X-Git-Url: http://www.privoxy.org/gitweb/?p=privoxy.git;a=blobdiff_plain;f=doc%2Fsource%2Fchangelog.sgml;h=6ca1058ddf991061b66ca33501962f01c67ab8d7;hp=c774583a33c355302acf5107db0d0cda1b676abc;hb=485f35a0d8a05cacdec28d7416cdd6a4234b0331;hpb=b2207e8badcd63c00fffcd646b30f2960b4bc371 diff --git a/doc/source/changelog.sgml b/doc/source/changelog.sgml index c774583a..6ca1058d 100644 --- a/doc/source/changelog.sgml +++ b/doc/source/changelog.sgml @@ -1,11 +1,9 @@ - - Privoxy 3.0.22 stable is mainly a bug-fix - release, it also has a couple of new features, though. - Note that the first two entries in the ChangeLog below refer to security - issues: - + + Privoxy 3.0.29 fixes a couple of memory + leaks and introduces https inspection which allows to filter encrypted + requests and responses. + + + Changes in Privoxy 3.0.29 stable: + - Bug fixes: + Security/Reliability: - Fixed a memory leak when rejecting client connections due to - the socket limit being reached (CID 66382). This affected - Privoxy 3.0.21 when compiled with IPv6 support (on most - platforms this is the default). + Fixed memory leaks when a response is buffered and the buffer + limit is reached or Privoxy is running out of memory. + Commits bbd53f1010b and 4490d451f9b. OVE-20201118-0001. + Sponsored by: Robert Klemme - Fixed an immediate-use-after-free bug (CID 66394) and two - additional unconfirmed use-after-free complaints made by - Coverity scan (CID 66391, CID 66376). + Fixed a memory leak in the show-status CGI handler when + no action files are configured. Commit c62254a686. + OVE-20201118-0002. + Sponsored by: Robert Klemme - Actually show the FORCE_PREFIX value on the show-status page. + Fixed a memory leak in the show-status CGI handler when + no filter files are configured. Commit 1b1370f7a8a. + OVE-20201118-0003. + Sponsored by: Robert Klemme - Properly deal with Keep-Alive headers with timeout= parameters - If the timeout still can't be parsed, use the configured - timeout instead of preventing the client from keeping the - connection alive. Fixes #3615312/#870 reported by Bernard Guillot. + Fixes a memory leak when client tags are active. + Commit 245e1cf32. OVE-20201118-0004. + Sponsored by: Robert Klemme - Not using any filter files no longer results in warning messages - unless an action file is referencing header taggers or filters. - Reported by Stefan Kurtz in #3614835. + Fixed a memory leak if multiple filters are executed + and the last one is skipped due to a pcre error. + Commit 5cfb7bc8fe. OVE-20201118-0005. - Fixed a bug that prevented Privoxy from reusing some reusable - connections. Two bit masks with different purpose unintentionally - shared the same bit. + Prevent an unlikely dereference of a NULL-pointer that + could result in a crash if accept-intercepted-requests + was enabled, Privoxy failed to get the request destination + from the Host header and a memory allocation failed. + Commit 7530132349. CID 267165. OVE-20201118-0006. - A couple of additional bugs were discovered by Coverity Scan. - The fixes that are not expected to affect users are not explicitly - mentioned here, for details please have a look at the CVS logs. + Fixed memory leaks in the client-tags CGI handler when + client tags are configured and memory allocations fail. + Commit cf5640eb2a. CID 267168. OVE-20201118-0007. + + + + + Fixed memory leaks in the show-status CGI handler when memory + allocations fail. Commit 064eac5fd0 and commit fdee85c0bf3. + CID 305233. OVE-20201118-0008. @@ -94,201 +106,295 @@ - Introduced negative tag patterns NO-REQUEST-TAG and NO-RESPONSE-TAG. - They apply if no matching tag is found after parsing client or - server headers. + Added experimental https inspection support which allows to filter + https traffic. To enable it, install MbedTLS and configure with + --with-mbedtls, or install OpenSSL or LibreSSL and configure + with --with-openssl. + Afterwards configure the directives in section 7 of the + config file and enable the +https-inspection action. + Initial MbedTLS-based code contributed by Vaclav Svec, + initial OpenSSL support contributed by Maxim Antonov. + With help from Nedzad Hrnjica and Ho+ Ho+ Ho+. + Integration and improvements sponsored by Robert Klemme. - Add support for external filters which allow to process the - response body with a script or program written in any language - the platform supports. External filters are enabled with - +external-filter{} after they have been defined in one of the - filter files with a header line starting with "EXTERNAL-FILTER:". - External filter support is experimental, not compiled by default - and known not to work on all platforms. + pcrs: Request JIT compilation if it's supported and + the filter isn't dynamic. This can speed up filtering. - Add support for the 'PATCH' method as defined in RFC5789. + Added support for Brotli decompression. + Sponsored by: Robert Klemme - Reject requests with unsupported Expect header values. - Fixes a couple of Co-Advisor tests. + Added FEATURE_EXTENDED_STATISTICS to gather statistics for + block reasons and filter executions. To enable it, configure + with --enable-extended-statistics and visit + http://config.privoxy.org/show-status. + Sponsored by: Robert Klemme - Normalize the HTTP-version in forwarded requests and responses. - This is an explicit RFC 2616 MUST and RFC 7230 mandates that - intermediaries send their own HTTP-version in forwarded - messages. + Use the IP_FREEBIND socket option, if defined. This allows + Privoxy to bind to not-yet assigned IP addresses which is + useful in failover environments. + Patch by Sam Varshavchik. - Server 'Keep-Alive' headers are no longer forwarded. From a user's - point of view it doesn't really matter, but RFC 2616 (obsolete) - mandates that the header is removed and this fixes a Co-Advisor - complaint. + Allow to use extended host patterns and vanilla host patterns + at the same time by prefixing extended host patterns with + "PCRE-HOST-PATTERN:". To enable this, configure with + --enable-pcre-host-patterns. + Sponsored by: Robert Klemme - Change declared template file encoding to UTF-8. The templates - already used a subset of UTF-8 anyway and changing the declaration - allows to properly display UTF-8 characters used in the action files. - This change may require existing action files with ISO-8859-1 - characters that aren't valid UTF-8 to be converted to UTF-8. - Requested by Sam Chen in #582. + Added "Cross-origin resource sharing" (CORS) support. + This allows to access Privoxy's CGI interface via JavaScript from + another domain (white-listed with the new cors-allowed-origin directive). + Based on a patch by Nedzad Hrnjica. + Sponsored by: Robert Klemme. - Do not pass rejected keep-alive timeouts to the server. It might - not have caused any problems (we know of), but doing the right - thing shouldn't hurt either. + Add SOCKS5 username/password support. + Based on a patch by Sam, improved by Ivan Romanov. + Closes Patch#141 and solves TODO#105. - Let log_error() use its own buffer size #define to make changing - the log buffer size slightly less inconvenient. + Bump the maximum number of action and filter files + to 100 each. + Sponsored by: Robert Klemme - Turned single-threaded into a "proper" toggle directive with arguments. + Fixed handling of filters with "split-large-forms 1" + when using the CGI editor. + Reported by withoutname in #921. - CGI templates no longer enforce new windows for some links. + Better detect a mismatch of connection details when + figuring out whether or not a connection can be reused. - Remove an undocumented workaround ('HOST' header removal) for - an Apple iTunes bug that according to #729900 got fixed in 2003. + Don't send a "Connection failure" message instead of the + "DNS failure" message. + Sponsored by: Robert Klemme - - - - - - - Action file improvements: - + + + + Let LOG_LEVEL_REQUEST log all requests. Previously unencrypted + requests were only logged with LOG_LEVEL_REQUEST when they weren't + crunched (in which case they were logged with LOG_LEVEL_CRUNCH). + This was documented behaviour, but logging all requests seems more useful. + + + + + Fixed locking around localtime() and gmtime(). + + + + + Removed OS/2 support. We haven't provided OS/2 packages in years, + it complicated the code and it depended on a fallback snprintf() + implementation which is GPLv2 only. + + + + + Remove the fallback snprintf() implementation + Now that OS/2 support is gone we no longer need it. + + + + + Fixed a bunch of format specifiers log messages. + + + + + Added a missing apostrophe in the 'More Privoxy' menu. + + + + + Explicitly prevent use of FEATURE_CONNECTION_SHARING + without FEATURE_CONNECTION_KEEP_ALIVE. It makes no sense + and does not compile anyway. + Sponsored by: Robert Klemme + + + + + Fix build without FEATURE_CONNECTION_KEEP_ALIVE. + Sponsored by: Robert Klemme + + + + + Downgrade the 'Graceful termination requested' message + to LOG_LEVEL_INFO as it isn't an error. + Sponsored by: Robert Klemme + + + + + decompress_iob(): Downgrade the no-content message to LOG_LEVEL_RE_FILTER + While at it, fix a typo in a comment. + Sponsored by: Robert Klemme + + - The pattern 'promotions.' is no longer being blocked. - Reported by rakista in #3608540. + Fixed a couple of cppcheck warnings. - Disable fast-redirects for .microsofttranslator.com/. + Rename LOG_LEVEL_GPC to LOG_LEVEL_REQUEST. + Only the shadow knows what "GPC" is supposed to stand for. - Disable filter{banners-by-size} for .dgb-tagungszentren.de/. + Remove SourceForge references in copyright headers. - Add adn.speedtest.net as a site-specific unblocker. - Support request #3612908. + Upgrade a bunch of links to the homepage to https://. - Disable filter{banners-by-size} for creativecommons.org/. + Add 'no-brotli-accepted' filter which prevents the + use of Brotli compression. - Block requests to data.gosquared.com/. Reported by cbug in #3613653. + Changed license for pcrs to GPLv2+ after getting the + permission from Andreas. This allows to redistribute + Privoxy under the GPLv3 which is required when linking + to future mbedTLS versions which are expected to be + licensed under the Apache 2.0 license only. - Unblock .conrad./newsletter/. Reported by David Bo in #3614238. + Updated a bunch of tests that have to expect status code 403 + now after r1.168/070e904afa5. - Unblock .bundestag.de/. + Lowercase the host name in the request line. + + + + + Only set SOURCE_DATE_EPOCH if it's not already set so + distributions can overwrite it through the environment. + + + + + + + + Documentation changes: + + + + Explain that Privoxy has to be distributed under the + GPLv3 (or later) when linked with an MbedTLS version + that is licensed under the Apache 2.0 license. - Unblock .rote-hilfe.de/. + Import the GNU GPLv3 and include it the user manual. - Disable fast-redirects for .facebook.com/plugins/like.php. + Clarify FEATURE_FORCE_LOAD's description. It allows to bypass + blocking not filtering and only does it if blocks aren't enforced. + Reported by: Robert Klemme - Unblock Stackexchange popup URLs that aren't used to serve ads. - Reported by David Wagner in #3615179. + FAQ: Remove Zwiebelfreunde e.V. from the list of fiduciary sponsors + As of 2021 they no longer handle donations for foreign organisations + due to lack of resources. - Disable fast-redirects for creativecommons.org/. + FAQ: Remove an obsolete comment with a link to the long-gone PDF manual. - Unblock .stopwatchingus.info/. + FAQ: Add a link to the TODO list. - Block requests for .adcash.com/script/. - Reported by Tyrexionibus in #3615289. + FAQ: Change the sponsor amounts to USD slightly rounding the + converted amounts up to get simple numbers. + Receiving USD is apparently easier for SPI and SPI is + preferred by sponsors as they can send invoices. - Disable HTML filters if the response was tagged as JavaScript. - Filtering JavaScript code with filters intended to deal with HTML - is usually a waste of time and, more importantly, may break stuff. + Advertise the client-tags CGI page in the user manual. - Use a custom redirect{} for .washingtonpost.com/wp-apps/imrs\.php\?src= - Previously enabling the 'Advanced' settings (or manually enabling - +fast-redirects{}) prevented some images from being loaded properly. + Stop advertising the show-version CGI page which no longer exists. - Unblock "adina*." Fixes #919 reported by Morton A. Goldberg. + Add yet another reason why +prevent-compression may cause problems. - Block '/.*DigiAd'. + Don't claim that contributors need ssh. It's only needed for committers. - Unblock 'adele*.'. Reported by Adele Lime in #1663. + Replace obsolete CVS instructions with Git instructions. - Disable banners-by-size for kggp.de/. + Remove an obsolete comment @@ -296,28 +402,30 @@ - Filter file improvements & bug fixes: + Config file changes: - Decrease the chances that js-annoyances creates invalid JavaScript. - Submitted by John McGowan on ijbswa-users@. + Change the suggested default-server-timeout to 5 to match the + suggested keep-alive-timeout. Otherwise using the defaults would + result in Privoxy reducing the default-server-timeout and logging + an error message. + Sponsored by: Robert Klemme - Let the msn filter hide 'related' ads again. + Update the 'debug 1' description. - Remove a stray '1' in the 'html-annoyances' filter. + Add a missing 'client-specific-tag' directive. - Prevent img-reorder from messing up img tags with empty src - attributes. Fixes #880 reported by Duncan. + Comment out trusted-cgi-referer pointing to example.org. @@ -325,110 +433,138 @@ - Documentation improvements: + Action file improvements: - Updated the 'Would you like to donate?' section. + Block requests to /(.*/)?piwik\.php + + + + + Block requests to .connectaserver.de/ + + + + + Block requests to pixel.inforsea.com/ + + + + + Block requests to t.vi-serve.com/ + + + + + Block requests to .ioam.de/ + + + + + Block requests to t.9gag.com/img.gif - Note that invalid forward-override{} parameter syntax isn't - detected until the parameter is used. + Block requests to .pixel.parsely.com/ as image - Add another +redirect{} example: a shortcut for illumos bugs. + Block requests to pixel.wp.com/ - Make it more obvious that many operating systems support log - rotation out of the box. + Disable fast-redirects for .librarything.com/ - Fixed dead links. Reported by Mark Nelson in #3614557. + Disable fast-redirects for issue.freebsdfoundation.org/ - Rephrased the 'Why is the configuration so complicated?' answer - to be slightly less condescending. Anonymously suggested in #3615122. + Disable fast-redirects for .twitter.com/.*origin=http - Be more explicit about accept-intercepted-requests's lack of MITM support. + Unblock belco24.de/ - Make 'demoronizer' FAQ entries more generic. + Add fast-redirects exception for .wikipedia.org/ - Add an example hostname to the --pre-chroot-nslookup description. + Add fast-redirects exception for oss-fuzz.com/ - Add an example for a host pattern that matches an IP address. + Disable fast-redirects for .consensu.org/delivery/pixel\.php + and block the requests as image instead - Rename the 'domain pattern' to 'host pattern' as it may - contain IP addresses as well. + Unblock .adbinstaller.com/ + Reported by lvm in #942. - Recommend forward-socks5t when using Tor. It seems to work fine and - modifying the Tor configuration to profit from it hasn't been necessary - for a while now. + Unblock .adbshell.com + Reported by lvm in #942. - Add another redirect{} example to stress that redirect loops can - and should be avoided. + Unblock .tagesschau.de/ - The usual spelling and grammar fixes. Parts of them were - reported by Reuben Thomas in #3615276. + Disable fast-redirects for collector.githubapp.com/ + and block requests to it as image instead - Mention the PCRS option letters T and D in the filter section. + Unblock 'ada*.' - Clarify that handle-as-empty-doc-returns-ok is still useful - and will not be removed without replacement. + Add fast-redirects{} exception for sourcepoint.vice.com/ - Note that security issues shouldn't be reported using the bug tracker. + Unblock adaway.org/ + Reported by DRS David Soft in AF#945. - Clarify what Privoxy does if both +block{} and +redirect{} apply. + Change two block reasons that previously were the same. + Sponsored by: Robert Klemme - Removed the obsolete bookmarklets section. + Added a +delay-response{} test. + + + + + Updated the location of the development version + of default.action.master. @@ -436,58 +572,160 @@ - Build system improvements: + Privoxy-Log-Parser: - Let --with-group properly deal with secondary groups. - Patch submitted by Anatoly Arzhnikov in #3615187. + Added a --keep-date option to keep the date in highlighted messages. + + + + + Highlight new log messages. + + + + + Make gather_loglevel_clf_stats() more tolerant. While at it, + count all CLF messages as requests, even if the request is invalid. + + + + + Only show HTTP version distribution if at least one version has been detected. + + + + + Only show crunch statistics if crunches were detected. + + + + + Warn if the request counts differ. + + + + + Generate statistics if the log only contains LOG_LEVEL_CLF messages + so it can be used with vanilla webserver logs. + Previously Privoxy-specific "Request:" messages were required. + + + + + Align the client-HTTP-version distribution like other distributions + + + + + Bump version to 0.9.1 + + + + + Include status code distribution in the stats. - Fix web-actions target. + Let the statistics include the size of the content Privoxy + transferred excluding HTTP headers. - Add a web-faq target that only updates the FAQ on the webserver. + Get with the program and expect all requests to be logged with LOG_LEVEL_REQUEST. + It's no longer necessary to count both LOG_LEVEL_REQUEST and + LOG_LEVEL_CRUNCH messages to get the total number of requests. - Remove already-commented-out non-portable DOSFILTER alternatives. + Leverage the LOG_LEVEL_CLF message to gather statistics that where + previously taken from LOG_LEVEL_HEADER lines. This results in less + confusing results if https inspection is enabled in which case there + are two LOG_LEVEL_HEADER lines with request lines. + Sponsored by: Robert Klemme - Remove the obsolete targets dok-put and dok-get. + Properly highlight the filter results message. Previously a brace got lost. - Add a sf-shell target. + Prefer the number of CLF lines to get the total number of requests + as it works with older Privoxy versions as well. + + + + + + + + Privoxy-Regression-Test: + + + + Turn curl's globbing mode off so we can allow more characters in URLs. + + + + + Allow '[' and ']' in URLs. + + + + + Include the action file when complaining about missing Sticky Actions. + + + + + Fix a sentence in the documentation. + + + + + Bump version to 0.7.1 - - - Known bugs: + url-pattern-translator: - + + + Detect a couple of pattern prefixes case-insensitively. + Sponsored by: Robert Klemme + + + + + Skip CLIENT-TAG patterns. + Sponsored by: Robert Klemme + + + - To compile with --disable-force you need this patch which - didn't make it into the release. - Thanks to Kai Raven for the report. + Skip patterns that have already been converted. + It should now be safe to "convert" a file multiple times. + Sponsored by: Robert Klemme + + + + + Add the new 'PCRE-HOST-PATTERN:' prefix. + Sponsored by: Robert Klemme - +