Hi,

HAProxy 3.0.29 was released on 2026/09/28. It added 4 new commits
after version 3.0.28.

This new version is out a few days after the previous one, to correct a
major regression introduced in the QUIC stack.

This regression was introduced by a change to RESET_STREAM frame
reception in the MUX layer. The objective was to ensure the proper
release of the related MUX stream once a RESET_STREAM frame has been
handled. Without it, there was a risk of preventing the connection from
closing, even after the QUIC idle timeout fired, resulting in a
connection leak. However, the fix was poorly written and it could have
caused a process crash. Thus, this release includes the latest patch in
QUIC MUX, which prevents crashes on RESET_STREAM reception while still
addressing the original leak issue.

Aside from this change, JSON log encoding has been extended as well. The
previous point release ensured that the "+json" log format encoding
would always produce valid ASCII printable characters. This is
particularly important when dumping external inputs, to prevent an
attacker from messing with the resulting log lines. However, this may
clutter log files for admins who rely on UTF-8 printable values. Thus, a
new "+utf8" encoding is now supported as well, so that such characters
can be passed through as-is. Here is an example of how to combine these
two flags.

  log-format "%{+json,+utf8}o %(request)r %(custom_expr)[str(custom)]"

Ring server reconnection was faulty when an issue occurred on a
connection that had been up for more than 24.85 days. This has been
present since the introduction of the 1-second delay between retries. It
now works as expected, using the last connection closing date instead of
the creation date, which could cause a wrap-around of the 32-bit timer.

That's it for the current release. For users running the previous
version who have active QUIC listeners in their configuration, an
upgrade must be conducted as soon as possible. If that is not possible,
ensure that QUIC listeners are disabled by using the following global
statement.

  no-quic

This can be turned back on once the upgrade is done. Our apologies to
our users and packagers for any inconvenience caused. Thanks to everyone
who contributed to this release, with a special mention to the users who
quickly reported the QUIC issue and tested the new fix so that this
version could be published.

Please find the usual URLs below :
   Site index       : https://www.haproxy.org/
   Documentation    : https://docs.haproxy.org/
   Wiki             : https://github.com/haproxy/wiki/wiki
   Discourse        : https://discourse.haproxy.org/
   Slack channel    : https://slack.haproxy.org/
   Issue tracker    : https://github.com/haproxy/haproxy/issues
   Q&A from devs    : https://github.com/orgs/haproxy/discussions
   Sources          : https://www.haproxy.org/download/3.0/src/
   Git repository   : https://git.haproxy.org/git/haproxy-3.0.git/
   Git Web browsing : https://git.haproxy.org/?p=haproxy-3.0.git
   Changelog        : https://www.haproxy.org/download/3.0/src/CHANGELOG
   Dataplane API    : 
https://github.com/haproxytech/dataplaneapi/releases/latest
   Pending bugs     : https://www.haproxy.org/l/pending-bugs
   Reviewed bugs    : https://www.haproxy.org/l/reviewed-bugs
   Code reports     : https://www.haproxy.org/l/code-reports
   Latest builds    : https://www.haproxy.org/l/dev-packages


---
Complete changelog :
Amaury Denoyelle (1):
      BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive

Aurelien DARRAGON (1):
      BUG/MEDIUM: sink: reconnect attempt not working after session lasted more 
than ~25 days

Willy Tarreau (2):
      MINOR: log: pass the input end to the _lf_encode_bytes() byte encoders
      MINOR: log: add the +utf8 encoding option to let valid UTF-8 pass

-- 
Amaury Denoyelle


Reply via email to