Re: [PATCH] http.c security

Stipe Tolj <[email protected]>
Newsgroups gmane.comp.mobile.kannel.devel
Organization tolj.org system architecture
Message-ID <[email protected]>
Enver ALTIN wrote:

> On Wed, 2006-10-25 at 22:06 +0200, Alexander Malysh wrote:
> 
>>please find attached security bug fix for http.c. We have issue when
>>we  use keep alive connections with our connection pool.
>>Just imagine such scenario without a patch:
>>
>>1) http_start_request(..., ssl=0,certkeyfile=NULL,our_host=NULL)
>>2) http_start_request(..., ssl=1,certkeyfile=XYZ,our_host=XYZ) 
> 
> 
> Looks good to me.

which translates to +0 or +1 ??? ;)

we use the following scalar convention:

-1 : veto against commit, with reasons
-0 : not convinced fully for patch need, but without veto
+0 : not convinced fully for patch need, but looks like we can do it
+1 : definetively needed to be commited

Stipe

-------------------------------------------------------------------
Kölner Landstrasse 419
40589 Düsseldorf, NRW, Germany

tolj.org system architecture      Kannel Software Foundation (KSF)
http://www.tolj.org/              http://www.kannel.org/

mailto:st_{at}_tolj.org           mailto:stolj_{at}_kannel.org
-------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.