Fabian Keil [Wed, 10 Feb 2021 02:39:23 +0000 (03:39 +0100)]
ssl_send_certificate_error(): Respect HEAD requests by not sending a body
Fabian Keil [Wed, 10 Feb 2021 02:33:46 +0000 (03:33 +0100)]
ssl_send_certificate_error(): End body with a single new line
Fabian Keil [Mon, 15 Feb 2021 15:47:03 +0000 (16:47 +0100)]
serve(): Increase the chances that the host is logged
... when closing a server socket.
Fabian Keil [Sat, 13 Feb 2021 21:36:51 +0000 (22:36 +0100)]
OpenSSL: Log the TLS version and the the cipher used
Fabian Keil [Sun, 14 Feb 2021 14:08:04 +0000 (15:08 +0100)]
Bump copyright
Fabian Keil [Sun, 14 Feb 2021 14:02:05 +0000 (15:02 +0100)]
Unblock requests to adri*.
Fabian Keil [Sat, 13 Feb 2021 21:49:18 +0000 (22:49 +0100)]
mbedTLS: Log the TLS version and cipher suite
Fabian Keil [Fri, 12 Feb 2021 20:46:26 +0000 (21:46 +0100)]
privoxy-log-parser: Highlight: "Evaluating tag 'change-tor-socks-port' for client 127.0.0.1. End of life
1613162302."
Fabian Keil [Fri, 12 Feb 2021 20:42:26 +0000 (21:42 +0100)]
privoxy-log-parser: Highlight: "Tag 'change-tor-socks-port' for client 127.0.0.1 expired 1 seconds ago. Deleting it."
Fabian Keil [Fri, 12 Feb 2021 17:00:34 +0000 (18:00 +0100)]
OpenSSL ssl_store_cert(): Fix two error messages
Fabian Keil [Thu, 11 Feb 2021 17:26:54 +0000 (18:26 +0100)]
Block requests for trc*.taboola.com/
Fabian Keil [Thu, 11 Feb 2021 17:21:44 +0000 (18:21 +0100)]
Disable fast-redirects for .linkedin.com/
Fabian Keil [Thu, 11 Feb 2021 11:35:09 +0000 (12:35 +0100)]
privoxy-regression-test: Bump version to 0.7.3
Fabian Keil [Thu, 11 Feb 2021 11:34:48 +0000 (12:34 +0100)]
privoxy-regression-test: Add the --check-bad-ssl option to the --help output
Fabian Keil [Tue, 9 Feb 2021 15:59:51 +0000 (16:59 +0100)]
Terminate the body of the HTTP snipplets with a single new line instead of \r\n
Fabian Keil [Tue, 9 Feb 2021 15:13:03 +0000 (16:13 +0100)]
OpenSSL ssl_store_cert(): Fix a format specifier
Fabian Keil [Tue, 9 Feb 2021 15:12:42 +0000 (16:12 +0100)]
Fix a couple of format specifiers
Fabian Keil [Mon, 8 Feb 2021 14:58:03 +0000 (15:58 +0100)]
log_error(): Treat LOG_LEVEL_FATAL as fatal even when --stfu is being used
Reported by: Joshua Rogers (Opera).
Fabian Keil [Sat, 6 Feb 2021 21:36:23 +0000 (22:36 +0100)]
Update cgi_send_banner()'s comment header
Logo support has been removed in 2002 (
2fd9e77391d).
Fabian Keil [Sat, 6 Feb 2021 10:07:13 +0000 (11:07 +0100)]
fuzz_server_header(): Fix compiler warning
Fabian Keil [Sat, 6 Feb 2021 10:07:03 +0000 (11:07 +0100)]
fuzz_client_header(): Fix compiler warning
Fabian Keil [Fri, 5 Feb 2021 04:27:38 +0000 (05:27 +0100)]
privoxy-log-parser.pl: Let highlight_request_line() tolerate 'Failed reading chunked client body'
Fabian Keil [Fri, 5 Feb 2021 04:13:29 +0000 (05:13 +0100)]
privoxy-log-parser.pl: Let gather_loglevel_clf_stats() tolerate another 'invalid' log message
Fabian Keil [Thu, 4 Feb 2021 18:05:35 +0000 (19:05 +0100)]
list_is_valid(): Remove '#if 1' block around the function body
The function can be disabled by compiling with NDEBUG now.
Fabian Keil [Thu, 4 Feb 2021 12:54:28 +0000 (13:54 +0100)]
configure: Bump copyright
Fabian Keil [Thu, 4 Feb 2021 12:54:07 +0000 (13:54 +0100)]
configure: Add --with-assertions option and only enable assertions when it is used
Fabian Keil [Thu, 4 Feb 2021 12:43:37 +0000 (13:43 +0100)]
decompress_iob(): Silence compiler warning when compiling with NDEBUG
Fabian Keil [Thu, 4 Feb 2021 12:40:42 +0000 (13:40 +0100)]
Only compile list_is_valid() when NDEBUG is undefined
Fabian Keil [Thu, 4 Feb 2021 12:38:09 +0000 (13:38 +0100)]
log_error(): Silence a warning when compiling with NDEBUG
Lee [Sun, 21 Feb 2021 13:47:26 +0000 (08:47 -0500)]
windows build: have to include extra libraries for a mingw build
or maybe it's the way I build the stand-alone library? dunno, but
building with mingw also needs "-lbrotlicommon -lbrotlienc" added
to $LIBS
Lee [Sun, 21 Feb 2021 13:43:03 +0000 (08:43 -0500)]
windows build: default build now uses --with-brotli
Lee [Sun, 21 Feb 2021 13:39:40 +0000 (08:39 -0500)]
windows build: default is now --with-mbedtls
Lee [Thu, 18 Feb 2021 17:56:51 +0000 (12:56 -0500)]
windows: static link privoxy with an external pcre library
The pcre code included with Privoy is very old. This at
least gets us up to the current PCRE 8.X library code.
Lee [Thu, 18 Feb 2021 17:53:36 +0000 (12:53 -0500)]
windows: enable dynamic error checking
I decided it was silly to have this stuff turned on just for testing
or turned on just for me.
Lee [Thu, 18 Feb 2021 16:22:38 +0000 (11:22 -0500)]
allow building privoxy with a statically linked external pcre library on windows
see /usr/i686-w64-mingw32/sys-root/mingw/include/pcre.h line 54
#if defined(_WIN32) && !defined(PCRE_STATIC)
# ifndef PCRE_EXP_DECL
# define PCRE_EXP_DECL extern __declspec(dllimport)
# endif
If you want to statically link a program against a PCRE library in the form of
a non-dll .a file, you must define PCRE_STATIC before including pcre.h or
pcrecpp.h, otherwise the pcre_malloc() and pcre_free() exported functions will
be declared __declspec(dllimport), with unwanted results.
Lee [Thu, 18 Feb 2021 16:17:37 +0000 (11:17 -0500)]
don't assume NSIS is in privoxy git
I wanted NSIS included with Privoxy
Fabian didn't want binaries in the git tree
So install NSIS outside of the Privoxy source code and stop
having to remember to update the location of the NSIS code
when releasing a new version of Privoxy.
Fabian Keil [Thu, 18 Feb 2021 02:24:26 +0000 (03:24 +0100)]
Add #192: The client TLS contexts should probably be shared among threads
Fabian Keil [Fri, 12 Feb 2021 13:35:07 +0000 (14:35 +0100)]
Add #191: The cipher-list directive should be split
Fabian Keil [Sun, 7 Feb 2021 14:17:55 +0000 (15:17 +0100)]
Add #190: The socks5 authentication code should send user name an password seperately
Fabian Keil [Sat, 6 Feb 2021 14:28:47 +0000 (15:28 +0100)]
TODO #170: Fix typo
Fabian Keil [Sun, 7 Feb 2021 13:32:16 +0000 (14:32 +0100)]
Add #189: Bring back binary packages for macOS
Fabian Keil [Sat, 6 Feb 2021 21:30:05 +0000 (22:30 +0100)]
privoxy-log-parser: Highlight 'Complete client request followed by 59 bytes of pipelined data received.'
Fabian Keil [Thu, 4 Feb 2021 15:43:35 +0000 (16:43 +0100)]
Add CVEs for security issues fixed in 3.0.31
Fabian Keil [Tue, 2 Feb 2021 11:13:39 +0000 (12:13 +0100)]
handle_established_connection(): Add parentheses to clarify an expression
Suggested by: David Binderman
Fabian Keil [Tue, 2 Feb 2021 10:22:03 +0000 (11:22 +0100)]
Add CVEs for security issues fixed in 3.0.29
Fabian Keil [Mon, 1 Feb 2021 12:14:16 +0000 (13:14 +0100)]
continue_https_chat(): Explicitly unset CSP_FLAG_CLIENT_CONNECTION_KEEP_ALIVE
... if process_encrypted_request() fails.
This makes it more obvious that the connection will not be reused.
Previously serve() relied on CSP_FLAG_SERVER_CONTENT_LENGTH_SET
and CSP_FLAG_CHUNKED being unset.
Inspired by a patch from Joshua Rogers.
Fabian Keil [Fri, 29 Jan 2021 11:16:22 +0000 (12:16 +0100)]
decompress_iob(): Improve a comment
Fabian Keil [Thu, 28 Jan 2021 20:10:28 +0000 (21:10 +0100)]
decompress_iob(): Add periods to a couple of log messages
Fabian Keil [Thu, 28 Jan 2021 10:58:07 +0000 (11:58 +0100)]
developer-manual: Add pushing the created tag to the release steps
Fabian Keil [Tue, 26 Jan 2021 09:28:48 +0000 (10:28 +0100)]
cgi_send_user_manual(): Also reject requests if the user-manual
... directive specifies a https:// URL.
Previously Privoxy would try and fail to open a local file.
Fabian Keil [Wed, 3 Feb 2021 10:10:34 +0000 (11:10 +0100)]
Rebuild HTML man page for 3.0.32 UNRELEASED
Fabian Keil [Wed, 3 Feb 2021 10:09:51 +0000 (11:09 +0100)]
Rebuild man page for 3.0.32 UNRELEASED
Fabian Keil [Wed, 3 Feb 2021 10:09:17 +0000 (11:09 +0100)]
Rebuild docs for 3.0.32 UNRELEASED
Fabian Keil [Wed, 3 Feb 2021 10:05:46 +0000 (11:05 +0100)]
Bump SMGL entities for 3.0.32 UNRELEASED
Fabian Keil [Tue, 2 Feb 2021 10:59:05 +0000 (11:59 +0100)]
Bump version to 3.0.32 UNRELEASED
Fabian Keil [Sun, 31 Jan 2021 09:40:31 +0000 (10:40 +0100)]
Update RSS feed for the 3.0.31 releases
Roland Rosenfeld [Sat, 30 Jan 2021 21:04:14 +0000 (22:04 +0100)]
Debian: Merge 3.0.31 release and prepare 3.0.32 GIT snapshot.
Roland Rosenfeld [Sat, 30 Jan 2021 21:05:02 +0000 (22:05 +0100)]
debian/copyright updated to new version.
Lee [Sat, 30 Jan 2021 19:13:16 +0000 (14:13 -0500)]
remember to configure the locally installed docs in config.txt
Fabian Keil [Sat, 30 Jan 2021 16:58:12 +0000 (17:58 +0100)]
Regenerate config file for 3.0.31 stable
Fabian Keil [Sat, 30 Jan 2021 16:56:52 +0000 (17:56 +0100)]
Regenerate HTML man page
Fabian Keil [Sat, 30 Jan 2021 16:54:34 +0000 (17:54 +0100)]
Rebuild man page for 3.0.31 stable
Fabian Keil [Sat, 30 Jan 2021 16:46:55 +0000 (17:46 +0100)]
Update announcement for Privoxy 3.0.31 stable
Fabian Keil [Sat, 30 Jan 2021 16:34:42 +0000 (17:34 +0100)]
Rebuild docs for 3.0.31 stable
Fabian Keil [Sat, 30 Jan 2021 16:36:42 +0000 (17:36 +0100)]
Bump SMGL entities for 3.0.31 stable
Fabian Keil [Sat, 30 Jan 2021 16:33:19 +0000 (17:33 +0100)]
Add Joshua Rogers as contributor
Fabian Keil [Sat, 30 Jan 2021 16:31:33 +0000 (17:31 +0100)]
Import changes for Privoxy 3.0.31 stable
Fabian Keil [Sat, 30 Jan 2021 16:10:55 +0000 (17:10 +0100)]
Add ChangeLog entries for 3.0.31 stable
Fabian Keil [Thu, 28 Jan 2021 17:02:56 +0000 (18:02 +0100)]
decompress_iob(): Fix a memory leak
... when decompression fails "unexpectedly".
OVE-
20210128-0001.
Fabian Keil [Thu, 28 Jan 2021 15:26:45 +0000 (16:26 +0100)]
decompress_iob(): Fix detection of insufficient data
Instead of checking the size of the iob we have to
check the size of the actual data.
Previously Privoxy could try to work on uninitialized data.
Fabian Keil [Sat, 30 Jan 2021 14:04:17 +0000 (15:04 +0100)]
parse_cgi_parameters(): Make sure the maximum number of segments is large enough
... for ssplit() to succeed.
Prevents an assertion from getting triggered. OVE-
20210130-0001.
Reported by: Joshua Rogers (Opera)
Fabian Keil [Sat, 30 Jan 2021 16:02:48 +0000 (17:02 +0100)]
Bump version to 3.0.31 stable
Roland Rosenfeld [Fri, 29 Jan 2021 16:50:02 +0000 (17:50 +0100)]
Debian: Support nodoc build option.
Roland Rosenfeld [Fri, 29 Jan 2021 16:49:28 +0000 (17:49 +0100)]
debian/source/lintian-overrides: Remove unused override.
Roland Rosenfeld [Thu, 28 Jan 2021 20:56:00 +0000 (21:56 +0100)]
Fix debian version number.
Fabian Keil [Thu, 28 Jan 2021 10:35:49 +0000 (11:35 +0100)]
Rebuild config file
Fabian Keil [Thu, 28 Jan 2021 10:34:51 +0000 (11:34 +0100)]
Add missing actionsfile directive
Fabian Keil [Wed, 27 Jan 2021 16:43:04 +0000 (17:43 +0100)]
windows: Enable extended statistics and pcre host patterns
... when configuring.
No objections from: Lee
Fabian Keil [Tue, 26 Jan 2021 08:08:51 +0000 (09:08 +0100)]
Rebuild HTML man page
Fabian Keil [Tue, 26 Jan 2021 08:08:02 +0000 (09:08 +0100)]
Rebuild man page
Fabian Keil [Tue, 26 Jan 2021 08:06:58 +0000 (09:06 +0100)]
Rebuild docs
Fabian Keil [Tue, 26 Jan 2021 08:05:45 +0000 (09:05 +0100)]
Add two new ChangeLog entries
Fabian Keil [Tue, 26 Jan 2021 08:02:54 +0000 (09:02 +0100)]
announcement: Add two new ChangeLog entries
Fabian Keil [Tue, 26 Jan 2021 08:00:52 +0000 (09:00 +0100)]
Add two more ChangeLog entries
Fabian Keil [Tue, 26 Jan 2021 06:57:38 +0000 (07:57 +0100)]
Bump copyright
Fabian Keil [Tue, 26 Jan 2021 06:29:37 +0000 (07:29 +0100)]
Let the uninstall target remove the config file if DESTDIR is set
... and properly announce the deletion of the configuration files.
Apparently I broke this in 2008 (
cc77d4eec4).
Fabian Keil [Tue, 26 Jan 2021 06:21:15 +0000 (07:21 +0100)]
Update MAN_DEST to use man section 8
Fabian Keil [Mon, 25 Jan 2021 20:33:01 +0000 (21:33 +0100)]
Fix a regression test
Even with FEATURE_GRACEFUL_TERMINATION enabled the request
for http://p.p/die will result in status code 403 as no
trusted Referer is set.
Fabian Keil [Mon, 25 Jan 2021 17:55:06 +0000 (18:55 +0100)]
Only compile ssl_release() when FEATURE_GRACEFUL_TERMINATION is enabled
Fabian Keil [Mon, 25 Jan 2021 15:56:29 +0000 (16:56 +0100)]
Fix build with LibreSSL 3.3.1
Fabian Keil [Mon, 25 Jan 2021 13:35:13 +0000 (14:35 +0100)]
announcement: Add Windows 10 to the list of supported operating systems
Fabian Keil [Mon, 25 Jan 2021 13:34:13 +0000 (14:34 +0100)]
announcement: Use the participate and donate redirect links
Fabian Keil [Mon, 25 Jan 2021 13:32:50 +0000 (14:32 +0100)]
Update announcement for 3.0.30 stable
Fabian Keil [Mon, 25 Jan 2021 13:17:17 +0000 (14:17 +0100)]
Rebuild user manual with changes for 3.0.30 stable
Fabian Keil [Mon, 25 Jan 2021 13:16:56 +0000 (14:16 +0100)]
Import changes for 3.0.30 stable
Fabian Keil [Mon, 25 Jan 2021 13:11:27 +0000 (14:11 +0100)]
Polish ChangeLog entries for 3.0.30 stable
Fabian Keil [Sun, 24 Jan 2021 11:26:57 +0000 (12:26 +0100)]
privoxy-regression-test: Bump copyright
Fabian Keil [Sun, 24 Jan 2021 11:25:54 +0000 (12:25 +0100)]
privoxy-regression-test: Add a --check-bad-ssl option
... that can be used to verify that Privoxy detects
certificate problems when accessing the test sites
from badssl.com.
Fabian Keil [Sun, 24 Jan 2021 11:00:45 +0000 (12:00 +0100)]
ssl_send_certificate_error(): Update the LOG_LEVEL_CLF message to use status code 403
Follow-up for
f048c3c93d1.
Fabian Keil [Sat, 23 Jan 2021 18:37:20 +0000 (19:37 +0100)]
Minor ChangeLog improvements