Compare commits

..

8 commits

Author SHA1 Message Date
Ingvar Hagelund
3bbdc44053 Added a sleep 0.5 to ExecStartPost, working around a race in
systemd, fixing bz#1478278
2022-02-22 08:32:37 +01:00
Ingvar Hagelund
a4fbf7b1a2 Added mitigation instructions for VSV00008 aka CVE-2022-23959
SECURITY, PLEASE NOTE: varnish-4.0.5 is marked END OF LIFE from the
  Varnish Cache upstream project. Please consider upgrading to varnish-6.0 LTS
  See /usr/share/doc/varnish-4.0.5/vsv8_epel7_varnish405.vcl for details.
Dropped el6 support
2022-02-16 17:54:37 +01:00
Ingvar Hagelund
4f73d9c72d New upstream release. Includes patches for security issue VSV00001
closes bz #1476784, #1477699
2017-08-02 22:22:28 +02:00
Ingvar Hagelund
8a38af109d Fixed missing user and group in varnish.service, so varnishd
runs as user and group 'varnish' instead of 'nobody'
Readded missing varnishlog.initrc
2016-12-13 01:10:51 +01:00
Ingvar Hagelund
527132f87d Fixed owner/group for varnishncsa/varnishlog logfiles, #1401272
- Patched varnishlog.service and varnishncsa.service to run as simple
  services, without pidfile handling, closes #1401272
- Patched logrotate script to use systemd reload instead of kill
- Added package ownership to "ghost" varnish.pid
2016-12-05 23:11:35 +01:00
Ingvar Hagelund
aef3cb9218 - Replaced long gone ChangeLog with doc/changes.rst 2016-12-02 13:00:21 +01:00
Ingvar Hagelund
c738cdecc8 added missing pkg-varnish tarball for 4.1.4 2016-12-02 12:19:47 +01:00
Ingvar Hagelund
829070ad37 New upstream release
- Package scripts are now external
- Removed old stuff about building rpm from source checkout
- Removed commented stuff about libs-static subpackage
- Removed patches merged upstream
- Added the example vcl files to the package
- red hat epel7 builders set _pkgdocdir fedora style without version
2016-12-02 12:10:40 +01:00
68 changed files with 3550 additions and 2251 deletions

69
.gitignore vendored
View file

@ -11,68 +11,7 @@ varnish-2.1.3.tar.gz
/varnish-4.0.1.tar.gz
/varnish-4.0.2.tar.gz
/varnish-4.0.3.tar.gz
/varnish-4.1.0.tar.gz
/varnish-cache-redhat-f3dbcce.tar.gz
/pkg-varnish-cache-105f20b.tar.gz
/varnish-4.1.1.tar.gz
/varnish-4.1.2.tar.gz
/varnish-4.1.2_fix_python24.el5.patch
/pkg-varnish-cache-eff850c.tar.gz
/varnish-4.1.3.tar.gz
/pkg-varnish-cache-4e27994.tar.gz
/varnish-5.0.0.tar.gz
/pkg-varnish-cache-502fcc0.tar.gz
/varnish-5.1.1.tar.gz
/pkg-varnish-cache-92373fe.tar.gz
/pkg-varnish-cache-5b97619.tar.gz
/varnish-5.1.2.tar.gz
/varnish-5.1.3.tar.gz
/varnish-5.2.0.tgz
/varnish-5.2.1.tgz
/pkg-varnish-cache-0ad2f22.tar.gz
/varnish-6.0.0.tgz
/varnish-6.0.1.tgz
/varnish-6.1.0.tgz
/varnish-6.1.1.tgz
/varnish-6.2.0.tgz
/pkg-varnish-cache-114fcdd.tar.gz
/varnish-6.2.1.tgz
/varnish-6.3.0.tgz
/varnish-6.3.1.tgz
/pkg-varnish-cache-ec7ad9e.tar.gz
/varnish-6.3.2.tgz
/varnish-6.4.0.tgz
/varnish-6.5.0.tgz
/varnish-6.5.1.tgz
/varnish-6.6.0.tgz
/varnish-6.6.1.tgz
/pkg-varnish-cache-d3e6a3f.tar.gz
/varnish-7.0.0.tgz
/varnish-7.0.1.tgz
/varnish-7.0.2.tgz
/pkg-varnish-cache-3ba24a8.tar.gz
/varnish-7.1.0.tgz
/varnish-7.1.1.tgz
/pkg-varnish-cache-ffc59a3.tar.gz
/varnish-7.2.0.tgz
/varnish-7.2.1.tgz
/pkg-varnish-cache-7126673.tar.gz
/varnish-7.3.0.tgz
/pkg-varnish-cache-cfa8cb3.tar.gz
/varnish-7.4.0.tgz
/varnish-7.4.1.tgz
/varnish-7.4.2.tgz
/varnish-7.5.0.tgz
/varnish-7.6.0.tgz
/pkg-varnish-cache-7d90347.tar.gz
/varnish-7.6.1.tgz
/varnish-7.7.0.tgz
/varnish-7.7.1.tgz
/jemalloc-5.3.0.tar.bz2
/varnish-7.7.3.tgz
/varnish-8.0.0.tgz
/pkg-varnish-cache-1f0d212.tar.gz
/varnish-9.0.0.tar.gz
/varnish-9.0.1.tar.gz
/varnish-9.0.2.tar.gz
/varnish-9.0.3.tar.gz
/varnish-4.0.4.tar.gz
/pkg-varnish-cache-c4ae063.tar.gz
/pkg-varnish-cache-29aa295.tar.gz
/varnish-4.0.5.tar.gz

View file

@ -1,140 +0,0 @@
diff --git a/test/unit/psset.c b/test/unit/psset.c
index 6ff7201..58b4a88 100644
--- a/test/unit/psset.c
+++ b/test/unit/psset.c
@@ -124,7 +124,7 @@ TEST_BEGIN(test_fill) {
hpdata_t pageslab;
hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE);
- edata_t alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -147,6 +147,8 @@ TEST_BEGIN(test_fill) {
edata_init_test(&extra_alloc);
err = test_psset_alloc_reuse(&psset, &extra_alloc, PAGE);
expect_true(err, "Alloc succeeded even though psset should be empty");
+
+ free(alloc);
}
TEST_END
@@ -157,7 +159,7 @@ TEST_BEGIN(test_reuse) {
hpdata_t pageslab;
hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE);
- edata_t alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -239,6 +241,8 @@ TEST_BEGIN(test_reuse) {
err = test_psset_alloc_reuse(&psset, &alloc[index_of_4], 4 * PAGE);
expect_false(err, "Should have been able to find alloc.");
edata_expect(&alloc[index_of_4], index_of_4, 4);
+
+ free(alloc);
}
TEST_END
@@ -249,7 +253,7 @@ TEST_BEGIN(test_evict) {
hpdata_t pageslab;
hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE);
- edata_t alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -273,6 +277,8 @@ TEST_BEGIN(test_evict) {
err = test_psset_alloc_reuse(&psset, &alloc[0], PAGE);
expect_true(err, "psset should be empty.");
+
+ free(alloc);
}
TEST_END
@@ -286,7 +292,9 @@ TEST_BEGIN(test_multi_pageslab) {
(void *)((uintptr_t)PAGESLAB_ADDR + HUGEPAGE),
PAGESLAB_AGE + 1);
- edata_t alloc[2][HUGEPAGE_PAGES];
+ edata_t* alloc[2];
+ alloc[0] = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
+ alloc[1] = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -336,6 +344,9 @@ TEST_BEGIN(test_multi_pageslab) {
*/
err = test_psset_alloc_reuse(&psset, &alloc[1][0], 2 * PAGE);
expect_false(err, "Allocation should have succeeded");
+
+ free(alloc[0]);
+ free(alloc[1]);
}
TEST_END
@@ -385,7 +396,7 @@ TEST_BEGIN(test_stats) {
hpdata_t pageslab;
hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE);
- edata_t alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -415,6 +426,8 @@ TEST_BEGIN(test_stats) {
stats_expect(&psset, 0);
psset_update_end(&psset, &pageslab);
stats_expect(&psset, 1);
+
+ free(alloc);
}
TEST_END
@@ -475,8 +488,8 @@ init_test_pageslabs(psset_t *psset, hpdata_t *pageslab,
TEST_BEGIN(test_oldest_fit) {
bool err;
- edata_t alloc[HUGEPAGE_PAGES];
- edata_t worse_alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
+ edata_t *worse_alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
hpdata_t pageslab;
hpdata_t worse_pageslab;
@@ -493,14 +506,19 @@ TEST_BEGIN(test_oldest_fit) {
expect_false(err, "Nonempty psset failed page allocation");
expect_ptr_eq(&pageslab, edata_ps_get(&test_edata),
"Allocated from the wrong pageslab");
+
+ free(alloc);
+ free(worse_alloc);
}
TEST_END
TEST_BEGIN(test_insert_remove) {
bool err;
hpdata_t *ps;
- edata_t alloc[HUGEPAGE_PAGES];
- edata_t worse_alloc[HUGEPAGE_PAGES];
+
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
+ edata_t *worse_alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
+
hpdata_t pageslab;
hpdata_t worse_pageslab;
@@ -539,6 +557,9 @@ TEST_BEGIN(test_insert_remove) {
psset_update_begin(&psset, &worse_pageslab);
err = test_psset_alloc_reuse(&psset, &alloc[HUGEPAGE_PAGES - 1], PAGE);
expect_true(err, "psset should be empty, but an alloc succeeded");
+
+ free(alloc);
+ free(worse_alloc);
}
TEST_END

View file

@ -1,29 +0,0 @@
commit 3de0c24859f4413bf03448249078169bb50bda0f
Author: divanorama <divanorama@gmail.com>
Date: Thu Sep 29 23:35:59 2022 +0200
Disable builtin malloc in tests
With `--with-jemalloc-prefix=` and without `-fno-builtin` or `-O1` both clang and gcc may optimize out `malloc` calls
whose result is unused. Comparing result to NULL also doesn't necessarily count as being used.
This won't be a problem in most client programs as this only concerns really unused pointers, but in
tests it's important to actually execute allocations.
`-fno-builtin` should disable this optimization for both gcc and clang, and applying it only to tests code shouldn't hopefully be an issue.
Another alternative is to force "use" of result but that'd require more changes and may miss some other optimization-related issues.
This should resolve https://github.com/jemalloc/jemalloc/issues/2091
diff --git a/Makefile.in b/Makefile.in
index 6809fb29..a964f07e 100644
--- a/Makefile.in
+++ b/Makefile.in
@@ -458,6 +458,8 @@ $(TESTS_OBJS): $(objroot)test/%.$(O): $(srcroot)test/%.c
$(TESTS_CPP_OBJS): $(objroot)test/%.$(O): $(srcroot)test/%.cpp
$(TESTS_OBJS): CPPFLAGS += -I$(srcroot)test/include -I$(objroot)test/include
$(TESTS_CPP_OBJS): CPPFLAGS += -I$(srcroot)test/include -I$(objroot)test/include
+$(TESTS_OBJS): CFLAGS += -fno-builtin
+$(TESTS_CPP_OBJS): CPPFLAGS += -fno-builtin
ifneq ($(IMPORTLIB),$(SO))
$(CPP_OBJS) $(C_SYM_OBJS) $(C_OBJS) $(C_JET_SYM_OBJS) $(C_JET_OBJS): CPPFLAGS += -DDLLEXPORT
endif

View file

@ -1,3 +1,2 @@
SHA512 (varnish-9.0.3.tar.gz) = 2789cff88632c2279062a109513cc00cab7690785f8f77e90b9968098c71ddcdc6403d6a9edc755b8f4055f0d32d9e330b0bc20fbab92ba80232955942dc912a
SHA512 (jemalloc-5.3.0.tar.bz2) = 22907bb052096e2caffb6e4e23548aecc5cc9283dce476896a2b1127eee64170e3562fa2e7db9571298814a7a2c7df6e8d1fbe152bd3f3b0c1abec22a2de34b1
SHA512 (pkg-varnish-cache-1f0d212.tar.gz) = 9f05978c99f292e64e71ba24ef2de791a33640e40fbad66d47889837fb0d4ced203873f5a17716edf757b5ad48098289882c2df196ce1fb457f279bf7f35bec3
SHA512 (varnish-4.0.5.tar.gz) = a08259f6f9c6fffa188b26c1f8c630de5e6d2f6d52f6efa9d5d8239cdd8721c53e2be3379f8100efb537e74416eadd6c865f4cc687db1c5a9f757bb3f73abeda
SHA512 (pkg-varnish-cache-29aa295.tar.gz) = 5fec8b555a643e5ca8518ab9103d5108dabc0180911015dd26bb6b5e98668a9d0ee2dc7f2c3bd0e0dc80f6d8490b1365f56221cef39c01d55bfeb3059d04f8a7

View file

@ -0,0 +1,112 @@
diff -Naur ../varnish-3.0.4.orig/bin/varnishd/cache_center.c ./bin/varnishd/cache_center.c
--- ../varnish-3.0.4.orig/bin/varnishd/cache_center.c 2013-06-14 10:39:31.000000000 +0200
+++ ./bin/varnishd/cache_center.c 2013-11-21 00:48:00.486460486 +0100
@@ -1471,9 +1471,12 @@
static int
cnt_start(struct sess *sp)
{
- uint16_t done;
+ uint16_t err_code;
char *p;
- const char *r = "HTTP/1.1 100 Continue\r\n\r\n";
+ const char *r_100 = "HTTP/1.1 100 Continue\r\n\r\n";
+ const char *r_400 = "HTTP/1.1 400 Bad Request\r\n\r\n";
+ const char *r_413 = "HTTP/1.1 413 Request Entity Too Large\r\n\r\n";
+ const char *r_417 = "HTTP/1.1 417 Expectation Failed\r\n\r\n";
CHECK_OBJ_NOTNULL(sp, SESS_MAGIC);
AZ(sp->restarts);
@@ -1496,10 +1499,14 @@
sp->wrk->vcl = NULL;
http_Setup(sp->http, sp->ws);
- done = http_DissectRequest(sp);
+ err_code = http_DissectRequest(sp);
/* If we could not even parse the request, just close */
- if (done == 400) {
+ if (err_code == 400)
+ (void)write(sp->fd, r_400, strlen(r_400));
+ else if (err_code == 413)
+ (void)write(sp->fd, r_413, strlen(r_413));
+ if (err_code != 0) {
sp->step = STP_DONE;
vca_close_session(sp, "junk");
return (0);
@@ -1511,12 +1518,6 @@
/* Catch original request, before modification */
HTTP_Copy(sp->http0, sp->http);
- if (done != 0) {
- sp->err_code = done;
- sp->step = STP_ERROR;
- return (0);
- }
-
sp->doclose = http_DoConnection(sp->http);
/* XXX: Handle TRACE & OPTIONS of Max-Forwards = 0 */
@@ -1526,13 +1527,14 @@
*/
if (http_GetHdr(sp->http, H_Expect, &p)) {
if (strcasecmp(p, "100-continue")) {
- sp->err_code = 417;
- sp->step = STP_ERROR;
+ (void)write(sp->fd, r_417, strlen(r_417));
+ sp->step = STP_DONE;
+ vca_close_session(sp, "junk");
return (0);
}
/* XXX: Don't bother with write failures for now */
- (void)write(sp->fd, r, strlen(r));
+ (void)write(sp->fd, r_100, strlen(r_100));
/* XXX: When we do ESI includes, this is not removed
* XXX: because we use http0 as our basis. Believed
* XXX: safe, but potentially confusing.
diff -Naur ../varnish-3.0.4.orig/bin/varnishd/cache_http.c ./bin/varnishd/cache_http.c
--- ../varnish-3.0.4.orig/bin/varnishd/cache_http.c 2013-06-14 10:39:31.000000000 +0200
+++ ./bin/varnishd/cache_http.c 2013-11-21 00:48:00.486460486 +0100
@@ -601,7 +601,7 @@
hp->hd[h2].e = p;
if (!Tlen(hp->hd[h2]))
- return (413);
+ return (400);
/* Skip SP */
for (; vct_issp(*p); p++) {
diff -Naur ../varnish-3.0.4.orig/bin/varnishtest/tests/r01367.vtc ./bin/varnishtest/tests/r01367.vtc
--- ../varnish-3.0.4.orig/bin/varnishtest/tests/r01367.vtc 1970-01-01 01:00:00.000000000 +0100
+++ ./bin/varnishtest/tests/r01367.vtc 2013-11-21 00:48:00.486460486 +0100
@@ -0,0 +1,30 @@
+varnishtest "blank GET"
+
+server s1 {
+ rxreq
+ txresp
+} -start
+
+varnish v1 -vcl+backend {
+ sub vcl_error {
+ return (restart);
+ }
+} -start
+
+client c1 {
+ send "GET \nHost: example.com\n\n"
+ rxresp
+ expect resp.status == 400
+} -run
+
+client c1 {
+ txreq -hdr "Expect: Santa-Claus"
+ rxresp
+ expect resp.status == 417
+} -run
+
+client c1 {
+ txreq
+ rxresp
+ expect resp.status == 200
+} -run

View file

@ -0,0 +1,13 @@
--- redhat/find-provides.orig 2014-04-10 11:19:18.000000000 +0200
+++ redhat/find-provides 2014-04-22 23:59:34.070312036 +0200
@@ -4,8 +4,8 @@
set -x
-if [ -x /usr/lib/rpm/find-requires ]; then
- /usr/lib/rpm/find-requires "$@"
+if [ -x /usr/lib/rpm/redhat/find-provides ]; then
+ /usr/lib/rpm/redhat/find-provides "$@"
fi
cd $(dirname $0)/..

View file

@ -0,0 +1,10 @@
--- doc/sphinx/Makefile.in.orig 2014-04-22 11:12:19.029824740 +0200
+++ doc/sphinx/Makefile.in 2014-04-22 11:14:09.493153140 +0200
@@ -553,6 +553,7 @@
rm -rf $(BUILDDIR)
include/params.rst: $(top_builddir)/bin/varnishd/varnishd
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnish/.libs:$(top_builddir)/lib/libvarnishcompat/.libs:$(top_builddir)/lib/libvcc/.libs:$(top_builddir)/lib/libvgz/.libs \
$(top_builddir)/bin/varnishd/varnishd -x dumprstparam > include/params.rst
# XXX add varnishstat here when it's been _opt2rst'ed

View file

@ -0,0 +1,11 @@
--- configure.orig 2014-03-11 23:25:41.618988565 +0100
+++ configure 2014-03-11 23:26:03.480225451 +0100
@@ -16746,7 +16746,7 @@
# The reason for -Wno-error=unused-result is a glibc/gcc interaction
# idiocy where write is marked as warn_unused_result, causing build
# failures.
-CFLAGS="${CFLAGS} -Wall -Werror"
+#CFLAGS="${CFLAGS} -Wall -Werror"
OCFLAGS="${OCFLAGS} -Wall -Werror"
as_CACHEVAR=`$as_echo "ax_cv_check_cflags__-Werror=unused-result" | $as_tr_sh`
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts -Werror=unused-result" >&5

View file

@ -0,0 +1,11 @@
--- configure.orig 2014-07-30 14:35:18.781987406 +0200
+++ configure 2014-07-30 14:36:12.686122224 +0200
@@ -16978,7 +16978,7 @@
# The reason for -Wno-error=unused-result is a glibc/gcc interaction
# idiocy where write is marked as warn_unused_result, causing build
# failures.
-CFLAGS="${CFLAGS} -Wall -Werror"
+#CFLAGS="${CFLAGS} -Wall -Werror"
OCFLAGS="${OCFLAGS} -Wall -Werror"
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts -Werror=unused-result" >&5
$as_echo_n "checking whether C compiler accepts -Werror=unused-result... " >&6; }

View file

@ -0,0 +1,37 @@
diff --git a/redhat/varnish.service b/redhat/varnish.service
index 659dba2..a4f3355 100644
--- a/redhat/varnish.service
+++ b/redhat/varnish.service
@@ -27,6 +27,7 @@ EnvironmentFile=/etc/varnish/varnish.params
Type=forking
PIDFile=/var/run/varnish.pid
PrivateTmp=true
+ExecStartPre=/usr/sbin/varnishd -C -f $VARNISH_VCL_CONF
ExecStart=/usr/sbin/varnishd \
-P /var/run/varnish.pid \
-f $VARNISH_VCL_CONF \
diff --git a/redhat/varnishlog.service b/redhat/varnishlog.service
index 1e3e274..c7a0193 100644
--- a/redhat/varnishlog.service
+++ b/redhat/varnishlog.service
@@ -1,6 +1,6 @@
[Unit]
Description=Varnish HTTP accelerator logging daemon
-After=network.target
+After=varnish.service
[Service]
Type=forking
diff --git a/redhat/varnishncsa.service b/redhat/varnishncsa.service
index df5f19f..e2ebdcd 100644
--- a/redhat/varnishncsa.service
+++ b/redhat/varnishncsa.service
@@ -1,6 +1,6 @@
[Unit]
-Description=Varnish NCSA logging
-After=network.target
+Description=Varnish HTTP accelerator NCSA daemon
+After=varnish.service
[Service]
Type=forking

View file

@ -0,0 +1,10 @@
--- doc/sphinx/Makefile.in.orig 2014-10-08 09:48:47.000000000 +0200
+++ doc/sphinx/Makefile.in 2014-11-25 22:49:55.137641462 +0100
@@ -517,6 +517,7 @@
rm -rf $(BUILDDIR)
include/params.rst: $(top_builddir)/bin/varnishd/varnishd
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnish/.libs:$(top_builddir)/lib/libvarnishcompat/.libs:$(top_builddir)/lib/libvcc/.libs:$(top_builddir)/lib/libvgz/.libs \
$(top_builddir)/bin/varnishd/varnishd -x dumprstparam > include/params.rst
# XXX add varnishstat here when it's been _opt2rst'ed

View file

@ -0,0 +1,11 @@
--- configure.old 2015-03-05 13:20:10.546649666 +0100
+++ configure 2015-03-05 13:20:14.099663485 +0100
@@ -16794,7 +16794,7 @@
# The reason for -Wno-error=unused-result is a glibc/gcc interaction
# idiocy where write is marked as warn_unused_result, causing build
# failures.
-CFLAGS="${CFLAGS} -Wall -Werror"
+#CFLAGS="${CFLAGS} -Wall -Werror"
OCFLAGS="${OCFLAGS} -Wall -Werror"
as_CACHEVAR=`$as_echo "ax_cv_check_cflags__-Werror=unused-result" | $as_tr_sh`
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts -Werror=unused-result" >&5

View file

@ -0,0 +1,274 @@
This patch is a rebase of commit 9d61ea4d722549a984d912603902fccfac473824
Author: Martin Blix Grydeland <martin@varnish-software.com>
Date: Fri Mar 13 15:23:15 2015 +0100
Fail fetch on malformed Content-Length header
Add a common content length parser that is being used by both client
and backend side.
Original patch by: fgs
Fixes: #1691
diff -Nur varnish-4.0.3.nofix/bin/varnishd/cache/cache.h varnish-4.0.3/bin/varnishd/cache/cache.h
--- varnish-4.0.3.nofix/bin/varnishd/cache/cache.h 2015-02-18 15:14:11.000000000 +0100
+++ varnish-4.0.3/bin/varnishd/cache/cache.h 2015-03-13 16:22:42.943549723 +0100
@@ -208,7 +208,7 @@
*
*/
-typedef ssize_t htc_read(struct http_conn *, void *, size_t);
+typedef ssize_t htc_read(struct http_conn *, void *, ssize_t);
struct http_conn {
unsigned magic;
@@ -560,7 +560,7 @@
struct pool_task fetch_task;
- char *h_content_length;
+ ssize_t content_length;
#define BO_FLAG(l, r, w, d) unsigned l:1;
#include "tbl/bo_flags.h"
@@ -1014,6 +1014,7 @@
int http_GetHdrField(const struct http *hp, const char *hdr,
const char *field, char **ptr);
double http_GetHdrQ(const struct http *hp, const char *hdr, const char *field);
+ssize_t http_GetContentLength(const struct http *hp);
uint16_t http_GetStatus(const struct http *hp);
void http_SetStatus(struct http *to, uint16_t status);
const char *http_GetReq(const struct http *hp);
@@ -1040,7 +1041,7 @@
unsigned maxbytes, unsigned maxhdr);
enum htc_status_e HTTP1_Reinit(struct http_conn *htc);
enum htc_status_e HTTP1_Rx(struct http_conn *htc);
-ssize_t HTTP1_Read(struct http_conn *htc, void *d, size_t len);
+ssize_t HTTP1_Read(struct http_conn *htc, void *d, ssize_t len);
enum htc_status_e HTTP1_Complete(struct http_conn *htc);
uint16_t HTTP1_DissectRequest(struct req *);
uint16_t HTTP1_DissectResponse(struct http *sp, const struct http_conn *htc);
diff -Nur varnish-4.0.3.nofix/bin/varnishd/cache/cache_http1_fetch.c varnish-4.0.3/bin/varnishd/cache/cache_http1_fetch.c
--- varnish-4.0.3.nofix/bin/varnishd/cache/cache_http1_fetch.c 2015-02-18 15:14:11.000000000 +0100
+++ varnish-4.0.3/bin/varnishd/cache/cache_http1_fetch.c 2015-03-13 16:22:42.944549727 +0100
@@ -43,29 +43,6 @@
#include "vtcp.h"
#include "vtim.h"
-/*--------------------------------------------------------------------
- * Convert a string to a size_t safely
- */
-
-static ssize_t
-vbf_fetch_number(const char *nbr, int radix)
-{
- uintmax_t cll;
- ssize_t cl;
- char *q;
-
- if (*nbr == '\0')
- return (-1);
- cll = strtoumax(nbr, &q, radix);
- if (q == NULL || *q != '\0')
- return (-1);
-
- cl = (ssize_t)cll;
- if((uintmax_t)cl != cll) /* Protect against bogusly large values */
- return (-1);
- return (cl);
-}
-
/*--------------------------------------------------------------------*/
static enum vfp_status __match_proto__(vfp_pull_f)
@@ -167,7 +144,6 @@
V1F_Setup_Fetch(struct busyobj *bo)
{
struct http_conn *htc;
- ssize_t cl;
CHECK_OBJ_NOTNULL(bo, BUSYOBJ_MAGIC);
htc = &bo->htc;
@@ -176,13 +152,15 @@
switch(htc->body_status) {
case BS_EOF:
+ assert(bo->content_length == -1);
VFP_Push(bo, v1f_pull_eof, 0);
return(-1);
case BS_LENGTH:
- cl = vbf_fetch_number(bo->h_content_length, 10);
- VFP_Push(bo, v1f_pull_straight, cl);
- return (cl);
+ assert(bo->content_length > 0);
+ VFP_Push(bo, v1f_pull_straight, bo->content_length);
+ return (bo->content_length);
case BS_CHUNKED:
+ assert(bo->content_length == -1);
VFP_Push(bo, v1f_pull_chunked, -1);
return (-1);
default:
diff -Nur varnish-4.0.3.nofix/bin/varnishd/cache/cache_http1_fsm.c varnish-4.0.3/bin/varnishd/cache/cache_http1_fsm.c
--- varnish-4.0.3.nofix/bin/varnishd/cache/cache_http1_fsm.c 2015-02-18 15:14:11.000000000 +0100
+++ varnish-4.0.3/bin/varnishd/cache/cache_http1_fsm.c 2015-03-13 16:22:42.944549727 +0100
@@ -262,22 +262,22 @@
static enum req_body_state_e
http1_req_body_status(struct req *req)
{
- char *ptr, *endp;
+ ssize_t cl;
CHECK_OBJ_NOTNULL(req, REQ_MAGIC);
- if (http_GetHdr(req->http, H_Content_Length, &ptr)) {
- AN(ptr);
- if (*ptr == '\0')
- return (REQ_BODY_FAIL);
- req->req_bodybytes = strtoul(ptr, &endp, 10);
- if (*endp != '\0' && !vct_islws(*endp))
- return (REQ_BODY_FAIL);
- if (req->req_bodybytes == 0)
- return (REQ_BODY_NONE);
+ req->req_bodybytes = 0;
+ cl = http_GetContentLength(req->http);
+ if (cl == -2)
+ return (REQ_BODY_FAIL);
+ else if (cl == 0)
+ return (REQ_BODY_NONE);
+ else if (cl > 0) {
+ req->req_bodybytes = cl;
req->h1.bytes_yet = req->req_bodybytes - req->h1.bytes_done;
return (REQ_BODY_PRESENT);
}
+ assert(cl == -1); /* No Content-Length header */
if (http_HdrIs(req->http, H_Transfer_Encoding, "chunked")) {
req->chunk_ctr = -1;
return (REQ_BODY_CHUNKED);
diff -Nur varnish-4.0.3.nofix/bin/varnishd/cache/cache_http1_proto.c varnish-4.0.3/bin/varnishd/cache/cache_http1_proto.c
--- varnish-4.0.3.nofix/bin/varnishd/cache/cache_http1_proto.c 2015-02-18 15:14:11.000000000 +0100
+++ varnish-4.0.3/bin/varnishd/cache/cache_http1_proto.c 2015-03-13 16:22:42.944549727 +0100
@@ -191,14 +191,15 @@
* Read up to len bytes, returning pipelined data first.
*/
-ssize_t
-HTTP1_Read(struct http_conn *htc, void *d, size_t len)
+ssize_t __match_proto__(htc_read)
+HTTP1_Read(struct http_conn *htc, void *d, ssize_t len)
{
size_t l;
unsigned char *p;
ssize_t i = 0;
CHECK_OBJ_NOTNULL(htc, HTTP_CONN_MAGIC);
+ assert(len > 0);
l = 0;
p = d;
if (htc->pipeline.b) {
diff -Nur varnish-4.0.3.nofix/bin/varnishd/cache/cache_http.c varnish-4.0.3/bin/varnishd/cache/cache_http.c
--- varnish-4.0.3.nofix/bin/varnishd/cache/cache_http.c 2015-02-18 15:14:11.000000000 +0100
+++ varnish-4.0.3/bin/varnishd/cache/cache_http.c 2015-03-13 16:22:42.943549723 +0100
@@ -488,6 +488,35 @@
return (i);
}
+/*--------------------------------------------------------------------*/
+
+ssize_t
+http_GetContentLength(const struct http *hp)
+{
+ ssize_t cl, cll;
+ char *b;
+
+ CHECK_OBJ_NOTNULL(hp, HTTP_MAGIC);
+
+ if (!http_GetHdr(hp, H_Content_Length, &b))
+ return (-1);
+ cl = 0;
+ if (!vct_isdigit(*b))
+ return (-2);
+ for (;vct_isdigit(*b); b++) {
+ cll = cl;
+ cl *= 10;
+ cl += *b - '0';
+ if (cll != cl / 10)
+ return (-2);
+ }
+ while (vct_islws(*b))
+ b++;
+ if (*b != '\0')
+ return (-2);
+ return (cl);
+}
+
/*--------------------------------------------------------------------
* XXX: redo with http_GetHdrField() ?
*/
diff -Nur varnish-4.0.3.nofix/bin/varnishd/cache/cache_rfc2616.c varnish-4.0.3/bin/varnishd/cache/cache_rfc2616.c
--- varnish-4.0.3.nofix/bin/varnishd/cache/cache_rfc2616.c 2015-02-18 15:14:11.000000000 +0100
+++ varnish-4.0.3/bin/varnishd/cache/cache_rfc2616.c 2015-03-13 16:22:42.944549727 +0100
@@ -188,6 +188,7 @@
RFC2616_Body(struct busyobj *bo, struct dstat *stats)
{
struct http *hp;
+ ssize_t cl;
char *b;
hp = bo->beresp;
@@ -199,6 +200,8 @@
else
bo->should_close = 0;
+ bo->content_length = -1;
+
if (!strcasecmp(http_GetReq(bo->bereq), "head")) {
/*
* A HEAD request can never have a body in the reply,
@@ -246,9 +249,18 @@
return (BS_ERROR);
}
- if (http_GetHdr(hp, H_Content_Length, &bo->h_content_length)) {
- stats->fetch_length++;
- return (BS_LENGTH);
+ cl = http_GetContentLength(hp);
+ if (cl == -2)
+ return (BS_ERROR);
+ if (cl >= 0) {
+ bo->content_length = cl;
+ if (cl == 0) {
+ stats->fetch_zero++;
+ return (BS_NONE);
+ } else {
+ stats->fetch_length++;
+ return (BS_LENGTH);
+ }
}
if (http_HdrIs(hp, H_Connection, "keep-alive")) {
diff -Nur varnish-4.0.3.nofix/bin/varnishtest/tests/r01691.vtc varnish-4.0.3/bin/varnishtest/tests/r01691.vtc
--- varnish-4.0.3.nofix/bin/varnishtest/tests/r01691.vtc 1970-01-01 01:00:00.000000000 +0100
+++ varnish-4.0.3/bin/varnishtest/tests/r01691.vtc 2015-03-13 16:22:42.945549731 +0100
@@ -0,0 +1,21 @@
+varnishtest "Test bogus Content-Length header"
+
+server s1 {
+ rxreq
+ txresp -nolen -hdr "Content-Length: bogus"
+} -start
+
+varnish v1 -vcl+backend {
+
+} -start
+
+logexpect l1 -v v1 {
+ expect * 1002 VCL_Error "Body cannot be fetched"
+} -start
+
+client c1 {
+ txreq
+ rxresp
+} -run
+
+logexpect l1 -wait

View file

@ -0,0 +1,77 @@
--- lib/libvcc/vmodtool.py.orig 2015-03-05 14:20:35.982791597 +0100
+++ lib/libvcc/vmodtool.py 2015-03-05 14:34:46.896115280 +0100
@@ -33,8 +33,8 @@
vmod_${name}.rst -- Extracted documentation
"""
-# This script should work with both Python 2 and Python 3.
-from __future__ import print_function
+## This script should work with both Python 2 and Python 3.
+#from __future__ import print_function
import sys
import re
@@ -67,6 +67,15 @@
#######################################################################
+# __future__ print_function is not available on python2.4 in rhel5, so
+# make a local simple variant _print
+
+def _print(*objects, **kwargs):
+ sep = kwargs.get('sep', ' ')
+ end = kwargs.get('end', '\n')
+ out = kwargs.get('file', sys.stdout)
+ out.write(sep.join(objects) + end)
+
def write_file_warning(fo, a, b, c):
fo.write(a + "\n")
fo.write(b + " NB: This file is machine generated, DO NOT EDIT!\n")
@@ -741,8 +750,8 @@
if opts.strict:
raise FormatError(m, details)
else:
- print("WARNING: %s:" % m, file=sys.stderr)
- print(details, file=sys.stderr)
+ _print("WARNING: %s:" % m, file=sys.stderr)
+ _print(details, file=sys.stderr)
else:
for ln, i in self.l:
o.doc(i)
@@ -784,9 +793,12 @@
def runmain(inputvcc, outputname="vcc_if"):
# Read the file in
lines = []
- with open(inputvcc, "r") as fp:
+ fp = open(inputvcc, "r")
+ try:
for i in fp:
lines.append(i.rstrip())
+ finally:
+ fp.close
ln = 0
#######################################################################
@@ -839,11 +851,11 @@
for i in sl:
i.parse(vx)
assert len(i.tl) == 0
- except ParseError as e:
+ except ParseError, e:
print("ERROR: Parse error reading \"%s\":" % inputvcc)
pprint(str(e))
exit(-1)
- except FormatError as e:
+ except FormatError, e:
print("ERROR: Format error reading \"%s\": %s" %
(inputvcc, pformat(e.msg)))
print(e.details)
@@ -916,7 +928,7 @@
if not i_vcc:
i_vcc = "vmod.vcc"
else:
- print("ERROR: No vmod.vcc file supplied or found.",
+ _print("ERROR: No vmod.vcc file supplied or found.",
file=sys.stderr)
oparser.print_help()
exit(-1)

View file

@ -0,0 +1,11 @@
--- configure.orig 2016-11-30 13:07:13.000000000 +0100
+++ configure 2016-12-02 11:28:49.176227489 +0100
@@ -17067,7 +17067,7 @@
# The reason for -Wno-error=unused-result is a glibc/gcc interaction
# idiocy where write is marked as warn_unused_result, causing build
# failures.
-CFLAGS="${CFLAGS} -Wall -Werror"
+#CFLAGS="${CFLAGS} -Wall -Werror"
OCFLAGS="${OCFLAGS} -Wall -Werror"
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts -Werror=unused-result" >&5
$as_echo_n "checking whether C compiler accepts -Werror=unused-result... " >&6; }

View file

@ -0,0 +1,42 @@
diff -Naur ../varnish-4.0.4.orig/redhat/varnishlog.service redhat/varnishlog.service
--- ../varnish-4.0.4.orig/redhat/varnishlog.service 1970-01-01 01:00:00.000000000 +0100
+++ redhat/varnishlog.service 2016-12-05 20:44:01.579083538 +0100
@@ -0,0 +1,15 @@
+[Unit]
+Description=Varnish Cache HTTP accelerator logging daemon
+After=varnish.service
+
+[Service]
+RuntimeDirectory=varnishlog
+Type=forking
+PIDFile=/run/varnishlog/varnishlog.pid
+User=varnish
+Group=varnish
+ExecStart=/usr/bin/varnishlog -a -w /var/log/varnish/varnish.log -D -P /run/varnishlog/varnishlog.pid
+ExecReload=/bin/kill -HUP $MAINPID
+
+[Install]
+WantedBy=multi-user.target
diff -Naur ../varnish-4.0.4.orig/redhat/varnishncsa.service redhat/varnishncsa.service
--- ../varnish-4.0.4.orig/redhat/varnishncsa.service 2016-11-29 10:45:14.000000000 +0100
+++ redhat/varnishncsa.service 2016-12-05 20:25:01.878729560 +0100
@@ -6,7 +6,7 @@
RuntimeDirectory=varnishncsa
Type=forking
PIDFile=/run/varnishncsa/varnishncsa.pid
-User=varnishlog
+User=varnish
Group=varnish
ExecStart=/usr/bin/varnishncsa -a -w /var/log/varnish/varnishncsa.log -D -P /run/varnishncsa/varnishncsa.pid
ExecReload=/bin/kill -HUP $MAINPID
diff -Naurw ../varnish-4.0.4.orig/redhat/varnish.service redhat/varnish.service
--- ../varnish-4.0.4.orig/redhat/varnish.service 2016-11-29 10:45:14.000000000 +0100
+++ redhat/varnish.service 2016-12-13 01:04:43.853627382 +0100
@@ -34,6 +34,7 @@
-a ${VARNISH_LISTEN_ADDRESS}:${VARNISH_LISTEN_PORT} \
-T ${VARNISH_ADMIN_LISTEN_ADDRESS}:${VARNISH_ADMIN_LISTEN_PORT} \
-S $VARNISH_SECRET_FILE \
+ -u $VARNISH_USER -g $VARNISH_GROUP \
-s $VARNISH_STORAGE \
$DAEMON_OPTS

View file

@ -0,0 +1,120 @@
diff -Naur redhat.orig/varnishlog.initrc redhat/varnishlog.initrc
--- redhat.orig/varnishlog.initrc 1970-01-01 01:00:00.000000000 +0100
+++ redhat/varnishlog.initrc 2016-12-09 14:54:38.721554162 +0100
@@ -0,0 +1,116 @@
+#! /bin/sh
+#
+# varnishlog Control the Varnish logging daemon
+#
+# chkconfig: - 90 10
+# description: Varnish Cache logging daemon
+# processname: varnishlog
+# config:
+# pidfile: /var/run/varnishlog.pid
+
+### BEGIN INIT INFO
+# Provides: varnishlog
+# Required-Start: $network $local_fs $remote_fs
+# Required-Stop: $network $local_fs $remote_fs
+# Default-Start:
+# Default-Stop:
+# Short-Description: start and stop varnishlog
+# Description: Varnish Cache logging daemon
+### END INIT INFO
+
+# Source function library.
+. /etc/init.d/functions
+
+retval=0
+pidfile="/var/run/varnishlog.pid"
+lockfile="/var/lock/subsys/varnishlog"
+logfile="/var/log/varnish/varnish.log"
+
+exec="/usr/bin/varnishlog"
+prog="varnishlog"
+
+DAEMON_OPTS="-a -w $logfile -D -P $pidfile"
+
+# Include varnishlog defaults
+[ -e /etc/sysconfig/varnishlog ] && . /etc/sysconfig/varnishlog
+
+start() {
+
+ if [ ! -x $exec ]
+ then
+ echo $exec not found
+ exit 5
+ fi
+
+ echo -n "Starting varnish logging daemon: "
+
+ daemon --pidfile $pidfile $exec "$DAEMON_OPTS"
+ echo
+ return $retval
+}
+
+stop() {
+ echo -n "Stopping varnish logging daemon: "
+ killproc -p $pidfile $prog
+ retval=$?
+ echo
+ [ $retval -eq 0 ] && rm -f $lockfile
+ return $retval
+}
+
+restart() {
+ stop
+ start
+}
+
+reload() {
+ restart
+}
+
+force_reload() {
+ restart
+}
+
+rh_status() {
+ status -p $pidfile $prog
+}
+
+rh_status_q() {
+ rh_status >/dev/null 2>&1
+}
+
+# See how we were called.
+case "$1" in
+ start)
+ rh_status_q && exit 0
+ $1
+ ;;
+ stop)
+ rh_status_q || exit 0
+ $1
+ ;;
+ restart)
+ $1
+ ;;
+ reload)
+ rh_status_q || exit 7
+ $1
+ ;;
+ force-reload)
+ force_reload
+ ;;
+ status)
+ rh_status
+ ;;
+ condrestart|try-restart)
+ rh_status_q || exit 0
+ restart
+ ;;
+ *)
+ echo "Usage: $0 {start|stop|status|restart|condrestart|try-restart|reload|force-reload}"
+
+ exit 2
+esac
+
+exit $?
+

View file

@ -0,0 +1,141 @@
diff -Naur ../varnish-4.0.5.pre/README ./README
--- ../varnish-4.0.5.pre/README 2017-08-01 11:53:28.000000000 +0200
+++ ./README 2022-02-22 07:58:56.821702441 +0100
@@ -1,5 +1,15 @@
This is Varnish Cache, the high-performance HTTP accelerator.
+SECURITY: The varnish-4.0.x branch is marked END OF LIFE by the Varnish Cache
+upstream project. Please consider upgrading to varnish-6.0 LTS or newer.
+Links to packages compatible with VCL 4.0 and EPEL7 may be found at
+http://varnish-cache.org/releases/
+
+varnish-4.0.5 is vulnerable to CVE-2022-23959.
+If you are unable to upgrade to a current version of varnish, consider
+mitigating against this attack, see instructions in the included file
+vsv8_epel7_varnish405.vcl
+
Documentation and additional information about Varnish is available on
https://www.varnish-cache.org/
diff -Naur ../varnish-4.0.5.pre/redhat/varnishlog.service ./redhat/varnishlog.service
--- ../varnish-4.0.5.pre/redhat/varnishlog.service 2022-02-16 17:36:32.395888407 +0100
+++ ./redhat/varnishlog.service 2022-02-22 08:00:31.199123798 +0100
@@ -9,6 +9,7 @@
User=varnish
Group=varnish
ExecStart=/usr/bin/varnishlog -a -w /var/log/varnish/varnish.log -D -P /run/varnishlog/varnishlog.pid
+ExecStartPost=/bin/sleep 0.5
ExecReload=/bin/kill -HUP $MAINPID
[Install]
diff -Naur ../varnish-4.0.5.pre/redhat/varnishncsa.service ./redhat/varnishncsa.service
--- ../varnish-4.0.5.pre/redhat/varnishncsa.service 2022-02-16 17:36:32.395888407 +0100
+++ ./redhat/varnishncsa.service 2022-02-22 08:00:20.845858003 +0100
@@ -9,6 +9,7 @@
User=varnish
Group=varnish
ExecStart=/usr/bin/varnishncsa -a -w /var/log/varnish/varnishncsa.log -D -P /run/varnishncsa/varnishncsa.pid
+ExecStartPost=/bin/sleep 0.5
ExecReload=/bin/kill -HUP $MAINPID
[Install]
diff -Naur ../varnish-4.0.5.pre/redhat/varnish_pre ./redhat/varnish_pre
--- ../varnish-4.0.5.pre/redhat/varnish_pre 1970-01-01 01:00:00.000000000 +0100
+++ ./redhat/varnish_pre 2022-02-22 07:58:56.821702441 +0100
@@ -0,0 +1,13 @@
+#!/bin/bash
+
+if /usr/sbin/varnishd -V 2>&1 | head -1 | grep -q 'varnish-4\.0\.'; then
+ if [ -f /etc/varnish/vsv8_epel7_varnish405.vcl ]; then true
+ else
+ echo ""
+ echo "WARNING: CVE-2022-23959 MITIGATION NOT FOUND!"
+ echo "Upgrade to varnish-6.0 LTS or add mitigation"
+ echo "See instructions in /usr/share/doc/varnish-4.0.5/vsv8_epel7_varnish405.vcl"
+ echo ""
+ fi
+fi
+
diff -Naur ../varnish-4.0.5.pre/redhat/varnish_reload_vcl ./redhat/varnish_reload_vcl
--- ../varnish-4.0.5.pre/redhat/varnish_reload_vcl 2022-02-16 17:37:15.285507970 +0100
+++ ./redhat/varnish_reload_vcl 2022-02-22 07:58:56.821702441 +0100
@@ -86,12 +86,12 @@
exit 1
fi
-if $VARNISHADM vcl.list | awk ' { print $4 } ' | grep -q $new_config; then
+if $VARNISHADM vcl.list | awk ' { print $3 } ' | grep -q $new_config; then
echo Trying to use new config $new_config, but that is already in use
exit 2
fi
-current_config=$( $VARNISHADM vcl.list | awk ' /^active/ { print $4 } ' )
+current_config=$( $VARNISHADM vcl.list | awk ' /^active/ { print $3 } ' )
echo "Loading vcl from $VARNISH_VCL_CONF"
echo "Current running config name is $current_config"
@@ -112,5 +112,6 @@
fi
$VARNISHADM vcl.list
echo Done
+/usr/sbin/varnish_pre
exit 0
diff -Naur ../varnish-4.0.5.pre/redhat/varnish.service ./redhat/varnish.service
--- ../varnish-4.0.5.pre/redhat/varnish.service 2022-02-16 17:37:15.285507970 +0100
+++ ./redhat/varnish.service 2022-02-22 08:00:06.888499689 +0100
@@ -28,6 +28,7 @@
Type=forking
PIDFile=/var/run/varnish.pid
PrivateTmp=true
+ExecStartPre=/usr/sbin/varnish_pre
ExecStart=/usr/sbin/varnishd \
-P /var/run/varnish.pid \
-f $VARNISH_VCL_CONF \
@@ -38,6 +39,7 @@
-s $VARNISH_STORAGE \
$DAEMON_OPTS
+ExecStartPost=/bin/sleep 0.5
ExecReload=/usr/sbin/varnish_reload_vcl
[Install]
diff -Naur ../varnish-4.0.5.pre/redhat/vsv8_epel7_varnish405.vcl ./redhat/vsv8_epel7_varnish405.vcl
--- ../varnish-4.0.5.pre/redhat/vsv8_epel7_varnish405.vcl 1970-01-01 01:00:00.000000000 +0100
+++ ./redhat/vsv8_epel7_varnish405.vcl 2022-02-22 07:58:56.821702441 +0100
@@ -0,0 +1,35 @@
+# VSV00008 Varnish HTTP/1 Request Smuggling Vulnerability
+# also known as CVE-2022-23959
+#
+# Full details on this CVE at http://varnish-cache.org/security/VSV00008.html
+#
+# SECURITY: The varnish-4.0.x branch is marked END OF LIFE by the Varnish Cache
+# upstream project. Please consider upgrading to varnish-6.0 LTS or newer.
+# Links to packages compatible with VCL 4.0 and EPEL7 may be found at
+# http://varnish-cache.org/releases/
+#
+# varnish-4.0.5 is vulnerable to CVE-2022-23959.
+# If you are unable to upgrade to a current version of varnish, consider
+# mitigating against this attack, by copying this file to
+# /etc/varnish/vsv8_epel7_varnish405.vcl
+# Then near the top of your default.vcl or similar, just below the
+# vcl 4.0; marker, add
+#
+# include "vsv8_epel7_varnish405.vcl";
+#
+# The systemd service unit will warn about this vulnerability in the log until
+# that file exists. If you know that your site is not vulnerable to this
+# attack, you may silence the warning in the log by dropping an empty file at
+# the same location.
+#
+
+sub vsv8_epel7_varnish405 {
+ if ((req.http.Content-Length || req.http.Transfer-Encoding) &&
+ req.proto != "HTTP/2.0") {
+ set resp.http.Connection = "close";
+ }
+}
+
+sub vcl_synth { call vsv8_epel7_varnish405; }
+sub vcl_deliver { call vsv8_epel7_varnish405; }
+

View file

@ -1,11 +0,0 @@
--- redhat/find-provides.orig 2015-10-04 16:55:34.057574682 +0200
+++ redhat/find-provides 2015-10-04 16:56:04.120280796 +0200
@@ -9,8 +9,6 @@
/usr/lib/rpm/find-provides "$@"
fi
-# We don't install vcs_version.h, so we can't use RPM_BUILD_ROOT directly.
-cd /builddir/build/BUILD/varnish* || true
cd ${RPM_BUILD_ROOT}/../../BUILD/varnish* || true
printf '#include "vcs_version.h"\nVCS_Version\n' \

View file

@ -1,41 +0,0 @@
--- doc/sphinx/Makefile.in.orig 2017-03-16 16:01:18.440999286 +0100
+++ doc/sphinx/Makefile.in 2017-03-16 16:02:38.557728852 +0100
@@ -626,28 +626,38 @@
# XXX add varnishstat here when it's been _opt2rst'ed
include/varnishncsa_options.rst: $(top_builddir)/bin/varnishncsa/varnishncsa
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishncsa/varnishncsa --options > $@
include/varnishncsa_synopsis.rst: $(top_builddir)/bin/varnishncsa/varnishncsa
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishncsa/varnishncsa --synopsis > $@
include/varnishlog_options.rst: $(top_builddir)/bin/varnishlog/varnishlog
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishlog/varnishlog --options > $@
include/varnishlog_synopsis.rst: $(top_builddir)/bin/varnishlog/varnishlog
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishlog/varnishlog --synopsis > $@
include/varnishtop_options.rst: $(top_builddir)/bin/varnishtop/varnishtop
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishtop/varnishtop --options > $@
include/varnishtop_synopsis.rst: $(top_builddir)/bin/varnishtop/varnishtop
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishtop/varnishtop --synopsis > $@
include/varnishhist_options.rst: $(top_builddir)/bin/varnishhist/varnishhist
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishhist/varnishhist --options > $@
include/varnishhist_synopsis.rst: $(top_builddir)/bin/varnishhist/varnishhist
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishhist/varnishhist --synopsis > $@
include/varnishstat_options.rst: $(top_builddir)/bin/varnishstat/varnishstat
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishstat/varnishstat --options > $@
include/varnishstat_synopsis.rst: $(top_builddir)/bin/varnishstat/varnishstat
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishstat/varnishstat --synopsis > $@
include/vsl-tags.rst: $(top_builddir)/lib/libvarnishapi/vsl2rst

View file

@ -1,62 +0,0 @@
--- configure.orig 2017-03-18 02:53:31.235204299 +0100
+++ configure 2017-03-18 02:54:54.229053852 +0100
@@ -13545,13 +13545,13 @@
if test -n "$PYTHON"; then
# If the user set $PYTHON, use it and don't search something else.
- { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether $PYTHON version is >= 2.7" >&5
-$as_echo_n "checking whether $PYTHON version is >= 2.7... " >&6; }
+ { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether $PYTHON version is >= 2.4" >&5
+$as_echo_n "checking whether $PYTHON version is >= 2.4... " >&6; }
prog="import sys
# split strings by '.' and convert to numeric. Append some zeros
# because we need at least 4 digits for the hex conversion.
# map returns an iterator in Python 3.0 and a list in 2.x
-minver = list(map(int, '2.7'.split('.'))) + [0, 0, 0]
+minver = list(map(int, '2.4'.split('.'))) + [0, 0, 0]
minverhex = 0
# xrange is not present in Python 3.0 and range returns an iterator
for i in list(range(0, 4)): minverhex = (minverhex << 8) + minver[i]
@@ -13572,8 +13572,8 @@
else
# Otherwise, try each interpreter until we find one that satisfies
# VERSION.
- { $as_echo "$as_me:${as_lineno-$LINENO}: checking for a Python interpreter with version >= 2.7" >&5
-$as_echo_n "checking for a Python interpreter with version >= 2.7... " >&6; }
+ { $as_echo "$as_me:${as_lineno-$LINENO}: checking for a Python interpreter with version >= 2.4" >&5
+$as_echo_n "checking for a Python interpreter with version >= 2.4... " >&6; }
if ${am_cv_pathless_PYTHON+:} false; then :
$as_echo_n "(cached) " >&6
else
@@ -13584,7 +13584,7 @@
# split strings by '.' and convert to numeric. Append some zeros
# because we need at least 4 digits for the hex conversion.
# map returns an iterator in Python 3.0 and a list in 2.x
-minver = list(map(int, '2.7'.split('.'))) + [0, 0, 0]
+minver = list(map(int, '2.4'.split('.'))) + [0, 0, 0]
minverhex = 0
# xrange is not present in Python 3.0 and range returns an iterator
for i in list(range(0, 4)): minverhex = (minverhex << 8) + minver[i]
@@ -13651,7 +13651,7 @@
if test "$PYTHON" = :; then
- as_fn_error $? "Python >= 2.7 is required." "$LINENO" 5
+ as_fn_error $? "Python >= 2.4 is required." "$LINENO" 5
else
@@ -13698,11 +13698,11 @@
can_use_sysconfig = 0
else:
can_use_sysconfig = 1
-# Can't use sysconfig in CPython 2.7, since it's broken in virtualenvs:
+# Can't use sysconfig in CPython 2.4, since it's broken in virtualenvs:
# <https://github.com/pypa/virtualenv/issues/118>
try:
from platform import python_implementation
- if python_implementation() == 'CPython' and sys.version[:3] == '2.7':
+ if python_implementation() == 'CPython' and sys.version[:3] == '2.4':
can_use_sysconfig = 0
except ImportError:
pass"

View file

@ -1,66 +0,0 @@
From 17c92e43fda114bf5341e51d752e882238b8fe8c Mon Sep 17 00:00:00 2001
From: Nils Goroll <nils.goroll@uplex.de>
Date: Thu, 5 Oct 2017 13:39:23 +0200
Subject: [PATCH] hack up vsctool to work with python 2 and 3
StringIO does not exist any more in python3, yet requiring 2.7 would
not pave the path forward, so try to be compatible with both.
Works for me on Python 2.7.9 and Python 3.4
I would appreciate if someone more fluent in serpentinous programming
language reviewed and/or rewrote this.
---
lib/libvcc/vsctool.py | 24 ++++++++++++++++++++----
1 file changed, 20 insertions(+), 4 deletions(-)
diff --git a/lib/libvcc/vsctool.py b/lib/libvcc/vsctool.py
index 854968e3b..829c6e518 100644
--- a/lib/libvcc/vsctool.py
+++ b/lib/libvcc/vsctool.py
@@ -37,7 +37,10 @@
import json
import sys
import gzip
-import StringIO
+try:
+ import StringIO
+except ImportError:
+ import io
import collections
import struct
@@ -54,9 +57,22 @@
"format": [ "integer", FORMATS],
}
+# http://python3porting.com/problems.html#bytes-strings-and-unicode
+if sys.version_info < (3,):
+ def b(x):
+ return x
+else:
+ import codecs
+ def b(x):
+ return codecs.latin_1_encode(x)[0]
+
def gzip_str(s):
- out = StringIO.StringIO()
- gzip.GzipFile(fileobj=out, mode="w").write(s)
+ try:
+ out = StringIO.StringIO()
+ except NameError:
+ out = io.BytesIO()
+
+ gzip.GzipFile(fileobj=out, mode="w").write(b(s))
out.seek(4)
out.write(struct.pack("<L", 0x12bfd58))
return out.getvalue()
@@ -285,7 +301,7 @@ class rst_vsc(directive):
def __init__(self, s):
super(rst_vsc, self).__init__(s)
- for i,v in PARAMS.iteritems():
+ for i,v in PARAMS.items():
if v is not True:
self.do_default(i, v[0], v[1])

View file

@ -1,20 +0,0 @@
--- bin/varnishtest/vtc_process.c.orig 2018-04-26 14:12:29.539178105 +0100
+++ bin/varnishtest/vtc_process.c 2018-04-26 15:27:49.851948252 +0100
@@ -216,7 +216,7 @@
vtc_dump(p->vl, 4, "stdout", buf, i);
else if (p->log == 3)
vtc_hexdump(p->vl, 4, "stdout", buf, i);
- (void)write(p->f_stdout, buf, i);
+ assert(write(p->f_stdout, buf, i) == i);
Term_Feed(p->term, buf, buf + i);
return (0);
}
@@ -239,7 +239,7 @@
p->stderr_bytes += i;
AZ(pthread_mutex_unlock(&p->mtx));
vtc_dump(p->vl, 4, "stderr", buf, i);
- (void)write(p->f_stderr, buf, i);
+ assert(write(p->f_stdout, buf, i) == i);
return (0);
}

View file

@ -1,96 +0,0 @@
Based on fix for upstream bug #2668, see
https://github.com/varnishcache/varnish-cache/commit/9bdc5f75d661a1659c4df60799612a7524a6caa7
diff -Naur ../varnish-6.0.1.orig/bin/varnishtest/gensequences ./bin/varnishtest/gensequences
--- ../varnish-6.0.1.orig/bin/varnishtest/gensequences 2018-08-29 11:48:32.000000000 +0200
+++ ./bin/varnishtest/gensequences 2018-09-27 12:18:20.946853383 +0200
@@ -149,6 +149,7 @@
if (l_prefix_name[p] != "teken_state_init") {
print "";
+ print "\tt->t_last = 0;";
print "\tteken_state_switch(t, teken_state_init);";
}
print "}";
diff -Naur ../varnish-6.0.1.orig/bin/varnishtest/sequences ./bin/varnishtest/sequences
--- ../varnish-6.0.1.orig/bin/varnishtest/sequences 2018-08-29 11:48:32.000000000 +0200
+++ ./bin/varnishtest/sequences 2018-09-27 12:18:50.193581932 +0200
@@ -113,3 +113,6 @@
# VT52 compatibility
#DECID VT52 DECID ^[ Z
+
+# ECMA-48
+REP Repeat last graphic char ^[ [ b n
diff -Naur ../varnish-6.0.1.orig/bin/varnishtest/teken.h ./bin/varnishtest/teken.h
--- ../varnish-6.0.1.orig/bin/varnishtest/teken.h 2018-08-29 11:48:32.000000000 +0200
+++ ./bin/varnishtest/teken.h 2018-09-27 12:18:20.947853442 +0200
@@ -153,6 +153,7 @@
unsigned int t_utf8_left;
teken_char_t t_utf8_partial;
+ teken_char_t t_last;
unsigned int t_curscs;
teken_scs_t *t_saved_curscs;
diff -Naur ../varnish-6.0.1.orig/bin/varnishtest/teken_subr.h ./bin/varnishtest/teken_subr.h
--- ../varnish-6.0.1.orig/bin/varnishtest/teken_subr.h 2018-08-29 11:48:32.000000000 +0200
+++ ./bin/varnishtest/teken_subr.h 2018-09-27 12:18:20.947853442 +0200
@@ -777,10 +777,11 @@
}
static void
-teken_subr_do_putchar(const teken_t *t, const teken_pos_t *tp, teken_char_t c,
+teken_subr_do_putchar(teken_t *t, const teken_pos_t *tp, teken_char_t c,
int width)
{
+ t->t_last = c;
if (t->t_stateflags & TS_INSERT &&
tp->tp_col < t->t_winsize.tp_col - width) {
teken_rect_t ctr;
@@ -1313,3 +1314,12 @@
t->t_stateflags &= ~TS_WRAPPED;
teken_funcs_cursor(t);
}
+
+static void
+teken_subr_repeat_last_graphic_char(teken_t *t, unsigned int rpts)
+{
+
+ for (; t->t_last != 0 && rpts > 0; rpts--)
+ teken_subr_regular_character(t, t->t_last);
+}
+
diff -Naur ../varnish-6.0.1.orig/bin/varnishtest/tests/a00001.vtc ./bin/varnishtest/tests/a00001.vtc
--- ../varnish-6.0.1.orig/bin/varnishtest/tests/a00001.vtc 2018-08-29 11:48:32.000000000 +0200
+++ ./bin/varnishtest/tests/a00001.vtc 2018-09-27 12:18:20.948853501 +0200
@@ -204,6 +204,27 @@
process p4 -expect-text 21 11 "Enter choice number (0 - 12):"
process p4 -screen_dump
+# 11. Test non-VT100 (e.g., VT220, XTERM) terminals
+process p4 -writehex "31 31 0d"
+process p4 -expect-text 0 0 "Menu 11: Non-VT100 Tests"
+
+process p4 -writehex "37 0d"
+process p4 -expect-text 0 0 "Menu 11.7: Miscellaneous ISO-6429 (ECMA-48) Tests"
+
+process p4 -writehex "32 0d"
+process p4 -expect-text 0 0 "Push <RETURN>"
+process p4 -screen_dump
+process p4 -expect-text 20 1 "Test Repeat (REP)"
+process p4 -expect-text 1 1 " ++ "
+process p4 -expect-text 2 2 " ++ "
+process p4 -expect-text 17 17 " ++ "
+process p4 -expect-text 18 18 "*++*"
+process p4 -writehex "0d"
+process p4 -expect-text 0 0 "Menu 11.7: Miscellaneous ISO-6429 (ECMA-48) Tests"
+process p4 -writehex "30 0d"
+process p4 -expect-text 0 0 "Menu 11: Non-VT100 Tests"
+process p4 -writehex "30 0d"
+
# 0. Exit
process p4 -writehex "30 0d"
process p4 -expect-text 12 30 "That's all, folks!"

View file

@ -1,53 +0,0 @@
--- doc/sphinx/Makefile.in.orig 2018-11-02 14:53:14.812956915 +0100
+++ doc/sphinx/Makefile.in 2018-11-02 14:54:31.575517733 +0100
@@ -642,9 +642,11 @@
rm -rf $(BUILDDIR)
include/cli.rst: $(top_builddir)/bin/varnishd/varnishd
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishd/varnishd -x cli > $@
include/params.rst: $(top_builddir)/bin/varnishd/varnishd
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishd/varnishd -x parameter > $@
include/counters.rst: $(top_srcdir)/lib/libvcc/vsctool.py $(COUNTERS)
@@ -656,28 +658,38 @@
# XXX add varnishstat here when it's been _opt2rst'ed
include/varnishncsa_options.rst: $(top_builddir)/bin/varnishncsa/varnishncsa
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishncsa/varnishncsa --options > $@
include/varnishncsa_synopsis.rst: $(top_builddir)/bin/varnishncsa/varnishncsa
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishncsa/varnishncsa --synopsis > $@
include/varnishlog_options.rst: $(top_builddir)/bin/varnishlog/varnishlog
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishlog/varnishlog --options > $@
include/varnishlog_synopsis.rst: $(top_builddir)/bin/varnishlog/varnishlog
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishlog/varnishlog --synopsis > $@
include/varnishtop_options.rst: $(top_builddir)/bin/varnishtop/varnishtop
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishtop/varnishtop --options > $@
include/varnishtop_synopsis.rst: $(top_builddir)/bin/varnishtop/varnishtop
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishtop/varnishtop --synopsis > $@
include/varnishhist_options.rst: $(top_builddir)/bin/varnishhist/varnishhist
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishhist/varnishhist --options > $@
include/varnishhist_synopsis.rst: $(top_builddir)/bin/varnishhist/varnishhist
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishhist/varnishhist --synopsis > $@
include/varnishstat_options.rst: $(top_builddir)/bin/varnishstat/varnishstat
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishstat/varnishstat --options > $@
include/varnishstat_synopsis.rst: $(top_builddir)/bin/varnishstat/varnishstat
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishstat/varnishstat --synopsis > $@
include/vsl-tags.rst: $(top_builddir)/lib/libvarnishapi/vsl2rst

View file

@ -1,13 +0,0 @@
--- bin/varnishtest/tests/u00008.vtc.orig 2018-11-02 16:06:40.731680282 +0100
+++ bin/varnishtest/tests/u00008.vtc 2018-11-02 16:07:21.587092836 +0100
@@ -38,8 +38,8 @@
process p1 -screen_dump
process p1 -winsz 25 132
-process p1 -expect-text 4 124 "AVG_1000"
-process p1 -expect-text 22 108 "UNSEEN DIAG"
+process p1 -expect-text 4 0 "AVG_1000"
+process p1 -expect-text 22 0 "UNSEEN DIAG"
process p1 -screen_dump -write {q} -wait

View file

@ -1,115 +0,0 @@
This patch is a fix for memory issues with
pcre-jit, see upstream bug report at
https://github.com/varnishcache/varnish-cache/issues/2817
The patch is based on upstream commits
a3129a5340566d17192de8058a9c1dbb051a7039
683b7cbe8cde1dde8f9e516a354b82430f1d318e
1226e77f9501c56976635c714c99d84f417aa5d2
diff -Naur a/bin/varnishd/cache/cache_panic.c b/bin/varnishd/cache/cache_panic.c
--- a/bin/varnishd/cache/cache_panic.c 2018-10-24 11:29:10.000000000 +0200
+++ b/bin/varnishd/cache/cache_panic.c 2019-03-07 16:27:16.592441674 +0100
@@ -601,6 +601,33 @@
VSB_indent(vsb, -2);
}
+#ifdef HAVE_PTHREAD_GETATTR_NP
+static void
+pan_threadattr(struct vsb *vsb)
+{
+ pthread_attr_t attr[1];
+ size_t sz;
+ void *addr;
+
+ if (pthread_getattr_np(pthread_self(), attr) != 0)
+ return;
+
+ VSB_cat(vsb, "pthread.attr = {\n");
+ VSB_indent(vsb, 2);
+
+ if (pthread_attr_getguardsize(attr, &sz) == 0)
+ VSB_printf(vsb, "guard = %zu,\n", sz);
+ if (pthread_attr_getstack(attr, &addr, &sz) == 0) {
+ VSB_printf(vsb, "stack_bottom = %p,\n", addr);
+ VSB_printf(vsb, "stack_top = %p,\n", (char *)addr + sz);
+ VSB_printf(vsb, "stack_size = %zu,\n", sz);
+ }
+ VSB_indent(vsb, -2);
+ VSB_cat(vsb, "}\n");
+ (void) pthread_attr_destroy(attr);
+}
+#endif
+
/*--------------------------------------------------------------------*/
static void __attribute__((__noreturn__))
@@ -673,6 +700,10 @@
if (q != NULL)
VSB_printf(pan_vsb, "thread = (%s)\n", q);
+#ifdef HAVE_PTHREAD_GETATTR_NP
+ pan_threadattr(pan_vsb);
+#endif
+
if (!FEATURE(FEATURE_SHORT_PANIC)) {
req = THR_GetRequest();
VSB_cat(pan_vsb, "thr.");
diff -Naur a/bin/varnishd/mgt/mgt_param.c b/bin/varnishd/mgt/mgt_param.c
--- a/bin/varnishd/mgt/mgt_param.c 2018-10-24 11:29:10.000000000 +0200
+++ b/bin/varnishd/mgt/mgt_param.c 2019-03-07 16:27:16.594441699 +0100
@@ -494,6 +494,8 @@
MCF_TcpParams();
+ def = 56 * 1024;
+
if (sizeof(void *) < 8) { /*lint !e506 !e774 */
/*
* Adjust default parameters for 32 bit systems to conserve
@@ -505,20 +507,16 @@
MCF_ParamConf(MCF_DEFAULT, "http_req_size", "12k");
MCF_ParamConf(MCF_DEFAULT, "gzip_buffer", "4k");
MCF_ParamConf(MCF_MAXIMUM, "vsl_space", "1G");
+ def = 48 * 1024;
}
-#if !defined(HAVE_ACCEPT_FILTERS) || defined(__linux)
- MCF_ParamConf(MCF_DEFAULT, "accept_filter", "off");
-#endif
-
low = sysconf(_SC_THREAD_STACK_MIN);
MCF_ParamConf(MCF_MINIMUM, "thread_pool_stack", "%jdb", (intmax_t)low);
#if defined(__SANITIZER) || __has_feature(address_sanitizer)
def = 92 * 1024;
-#else
- def = 48 * 1024;
#endif
+
if (def < low)
def = low;
MCF_ParamConf(MCF_DEFAULT, "thread_pool_stack", "%jdb", (intmax_t)def);
@@ -529,6 +527,10 @@
MCF_ParamConf(MCF_MAXIMUM, "thread_pools", "%d", MAX_THREAD_POOLS);
+#if !defined(HAVE_ACCEPT_FILTERS) || defined(__linux)
+ MCF_ParamConf(MCF_DEFAULT, "accept_filter", "off");
+#endif
+
VCLS_AddFunc(mgt_cls, MCF_AUTH, cli_params);
vsb = VSB_new_auto();
diff -Naur a/configure.ac b/configure.ac
--- a/configure.ac 2018-10-26 13:22:45.000000000 +0200
+++ b/configure.ac 2019-03-07 16:27:16.592441674 +0100
@@ -239,6 +239,7 @@
AC_CHECK_FUNCS([pthread_set_name_np])
AC_CHECK_FUNCS([pthread_setname_np])
AC_CHECK_FUNCS([pthread_mutex_isowned_np])
+AC_CHECK_FUNCS([pthread_getattr_np])
LIBS="${save_LIBS}"
# Support for visibility attribute

View file

@ -1,68 +0,0 @@
--- doc/sphinx/Makefile.in.orig 2018-11-06 16:46:59.403632379 +0100
+++ doc/sphinx/Makefile.in 2018-11-06 16:48:28.011784013 +0100
@@ -643,10 +643,12 @@
rm -rf $(BUILDDIR)
include/cli.rst: $(top_builddir)/bin/varnishd/varnishd
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishd/varnishd -x cli > ${@}_
mv ${@}_ ${@}
include/params.rst: $(top_builddir)/bin/varnishd/varnishd
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishd/varnishd -x parameter > ${@}_
mv ${@}_ ${@}
@@ -660,41 +662,52 @@
# XXX add varnishstat here when it's been _opt2rst'ed
include/varnishncsa_options.rst: $(top_builddir)/bin/varnishncsa/varnishncsa
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishncsa/varnishncsa --options > ${@}_
mv ${@}_ ${@}
include/varnishncsa_synopsis.rst: $(top_builddir)/bin/varnishncsa/varnishncsa
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishncsa/varnishncsa --synopsis > ${@}_
mv ${@}_ ${@}
include/varnishlog_options.rst: $(top_builddir)/bin/varnishlog/varnishlog
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishlog/varnishlog --options > ${@}_
mv ${@}_ ${@}
include/varnishlog_synopsis.rst: $(top_builddir)/bin/varnishlog/varnishlog
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishlog/varnishlog --synopsis > ${@}_
mv ${@}_ ${@}
include/varnishtop_options.rst: $(top_builddir)/bin/varnishtop/varnishtop
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishtop/varnishtop --options > ${@}_
mv ${@}_ ${@}
include/varnishtop_synopsis.rst: $(top_builddir)/bin/varnishtop/varnishtop
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishtop/varnishtop --synopsis > ${@}_
mv ${@}_ ${@}
include/varnishhist_options.rst: $(top_builddir)/bin/varnishhist/varnishhist
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishhist/varnishhist --options > ${@}_
mv ${@}_ ${@}
include/varnishhist_synopsis.rst: $(top_builddir)/bin/varnishhist/varnishhist
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishhist/varnishhist --synopsis > ${@}_
mv ${@}_ ${@}
include/varnishstat_options.rst: $(top_builddir)/bin/varnishstat/varnishstat
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishstat/varnishstat --options > ${@}_
mv ${@}_ ${@}
include/varnishstat_synopsis.rst: $(top_builddir)/bin/varnishstat/varnishstat
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/bin/varnishstat/varnishstat --synopsis > ${@}_
mv ${@}_ ${@}
include/vsl-tags.rst: $(top_builddir)/lib/libvarnishapi/vsl2rst
+ LD_LIBRARY_PATH=$(top_builddir)/lib/libvarnishapi/.libs \
$(top_builddir)/lib/libvarnishapi/vsl2rst > ${@}_
mv ${@}_ ${@}
include/vtc-syntax.rst: vtc-syntax.py $(VTCSYN_SRC)

View file

@ -1,39 +0,0 @@
commit 7119d790b590e7fb560ad602cedfda5185c7e841
Author: Poul-Henning Kamp <phk@FreeBSD.org>
Date: Fri Jan 11 10:26:44 2019 +0000
Avoid printing %s,NULL in case of errors we do not expect.
Fixes #2879
diff --git a/lib/libvarnish/vnum.c b/lib/libvarnish/vnum.c
index b619199c6..59e804ec8 100644
--- a/lib/libvarnish/vnum.c
+++ b/lib/libvarnish/vnum.c
@@ -349,15 +349,17 @@ main(int argc, char *argv[])
for (tc = test_cases; tc->str; ++tc) {
e = VNUM_2bytes(tc->str, &val, tc->rel);
- if (e != tc->err) {
- printf("%s: VNUM_2bytes(\"%s\", %ju) (%s) != (%s)\n",
- *argv, tc->str, tc->rel, tc->err, e);
- ++ec;
- } else if (e == NULL && val != tc->val) {
- printf("%s: VNUM_2bytes(\"%s\", %ju) %ju != %ju (%s)\n",
- *argv, tc->str, tc->rel, val, tc->val, e);
- ++ec;
- }
+ if (e != NULL)
+ val = 0;
+ if (e == tc->err && val == tc->val)
+ continue;
+ ++ec;
+ printf("%s: VNUM_2bytes(\"%s\", %ju)\n",
+ *argv, tc->str, tc->rel);
+ printf("\tExpected:\tstatus %s - value %ju\n",
+ tc->err ? tc->err : "Success", tc->val);
+ printf("\tGot:\t\tstatus %s - value %ju\n",
+ e ? e : "Success", val);
}
if (!isnan(VNUM_duration(NULL))) {
printf("%s: VNUM_Duration(NULL) fail\n", *argv);

View file

@ -1,73 +0,0 @@
--- bin/varnishtest/vtc_main.c.orig 2019-03-15 12:31:56.999877378 +0100
+++ bin/varnishtest/vtc_main.c 2019-03-15 12:33:07.679889311 +0100
@@ -228,7 +228,7 @@
assert(cleaner_pid >= 0);
if (cleaner_pid == 0) {
closefd(&p[1]);
- (void)nice(1); /* Not important */
+ if (nice(1)) 1; /* Not important */
setbuf(stdin, NULL);
AZ(dup2(p[0], STDIN_FILENO));
while (fgets(buf, sizeof buf, stdin)) {
--- lib/libvarnishapi/vsm.c.orig 2019-03-18 13:24:01.377237092 +0100
+++ lib/libvarnishapi/vsm.c 2019-03-18 13:24:42.765783845 +0100
@@ -682,18 +682,18 @@
VSM_ResetError(vd);
if (u & VSM_MGT_RUNNING) {
if (progress >= 0 && n > 4)
- (void)write(progress, "\n", 1);
+ if (write(progress, "\n", 1)) 1;
vd->attached = 1;
return (0);
}
if (t0 < VTIM_mono()) {
if (progress >= 0 && n > 4)
- (void)write(progress, "\n", 1);
+ if (write(progress, "\n", 1)) 1;
return (vsm_diag(vd,
"Could not get hold of varnishd, is it running?"));
}
if (progress >= 0 && !(++n % 4))
- (void)write(progress, ".", 1);
+ if (write(progress, ".", 1)) 1;
VTIM_sleep(.25);
}
return (vsm_diag(vd, "Attach interrupted"));
--- bin/varnishd/http1/cache_http1_deliver.c.orig 2019-03-18 13:30:43.262546105 +0100
+++ bin/varnishd/http1/cache_http1_deliver.c 2019-03-18 14:12:48.980850397 +0100
@@ -74,7 +74,7 @@
VSLb(req->vsl, SLT_RespReason, "Internal Server Error");
req->wrk->stats->client_resp_500++;
- (void)write(req->sp->fd, r_500, sizeof r_500 - 1);
+ if (write(req->sp->fd, r_500, sizeof r_500 - 1)) 0;
req->doclose = SC_TX_EOF;
}
--- ./bin/varnishd/mgt/mgt_param.c.orig 2019-03-18 14:48:56.084720420 +0100
+++ ./bin/varnishd/mgt/mgt_param.c 2019-03-18 14:51:25.867836687 +0100
@@ -802,11 +802,11 @@
t2 = strchr(t1 + 1, '\t');
AN(t2);
printf("\n\t*");
- (void)fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout);
+ if (fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout)) 1;
printf("*\n\t\t");
p = t2 + 1;
}
- (void)fwrite(p, q - p, 1, stdout);
+ if (fwrite(p, q - p, 1, stdout)) 1;
p = q;
if (*p == '\n') {
printf("\n");
--- ./bin/varnishd/proxy/cache_proxy_proto.c.orig 2019-03-18 14:54:18.257283901 +0100
+++ ./bin/varnishd/proxy/cache_proxy_proto.c 2019-03-18 14:54:47.119693630 +0100
@@ -669,7 +669,7 @@
WRONG("Wrong proxy version");
AZ(VSB_finish(vsb));
- (void)write(fd, VSB_data(vsb), VSB_len(vsb));
+ if (write(fd, VSB_data(vsb), VSB_len(vsb))) 1;
if (!DO_DEBUG(DBG_PROTOCOL)) {
VSB_delete(vsb);
return;

View file

@ -1,40 +0,0 @@
commit 88948d982bcd165e05967d2a9c8684eb9f9cbd01
Author: Nils Goroll <nils.goroll@uplex.de>
Date: Wed Mar 20 11:24:33 2019 +0100
Change the stack overflow test to 128kb stacksize
on ppc64 fedora, the thread_pool_stack minimum is 128kb due to
sysconf(_SC_THREAD_STACK_MIN) = 131072
It does not harm the test to use a larger stacksize, so we adjust it to
this requirement for consistency and simplicity
diff --git a/bin/varnishtest/tests/c00057.vtc b/bin/varnishtest/tests/c00057.vtc
index 5118c79a0..be6569d24 100644
--- a/bin/varnishtest/tests/c00057.vtc
+++ b/bin/varnishtest/tests/c00057.vtc
@@ -12,7 +12,7 @@ server s1 {
varnish v1 \
-arg "-p feature=+no_coredump" \
-arg "-p vcc_allow_inline_c=true" \
- -arg "-p thread_pool_stack=48k" \
+ -arg "-p thread_pool_stack=128k" \
-vcl+backend {
C{
#include <signal.h>
@@ -27,11 +27,12 @@ void (*accessor)(volatile char *p) = _accessor;
}C
sub vcl_recv { C{
+ const int stkkb = 128;
int i;
- volatile char overflow[48*1024];
+ volatile char overflow[stkkb * 1024];
/* for downwards stack, take care to hit a single guard page */
- for (i = 47*1024; i >= 0; i -= 1024)
+ for (i = (stkkb - 1) * 1024; i >= 0; i -= 1024)
accessor(overflow + i);
/* NOTREACHED */
sleep(2);

View file

@ -1,79 +0,0 @@
diff -Naur varnish-6.3.0.orig/bin/varnishd/http1/cache_http1_deliver.c varnish-6.3.0/bin/varnishd/http1/cache_http1_deliver.c
--- varnish-6.3.0.orig/bin/varnishd/http1/cache_http1_deliver.c 2019-09-16 10:24:15.000000000 +0200
+++ varnish-6.3.0/bin/varnishd/http1/cache_http1_deliver.c 2019-09-20 08:59:52.609482627 +0200
@@ -74,7 +74,7 @@
VSLb(req->vsl, SLT_RespReason, "Internal Server Error");
req->wrk->stats->client_resp_500++;
- (void)write(req->sp->fd, r_500, sizeof r_500 - 1);
+ if (write(req->sp->fd, r_500, sizeof r_500 - 1)) 0;
req->doclose = SC_TX_EOF;
}
diff -Naur varnish-6.3.0.orig/bin/varnishd/mgt/mgt_param.c varnish-6.3.0/bin/varnishd/mgt/mgt_param.c
--- varnish-6.3.0.orig/bin/varnishd/mgt/mgt_param.c 2019-09-16 10:24:15.000000000 +0200
+++ varnish-6.3.0/bin/varnishd/mgt/mgt_param.c 2019-09-20 09:01:38.866609297 +0200
@@ -805,11 +805,11 @@
t2 = strchr(t1 + 1, '\t');
AN(t2);
printf("\n\t*");
- (void)fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout);
+ if (fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout)) 1;
printf("*\n\t\t");
p = t2 + 1;
}
- (void)fwrite(p, q - p, 1, stdout);
+ if(fwrite(p, q - p, 1, stdout)) 1;
p = q;
if (*p == '\n') {
printf("\n");
diff -Naur varnish-6.3.0.orig/bin/varnishd/proxy/cache_proxy_proto.c varnish-6.3.0/bin/varnishd/proxy/cache_proxy_proto.c
--- varnish-6.3.0.orig/bin/varnishd/proxy/cache_proxy_proto.c 2019-09-16 10:24:15.000000000 +0200
+++ varnish-6.3.0/bin/varnishd/proxy/cache_proxy_proto.c 2019-09-20 09:02:55.762424644 +0200
@@ -645,7 +645,7 @@
WRONG("Wrong proxy version");
AZ(VSB_finish(vsb));
- (void)VSB_tofile(fd, vsb); // XXX: Error handling ?
+ if (VSB_tofile(fd, vsb)) 1; // XXX: Error handling ?
if (!DO_DEBUG(DBG_PROTOCOL)) {
VSB_delete(vsb);
return;
diff -Naur varnish-6.3.0.orig/bin/varnishtest/vtc_main.c varnish-6.3.0/bin/varnishtest/vtc_main.c
--- varnish-6.3.0.orig/bin/varnishtest/vtc_main.c 2019-09-16 10:24:15.000000000 +0200
+++ varnish-6.3.0/bin/varnishtest/vtc_main.c 2019-09-20 08:56:45.639506046 +0200
@@ -230,7 +230,7 @@
assert(cleaner_pid >= 0);
if (cleaner_pid == 0) {
closefd(&p[1]);
- (void)nice(1); /* Not important */
+ if (nice(1)) 1;
setbuf(stdin, NULL);
AZ(dup2(p[0], STDIN_FILENO));
while (fgets(buf, sizeof buf, stdin)) {
diff -Naur varnish-6.3.0.orig/lib/libvarnishapi/vsm.c varnish-6.3.0/lib/libvarnishapi/vsm.c
--- varnish-6.3.0.orig/lib/libvarnishapi/vsm.c 2019-09-16 10:24:19.000000000 +0200
+++ varnish-6.3.0/lib/libvarnishapi/vsm.c 2019-09-20 10:36:02.434763755 +0200
@@ -763,18 +763,18 @@
VSM_ResetError(vd);
if (u & VSM_MGT_RUNNING) {
if (progress >= 0 && n > 4)
- (void)write(progress, "\n", 1);
+ if (!write(progress, "\n", 1)) return (vsm_diag(vd, "Unable to write progress"));
vd->attached = 1;
return (0);
}
if (t0 < VTIM_mono()) {
if (progress >= 0 && n > 4)
- (void)write(progress, "\n", 1);
+ if (!write(progress, "\n", 1)) return (vsm_diag(vd, "Unable to write progress"));
return (vsm_diag(vd,
"Could not get hold of varnishd, is it running?"));
}
if (progress >= 0 && !(++n % 4))
- (void)write(progress, ".", 1);
+ if (!write(progress, ".", 1)) return (vsm_diag(vd, "Unable to write progress"));
VTIM_sleep(.25);
}
return (vsm_diag(vd, "Attach interrupted"));

View file

@ -1,19 +0,0 @@
commit b0af060fb688b8fc2ff3817ea99430432668b291
Author: Ingvar Hagelund <ingvar@redpill-linpro.com>
Date: Tue Feb 11 12:56:54 2020 +0100
simple fix for fedora/gcc-10.0.1: -Werror=format-overflow, by some reason hit on s390x
diff --git a/bin/varnishtest/vtc_varnish.c b/bin/varnishtest/vtc_varnish.c
index 1ec748cb6..09e49d258 100644
--- a/bin/varnishtest/vtc_varnish.c
+++ b/bin/varnishtest/vtc_varnish.c
@@ -121,7 +121,7 @@ varnish_ask_cli(const struct varnish *v, const char *cmd, char **repl)
i = VCLI_ReadResult(v->cli_fd, &retval, &r, vtc_maxdur);
if (i != 0 && !vtc_stop)
vtc_fatal(v->vl, "CLI failed (%s) = %d %u %s",
- cmd, i, retval, r);
+ cmd != NULL ? cmd : "NULL", i, retval, r);
vtc_log(v->vl, 3, "CLI RX %u", retval);
vtc_dump(v->vl, 4, "CLI RX", r, -1);
if (repl != NULL)

View file

@ -1,67 +0,0 @@
diff -Naur varnish-6.3.0.orig/bin/varnishd/http1/cache_http1_deliver.c varnish-6.3.0/bin/varnishd/http1/cache_http1_deliver.c
--- varnish-6.3.0.orig/bin/varnishd/http1/cache_http1_deliver.c 2019-09-16 10:24:15.000000000 +0200
+++ varnish-6.3.0/bin/varnishd/http1/cache_http1_deliver.c 2019-09-20 08:59:52.609482627 +0200
@@ -74,7 +74,7 @@
VSLb(req->vsl, SLT_RespReason, "Internal Server Error");
req->wrk->stats->client_resp_500++;
- (void)write(req->sp->fd, r_500, sizeof r_500 - 1);
+ if (write(req->sp->fd, r_500, sizeof r_500 - 1)) 0;
req->doclose = SC_TX_EOF;
}
diff -Naur varnish-6.3.0.orig/bin/varnishd/mgt/mgt_param.c varnish-6.3.0/bin/varnishd/mgt/mgt_param.c
--- varnish-6.3.0.orig/bin/varnishd/mgt/mgt_param.c 2019-09-16 10:24:15.000000000 +0200
+++ varnish-6.3.0/bin/varnishd/mgt/mgt_param.c 2019-09-20 09:01:38.866609297 +0200
@@ -805,11 +805,11 @@
t2 = strchr(t1 + 1, '\t');
AN(t2);
printf("\n\t*");
- (void)fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout);
+ if (fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout)) 1;
printf("*\n\t\t");
p = t2 + 1;
}
- (void)fwrite(p, q - p, 1, stdout);
+ if(fwrite(p, q - p, 1, stdout)) 1;
p = q;
if (*p == '\n') {
printf("\n");
diff -Naur varnish-6.3.0.orig/bin/varnishtest/vtc_main.c varnish-6.3.0/bin/varnishtest/vtc_main.c
--- varnish-6.3.0.orig/bin/varnishtest/vtc_main.c 2019-09-16 10:24:15.000000000 +0200
+++ varnish-6.3.0/bin/varnishtest/vtc_main.c 2019-09-20 08:56:45.639506046 +0200
@@ -230,7 +230,7 @@
assert(cleaner_pid >= 0);
if (cleaner_pid == 0) {
closefd(&p[1]);
- (void)nice(1); /* Not important */
+ if (nice(1)) 1;
setbuf(stdin, NULL);
AZ(dup2(p[0], STDIN_FILENO));
while (fgets(buf, sizeof buf, stdin)) {
diff -Naur varnish-6.3.0.orig/lib/libvarnishapi/vsm.c varnish-6.3.0/lib/libvarnishapi/vsm.c
--- varnish-6.3.0.orig/lib/libvarnishapi/vsm.c 2019-09-16 10:24:19.000000000 +0200
+++ varnish-6.3.0/lib/libvarnishapi/vsm.c 2019-09-20 10:36:02.434763755 +0200
@@ -763,18 +763,18 @@
VSM_ResetError(vd);
if (u & VSM_MGT_RUNNING) {
if (progress >= 0 && n > 4)
- (void)write(progress, "\n", 1);
+ if (!write(progress, "\n", 1)) return (vsm_diag(vd, "Unable to write progress"));
vd->attached = 1;
return (0);
}
if (t0 < VTIM_mono()) {
if (progress >= 0 && n > 4)
- (void)write(progress, "\n", 1);
+ if (!write(progress, "\n", 1)) return (vsm_diag(vd, "Unable to write progress"));
return (vsm_diag(vd,
"Could not get hold of varnishd, is it running?"));
}
if (progress >= 0 && !(++n % 4))
- (void)write(progress, ".", 1);
+ if (!write(progress, ".", 1)) return (vsm_diag(vd, "Unable to write progress"));
VTIM_sleep(.25);
}
return (vsm_diag(vd, "Attach interrupted"));

View file

@ -1,78 +0,0 @@
diff -Naur ../varnish-6.5.0.orig/bin/varnishd/http1/cache_http1_deliver.c ./bin/varnishd/http1/cache_http1_deliver.c
--- ../varnish-6.5.0.orig/bin/varnishd/http1/cache_http1_deliver.c 2020-09-15 17:06:03.000000000 +0200
+++ ./bin/varnishd/http1/cache_http1_deliver.c 2020-09-16 11:45:28.663086943 +0200
@@ -76,7 +76,7 @@
VSLb(req->vsl, SLT_RespReason, "Internal Server Error");
req->wrk->stats->client_resp_500++;
- (void)write(req->sp->fd, r_500, sizeof r_500 - 1);
+ if (write(req->sp->fd, r_500, sizeof r_500 - 1)) 0;
req->doclose = SC_TX_EOF;
}
diff -Naur ../varnish-6.5.0.orig/bin/varnishd/mgt/mgt_main.c ./bin/varnishd/mgt/mgt_main.c
--- ../varnish-6.5.0.orig/bin/varnishd/mgt/mgt_main.c 2020-09-15 17:06:03.000000000 +0200
+++ ./bin/varnishd/mgt/mgt_main.c 2020-09-16 11:46:21.323667133 +0200
@@ -252,7 +252,7 @@
return;
VJ_rmdir("vmod_cache");
VJ_unlink("_.pid");
- (void)chdir("/");
+ if (chdir("/")) 0;
VJ_rmdir(workdir);
}
diff -Naur ../varnish-6.5.0.orig/bin/varnishd/mgt/mgt_param.c ./bin/varnishd/mgt/mgt_param.c
--- ../varnish-6.5.0.orig/bin/varnishd/mgt/mgt_param.c 2020-09-15 17:06:03.000000000 +0200
+++ ./bin/varnishd/mgt/mgt_param.c 2020-09-16 11:45:28.771086082 +0200
@@ -829,11 +829,11 @@
t2 = strchr(t1 + 1, '\t');
AN(t2);
printf("\n\t*");
- (void)fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout);
+ if (fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout)) 1;
printf("*\n\t\t");
p = t2 + 1;
}
- (void)fwrite(p, q - p, 1, stdout);
+ if(fwrite(p, q - p, 1, stdout)) 1;
p = q;
if (*p == '\n') {
printf("\n");
diff -Naur ../varnish-6.5.0.orig/bin/varnishtest/vtc_main.c ./bin/varnishtest/vtc_main.c
--- ../varnish-6.5.0.orig/bin/varnishtest/vtc_main.c 2020-09-15 17:06:03.000000000 +0200
+++ ./bin/varnishtest/vtc_main.c 2020-09-16 11:45:28.771086082 +0200
@@ -233,7 +233,7 @@
assert(cleaner_pid >= 0);
if (cleaner_pid == 0) {
closefd(&p[1]);
- (void)nice(1); /* Not important */
+ if (nice(1)) 1;
setbuf(stdin, NULL);
AZ(dup2(p[0], STDIN_FILENO));
while (fgets(buf, sizeof buf, stdin)) {
diff -Naur ../varnish-6.5.0.orig/lib/libvarnishapi/vsm.c ./lib/libvarnishapi/vsm.c
--- ../varnish-6.5.0.orig/lib/libvarnishapi/vsm.c 2020-09-15 17:06:03.000000000 +0200
+++ ./lib/libvarnishapi/vsm.c 2020-09-16 11:45:28.772086074 +0200
@@ -764,18 +764,18 @@
VSM_ResetError(vd);
if (u & VSM_MGT_RUNNING) {
if (progress >= 0 && n > 4)
- (void)write(progress, "\n", 1);
+ if (!write(progress, "\n", 1)) return (vsm_diag(vd, "Unable to write progress"));
vd->attached = 1;
return (0);
}
if (t0 < VTIM_mono()) {
if (progress >= 0 && n > 4)
- (void)write(progress, "\n", 1);
+ if (!write(progress, "\n", 1)) return (vsm_diag(vd, "Unable to write progress"));
return (vsm_diag(vd,
"Could not get hold of varnishd, is it running?"));
}
if (progress >= 0 && !(++n % 4))
- (void)write(progress, ".", 1);
+ if (!write(progress, ".", 1)) return (vsm_diag(vd, "Unable to write progress"));
VTIM_sleep(.25);
}
return (vsm_diag(vd, "Attach interrupted"));

View file

@ -1,178 +0,0 @@
commit 95e41dfa584d108e444949534c7ce5801cffeacc
Author: Poul-Henning Kamp <phk@FreeBSD.org>
Date: Wed Mar 26 09:25:43 2025 +0000
If the client sends NO_RFC7540_PRIORITIES, "rxprio" verbs become no-ops.
Fixes: #4298
Tested by: @ingvarha
commit 3a1eb57d8bd57205db7d2c766aed39cf73c4f578
Author: Poul-Henning Kamp <phk@FreeBSD.org>
Date: Wed Mar 26 09:24:17 2025 +0000
Add more HTTP2 Settings to the table
diff --git a/bin/varnishtest/vtc.h b/bin/varnishtest/vtc.h
index 2e5d4161a..b765fe60a 100644
--- a/bin/varnishtest/vtc.h
+++ b/bin/varnishtest/vtc.h
@@ -148,7 +148,7 @@ struct http;
void cmd_stream(CMD_ARGS);
void start_h2(struct http *hp);
void stop_h2(struct http *hp);
-void b64_settings(const struct http *hp, const char *s);
+void b64_settings(struct http *hp, const char *s);
/* vtc_gzip.c */
void vtc_gunzip(struct http *, char *, long *);
diff --git a/bin/varnishtest/vtc_http.h b/bin/varnishtest/vtc_http.h
index 7a86de8da..62c598a55 100644
--- a/bin/varnishtest/vtc_http.h
+++ b/bin/varnishtest/vtc_http.h
@@ -83,6 +83,7 @@ struct http {
/* H/2 */
unsigned h2;
int wf;
+ int no_rfc7540_priorities;
pthread_t tp;
VTAILQ_HEAD(, stream) streams;
diff --git a/bin/varnishtest/vtc_http2.c b/bin/varnishtest/vtc_http2.c
index 822abbae1..7feeb42b0 100644
--- a/bin/varnishtest/vtc_http2.c
+++ b/bin/varnishtest/vtc_http2.c
@@ -629,7 +629,7 @@ parse_settings(const struct stream *s, struct frame *f)
buf = "unknown";
u += 4;
- if (t == 1) {
+ if (t == SETTINGS_HEADER_TABLE_SIZE) {
r = HPK_ResizeTbl(s->hp->encctx, v);
assert(r == hpk_done);
}
@@ -2460,28 +2460,47 @@ cmd_rxsettings(CMD_ARGS)
hp->h2_win_peer->init = val;
}
}
+/* SECTION: stream.spec.prio_rxprio rxprio
+ *
+ * Receive a PRIORITY frame.
+ */
+static void
+cmd_rxprio (CMD_ARGS)
+{
+ struct stream *s;
+ (void)av;
+ CAST_OBJ_NOTNULL(s, priv, STREAM_MAGIC);
+ if (s->hp->no_rfc7540_priorities) {
+ vtc_log(vl, 4, "skipping rxprio: no_rfc7540_priorities is set");
+ return;
+ }
+ s->frame = rxstuff(s);
+ if (s->frame != NULL && s->frame->type != TYPE_PRIORITY) {
+ vtc_fatal(vl,
+ "Wrong frame type %s (%d) wanted %s",
+ s->frame->type < TYPE_MAX ?
+ h2_types[s->frame->type] : "?",
+ s->frame->type, "PRIORITY");
+ }
+}
#define RXFUNC(lctype, upctype) \
static void \
- cmd_rx ## lctype(CMD_ARGS) { \
+ cmd_rx ## lctype(CMD_ARGS) \
+ { \
struct stream *s; \
(void)av; \
CAST_OBJ_NOTNULL(s, priv, STREAM_MAGIC); \
s->frame = rxstuff(s); \
- if (s->frame != NULL && s->frame->type != TYPE_ ## upctype) \
+ if (s->frame != NULL && s->frame->type != TYPE_ ## upctype) { \
vtc_fatal(vl, \
"Wrong frame type %s (%d) wanted %s", \
s->frame->type < TYPE_MAX ? \
h2_types[s->frame->type] : "?", \
s->frame->type, #upctype); \
+ } \
}
-/* SECTION: stream.spec.prio_rxprio rxprio
- *
- * Receive a PRIORITY frame.
- */
-RXFUNC(prio, PRIORITY)
-
/* SECTION: stream.spec.reset_rxrst rxrst
*
* Receive a RST_STREAM frame.
@@ -2857,7 +2876,7 @@ cmd_stream(CMD_ARGS)
}
void
-b64_settings(const struct http *hp, const char *s)
+b64_settings(struct http *hp, const char *s)
{
uint16_t i;
uint64_t v, vv;
@@ -2891,7 +2910,10 @@ b64_settings(const struct http *hp, const char *s)
else
buf = "unknown";
- if (v == 1) {
+ if (i == SETTINGS_NO_RFC7540_PRIORITIES) {
+ hp->no_rfc7540_priorities = v;
+ }
+ if (i == SETTINGS_HEADER_TABLE_SIZE) {
enum hpk_result hrs;
if (hp->sfd) {
AN(hp->encctx);
diff --git a/include/tbl/h2_settings.h b/include/tbl/h2_settings.h
index 2dbac671f..273f157fe 100644
--- a/include/tbl/h2_settings.h
+++ b/include/tbl/h2_settings.h
@@ -102,7 +102,39 @@ H2_SETTING( // rfc7540,l,2159,2167
0xffffffff,
0
)
-#endif
+
+H2_SETTING( // rfc8441
+ ENABLE_CONNECT_PROTOCOL,
+ enable_connect_protocol,
+ 0x8,
+ 0,
+ 0,
+ 1,
+ H2CE_PROTOCOL_ERROR
+)
+
+H2_SETTING( // rfc9218
+ NO_RFC7540_PRIORITIES,
+ no_rfc7540_priorities,
+ 0x9,
+ 0,
+ 0,
+ 1,
+ H2CE_PROTOCOL_ERROR
+)
+
+H2_SETTING( // [MS-HTTP2E]
+ // [Gabriel_Montenegro]
+ TLS_RENEG_PERMITTED,
+ tls_reneg_permitted,
+ 0x10,
+ 0,
+ 0,
+ 3,
+ H2CE_PROTOCOL_ERROR
+)
+#endif /* !H2_SETTINGS_PARAM_ONLY */
+
#undef H2_SETTING
/*lint -restore */

View file

@ -1,38 +0,0 @@
Author: Ingvar Hagelund <ingvar@redpill-linpro.com>
Date: Wed Apr 15 00:17:59 2026 +0200
Use ASN1_STRING functions for openssl-4.0.0
diff -Naur varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_asn_gentm.c varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_asn_gentm.c
--- varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_asn_gentm.c 2026-04-08 18:57:33.000000000 +0200
+++ varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_asn_gentm.c 2026-04-15 00:34:44.788211992 +0200
@@ -142,10 +142,10 @@
char *a;
int n, i, l, o;
- if (d->type != V_ASN1_GENERALIZEDTIME)
+ if (ASN1_STRING_type(d) != V_ASN1_GENERALIZEDTIME)
return (0);
- l = d->length;
- a = (char *)d->data;
+ l = ASN1_STRING_length(d);
+ a = (char *)ASN1_STRING_get0_data(d);
o = 0;
/*
* GENERALIZEDTIME is similar to UTCTIME except the year is represented
diff -Naur varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_tls.c varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_tls.c
--- varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_tls.c 2026-04-08 18:57:33.000000000 +0200
+++ varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_tls.c 2026-04-15 00:35:53.447792774 +0200
@@ -1060,10 +1060,10 @@
break;
case GEN_IPADD:
- p = n->d.ip->data;
+ p = ASN1_STRING_get0_data(n->d.ip);
AN(p);
- if (inet_ntop(n->d.ip->length == 16 ? AF_INET6 : AF_INET,
+ if (inet_ntop(ASN1_STRING_length(n->d.ip) == 16 ? AF_INET6 : AF_INET,
p, b, INET6_ADDRSTRLEN) == 0)
continue;

18
varnish-cs1913.patch Normal file
View file

@ -0,0 +1,18 @@
Index: bin/varnishd/cache_center.c
===================================================================
--- bin/varnishd/cache_center.c (revision 1912)
+++ bin/varnishd/cache_center.c (revision 1913)
@@ -524,7 +524,12 @@
*/
WSL(sp->wrk, SLT_Debug, sp->fd,
"on waiting list on obj %u", sp->obj->xid);
- assert(!isnan(sp->wrk->used));
+ /*
+ * There is a non-zero risk that we come here more than once
+ * before we get through, in that case cnt_recv must be set
+ */
+ if (isnan(sp->wrk->used))
+ sp->wrk->used = TIM_real();
SES_Charge(sp);
return (1);
}

32
varnish.S-option.patch Normal file
View file

@ -0,0 +1,32 @@
--- ../varnish-2.1.orig/man/vcl.7so
+++ man/vcl.7so
@@ -126,7 +126,6 @@ it's saintmode list
can be set to the maximum list size. Setting a value of 0 disables
saintmode checking entirely for that backend. The value in the backend
declaration overrides the parameter.
-
.Ss Directors
Directors choose from different backends based on health status and a
per-director algorithm.
--- ../varnish-2.1.orig/bin/varnishd/varnishd.1
+++ bin/varnishd/varnishd.1
@@ -173,6 +173,9 @@ to the specified
See
.Sx Run-Time Parameters
for a list of parameters.
+.It Fl S Ar file
+Path to a file containing a secret used for authorizing access to the
+management port.
.It Fl s Ar type Ns Xo
.Op , Ns Ar options
.Xc
--- ../varnish-2.1.orig/redhat/varnish.sysconfig
+++ ./redhat/varnish.sysconfig
@@ -38,6 +38,7 @@
-T localhost:6082 \
-f /etc/varnish/default.vcl \
-u varnish -g varnish \
+ -S /etc/varnish/secret \
-s file,/var/lib/varnish/varnish_storage.bin,1G"

View file

@ -0,0 +1,277 @@
diff -Naur ../varnish-2.1.4/redhat/varnish.initrc ./redhat/varnish.initrc
--- ../varnish-2.1.4/redhat/varnish.initrc 2010-11-04 13:57:41.208455907 +0100
+++ ./redhat/varnish.initrc 2010-11-04 14:00:14.516330982 +0100
@@ -1,6 +1,6 @@
#! /bin/sh
#
-# varnish Control the varnish HTTP accelerator
+# varnish Control the Varnish Cache
#
# chkconfig: - 90 10
# description: Varnish is a high-perfomance HTTP accelerator
@@ -26,6 +26,7 @@
pidfile=/var/run/varnish.pid
exec="/usr/sbin/varnishd"
+reload_exec="/usr/bin/varnish_reload_vcl"
prog="varnishd"
config="/etc/sysconfig/varnish"
lockfile="/var/lock/subsys/varnish"
@@ -47,7 +48,7 @@
echo $config not found
exit 6
fi
- echo -n "Starting varnish HTTP accelerator: "
+ echo -n "Starting Varnish Cache: "
# Open files (usually 1024, which is way too small for varnish)
ulimit -n ${NFILES:-131072}
@@ -79,7 +80,7 @@
}
stop() {
- echo -n "Stopping varnish HTTP accelerator: "
+ echo -n "Stopping Varnish Cache: "
killproc -p $pidfile $prog
retval=$?
echo
@@ -93,7 +94,12 @@
}
reload() {
- restart
+ if [ "$RELOAD_VCL" = "1" ]
+ then
+ $reload_exec
+ else
+ force_reload
+ fi
}
force_reload() {
diff -Naur ../varnish-2.1.4/redhat/varnish_reload_vcl ./redhat/varnish_reload_vcl
--- ../varnish-2.1.4/redhat/varnish_reload_vcl 1970-01-01 01:00:00.000000000 +0100
+++ ./redhat/varnish_reload_vcl 2010-11-04 13:58:14.708330664 +0100
@@ -0,0 +1,114 @@
+#!/bin/bash
+#
+# reload vcl revisited
+# A script that loads new vcl based on data from /etc/sysconfig/varnish
+# Ingvar Hagelund <ingvar@redpill-linpro.com>
+#
+# This is free software, distributed under the standard 2 clause BSD license,
+# see the LICENSE file in the Varnish documentation directory
+#
+# The following environment variables have to be set:
+# RELOAD_VCL, VARNISH_VCL_CONF, VARNISH_ADMIN_LISTEN_PORT
+# The following are optional:
+# VARNISH_SECRET_FILE, VARNISH_ADMIN_LISTEN_ADDRESS
+#
+# Requires GNU bash and GNU date
+#
+
+debug=false
+
+missing() {
+ echo "Missing configuration variable: $1"
+ exit 2
+}
+
+print_debug() {
+ echo "
+Parsed configuration:
+RELOAD_VCL=\"$RELOAD_VCL\"
+VARNISH_VCL_CONF=\"$VARNISH_VCL_CONF\"
+VARNISH_ADMIN_LISTEN_ADDRESS=\"$VARNISH_ADMIN_LISTEN_ADDRESS\"
+VARNISH_ADMIN_LISTEN_PORT=\"$VARNISH_ADMIN_LISTEN_PORT\"
+VARNISH_SECRET_FILE=\"$VARNISH_SECRET_FILE\"
+"
+}
+
+# Read configuration
+. /etc/sysconfig/varnish
+
+$debug && print_debug
+
+# Check configuration
+if [ ! "$RELOAD_VCL" = "1" ]; then
+ echo "Error: RELOAD_VCL is not set to 1"
+ exit 2
+
+elif [ -z "$VARNISH_VCL_CONF" ]; then
+ echo "Error: VARNISH_VCL_CONF is not set"
+ exit 2
+
+elif [ ! -s "$VARNISH_VCL_CONF" ]; then
+ echo "Eror: VCL config $VARNISH_VCL_CONF is unreadable or empty"
+ exit 2
+
+elif [ -z "$VARNISH_ADMIN_LISTEN_ADDRESS" ]; then
+ echo "Warning: VARNISH_ADMIN_LISTEN_ADDRESS is not set, using 127.0.0.1"
+ VARNISH_ADMIN_LISTEN_ADDRESS="127.0.0.1"
+
+elif [ -z "$VARNISH_ADMIN_LISTEN_PORT" ]; then
+ echo "Error: VARNISH_ADMIN_LISTEN_PORT is not set"
+ exit 2
+
+elif [ -z "$VARNISH_SECRET_FILE" ]; then
+ echo "Warning: VARNISH_SECRET_FILE is not set"
+ secret=""
+
+elif [ ! -s "$VARNISH_SECRET_FILE" ]; then
+ echo "Error: varnish secret file $VARNISH_SECRET_FILE is unreadable or empty"
+ exit 2
+else
+ secret="-S $VARNISH_SECRET_FILE"
+fi
+
+# Done parsing, set up command
+VARNISHADM="varnishadm $secret -T $VARNISH_ADMIN_LISTEN_ADDRESS:$VARNISH_ADMIN_LISTEN_PORT"
+
+# Now do the real work
+new_config="reload_$(date +%FT%H:%M:%S)"
+
+# Check if we are able to connect at all
+if $VARNISHADM vcl.list > /dev/null; then
+ $debug && echo vcl.list succeeded
+else
+ echo "Unable to run $VARNISHADM vcl.list"
+ exit 1
+fi
+
+if $VARNISHADM vcl.list | awk ' { print $3 } ' | grep -q $new_config; then
+ echo Trying to use new config $new_config, but that is already in use
+ exit 2
+fi
+
+current_config=$( $VARNISHADM vcl.list | awk ' /^active/ { print $3 } ' )
+
+echo "Loading vcl from $VARNISH_VCL_CONF"
+echo "Current running config name is $current_config"
+echo "Using new config name $new_config"
+
+if $VARNISHADM vcl.load $new_config $VARNISH_VCL_CONF; then
+ $debug && echo "$VARNISHADM vcl.load succeded"
+else
+ echo "$VARNISHADM vcl.load failed"
+ exit 1
+fi
+
+if $VARNISHADM vcl.use $new_config; then
+ $debug && echo "$VARNISHADM vcl.use succeded"
+else
+ echo "$VARNISHADM vcl.use failed"
+ exit 1
+fi
+$VARNISHADM vcl.list
+echo Done
+exit 0
+
diff -Naur ../varnish-2.1.4/redhat/varnish.sysconfig ./redhat/varnish.sysconfig
--- ../varnish-2.1.4/redhat/varnish.sysconfig 2010-10-21 10:57:22.000000000 +0200
+++ ./redhat/varnish.sysconfig 2010-11-04 13:59:34.293455974 +0100
@@ -14,6 +14,13 @@
# Maximum size of corefile (for ulimit -c). Default in Fedora is 0
# DAEMON_COREFILE_LIMIT="unlimited"
+# Set this to 1 to make init script reload try to switch vcl without restart.
+# To make this work, you need to set the following variables
+# explicit: VARNISH_VCL_CONF, VARNISH_ADMIN_LISTEN_ADDRESS,
+# VARNISH_ADMIN_LISTEN_PORT, VARNISH_SECRET_FILE, or in short,
+# use Alternative 3, Advanced configuration, below
+RELOAD_VCL=1
+
# This file contains 4 alternatives, please use only one.
## Alternative 1, Minimal configuration, no VCL
@@ -34,12 +41,12 @@
# one content server selected by the vcl file, based on the request. Use a
# fixed-size cache file.
#
-DAEMON_OPTS="-a :6081 \
- -T localhost:6082 \
- -f /etc/varnish/default.vcl \
- -u varnish -g varnish \
- -S /etc/varnish/secret \
- -s file,/var/lib/varnish/varnish_storage.bin,1G"
+#DAEMON_OPTS="-a :6081 \
+# -T localhost:6082 \
+# -f /etc/varnish/default.vcl \
+# -u varnish -g varnish \
+# -S /etc/varnish/secret \
+# -s file,/var/lib/varnish/varnish_storage.bin,1G"
## Alternative 3, Advanced configuration
@@ -47,49 +54,53 @@
# See varnishd(1) for more information.
#
# # Main configuration file. You probably want to change it :)
-# VARNISH_VCL_CONF=/etc/varnish/default.vcl
+VARNISH_VCL_CONF=/etc/varnish/default.vcl
#
# # Default address and port to bind to
# # Blank address means all IPv4 and IPv6 interfaces, otherwise specify
# # a host name, an IPv4 dotted quad, or an IPv6 address in brackets.
# VARNISH_LISTEN_ADDRESS=
-# VARNISH_LISTEN_PORT=6081
+VARNISH_LISTEN_PORT=6081
#
# # Telnet admin interface listen address and port
-# VARNISH_ADMIN_LISTEN_ADDRESS=127.0.0.1
-# VARNISH_ADMIN_LISTEN_PORT=6082
+VARNISH_ADMIN_LISTEN_ADDRESS=127.0.0.1
+VARNISH_ADMIN_LISTEN_PORT=6082
+#
+# # Shared secret file for admin interface
+VARNISH_SECRET_FILE=/etc/varnish/secret
#
# # The minimum number of worker threads to start
-# VARNISH_MIN_THREADS=1
+VARNISH_MIN_THREADS=1
#
# # The Maximum number of worker threads to start
-# VARNISH_MAX_THREADS=1000
+VARNISH_MAX_THREADS=1000
#
# # Idle timeout for worker threads
-# VARNISH_THREAD_TIMEOUT=120
+VARNISH_THREAD_TIMEOUT=120
#
# # Cache file location
-# VARNISH_STORAGE_FILE=/var/lib/varnish/varnish_storage.bin
+VARNISH_STORAGE_FILE=/var/lib/varnish/varnish_storage.bin
#
# # Cache file size: in bytes, optionally using k / M / G / T suffix,
# # or in percentage of available disk space using the % suffix.
-# VARNISH_STORAGE_SIZE=1G
+VARNISH_STORAGE_SIZE=1G
#
# # Backend storage specification
-# VARNISH_STORAGE="file,${VARNISH_STORAGE_FILE},${VARNISH_STORAGE_SIZE}"
+VARNISH_STORAGE="file,${VARNISH_STORAGE_FILE},${VARNISH_STORAGE_SIZE}"
#
# # Default TTL used when the backend does not specify one
-# VARNISH_TTL=120
+VARNISH_TTL=120
#
# # DAEMON_OPTS is used by the init script. If you add or remove options, make
# # sure you update this section, too.
-# DAEMON_OPTS="-a ${VARNISH_LISTEN_ADDRESS}:${VARNISH_LISTEN_PORT} \
-# -f ${VARNISH_VCL_CONF} \
-# -T ${VARNISH_ADMIN_LISTEN_ADDRESS}:${VARNISH_ADMIN_LISTEN_PORT} \
-# -t ${VARNISH_TTL} \
-# -w ${VARNISH_MIN_THREADS},${VARNISH_MAX_THREADS},${VARNISH_THREAD_TIMEOUT} \
-# -u varnish -g varnish \
-# -s ${VARNISH_STORAGE}"
+DAEMON_OPTS="-a ${VARNISH_LISTEN_ADDRESS}:${VARNISH_LISTEN_PORT} \
+ -f ${VARNISH_VCL_CONF} \
+ -T ${VARNISH_ADMIN_LISTEN_ADDRESS}:${VARNISH_ADMIN_LISTEN_PORT} \
+ -t ${VARNISH_TTL} \
+ -w ${VARNISH_MIN_THREADS},${VARNISH_MAX_THREADS},${VARNISH_THREAD_TIMEOUT} \
+ -u varnish -g varnish \
+ -S ${VARNISH_SECRET_FILE} \
+ -s ${VARNISH_STORAGE}"
#

View file

@ -0,0 +1,9 @@
--- doc/changes-2.0.5-2.0.6.xml.orig 2009-12-23 11:42:58.168643121 +0100
+++ doc/changes-2.0.5-2.0.6.xml 2009-12-23 11:43:05.827643574 +0100
@@ -49,5 +49,5 @@
<para>Document the <code>-C</code> option
to <code>varnishd</code>.</para>
</change>
- <subsystem>
+ </subsystem>
</group>

View file

@ -0,0 +1,53 @@
--- doc/changes-2.0.6-2.1.0.xml.orig 2010-04-14 15:16:12.308484148 +0200
+++ doc/changes-2.0.6-2.1.0.xml 2010-04-14 15:16:28.844484368 +0200
@@ -2,7 +2,7 @@
<!DOCTYPE group [
<!ENTITY mdash "&#8212;">
]>
-<!-- $Id: changes-2.0.6-2.1.0.xml 4641 2010-03-24 10:36:56Z tfheen $ -->
+<!-- $Id: changes-2.0.6-2.1.0.xml 4643 2010-03-24 12:41:53Z tfheen $ -->
<group from="2.0.6" to="2.1.0">
<subsystem>
<name>varnishd</name>
@@ -48,7 +48,7 @@
<para>When closing connections, we experimented with sending RST
to free up load balancers and free up threads more quickly.
This caused some problems with NAT routers and so has been
- reverted for now.
+ reverted for now.</para>
</change>
<change type="enh">
@@ -176,7 +176,7 @@
<change type="enh">
<para><code>purge.hash</code> is now deprecated and no longer
- shown in help listings.</code>.</para>
+ shown in help listings.</para>
</change>
<change type="enh" ref="607">
@@ -298,11 +298,19 @@
<para>Exit at the end of the file when started
with <code>-d</code>.</para>
</change>
+ </subsystem>
+ <subsystem>
+ <name>varnishadm</name>
-varnishadm:
- - timeout support
- - secret support
- - handle cli banner
+ <change type="enh">
+ <para><code>varnishadm</code> can now have a timeout when trying
+ to connect to the running <code>varnishd</code>.</para>
+ </change>
+ <change type="enh">
+ <para><code>varnishadm</code> now knows how to respond to the
+ secret from a secured <code>varnishd</code></para>
+ </change>
+ </subsystem>
</group>

13
varnish.coresize.patch Normal file
View file

@ -0,0 +1,13 @@
diff -Naur ../varnish-2.0-beta1.orig/redhat/varnish.sysconfig ./redhat/varnish.sysconfig
--- ../varnish-2.0-beta1.orig/redhat/varnish.sysconfig 2008-06-18 12:59:41.000000000 +0200
+++ ./redhat/varnish.sysconfig 2008-09-02 14:50:51.000000000 +0200
@@ -11,6 +11,9 @@
# Default log size is 82MB + header
MEMLOCK=82000
+# Maximum size of corefile (for ulimit -c). Default in Fedora is 0
+# DAEMON_COREFILE_LIMIT="unlimited"
+
# This file contains 4 alternatives, please use only one.
## Alternative 1, Minimal configuration, no VCL

13
varnish.cs3157.patch Normal file
View file

@ -0,0 +1,13 @@
Index: bin/varnishtest/vtc_server.c
===================================================================
--- bin/varnishtest/vtc_server.c (revision 3155)
+++ bin/varnishtest/vtc_server.c (revision 3157)
@@ -97,7 +97,7 @@
vtc_log(vl, 3, "Accepted socket fd is %d", fd);
http_process(vl, s->spec, fd, 0);
vtc_log(vl, 3, "shutting fd %d", fd);
- AZ(shutdown(fd, SHUT_WR));
+ assert((shutdown(fd, SHUT_WR) == 0) || errno == ENOTCONN);
TCP_close(&fd);
}
vtc_log(vl, 2, "Ending");

View file

@ -0,0 +1,85 @@
Index: include/vrt.h
===================================================================
--- include/vrt.h (revisjon 3169)
+++ include/vrt.h (revisjon 3171)
@@ -154,6 +154,7 @@
/* Simple stuff */
int VRT_strcmp(const char *s1, const char *s2);
+void VRT_memmove(void *dst, const void *src, unsigned len);
void VRT_ESI(struct sess *sp);
void VRT_Rollback(struct sess *sp);
Index: lib/libvcl/vcc_fixed_token.c
===================================================================
--- lib/libvcl/vcc_fixed_token.c (revisjon 3169)
+++ lib/libvcl/vcc_fixed_token.c (revisjon 3171)
@@ -434,6 +434,7 @@
vsb_cat(sb, "\n");
vsb_cat(sb, "/* Simple stuff */\n");
vsb_cat(sb, "int VRT_strcmp(const char *s1, const char *s2);\n");
+ vsb_cat(sb, "void VRT_memmove(void *dst, const void *src, unsigned len);\n");
vsb_cat(sb, "\n");
vsb_cat(sb, "void VRT_ESI(struct sess *sp);\n");
vsb_cat(sb, "void VRT_Rollback(struct sess *sp);\n");
Index: lib/libvcl/vcc_acl.c
===================================================================
--- lib/libvcl/vcc_acl.c (revisjon 3169)
+++ lib/libvcl/vcc_acl.c (revisjon 3171)
@@ -328,23 +328,37 @@
int depth, l, m, i;
unsigned at[VRT_ACL_MAXADDR + 1];
const char *oc;
+ struct sockaddr sa;
Fh(tl, 0, "\nstatic int\n");
Fh(tl, 0, "match_acl_%s_%s(const struct sess *sp, const void *p)\n",
pfx, acln);
Fh(tl, 0, "{\n");
- Fh(tl, 0, "\tunsigned fam;\n");
Fh(tl, 0, "\tconst unsigned char *a;\n");
+ assert(sizeof (unsigned char) == 1);
+ assert(sizeof (unsigned short) == 2);
+ assert(sizeof (unsigned int) == 4);
+ if (sizeof sa.sa_family == 1)
+ Fh(tl, 0, "\tunsigned char fam;\n");
+ else if (sizeof sa.sa_family == 2)
+ Fh(tl, 0, "\tunsigned short fam;\n");
+ else if (sizeof sa.sa_family == 4)
+ Fh(tl, 0, "\tunsigned int fam;\n");
+ else
+ assert(0 == __LINE__);
+
Fh(tl, 0, "\n");
Fh(tl, 0, "\ta = p;\n");
- Fh(tl, 0, "\tfam = a[%d];\n", offsetof(struct sockaddr, sa_family));
+ Fh(tl, 0, "\tVRT_memmove(&fam, a + %d, sizeof fam);\n",
+ offsetof(struct sockaddr, sa_family));
Fh(tl, 0, "\tif (fam == %d)\n", PF_INET);
Fh(tl, 0, "\t\ta += %d;\n", offsetof(struct sockaddr_in, sin_addr));
Fh(tl, 0, "\telse if (fam == %d)\n", PF_INET6);
Fh(tl, 0, "\t\ta += %d;\n", offsetof(struct sockaddr_in6, sin6_addr));
- Fh(tl, 0, "\telse\n");
+ Fh(tl, 0, "\telse {\n");
+ Fh(tl, 0, "\t\tVRT_acl_log(sp, \"NO_FAM %s\");\n", acln);
Fh(tl, 0, "\t\treturn(0);\n");
- Fh(tl, 0, "\n");
+ Fh(tl, 0, "\t}\n\n");
depth = -1;
oc = 0;
at[0] = 256;
Index: bin/varnishd/cache_vrt.c
===================================================================
--- bin/varnishd/cache_vrt.c (revisjon 3169)
+++ bin/varnishd/cache_vrt.c (revisjon 3171)
@@ -726,3 +726,10 @@
return (strcmp(s1, s2));
}
+void
+VRT_memmove(void *dst, const void *src, unsigned len)
+{
+
+ (void)memmove(dst, src, len);
+}
+

View file

@ -0,0 +1,46 @@
Index: bin/varnishtest/tests/r00801.vtc
===================================================================
--- bin/varnishtest/tests/r00801.vtc (revisjon 0)
+++ bin/varnishtest/tests/r00801.vtc (revisjon 5461)
@@ -0,0 +1,24 @@
+# $Id$
+
+test "Regression test for duplicate content-length in pass"
+
+server s1 {
+ rxreq
+ txresp \
+ -hdr "Date: Mon, 25 Oct 2010 06:34:06 GMT" \
+ -hdr "Content-length: 10xx" \
+ -nolen -bodylen 10
+} -start
+
+
+varnish v1 -vcl+backend {
+ sub vcl_recv { return (pass); }
+} -start
+
+client c1 {
+ txreq
+ rxresp
+ expect resp.http.content-length == "10"
+} -run
+
+
Index: bin/varnishd/cache_fetch.c
===================================================================
--- bin/varnishd/cache_fetch.c (revisjon 5460)
+++ bin/varnishd/cache_fetch.c (revisjon 5461)
@@ -552,9 +552,11 @@
assert(uu == sp->obj->len);
}
- if (mklen > 0)
+ if (mklen > 0) {
+ http_Unset(sp->obj->http, H_Content_Length);
http_PrintfHeader(sp->wrk, sp->fd, sp->obj->http,
"Content-Length: %u", sp->obj->len);
+ }
if (http_HdrIs(hp, H_Connection, "close"))
cls = 1;

View file

@ -0,0 +1,12 @@
Index: redhat/varnish.initrc
===================================================================
--- redhat/varnish.initrc (revisjon 5498)
+++ redhat/varnish.initrc (arbeidskopi)
@@ -70,6 +70,7 @@
echo
else
echo_failure
+ echo
fi
return $retval
fi

View file

@ -0,0 +1,36 @@
diff -Naur ../varnish-2.1.4/redhat/varnish.initrc ./redhat/varnish.initrc
--- ../varnish-2.1.4/redhat/varnish.initrc 2010-10-21 10:57:22.000000000 +0200
+++ ./redhat/varnish.initrc 2010-11-03 15:20:07.663331341 +0100
@@ -12,6 +12,8 @@
# Provides: varnish
# Required-Start: $network $local_fs $remote_fs
# Required-Stop: $network $local_fs $remote_fs
+# Default-Start:
+# Default-Stop:
# Should-Start: $syslog
# Short-Description: start and stop varnishd
# Description: Varnish is a high-perfomance HTTP accelerator
diff -Naur ../varnish-2.1.4/redhat/varnishlog.initrc ./redhat/varnishlog.initrc
--- ../varnish-2.1.4/redhat/varnishlog.initrc 2010-10-21 10:57:22.000000000 +0200
+++ ./redhat/varnishlog.initrc 2010-11-03 15:20:07.664330786 +0100
@@ -12,6 +12,8 @@
# Provides: varnishlog
# Required-Start: $network $local_fs $remote_fs
# Required-Stop: $network $local_fs $remote_fs
+# Default-Start:
+# Default-Stop:
# Short-Description: start and stop varnishlog
# Description: Varnish HTTP accelerator logging daemon
### END INIT INFO
diff -Naur ../varnish-2.1.4/redhat/varnishncsa.initrc ./redhat/varnishncsa.initrc
--- ../varnish-2.1.4/redhat/varnishncsa.initrc 2010-10-21 10:57:22.000000000 +0200
+++ ./redhat/varnishncsa.initrc 2010-11-03 15:20:07.664330786 +0100
@@ -12,6 +12,8 @@
# Provides: varnishncsa
# Required-Start: $network $local_fs $remote_fs
# Required-Stop: $network $local_fs $remote_fs
+# Default-Start:
+# Default-Stop:
# Short-Description: start and stop varnishncsa
# Description: Varnish HTTP accelerator logging daemon
### END INIT INFO

View file

@ -0,0 +1,11 @@
--- bin/varnishd/cache_ban.c.orig 2012-09-18 11:44:55.867165803 +0200
+++ bin/varnishd/cache_ban.c 2012-09-18 11:45:37.879300620 +0200
@@ -81,7 +81,7 @@
const void *arg2_spec;
};
-static VTAILQ_HEAD(banhead_s,ban) ban_head = VTAILQ_HEAD_INITIALIZER(ban_head);
+static volatile VTAILQ_HEAD(banhead_s,ban) ban_head = VTAILQ_HEAD_INITIALIZER(ban_head);
static struct lock ban_mtx;
static struct ban *ban_magic;
static pthread_t ban_thread;

15
varnish.floor.patch Normal file
View file

@ -0,0 +1,15 @@
Patch by Robert Scheck <robert@fedoraproject.org> for varnish >= 2.1, which adds the
missing (former implicit) linking to libm. And as implicit linking can be dangerous,
this changed, see: http://fedoraproject.org/wiki/Features/ChangeInImplicitDSOLinking
--- bin/varnishtest/Makefile.am 2010-03-24 10:44:13.000000000 +0100
+++ bin/varnishtest/Makefile.am.libm 2010-04-07 22:57:03.000000000 +0200
@@ -25,7 +25,7 @@
$(top_builddir)/lib/libvarnish/libvarnish.la \
$(top_builddir)/lib/libvarnishcompat/libvarnishcompat.la \
$(top_builddir)/lib/libvarnishapi/libvarnishapi.la \
- ${PTHREAD_LIBS}
+ ${LIBM} ${PTHREAD_LIBS}
EXTRA_DIST = $(top_srcdir)/bin/varnishtest/tests/*.vtc \
$(top_srcdir)/bin/varnishtest/tests/README

View file

@ -0,0 +1,170 @@
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/b00000.vtc ./bin/varnishtest/tests/b00000.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/b00000.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/b00000.vtc 2010-04-30 10:58:57.199838479 +0200
@@ -9,7 +9,7 @@
txresp -body "012345\n"
} -start
-varnish v1 -arg "-smalloc,1m" -vcl+backend {} -start
+varnish v1 -storage "-smalloc,1m" -vcl+backend {} -start
varnish v1 -cliok "param.set diag_bitmap 0x2"
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/p00000.vtc ./bin/varnishtest/tests/p00000.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/p00000.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/p00000.vtc 2010-04-30 10:58:57.150839765 +0200
@@ -11,7 +11,8 @@
varnish v1 \
-arg "-pdiag_bitmap=0x20000" \
- -arg "-spersistent,${tmpdir}/_.per,10m" -vcl+backend { } -start
+ -storage "-spersistent,${tmpdir}/_.per,10m" \
+ -vcl+backend { } -start
varnish v1 -stop
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/p00001.vtc ./bin/varnishtest/tests/p00001.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/p00001.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/p00001.vtc 2010-04-30 11:05:26.478837801 +0200
@@ -11,7 +11,8 @@
varnish v1 \
-arg "-pdiag_bitmap=0x20000" \
- -arg "-spersistent,${tmpdir}/_.per,10m" -vcl+backend { } -start
+ -storage "-spersistent,${tmpdir}/_.per,10m" \
+ -vcl+backend { } -start
client c1 {
txreq -url "/"
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/p00002.vtc ./bin/varnishtest/tests/p00002.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/p00002.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/p00002.vtc 2010-04-30 10:58:57.151838730 +0200
@@ -11,8 +11,8 @@
varnish v1 \
-arg "-pdiag_bitmap=0x20000" \
- -arg "-spersistent,${tmpdir}/_.per1,10m" \
- -arg "-spersistent,${tmpdir}/_.per2,10m" \
+ -storage "-spersistent,${tmpdir}/_.per1,10m" \
+ -storage "-spersistent,${tmpdir}/_.per2,10m" \
-vcl+backend { } -start
client c1 {
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/p00003.vtc ./bin/varnishtest/tests/p00003.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/p00003.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/p00003.vtc 2010-04-30 11:06:28.054838375 +0200
@@ -11,7 +11,7 @@
varnish v1 \
-arg "-pdiag_bitmap=0x20000" \
- -arg "-spersistent,${tmpdir}/_.per,10m" \
+ -storage "-spersistent,${tmpdir}/_.per,10m" \
-vcl+backend { } -start
varnish v1 -cliok purge.list
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/p00004.vtc ./bin/varnishtest/tests/p00004.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/p00004.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/p00004.vtc 2010-04-30 11:03:35.717837935 +0200
@@ -13,7 +13,7 @@
varnish v1 \
-arg "-pdiag_bitmap=0x20000" \
- -arg "-spersistent,${tmpdir}/_.per,10m" \
+ -storage "-spersistent,${tmpdir}/_.per,10m" \
-vcl+backend { } -start
client c1 {
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/p00005.vtc ./bin/varnishtest/tests/p00005.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/p00005.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/p00005.vtc 2010-04-30 11:06:59.774838225 +0200
@@ -11,7 +11,7 @@
varnish v1 \
-arg "-pdiag_bitmap=0x30000" \
- -arg "-spersistent,${tmpdir}/_.per,10m" \
+ -storage "-spersistent,${tmpdir}/_.per,10m" \
-vcl+backend {
sub vcl_fetch {
set beresp.ttl = 3s;
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/p00006.vtc ./bin/varnishtest/tests/p00006.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/p00006.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/p00006.vtc 2010-04-30 11:04:20.310962837 +0200
@@ -13,7 +13,7 @@
varnish v1 \
- -arg "-spersistent,${tmpdir}/_.per,10m" \
+ -storage "-spersistent,${tmpdir}/_.per,10m" \
-vcl+backend { } -start
client c1 {
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/tests/v00010.vtc ./bin/varnishtest/tests/v00010.vtc
--- ../varnish-2.1.1.orig/bin/varnishtest/tests/v00010.vtc 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/tests/v00010.vtc 2010-04-30 10:58:57.199838479 +0200
@@ -13,7 +13,7 @@
txresp -hdr "Foo: foo" -body "abcdef\n"
} -start
-varnish v1 -arg "-smalloc,1m" -vcl+backend {
+varnish v1 -storage "-smalloc,1m" -vcl+backend {
sub vcl_fetch {
if (beresp.http.panic) {
diff -Naur ../varnish-2.1.1.orig/bin/varnishtest/vtc_varnish.c ./bin/varnishtest/vtc_varnish.c
--- ../varnish-2.1.1.orig/bin/varnishtest/vtc_varnish.c 2010-04-26 10:50:52.000000000 +0200
+++ ./bin/varnishtest/vtc_varnish.c 2010-04-30 10:58:57.261838026 +0200
@@ -33,6 +33,7 @@
#include <stdio.h>
+#include <limits.h>
#include <ctype.h>
#include <fcntl.h>
#include <stdlib.h>
@@ -68,6 +69,8 @@
struct varnish_stats *stats;
+ struct vsb *storage;
+
struct vsb *args;
int fds[4];
pid_t pid;
@@ -171,9 +174,15 @@
vtc_log(v->vl, 0, "Varnish name must start with 'v'");
v->args = vsb_newauto();
+
+ v->storage = vsb_newauto();
+ vsb_printf(v->storage, "-sfile,%s,10M", v->workdir);
+ vsb_finish(v->storage);
+
v->cli_fd = -1;
VTAILQ_INSERT_TAIL(&varnishes, v, list);
+
return (v);
}
@@ -269,6 +278,7 @@
vsb_printf(vsb, " -S %s/_S", v->workdir);
vsb_printf(vsb, " -M %s:%s", abuf, pbuf);
vsb_printf(vsb, " -P %s/varnishd.pid", v->workdir);
+ vsb_printf(vsb, " %s", vsb_data(v->storage));
vsb_printf(vsb, " %s", vsb_data(v->args));
vsb_finish(vsb);
AZ(vsb_overflowed(vsb));
@@ -663,6 +673,13 @@
for (; *av != NULL; av++) {
if (vtc_error)
break;
+ if (!strcmp(*av, "-storage")) {
+ vsb_clear(v->storage);
+ vsb_cat(v->storage, av[1]);
+ vsb_finish(v->storage);
+ av++;
+ continue;
+ }
if (!strcmp(*av, "-arg")) {
AN(av[1]);
AZ(v->pid);

View file

@ -0,0 +1,73 @@
Index: configure.ac
===================================================================
--- configure.ac (revision 5691)
+++ configure.ac (working copy)
@@ -39,6 +39,13 @@
# Checks for libraries.
save_LIBS="${LIBS}"
LIBS=""
+AC_CHECK_LIB(jemalloc, malloc)
+RT_LIBS="${LIBS}"
+LIBS="${save_LIBS}"
+AC_SUBST(RT_LIBS)
+
+save_LIBS="${LIBS}"
+LIBS=""
AC_CHECK_LIB(rt, clock_gettime)
RT_LIBS="${LIBS}"
LIBS="${save_LIBS}"
@@ -423,25 +430,21 @@
AC_DEFINE_UNQUOTED([VCC_CC],"$VCC_CC",[C compiler command line for VCL code])
# Use jemalloc on Linux
-JEMALLOC_SUBDIR=
JEMALLOC_LDADD=
AC_ARG_ENABLE(jemalloc,
AS_HELP_STRING([--disable-jemalloc],[do not use jemalloc (default is yes on Linux, no everywhere else)]),
[if test "x$enableval" = "xyes"; then
- JEMALLOC_SUBDIR=libjemalloc
- JEMALLOC_LDADD='$(top_builddir)/lib/libjemalloc/libjemalloc_mt.la'
+ JEMALLOC_LDADD='-ljemalloc'
fi],
[case $target in #(
*-*-linux*)
- JEMALLOC_SUBDIR=libjemalloc
- JEMALLOC_LDADD='$(top_builddir)/lib/libjemalloc/libjemalloc_mt.la'
+ JEMALLOC_LDADD='-ljemalloc'
;; #(
*)
true
;;
esac])
-AC_SUBST(JEMALLOC_SUBDIR)
AC_SUBST(JEMALLOC_LDADD)
# Generate output
@@ -467,7 +470,6 @@
lib/libvarnishapi/Makefile
lib/libvarnishcompat/Makefile
lib/libvcl/Makefile
- lib/libjemalloc/Makefile
man/Makefile
redhat/Makefile
varnishapi.pc
Index: lib/Makefile.am
===================================================================
--- lib/Makefile.am (revision 5691)
+++ lib/Makefile.am (working copy)
@@ -4,12 +4,10 @@
libvarnishcompat \
libvarnish \
libvarnishapi \
- libvcl \
- @JEMALLOC_SUBDIR@
+ libvcl
DIST_SUBDIRS = \
libvarnishcompat \
libvarnish \
libvarnishapi \
- libvcl \
- libjemalloc
+ libvcl

24
varnish.lockfile.patch Normal file
View file

@ -0,0 +1,24 @@
diff -Naur ../varnish-2.0-beta1.orig/redhat/varnish.initrc ./redhat/varnish.initrc
--- ../varnish-2.0-beta1.orig/redhat/varnish.initrc 2008-08-27 09:45:40.000000000 +0200
+++ ./redhat/varnish.initrc 2008-08-29 22:52:23.000000000 +0200
@@ -31,8 +31,6 @@
# Include varnish defaults
[ -e /etc/sysconfig/varnish ] && . /etc/sysconfig/varnish
-lockfile=/var/lock/subsys/$prog
-
start() {
if [ ! -x $exec ]
diff -Naur ../varnish-2.0-beta1.orig/redhat/varnishlog.initrc ./redhat/varnishlog.initrc
--- ../varnish-2.0-beta1.orig/redhat/varnishlog.initrc 2008-08-27 09:45:40.000000000 +0200
+++ ./redhat/varnishlog.initrc 2008-08-29 22:53:30.000000000 +0200
@@ -32,8 +32,6 @@
# Include varnish defaults
[ -e /etc/sysconfig/varnishlog ] && . /etc/sysconfig/varnishlog
-lockfile=/var/lock/subsys/$prog
-
start() {
if [ ! -x $exec ]

13
varnish.no_pcre_jit.patch Normal file
View file

@ -0,0 +1,13 @@
--- lib/libvarnish/vre.c.orig 2012-08-28 23:56:02.163515172 +0200
+++ lib/libvarnish/vre.c 2012-08-28 23:56:18.111315730 +0200
@@ -40,9 +40,7 @@
pcre_extra *re_extra;
};
-#ifndef PCRE_STUDY_JIT_COMPILE
-#define PCRE_STUDY_JIT_COMPILE 0
-#endif
+#define PCRE_STUDY_JIT_COMPILE 0
/*
* We don't want to spread or even expose the majority of PCRE options

View file

@ -0,0 +1,11 @@
--- bin/varnishtest/tests/c00031.vtc.orig 2010-08-24 12:33:29.062232351 +0200
+++ bin/varnishtest/tests/c00031.vtc 2010-08-24 12:31:57.804150780 +0200
@@ -9,7 +9,7 @@
txresp
} -start
-varnish v1 -arg "-p thread_pool_stack=131072" -vcl+backend {} -start
+varnish v1 -arg "-p thread_pool_stack=262144" -vcl+backend {} -start
client c1 {
txreq -url "/"

View file

@ -0,0 +1,24 @@
diff -Naur ../varnish-2.0-beta2.orig/lib/libjemalloc/jemalloc_linux.c ./lib/libjemalloc/jemalloc_linux.c
--- ../varnish-2.0-beta2.orig/lib/libjemalloc/jemalloc_linux.c 2008-09-24 20:05:19.000000000 +0200
+++ ./lib/libjemalloc/jemalloc_linux.c 2008-10-06 14:13:28.950350627 +0200
@@ -257,7 +257,7 @@
# define NO_TLS
#endif
#ifdef __powerpc__
-# define PAGESIZE_2POW 12
+# define PAGESIZE_2POW 16
# define QUANTUM_2POW 4
# define SIZEOF_PTR_2POW 2
#endif
diff -Naur ../varnish-2.0-beta2.orig/lib/libjemalloc/malloc.c ./lib/libjemalloc/malloc.c
--- ../varnish-2.0-beta2.orig/lib/libjemalloc/malloc.c 2008-09-24 20:05:19.000000000 +0200
+++ ./lib/libjemalloc/malloc.c 2008-10-06 14:13:42.023005090 +0200
@@ -261,7 +261,7 @@
# define NO_TLS
#endif
#ifdef __powerpc__
-# define PAGESIZE_2POW 12
+# define PAGESIZE_2POW 16
# define QUANTUM_2POW 4
# define SIZEOF_PTR_2POW 2
#endif

View file

@ -0,0 +1,15 @@
diff -Naur ../varnish-2.1.2.orig/lib/libjemalloc/jemalloc_linux.c ./lib/libjemalloc/jemalloc_linux.c
--- ../varnish-2.1.2.orig/lib/libjemalloc/jemalloc_linux.c 2010-05-05 09:32:02.000000000 +0200
+++ ./lib/libjemalloc/jemalloc_linux.c 2010-07-29 15:39:00.221232248 +0200
@@ -273,6 +273,11 @@
# define QUANTUM_2POW 4
# define SIZEOF_PTR_2POW 2
#endif
+#ifdef __s390__
+# define PAGESIZE_2POW 12
+# define QUANTUM_2POW 4
+# define SIZEOF_PTR_2POW 2
+#endif
#ifdef __s390x__
# define PAGESIZE_2POW 12
# define QUANTUM_2POW 4

View file

@ -0,0 +1,15 @@
diff -Naur ../varnish-2.0.3.orig/lib/libjemalloc/jemalloc_linux.c ./lib/libjemalloc/jemalloc_linux.c
--- ../varnish-2.0.3.orig/lib/libjemalloc/jemalloc_linux.c 2009-02-12 12:15:24.000000000 +0100
+++ ./lib/libjemalloc/jemalloc_linux.c 2009-06-04 15:27:34.000000000 +0200
@@ -272,6 +272,11 @@
# define QUANTUM_2POW 4
# define SIZEOF_PTR_2POW 2
#endif
+#ifdef __s390x__
+# define PAGESIZE_2POW 12
+# define QUANTUM_2POW 4
+# define SIZEOF_PTR_2POW 3
+#endif
#define QUANTUM ((size_t)(1U << QUANTUM_2POW))
#define QUANTUM_MASK (QUANTUM - 1)

View file

@ -0,0 +1,11 @@
--- lib/libjemalloc/jemalloc_linux.c.old 2009-08-14 10:38:53.783906580 +0200
+++ lib/libjemalloc/jemalloc_linux.c 2009-08-14 10:39:04.215906982 +0200
@@ -243,7 +243,7 @@
# define SIZEOF_PTR_2POW 3
# define NO_TLS
#endif
-#ifdef __sparc64__
+#ifdef __sparc__
# define PAGESIZE_2POW 13
# define QUANTUM_2POW 4
# define SIZEOF_PTR_2POW 3

File diff suppressed because it is too large Load diff

View file

@ -1,3 +0,0 @@
#Type Name ID GECOS Home directory Shell
g varnish -
u varnish - "Varnish Cache" /var/lib/varnish /sbin/nologin

View file

@ -0,0 +1,607 @@
Index: include/libvarnish.h
===================================================================
--- include/libvarnish.h (revision 3417)
+++ include/libvarnish.h (working copy)
@@ -63,6 +63,7 @@
void TCP_name(const struct sockaddr *addr, unsigned l, char *abuf, unsigned alen, char *pbuf, unsigned plen);
int TCP_connect(int s, const struct sockaddr *name, socklen_t namelen, int msec);
void TCP_close(int *s);
+void TCP_set_read_timeout(int socket, double seconds);
#endif
/* from libvarnish/time.c */
Index: include/vrt_obj.h
===================================================================
--- include/vrt_obj.h (revision 3417)
+++ include/vrt_obj.h (working copy)
@@ -28,6 +28,12 @@
void VRT_l_bereq_url(const struct sess *, const char *, ...);
const char * VRT_r_bereq_proto(const struct sess *);
void VRT_l_bereq_proto(const struct sess *, const char *, ...);
+double VRT_r_bereq_connect_timeout(struct sess *);
+void VRT_l_bereq_connect_timeout(struct sess *, double);
+double VRT_r_bereq_first_byte_timeout(struct sess *);
+void VRT_l_bereq_first_byte_timeout(struct sess *, double);
+double VRT_r_bereq_between_bytes_timeout(struct sess *);
+void VRT_l_bereq_between_bytes_timeout(struct sess *, double);
const char * VRT_r_obj_proto(const struct sess *);
void VRT_l_obj_proto(const struct sess *, const char *, ...);
int VRT_r_obj_status(const struct sess *);
Index: include/vrt.h
===================================================================
--- include/vrt.h (revision 3417)
+++ include/vrt.h (working copy)
@@ -69,6 +69,8 @@
const unsigned char *ipv6_sockaddr;
double connect_timeout;
+ double first_byte_timeout;
+ double between_bytes_timeout;
unsigned max_connections;
struct vrt_backend_probe probe;
};
Index: lib/libvarnish/tcp.c
===================================================================
--- lib/libvarnish/tcp.c (revision 3417)
+++ lib/libvarnish/tcp.c (working copy)
@@ -47,6 +47,7 @@
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
+#include <math.h>
#include "config.h"
#ifndef HAVE_STRLCPY
@@ -209,3 +210,16 @@
errno == ENOTCONN);
*s = -1;
}
+
+
+void
+TCP_set_read_timeout(int s, double seconds)
+{
+ struct timeval timeout;
+ timeout.tv_sec = floor(seconds);
+ timeout.tv_usec = 1e6 * (seconds - timeout.tv_sec);
+#ifdef SO_RCVTIMEO_WORKS
+ AZ(setsockopt(s, SOL_SOCKET, SO_RCVTIMEO, &timeout, sizeof timeout));
+#endif
+}
+
Index: lib/libvcl/vcc_gen_obj.tcl
===================================================================
--- lib/libvcl/vcc_gen_obj.tcl (revision 3417)
+++ lib/libvcl/vcc_gen_obj.tcl (working copy)
@@ -127,6 +127,22 @@
{ pipe pass miss fetch }
"const struct sess *"
}
+ { bereq.connect_timeout
+ RW TIME
+ { pass miss }
+ "struct sess *"
+ }
+ { bereq.first_byte_timeout
+ RW TIME
+ { pass miss }
+ "struct sess *"
+ }
+ { bereq.between_bytes_timeout
+ RW TIME
+ { pass miss }
+ "struct sess *"
+ }
+
# The (possibly) cached object
{ obj.proto
Index: lib/libvcl/vcc_obj.c
===================================================================
--- lib/libvcl/vcc_obj.c (revision 3417)
+++ lib/libvcl/vcc_obj.c (working copy)
@@ -123,6 +123,27 @@
"HDR_BEREQ",
VCL_MET_PIPE | VCL_MET_PASS | VCL_MET_MISS | VCL_MET_FETCH
},
+ { "bereq.connect_timeout", TIME, 21,
+ "VRT_r_bereq_connect_timeout(sp)",
+ "VRT_l_bereq_connect_timeout(sp, ",
+ V_RW,
+ 0,
+ VCL_MET_PASS | VCL_MET_MISS
+ },
+ { "bereq.first_byte_timeout", TIME, 24,
+ "VRT_r_bereq_first_byte_timeout(sp)",
+ "VRT_l_bereq_first_byte_timeout(sp, ",
+ V_RW,
+ 0,
+ VCL_MET_PASS | VCL_MET_MISS
+ },
+ { "bereq.between_bytes_timeout", TIME, 27,
+ "VRT_r_bereq_between_bytes_timeout(sp)",
+ "VRT_l_bereq_between_bytes_timeout(sp, ",
+ V_RW,
+ 0,
+ VCL_MET_PASS | VCL_MET_MISS
+ },
{ "obj.proto", STRING, 9,
"VRT_r_obj_proto(sp)",
"VRT_l_obj_proto(sp, ",
Index: lib/libvcl/vcc_backend.c
===================================================================
--- lib/libvcl/vcc_backend.c (revision 3417)
+++ lib/libvcl/vcc_backend.c (working copy)
@@ -481,6 +481,8 @@
"?port",
"?host_header",
"?connect_timeout",
+ "?first_byte_timeout",
+ "?between_bytes_timeout",
"?probe",
"?max_connections",
NULL);
@@ -545,6 +547,20 @@
Fb(tl, 0, ",\n");
ExpectErr(tl, ';');
vcc_NextToken(tl);
+ } else if (vcc_IdIs(t_field, "first_byte_timeout")) {
+ Fb(tl, 0, "\t.first_byte_timeout = ");
+ vcc_TimeVal(tl);
+ ERRCHK(tl);
+ Fb(tl, 0, ",\n");
+ ExpectErr(tl, ';');
+ vcc_NextToken(tl);
+ } else if (vcc_IdIs(t_field, "between_bytes_timeout")) {
+ Fb(tl, 0, "\t.between_bytes_timeout = ");
+ vcc_TimeVal(tl);
+ ERRCHK(tl);
+ Fb(tl, 0, ",\n");
+ ExpectErr(tl, ';');
+ vcc_NextToken(tl);
} else if (vcc_IdIs(t_field, "max_connections")) {
u = vcc_UintVal(tl);
vcc_NextToken(tl);
Index: lib/libvcl/vcc_fixed_token.c
===================================================================
--- lib/libvcl/vcc_fixed_token.c (revision 3417)
+++ lib/libvcl/vcc_fixed_token.c (working copy)
@@ -349,6 +349,8 @@
vsb_cat(sb, " const unsigned char *ipv6_sockaddr;\n");
vsb_cat(sb, "\n");
vsb_cat(sb, " double connect_timeout;\n");
+ vsb_cat(sb, " double first_byte_timeout;\n");
+ vsb_cat(sb, " double between_bytes_timeout;\n");
vsb_cat(sb, " unsigned max_connections;\n");
vsb_cat(sb, " struct vrt_backend_probe probe;\n");
vsb_cat(sb, "};\n");
@@ -488,6 +490,12 @@
vsb_cat(sb, "void VRT_l_bereq_url(const struct sess *, const char *, ...);\n");
vsb_cat(sb, "const char * VRT_r_bereq_proto(const struct sess *);\n");
vsb_cat(sb, "void VRT_l_bereq_proto(const struct sess *, const char *, ...);\n");
+ vsb_cat(sb, "double VRT_r_bereq_connect_timeout(struct sess *);\n");
+ vsb_cat(sb, "void VRT_l_bereq_connect_timeout(struct sess *, double);\n");
+ vsb_cat(sb, "double VRT_r_bereq_first_byte_timeout(struct sess *);\n");
+ vsb_cat(sb, "void VRT_l_bereq_first_byte_timeout(struct sess *, double);\n");
+ vsb_cat(sb, "double VRT_r_bereq_between_bytes_timeout(struct sess *);\n");
+ vsb_cat(sb, "void VRT_l_bereq_between_bytes_timeout(struct sess *, double);\n");
vsb_cat(sb, "const char * VRT_r_obj_proto(const struct sess *);\n");
vsb_cat(sb, "void VRT_l_obj_proto(const struct sess *, const char *, ...);\n");
vsb_cat(sb, "int VRT_r_obj_status(const struct sess *);\n");
Index: bin/varnishd/mgt_param.c
===================================================================
--- bin/varnishd/mgt_param.c (revision 3417)
+++ bin/varnishd/mgt_param.c (working copy)
@@ -98,6 +98,24 @@
cli_out(cli, "%u", *dst);
}
+static void
+tweak_generic_timeout_double(struct cli *cli, volatile double *dst, const char *arg)
+{
+ double u;
+
+ if (arg != NULL) {
+ u = strtod(arg, NULL);
+ if (u < 0) {
+ cli_out(cli, "Timeout must be greater or equal to zero\n");
+ cli_result(cli, CLIS_PARAM);
+ return;
+ }
+ *dst = u;
+ } else
+ cli_out(cli, "%f", *dst);
+}
+
+
/*--------------------------------------------------------------------*/
static void
@@ -109,7 +127,15 @@
tweak_generic_timeout(cli, dest, arg);
}
+static void
+tweak_timeout_double(struct cli *cli, const struct parspec *par, const char *arg)
+{
+ volatile double *dest;
+ dest = par->priv;
+ tweak_generic_timeout_double(cli, dest, arg);
+}
+
/*--------------------------------------------------------------------*/
static void
@@ -739,14 +765,33 @@
"Cache vbe_conn's or rely on malloc, that's the question.",
EXPERIMENTAL,
"off", "bool" },
- { "connect_timeout", tweak_uint,
+ { "connect_timeout", tweak_timeout_double,
&master.connect_timeout,0, UINT_MAX,
- "Default connection timeout for backend connections. "
+ "Default connection timeout for backend connections. "
"We only try to connect to the backend for this many "
- "milliseconds before giving up. "
- "VCL can override this default value for each backend.",
+ "seconds before giving up. "
+ "VCL can override this default value for each backend "
+ "and backend request.",
0,
- "400", "ms" },
+ "0.4", "s" },
+ { "first_byte_timeout", tweak_timeout_double,
+ &master.first_byte_timeout,0, UINT_MAX,
+ "Default timeout for receiving first byte from backend. "
+ "We only wait for this many seconds for the first "
+ "byte before giving up. A value of 0 means it will never time out. "
+ "VCL can override this default value for each backend and"
+ "backend request. This parameter does not apply to pipe.",
+ 0,
+ "60", "s" },
+ { "between_bytes_timeout", tweak_timeout_double,
+ &master.between_bytes_timeout,0, UINT_MAX,
+ "Default timeout between bytes when receiving data from backend. "
+ "We only wait for this many seconds between bytes "
+ "before giving up. A value of 0 means it will never time out. "
+ "VCL can override this default value for each backend and "
+ "backend request. This parameter does not apply to pipe.",
+ 0,
+ "60", "s" },
{ "accept_fd_holdoff", tweak_timeout,
&master.accept_fd_holdoff, 0, 3600*1000,
"If we run out of file descriptors, the accept thread will "
Index: bin/varnishd/cache_backend_cfg.c
===================================================================
--- bin/varnishd/cache_backend_cfg.c (revision 3417)
+++ bin/varnishd/cache_backend_cfg.c (working copy)
@@ -222,6 +222,8 @@
REPLACE(b->hosthdr, vb->hosthdr);
b->connect_timeout = vb->connect_timeout;
+ b->first_byte_timeout = vb->first_byte_timeout;
+ b->between_bytes_timeout = vb->between_bytes_timeout;
b->max_conn = vb->max_connections;
/*
Index: bin/varnishd/varnishd.1
===================================================================
--- bin/varnishd/varnishd.1 (revision 3417)
+++ bin/varnishd/varnishd.1 (working copy)
@@ -387,6 +387,15 @@
.Pp
The default is
.Dv off .
+.It Va between_bytes_timeout
+Default timeout between bytes when receiving data from backend.
+We only wait for this many seconds between bytes before giving up.
+A value of 0 means it will never time out.
+VCL can override this default value for each backend and backend request.
+This parameter does not apply to pipe.
+.Pp
+The default is
+.Dv 60 seconds
.It Va client_http11
Whether to force the use of HTTP/1.1 when responding to client
requests, or just use the same protocol version as that used by the
@@ -394,6 +403,13 @@
.Pp
The default is
.Dv off .
+.It Va connect_timeout
+Default connection timeout for backend connections.
+We only try to connect to the backend for this many seconds before giving up.
+VCL can override this default value for each backend and backend request.
+.Pp
+The default is
+.Dv 0.4 seconds
.It Va default_ttl
The default time-to-live assigned to objects if neither the backend
nor the configuration assign one.
@@ -409,6 +425,15 @@
backend server does not specify a content length.
.Pp
The default is 128 kilobytes.
+.It Va first_byte_timeout
+Default timeout for receiving first byte from backend.
+We only wait for this many seconds for the first byte before giving up.
+A value of 0 means it will never time out.
+VCL can override this default value for each backend and backend request.
+This parameter does not apply to pipe.
+.Pp
+The default is
+.Dv 60 seconds
.It Va group
The name of an unprivileged group to which the child process should
switch before it starts accepting connections.
Index: bin/varnishd/cache_backend.c
===================================================================
--- bin/varnishd/cache_backend.c (revision 3417)
+++ bin/varnishd/cache_backend.c (working copy)
@@ -94,7 +94,7 @@
if (s < 0)
return (s);
- tmo = params->connect_timeout;
+ tmo = (int)(sp->connect_timeout * 1000);
if (bp->connect_timeout > 10e-3)
tmo = (int)(bp->connect_timeout * 1000);
Index: bin/varnishd/cache_fetch.c
===================================================================
--- bin/varnishd/cache_fetch.c (revision 3417)
+++ bin/varnishd/cache_fetch.c (working copy)
@@ -336,6 +336,8 @@
if (sp->vbe == NULL)
return (__LINE__);
vc = sp->vbe;
+ /* Inherit the backend timeouts from the selected backend */
+ SES_InheritBackendTimeouts(sp);
/*
* Now that we know our backend, we can set a default Host:
@@ -369,8 +371,12 @@
VSL_stats->backend_req++;
HTC_Init(htc, bereq->ws, vc->fd);
- do
- i = HTC_Rx(htc);
+ TCP_set_read_timeout(vc->fd, sp->first_byte_timeout);
+ do {
+ i = HTC_Rx(htc);
+ TCP_set_read_timeout(vc->fd, sp->between_bytes_timeout);
+ }
+
while (i == 0);
if (i < 0) {
Index: bin/varnishd/cache_backend.h
===================================================================
--- bin/varnishd/cache_backend.h (revision 3417)
+++ bin/varnishd/cache_backend.h (working copy)
@@ -104,6 +104,8 @@
char *ident;
char *vcl_name;
double connect_timeout;
+ double first_byte_timeout;
+ double between_bytes_timeout;
uint32_t hash;
Index: bin/varnishd/cache_vrt.c
===================================================================
--- bin/varnishd/cache_vrt.c (revision 3417)
+++ bin/varnishd/cache_vrt.c (working copy)
@@ -288,6 +288,49 @@
return (atoi(sp->http->hd[HTTP_HDR_STATUS].b));
}
+void
+VRT_l_bereq_connect_timeout(struct sess *sp, double num)
+{
+ CHECK_OBJ_NOTNULL(sp, SESS_MAGIC);
+ sp->connect_timeout = (num > 0 ? num : 0);
+}
+
+double
+VRT_r_bereq_connect_timeout(struct sess *sp)
+{
+ CHECK_OBJ_NOTNULL(sp, SESS_MAGIC);
+ return sp->connect_timeout;
+}
+
+void
+VRT_l_bereq_first_byte_timeout(struct sess *sp, double num)
+{
+ CHECK_OBJ_NOTNULL(sp, SESS_MAGIC);
+ sp->first_byte_timeout = (num > 0 ? num : 0);
+}
+
+double
+VRT_r_bereq_first_byte_timeout(struct sess *sp)
+{
+ CHECK_OBJ_NOTNULL(sp, SESS_MAGIC);
+ return sp->first_byte_timeout;
+}
+
+void
+VRT_l_bereq_between_bytes_timeout(struct sess *sp, double num)
+{
+ CHECK_OBJ_NOTNULL(sp, SESS_MAGIC);
+ sp->between_bytes_timeout = (num > 0 ? num : 0);
+}
+
+double
+VRT_r_bereq_between_bytes_timeout(struct sess *sp)
+{
+ CHECK_OBJ_NOTNULL(sp, SESS_MAGIC);
+ return sp->between_bytes_timeout;
+}
+
+
/*--------------------------------------------------------------------*/
void
Index: bin/varnishd/cache_center.c
===================================================================
--- bin/varnishd/cache_center.c (revision 3417)
+++ bin/varnishd/cache_center.c (working copy)
@@ -851,6 +851,8 @@
CHECK_OBJ_NOTNULL(sp->vcl, VCL_CONF_MAGIC);
AZ(sp->obj);
+ SES_ResetBackendTimeouts(sp);
+
/* By default we use the first backend */
AZ(sp->director);
sp->director = sp->vcl->director[0];
Index: bin/varnishd/cache_session.c
===================================================================
--- bin/varnishd/cache_session.c (revision 3417)
+++ bin/varnishd/cache_session.c (working copy)
@@ -58,6 +58,7 @@
#include "shmlog.h"
#include "cache.h"
+#include "cache_backend.h"
/*--------------------------------------------------------------------*/
@@ -316,6 +317,8 @@
sp->http = &sm->http[0];
sp->http0 = &sm->http[1];
+ SES_ResetBackendTimeouts(sp);
+
return (sp);
}
@@ -367,3 +370,37 @@
MTX_INIT(&stat_mtx);
MTX_INIT(&ses_mem_mtx);
}
+
+void
+SES_ResetBackendTimeouts(struct sess *sp)
+{
+ sp->connect_timeout = params->connect_timeout;
+ sp->first_byte_timeout = params->first_byte_timeout;
+ sp->between_bytes_timeout = params->between_bytes_timeout;
+}
+
+void
+SES_InheritBackendTimeouts(struct sess *sp)
+{
+ struct backend *be = NULL;
+
+ AN(sp);
+ AN(sp->vbe);
+ AN(sp->vbe->backend);
+
+ be = sp->vbe->backend;
+ /*
+ * We only inherit the backend's timeout if the session timeout
+ * has not already been set in the VCL, as the order of precedence
+ * is parameter < backend definition < VCL.
+ */
+ if (be->connect_timeout > 1e-3 &&
+ sp->connect_timeout == params->connect_timeout)
+ sp->connect_timeout = be->connect_timeout;
+ if (be->first_byte_timeout > 1e-3 &&
+ sp->first_byte_timeout == params->first_byte_timeout)
+ sp->first_byte_timeout = be->first_byte_timeout;
+ if (be->between_bytes_timeout > 1e-3
+ && sp->between_bytes_timeout == params->between_bytes_timeout)
+ sp->between_bytes_timeout = be->between_bytes_timeout;
+}
Index: bin/varnishd/cache.h
===================================================================
--- bin/varnishd/cache.h (revision 3417)
+++ bin/varnishd/cache.h (working copy)
@@ -344,6 +344,12 @@
double t_resp;
double t_end;
+ /* Timeouts */
+ double connect_timeout;
+ double first_byte_timeout;
+ double between_bytes_timeout;
+
+
/* Acceptable grace period */
double grace;
@@ -529,6 +535,8 @@
void SES_Delete(struct sess *sp);
void SES_RefSrcAddr(struct sess *sp);
void SES_Charge(struct sess *sp);
+void SES_ResetBackendTimeouts(struct sess *sp);
+void SES_InheritBackendTimeouts(struct sess *sp);
/* cache_shmlog.c */
void VSL_Init(void);
Index: bin/varnishd/heritage.h
===================================================================
--- bin/varnishd/heritage.h (revision 3417)
+++ bin/varnishd/heritage.h (working copy)
@@ -154,8 +154,12 @@
unsigned cache_vbe_conns;
/* Default connection_timeout */
- unsigned connect_timeout;
+ double connect_timeout;
+ /* Read timeouts for backend */
+ double first_byte_timeout;
+ double between_bytes_timeout;
+
/* How long to linger on sessions */
unsigned session_linger;
Index: man/vcl.7so
===================================================================
--- man/vcl.7so (revision 3417)
+++ man/vcl.7so (working copy)
@@ -92,6 +92,26 @@
set req.backend = www;
}
.Ed
+.Pp
+The timeout parameters can be overridden in the backend declaration.
+The timeout parameters are
+.Fa .connect_timeout
+for the time to wait for a backend connection,
+.Fa .first_byte_timeout
+for the time to wait for the first byte from the backend and
+.Fa .between_bytes_timeout
+for time to wait between each received byte.
+.Pp
+These can be set in the declaration like this:
+.Bd -literal -offset 4n
+backend www {
+ .host = "www.example.com";
+ .port = "http";
+ .connect_timeout = 1s;
+ .first_byte_timeout = 5s;
+ .between_bytes_timeout = 2s;
+}
+.Ed
.Ss Directors
Directors choose from different backends based on health status and a
per-director algorithm.
@@ -484,6 +504,14 @@
.It Va req.http. Ns Ar header
The corresponding HTTP
.Ar header .
+.It Va bereq.connect_timeout
+The time in seconds to wait for a backend connection.
+.It Va bereq.first_byte_timeout
+The time in seconds to wait for the first byte from the backend.
+Not available in pipe mode.
+.It Va bereq.between_bytes_timeout
+The time in seconds to wait between each received byte from the backend.
+Not available in pipe mode.
.El
.Pp
The following variables are available while preparing a backend

View file

@ -1,2 +0,0 @@
d /var/lib/varnish 755 root root -
d /var/log/varnish 700 varnish varnish -

13
varnish.v00002fix.patch Normal file
View file

@ -0,0 +1,13 @@
Index: bin/varnishtest/tests/v00002.vtc
===================================================================
--- bin/varnishtest/tests/v00002.vtc (revision 4730)
+++ bin/varnishtest/tests/v00002.vtc (revision 4731)
@@ -114,7 +114,7 @@
varnish v1 -badvcl {
/* too many IP numbers */
- backend b1 { .host = "cnn.com"; }
+ backend b1 { .host = "v00002.freebsd.dk"; }
}
varnish v1 -badvcl {

View file

@ -0,0 +1,23 @@
diff -Naur ../varnish-2.0.2.orig/bin/varnishtest/Makefile.am ./bin/varnishtest/Makefile.am
--- ../varnish-2.0.2.orig/bin/varnishtest/Makefile.am 2008-11-14 13:24:08.000000000 +0100
+++ ./bin/varnishtest/Makefile.am 2008-11-17 13:40:05.964237951 +0100
@@ -1,6 +1,6 @@
# $Id: Makefile.am 3374 2008-11-10 10:12:28Z tfheen $
-TESTS_ENVIRONMENT = ./varnishtest
+TESTS_ENVIRONMENT = ./varnishtest -v
TESTS = $(srcdir)/tests/*.vtc
DISTCLEANFILES = _.ok
diff -Naur ../varnish-2.0.2.orig/bin/varnishtest/Makefile.in ./bin/varnishtest/Makefile.in
--- ../varnish-2.0.2.orig/bin/varnishtest/Makefile.in 2008-11-14 13:59:33.000000000 +0100
+++ ./bin/varnishtest/Makefile.in 2008-11-17 13:40:51.503384938 +0100
@@ -204,7 +204,7 @@
top_builddir = @top_builddir@
top_srcdir = @top_srcdir@
varnishconfdir = @varnishconfdir@
-TESTS_ENVIRONMENT = ./varnishtest
+TESTS_ENVIRONMENT = ./varnishtest -v
TESTS = $(srcdir)/tests/*.vtc
DISTCLEANFILES = _.ok
INCLUDES = -I$(top_srcdir)/include

View file

@ -0,0 +1,781 @@
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/Makefile.in bin/varnishtest/Makefile.in
--- ../varnish-2.0-rc1/bin/varnishtest/Makefile.in 2008-10-08 13:39:45.000000000 +0200
+++ bin/varnishtest/Makefile.in 2008-10-09 20:05:13.000000000 +0200
@@ -96,7 +96,6 @@
DEFS = @DEFS@
DEPDIR = @DEPDIR@
DL_LIBS = @DL_LIBS@
-DSYMUTIL = @DSYMUTIL@
ECHO = @ECHO@
ECHO_C = @ECHO_C@
ECHO_N = @ECHO_N@
@@ -123,7 +122,6 @@
MAKEINFO = @MAKEINFO@
MKDIR_P = @MKDIR_P@
NET_LIBS = @NET_LIBS@
-NMEDIT = @NMEDIT@
OBJEXT = @OBJEXT@
PACKAGE = @PACKAGE@
PACKAGE_BUGREPORT = @PACKAGE_BUGREPORT@
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/tests/a00008.vtc bin/varnishtest/tests/a00008.vtc
--- ../varnish-2.0-rc1/bin/varnishtest/tests/a00008.vtc 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/tests/a00008.vtc 2008-10-09 13:49:15.000000000 +0200
@@ -1,4 +1,4 @@
-# $Id: a00008.vtc 3012 2008-07-24 12:22:35Z des $
+# $Id: a00008.vtc 3272 2008-10-09 11:39:24Z phk $
test "Sema operations"
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/vtc.c bin/varnishtest/vtc.c
--- ../varnish-2.0-rc1/bin/varnishtest/vtc.c 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/vtc.c 2008-10-09 13:49:16.000000000 +0200
@@ -23,7 +23,7 @@
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
- * $Id: vtc.c 3243 2008-10-05 10:22:21Z phk $
+ * $Id: vtc.c 3272 2008-10-09 11:39:24Z phk $
*/
#include <stdio.h>
@@ -41,7 +41,8 @@
#define MAX_FILESIZE (1024 * 1024)
#define MAX_TOKENS 100
-static struct vtclog *vl;
+const char *vtc_file;
+char *vtc_desc;
/**********************************************************************
* Read a file into memory
@@ -80,7 +81,7 @@
*/
void
-parse_string(char *buf, const struct cmds *cmd, void *priv)
+parse_string(char *buf, const struct cmds *cmd, void *priv, struct vtclog *vl)
{
char *token_s[MAX_TOKENS], *token_e[MAX_TOKENS];
char *p, *q;
@@ -183,7 +184,7 @@
}
assert(cp->cmd != NULL);
- cp->cmd(token_s, priv, cmd);
+ cp->cmd(token_s, priv, cmd, vl);
}
}
@@ -196,7 +197,7 @@
{
for (; cmd->name != NULL; cmd++)
- cmd->cmd(NULL, NULL, NULL);
+ cmd->cmd(NULL, NULL, NULL, NULL);
}
/**********************************************************************
@@ -209,6 +210,7 @@
(void)priv;
(void)cmd;
+ (void)vl;
if (av == NULL)
return;
@@ -216,6 +218,7 @@
printf("# TEST %s\n", av[1]);
AZ(av[2]);
+ vtc_desc = strdup(av[1]);
}
/**********************************************************************
@@ -270,6 +273,7 @@
{
(void)cmd;
+ (void)vl;
if (av == NULL)
return;
printf("cmd_dump(%p)\n", priv);
@@ -293,16 +297,20 @@
};
static void
-exec_file(const char *fn)
+exec_file(const char *fn, struct vtclog *vl)
{
char *buf;
- printf("# TEST %s starting\n", fn);
+ vtc_file = fn;
+ vtc_desc = NULL;
+ vtc_log(vl, 1, "TEST %s starting", fn);
buf = read_file(fn);
- parse_string(buf, cmds, NULL);
- printf("# RESETTING after %s\n", fn);
+ parse_string(buf, cmds, NULL, vl);
+ vtc_log(vl, 1, "RESETTING after %s", fn);
reset_cmds(cmds);
- printf("# TEST %s completed\n", fn);
+ vtc_log(vl, 1, "TEST %s completed", fn);
+ vtc_file = NULL;
+ free(vtc_desc);
}
/**********************************************************************
@@ -325,10 +333,11 @@
{
int ch;
FILE *fok;
+ static struct vtclog *vl;
setbuf(stdout, NULL);
setbuf(stderr, NULL);
- vl = vtc_logopen("");
+ vl = vtc_logopen("top");
AN(vl);
while ((ch = getopt(argc, argv, "qv")) != -1) {
switch (ch) {
@@ -350,7 +359,7 @@
init_sema();
for (ch = 0; ch < argc; ch++)
- exec_file(argv[ch]);
+ exec_file(argv[ch], vl);
fok = fopen("_.ok", "w");
if (fok != NULL)
fclose(fok);
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/vtc_client.c bin/varnishtest/vtc_client.c
--- ../varnish-2.0-rc1/bin/varnishtest/vtc_client.c 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/vtc_client.c 2008-10-09 13:49:16.000000000 +0200
@@ -23,7 +23,7 @@
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
- * $Id: vtc_client.c 3127 2008-08-26 07:51:12Z phk $
+ * $Id: vtc_client.c 3272 2008-10-09 11:39:24Z phk $
*/
#include <stdio.h>
@@ -51,7 +51,7 @@
char *spec;
- const char *connect;
+ char *connect;
pthread_t tp;
};
@@ -98,26 +98,42 @@
*/
static struct client *
-client_new(char *name)
+client_new(const char *name)
{
struct client *c;
+ AN(name);
ALLOC_OBJ(c, CLIENT_MAGIC);
AN(c);
- c->name = name;
+ REPLACE(c->name, name);
c->vl = vtc_logopen(name);
AN(c->vl);
- if (*name != 'c') {
+ if (*c->name != 'c')
vtc_log(c->vl, 0, "Client name must start with 'c'");
- exit (1);
- }
- c->connect = "127.0.0.1:9081";
+ REPLACE(c->connect, "127.0.0.1:9081");
VTAILQ_INSERT_TAIL(&clients, c, list);
return (c);
}
/**********************************************************************
+ * Clean up client
+ */
+
+static void
+client_delete(struct client *c)
+{
+
+ CHECK_OBJ_NOTNULL(c, CLIENT_MAGIC);
+ vtc_logclose(c->vl);
+ free(c->spec);
+ free(c->name);
+ free(c->connect);
+ /* XXX: MEMLEAK (?)*/
+ FREE_OBJ(c);
+}
+
+/**********************************************************************
* Start the client thread
*/
@@ -173,6 +189,7 @@
(void)priv;
(void)cmd;
+ (void)vl;
if (av == NULL) {
/* Reset and free */
@@ -180,8 +197,7 @@
VTAILQ_REMOVE(&clients, c, list);
if (c->tp != 0)
client_wait(c);
- FREE_OBJ(c);
- /* XXX: MEMLEAK */
+ client_delete(c);
}
return;
}
@@ -198,7 +214,7 @@
for (; *av != NULL; av++) {
if (!strcmp(*av, "-connect")) {
- c->connect = av[1];
+ REPLACE(c->connect, av[1]);
av++;
continue;
}
@@ -218,6 +234,6 @@
vtc_log(c->vl, 0, "Unknown client argument: %s", *av);
exit (1);
}
- c->spec = *av;
+ REPLACE(c->spec, *av);
}
}
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/vtc.h bin/varnishtest/vtc.h
--- ../varnish-2.0-rc1/bin/varnishtest/vtc.h 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/vtc.h 2008-10-09 13:49:15.000000000 +0200
@@ -23,14 +23,14 @@
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
- * $Id: vtc.h 3244 2008-10-05 10:22:53Z phk $
+ * $Id: vtc.h 3272 2008-10-09 11:39:24Z phk $
*/
struct vsb;
struct vtclog;
struct cmds;
-#define CMD_ARGS char * const *av, void *priv, const struct cmds *cmd
+#define CMD_ARGS char * const *av, void *priv, const struct cmds *cmd, struct vtclog *vl
typedef void cmd_f(CMD_ARGS);
struct cmds {
@@ -38,7 +38,7 @@
cmd_f *cmd;
};
-void parse_string(char *buf, const struct cmds *cmd, void *priv);
+void parse_string(char *buf, const struct cmds *cmd, void *priv, struct vtclog *vl);
cmd_f cmd_dump;
cmd_f cmd_delay;
@@ -47,13 +47,17 @@
cmd_f cmd_varnish;
cmd_f cmd_sema;
+extern const char *vtc_file;
+extern char *vtc_desc;
+extern int vtc_verbosity;
+
void init_sema(void);
void http_process(struct vtclog *vl, const char *spec, int sock, int client);
void cmd_server_genvcl(struct vsb *vsb);
-extern int vtc_verbosity;
struct vtclog *vtc_logopen(const char *id);
+void vtc_logclose(struct vtclog *vl);
void vtc_log(struct vtclog *vl, unsigned lvl, const char *fmt, ...);
void vtc_dump(struct vtclog *vl, unsigned lvl, const char *pfx, const char *str);
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/vtc_http.c bin/varnishtest/vtc_http.c
--- ../varnish-2.0-rc1/bin/varnishtest/vtc_http.c 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/vtc_http.c 2008-10-09 13:49:16.000000000 +0200
@@ -23,7 +23,7 @@
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
- * $Id: vtc_http.c 3207 2008-09-21 06:47:37Z phk $
+ * $Id: vtc_http.c 3272 2008-10-09 11:39:24Z phk $
*/
@@ -70,7 +70,7 @@
* Generate a synthetic body
*/
-static const char *
+static char *
synth_body(const char *len)
{
int i, j, k, l;
@@ -185,6 +185,7 @@
char *rhs;
(void)cmd;
+ (void)vl;
CAST_OBJ_NOTNULL(hp, priv, HTTP_MAGIC);
assert(!strcmp(av[0], "expect"));
av++;
@@ -419,6 +420,7 @@
struct http *hp;
(void)cmd;
+ (void)vl;
CAST_OBJ_NOTNULL(hp, priv, HTTP_MAGIC);
AN(hp->client);
assert(!strcmp(av[0], "rxresp"));
@@ -445,9 +447,10 @@
const char *proto = "HTTP/1.1";
const char *status = "200";
const char *msg = "Ok";
- const char *body = NULL;
+ char *body = NULL;
(void)cmd;
+ (void)vl;
CAST_OBJ_NOTNULL(hp, priv, HTTP_MAGIC);
AZ(hp->client);
assert(!strcmp(av[0], "txresp"));
@@ -482,7 +485,7 @@
for(; *av != NULL; av++) {
if (!strcmp(*av, "-body")) {
AZ(body);
- body = av[1];
+ REPLACE(body, av[1]);
av++;
} else if (!strcmp(*av, "-bodylen")) {
AZ(body);
@@ -515,6 +518,7 @@
struct http *hp;
(void)cmd;
+ (void)vl;
CAST_OBJ_NOTNULL(hp, priv, HTTP_MAGIC);
AZ(hp->client);
assert(!strcmp(av[0], "rxreq"));
@@ -544,6 +548,7 @@
const char *body = NULL;
(void)cmd;
+ (void)vl;
CAST_OBJ_NOTNULL(hp, priv, HTTP_MAGIC);
AN(hp->client);
assert(!strcmp(av[0], "txreq"));
@@ -609,6 +614,7 @@
int i;
(void)cmd;
+ (void)vl;
CAST_OBJ_NOTNULL(hp, priv, HTTP_MAGIC);
AN(av[1]);
AZ(av[2]);
@@ -628,6 +634,7 @@
struct http *hp;
(void)cmd;
+ (void)vl;
CAST_OBJ_NOTNULL(hp, priv, HTTP_MAGIC);
AN(av[1]);
AZ(av[2]);
@@ -646,6 +653,7 @@
struct http *hp;
(void)cmd;
+ (void)vl;
CAST_OBJ_NOTNULL(hp, priv, HTTP_MAGIC);
AN(av[1]);
AZ(av[2]);
@@ -692,7 +700,7 @@
q = strchr(s, '\0');
assert(q > s);
AN(s);
- parse_string(s, http_cmds, hp);
+ parse_string(s, http_cmds, hp, vl);
vsb_delete(hp->vsb);
free(hp->rxbuf);
free(hp);
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/vtc_log.c bin/varnishtest/vtc_log.c
--- ../varnish-2.0-rc1/bin/varnishtest/vtc_log.c 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/vtc_log.c 2008-10-09 13:49:16.000000000 +0200
@@ -23,7 +23,7 @@
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
- * $Id: vtc_log.c 3248 2008-10-05 10:40:46Z phk $
+ * $Id: vtc_log.c 3272 2008-10-09 11:39:24Z phk $
*/
#include <stdio.h>
@@ -62,6 +62,15 @@
return (vl);
}
+void
+vtc_logclose(struct vtclog *vl)
+{
+
+ CHECK_OBJ_NOTNULL(vl, VTCLOG_MAGIC);
+ vsb_delete(vl->vsb);
+ FREE_OBJ(vl);
+}
+
static const char *lead[] = {
"----",
"# ",
@@ -77,6 +86,7 @@
vtc_log(struct vtclog *vl, unsigned lvl, const char *fmt, ...)
{
+ CHECK_OBJ_NOTNULL(vl, VTCLOG_MAGIC);
assert(lvl < NLEAD);
if (lvl > vtc_verbosity)
return;
@@ -91,8 +101,11 @@
AZ(vsb_overflowed(vl->vsb));
(void)fputs(vsb_data(vl->vsb), stdout);
vsb_clear(vl->vsb);
- if (lvl == 0)
+ if (lvl == 0) {
+ printf("---- TEST FILE: %s\n", vtc_file);
+ printf("---- TEST DESCRIPTION: %s\n", vtc_desc);
exit (1);
+ }
}
/**********************************************************************
@@ -105,6 +118,7 @@
{
int nl = 1;
+ CHECK_OBJ_NOTNULL(vl, VTCLOG_MAGIC);
assert(lvl < NLEAD);
if (lvl > vtc_verbosity)
return;
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/vtc_sema.c bin/varnishtest/vtc_sema.c
--- ../varnish-2.0-rc1/bin/varnishtest/vtc_sema.c 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/vtc_sema.c 2008-10-09 13:49:16.000000000 +0200
@@ -23,7 +23,7 @@
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
- * $Id: vtc_sema.c 3012 2008-07-24 12:22:35Z des $
+ * $Id: vtc_sema.c 3272 2008-10-09 11:39:24Z phk $
*/
#include <stdio.h>
@@ -42,7 +42,6 @@
unsigned magic;
#define SEMA_MAGIC 0x29b64317
char *name;
- struct vtclog *vl;
VTAILQ_ENTRY(sema) list;
pthread_mutex_t mtx;
pthread_cond_t cond;
@@ -59,17 +58,15 @@
*/
static struct sema *
-sema_new(char *name)
+sema_new(char *name, struct vtclog *vl)
{
struct sema *r;
ALLOC_OBJ(r, SEMA_MAGIC);
AN(r);
- r->vl = vtc_logopen(name);
- AN(r->vl);
r->name = name;
if (*name != 'r')
- vtc_log(r->vl, 0, "Sema name must start with 'r'");
+ vtc_log(vl, 0, "Sema name must start with 'r' (%s)", *name);
AZ(pthread_mutex_init(&r->mtx, NULL));
AZ(pthread_cond_init(&r->cond, NULL));
@@ -84,24 +81,31 @@
*/
static void
-sema_sync(struct sema *r, const char *av)
+sema_sync(struct sema *r, const char *av, struct vtclog *vl)
{
unsigned u;
+ CHECK_OBJ_NOTNULL(r, SEMA_MAGIC);
u = strtoul(av, NULL, 0);
AZ(pthread_mutex_lock(&r->mtx));
if (r->expected == 0)
r->expected = u;
- assert(r->expected == u);
+ if (r->expected != u)
+ vtc_log(vl, 0,
+ "Sema(%s) use error: different expectations (%u vs %u)",
+ r->name, r->expected, u);
if (++r->waiters == r->expected) {
- vtc_log(r->vl, 4, "Wake %u", r->expected);
+ vtc_log(vl, 4, "Sema(%s) wake %u", r->name, r->expected);
AZ(pthread_cond_broadcast(&r->cond));
r->waiters = 0;
r->expected = 0;
- } else
+ } else {
+ vtc_log(vl, 4, "Sema(%s) wait %u of %u",
+ r->name, r->waiters, r->expected);
AZ(pthread_cond_wait(&r->cond, &r->mtx));
+ }
AZ(pthread_mutex_unlock(&r->mtx));
}
@@ -121,9 +125,10 @@
AZ(pthread_mutex_lock(&sema_mtx));
/* Reset and free */
VTAILQ_FOREACH_SAFE(r, &semas, list, r2) {
- VTAILQ_REMOVE(&semas, r, list);
- FREE_OBJ(r);
- /* XXX: MEMLEAK */
+ AZ(pthread_mutex_lock(&r->mtx));
+ AZ(r->waiters);
+ AZ(r->expected);
+ AZ(pthread_mutex_unlock(&r->mtx));
}
AZ(pthread_mutex_unlock(&sema_mtx));
return;
@@ -137,7 +142,7 @@
if (!strcmp(r->name, av[0]))
break;
if (r == NULL)
- r = sema_new(av[0]);
+ r = sema_new(av[0], vl);
AZ(pthread_mutex_unlock(&sema_mtx));
av++;
@@ -145,10 +150,10 @@
if (!strcmp(*av, "sync")) {
av++;
AN(*av);
- sema_sync(r, *av);
+ sema_sync(r, *av, vl);
continue;
}
- vtc_log(r->vl, 0, "Unknown sema argument: %s", *av);
+ vtc_log(vl, 0, "Unknown sema argument: %s", *av);
}
}
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/vtc_server.c bin/varnishtest/vtc_server.c
--- ../varnish-2.0-rc1/bin/varnishtest/vtc_server.c 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/vtc_server.c 2008-10-09 13:49:16.000000000 +0200
@@ -23,7 +23,7 @@
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
- * $Id: vtc_server.c 3157 2008-09-02 20:20:48Z phk $
+ * $Id: vtc_server.c 3272 2008-10-09 11:39:24Z phk $
*/
@@ -57,7 +57,7 @@
int depth;
int sock;
- const char *listen;
+ char *listen;
struct vss_addr **vss_addr;
char *addr;
char *port;
@@ -109,20 +109,20 @@
*/
static struct server *
-server_new(char *name)
+server_new(const char *name)
{
struct server *s;
+ AN(name);
ALLOC_OBJ(s, SERVER_MAGIC);
AN(s);
- s->name = name;
+ REPLACE(s->name, name);
s->vl = vtc_logopen(name);
AN(s->vl);
- if (*name != 's') {
+ if (*s->name != 's')
vtc_log(s->vl, 0, "Server name must start with 's'");
- exit (1);
- }
- s->listen = "127.0.0.1:9080";
+
+ REPLACE(s->listen, "127.0.0.1:9080");
AZ(VSS_parse(s->listen, &s->addr, &s->port));
s->repeat = 1;
s->depth = 1;
@@ -132,6 +132,22 @@
}
/**********************************************************************
+ * Clean up a server
+ */
+
+static void
+server_delete(struct server *s)
+{
+
+ CHECK_OBJ_NOTNULL(s, SERVER_MAGIC);
+ vtc_logclose(s->vl);
+ free(s->listen);
+ free(s->name);
+ /* XXX: MEMLEAK (?) (VSS ??) */
+ FREE_OBJ(s);
+}
+
+/**********************************************************************
* Start the server thread
*/
@@ -211,6 +227,7 @@
(void)priv;
(void)cmd;
+ (void)vl;
if (av == NULL) {
/* Reset and free */
@@ -218,8 +235,7 @@
VTAILQ_REMOVE(&servers, s, list);
if (s->sock >= 0)
server_wait(s);
- FREE_OBJ(s);
- /* XXX: MEMLEAK */
+ server_delete(s);
}
return;
}
@@ -241,7 +257,7 @@
continue;
}
if (!strcmp(*av, "-listen")) {
- s->listen = av[1];
+ REPLACE(s->listen, av[1]);
AZ(VSS_parse(s->listen, &s->addr, &s->port));
av++;
continue;
diff -Naur ../varnish-2.0-rc1/bin/varnishtest/vtc_varnish.c bin/varnishtest/vtc_varnish.c
--- ../varnish-2.0-rc1/bin/varnishtest/vtc_varnish.c 2008-10-08 13:18:24.000000000 +0200
+++ bin/varnishtest/vtc_varnish.c 2008-10-09 13:49:16.000000000 +0200
@@ -23,7 +23,7 @@
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
- * $Id: vtc_varnish.c 3242 2008-10-01 08:27:59Z phk $
+ * $Id: vtc_varnish.c 3272 2008-10-09 11:39:24Z phk $
*/
@@ -131,21 +131,20 @@
*/
static struct varnish *
-varnish_new(char *name)
+varnish_new(const char *name)
{
struct varnish *v;
+ AN(name);
ALLOC_OBJ(v, VARNISH_MAGIC);
AN(v);
- v->name = name;
+ REPLACE(v->name, name);
v->vl = vtc_logopen(name);
AN(v->vl);
v->vl1 = vtc_logopen(name);
AN(v->vl1);
- if (*name != 'v') {
+ if (*v->name != 'v')
vtc_log(v->vl, 0, "Varnish name must start with 'v'");
- exit (1);
- }
v->args = "";
v->telnet = "127.0.0.1:9001";
@@ -156,6 +155,21 @@
}
/**********************************************************************
+ * Delete a varnish instance
+ */
+
+static void
+varnish_delete(struct varnish *v)
+{
+
+ CHECK_OBJ_NOTNULL(v, VARNISH_MAGIC);
+ vtc_logclose(v->vl);
+ free(v->name);
+ /* XXX: MEMLEAK */
+ FREE_OBJ(v);
+}
+
+/**********************************************************************
* Varnish listener
*/
@@ -418,8 +432,8 @@
*/
static void
-varnish_expect(struct varnish *v, char * const *av) {
- uint64_t val, ref;
+varnish_expect(const struct varnish *v, char * const *av) {
+ uint64_t val, ref;
int good;
char *p;
int i;
@@ -428,6 +442,7 @@
for (i = 0; i < 10; i++, usleep(100000)) {
+
#define MAC_STAT(n, t, f, d) \
if (!strcmp(av[0], #n)) { \
val = v->stats->n; \
@@ -435,6 +450,7 @@
#include "stat_field.h"
#undef MAC_STAT
{
+ val = 0;
vtc_log(v->vl, 0, "stats field %s unknown", av[0]);
}
@@ -472,6 +488,7 @@
(void)priv;
(void)cmd;
+ (void)vl;
if (av == NULL) {
/* Reset and free */
@@ -479,8 +496,7 @@
if (v->cli_fd >= 0)
varnish_wait(v);
VTAILQ_REMOVE(&varnishes, v, list);
- FREE_OBJ(v);
- /* XXX: MEMLEAK */
+ varnish_delete(v);
}
return;
}

28
varnish.vcl_changes.patch Normal file
View file

@ -0,0 +1,28 @@
diff -Naur ../varnish-2.0-beta1.orig/redhat/README.redhat ./redhat/README.redhat
--- ../varnish-2.0-beta1.orig/redhat/README.redhat 2008-08-27 09:45:40.000000000 +0200
+++ ./redhat/README.redhat 2008-09-02 16:14:43.000000000 +0200
@@ -5,6 +5,24 @@
Varnish should work fine with GCC 3.3 and above.
+Upgrading from 1.x to 2.0
+=========================
+There are a few changes in the vcl language from varnish-1.x to 2.0.
+Because of varnish' dynamic vcl loading feature, there is no way to
+guarantee that the vcl file in use actually exists on disk. Thus,
+there is no way to securely automate this process, and one must do the
+changes by hand.
+
+In vcl, the word "insert" has been replaced by "deliver".
+
+In the vcl declaration of backends, where one earlier used "set
+backend", backend parts are now just prefixed with a dot, so the
+default localhost configuration will look like this:
+
+backend default {
+ .host = "127.0.0.1";
+ .port = "80";
+}
Configuration of addresses and ports
====================================

View file

@ -1,11 +0,0 @@
--- bin/varnishtest/tests/r02429.vtc.orig 2017-11-16 11:08:04.718822949 +0100
+++ bin/varnishtest/tests/r02429.vtc 2017-11-16 11:08:12.411275341 +0100
@@ -4,7 +4,7 @@
accept
} -start
-varnish v1 -arg "-s Transient=file,${tmpdir}/_.file,1m" -vcl+backend {
+varnish v1 -arg "-s Transient=file,${tmpdir}/_.file,10m" -vcl+backend {
sub vcl_backend_error {
synthetic("foo");
return (deliver);