585267
## % define _use_internal_dependency_generator 0
585267
%define __perl_requires %{SOURCE98}
585267
## % define __find_requires %{SOURCE99}
585267
585267
Name:     squid
192ec7
Version:  3.5.20
cc499f
Release:  17%{?dist}.7
585267
Summary:  The Squid proxy caching server
585267
Epoch:    7
585267
# See CREDITS for breakdown of non GPLv2+ code
585267
License:  GPLv2+ and (LGPLv2+ and MIT and BSD and Public Domain)
585267
Group:    System Environment/Daemons
585267
URL:      http://www.squid-cache.org
192ec7
Source0:  http://www.squid-cache.org/Versions/v3/3.5/squid-%{version}.tar.xz
192ec7
Source1:  http://www.squid-cache.org/Versions/v3/3.5/squid-%{version}.tar.xz.asc
585267
Source2:  squid.init
585267
Source3:  squid.logrotate
585267
Source4:  squid.sysconfig
585267
Source5:  squid.pam
585267
Source6:  squid.nm
585267
Source7:  squid.service
585267
Source8:  cache_swap.sh
585267
Source98: perl-requires-squid.sh
192ec7
Source99: squid-migrate-conf.py
585267
585267
# Local patches
585267
# Applying upstream patches first makes it less likely that local patches
585267
# will break upstream ones.
585267
Patch201: squid-3.1.0.9-config.patch
585267
Patch202: squid-3.1.0.9-location.patch
585267
Patch203: squid-3.0.STABLE1-perlpath.patch
585267
Patch204: squid-3.2.0.9-fpic.patch
585267
Patch205: squid-3.1.9-ltdl.patch
d3a8ee
# https://bugzilla.redhat.com/show_bug.cgi?id=980511
192ec7
Patch206: squid-3.3.8-active-ftp-1.patch
192ec7
Patch207: squid-3.3.8-active-ftp-2.patch
192ec7
# https://bugzilla.redhat.com/show_bug.cgi?id=1265328#c23
192ec7
Patch208: squid-3.5.10-ssl-helper.patch
192ec7
# https://bugzilla.redhat.com/show_bug.cgi?id=1378025
192ec7
# http://bazaar.launchpad.net/~squid/squid/3.4/revision/12713
192ec7
Patch209: squid-3.5.20-conf-casecmp.patch
ba1db3
# http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2016_11.patch
ba1db3
Patch210: squid-CVE-2016-10002.patch
1e190c
# https://bugzilla.redhat.com/show_bug.cgi?id=1404817
1e190c
Patch211: squid-3.5.20-tunnel-sigsegv.patch
bb6014
# https://bugzilla.redhat.com/show_bug.cgi?id=1414853
bb6014
Patch212: squid-3.5.20-man-typos.patch
bb6014
# https://bugzilla.redhat.com/show_bug.cgi?id=1290404
bb6014
Patch213: squid-3.5.20-man-see-also.patch
fbf736
# https://bugzilla.redhat.com/show_bug.cgi?id=1620546
fbf736
Patch214: squid-3.5.20-empty-cname.patch
e6ac7e
# https://bugzilla.redhat.com/show_bug.cgi?id=1690551
e6ac7e
Patch215: squid-3.5.20-cache-peer-tolower.patch
e6ac7e
# https://bugzilla.redhat.com/show_bug.cgi?id=1680022
e6ac7e
Patch216: squid-3.5.20-https-packet-size.patch
e6ac7e
# https://bugzilla.redhat.com/show_bug.cgi?id=1717430
e6ac7e
Patch217: squid-3.5.20-mem-usage-out-of-fd.patch
e6ac7e
# https://bugzilla.redhat.com/show_bug.cgi?id=1676420
e6ac7e
Patch218: squid-3.5.20-cache-siblings-gw.patch
fbf736
585267
e6ac7e
# Security Fixes:
e6ac7e
e6ac7e
# https://bugzilla.redhat.com/show_bug.cgi?id=1727744
76e176
# Regression caused by original patch fixed -
76e176
# https://bugzilla.redhat.com/show_bug.cgi?id=1890581
e6ac7e
Patch500: squid-3.5.20-CVE-2019-13345.patch
e6ac7e
# https://bugzilla.redhat.com/show_bug.cgi?id=1582301
e6ac7e
Patch501: squid-3.5.20-CVE-2018-1000024.patch
e6ac7e
Patch502: squid-3.5.20-CVE-2018-1000027.patch
07d5a6
Patch503: squid-3.5.20-CVE-2019-12525.patch
712647
# https://bugzilla.redhat.com/show_bug.cgi?id=1828361
07d5a6
Patch504: squid-3.5.20-CVE-2020-11945.patch
712647
# https://bugzilla.redhat.com/show_bug.cgi?id=1828362
07d5a6
Patch505: squid-3.5.20-CVE-2019-12519.patch
07d5a6
# https://bugzilla.redhat.com/show_bug.cgi?id=1798540
07d5a6
# https://bugzilla.redhat.com/show_bug.cgi?id=1798552
07d5a6
Patch506: squid-3.5.20-CVE-2020-8449-and-8450.patch
07d5a6
# https://bugzilla.redhat.com/show_bug.cgi?id=1852550
07d5a6
Patch507: squid-3.5.20-CVE-2020-15049.patch
07d5a6
# https://bugzilla.redhat.com/show_bug.cgi?id=1802517
07d5a6
Patch508: squid-3.5.20-CVE-2019-12528.patch
07d5a6
# https://bugzilla.redhat.com/show_bug.cgi?id=1871705
07d5a6
Patch509: squid-3.5.20-CVE-2020-24606.patch
07d5a6
# https://bugzilla.redhat.com/show_bug.cgi?id=1871700
07d5a6
Patch510: squid-3.5.20-CVE-2020-15810.patch
07d5a6
# https://bugzilla.redhat.com/show_bug.cgi?id=1871702
07d5a6
Patch511: squid-3.5.20-CVE-2020-15811.patch
a7644e
# https://bugzilla.redhat.com/show_bug.cgi?id=1939925
a7644e
Patch512: squid-3.5.20-CVE-2020-25097.patch
cc499f
# https://bugzilla.redhat.com/show_bug.cgi?id=2100721
cc499f
Patch513: squid-3.5.20-CVE-2021-46784.patch
e6ac7e
585267
Buildroot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
585267
Requires: bash >= 2.0
192ec7
Requires: squid-migration-script
585267
Requires(pre): shadow-utils
585267
Requires(post): /sbin/chkconfig
585267
Requires(preun): /sbin/chkconfig
585267
Requires(post): systemd
585267
Requires(preun): systemd
585267
Requires(postun): systemd
585267
# squid_ldap_auth and other LDAP helpers require OpenLDAP
585267
BuildRequires: openldap-devel
585267
# squid_pam_auth requires PAM development libs
585267
BuildRequires: pam-devel
585267
# SSL support requires OpenSSL
585267
BuildRequires: openssl-devel
585267
# squid_kerb_aut requires Kerberos development libs
585267
BuildRequires: krb5-devel
585267
# ESI support requires Expat & libxml2
585267
BuildRequires: expat-devel libxml2-devel
585267
# TPROXY requires libcap, and also increases security somewhat
585267
BuildRequires: libcap-devel
585267
# eCAP support
192ec7
BuildRequires: libecap-devel >= 1.0.0
585267
# 
585267
BuildRequires: libtool libtool-ltdl-devel
585267
# For test suite
585267
BuildRequires: cppunit-devel
d3a8ee
# DB helper requires
d3a8ee
BuildRequires: perl-podlators libdb-devel
192ec7
# c++ source files
192ec7
BuildRequires: gcc-c++
585267
585267
%description
585267
Squid is a high-performance proxy caching server for Web clients,
585267
supporting FTP, gopher, and HTTP data objects. Unlike traditional
585267
caching software, Squid handles all requests in a single,
585267
non-blocking, I/O-driven process. Squid keeps meta data and especially
585267
hot objects cached in RAM, caches DNS lookups, supports non-blocking
585267
DNS lookups, and implements negative caching of failed requests.
585267
585267
Squid consists of a main server program squid, a Domain Name System
585267
lookup program (dnsserver), a program for retrieving FTP data
585267
(ftpget), and some management and client tools.
585267
585267
%package sysvinit
585267
Group: System Environment/Daemons
585267
Summary: SysV initscript for squid caching proxy
585267
Requires: %{name} = %{epoch}:%{version}-%{release}
585267
Requires(preun): /sbin/service
585267
Requires(postun): /sbin/service
585267
585267
%description sysvinit
585267
The squid-sysvinit contains SysV initscritps support.
585267
192ec7
%package migration-script
192ec7
Group: System Environment/Daemons
192ec7
Summary: Migration script for squid caching proxy
585267
192ec7
%description migration-script
192ec7
The squid-migration-script contains scripts for squid configuration
192ec7
migration and script which prepares squid for downgrade operation.
585267
192ec7
%prep
192ec7
%setup -q
585267
585267
# Local patches
585267
%patch201 -p1 -b .config
585267
%patch202 -p1 -b .location
585267
%patch203 -p1 -b .perlpath
585267
%patch204 -p1 -b .fpic
585267
%patch205 -p1 -b .ltdl
192ec7
%patch206 -p1 -b .active-ftp-1
192ec7
%patch207 -p1 -b .active-ftp-2
192ec7
%patch208 -p1 -b .ssl-helper
192ec7
%patch209 -p1 -b .conf-casecmp
ba1db3
%patch210 -p0 -b .CVE-2016-10002
1e190c
%patch211 -p1 -b .tunnel-sigsegv
bb6014
%patch212 -p1 -b .man-see-also
bb6014
%patch213 -p1 -b .man-typos
fbf736
%patch214 -p1 -b .empty-cname
e6ac7e
%patch215 -p1 -b .cache-peer-tolower
e6ac7e
%patch216 -p1 -b .https-packet-size
e6ac7e
%patch217 -p1 -b .mem-usage-out-of-fd
e6ac7e
%patch218 -p1 -b .cache-siblings-gw
e6ac7e
e6ac7e
# security fixes
e6ac7e
%patch500 -p1 -b .CVE-2019-13345
e6ac7e
%patch501 -p1 -b .CVE-2018-1000024
e6ac7e
%patch502 -p1 -b .CVE-2018-1000027
07d5a6
%patch503 -p1 -b .CVE-2019-12525
07d5a6
%patch504 -p1 -b .CVE-2020-11945
07d5a6
%patch505 -p1 -b .CVE-2019-12519
07d5a6
%patch506 -p1 -b .CVE-2020-8449-and-8450
07d5a6
%patch507 -p1 -b .CVE-2020-15049
07d5a6
%patch508 -p1 -b .CVE-2019-12528
07d5a6
%patch509 -p1 -b .CVE-2020-24606
07d5a6
%patch510 -p1 -b .CVE-2020-15810
07d5a6
%patch511 -p1 -b .CVE-2020-15811
a7644e
%patch512 -p1 -b .CVE-2020-25097
cc499f
%patch513 -p1 -b .CVE-2021-46784
585267
bcb844
# https://bugzilla.redhat.com/show_bug.cgi?id=1471140
bcb844
# Patch in the vendor documentation and used different location for documentation
bcb844
sed -i 's|@SYSCONFDIR@/squid.conf.documented|%{_docdir}/squid-%{version}/squid.conf.documented|' src/squid.8.in
bcb844
585267
%build
585267
%ifarch sparcv9 sparc64 s390 s390x
585267
   CXXFLAGS="$RPM_OPT_FLAGS -fPIE" \
585267
   CFLAGS="$RPM_OPT_FLAGS -fPIE" \
585267
%else
585267
   CXXFLAGS="$RPM_OPT_FLAGS -fpie" \
585267
   CFLAGS="$RPM_OPT_FLAGS -fpie" \
585267
%endif
585267
LDFLAGS="$RPM_LD_FLAGS -pie -Wl,-z,relro -Wl,-z,now"
585267
585267
%configure \
585267
   --disable-strict-error-checking \
585267
   --exec_prefix=/usr \
585267
   --libexecdir=%{_libdir}/squid \
c63618
   --localstatedir=%{_var} \
585267
   --datadir=%{_datadir}/squid \
585267
   --sysconfdir=%{_sysconfdir}/squid \
585267
   --with-logdir='$(localstatedir)/log/squid' \
585267
   --with-pidfile='$(localstatedir)/run/squid.pid' \
585267
   --disable-dependency-tracking \
585267
   --enable-eui \
585267
   --enable-follow-x-forwarded-for \
585267
   --enable-auth \
192ec7
   --enable-auth-basic="DB,LDAP,MSNT-multi-domain,NCSA,NIS,PAM,POP3,RADIUS,SASL,SMB,SMB_LM,getpwnam" \
585267
   --enable-auth-ntlm="smb_lm,fake" \
585267
   --enable-auth-digest="file,LDAP,eDirectory" \
585267
   --enable-auth-negotiate="kerberos" \
bcb844
   --enable-external-acl-helpers="file_userip,LDAP_group,time_quota,session,unix_group,wbinfo_group,kerberos_ldap_group" \
585267
   --enable-cache-digests \
585267
   --enable-cachemgr-hostname=localhost \
585267
   --enable-delay-pools \
585267
   --enable-epoll \
585267
   --enable-ident-lookups \
d3a8ee
   %ifnarch ppc64 ia64 x86_64 s390x aarch64
585267
   --with-large-files \
585267
   %endif
585267
   --enable-linux-netfilter \
585267
   --enable-removal-policies="heap,lru" \
585267
   --enable-snmp \
585267
   --enable-ssl-crtd \
bb6014
   --enable-storeio="aufs,diskd,rock,ufs" \
585267
   --enable-wccpv2 \
585267
   --enable-esi \
585267
   --enable-ecap \
585267
   --with-aio \
585267
   --with-default-user="squid" \
585267
   --with-dl \
585267
   --with-openssl \
192ec7
   --with-pthreads \
e3a218
   --disable-arch-native
585267
585267
make \
585267
	DEFAULT_SWAP_DIR='$(localstatedir)/spool/squid' \
585267
	%{?_smp_mflags}
585267
585267
%check
585267
make check
192ec7
585267
%install
585267
rm -rf $RPM_BUILD_ROOT
585267
make \
585267
	DESTDIR=$RPM_BUILD_ROOT \
585267
	install
585267
echo "
585267
#
585267
# This is %{_sysconfdir}/httpd/conf.d/squid.conf
585267
#
585267
585267
ScriptAlias /Squid/cgi-bin/cachemgr.cgi %{_libdir}/squid/cachemgr.cgi
585267
585267
# Only allow access from localhost by default
585267
<Location /Squid/cgi-bin/cachemgr.cgi>
585267
 Require local
585267
 # Add additional allowed hosts as needed
585267
 # Require host example.com
585267
</Location>" > $RPM_BUILD_ROOT/squid.httpd.tmp
585267
585267
585267
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/rc.d/init.d
585267
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d
585267
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/sysconfig
585267
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/pam.d
585267
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/httpd/conf.d/
585267
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/NetworkManager/dispatcher.d
585267
mkdir -p $RPM_BUILD_ROOT%{_unitdir}
585267
mkdir -p $RPM_BUILD_ROOT%{_libexecdir}/squid
c63618
mkdir -p $RPM_BUILD_ROOT%{_prefix}/lib/firewalld/services
c63618
585267
install -m 755 %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/rc.d/init.d/squid
585267
install -m 644 %{SOURCE3} $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/squid
585267
install -m 644 %{SOURCE4} $RPM_BUILD_ROOT%{_sysconfdir}/sysconfig/squid
585267
install -m 644 %{SOURCE5} $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/squid
585267
install -m 644 %{SOURCE7} $RPM_BUILD_ROOT%{_unitdir}
585267
install -m 755 %{SOURCE8} $RPM_BUILD_ROOT%{_libexecdir}/squid
585267
install -m 644 $RPM_BUILD_ROOT/squid.httpd.tmp $RPM_BUILD_ROOT%{_sysconfdir}/httpd/conf.d/squid.conf
585267
install -m 644 %{SOURCE6} $RPM_BUILD_ROOT%{_sysconfdir}/NetworkManager/dispatcher.d/20-squid
c63618
mkdir -p $RPM_BUILD_ROOT%{_var}/log/squid
c63618
mkdir -p $RPM_BUILD_ROOT%{_var}/spool/squid
c63618
mkdir -p $RPM_BUILD_ROOT%{_var}/run/squid
585267
chmod 644 contrib/url-normalizer.pl contrib/rredir.* contrib/user-agents.pl
585267
iconv -f ISO88591 -t UTF8 ChangeLog -o ChangeLog.tmp
585267
mv -f ChangeLog.tmp ChangeLog
585267
c63618
# install /usr/lib/tmpfiles.d/squid.conf
c63618
mkdir -p ${RPM_BUILD_ROOT}%{_tmpfilesdir}
c63618
cat > ${RPM_BUILD_ROOT}%{_tmpfilesdir}/squid.conf <
c63618
# See tmpfiles.d(5) for details
c63618
c63618
d /run/squid 0755 squid squid - -
c63618
EOF
c63618
585267
# Move the MIB definition to the proper place (and name)
585267
mkdir -p $RPM_BUILD_ROOT/usr/share/snmp/mibs
585267
mv $RPM_BUILD_ROOT/usr/share/squid/mib.txt $RPM_BUILD_ROOT/usr/share/snmp/mibs/SQUID-MIB.txt
585267
585267
# squid.conf.documented is documentation. We ship that in doc/
585267
rm -f $RPM_BUILD_ROOT%{_sysconfdir}/squid/squid.conf.documented
585267
585267
# remove unpackaged files from the buildroot
585267
rm -f $RPM_BUILD_ROOT%{_bindir}/{RunAccel,RunCache}
585267
rm -f $RPM_BUILD_ROOT/squid.httpd.tmp
585267
192ec7
# bug #447156
192ec7
# /usr/share/squid/errors/zh-cn and /usr/share/squid/errors/zh-tw were
192ec7
# substituted directories substituted by symlinks and RPM, can't handle
192ec7
# this change
192ec7
rm -f $RPM_BUILD_ROOT%{_prefix}/share/squid/errors/zh-tw
192ec7
rm -f $RPM_BUILD_ROOT%{_prefix}/share/squid/errors/zh-cn
192ec7
cp -R --preserve=all $RPM_BUILD_ROOT%{_prefix}/share/squid/errors/zh-hant $RPM_BUILD_ROOT%{_prefix}/share/squid/errors/zh-tw
192ec7
cp -R --preserve=all $RPM_BUILD_ROOT%{_prefix}/share/squid/errors/zh-hans $RPM_BUILD_ROOT%{_prefix}/share/squid/errors/zh-cn
192ec7
192ec7
# squid-migration-script
192ec7
mkdir -p $RPM_BUILD_ROOT%{_libexecdir}/squid
192ec7
install -m 755 %{SOURCE99} $RPM_BUILD_ROOT%{_bindir}
192ec7
585267
%clean
585267
rm -rf $RPM_BUILD_ROOT
585267
585267
%files
585267
%defattr(-,root,root,-)
192ec7
%doc COPYING README ChangeLog QUICKSTART src/squid.conf.documented
585267
%doc contrib/url-normalizer.pl contrib/rredir.* contrib/user-agents.pl
585267
585267
%{_unitdir}/squid.service
585267
%attr(755,root,root) %dir %{_libexecdir}/squid
585267
%attr(755,root,root) %{_libexecdir}/squid/cache_swap.sh
585267
%attr(755,root,root) %dir %{_sysconfdir}/squid
585267
%attr(755,root,root) %dir %{_libdir}/squid
c63618
%attr(750,squid,squid) %dir %{_var}/log/squid
c63618
%attr(750,squid,squid) %dir %{_var}/spool/squid
c63618
%attr(755,squid,squid) %dir %{_var}/run/squid
585267
585267
%config(noreplace) %attr(644,root,root) %{_sysconfdir}/httpd/conf.d/squid.conf
585267
%config(noreplace) %attr(640,root,squid) %{_sysconfdir}/squid/squid.conf
585267
%config(noreplace) %attr(644,root,squid) %{_sysconfdir}/squid/cachemgr.conf
585267
%config(noreplace) %{_sysconfdir}/squid/mime.conf
585267
%config(noreplace) %{_sysconfdir}/squid/errorpage.css
585267
%config(noreplace) %{_sysconfdir}/sysconfig/squid
c63618
585267
# These are not noreplace because they are just sample config files
585267
%config %{_sysconfdir}/squid/squid.conf.default
585267
%config %{_sysconfdir}/squid/mime.conf.default
585267
%config %{_sysconfdir}/squid/errorpage.css.default
585267
%config %{_sysconfdir}/squid/cachemgr.conf.default
585267
%config(noreplace) %{_sysconfdir}/pam.d/squid
585267
%config(noreplace) %{_sysconfdir}/logrotate.d/squid
585267
585267
%dir %{_datadir}/squid
585267
%attr(-,root,root) %{_datadir}/squid/errors
585267
%attr(755,root,root) %{_sysconfdir}/NetworkManager/dispatcher.d/20-squid
585267
%{_datadir}/squid/icons
585267
%{_sbindir}/squid
585267
%{_bindir}/squidclient
585267
%{_bindir}/purge
585267
%{_mandir}/man8/*
585267
%{_mandir}/man1/*
585267
%{_libdir}/squid/*
585267
%{_datadir}/snmp/mibs/SQUID-MIB.txt
c63618
%{_tmpfilesdir}/squid.conf
585267
585267
%files sysvinit
585267
%attr(755,root,root) %{_sysconfdir}/rc.d/init.d/squid
585267
192ec7
%files migration-script
192ec7
%defattr(-,root,root,-)
192ec7
%attr(755,root,root) %{_bindir}/squid-migrate-conf.py*
192ec7
585267
%pre
585267
if ! getent group squid >/dev/null 2>&1; then
585267
  /usr/sbin/groupadd -g 23 squid
585267
fi
585267
585267
if ! getent passwd squid >/dev/null 2>&1 ; then
585267
  /usr/sbin/useradd -g 23 -u 23 -d /var/spool/squid -r -s /sbin/nologin squid >/dev/null 2>&1 || exit 1 
585267
fi
585267
585267
for i in /var/log/squid /var/spool/squid ; do
585267
        if [ -d $i ] ; then
585267
                for adir in `find $i -maxdepth 0 \! -user squid`; do
585267
                        chown -R squid:squid $adir
585267
                done
585267
        fi
585267
done
585267
585267
exit 0
585267
585267
%post
192ec7
/usr/bin/squid-migrate-conf.py --write-changes --conf %{_sysconfdir}/squid/squid.conf &>/dev/null
585267
%systemd_post squid.service
585267
585267
%preun
585267
%systemd_preun squid.service
585267
585267
%postun
585267
%systemd_postun_with_restart squid.service
585267
585267
%triggerin -- samba-common
585267
if ! getent group wbpriv >/dev/null 2>&1 ; then
585267
  /usr/sbin/groupadd -g 88 wbpriv >/dev/null 2>&1 || :
585267
fi
585267
/usr/sbin/usermod -a -G wbpriv squid >/dev/null 2>&1 || \
585267
    chgrp squid /var/cache/samba/winbindd_privileged >/dev/null 2>&1 || :
585267
585267
%changelog
cc499f
* Tue Jun 28 2022 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7
cc499f
- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
cc499f
  responses
cc499f
a7644e
* Wed Mar 31 2021 Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6
a7644e
- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
a7644e
  a trusted client to perform HTTP Request Smuggling
a7644e
76e176
* Mon Oct 26 2020 Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5
76e176
- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
76e176
  cachemgr.cgi
76e176
07d5a6
* Fri Aug 28 2020 Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4
07d5a6
- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
07d5a6
  result in a DoS
07d5a6
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
07d5a6
  result in cache poisoning
07d5a6
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
07d5a6
  result in cache poisoning
07d5a6
07d5a6
* Fri Jul 31 2020 Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2
07d5a6
- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
07d5a6
  in HTTP Request processing
07d5a6
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
07d5a6
  as reverse-proxy
07d5a6
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
07d5a6
  attack against the HTTP cache
07d5a6
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
07d5a6
  FTP Gateway
07d5a6
07d5a6
* Tue Apr 28 2020 Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17
07d5a6
- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
712647
  Digest Authentication nonce replay could lead to remote code execution
07d5a6
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
07d5a6
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
07d5a6
07d5a6
* Fri Mar 27 2020 Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16
07d5a6
- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
712647
  Proxy-Authentication leads to memory corruption
712647
e6ac7e
* Thu Jul 25 2019 Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15
e6ac7e
- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
e6ac7e
  case
e6ac7e
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
e6ac7e
  sites
e6ac7e
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
e6ac7e
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
e6ac7e
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
e6ac7e
  in cachemgr.cgi
e6ac7e
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flaws
e6ac7e
e6ac7e
* Thu Dec 06 2018 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13
e6ac7e
- Resolves: #1620546 - migration of upstream squid
fbf736
bcb844
* Mon Oct 02 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12
bcb844
- Resolves: #1471140 - Missing detailed configuration file
bcb844
bcb844
* Mon Oct 02 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11
bcb844
- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
bcb844
bb6014
* Tue Apr 25 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-10
bb6014
- Resolves: #1445219 - [RFE] Add rock cache directive to squid
bb6014
bb6014
* Thu Mar 23 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-9
bb6014
- Resolves: #1290404 - wrong names of components in man page, section SEE ALSO
bb6014
bb6014
* Thu Mar 23 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-8
bb6014
- Resolves: #1414853 - typo error(s) in man page(s)
bb6014
bb6014
* Mon Mar 20 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-7
bb6014
- Related: #1347096 - squid: ERROR: No running copy
bb6014
bb6014
* Mon Mar 20 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-6
bb6014
- Resolves: #1347096 - squid: ERROR: No running copy
bb6014
bb6014
* Thu Mar 02 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-5
bb6014
- Resolves: #1404817 - SIGSEV in TunnelStateData::handleConnectResponse()
1e190c
  during squid reconfigure and restart
1e190c
bb6014
* Fri Jan 13 2017 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-4
bb6014
- Resolves: #1412736 - CVE-2016-10002 squid: Information disclosure in HTTP
ba1db3
  request processing
ba1db3
bb6014
* Thu Dec 15 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-3
bb6014
- Resolves: #1404894 - icap support has been disabled on squid 3.5.20-2.el7
e3a218
192ec7
* Wed Sep 21 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-2
192ec7
- Resolves: #1378025 - host_verify_strict only accepts lowercase arguments
192ec7
192ec7
* Tue Aug 09 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-1
192ec7
- Resolves: #1273942 - Rebase squid to latest mature 3.5 version (3.5.20)
192ec7
192ec7
* Mon Aug 08 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-9
192ec7
- Related: #1349775 - Provide migration tools needed due to rebase
192ec7
  to squid 3.5 as a separate sub-package
192ec7
192ec7
* Mon Aug 01 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-8
192ec7
- Related: #1349775 - Provide migration tools needed due to rebase
192ec7
  to squid 3.5 as a separate sub-package
192ec7
192ec7
* Mon Aug 01 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-7
192ec7
- Related: #1349775 - Provide migration tools needed due to rebase
192ec7
  to squid 3.5 as a separate sub-package
192ec7
192ec7
* Wed Jul 27 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-6
192ec7
- Related: #1349775 - Provide migration tools needed due to rebase
192ec7
  to squid 3.5 as a separate sub-package
192ec7
192ec7
* Tue Jul 26 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-5
192ec7
- Related: #1349775 - Provide migration tools needed due to rebase
192ec7
  to squid 3.5 as a separate sub-package
192ec7
192ec7
* Tue Jul 19 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-4
192ec7
- Resolves: #1349775 - Provide migration tools needed due to rebase
192ec7
  to squid 3.5 as a separate sub-package
192ec7
192ec7
* Tue Jun 14 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-3
192ec7
- Resolves: #1330186 - digest doesn't properly work with squid 3.3 on CentOS 7
192ec7
192ec7
* Tue Jun 14 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-2
192ec7
- Resolves: #1336387 - Squid send wrong respond for GET-request following
192ec7
  Range-GET request
192ec7
192ec7
* Wed Jun 08 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.10-1
192ec7
- Resolves: #1273942 - Rebase squid to latest mature 3.5 version (3.5.10)
192ec7
- Resolves: #1322770 - CVE-2016-2569 CVE-2016-2570 CVE-2016-2571 CVE-2016-2572
192ec7
  CVE-2016-3948 squid: various flaws
192ec7
- Resolves: #1254016 - IPv4 fallback is not working when connecting
192ec7
  to a dualstack host with non-functional IPv6
192ec7
- Resolves: #1254018 - should BuildRequire: g++
192ec7
- Resolves: #1262456 - Squid delays on FQDNs that don't contains AAAA record
192ec7
- Resolves: #1336940 - Disable squid systemd unit start/stop timeouts
192ec7
- Resolves: #1344197 - /usr/lib/firewalld/services/squid.xml conflicts between
192ec7
  attempted installs of squid-7:3.3.8-31.el7.x86_64 and
192ec7
  firewalld-0.4.2-1.el7.noarch
192ec7
- Resolves: #1299972 - squid file descriptor limit hardcoded to 16384 via 
192ec7
  compile option in spec file
192ec7
192ec7
* Wed Jun 08 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-31
192ec7
- Resolves: #1283078 - max_filedescriptors in squid.conf is ignored
192ec7
192ec7
* Mon May 09 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-30
192ec7
- Related: #1334509 - CVE-2016-4553 squid: Cache poisoning issue in
4056b0
  HTTP Request handling
192ec7
- Related: #1334492 - CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 
4056b0
  squid: various flaws
4056b0
192ec7
* Tue May 03 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-29
192ec7
- Related: #1330577 - CVE-2016-4052 CVE-2016-4053 CVE-2016-4054 squid: multiple
192ec7
  issues in ESI processing
4056b0
192ec7
* Thu Apr 28 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-28
192ec7
- Related: #1330577 - CVE-2016-4052 CVE-2016-4053 CVE-2016-4054 squid: multiple
192ec7
  issues in ESI processing
192ec7
192ec7
* Thu Apr 28 2016 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-27
192ec7
- Resolves: #1330577 - CVE-2016-4051 squid: buffer overflow in cachemgr.cgi
4056b0
c63618
* Wed Oct 14 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-26
c63618
- Related: #1186768 - removing patch, because of missing tests and 
c63618
  incorrent patch
c63618
c63618
* Tue Oct 13 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-25
c63618
- Related: #1102842 - squid rpm package misses /var/run/squid needed for
c63618
  smp mode. Squid needs write access to /var/run/squid.
c63618
c63618
* Fri Oct 09 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-24
c63618
- Related: #1102842 - squid rpm package misses /var/run/squid needed for
c63618
  smp mode. Creation of /var/run/squid was also needed to be in SPEC file.
c63618
c63618
* Tue Oct 06 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-23
c63618
- Related: #1102842 - squid rpm package misses /var/run/squid needed for
c63618
  smp mode. Creation of this directory was moved to tmpfiles.d conf file.
c63618
c63618
* Fri Oct 02 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-22
c63618
- Related: #1102842 - squid rpm package misses /var/run/squid needed for
c63618
  smp mode. Creation of this directory was moved to service file.
c63618
c63618
* Tue Sep 22 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-21
c63618
- Resolves: #1263338 - squid with digest auth on big endian systems 
c63618
  start looping
c63618
c63618
* Mon Aug 10 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-20
c63618
- Resolves: #1186768 - security issue: Nonce replay vulnerability 
c63618
  in Digest authentication
c63618
c63618
* Tue Jul 14 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-19
c63618
- Resolves: #1225640 - squid crashes by segfault when it reboots
c63618
c63618
* Thu Jun 25 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-18
c63618
- Resolves: #1102842 - squid rpm package misses /var/run/squid needed for 
c63618
  smp mode
c63618
c63618
* Wed Jun 24 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-17
c63618
- Resolves: #1233265 - CVE-2015-3455 squid: incorrect X509 server
c63618
  certificate validation
c63618
c63618
* Fri Jun 19 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-16
c63618
- Resolves: #1080042 - Supply a firewalld service file with squid
c63618
c63618
* Wed Jun 17 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-15
c63618
- Resolves: #1161600 - Squid does not serve cached responses 
c63618
  with Vary headers
c63618
c63618
* Wed Jun 17 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-14
c63618
- Resolves: #1198778 - Filedescriptor leaks on snmp
c63618
c63618
* Wed Jun 17 2015 Luboš Uhliarik <luhliari@redhat.com> - 7:3.3.8-13
c63618
- Resolves: #1204375 - squid sends incorrect ssl chain breaking newer gnutls 
c63618
  using applications
c63618
6dd3ac
* Fri Aug 29 2014 Michal Luscon <mluscon@redhat.com> - 7:3.3.8-12
c63618
- Resolves: #1134934 - CVE-2014-3609 assertion failure in header processing
6dd3ac
d3a8ee
* Mon Mar 17 2014 Pavel Å imerda <psimerda@redhat.com> - 7:3.3.8-11
d3a8ee
- Resolves: #1074873 - CVE-2014-0128 squid: denial of service when using
d3a8ee
  SSL-Bump
d3a8ee
d3a8ee
* Wed Mar 05 2014 Pavel Å imerda <psimerda@redhat.com>' - 7:3.3.8-10
d3a8ee
- Resolves: #1072973 - don't depend on libdb4
d3a8ee
d3a8ee
* Tue Feb 11 2014 Pavel Å imerda <psimerda@redhat.com> - 7:3.3.8-9
d3a8ee
- revert: Resolves: #1038160 - avoid running squid's own supervisor process
d3a8ee
d3a8ee
* Tue Feb 11 2014 Pavel Å imerda <psimerda@redhat.com> - 7:3.3.8-8
d3a8ee
- Resolves: #1063248 - missing helpers
d3a8ee
d3a8ee
* Fri Jan 24 2014 Daniel Mach <dmach@redhat.com> - 7:3.3.8-7
d3a8ee
- Mass rebuild 2014-01-24
d3a8ee
d3a8ee
* Thu Jan 02 2014 Pavel Å imerda <psimerda@redhat.com> - 7:3.3.8-6
d3a8ee
- Resolves: #980511 - squid doesn't work with active FTP
d3a8ee
d3a8ee
* Fri Dec 27 2013 Daniel Mach <dmach@redhat.com> - 7:3.3.8-5
d3a8ee
- Mass rebuild 2013-12-27
d3a8ee
d3a8ee
* Tue Dec 10 2013 Pavel Å imerda <psimerda@redhat.com> - 7:3.3.8-4
d3a8ee
- Resolves: #1038160 - avoid running squid's own supervisor process
d3a8ee
d3a8ee
* Thu Nov 21 2013 Pavel Å imerda <psimerda@redhat.com> - 7:3.3.8-3
d3a8ee
- Resolves: #1028588 - fix build on aarch64
d3a8ee
585267
* Tue Aug 27 2013 Michal Luscon <mluscon@redhat.com> - 7:3.3.8-2
585267
- Fixed: source code url
585267
585267
* Thu Jul 25 2013 Michal Luscon <mluscon@redhat.com> - 7:3.3.8-1
585267
- Update to latest upstream version 3.3.8
585267
- Fixed: active ftp crashing
585267
- Fix basic auth and log daemon DB helper builds.
585267
- Use xz compressed tarball, fix source URLs.
585267
- Fix bogus dates in %%changelog.
585267
585267
* Fri May 3 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.11-1
585267
- Update to latest upstream version 3.2.11
585267
585267
* Tue Apr 23 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.9-3
585267
- Option '-k' is not stated in squidclient man
585267
- Remove pid from service file(#913262)
585267
585267
* Fri Apr 19 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.9-2
585267
- Enable full RELRO (-Wl,-z,relro -Wl,-z,now)
585267
585267
* Tue Mar 19 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.9-1
585267
- Update to latest upstream version 3.2.9
585267
- Fixed: CVE-2013-1839
585267
- Removed: makefile-patch (+make check)
585267
585267
* Mon Mar 11 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.8-3
585267
- Resolved: /usr move - squid service file
585267
585267
* Sat Mar 09 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.8-2
585267
- Resolved: #896127 - basic_ncsa_auth does not work
585267
585267
* Fri Mar 08 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.8-1
585267
- Update to latest upstream version 3.2.8
585267
- Fixed rawhide build issues (-make check)
585267
585267
* Thu Feb 07 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.7-1
585267
- Update to latest upstream version 3.2.7
585267
585267
* Thu Jan 24 2013 Michal Luscon <mluscon@redhat.com> - 7:3.2.5-2
585267
- CVE-2013-0189: Incomplete fix for the CVE-2012-5643
585267
585267
* Mon Dec 17 2012 Michal Luscon <mluscon@redhat.com> - 7:3.2.5-1
585267
- Update to latest upstream version 3.2.5
585267
585267
* Mon Nov 05 2012 Michal Luscon <mluscon@redhat.com> - 7:3.2.3-3
585267
- Resolved: #71483 - httpd 2.4 requires new configuration directives
585267
585267
* Fri Oct 26 2012 Michal Luscon <mluscon@redhat.com> - 7:3.2.3-2
585267
- Resolved: #854356 - squid.service use PIDFile
585267
- Resolved: #859393 - Improve cache_swap script
585267
- Resolved: #791129 - disk space warning
585267
- Resolved: #862252 - reload on VPN or network up/down
585267
- Resolved: #867531 - run test suite during build
585267
- Resolved: #832684 - missing after dependency nss-lookup.target
585267
- Removed obsolete configure options
585267
585267
* Mon Oct 22 2012 Tomas Hozza <thozza@redhat.com> - 7:3.2.3-1
585267
- Update to latest upstream version 3.2.3
585267
585267
* Tue Oct 16 2012 Tomas Hozza <thozza@redhat.com> - 7:3.2.2-1
585267
- Update to latest upstream version 3.2.2
585267
585267
* Fri Oct 05 2012 Tomas Hozza <thozza@redhat.com> - 7:3.2.1-2
585267
- Introduced new systemd-rpm macros in squid spec file. (#850326)
585267
585267
* Wed Aug 29 2012 Michal Luscon <mluscon@redhat.com> - 7:3.2.1-1
585267
- Update to latest upstream 3.2.1
585267
585267
* Sat Jul 21 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 7:3.2.0.16-3
585267
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
585267
585267
* Mon Apr 02 2012 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.2.0.16-2
585267
- Enable SSL CRTD for ssl bump
585267
585267
* Wed Mar 07 2012 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.2.0.16-1
585267
- Upstream 3.2.0.16 bugfix release
585267
585267
* Tue Feb 28 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 7:3.2.0.15-2
585267
- Rebuilt for c++ ABI breakage
585267
585267
* Mon Feb 06 2012 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.2.0.15-1
585267
- Upstream 3.2.0.15 bugfix release
585267
585267
* Wed Feb 01 2012 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.2.0.14-7
585267
- update with upstreamed patch versions
585267
585267
* Tue Jan 17 2012 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.2.0.14-6
585267
- upstream gcc-4.7 patch
585267
- fix for bug #772483 running out of memory, mem_node growing out of bounds
585267
585267
* Mon Jan 16 2012 Jiri Skala <jskala@redhat.com> - 7:3.2.0.14-5
585267
- fixes FTBFS due to gcc-4.7
585267
585267
* Fri Jan 13 2012 Jiri Skala <jskala@redhat.com> - 7:3.2.0.14-4
585267
- fixes #772481 - Low number of open files for squid process
585267
- fixes FTBFS due to gcc4.7
585267
585267
* Thu Jan 05 2012 Henrik Nordstrom <henrik@henriknordstrom.net> - 3.2.0.14-3
585267
- rebuild for gcc-4.7.0
585267
585267
* Mon Dec 19 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.14-2
585267
- fixes #768586 - Please enable eCAP support again
585267
585267
* Wed Dec 14 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.14-1
585267
- update to latest upstream 3.2.0.14
585267
585267
* Mon Nov 07 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.13-5
585267
- fixes #751679 - host_strict_verify setting inverted in squid.conf
585267
585267
* Thu Nov 03 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.13-4
585267
- fixes #750550 - Squid might depend on named
585267
585267
* Wed Oct 26 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.13-3
585267
- added upstream fix for #747125
585267
585267
* Wed Oct 26 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.13-2
585267
- fixes #747103 - squid does not start if /var/spool/squid is empty
585267
- fixes #747110 - squid does not start adding "memory_pools off"
585267
585267
* Mon Oct 17 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.13-1
585267
- update to latest upstream 3.2.0.13
585267
585267
* Tue Sep 20 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.12-1
585267
- update to latest upstream 3.2.0.12
585267
585267
* Mon Aug 29 2011 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.2.0.11-3
585267
- update to latest upstream 3.2.0.11
585267
585267
* Sat Aug 27 2011 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.2.0.10-3
585267
- Fix for SQUID-2011:3 Gopher vulnerability
585267
585267
* Thu Aug 18 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.10-2
585267
- rebuild for rpm
585267
585267
* Mon Aug 01 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.10-1
585267
- update to latest upsteam 3.2.0.10
585267
585267
* Mon Aug 01 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.9-2
585267
- rebuild for libcap
585267
585267
* Tue Jun 07 2011 Jiri Skala <jskala@redhat.com> - 7:3.2.0.9-1
585267
- upgrade to squid-3.2
585267
- fixes #720445 - Provide native systemd unit file
585267
- SysV initscript moved to subpackage
585267
- temproary disabled eCap
585267
585267
* Wed May 18 2011 Jiri Skala <jskala@redhat.com> - 7:3.1.12-3
585267
- enabled eCAP support
585267
585267
* Wed May 04 2011 Jiri Skala <jskala@redhat.com> - 7:3.1.12-2
585267
- applied corrections of unused patch (Ismail Dönmez)
585267
585267
* Fri Apr 15 2011 Jiri Skala <jskala@redhat.com> - 7:3.1.12-1
585267
- Update to 3.1.12 upstream release
585267
585267
* Thu Feb 10 2011 Jiri Skala <jskala@redhat.com> - 7:3.1.11-1
585267
- Update to 3.1.11 upstream release
585267
- fixes issue with unused variale after mass rebuild (gcc-4.6)
585267
585267
* Wed Feb 09 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 7:3.1.10-2
585267
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
585267
585267
* Thu Jan 06 2011 Jiri Skala <jskala@redhat.com> - 7:3.1.10-1
585267
- Update to 3.1.10 upstream release
585267
585267
* Fri Nov 05 2010 Jiri Skala <jskala@redhat.com> - 7:3.1.9-5
585267
- rebuild for libxml2
585267
585267
* Mon Nov 01 2010 Jiri Skala <jskala@redhat.com> - 7:3.1.9-4
585267
- fixes #647967 - build with -fPIE option back and dropped proper libltdl usage
585267
585267
* Sat Oct 30 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.9-3
585267
- Bug #647967 - License clarification & spec-file cleanup
585267
585267
* Mon Oct 25 2010 Henrik Nordstrom <henrik@henriknordstrom.net> 7:3.1.9-2
585267
- Upstream 3.1.9 bugfix release
585267
585267
* Wed Oct 13 2010 Jiri Skala <jskala@redhat.com> - 7:3.1.8-2
585267
- fixes #584161 - squid userid not added to wbpriv group
585267
585267
* Sun Sep 05 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.8-1
585267
- Bug #630445: SQUID-2010:3 Denial of service issue
585267
585267
* Tue Aug 24 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.7-1
585267
- Upstream 3.1.7 bugfix release
585267
585267
* Fri Aug 20 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.6-1
585267
- Upstream 3.1.6 bugfix release
585267
- Build with system libtool-ltdl
585267
585267
* Thu Jul 15 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.5-2
585267
- Upstream 3.1.5 bugfix release
585267
- Upstream patch for Bug #614665: Squid crashes with  ident auth
585267
- Upstream patches for various memory leaks
585267
585267
* Mon May 31 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.4-2
585267
- Correct case-insensitiveness in HTTP list header parsing
585267
585267
* Sun May 30 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.4-1
585267
- Upstream 3.1.4 bugfix release, issues relating to IPv6, TPROXY, Memory
585267
  management, follow_x_forwarded_for, and stability fixes
585267
585267
* Fri May 14 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.3-2
585267
- Fully fix #548903 - "comm_open: socket failure: (97) Address family not supported by protocol" if IPv6 disabled
585267
- Various IPv6 related issues fixed, making tcp_outgoing_address behave
585267
  as expected and no commResetFD warnings when using tproxy setups.
585267
585267
* Sun May 02 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.3-1
585267
- Update to 3.1.3 Upstream bugfix release, fixing WCCPv1
585267
585267
* Mon Apr 19 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.1-4
585267
- Bug #583489: Adjust logrotate script to changes in logrotate package.
585267
585267
* Mon Apr 19 2010 Jiri Skala <jskala@redhat.com>
585267
- fixes #548903 - "comm_open: socket failure: (97) Address family not supported by protocol" if IPv6 disabled
585267
585267
* Tue Mar 30 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.1-2
585267
- Update to 3.1.1 Squid bug #2827 crash with assertion failed:
585267
  FilledChecklist.cc:90: "conn() != NULL" under high load.
585267
585267
* Mon Mar 15 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.18-1
585267
- Upgrade to 3.1.0.18 fixing Digest authentication and improved HTTP/1.1 support
585267
585267
* Sun Feb 28 2010 Henrik Nordstrom <henrik@henriknordstrom.net> -  7:3.1.0.17-3
585267
- Bug 569120, fails to open unbound ipv4 listening sockets
585267
585267
* Thu Feb 25 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.17-2
585267
- Upgrade to 3.1.0.17
585267
585267
* Thu Feb 18 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.16-7
585267
- Workaround for Fedora-13 build failure
585267
585267
* Sun Feb 14 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.16-6
585267
- Patch for Squid security advisory SQUID-2010:2, denial of service
585267
  issue in HTCP processing (CVE-2010-0639)
585267
585267
* Sun Feb 07 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.16-5
585267
- Rebuild 3.1.0.16 with corrected upstream release.
585267
585267
* Wed Feb 03 2010 Jiri Skala <jskala@redhat.com> - 7:3.1.0.16-4
585267
- spec file modified to be fedora packaging guidline compliant
585267
- little shifting lines in init script header due to rpmlint complaint
585267
- fixes assertion during start up
585267
585267
* Mon Feb 01 2010 Henrik Nordstrom <henrik@henriknordstrom.net> 7:3.1.0.16-3
585267
- Upgrade to 3.1.0.16 for DNS related DoS fix (Squid-2010:1)
585267
585267
* Sat Jan 09 2010 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.15-3
585267
- fixed #551302 PROXY needs libcap. Also increases security a little.
585267
- merged relevant upstream bugfixes waiting for next 3.1 release
585267
585267
* Mon Nov 23 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.15-2
585267
- Update to 3.1.0.15 with a number of bugfixes and a workaround for
585267
  ICEcast/SHOUTcast streams.
585267
585267
* Mon Nov 23 2009 Jiri Skala <jskala@redhat.com> 7:3.1.0.14-2
585267
- fixed #532930 Syntactic error in /etc/init.d/squid
585267
- fixed #528453 cannot initialize cache_dir with user specified config file
585267
585267
* Sun Sep 27 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.14-1
585267
- Update to 3.1.0.14
585267
585267
* Sat Sep 26 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.13-7
585267
- Include upstream patches fixing important operational issues
585267
- Enable ESI support now that it does not conflict with normal operation
585267
585267
* Fri Sep 18 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.13-6
585267
- Rotate store.log if enabled
585267
585267
* Wed Sep 16 2009 Tomas Mraz <tmraz@redhat.com> - 7:3.1.0.13-5
585267
- Use password-auth common PAM configuration instead of system-auth
585267
585267
* Tue Sep 15 2009 Jiri Skala <jskala@redhat.com> - 7:3.1.0.13-4
585267
- fixed #521596 - wrong return code of init script
585267
585267
* Tue Sep 08 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.13-3
585267
- Enable squid_kerb_auth
585267
585267
* Mon Sep 07 2009 Henrik Nordstrom <henrik@henriknordtrom.net> - 7:3.1.0.13-2
585267
- Cleaned up packaging to ease future maintenance
585267
585267
* Fri Sep 04 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.1.0.13-1
585267
- Upgrade to next upstream release 3.1.0.13 with many new features
585267
  * IPv6 support
585267
  * NTLM-passthru
585267
  * Kerberos/Negotiate authentication scheme support
585267
  * Localized error pages based on browser language preferences
585267
  * Follow X-Forwarded-For capability
585267
  * and more..
585267
585267
* Mon Aug 31 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 3.0.STABLE18-3
585267
- Bug #520445 silence logrotate when Squid is not running
585267
585267
* Fri Aug 21 2009 Tomas Mraz <tmraz@redhat.com> - 7:3.0.STABLE18-2
585267
- rebuilt with new openssl
585267
585267
* Tue Aug 04 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE18-1
585267
- Update to 3.0.STABLE18
585267
585267
* Sat Aug 01 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE17-3
585267
- Squid Bug #2728: regression: assertion failed: http.cc:705: "!eof"
585267
585267
* Mon Jul 27 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE17-2
585267
- Bug #514014, update to 3.0.STABLE17 fixing the denial of service issues
585267
  mentioned in Squid security advisory SQUID-2009_2.
585267
585267
* Sun Jul 26 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 7:3.0.STABLE16-3
585267
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
585267
585267
* Wed Jul 01 2009 Jiri Skala <jskala@redhat.com> 7:3.0.STABLE16-2
585267
- fixed patch parameter of bXXX patches
585267
585267
* Mon Jun 29 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE16-1
585267
- Upgrade to 3.0.STABLE16
585267
585267
* Sat May 23 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE15-2
585267
- Bug #453304 - Squid requires restart after Network Manager connection setup
585267
585267
* Sat May 09 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE15-1
585267
- Upgrade to 3.0.STABLE15
585267
585267
* Tue Apr 28 2009 Jiri Skala <jskala@redhat.com> - 7:3.0.STABLE14-3
585267
- fixed ambiguous condition in the init script (exit 4)
585267
585267
* Mon Apr 20 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE14-2
585267
- Squid bug #2635: assertion failed: HttpHeader.cc:1196: "Headers[id].type == ftInt64"
585267
585267
* Sun Apr 19 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE14-1
585267
- Upgrade to 3.0.STABLE14
585267
585267
* Fri Mar 06 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE13-2
585267
- backported logfile.cc syslog parameters patch from 3.1 (b9443.patch)
585267
- GCC-4.4 workaround in src/wccp2.cc
585267
585267
* Wed Feb 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 7:3.0.STABLE13-2
585267
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
585267
585267
* Thu Feb 5 2009 Jonathan Steffan <jsteffan@fedoraproject.org> - 7:3.0.STABLE13-1
585267
- upgrade to latest upstream
585267
585267
* Tue Jan 27 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE12-1
585267
- upgrade to latest upstream
585267
585267
* Sun Jan 18 2009 Tomas Mraz <tmraz@redhat.com> - 7:3.0.STABLE10-4
585267
- rebuild with new openssl
585267
585267
* Fri Dec 19 2008 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE10-3
585267
- actually include the upstream bugfixes in the build
585267
585267
* Fri Dec 19 2008 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE10-2
585267
- upstream bugfixes for cache corruption and access.log response size errors
585267
585267
* Fri Oct 24 2008 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE10-1
585267
- upgrade to latest upstream
585267
585267
* Sun Oct 19 2008 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE9-2
585267
- disable coss support, not officially supported in 3.0
585267
585267
* Sun Oct 19 2008 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE9-1
585267
- update to latest upstream
585267
585267
* Thu Oct 09 2008 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE7-4
585267
- change logrotate to move instead of copytruncate
585267
585267
* Wed Oct 08 2008 Jiri Skala <jskala@redhat.com> - 7:3.0.STABLE7-3
585267
- fix #465052 -  FTBFS squid-3.0.STABLE7-1.fc10
585267
585267
* Thu Aug 14 2008 Jiri Skala <jskala@redhat.com> - 7:3.0.STABLE7-2
585267
- used ncsa_auth.8 from man-pages. there will be this file removed due to conflict
585267
- fix #458593 noisy initscript
585267
- fix #463129 init script tests wrong conf file
585267
- fix #450352 - build.patch patches only generated files
585267
585267
* Wed Jul 02 2008 Jiri Skala <jskala@redhat.com> - 7:3.0.STABLE7-1
585267
- update to latest upstream
585267
- fix #453214
585267
585267
* Mon May 26 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE6-2
585267
- fix bad allocation
585267
585267
* Wed May 21 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE6-1
585267
- upgrade to latest upstream
585267
- fix bad allocation
585267
585267
* Fri May 09 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE5-2
585267
- fix configure detection of netfilter kernel headers (#435499),
585267
  patch by aoliva@redhat.com
585267
- add support for negotiate authentication (#445337)
585267
585267
* Fri May 02 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE5-1
585267
- upgrade to latest upstream
585267
585267
* Tue Apr 08 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE4-1
585267
- upgrade to latest upstream
585267
585267
* Thu Apr 03 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE2-2
585267
- add %%{optflags} to make
585267
- remove warnings about unused return values
585267
585267
* Thu Mar 13 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE2-1
585267
- upgrade to latest upstream 3.0.STABLE2
585267
- check config file before starting (#428998)
585267
- whitespace unification of init script
585267
- some minor path changes in the QUICKSTART file
585267
- configure with the --with-filedescriptors=16384 option
585267
585267
* Tue Feb 26 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE1-3
585267
- change the cache_effective_group default back to none
585267
585267
* Mon Feb 11 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE1-2
585267
- rebuild for 4.3
585267
585267
* Wed Jan 23 2008 Martin Nagy <mnagy@redhat.com> - 7:3.0.STABLE1-1
585267
- upgrade to latest upstream 3.0.STABLE1
585267
585267
* Tue Dec 04 2007 Martin Bacovsky <mbacovsk@redhat.com> - 2.6.STABLE17-1
585267
- upgrade to latest upstream 2.6.STABLE17
585267
585267
* Wed Oct 31 2007 Martin Bacovsky <mbacovsk@redhat.com> - 7:2.6.STABLE16-3
585267
- arp-acl was enabled
585267
585267
* Tue Sep 25 2007 Martin Bacovsky <mbacovsk@redhat.com> - 7:2.6.STABLE16-2
585267
- our fd_config patch was replaced by upstream's version 
585267
- Source1 (FAQ.sgml) points to local source (upstream's moved to wiki)
585267
585267
* Fri Sep 14 2007 Martin Bacovsky <mbacovsk@redhat.com> - 7:2.6.STABLE16-1
585267
- upgrade to latest upstream 2.6.STABLE16
585267
585267
* Wed Aug 29 2007 Fedora Release Engineering <rel-eng at fedoraproject dot org> - 7:2.6.STABLE14-2
585267
- Rebuild for selinux ppc32 issue.
585267
585267
* Thu Jul 19 2007 Martin Bacovsky <mbacovsk@redhat.com> - 7:2.6.STABLE14-1
585267
- update to latest upstream 2.6.STABLE14
585267
- resolves: #247064: Initscript Review
585267
585267
* Tue Mar 27 2007 Martin Bacovsky <mbacovsk@redhat.com> - 7:2.6.STABLE12-1
585267
- update to latest upstream 2.6.STABLE12
585267
- Resolves: #233913: squid: unowned directory
585267
585267
* Mon Feb 19 2007 Martin Bacovsky <mbacovsk@redhat.com> - 7:2.6.STABLE9-2
585267
- Resolves: #226431: Merge Review: squid
585267
585267
* Mon Jan 29 2007 Martin Bacovsky <mbacovsk@redhat.com> - 7:2.6.STABLE9-1
585267
- update to the latest upstream
585267
585267
* Sun Jan 14 2007 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE7-1
585267
- update to the latest upstream
585267
585267
* Tue Dec 12 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE6-1
585267
- update to the latest upstream
585267
585267
* Mon Nov  6 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE5-1
585267
- update to the latest upstream
585267
585267
* Thu Oct 26 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE4-4
585267
- added fix for #205568 - marked cachemgr.conf as world readable
585267
585267
* Wed Oct 25 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE4-3
585267
- added fix for #183869 - squid can abort when getting status
585267
- added upstream fixes:
585267
    * Bug #1796: Assertion error HttpHeader.c:914: "str"
585267
    * Bug #1779: Delay pools fairness, correction to first patch
585267
    * Bug #1802: Crash on exit in certain conditions where cache.log is not writeable
585267
    * Bug #1779: Delay pools fairness when multiple connections compete for bandwidth
585267
    * Clarify the select/poll/kqueue/epoll configure --enable/disable options
585267
- reworked fd patch for STABLE4
585267
585267
* Tue Oct 17 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE4-2
585267
- upstream fixes:
585267
  * Accept 00:00-24:00 as a valid time specification (upstream BZ #1794)
585267
  * aioDone() could be called twice
585267
  * Squid reconfiguration (upstream BZ #1800)
585267
585267
* Mon Oct 2 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE4-1
585267
- new upstream
585267
- fixes from upstream bugzilla, items #1782,#1780,#1785,#1719,#1784,#1776
585267
585267
* Tue Sep 5 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE3-2
585267
- added upstream patches for ACL
585267
585267
* Mon Aug 21 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE3-1
585267
- the latest stable upstream
585267
585267
* Thu Aug 10 2006 Karsten Hopp <karsten@redhat.de> 7:2.6.STABLE2-3
585267
- added some requirements for pre/post install scripts
585267
585267
* Fri Aug 04 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE2-2
585267
- added patch for #198253 - squid: don't chgrp another pkg's
585267
  files/directory
585267
585267
* Mon Jul 31 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE2-1
585267
- the latest stable upstream
585267
- reworked fd config patch
585267
585267
* Tue Jul 25 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE1-3
585267
- the latest CVS upstream snapshot
585267
585267
* Wed Jul 19 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE1-2
585267
- the latest CVS snapshot
585267
585267
* Tue Jul 18 2006 Martin Stransky <stransky@redhat.com> - 7:2.6.STABLE1-1
585267
- new upstream + the latest CVS snapshot from 2006/07/18
585267
- updated fd config patch
585267
- enabled epoll
585267
- fixed release format (#197405)
585267
- enabled WCCPv2 support (#198642)
585267
585267
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 7:2.5.STABLE14-2.1
585267
- rebuild
585267
585267
* Thu Jun 8 2006 Martin Stransky <stransky@redhat.com> - 7:2.5.STABLE14-2
585267
- fix for squid BZ#1511 - assertion failed: HttpReply.c:105: "rep"
585267
585267
* Tue May 30 2006 Martin Stransky <stransky@redhat.com> - 7:2.5.STABLE14-1
585267
- update to new upstream
585267
585267
* Sun May 28 2006 Martin Stransky <stransky@redhat.com> - 7:2.5.STABLE13-5
585267
- fixed libbind patch (#193298)
585267
585267
* Wed May 3  2006 Martin Stransky <stransky@redhat.com> - 7:2.5.STABLE13-4
585267
- added extra group check (#190544)
585267
585267
* Wed Mar 29 2006 Martin Stransky <stransky@redhat.com> - 7:2.5.STABLE13-3
585267
- improved pre script (#187217) - added group switch
585267
585267
* Thu Mar 23 2006 Martin Stransky <stransky@redhat.com> - 7:2.5.STABLE13-2
585267
- removed "--with-large-files" on 64bit arches
585267
585267
* Mon Mar 13 2006 Martin Stransky <stransky@redhat.com> - 7:2.5.STABLE13-1
585267
- update to new upstream
585267
585267
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 7:2.5.STABLE12-5.1
585267
- bump again for double-long bug on ppc(64)
585267
585267
* Tue Feb 07 2006 Martin Stransky <stransky@redhat.com> - 7:2.5.STABLE12-5
585267
- new upstream patches
585267
585267
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 7:2.5.STABLE12-4.1
585267
- rebuilt for new gcc4.1 snapshot and glibc changes
585267
585267
* Wed Dec 28 2005  Martin Stransky <stransky@redhat.com> 7:2.5.STABLE12-4
585267
- added follow-xff patch (#176055)
585267
- samba path fix (#176659)
585267
585267
* Mon Dec 19 2005  Martin Stransky <stransky@redhat.com> 7:2.5.STABLE12-3
585267
- fd-config.patch clean-up
585267
- SMB_BadFetch patch from upstream
585267
585267
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
585267
- rebuilt
585267
585267
* Mon Nov 28 2005  Martin Stransky <stransky@redhat.com> 7:2.5.STABLE12-2
585267
- rewriten patch squid-2.5.STABLE10-64bit.patch, it works with
585267
  "--with-large-files" option now
585267
- fix for #72896 - squid does not support > 1024 file descriptors,
585267
  new "--enable-fd-config" option for it.
585267
585267
* Wed Nov 9 2005  Martin Stransky <stransky@redhat.com> 7:2.5.STABLE12-1
585267
- update to STABLE12
585267
- setenv patch
585267
585267
* Mon Oct 24 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE11-6
585267
- fix for delay pool from upstream
585267
585267
* Thu Oct 20 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE11-5
585267
- fix for #171213 - CVE-2005-3258 Squid crash due to malformed FTP response
585267
- more fixes from upstream
585267
585267
* Fri Oct 14 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE11-4
585267
- enabled support for large files (#167503)
585267
585267
* Thu Oct 13 2005 Tomas Mraz <tmraz@redhat.com> 7:2.5.STABLE11-3
585267
- use include instead of pam_stack in pam config
585267
585267
* Thu Sep 29 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE11-2
585267
- added patch for delay pools and some minor fixes
585267
585267
* Fri Sep 23 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE11-1
585267
- update to STABLE11
585267
585267
* Mon Sep 5 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE10-4
585267
- Three upstream patches for #167414
585267
- Spanish and Greek messages
585267
- patch for -D_FORTIFY_SOURCE=2 
585267
585267
* Tue Aug 30 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE10-3
585267
- removed "--enable-truncate" option (#165948)
585267
- added "--enable-cache-digests" option (#102134)
585267
- added "--enable-ident-lookups" option (#161640)
585267
- some clean up (#165949)
585267
585267
* Fri Jul 15 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE10-2
585267
- pam_auth and ncsa_auth have setuid (#162660)
585267
585267
* Thu Jul 7 2005 Martin Stransky <stransky@redhat.com> 7:2.5.STABLE10-1
585267
- new upstream version
585267
- enabled fakeauth utility (#154020)
585267
- enabled digest authentication scheme (#155882)
585267
- all error pages marked as config (#127836)
585267
- patch for 64bit statvfs interface (#153274)
585267
- added httpd config file for cachemgr.cgi (#112725)
585267
585267
* Mon May 16 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE9-7
585267
- Upgrade the upstream -dns_query patch from -4 to -5
585267
585267
* Wed May 11 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE9-6
585267
- More upstream patches, including a fix for
585267
  bz#157456 CAN-2005-1519 DNS lookups unreliable on untrusted networks
585267
585267
* Tue Apr 26 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE9-5
585267
- more upstream patches, including a fix for
585267
  CVE-1999-0710 cachemgr malicious use
585267
585267
* Fri Apr 22 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE9-4
585267
- More upstream patches, including the fixed 2GB patch.
585267
- include the -libbind patch, which prevents squid from using the optional
585267
  -lbind library, even if it's installed.
585267
585267
* Tue Mar 15 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE9-2
585267
- New upstream version, with 14 upstream patches.
585267
585267
* Wed Feb 16 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE8-2
585267
- new upstream version with 4 upstream patches.
585267
- Reorganize spec file to apply upstream patches first
585267
585267
* Tue Feb 1 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE7-4
585267
- Include two more upstream patches for security vulns:
585267
  bz#146783 Correct handling of oversized reply headers
585267
  bz#146778 CAN-2005-0211 Buffer overflow in WCCP recvfrom() call
585267
585267
* Tue Jan 25 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE7-3
585267
- Include more upstream patches, including two for security holes.
585267
585267
* Tue Jan 18 2005 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE7-2
585267
- Add a triggerin on samba-common to make /var/cache/samba/winbindd_privileged
585267
  accessable so that ntlm_auth will work.  It needs to be in this rpm,
585267
  because the Samba RPM can't assume the squid user exists.
585267
  Note that this will only work if the Samba RPM is recent enough to create
585267
  that directory at install time instead of at winbindd startup time.
585267
  That should be samba-common-3.0.0-15 or later.
585267
  This fixes bugzilla #103726
585267
- Clean up extra whitespace in this spec file.
585267
- Add additional upstream patches. (Now 18 upstream patches).
585267
- patch #112 closes CAN-2005-0096 and CAN-2005-0097, remote DOS security holes.
585267
- patch #113 closes CAN-2005-0094, a remote buffer-overflow DOS security hole.
585267
- patch #114 closes CAN-2005-0095, a remote DOS security hole.
585267
- Remove the -nonbl (replaced by #104) and -close (replaced by #111) patches, since
585267
  they're now fixed by upstream patches.
585267
585267
* Mon Oct 25 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE7-1
585267
- new upstream version, with 3 upstream patches.
585267
  Updated the -build and -config patches
585267
- Include patch from Ulrich Drepper <frepper@redhat.com> to more
585267
  intelligently close all file descriptors.
585267
585267
* Mon Oct 18 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE6-3
585267
- include patch from Ulrich Drepper <drepper@redhat.com> to stop
585267
  problems with O_NONBLOCK.  This closes #136049
585267
585267
* Tue Oct 12 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE6-2
585267
- Include fix for CAN-2004-0918
585267
585267
* Tue Sep 28 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE6-1
585267
- New upstream version, with 32 upstream patches.
585267
  This closes #133970, #133931, #131728, #128143, #126726
585267
585267
- Change the permissions on /etc/squid/squid.conf to 640.  This closes
585267
  bugzilla #125007
585267
585267
* Mon Jun 28 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5STABLE5-5
585267
- Merge current upstream patches.
585267
- Fix the -pipe patch to have the correct name of the winbind pipe.
585267
585267
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
585267
- rebuilt
585267
585267
* Mon Apr 5 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE5-2
585267
- Include the first 10 upstream patches
585267
- Add a patch for the correct location of the winbindd pipe.  This closes
585267
  bugzilla #107561
585267
- Remove the change to ssl_support.c from squid-2.5.STABLE3-build patch
585267
  This closes #117851
585267
- Include /etc/pam.d/squid .  This closes #113404
585267
- Include a patch to close #111254 (assignment in assert)
585267
- Change squid.init to put output messages in /var/log/squid/squid.out
585267
  This closes #104697
585267
- Only useradd the squid user if it doesn't already exist, and error out
585267
  if the useradd fails.  This closes #118718.
585267
585267
* Tue Mar 2 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE5-1
585267
- New upstream version, obsoletes many patches.
585267
- Fix --datadir passed to configure.  Configure automatically adds /squid
585267
  so we shouldn't.
585267
- Remove the problematic triggerpostun trigger, since is's broken, and FC2
585267
  never shipped with that old version.
585267
- add %%{?_smp_mflags} to make line.
585267
585267
* Tue Mar 02 2004 Elliot Lee <sopwith@redhat.com>
585267
- rebuilt
585267
585267
* Mon Feb 23 2004 Tim Waugh <twaugh@redhat.com>
585267
- Use ':' instead of '.' as separator for chown.
585267
585267
* Fri Feb 20 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE4-3
585267
- Clean up the spec file to work on 64-bit platforms (use %%{_libdir}
585267
  instead of /usr/lib, etc)
585267
- Make the release number in the changelog section agree with reality.
585267
- use -fPIE rather than -fpie.  s390 fails with just -fpie
585267
585267
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
585267
- rebuilt
585267
585267
* Thu Feb 5 2004 Jay Fenlason <fenlason@redhat.com>
585267
- Incorporate many upstream patches
585267
- Include many spec file changes from D.Johnson <dj@www.uk.linux.org>
585267
585267
* Tue Sep 23 2003 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE4-1
585267
- New upstream version.
585267
- Fix the Source: line in this spec file to point to the correct URL.
585267
- redo the -location patch to work with the new upstream version.
585267
585267
* Mon Jun 30 2003 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE3-0
585267
- Spec file change to enable the nul storage module. bugzilla #74654
585267
- Upgrade to 2.5STABLE3 with current official patches.
585267
- Added --enable-auth="basic,ntlm": closes bugzilla #90145
585267
- Added --with-winbind-auth-challenge: closes bugzilla #78691
585267
- Added --enable-useragent-log and --enable-referer-log, closes
585267
- bugzilla #91884
585267
# - Changed configure line to enable pie
585267
# (Disabled due to broken compilers on ia64 build machines)
585267
#- Patched to increase the maximum number of file descriptors #72896
585267
#- (disabled for now--needs more testing)
585267
585267
* Wed Jun 04 2003 Elliot Lee <sopwith@redhat.com>
585267
- rebuilt
585267
585267
* Wed Jan 22 2003 Tim Powers <timp@redhat.com>
585267
- rebuilt
585267
585267
* Wed Jan 15 2003 Bill Nottingham <notting@redhat.com> 7:2.5.STABLE1-1
585267
- update to 2.5.STABLE1
585267
585267
* Wed Nov 27 2002 Tim Powers <timp@redhat.com> 7:2.4.STABLE7-5
585267
- remove unpackaged files from the buildroot
585267
585267
* Tue Aug 27 2002 Nalin Dahyabhai <nalin@redhat.com> 2.4.STABLE7-4
585267
- rebuild
585267
585267
* Wed Jul 31 2002 Karsten Hopp <karsten@redhat.de>
585267
- don't raise an error if the config file is incomplete
585267
  set defaults instead (#69322, #70065)
585267
585267
* Thu Jul 18 2002 Bill Nottingham <notting@redhat.com> 2.4.STABLE7-2
585267
- don't strip binaries
585267
585267
* Mon Jul  8 2002 Bill Nottingham <notting@redhat.com>
585267
- update to 2.4.STABLE7
585267
- fix restart (#53761)
585267
585267
* Tue Jun 25 2002 Bill Nottingham <notting@redhat.com>
585267
- add various upstream bugfix patches
585267
585267
* Fri Jun 21 2002 Tim Powers <timp@redhat.com>
585267
- automated rebuild
585267
585267
* Thu May 23 2002 Tim Powers <timp@redhat.com>
585267
- automated rebuild
585267
585267
* Fri Mar 22 2002 Bill Nottingham <notting@redhat.com>
585267
- 2.4.STABLE6
585267
- turn off carp
585267
585267
* Mon Feb 18 2002 Bill Nottingham <notting@redhat.com>
585267
- 2.4.STABLE3 + patches
585267
- turn off HTCP at request of maintainers
585267
- leave SNMP enabled in the build, but disabled in the default config
585267
585267
* Fri Jan 25 2002 Tim Powers <timp@redhat.com>
585267
- rebuild against new libssl
585267
585267
* Wed Jan 09 2002 Tim Powers <timp@redhat.com>
585267
- automated rebuild
585267
585267
* Mon Jan 07 2002 Florian La Roche <Florian.LaRoche@redhat.de>
585267
- require linuxdoc-tools instead of sgml-tools
585267
585267
* Tue Sep 25 2001 Bill Nottingham <notting@redhat.com>
585267
- update to 2.4.STABLE2
585267
585267
* Mon Sep 24 2001 Bill Nottingham <notting@redhat.com>
585267
- add patch to fix FTP crash
585267
585267
* Mon Aug  6 2001 Bill Nottingham <notting@redhat.com>
585267
- fix uninstall (#50411)
585267
585267
* Mon Jul 23 2001 Bill Nottingham <notting@redhat.com>
585267
- add some buildprereqs (#49705)
585267
585267
* Sun Jul 22 2001 Bill Nottingham <notting@redhat.com>
585267
- update FAQ
585267
585267
* Tue Jul 17 2001 Bill Nottingham <notting@redhat.com>
585267
- own /etc/squid, /usr/lib/squid
585267
585267
* Tue Jun 12 2001 Nalin Dahyabhai <nalin@redhat.com>
585267
- rebuild in new environment
585267
- s/Copyright:/License:/
585267
585267
* Tue Apr 24 2001 Bill Nottingham <notting@redhat.com>
585267
- update to 2.4.STABLE1 + patches
585267
- enable some more configure options (#24981)
585267
- oops, ship /etc/sysconfig/squid
585267
585267
* Fri Mar  2 2001 Nalin Dahyabhai <nalin@redhat.com>
585267
- rebuild in new environment
585267
585267
* Tue Feb  6 2001 Trond Eivind Glomsrød <teg@redhat.com>
585267
- improve i18n
585267
- make the initscript use the standard OK/FAILED
585267
585267
* Tue Jan 23 2001 Bill Nottingham <notting@redhat.com>
585267
- change i18n mechanism
585267
585267
* Fri Jan 19 2001 Bill Nottingham <notting@redhat.com>
585267
- fix path references in QUICKSTART (#15114)
585267
- fix initscript translations (#24086)
585267
- fix shutdown logic (#24234), patch from <jos@xos.nl>
585267
- add /etc/sysconfig/squid for daemon options & shutdown timeouts
585267
- three more bugfixes from the Squid people
585267
- update FAQ.sgml
585267
- build and ship auth modules (#23611)
585267
585267
* Thu Jan 11 2001 Bill Nottingham <notting@redhat.com>
585267
- initscripts translations
585267
585267
* Mon Jan  8 2001 Bill Nottingham <notting@redhat.com>
585267
- add patch to use mkstemp (greg@wirex.com)
585267
585267
* Fri Dec 01 2000 Bill Nottingham <notting@redhat.com>
585267
- rebuild because of broken fileutils
585267
585267
* Sat Nov 11 2000 Bill Nottingham <notting@redhat.com>
585267
- fix the acl matching cases (only need the second patch)
585267
585267
* Tue Nov  7 2000 Bill Nottingham <notting@redhat.com>
585267
- add two patches to fix domain ACLs
585267
- add 2 bugfix patches from the squid people
585267
585267
* Fri Jul 28 2000 Bill Nottingham <notting@redhat.com>
585267
- clean up init script; fix condrestart
585267
- update to STABLE4, more bugfixes
585267
- update FAQ
585267
585267
* Tue Jul 18 2000 Nalin Dahyabhai <nalin@redhat.com>
585267
- fix syntax error in init script
585267
- finish adding condrestart support
585267
585267
* Fri Jul 14 2000 Bill Nottingham <notting@redhat.com>
585267
- move initscript back
585267
585267
* Wed Jul 12 2000 Prospector <bugzilla@redhat.com>
585267
- automatic rebuild
585267
585267
* Thu Jul  6 2000 Bill Nottingham <notting@redhat.com>
585267
- prereq /etc/init.d
585267
- add bugfix patch
585267
- update FAQ
585267
585267
* Thu Jun 29 2000 Bill Nottingham <notting@redhat.com>
585267
- fix init script
585267
585267
* Tue Jun 27 2000 Bill Nottingham <notting@redhat.com>
585267
- don't prereq new initscripts
585267
585267
* Mon Jun 26 2000 Bill Nottingham <notting@redhat.com>
585267
- initscript munging
585267
585267
* Sat Jun 10 2000 Bill Nottingham <notting@redhat.com>
585267
- rebuild for exciting FHS stuff
585267
585267
* Wed May 31 2000 Bill Nottingham <notting@redhat.com>
585267
- fix init script again (#11699)
585267
- add --enable-delay-pools (#11695)
585267
- update to STABLE3
585267
- update FAQ
585267
585267
* Fri Apr 28 2000 Bill Nottingham <notting@redhat.com>
585267
- fix init script (#11087)
585267
585267
* Fri Apr  7 2000 Bill Nottingham <notting@redhat.com>
585267
- three more bugfix patches from the squid people
585267
- buildprereq jade, sgmltools
585267
585267
* Sun Mar 26 2000 Florian La Roche <Florian.LaRoche@redhat.com>
585267
- make %%pre more portable
585267
585267
* Thu Mar 16 2000 Bill Nottingham <notting@redhat.com>
585267
- bugfix patches
585267
- fix dependency on /usr/local/bin/perl
585267
585267
* Sat Mar  4 2000 Bill Nottingham <notting@redhat.com>
585267
- 2.3.STABLE2
585267
585267
* Mon Feb 14 2000 Bill Nottingham <notting@redhat.com>
585267
- Yet More Bugfix Patches
585267
585267
* Tue Feb  8 2000 Bill Nottingham <notting@redhat.com>
585267
- add more bugfix patches
585267
- --enable-heap-replacement
585267
585267
* Mon Jan 31 2000 Cristian Gafton <gafton@redhat.com>
585267
- rebuild to fix dependencies
585267
585267
* Fri Jan 28 2000 Bill Nottingham <notting@redhat.com>
585267
- grab some bugfix patches
585267
585267
* Mon Jan 10 2000 Bill Nottingham <notting@redhat.com>
585267
- 2.3.STABLE1 (whee, another serial number)
585267
585267
* Tue Dec 21 1999 Bernhard Rosenkraenzer <bero@redhat.com>
585267
- Fix compliance with ftp RFCs
585267
  (http://www.wu-ftpd.org/broken-clients.html)
585267
- Work around a bug in some versions of autoconf
585267
- BuildPrereq sgml-tools - we're using sgml2html
585267
585267
* Mon Oct 18 1999 Bill Nottingham <notting@redhat.com>
585267
- add a couple of bugfix patches
585267
585267
* Wed Oct 13 1999 Bill Nottingham <notting@redhat.com>
585267
- update to 2.2.STABLE5.
585267
- update FAQ, fix URLs.
585267
585267
* Sat Sep 11 1999 Cristian Gafton <gafton@redhat.com>
585267
- transform restart in reload and add restart to the init script
585267
585267
* Tue Aug 31 1999 Bill Nottingham <notting@redhat.com>
585267
- add squid user as user 23.
585267
585267
* Mon Aug 16 1999 Bill Nottingham <notting@redhat.com>
585267
- initscript munging
585267
- fix conflict between logrotate & squid -k (#4562)
585267
585267
* Wed Jul 28 1999 Bill Nottingham <notting@redhat.com>
585267
- put cachemgr.cgi back in /usr/lib/squid
585267
585267
* Wed Jul 14 1999 Bill Nottingham <notting@redhat.com>
585267
- add webdav bugfix patch (#4027)
585267
585267
* Mon Jul 12 1999 Bill Nottingham <notting@redhat.com>
585267
- fix path to config in squid.init (confuses linuxconf)
585267
585267
* Wed Jul  7 1999 Bill Nottingham <notting@redhat.com>
585267
- 2.2.STABLE4
585267
585267
* Wed Jun 9 1999 Dale Lovelace <dale@redhat.com>
585267
- logrotate changes
585267
- errors from find when /var/spool/squid or
585267
- /var/log/squid didn't exist
585267
585267
* Thu May 20 1999 Bill Nottingham <notting@redhat.com>
585267
- 2.2.STABLE3
585267
585267
* Thu Apr 22 1999 Bill Nottingham <notting@redhat.com>
585267
- update to 2.2.STABLE.2
585267
585267
* Sun Apr 18 1999 Bill Nottingham <notting@redhat.com>
585267
- update to 2.2.STABLE1
585267
585267
* Thu Apr 15 1999 Bill Nottingham <notting@redhat.com>
585267
- don't need to run groupdel on remove
585267
- fix useradd
585267
585267
* Mon Apr 12 1999 Bill Nottingham <notting@redhat.com>
585267
- fix effective_user (bug #2124)
585267
585267
* Mon Apr  5 1999 Bill Nottingham <notting@redhat.com>
585267
- strip binaries
585267
585267
* Thu Apr  1 1999 Bill Nottingham <notting@redhat.com>
585267
- duh. adduser does require a user name.
585267
- add a serial number
585267
585267
* Tue Mar 30 1999 Bill Nottingham <notting@redhat.com>
585267
- add an adduser in %%pre, too
585267
585267
* Thu Mar 25 1999 Bill Nottingham <notting@redhat.com>
585267
- oog. chkconfig must be in %%preun, not %%postun
585267
585267
* Wed Mar 24 1999 Bill Nottingham <notting@redhat.com>
585267
- switch to using group squid
585267
- turn off icmp (insecure)
585267
- update to 2.2.DEVEL3
585267
- build FAQ docs from source
585267
585267
* Tue Mar 23 1999 Bill Nottingham <notting@redhat.com>
585267
- logrotate changes
585267
585267
* Sun Mar 21 1999 Cristian Gafton <gafton@redhat.com>
585267
- auto rebuild in the new build environment (release 4)
585267
585267
* Wed Feb 10 1999 Bill Nottingham <notting@redhat.com>
585267
- update to 2.2.PRE2
585267
585267
* Wed Dec 30 1998 Bill Nottingham <notting@redhat.com>
585267
- cache & log dirs shouldn't be world readable
585267
- remove preun script (leave logs & cache @ uninstall)
585267
585267
* Tue Dec 29 1998 Bill Nottingham <notting@redhat.com>
585267
- fix initscript to get cache_dir correct
585267
585267
* Fri Dec 18 1998 Bill Nottingham <notting@redhat.com>
585267
- update to 2.1.PATCH2
585267
- merge in some changes from RHCN version
585267
585267
* Sat Oct 10 1998 Cristian Gafton <gafton@redhat.com>
585267
- strip binaries
585267
- version 1.1.22
585267
585267
* Sun May 10 1998 Cristian Gafton <gafton@redhat.com>
585267
- don't make packages conflict with each other...
585267
585267
* Sat May 02 1998 Cristian Gafton <gafton@redhat.com>
585267
- added a proxy auth patch from Alex deVries <adevries@engsoc.carleton.ca>
585267
- fixed initscripts
585267
585267
* Thu Apr 09 1998 Cristian Gafton <gafton@redhat.com>
585267
- rebuilt for Manhattan
585267
585267
* Fri Mar 20 1998 Cristian Gafton <gafton@redhat.com>
585267
- upgraded to 1.1.21/1.NOVM.21
585267
585267
* Mon Mar 02 1998 Cristian Gafton <gafton@redhat.com>
585267
- updated the init script to use reconfigure option to restart squid instead
585267
  of shutdown/restart (both safer and quicker)
585267
585267
* Sat Feb 07 1998 Cristian Gafton <gafton@redhat.com>
585267
- upgraded to 1.1.20
585267
- added the NOVM package and tryied to reduce the mess in the spec file
585267
585267
* Wed Jan 7 1998 Cristian Gafton <gafton@redhat.com>
585267
- first build against glibc
585267
- patched out the use of setresuid(), which is available only on kernels
585267
  2.1.44 and later
585267