Changes since version 3.4.2 : Amaury Denoyelle (13): BUG/MEDIUM: h3: fix parser desync on error with multiple frames BUG/MINOR: mux_quic: prevent multiple STOP_SENDING emission per stream BUG/MEDIUM: mux_quic: do not free QCS if STOP_SENDING to sent MINOR: mux_quic: use separate error code for STOP_SENDING BUG/MEDIUM: mux_quic: complete stream shutdown for read channel BUG/MINOR: quic: ignore STREAM after MUX closure on BE side BUG/MINOR: ssl: fix proxy lookup for show ssl sni DOC: fix typo in "del ssl ech" command DOC: remove outdated experimental mention on dynamic backends BUG/MEDIUM: proxy: protect "show servers ..." against server deletion BUG/MEDIUM: proxy: protect "show servers ..." against backend deletion BUG/MEDIUM: proxy: protect show backend against be deletion BUG/MEDIUM: proxy: protect "show errors" against backend deletion Christopher Faulet (24): BUG/MEDIUM: tcpcheck: Add proxy used for healthcheck sections in proxies list BUG/MINOR: sample: Fix a possible underflow on be2hex for large chunk size MINOR: chunks: Add function to get a large/regular chunk depending on a buffer BUG/MEDIUM: chunk: Review chunks usage to not retrieve a large buffer by error MINOR: htx: Add a field to save the headers data size MEDIUM: htx: Be sure size of headers never exceed regular buffer on update BUG/MINOR: stream: Fix custom timeouts initialization when setting backend REGTESTS: Improve script testing the set-timeout action BUG/MINOR: stream: Fix custom max-retries initialization when setting backend BUG/MINOR: http-conv: Make url-dec failed if no space for trailing null byte BUG/MINOR: hlua: Apply socket timeout on server side only BUG/MEDIUM: applet: Reenable reads in applet context if requesting a connection BUG/MINOR: mux-h1: Don't delay send if message with c-l was fully sent BUG/MEDIUM: net-helper: Adjust sample size capacity after pointer shift BUG/MEDIUM: sample: Adjust sample size capacity after pointer shift for bytes() BUG/MEDIUM: sample: Adjust sample size capacity after pointer shift for ltrim() BUG/MINOR: sample: Fix bytes() when length it greater than remaining data REORG: h1-htx: Move h1 headers map in h1-htx BUG/MEDIUM: mux-h1: Always adjust case for all outgoing headers as expected BUG/MEDIUM: http-fetch: don't parse a non-HTTP check buffer as an HTX message BUG/MEDIUM: tools: make string encoding possible to fail instead of truncating BUG/MINOR: htx: Perform raw copy for messages of same size in htx_copy_msg() BUG/MINOR: htx: Transfer HTX_FL_EOM flag on success in htx_append_msg() BUG/MINOR: http-rules: fix release of a failed "set-cookie-fmt" redirect rule Frederic Lecaille (4): MINOR: haterm: add note about QUIC usage on SSL port BUG/MEDIUM: protobuf: adjust sample size capacity after pointer shift BUG/MEDIUM: protobuf: fix nested path bypass in field lookup REGTESTS: protobuf: add regression test for nested vs flat paths Maxime Henrion (4): BUG/MINOR: shctx: fix shctx_row_data_get() when offset exceeds a block MINOR: shctx: clamp shctx_row_data_get() reads against the offset DOC: stats: document the per-proxy byte count fields in the CSV list BUG/MEDIUM: cache: reattach the row when a secondary entry is incomplete Olivier Houchard (7): BUG/MEDIUM: fd: Fix a deadlock when closing other tgroups fds BUG/MEDIUM: stats: Ensure that Origin is valid on POSTs DOC: stats: Document that stats admin is vulnerable to a CSRF attack BUG/MEDIUM: ssl-gencert: Don't forget to free memory when done BUG/MEDIUM: server: Properly check for streams before deletion BUG/MEDIUM: ssl: Spell HAVE_VANILLA_OPENSSL correctly BUG/MEDIUM: ssl: Handle non-application data record while splicing Willy Tarreau (32): BUILD: quic: workaround a gcc bug saying "maybe used uninitialized" when USE_TRACE=0 CLEANUP: traces: get rid of a few rare empty args in TRACE calls MINOR: compiler: add a macro to ignore all arguments MINOR: trace: always pretend to use args when disabled BUG/MINOR: trace/quic_frame: use buf, not trace_buf in chunk_frm_appendf() MINOR: stats: factor the proxy vs scope check into its own function BUG/MEDIUM: stats: subject "stats admin" accesses to "stats scope" filtering BUG/MINOR: resolvers: do not index resolvers names in the proxies DEBUG: fd: catch access attempts to closed FDs BUG/MINOR: http-htx: fix the length moved when removing a header value BUG/MEDIUM: http-fetch: reject a negative capture id in capture.{req,res}.hdr BUG/MINOR: http-fetch: fix a NULL channel dereference in smp_fetch_body() BUG/MINOR: http: fix an out-of-bounds read in http_get_host_port() on empty host BUG/MINOR: http-htx: check the trash allocation in http_scheme_based_normalize() BUG/MINOR: h1: report the right error position on authority/host mismatch BUG/MINOR: h2: don't use a block pointer to roll back a partial HTX conversion BUG/MINOR: h3: don't use a block pointer to roll back a partial HTX conversion BUG/MINOR: http-ana: fix a one-byte over-read in the client-side cookie parser BUG/MINOR: http-act: fix a double free of the regex on a rule parsing error BUG/MINOR: http-act: fix a double free of the map reference on a parsing error BUG/MINOR: http-act: restore the response buffer state in the early-hint action BUG/MINOR: http-act: work on a copy of the sample in del-headers-bin BUG/MINOR: http-act: reject a negative capture id in the capture actions BUG/MINOR: http-htx: check the strdup() of the "lf-string" http reply argument BUG/MINOR: slz: do not read past the end of the input around the match loop CLEANUP: slz: fix the documented worst case size of flush() and finish() BUG/MINOR: slz: use the exact switch cost for the last literals of a block BUG/MEDIUM: slz: bound the bits wasted by the 9-bit literals BUG/MINOR: slz: do not append a block to an already finished stream BUG/MINOR: slz: fix the adler32 accumulators signedness on 32-bit BUG/MINOR: slz: avoid undefined shifts when building the word byte by byte CLEANUP: slz: clarify that the size promise applies to the stream, not to a call