10841 Commits
Author SHA1 Message Date
Rod Vagg 2332fc9445 Working on v0.12.19 2016-12-22 00:39:59 +11:00
Rod Vagg eb454c8212 2016-12-21 Version 0.12.18 (Maintenance) Release
Notable changes:

* npm: upgrade from v2.15.1 to v2.15.11, including accurate updated
  license (Jeremiah Senkpiel)
* process: `process.versions.ares` now outputs the c-ares version (Johan
  Bergström)

PR-URL: https://github.com/nodejs/node/pull/10352
v0.12.18
2016-12-21 23:14:28 +11:00
Rod Vagg bc6766d847 doc: update npm license in main LICENSE file
PR-URL: https://github.com/nodejs/node/pull/10352
2016-12-21 23:08:24 +11:00
John Barboza 830584ca59 deps: define missing operator delete functions
Section 3.2 of the C++ standard states that destructor definitions
implicitly "use" operator delete functions. Therefore, these operator
delete functions must be defined even if they are never called by
user code explicitly.
http://www.open-std.org/JTC1/SC22/WG21/docs/cwg_defects.html#261

gcc allows them to remain as empty definitions. However, not all
compilers allow this.

This pull request creates definitions which if ever called, result
in an abort.

PR-URL: https://github.com/nodejs/node/pull/10356
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: Rod Vagg <rod@vagg.org>
2016-12-21 23:07:24 +11:00
Jeremiah Senkpiel c130b31cba deps: upgrade npm to 2.15.11
Refs: https://github.com/nodejs/LTS/issues/143
PR-URL: https://github.com/nodejs/node/pull/9619
Reviewed-By: Myles Borins <myles.borins@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Rod Vagg <rod@vagg.org>
2016-11-18 16:20:45 -05:00
Rod Vagg d8e27ec30a test: mark dgram-multicast-multi-process as flaky
PR-URL: https://github.com/nodejs/node/pull/9150
Reviewed-By: João Reis <reis@janeasystems.com>
2016-10-29 18:09:55 +11:00
Rod Vagg a47fd4549d build: add working lint-ci make target
PR-URL: https://github.com/nodejs/node/pull/9151
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: Minwoo Jung <jmwsoft@gmail.com>
Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
Reviewed-By: James M Snell <jasnell@gmail.com>
2016-10-28 09:28:17 -07:00
Johan Bergström 0cdf344c80 process: reintroduce ares to versions
PR-URL: https://github.com/nodejs/node/pull/9191
Reviewed-By: Gibson Fahnestock <gibfahn@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
2016-10-28 09:25:31 -07:00
Rod Vagg c722335ead tls: fix minor jslint failure
PR-URL: https://github.com/nodejs/node/pull/9107
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2016-10-19 03:14:58 +11:00
Rod Vagg caae3e7a03 Working on v0.12.18 2016-10-19 03:14:34 +11:00
Rod Vagg 1da5ccffbc 2016-10-18 Version 0.12.17 (Maintenance) Release
This is a security release. All Node.js users should consult the
security release summary at
https://nodejs.org/en/blog/vulnerability/october-2016-security-releases/
for details on patched vulnerabilities.

Notable changes:

* c-ares: fix for single-byte buffer overwrite, CVE-2016-5180, more
  information at https://c-ares.haxx.se/adv_20160929.html
  (Daniel Stenberg)

PR-URL: https://github.com/nodejs/node/pull/9147
v0.12.17
2016-10-19 00:41:01 +11:00
Rod Vagg 5f1097dcb0 win,build: try multiple timeservers when signing
PR-URL: https://github.com/nodejs/node/pull/9155
Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
Reviewed-By: João Reis <reis@janeasystems.com>
2016-10-19 00:41:01 +11:00
Daniel Stenberg c5b095ecf8 deps: avoid single-byte buffer overwrite
Incorrect string length calculation when passing escaped dot.

- CVE: CVE-2016-5180
- Upstream bug: https://c-ares.haxx.se/adv_20160929.html

Ref: https://github.com/nodejs/node/pull/9037
PR-URL: https://github.com/nodejs/node/pull/8849
Reviewed-By: Myles Borins <myles.borins@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
Reviewed-By: Fedor Indutny <fedor.indutny@gmail.com>
2016-10-15 22:07:25 +11:00
Rod Vagg c3f2f02b0f Working on v0.12.17 2016-09-28 09:51:25 +10:00
Rod Vagg 0ad4bbd94a 2016-09-27 Version 0.12.16 (Maintenance) Release
This is a security release. All Node.js users should consult the
security release summary at
https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/
for details on patched vulnerabilities.

Notable changes:

* buffer: Zero-fill excess bytes in new `Buffer` objects created with
  `Buffer.concat()` while providing a `totalLength` parameter that
  exceeds the total length of the original `Buffer` objects being
  concatenated. (Сковорода Никита Андреевич)
* http:
  - CVE-2016-5325 - Properly validate for allowable characters in the
    `reason` argument in `ServerResponse#writeHead()`. Fixes a
    possible response splitting attack vector. This introduces a new
    case where `throw` may occur when configuring HTTP responses,
    users should already be adopting try/catch here. Originally
    reported independently by Evan Lucas and Romain Gaucher.
    (Evan Lucas)
  - Invalid status codes can no longer be sent. Limited to 3 digit
    numbers between 100 - 999. Lack of proper validation may also
    serve as a potential response splitting attack vector. Backported
    from v4.x. (Brian White)
* openssl:
  - Upgrade to 1.0.1u, fixes a number of defects impacting Node.js:
    CVE-2016-6304 ("OCSP Status Request extension unbounded memory
    growth", high severity), CVE-2016-2183, CVE-2016-6303,
    CVE-2016-2178 and CVE-2016-6306.
  - Remove support for loading dynamic third-party engine modules.
    An attacker may be able to hide malicious code to be inserted
    into Node.js at runtime by masquerading as one of the dynamic
    engine modules. Originally reported by Ahmed Zaki (Skype).
    (Ben Noordhuis, Rod Vagg)
* tls: CVE-2016-7099 - Fix invalid wildcard certificate validation
  check whereby a TLS server may be able to serve an invalid wildcard
  certificate for its hostname due to improper validation of `*.` in
  the wildcard string. Originally reported by Alexander Minozhenko
  and James Bunton (Atlassian). (Ben Noordhuis)

PR-URL: https://github.com/nodejs/node-private/pull/72
v0.12.16
2016-09-28 03:30:02 +10:00
Rod Vagg 71e4285e27 crypto: don't build hardware engines
Compile out hardware engines.  Most are stubs that dynamically load
the real driver but that poses a security liability when an attacker
is able to create a malicious DLL in one of the default search paths.

Backport of
https://github.com/nodejs/node-private/pull/58

PR-URL: https://github.com/nodejs/node-private/pull/69
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: Fedor Indutny <fedor.indutny@gmail.com>
2016-09-28 00:11:08 +10:00
Сковорода Никита Андреевич 38d7258d89 buffer: zero-fill uninitialized bytes in .concat()
This makes sure that no uninitialized bytes are leaked when the specified
`totalLength` input value is greater than the actual total length of the
specified buffers array, e.g. in Buffer.concat([Buffer.alloc(0)], 100).

PR-URL: https://github.com/nodejs/node-private/pull/66
Reviewed-By: Rod Vagg <rod@vagg.org>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
2016-09-28 00:09:14 +10:00
Ben Noordhuis 9dbde2fc88 lib: make tls.checkServerIdentity() more strict
CVE-2016-7099

PR-URL: https://github.com/nodejs/node-private/pull/61
Reviewed-By: Rod Vagg <rod@vagg.org>
2016-09-28 00:07:00 +10:00
Evan Lucas 6d977902bd http: check reason chars in writeHead
Previously, the reason argument passed to ServerResponse#writeHead was
not being properly validated.  One could pass CRLFs which could lead to
http response splitting. This commit changes the behavior to throw an
error in the event any invalid characters are included in the reason.

CVE-2016-5325

PR-URL: https://github.com/nodejs/node-private/pull/47
Reviewed-By: Rod Vagg <rod@vagg.org>
Reviewed-By: Fedor Indutny <fedor.indutny@gmail.com>
Reviewed-By: Douglas Wilson <doug@somethingdoug.com>
2016-09-28 00:02:05 +10:00
Evan Lucas ad470e496b http: disallow sending obviously invalid status codes
Back port of
https://github.com/nodejs/node/commit/7e9b0dd6949aaa6afda4da9f41e1d60d9b
3d6225 to v0.12.

PR-URL: https://github.com/nodejs/node-private/pull/47
Reviewed-By: Rod Vagg <rod@vagg.org>
Reviewed-By: Fedor Indutny <fedor.indutny@gmail.com>
Reviewed-By: Douglas Wilson <doug@somethingdoug.com>
2016-09-28 00:00:05 +10:00
Shigeki Ohtsu b6e0105a66 deps: add -no_rand_screen to openssl s_client
In openssl s_client on Windows, RAND_screen() is invoked to initialize
random state but it takes several seconds in each connection.
This added -no_rand_screen to openssl s_client on Windows to skip
RAND_screen() and gets a better performance in the unit test of
test-tls-server-verify.
Do not enable this except to use in the unit test.

(cherry picked from commit 9f0f7c38e6df975dd39735d0e9ef968076369c74)

Reviewed-By: James M Snell <jasnell@gmail.com>
PR-URL: https://github.com/joyent/node/pull/25368
2016-09-23 09:47:09 +10:00
Shigeki Ohtsu db80592071 openssl: fix keypress requirement in apps on win32
reapply b910613792

PR: #9451
PR-URL: https://github.com/joyent/node/pull/9451
Reviewed-By: Julien Gilli <julien.gilli@joyent.com>

PR: #25523
PR-URL: https://github.com/joyent/node/pull/25523
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>

PR: #25654
PR-URL: https://github.com/joyent/node/pull/25654
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>
2016-09-23 09:47:09 +10:00
Fedor Indutny 1caec97eab deps: fix openssl assembly error on ia32 win32
`x86masm.pl` was mistakenly using .486 instruction set, why `cpuid` (and
perhaps others) are requiring .686 .

PR: #9451
PR-URL: https://github.com/joyent/node/pull/9451
Reviewed-By: Julien Gilli <julien.gilli@joyent.com>

PR: #25523
PR-URL: https://github.com/joyent/node/pull/25523
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>

PR: #25654
PR-URL: https://github.com/joyent/node/pull/25654
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>
2016-09-23 09:47:09 +10:00
Shigeki Ohtsu 734bc6938b deps: separate sha256/sha512-x86_64.pl for openssl
sha256-x86_64.pl does not exist in the origin openssl distribution. It
was copied from sha512-x86_64.pl and both sha256/sha512 scripts were
modified so as to generates only one asm file specified as its key
hash length.

PR: #9451
PR-URL: https://github.com/joyent/node/pull/9451
Reviewed-By: Julien Gilli <julien.gilli@joyent.com>

PR: #25523
PR-URL: https://github.com/joyent/node/pull/25523
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>

PR: #25654
PR-URL: https://github.com/joyent/node/pull/25654
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>
2016-09-23 09:47:09 +10:00
Shigeki Ohtsu 7cc6d4eb5c deps: copy all openssl header files to include dir
All symlink files in `deps/openssl/openssl/include/openssl/`
are removed and replaced with real header files to avoid
issues on Windows. Two files of opensslconf.h in crypto and
include dir are replaced to refer config/opensslconf.h.

PR-URL: https://github.com/nodejs/node/pull/8718
Reviewed-By: Fedor Indutny <fedor@indutny.com>
Reviewed-By: Myles Borins <mborins@us.ibm.com>
2016-09-23 09:47:09 +10:00
Shigeki Ohtsu 4a9da21217 deps: upgrade openssl sources to 1.0.1u
This just replaces all sources of openssl-1.0.1u.tar.gz
into deps/openssl/openssl.

PR-URL: https://github.com/nodejs/node/pull/8718
Reviewed-By: Fedor Indutny <fedor@indutny.com>
Reviewed-By: Myles Borins <mborins@us.ibm.com>
2016-09-23 09:47:09 +10:00
Ben Noordhuis 1ba6d16786 build: turn on -fno-delete-null-pointer-checks
Work around spec violations in V8 where it checks that `this == NULL`.
GCC 6 started exploiting this particular kind of UB, resulting in
runtime crashes.

Fixes: https://github.com/nodejs/node/issues/6724
PR-URL: https://github.com/nodejs/node/pull/6737
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Michaël Zasso <mic.besace@gmail.com>
2016-06-24 09:18:02 +10:00
Rod Vagg 8a4a26b5b8 Working on v0.12.16 2016-06-24 09:17:11 +10:00
Rod Vagg 2bd9dabf79 2016-06-23 Version 0.12.15 (Maintenance) Release
This is a security release. All Node.js users should consult the security
release summary at
https://nodejs.org/en/blog/vulnerability/june-2016-security-releases/ for
details on patched vulnerabilities.

Notable changes:

* libuv: (CVE-2014-9748) Fixes a bug in the read/write locks implementation for
  Windows XP and Windows 2003 that can lead to undefined and potentially unsafe
  behaviour. More information can be found at
  https://github.com/libuv/libuv/issues/515 or at
  https://nodejs.org/en/blog/vulnerability/june-2016-security-releases/.
* V8: (CVE-2016-1669) Fixes a potential Buffer overflow vulnerability
  discovered in V8, more details can be found in the CVE at
  https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1669 or at
  https://nodejs.org/en/blog/vulnerability/june-2016-security-releases/.

PR-URL: https://github.com/nodejs/node-private/pull/53
v0.12.15
2016-06-24 02:46:33 +10:00
Rod Vagg da8501edf6 deps: backport bd1777fd from libuv upstream
Original commit message:

    unix, win: consolidate mutex trylock errors

    Fold EAGAIN into EBUSY, and make it the only acceptable error.

    PR-URL: https://github.com/libuv/libuv/pull/535
    Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>

PR-URL: https://github.com/nodejs/node-private/pull/54
Reviewed-By: Saúl Ibarra Corretgé <saghul@gmail.com>
2016-06-24 02:42:30 +10:00
Rod Vagg 9207a00f8e deps: backport 85adf43e from libuv upstream
Original commit message:

    unix: consolidate rwlock tryrdlock trywrlock errors

    Fold EAGAIN and EBUSY into EBUSY. This makes it consistent across all
    Unix platforms and Windows.

    Refs: https://github.com/libuv/libuv/pull/525
    PR-URL: https://github.com/libuv/libuv/pull/535
    Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>

PR-URL: https://github.com/nodejs/node-private/pull/54
Reviewed-By: Saúl Ibarra Corretgé <saghul@gmail.com>
2016-06-24 02:42:29 +10:00
Rod Vagg 9627f34230 deps: backport 98239224 from libuv upstream
Original commit message:

    win: don't fetch function pointers to SRWLock APIs

    They're no longer needed, since the Windows-native SRWLock functions are
    no longer used.

    PR-URL: https://github.com/libuv/libuv/pull/525
    Reviewed-By: Saúl Ibarra Corretgé <saghul@gmail.com>

PR-URL: https://github.com/nodejs/node-private/pull/54
Reviewed-By: Saúl Ibarra Corretgé <saghul@gmail.com>
2016-06-24 02:42:29 +10:00
Rod Vagg 5df21b2e36 deps: backport 9a4fd268 from libuv upstream
Original commit message:

    win: redo/fix the uv_rwlock APIs

    Previously, on Windows Vista and later, we'd use the Windows native
    SRWLock APIs. However they turned out to be semantically incompatible
    with pthread read-write locks and/or plain buggy. This patch makes sure
    that the custom implementation that was previously only used on old
    Windows versions is now used everywhere.

    This patch fixes a number of issues with the old fallback
    implementation. Specifically:

    * The reader count would not be incremented when a thread successfully
      acquired a read lock while another thread *also* held a read lock.

    * `uv_rwlock_tryrdlock()` and `uv_rwlock_trywrlock()` now
      consistently return UV_EBUSY when a lock couldn't be acquired.

    * Any unexpected errors now cause libuv to abort, with the exception of
      `uv_rwlock_init()`.

    See also https://github.com/libuv/libuv/issues/515.

    PR-URL: https://github.com/libuv/libuv/pull/525
    Reviewed-By: Saúl Ibarra Corretgé <saghul@gmail.com>

PR-URL: https://github.com/nodejs/node-private/pull/54
Reviewed-By: Saúl Ibarra Corretgé <saghul@gmail.com>
2016-06-24 02:42:29 +10:00
Rod Vagg e75de35057 deps: backport 3eb6764a from libuv upstream
Original commit message:

    win: fix unsavory rwlock fallback implementation

    Before this patch an uv_mutex_t (backed by a critical section) could be
    released by a tread different from the thread that acquired it, which is
    not allowed. This is fixed by using a semaphore instead.

    Note that the affected code paths were used on Windows XP and Windows
    Server 2003 only.

    Fixes: https://github.com/libuv/libuv/issues/515
    PR-URL: https://github.com/libuv/libuv/pull/516
    Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
    Reviewed-By: Saúl Ibarra Corretgé <saghul@gmail.com>

PR-URL: https://github.com/nodejs/node-private/pull/54
Reviewed-By: Saúl Ibarra Corretgé <saghul@gmail.com>
2016-06-24 02:42:29 +10:00
Ben Noordhuis a113e02f16 deps: backport 3a9bfec from v8 upstream
Original commit message:

	Fix overflow issue in Zone::New

	When requesting a large allocation near the end of the address space,
	the computation could overflow and erroneously *not* grow the Zone
	as required.

	BUG=chromium:606115
	LOG=y

	Review-Url: https://codereview.chromium.org/1930873002
	Cr-Commit-Position: refs/heads/master@{#35903}

PR-URL: https://github.com/nodejs/node-private/pull/44
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: Rod Vagg <rod@vagg.org>
2016-06-23 23:39:15 +10:00
Ben Noordhuis 8138055c88 test: fix test failure due to expired certificates
Back-port commit 76f40f7 ("test: stronger crypto in test fixtures") from
the master branch.

Pushes back the expiration date of test/fixtures/keys/ca2-crl.pem to
2018, fixing a CRL_HAS_EXPIRED error in simple/test-tls-server-verify.

Fixes: https://github.com/nodejs/node/issues/7194
PR-URL: https://github.com/nodejs/node/pull/7195
Reviewed-By: Michael Dawson <michael_dawson@ca.ibm.com>
Reviewed-By: Myles Borins <myles.borins@gmail.com>
2016-06-23 23:24:34 +10:00
Rod Vagg 41c84c503c Working on v0.12.15 2016-05-06 23:51:49 +10:00
Rod Vagg a7376c9b8e 2016-05-06 Version 0.12.14 (Maintenance) Release
Notable changes:

* npm: Correct erroneous version number in v2.15.1 code
  (Forrest L Norvell) https://github.com/nodejs/node/pull/5988
* openssl: Upgrade to v1.0.1t, addressing security vulnerabilities
  (Shigeki Ohtsu) https://github.com/nodejs/node/pull/6553
  - Fixes CVE-2016-2107 "Padding oracle in AES-NI CBC MAC check"
  - Fixes CVE-2016-2105 "EVP_EncodeUpdate overflow"
  - See https://nodejs.org/en/blog/vulnerability/openssl-may-2016/
    for full details
v0.12.14
2016-05-06 22:59:34 +10:00
Kat Marchán 810fb211a7 tools: remove obsolete npm test-legacy command
PR-URL: https://github.com/nodejs/node/pull/5988
Reviewed-By: Myles Borins <myles.borins@gmail.com>
2016-05-05 10:08:05 -07:00
Forrest L Norvell 3e99ee1b47 deps: completely upgrade npm in LTS to 2.15.1
PR-URL: https://github.com/nodejs/node/pull/5988
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Myles Borins <myles.borins@gmail.com>
2016-05-05 10:07:48 -07:00
Shigeki Ohtsu 2b63396e1f deps: add -no_rand_screen to openssl s_client
In openssl s_client on Windows, RAND_screen() is invoked to initialize
random state but it takes several seconds in each connection.
This added -no_rand_screen to openssl s_client on Windows to skip
RAND_screen() and gets a better performance in the unit test of
test-tls-server-verify.
Do not enable this except to use in the unit test.

(cherry picked from commit 9f0f7c38e6df975dd39735d0e9ef968076369c74)

Reviewed-By: James M Snell <jasnell@gmail.com>
PR-URL: https://github.com/joyent/node/pull/25368
2016-05-05 21:44:48 +09:00
Shigeki Ohtsu f21705df58 deps: update openssl asm files
Regenerate asm files with Makefile without CC and ASM envs.

Fixes: https://github.com/nodejs/node/issues/6458
PR-URL: https://github.com/nodejs/node/pull/6553
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
2016-05-05 21:44:42 +09:00
Shigeki Ohtsu f5a961ab13 openssl: fix keypress requirement in apps on win32
reapply b910613792

PR: #9451
PR-URL: https://github.com/joyent/node/pull/9451
Reviewed-By: Julien Gilli <julien.gilli@joyent.com>

PR: #25523
PR-URL: https://github.com/joyent/node/pull/25523
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>

PR: #25654
PR-URL: https://github.com/joyent/node/pull/25654
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>
2016-05-05 21:44:42 +09:00
Fedor Indutny 02b6a6bc27 deps: fix openssl assembly error on ia32 win32
`x86masm.pl` was mistakenly using .486 instruction set, why `cpuid` (and
perhaps others) are requiring .686 .

PR: #9451
PR-URL: https://github.com/joyent/node/pull/9451
Reviewed-By: Julien Gilli <julien.gilli@joyent.com>

PR: #25523
PR-URL: https://github.com/joyent/node/pull/25523
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>

PR: #25654
PR-URL: https://github.com/joyent/node/pull/25654
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>
2016-05-05 21:44:41 +09:00
Shigeki Ohtsu 1aecc668b0 deps: separate sha256/sha512-x86_64.pl for openssl
sha256-x86_64.pl does not exist in the origin openssl distribution. It
was copied from sha512-x86_64.pl and both sha256/sha512 scripts were
modified so as to generates only one asm file specified as its key
hash length.

PR: #9451
PR-URL: https://github.com/joyent/node/pull/9451
Reviewed-By: Julien Gilli <julien.gilli@joyent.com>

PR: #25523
PR-URL: https://github.com/joyent/node/pull/25523
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>

PR: #25654
PR-URL: https://github.com/joyent/node/pull/25654
Reviewed-By: Julien Gilli <jgilli@fastmail.fm>
2016-05-05 21:44:41 +09:00
Shigeki Ohtsu 39380836a0 deps: copy all openssl header files to include dir
All symlink files in `deps/openssl/openssl/include/openssl/`
are removed and replaced with real header files to avoid
issues on Windows.

Fixes: https://github.com/nodejs/node/issues/6458
PR-URL: https://github.com/nodejs/node/pull/6553
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
2016-05-05 21:44:34 +09:00
Shigeki Ohtsu 08c8ae44a8 deps: upgrade openssl sources to 1.0.1t
This just replaces all sources of openssl-1.0.1t.tar.gz
into deps/openssl/openssl.

Fixes: https://github.com/nodejs/node/issues/6458
PR-URL: https://github.com/nodejs/node/pull/6553
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
2016-05-05 21:41:56 +09:00
Rod Vagg 98060a43f4 Working on v0.12.14 2016-03-31 16:29:41 -07:00
Rod Vagg 5f4849ac2a 2016-03-31 Version 0.12.13 (LTS) Release
Notable changes:

* npm: Upgrade to v2.15.1. Fixes a security flaw in the use of
  authentication tokens in HTTP requests that would allow an attacker
  to set up a server that could collect tokens from users of the
  command-line interface. Authentication tokens have previously been
  sent with every request made by the CLI for logged-in users,
  regardless of the destination of the request. This update fixes this
  by only including those tokens for requests made against the
  registry or registries used for the current install.
  (Forrest L Norvell) https://github.com/nodejs/node/pull/5967
* openssl: OpenSSL v1.0.1s disables the EXPORT and LOW ciphers as they
  are obsolete and not considered safe. This release of Node.js turns
  on `OPENSSL_NO_WEAK_SSL_CIPHERS` to fully disable the 27 ciphers
  included in these lists which can be used in SSLv3 and higher. Full
  details can be found in our LTS discussion on the matter
  (https://github.com/nodejs/LTS/issues/85).
  (Shigeki Ohtsu) https://github.com/nodejs/node/pull/5712

PR-URL: https://github.com/nodejs/node/pull/5967
v0.12.13
2016-03-31 16:26:45 -07:00
Forrest L Norvell 4041ea6bc5 deps: upgrade npm in LTS to 2.15.1
PR-URL: https://github.com/nodejs/node/pull/5967
2016-03-31 16:25:30 -07:00