- Dec 19, 2013
-
-
Alexis Campailla authored
Eliminate a race condition between uv_async_send and the closing of the corresponding handle. Also made errors in Watchdog constructor call abort() Fixes #6088
-
- Dec 18, 2013
-
-
Yorkie authored
-
- Dec 15, 2013
-
-
Ahamed Nafeez authored
This is a comment change, where it originally says disabling TLS Compression protects against BEAST attack. But in fact, it is the CRIME attack(Compression Ratio Info-leak Made Easy) that makes use of TLS Compression and not BEAST. BEAST(Browser Exploit Against SSL/TLS) is an entirely another variant making use of the chosen boundary attack against CBC mode in encryption. Just making sure, that the exact reason for disabling TLS compression must be made clear and not be misleading with some other attack.
-
- Dec 14, 2013
-
-
Fedor Indutny authored
-
Fedor Indutny authored
Conflicts: deps/v8/src/elements-kind.cc deps/v8/src/elements-kind.h deps/v8/src/hydrogen-instructions.h deps/v8/src/hydrogen.cc deps/v8/src/lithium.cc deps/v8/src/lithium.h
-
jkummerow@chromium.org authored
Quoting CVE-2013-6639: The DehoistArrayIndex function in hydrogen-dehoist.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via JavaScript code that sets the value of an array element with a crafted index. Quoting CVE-2013-6640: The DehoistArrayIndex function in hydrogen-dehoist.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds read) via JavaScript code that sets a variable to the value of an array element with a crafted index. Like 6b92a7, this is unlikely to affect node.js because it only runs local, trusted code. However, if there exists some module somewhere that populates an array index with remotely provided data this could very well be used to crash a remote server running node. Defense in depth and all. This is a backport of upstream commit r17801. Original commit log: Limit size of dehoistable array indices LOG=Y BUG=chromium:319835,chromium:319860 R=dslomov@chromium.org Review URL: https://codereview.chromium.org/74113002 -
Fedor Indutny authored
-
- Dec 13, 2013
-
-
Timothy J Fontaine authored
Conflicts: AUTHORS ChangeLog deps/uv/.mailmap deps/uv/ChangeLog deps/uv/build.mk deps/uv/src/unix/darwin.c deps/uv/src/unix/udp.c deps/uv/src/version.c deps/uv/test/test-list.h src/node_version.h
-
Wyatt Preul authored
-
Lalit Kapoor authored
fixes #6647
-
- Dec 12, 2013
-
-
Timothy J Fontaine authored
-
Timothy J Fontaine authored
-
Timothy J Fontaine authored
-
Timothy J Fontaine authored
* uv: Upgrade to v0.10.20 (Timothy J Fontaine) * npm: Upgrade to 1.3.17 (isaacs) * gyp: update to 78b26f7 (Timothy J Fontaine) * build: include postmortem symbols on linux (Timothy J Fontaine) * crypto: Make Decipher._flush() emit errors. (Kai Groner) * dgram: fix abort when getting `fd` of closed dgram (Fedor Indutny) * events: do not accept NaN in setMaxListeners (Fedor Indutny) * events: avoid calling `once` functions twice (Tim Wood) * events: fix TypeError in removeAllListeners (Jeremy Martin) * fs: report correct path when EEXIST (Fedor Indutny) * process: enforce allowed signals for kill (Sam Roberts) * tls: emit 'end' on .receivedShutdown (Fedor Indutny) * tls: fix potential data corruption (Fedor Indutny) * tls: handle `ssl.start()` errors appropriately (Fedor Indutny) * tls: reset NPN callbacks after SNI (Fedor Indutny)
-
Nicolas Kaiser authored
-
Mathias Bynens authored
-
Gabriel Farrell authored
-
Timothy J Fontaine authored
-
Timothy J Fontaine authored
-
isaacs authored
-
Fedor Indutny authored
fix #6663
-
- Dec 11, 2013
-
-
Alexis Campailla authored
The test is expecting an invalid result for the loopback interface network mask, but this issue was fixed in libuv commit 1d5c61a8b31257733c41fb507762d3eb56eecb2d Closes #5262 #6673
-
Alexis Campailla authored
The test is making the wrong assumptions about the value of os.tmpdir() on Windows
-
Fedor Indutny authored
Conflicts: src/node_file.cc
-
Fedor Indutny authored
When `symlink`, `link` or `rename` report EEXIST, ENOTEMPTY or EPERM - the destination file name should be included in the error message, instead of source file name. fix #6510
-
Fedor Indutny authored
Conflicts: lib/tls.js src/node_crypto.cc src/node_crypto.h
-
Fedor Indutny authored
NOTE: Also removed `.receivedShutdown` method of `Connection` it wasn't documented anywhere, and was rewritten with `true` after receiving `close_notify`. fix #6638
-
Fedor Indutny authored
-
Timothy J Fontaine authored
Closes #6629
-
Fedor Indutny authored
FSEventStream may emit events that happened right before it has started. Ignore changes emitted for the directory itself, since they may come from the stale events.
-
Vladimir Kurchatkin authored
Avoid segmentation fault when `undefined` is thrown
-
Alexis Campailla authored
This was failing if the file didn't already exist. Fixes unit tests on Windows: * test\simple\test-http-curl-chunk-problem.js * test\simple\test-pipe-file-to-http.js
-
- Dec 10, 2013
-
-
Trevor Norris authored
Fixes #6664
-
- Dec 08, 2013
-
-
Ingmar Runge authored
This adds two new member functions getAuthTag and setAuthTag that are useful for AES-GCM encryption modes. Use getAuthTag after Cipheriv.final, transmit the tag along with the data and use Decipheriv.setAuthTag to have the encrypted data verified.
-
Timothy J Fontaine authored
-
- Dec 07, 2013
-
-
Timothy J Fontaine authored
Conflicts: lib/tls.js src/node.js
-
Timothy J Fontaine authored
gyp by default now tries to process gyp files in parallel by using python's multiprocessing module, but it has problems on oddball platforms. We don't have many files or complex dependency chains that would benefit from parallel processing so disable by deafult fixes #6640
-
Timothy J Fontaine authored
use `--` to specify the arguments you want to pass directly to gyp. for example: `./configure -- --no-parallel -Dsome_define=foo` fixes #6370
-
Steven Kabbes authored
The android generator for gyp currently doesn't support --generator-output - this makes embedding node.js as project dependency difficult for android projects. Note: the generated files in deps/uv should be ignored in libuv's .gitignore
-