** Description changed:
This bug tracks an update for the HAProxy package in the following Ubuntu
releases to the versions below:
* noble 24.04: HAProxy 2.8.28 (from 2.8.16-0ubuntu0.24.04.3)
* resolute 26.04: HAProxy 3.2.23 (from 3.2.9-1ubuntu2.2)
- * stonking 26.10: HAProxy 3.4.4 (from 3.4.2-1ubuntu3)
These updates include bugfixes only following the SRU policy exception defined
at
https://documentation.ubuntu.com/sru/en/latest/reference/exception-HAProxy-Updates
[Upstream changes]
(only major bugs listed, for others see the changelog link)
-
- - for 26.10 - 3.4: https://www.haproxy.org/download/3.4/src/CHANGELOG
- - BUG/MAJOR: ssl/ocsp: lock the OCSP response around reads in the
stapling callback
- for 26.04 - 3.2: https://www.haproxy.org/download/3.2/src/CHANGELOG
- BUG/MAJOR: ssl/ocsp: lock the OCSP response around reads in the
stapling callback
- BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error
- BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in
h2c_dec_hdrs()
- BUG/MAJOR: http: forbid comma character in authority value
- BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based
normalization
- BUG/MAJOR: mux-h1: Deal with true 64-bits integer to emit chunks size
- BUG/MAJOR: slz: always make sure to limit fixed output to less than
worst case literals
- BUG/MAJOR: sched: protect task->expire on 32-bit platforms
- BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well
- BUG/MAJOR: h3: check body size with content-length on empty FIN
- BUG/MAJOR: qpack: unchecked length passed to huffman decoder
- BUG/MAJOR: fcgi: Fix param decoding by properly checking its size
- BUG/MAJOR: resolvers: Properly lowered the names found in DNS response
- BUG/MAJOR: Revert "MEDIUM: mux-quic: add BUG_ON if sending on locally
closed QCS"
- BUG/MAJOR: applet: Don't call I/O handler if the applet was shut
- BUG/MAJOR: quic: reject invalid token
- BUG/MAJOR: quic: fix parsing frame type
- for noble - 2.8: https://www.haproxy.org/download/2.8/src/CHANGELOG
- BUG/MAJOR: ssl/ocsp: lock the OCSP response around reads in the
stapling callback
- BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error
- BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in
h2c_dec_hdrs()
- BUG/MAJOR: http: forbid comma character in authority value
- BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based
normalization
- BUG/MAJOR: slz: always make sure to limit fixed output to less than
worst case literals
- BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well
- BUG/MAJOR: h3: check body size with content-length on empty FIN
- BUG/MAJOR: qpack: unchecked length passed to huffman decoder
- BUG/MAJOR: fcgi: Fix param decoding by properly checking its size
- BUG/MAJOR: resolvers: Properly lowered the names found in DNS response
- BUG/MAJOR: stream: Force channel analysis on successful synchronous send
- BUG/MAJOR: quic: use ncbmbuf for CRYPTO handling
[Test Plan]
TODO: link to the upstream CI pipelines demonstrating all tests are passing
TODO: if there are any non passing tests - explain why that is ok in this case
TODO: add results of a local autopkgtest run against all the new HAProxy
versions
[Regression Potential]
HAProxy itself does not have many reverse dependencies, however, any upgrade
is
a risk to introduce some breakage to other packages. Whenever a test failure
is
detected, we will be on top of it and make sure it doesn't affect existing
users.
TODO: consider any other regression potential specific to the version being
updated and list if any.
** Changed in: haproxy (Ubuntu)
Status: New => In Progress
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153485
Title:
Backport haproxy for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/haproxy/+bug/2153485/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs