** Description changed:
This bug tracks an update for the HAProxy package in the following Ubuntu
releases to the versions below:
* resolute 26.04: HAProxy 3.2.25 (from 3.2.9-1ubuntu2.2)
* noble 24.04: HAProxy 2.8.30 (from 2.8.16-0ubuntu0.24.04.3)
These updates include bugfixes only following the SRU policy exception defined
at
https://documentation.ubuntu.com/sru/en/latest/reference/exception-HAProxy-Updates
[Upstream changes]
(only major bugs listed, for others see the changelog link)
- for 26.04 - 3.2: https://www.haproxy.org/download/3.2/src/CHANGELOG
- - BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
- - BUG/MAJOR: h3: reject H3 truncated frames
- - BUG/MAJOR: htx: Check the header/trailer length limits when one is
updated
- - BUG/MAJOR: mux_quic: fix leak on RESET_STREAM reception
+ - BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
+ - BUG/MAJOR: h3: reject H3 truncated frames
+ - BUG/MAJOR: htx: Check the header/trailer length limits when one is
updated
+ - BUG/MAJOR: mux_quic: fix leak on RESET_STREAM reception
- BUG/MAJOR: ssl/ocsp: lock the OCSP response around reads in the
stapling callback
- BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error
- BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in
h2c_dec_hdrs()
- BUG/MAJOR: http: forbid comma character in authority value
- BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based
normalization
- BUG/MAJOR: mux-h1: Deal with true 64-bits integer to emit chunks size
- BUG/MAJOR: slz: always make sure to limit fixed output to less than
worst case literals
- BUG/MAJOR: sched: protect task->expire on 32-bit platforms
- BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well
- BUG/MAJOR: h3: check body size with content-length on empty FIN
- BUG/MAJOR: qpack: unchecked length passed to huffman decoder
- BUG/MAJOR: fcgi: Fix param decoding by properly checking its size
- BUG/MAJOR: resolvers: Properly lowered the names found in DNS response
- BUG/MAJOR: Revert "MEDIUM: mux-quic: add BUG_ON if sending on locally
closed QCS"
- BUG/MAJOR: applet: Don't call I/O handler if the applet was shut
- BUG/MAJOR: quic: reject invalid token
- BUG/MAJOR: quic: fix parsing frame type
- for noble - 2.8: https://www.haproxy.org/download/2.8/src/CHANGELOG
- - BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
- - BUG/MAJOR: h3: reject H3 truncated frames
- - BUG/MAJOR: htx: Check the header/trailer length limits when one is
updated
- - BUG/MAJOR: mux_quic: fix leak on RESET_STREAM reception
+ - BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
+ - BUG/MAJOR: h3: reject H3 truncated frames
+ - BUG/MAJOR: htx: Check the header/trailer length limits when one is
updated
+ - BUG/MAJOR: mux_quic: fix leak on RESET_STREAM reception
- BUG/MAJOR: ssl/ocsp: lock the OCSP response around reads in the
stapling callback
- BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error
- BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in
h2c_dec_hdrs()
- BUG/MAJOR: http: forbid comma character in authority value
- BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based
normalization
- BUG/MAJOR: slz: always make sure to limit fixed output to less than
worst case literals
- BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well
- BUG/MAJOR: h3: check body size with content-length on empty FIN
- BUG/MAJOR: qpack: unchecked length passed to huffman decoder
- BUG/MAJOR: fcgi: Fix param decoding by properly checking its size
- BUG/MAJOR: resolvers: Properly lowered the names found in DNS response
- BUG/MAJOR: stream: Force channel analysis on successful synchronous send
- BUG/MAJOR: quic: use ncbmbuf for CRYPTO handling
[Test Plan]
- TODO: link to the upstream CI pipelines demonstrating all tests are passing
- TODO: if there are any non passing tests - explain why that is ok in this case
+ GitHub Actions runs:
+ https://github.com/TheJJ/haproxy/tree/verify-2.8.30
+ 70dae8f09d58bd05c28a761d9b47136895b679d3
+ - testsuite needed pcre header fix (my commit
413f957846e5ff0aca155749aa0fb4e15a5ececc)
+ - all tests pass, except openssl=4.1.0-beta1 (which is not in noble)
+ - autopkgtest results:
+ cli PASS
+ proxy-localhost PASS
+ proxy-ssl-termination PASS
+ proxy-ssl-pass-through PASS
- TODO: add results of a local autopkgtest run against all the new HAProxy
- versions
+ https://github.com/TheJJ/haproxy/tree/verify-3.2.25
70469d33ba0edc5503e292518ddf3e5df7aa9605
+ - testsuite also needs pcre header fix (commit
e20cb386df653848c5f43e6259805a6fafe2cdb9)
+ - all tests pass except openssl=4.1.0-beta1 (which is not in resolute)
+ - autopkgtest results:
+ cli PASS
+ proxy-localhost PASS
+ proxy-ssl-termination PASS
+ proxy-ssl-pass-through PASS
+
[Regression Potential]
- HAProxy itself does not have many reverse dependencies, however, any upgrade
is
- a risk to introduce some breakage to other packages. Whenever a test failure
is
- detected, we will be on top of it and make sure it doesn't affect existing
- users.
-
- TODO: consider any other regression potential specific to the version being
- updated and list if any.
+ HAProxy itself does not have many reverse dependencies, however, any
+ upgrade is a risk to introduce some breakage to other packages. Whenever
+ a test failure is detected, we will be on top of it and make sure it
+ doesn't affect existing users.
** Also affects: haproxy (Ubuntu Noble)
Importance: Undecided
Status: New
** Also affects: haproxy (Ubuntu Resolute)
Importance: Undecided
Status: New
** Changed in: haproxy (Ubuntu Noble)
Status: New => In Progress
** Changed in: haproxy (Ubuntu Resolute)
Status: New => In Progress
** Changed in: haproxy (Ubuntu Noble)
Assignee: (unassigned) => Jonas Jelten (jj)
** Changed in: haproxy (Ubuntu Resolute)
Assignee: (unassigned) => Jonas Jelten (jj)
** Changed in: haproxy (Ubuntu)
Status: In Progress => Invalid
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153485
Title:
Backport haproxy for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/haproxy/+bug/2153485/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs