was not handled correctly with systemd.
  * debian/nginx-common.nginx.init:
    + Gracefully stop nginx by default, we are switcing to a configurable
      STOP/5/TERM/5/KILL/5 schedule. We are now in sync with the systemd
      service file. (Closes: #762708)
  * debian/conf:
    + Introduce a `snippets/fastcgi-php.conf` snippet with a basic
      php configuration that can be included when needed. (Closes: #762491)
    + Introduce a `snippets/snakeoil.conf` snippet that enabled https
      using the certs installed by the ssl-cert package.
    + Suggest disabling SSLv3 in default site with a ref to POODLE.
  * debian/control:
    + nginx-common now suggests ssl-cert.

687e59f... by ctrochalakis on 2014-09-26

Import patches-unapplied version 1.6.2-2 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 0776d8459e3548befeed669516eed1ea86bc2fe1

New changelog entries:
  [ Christos Trochalakis ]
  * Drop nginx-naxsi, nginx-naxsi-dbg, nginx-naxsi-ui packages.
    (Closes: #746199, #737146, #712445)
  * debian/conf/nginx.conf:
    + Remove relic passenger stanga.