Please be sure that the following two are included in 1.7.1 :

PR 63491 regression in 1.7, see https://www.apachelounge.com/viewtopic.php?p=39558 PR 61165 CPU deadlock under load, see https://github.com/SpiderLabs/ModSecurity/issues/2181


Steffen



On Friday 10/09/2021 at 00:00, William A Rowe Jr  wrote:
Just as a reminder, with the goal to drop 1.7 apr and 1.7 apr-util
releases in one week,
please observe the practices in other projects and ask for 2 more sets
of eyeballs for
3 validated +1's on patches before backporting to these trees for the
next week. TIA!

I've had some success tweaking the abts framework to accomplish some
win32 fileinfo
validation of my proposed patch, so I should land that for willing
reviewers by CoB
tomorrow. I know we have several associated with the Subversion PMC willing to
lend a review, but I'll be following the same process with these fixes
to cure, and
further solve the apr 1.6.0 original and 1.7.1 release quirks with
mount symlinks.

Bill

On Thu, Sep 2, 2021 at 8:44 PM William A Rowe Jr <wr...@rowe-clan.net> wrote:


I'm willing to RM APR and APR-util 1.7 releases.

Would propose we set a date out 2 weeks, anything lingering needs
to be finalized with the usual oversight no later than the 8th, and
we tag on the 14th, announce on the 15th when the mirrors have
caught up. That gives enough days for committers to review the
last changes to these release branches.

But I'd be happier co-RM'ing this with a newer committer/PMC
participant who wants to learn the ropes. Any volunteers?
Other thoughts or observations?

On Tue, Aug 31, 2021 at 3:09 AM Rainer Jung <rainer.j...@kippdata.de> wrote:


Hi there,

any chance we find an RM for a APR 1.7.1 release? At least there was the fix for CVE-2021-35940 and CHANGES contains 15 more items (many of them
platform specific or build improvements). Last release 1.7.0 was in
April 2019.

For APR-util I don't know the current state and release needs for the
1.6.x and 1.7.x branches. Last 1.6.x release was in October 2017, 1.7.x
has never been released. CHANGES for 1.6.x only contains one
apr_dbm_gdbm fix plus a minor libtool use improvement.

Apache httpd is planing to start a release cycle soon and it would be
nice to have a clean APR 1.7.1 and maybe APR-util also.

Thanks and regards,

Rainer

Reply via email to