Skip to content

[2.4.x] Merge changes to mod_remoteip - #819

Open
notroj wants to merge 11 commits into
apache:2.4.xfrom
notroj:2.4.x-mod_remoteip
Open

notroj wants to merge 11 commits into
apache:2.4.xfrom
notroj:2.4.x-mod_remoteip

Conversation

@notroj

@notroj notroj commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator

Merge r1874344, r1933436, r1936258, r1936357, r1936366, r1938292, r1938908, r1938909, r1938927, r1938928 from trunk:

handle LOCAL ver_cmd proxy headers
bz 63893

fix support for rfc4291 (ipv6 mapped ipv4 addresses)
bz #69672

mod_remoteip: fix NULL dereference with PROXY v2 LOCAL command

  • modules/metadata/mod_remoteip.c (remoteip_process_v2_header): Set
    conn_conf->client_addr and client_ip for the LOCAL case, matching
    the v1 UNKNOWN path.

Assisted-by: Claude Sonnet 4.6 noreply@anthropic.com
GitHub: PR #685

mod_remoteip: Validate v2 PROXY protocol address length

  • modules/metadata/mod_remoteip.c
    (remoteip_get_v2_len): Move definition before first use.
    (remoteip_parse_v2_header): Add length validation for TCPv4
    and TCPv6 address families before parsing, returning HDR_ERROR
    if the header length is too short.

Submitted by: arshiya tabasum
GitHub: closes #683

Fill in APLOGNO() missed in r1936357.

  • modules/metadata/mod_remoteip.c (remoteip_modify_request): Trim
    trailing spaces using a one-past-the-end pointer, so the pointer is
    never decremented to before the start of the buffer when the
    token is empty. Test for an empty token with equality instead.

  • test/modules/proxy/test_03_response.py (TestProxyResponse): Add
    127.0.0.1 as a trusted RemoteIP proxy.
    (test_proxy_03_005): New test: an X-Forwarded-For header ending in
    an empty token must still get a 200 response.

Submitted by: Robert McConnell
GitHub: closes #756

mod_remoteip: Apply RemoteIP{Trusted,Internal}ProxyList to the virtual host
they are configured in, and fix merging.

  • modules/metadata/mod_remoteip.c
    (merge_remoteip_server_config): When both the main server and the virtual
    host have proxymatch_ip entries, merge the two arrays.
    (remoteip_hook_post_config): Log a warning (APLOGNO 10633) for each
    virtual host whose proxy entries were merged with the main server's.
    (remoteip_cmds): Drop EXEC_ON_READ from RemoteIPTrustedProxyList and
    RemoteIPInternalProxyList so the directives apply in the server/vhost
    scope they are configured in, rather than globally at config read time.

PR: 70207
Submitted by: Arturo Bernal
GitHub: closes #793

  • modules/metadata/mod_remoteip.c (remoteip_hook_post_config):
    Use the passed-in pointer to ap_server_conf; no functional change.

mod_remoteip: PROXY protocol: handle a peer going away before the header.

  • modules/metadata/mod_remoteip.c (remoteip_input_filter): Log EOF while
    reading the PROXY protocol header at info level, as the peer going away;
    other read errors are still logged as errors. Skip metadata buckets
    rather than copying from them: the EOS bucket arriving before the EOF
    was passed to memcpy() as a NULL source.

PR: 63893
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
GitHub: closes #805

  • modules/metadata/mod_remoteip.c: Add missing APLOGNO.

The test changes under test/modules/metadata/ in r1938908 and r1938927 are omitted, since that suite does not exist on 2.4.x; the move of test_proxy_03_004 in r1938292 is omitted for the same reason. With all ten applied, mod_remoteip.c is byte-identical to trunk's.

🤖 Generated with Claude Code

bigio and others added 11 commits October 10, 2026 08:15
bz 63893

(cherry picked from commit f7448ff)
* modules/metadata/mod_remoteip.c (remoteip_process_v2_header): Set
  conn_conf->client_addr and client_ip for the LOCAL case, matching
  the v1 UNKNOWN path.

Assisted-by: Claude Sonnet 4.6 <noreply@anthropic.com>
GitHub: PR apache#685

(cherry picked from commit 22dc622)
* modules/metadata/mod_remoteip.c
  (remoteip_get_v2_len): Move definition before first use.
  (remoteip_parse_v2_header): Add length validation for TCPv4
  and TCPv6 address families before parsing, returning HDR_ERROR
  if the header length is too short.

Submitted by: arshiya tabasum <arshi bugqore.com>
GitHub: closes apache#683

(cherry picked from commit 7c6129b)
(cherry picked from commit f6c2694cc27cbfe848d6ed25c3b08a455087052c)
not present in 2.4.x):

* modules/metadata/mod_remoteip.c (remoteip_modify_request): Trim
  trailing spaces using a one-past-the-end pointer, so the pointer is
  never decremented to before the start of the buffer when the
  token is empty.  Test for an empty token with equality instead.

* test/modules/proxy/test_03_response.py (TestProxyResponse): Add
  127.0.0.1 as a trusted RemoteIP proxy.
  (test_proxy_03_005): New test: an X-Forwarded-For header ending in
  an empty token must still get a 200 response.

Submitted by: Robert McConnell <robert mcc0nnell.org>
GitHub: closes apache#756

(cherry picked from commit 82313d0)
mod_remoteip: Apply RemoteIP{Trusted,Internal}ProxyList to the virtual host
they are configured in, and fix merging.

* modules/metadata/mod_remoteip.c
  (merge_remoteip_server_config): When both the main server and the virtual
  host have proxymatch_ip entries, merge the two arrays.
  (remoteip_hook_post_config): Log a warning (APLOGNO 10633) for each
  virtual host whose proxy entries were merged with the main server's.
  (remoteip_cmds): Drop EXEC_ON_READ from RemoteIPTrustedProxyList and
  RemoteIPInternalProxyList so the directives apply in the server/vhost
  scope they are configured in, rather than globally at config read time.

PR: 70207
Submitted by: Arturo Bernal <abernal apache.org>
GitHub: closes apache#793

(cherry picked from commit 47717ee2e4e14cbec940f5b644135a09711f30f9)
  Use the passed-in pointer to ap_server_conf; no functional change.

(cherry picked from commit 845c5e9)
mod_remoteip: PROXY protocol: handle a peer going away before the header.

* modules/metadata/mod_remoteip.c (remoteip_input_filter): Log EOF while
  reading the PROXY protocol header at info level, as the peer going away;
  other read errors are still logged as errors.  Skip metadata buckets
  rather than copying from them: the EOS bucket arriving before the EOF
  was passed to memcpy() as a NULL source.

PR: 63893
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
GitHub: closes apache#805

(cherry picked from commit 3f95bd3fe6908f95e5a023ea1f52a16f0b0bdbf2)
(cherry picked from commit cea73f6f0894e92e37d0b0a93c1b0f1b43cab8d6)
  shipped in 2.4.x.

* changes-entries/remoteip-pp-eof.txt: Drop the undefined-memcpy()
  clause, which is not user-visible.

[skip ci]

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants