From 97f32c47046e716ea8e57ba992c0cb7390d8c165 Mon Sep 17 00:00:00 2001 From: Giovanni Bechis Date: Fri, 21 Feb 2020 23:19:07 +0000 Subject: [PATCH 01/11] handle LOCAL ver_cmd proxy headers bz 63893 (cherry picked from commit f7448ffe8209359ebb000dcd60751dd17f2f79f0) --- modules/metadata/mod_remoteip.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index 045e9887be3..e88c9c9ee6e 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -948,6 +948,9 @@ static remoteip_parse_status_t remoteip_process_v2_header(conn_rec *c, apr_status_t ret; switch (hdr->v2.ver_cmd & 0xF) { + case 0x00: /* LOCAL command */ + /* keep local connection address for LOCAL */ + return HDR_DONE; case 0x01: /* PROXY command */ switch (hdr->v2.fam) { case 0x11: /* TCPv4 */ From 459ae9d5e28220aa514158bca4571eb270694058 Mon Sep 17 00:00:00 2001 From: Giovanni Bechis Date: Tue, 28 Apr 2026 15:50:40 +0000 Subject: [PATCH 02/11] fix support for rfc4291 (ipv6 mapped ipv4 addresses) bz #69672 (cherry picked from commit 035316f9ac9c8fc04a2584d2f0957b448447f3e3) --- modules/metadata/mod_remoteip.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index e88c9c9ee6e..27a42d3cd37 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -813,7 +813,7 @@ static remoteip_parse_status_t remoteip_process_v1_header(conn_rec *c, else if (strcmp(word, "TCP6") == 0) { #if APR_HAVE_IPV6 family = APR_INET6; - valid_addr_chars = "0123456789abcdefABCDEF:"; + valid_addr_chars = "0123456789abcdefABCDEF:."; #else ap_log_cerror(APLOG_MARK, APLOG_ERR, 0, c, APLOGNO(03498) "RemoteIPProxyProtocol: Unable to parse v6 address - APR is not compiled with IPv6 support"); From 890bca96b862fa036697b47e484dfff5eda56e23 Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Fri, 17 Jul 2026 12:12:05 +0000 Subject: [PATCH 03/11] mod_remoteip: fix NULL dereference with PROXY v2 LOCAL command * modules/metadata/mod_remoteip.c (remoteip_process_v2_header): Set conn_conf->client_addr and client_ip for the LOCAL case, matching the v1 UNKNOWN path. Assisted-by: Claude Sonnet 4.6 GitHub: PR #685 (cherry picked from commit 22dc622fc5c1cefcca4a889560ccc08a0592d2a4) --- changes-entries/remoteip-proxy-v2-local.txt | 2 ++ modules/metadata/mod_remoteip.c | 2 ++ 2 files changed, 4 insertions(+) create mode 100644 changes-entries/remoteip-proxy-v2-local.txt diff --git a/changes-entries/remoteip-proxy-v2-local.txt b/changes-entries/remoteip-proxy-v2-local.txt new file mode 100644 index 00000000000..c2b240b7e3c --- /dev/null +++ b/changes-entries/remoteip-proxy-v2-local.txt @@ -0,0 +1,2 @@ + *) mod_remoteip: Fix crash with PROXY v2 LOCAL command and + RemoteIPProxyProtocol enabled. [Joe Orton] diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index 27a42d3cd37..eaa2d7c7926 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -950,6 +950,8 @@ static remoteip_parse_status_t remoteip_process_v2_header(conn_rec *c, switch (hdr->v2.ver_cmd & 0xF) { case 0x00: /* LOCAL command */ /* keep local connection address for LOCAL */ + conn_conf->client_addr = c->client_addr; + conn_conf->client_ip = c->client_ip; return HDR_DONE; case 0x01: /* PROXY command */ switch (hdr->v2.fam) { From d517fd514d2ae213fe6cf95b3dd6b35f71117659 Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Mon, 20 Jul 2026 10:08:18 +0000 Subject: [PATCH 04/11] mod_remoteip: Validate v2 PROXY protocol address length * modules/metadata/mod_remoteip.c (remoteip_get_v2_len): Move definition before first use. (remoteip_parse_v2_header): Add length validation for TCPv4 and TCPv6 address families before parsing, returning HDR_ERROR if the header length is too short. Submitted by: arshiya tabasum GitHub: closes #683 (cherry picked from commit 7c6129b51935d9165241279637915eaf905c58f1) --- modules/metadata/mod_remoteip.c | 26 ++++++++++++++++++++------ 1 file changed, 20 insertions(+), 6 deletions(-) diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index eaa2d7c7926..6b22225223e 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -931,6 +931,12 @@ static int remoteip_hook_pre_connection(conn_rec *c, void *csd) return OK; } +/** Return length for a v2 protocol header. */ +static apr_size_t remoteip_get_v2_len(proxy_header *hdr) +{ + return ntohs(hdr->v2.len); +} + /* Binary format: * * sig = \x0D \x0A \x0D \x0A \x00 \x0D \x0A \x51 \x55 \x49 \x54 \x0A @@ -956,6 +962,13 @@ static remoteip_parse_status_t remoteip_process_v2_header(conn_rec *c, case 0x01: /* PROXY command */ switch (hdr->v2.fam) { case 0x11: /* TCPv4 */ + if (remoteip_get_v2_len(hdr) < sizeof(hdr->v2.addr.ip4)) { + ap_log_cerror(APLOG_MARK, APLOG_ERR, 0, c, APLOGNO() + "RemoteIPProxyProtocol: address length " + "%" APR_SIZE_T_FMT " too short for TCPv4", + remoteip_get_v2_len(hdr)); + return HDR_ERROR; + } ret = apr_sockaddr_info_get(&conn_conf->client_addr, NULL, APR_INET, ntohs(hdr->v2.addr.ip4.src_port), @@ -973,6 +986,13 @@ static remoteip_parse_status_t remoteip_process_v2_header(conn_rec *c, case 0x21: /* TCPv6 */ #if APR_HAVE_IPV6 + if (remoteip_get_v2_len(hdr) < sizeof(hdr->v2.addr.ip6)) { + ap_log_cerror(APLOG_MARK, APLOG_ERR, 0, c, APLOGNO() + "RemoteIPProxyProtocol: address length " + "%" APR_SIZE_T_FMT " too short for TCPv6", + remoteip_get_v2_len(hdr)); + return HDR_ERROR; + } ret = apr_sockaddr_info_get(&conn_conf->client_addr, NULL, APR_INET6, ntohs(hdr->v2.addr.ip6.src_port), @@ -1019,12 +1039,6 @@ static remoteip_parse_status_t remoteip_process_v2_header(conn_rec *c, return HDR_DONE; } -/** Return length for a v2 protocol header. */ -static apr_size_t remoteip_get_v2_len(proxy_header *hdr) -{ - return ntohs(hdr->v2.len); -} - /** Determine if this is a v1 or v2 PROXY header. */ static int remoteip_determine_version(conn_rec *c, const char *ptr) From ceb8e4c6c6836072ce95ebf37aa36d906277fdbc Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Mon, 20 Jul 2026 11:30:00 +0000 Subject: [PATCH 05/11] Fill in APLOGNO() missed in r1936357. (cherry picked from commit f6c2694cc27cbfe848d6ed25c3b08a455087052c) --- modules/metadata/mod_remoteip.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index 6b22225223e..805c6543ea5 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -963,7 +963,7 @@ static remoteip_parse_status_t remoteip_process_v2_header(conn_rec *c, switch (hdr->v2.fam) { case 0x11: /* TCPv4 */ if (remoteip_get_v2_len(hdr) < sizeof(hdr->v2.addr.ip4)) { - ap_log_cerror(APLOG_MARK, APLOG_ERR, 0, c, APLOGNO() + ap_log_cerror(APLOG_MARK, APLOG_ERR, 0, c, APLOGNO(10597) "RemoteIPProxyProtocol: address length " "%" APR_SIZE_T_FMT " too short for TCPv4", remoteip_get_v2_len(hdr)); @@ -987,7 +987,7 @@ static remoteip_parse_status_t remoteip_process_v2_header(conn_rec *c, case 0x21: /* TCPv6 */ #if APR_HAVE_IPV6 if (remoteip_get_v2_len(hdr) < sizeof(hdr->v2.addr.ip6)) { - ap_log_cerror(APLOG_MARK, APLOG_ERR, 0, c, APLOGNO() + ap_log_cerror(APLOG_MARK, APLOG_ERR, 0, c, APLOGNO(10598) "RemoteIPProxyProtocol: address length " "%" APR_SIZE_T_FMT " too short for TCPv6", remoteip_get_v2_len(hdr)); From 4f7607e53e8ce5f9b82e3509f2393f5c17a2c75a Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Wed, 16 Sep 2026 14:36:32 +0000 Subject: [PATCH 06/11] Merge r1938292 from trunk (test_proxy_03_004 move omitted, the test is not present in 2.4.x): * modules/metadata/mod_remoteip.c (remoteip_modify_request): Trim trailing spaces using a one-past-the-end pointer, so the pointer is never decremented to before the start of the buffer when the token is empty. Test for an empty token with equality instead. * test/modules/proxy/test_03_response.py (TestProxyResponse): Add 127.0.0.1 as a trusted RemoteIP proxy. (test_proxy_03_005): New test: an X-Forwarded-For header ending in an empty token must still get a 200 response. Submitted by: Robert McConnell GitHub: closes #756 (cherry picked from commit 82313d0a9624d60ed97f601b31eecf619e21ebde) --- modules/metadata/mod_remoteip.c | 8 ++++---- test/modules/proxy/test_03_response.py | 11 +++++++++++ 2 files changed, 15 insertions(+), 4 deletions(-) diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index 805c6543ea5..e017d9aec4f 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -616,12 +616,12 @@ static int remoteip_modify_request(request_rec *r) ++parse_remote; } - eos = parse_remote + strlen(parse_remote) - 1; - while (eos >= parse_remote && *eos == ' ') { - *(eos--) = '\0'; + eos = parse_remote + strlen(parse_remote); + while (eos > parse_remote && eos[-1] == ' ') { + *--eos = '\0'; } - if (eos < parse_remote) { + if (eos == parse_remote) { if (remote) { *(remote + strlen(remote)) = ','; } diff --git a/test/modules/proxy/test_03_response.py b/test/modules/proxy/test_03_response.py index 60a4afa8af9..93f9825c99c 100644 --- a/test/modules/proxy/test_03_response.py +++ b/test/modules/proxy/test_03_response.py @@ -70,6 +70,7 @@ def _class_scope(self, env): conf.add([ "RemoteIPHeader X-Forwarded-For", "RemoteIPTrustedProxy 0.0.0.0", + "RemoteIPTrustedProxy 127.0.0.1", ]) conf.end_vhost() conf.install() @@ -122,3 +123,13 @@ def test_proxy_03_003(self, env): env.httpd_error_log.ignore_recent( lognos=["AH00957", "AH00959", "AH01114"] ) + + # a trailing empty RemoteIPHeader token must not underflow the trim pointer + def test_proxy_03_005(self, env): + if not env.has_shared_module("remoteip"): + pytest.skip("need mod_remoteip for this") + + r = env.curl_get(env.mkurl("http", "test1", "/forwarded"), options=[ + '-H', 'X-Forwarded-For: 192.0.2.1,', + ]) + assert r.response["status"] == 200 From 3931de7f76a8e3864ffa2d1f4acbc59074fd417b Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Thu, 8 Oct 2026 08:31:23 +0000 Subject: [PATCH 07/11] Merge r1938908 from trunk (test changes omitted): mod_remoteip: Apply RemoteIP{Trusted,Internal}ProxyList to the virtual host they are configured in, and fix merging. * modules/metadata/mod_remoteip.c (merge_remoteip_server_config): When both the main server and the virtual host have proxymatch_ip entries, merge the two arrays. (remoteip_hook_post_config): Log a warning (APLOGNO 10633) for each virtual host whose proxy entries were merged with the main server's. (remoteip_cmds): Drop EXEC_ON_READ from RemoteIPTrustedProxyList and RemoteIPInternalProxyList so the directives apply in the server/vhost scope they are configured in, rather than globally at config read time. PR: 70207 Submitted by: Arturo Bernal GitHub: closes #793 (cherry picked from commit 47717ee2e4e14cbec940f5b644135a09711f30f9) --- changes-entries/remoteip-proxylist-scope.txt | 4 ++ modules/metadata/mod_remoteip.c | 40 +++++++++++++++++--- 2 files changed, 38 insertions(+), 6 deletions(-) create mode 100644 changes-entries/remoteip-proxylist-scope.txt diff --git a/changes-entries/remoteip-proxylist-scope.txt b/changes-entries/remoteip-proxylist-scope.txt new file mode 100644 index 00000000000..7bcff9c51b3 --- /dev/null +++ b/changes-entries/remoteip-proxylist-scope.txt @@ -0,0 +1,4 @@ + *) mod_remoteip: Apply RemoteIP{Trusted,Internal}ProxyList to the virtual host + they are configured in, and merge the proxy entries of the main server + and of the virtual host, logging a warning when both have some. + PR 70207. [Arturo Bernal] diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index e017d9aec4f..da818e43edb 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -176,9 +176,18 @@ static void *merge_remoteip_server_config(apr_pool_t *p, void *globalv, config->proxies_header_name = server->proxies_header_name ? server->proxies_header_name : global->proxies_header_name; - config->proxymatch_ip = server->proxymatch_ip - ? server->proxymatch_ip - : global->proxymatch_ip; + if (server->proxymatch_ip && global->proxymatch_ip) { + /* Both have entries: merge them. remoteip_modify_request() uses the + * first match, so the more specific entries of the vhost go first. + */ + config->proxymatch_ip = apr_array_append(p, server->proxymatch_ip, + global->proxymatch_ip); + } + else { + config->proxymatch_ip = server->proxymatch_ip + ? server->proxymatch_ip + : global->proxymatch_ip; + } return config; } @@ -495,8 +504,9 @@ static const char *remoteip_disable_networks(cmd_parms *cmd, void *d, static int remoteip_hook_post_config(apr_pool_t *pconf, apr_pool_t *plog, apr_pool_t *ptemp, server_rec *s) { - remoteip_config_t *conf; + remoteip_config_t *conf, *vconf; remoteip_addr_info *info; + server_rec *vs; char buf[INET6_ADDRSTRLEN]; conf = ap_get_module_config(ap_server_conf->module_config, @@ -513,6 +523,24 @@ static int remoteip_hook_post_config(apr_pool_t *pconf, apr_pool_t *plog, "RemoteIPProxyProtocol: disabled on %s:%hu", buf, info->addr->port); } + /* A vhost with entries of its own got a new array in the config + * merge, otherwise it shares the one of the main server. Warn for + * this case (temporarily) since the behaviour has changed with + * the fix for PR 70207. */ + if (conf->proxymatch_ip) { + for (vs = s->next; vs; vs = vs->next) { + vconf = ap_get_module_config(vs->module_config, &remoteip_module); + if (vconf->proxymatch_ip + && vconf->proxymatch_ip != conf->proxymatch_ip) { + ap_log_error(APLOG_MARK, APLOG_WARNING, 0, vs, APLOGNO(10633) + "RemoteIP proxy entries are configured in both " + "the main server and the virtual host defined " + "at %s:%u, they are merged", + vs->defn_name, vs->defn_line_number); + } + } + } + return OK; } @@ -1247,11 +1275,11 @@ static const command_rec remoteip_cmds[] = "Specifies one or more internal (transparent) proxies " "which are trusted to present IP headers"), AP_INIT_TAKE1("RemoteIPTrustedProxyList", proxylist_read, 0, - RSRC_CONF | EXEC_ON_READ, + RSRC_CONF, "The filename to read the list of trusted proxies, " "see the RemoteIPTrustedProxy directive"), AP_INIT_TAKE1("RemoteIPInternalProxyList", proxylist_read, (void*)1, - RSRC_CONF | EXEC_ON_READ, + RSRC_CONF, "The filename to read the list of internal proxies, " "see the RemoteIPInternalProxy directive"), AP_INIT_FLAG("RemoteIPProxyProtocol", remoteip_enable_proxy_protocol, NULL, From e23b0ca15b2c4ea6917428dcb027592e051f17c8 Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Thu, 8 Oct 2026 08:36:22 +0000 Subject: [PATCH 08/11] * modules/metadata/mod_remoteip.c (remoteip_hook_post_config): Use the passed-in pointer to ap_server_conf; no functional change. (cherry picked from commit 845c5e9ae37755f11aa5063f2b29dff4657a6724) --- modules/metadata/mod_remoteip.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index da818e43edb..b1ff301c860 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -502,15 +502,14 @@ static const char *remoteip_disable_networks(cmd_parms *cmd, void *d, } static int remoteip_hook_post_config(apr_pool_t *pconf, apr_pool_t *plog, - apr_pool_t *ptemp, server_rec *s) + apr_pool_t *ptemp, server_rec *s) { remoteip_config_t *conf, *vconf; remoteip_addr_info *info; server_rec *vs; char buf[INET6_ADDRSTRLEN]; - conf = ap_get_module_config(ap_server_conf->module_config, - &remoteip_module); + conf = ap_get_module_config(s->module_config, &remoteip_module); for (info = conf->proxy_protocol_enabled; info; info = info->next) { apr_sockaddr_ip_getbuf(buf, sizeof(buf), info->addr); From c5a015d2356c6067a444ef18c457214c4c0c929a Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Thu, 8 Oct 2026 20:04:38 +0000 Subject: [PATCH 09/11] Merge r1938927 from trunk (test changes omitted): mod_remoteip: PROXY protocol: handle a peer going away before the header. * modules/metadata/mod_remoteip.c (remoteip_input_filter): Log EOF while reading the PROXY protocol header at info level, as the peer going away; other read errors are still logged as errors. Skip metadata buckets rather than copying from them: the EOS bucket arriving before the EOF was passed to memcpy() as a NULL source. PR: 63893 Co-Authored-By: Claude Fable 5.1 GitHub: closes #805 (cherry picked from commit 3f95bd3fe6908f95e5a023ea1f52a16f0b0bdbf2) --- changes-entries/remoteip-pp-eof.txt | 4 ++++ modules/metadata/mod_remoteip.c | 15 +++++++++++++++ 2 files changed, 19 insertions(+) create mode 100644 changes-entries/remoteip-pp-eof.txt diff --git a/changes-entries/remoteip-pp-eof.txt b/changes-entries/remoteip-pp-eof.txt new file mode 100644 index 00000000000..e1a31b1be0e --- /dev/null +++ b/changes-entries/remoteip-pp-eof.txt @@ -0,0 +1,4 @@ + *) mod_remoteip: Log a connection closed before a complete PROXY protocol + header was received at info level rather than as an error, and fix an + undefined memcpy() with a NULL source in that case. PR 63893. + [Joe Orton] diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index b1ff301c860..459bf954af1 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -1134,6 +1134,14 @@ static apr_status_t remoteip_input_filter(ap_filter_t *f, apr_off_t got, want = ctx->need - ctx->rcvd; ret = ap_get_brigade(f->next, ctx->bb, ctx->mode, block, want); + if (APR_STATUS_IS_EOF(ret)) { + /* The peer went away before sending a whole header, as a + * health check may. */ + ap_log_cerror(APLOG_MARK, APLOG_INFO, ret, f->c, APLOGNO() + "RemoteIPProxyProtocol: connection closed " + "before a complete header was received"); + return ret; + } if (ret != APR_SUCCESS) { ap_log_cerror(APLOG_MARK, APLOG_ERR, ret, f->c, APLOGNO(10184) "failed reading input"); @@ -1157,6 +1165,13 @@ static apr_status_t remoteip_input_filter(ap_filter_t *f, while (!ctx->done && !APR_BRIGADE_EMPTY(ctx->bb)) { b = APR_BRIGADE_FIRST(ctx->bb); + if (APR_BUCKET_IS_METADATA(b)) { + /* Nothing to copy from EOS or FLUSH; EOF is reported by + * the next read. */ + apr_bucket_delete(b); + continue; + } + ret = apr_bucket_read(b, &ptr, &len, block); if (APR_STATUS_IS_EAGAIN(ret) && block == APR_NONBLOCK_READ) { return APR_SUCCESS; From 2c5419e4f4e1a82aaa0033c70abcdd696d5fa5f5 Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Thu, 8 Oct 2026 20:09:10 +0000 Subject: [PATCH 10/11] * modules/metadata/mod_remoteip.c: Add missing APLOGNO. (cherry picked from commit cea73f6f0894e92e37d0b0a93c1b0f1b43cab8d6) --- modules/metadata/mod_remoteip.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/metadata/mod_remoteip.c b/modules/metadata/mod_remoteip.c index 459bf954af1..25a7bfca24e 100644 --- a/modules/metadata/mod_remoteip.c +++ b/modules/metadata/mod_remoteip.c @@ -1137,7 +1137,7 @@ static apr_status_t remoteip_input_filter(ap_filter_t *f, if (APR_STATUS_IS_EOF(ret)) { /* The peer went away before sending a whole header, as a * health check may. */ - ap_log_cerror(APLOG_MARK, APLOG_INFO, ret, f->c, APLOGNO() + ap_log_cerror(APLOG_MARK, APLOG_INFO, ret, f->c, APLOGNO(10634) "RemoteIPProxyProtocol: connection closed " "before a complete header was received"); return ret; From 9d418726853477fec47a1828ca259ac3c99c0243 Mon Sep 17 00:00:00 2001 From: Joe Orton Date: Sat, 10 Oct 2026 11:21:46 +0100 Subject: [PATCH 11/11] * changes-entries/remoteip-proxy-v2-local.txt: Removed, the crash never shipped in 2.4.x. * changes-entries/remoteip-pp-eof.txt: Drop the undefined-memcpy() clause, which is not user-visible. [skip ci] Co-Authored-By: Claude Fable 5 --- changes-entries/remoteip-pp-eof.txt | 3 +-- changes-entries/remoteip-proxy-v2-local.txt | 2 -- 2 files changed, 1 insertion(+), 4 deletions(-) delete mode 100644 changes-entries/remoteip-proxy-v2-local.txt diff --git a/changes-entries/remoteip-pp-eof.txt b/changes-entries/remoteip-pp-eof.txt index e1a31b1be0e..bb9205a2a26 100644 --- a/changes-entries/remoteip-pp-eof.txt +++ b/changes-entries/remoteip-pp-eof.txt @@ -1,4 +1,3 @@ *) mod_remoteip: Log a connection closed before a complete PROXY protocol - header was received at info level rather than as an error, and fix an - undefined memcpy() with a NULL source in that case. PR 63893. + header was received at info level rather than as an error. PR 63893. [Joe Orton] diff --git a/changes-entries/remoteip-proxy-v2-local.txt b/changes-entries/remoteip-proxy-v2-local.txt deleted file mode 100644 index c2b240b7e3c..00000000000 --- a/changes-entries/remoteip-proxy-v2-local.txt +++ /dev/null @@ -1,2 +0,0 @@ - *) mod_remoteip: Fix crash with PROXY v2 LOCAL command and - RemoteIPProxyProtocol enabled. [Joe Orton]