Changes since version 2.5-dev0 : Alex (1): DOC: use the req.ssl_sni in examples Alexandar Lazic (1): DOC/MINOR: move uuid in the configuration to the right alphabetical order Amaury Denoyelle (17): BUG/MAJOR: server: prevent deadlock when using 'set maxconn server' MINOR: errors: allow empty va_args for diag variadic macro REORG: errors: split errors reporting function from log.c CLEANUP: server: fix cosmetic of error message on sni parsing MEDIUM: errors: implement user messages buffer MINOR: log: do not discard stderr when starting is over MEDIUM: errors: implement parsing context type MINOR: errors: use user messages context in print_message MINOR: log: display exec path on first warning MINOR: errors: specify prefix "config" for parsing output MINOR: log: define server user message format REORG: server: use parsing ctx for server parsing REORG: config: use parsing ctx for server config check MINOR: server: use parsing ctx for server init addr MINOR: server: use ha_alert in server parsing functions BUG: errors: remove printf positional args for user messages context BUG/MINOR: server: explicitly set "none" init-addr for dynamic servers Christopher Faulet (31): BUG/MEDIUM: filters: Exec pre/post analysers only one time per filter BUG/MINOR: http-comp: Preserve HTTP_MSGF_COMPRESSIONG flag on the response MINOR: h1-htx: Update h1 parsing functions to return result as a size_t MEDIUM: h1-htx: Adapt H1 data parsing to copy wrapping data in one call MINOR: mux-h1/mux-fcgi: Don't needlessly loop on data parsing MINOR: h1-htx: Move HTTP chunks parsing into a dedicated function MEDIUM: h1-htx: Split function to parse a chunk and the loop on the buffer MEDIUM: h1-htx: Add a function to parse contiguous small chunks MINOR: h1-htx: Use a correlation table to speed-up small chunks parsing MINOR: buf: Add function to realign a buffer with a specific head position MINOR: muxes/h1-htx: Realign input buffer using b_slow_realign_ofs() CLEANUP: mux-h1: Rename functions parsing input buf and filling output buf Revert "MEDIUM: http-ana: Deal with L7 retries in HTTP analysers" BUG/MINOR: http-ana: Send the right error if max retries is reached on L7 retry BUG/MINOR: http-ana: Handle L7 retries on refused early data before K/A aborts MINOR: http-ana: Perform L7 retries because of status codes in response analyser CLEANUP: http-ana: Remove useless if statement about L7 retries BUG/MAJOR: stream-int: Release SI endpoint on server side ASAP on retry MINOR: backend: Don't release SI endpoint anymore in connect_server() BUG/MINOR: vars: Be sure to have a session to get checks variables CLEANUP: mux-fcgi: Don't needlessly store result of data/trailers parsing MINOR: http-ana: Use -1 status for client aborts during queuing and connect REGTESTS: Fix http_abortonclose.vtc to support -1 status for some client aborts BUG/MEDIUM: compression: Fix loop skipping unused blocks to get the next block BUG/MEDIUM: compression: Properly get the next block to iterate on payload BUG/MEDIUM: compression: Add a flag to know the filter is still processing data BUG/MAJOR: htx: Fix htx_defrag() when an HTX block is expanded BUG/MINOR: mux-fcgi: Expose SERVER_SOFTWARE parameter by default BUG/MINOR: h1-htx: Fix a signess bug with char data type when parsing chunk size CLEANUP: l7-retries: do not test the buffer before calling b_alloc() BUG/MINOR: server-state: load SRV resolution only if params match the config Dragan Dosen (2): MINOR: map/acl: print the count of all the map/acl entries in "show map/acl" CLEANUP: pattern: remove export of non-existent function pattern_delete() Emeric Brun (3): BUG/MINOR: resolvers: answser item list was randomly purged or errors MEDIUM: resolvers: add a ref on server to the used A/AAAA answer item MEDIUM: resolvers: add a ref between servers and srv request or used SRV record Ilya Shipitsin (4): CI: introduce scripts/build-vtest.sh for installing VTest CI: github actions: add OpenTracing builds CI: github actions: add OpenSSL-3.0.0 builds CI: github actions: enable alpine/musl builds Mark Mullan (1): DOC: intro: Fix typo in starter guide Maximilian Mader (2): CLEANUP: tools: Make errptr const in `parse_line()` MINOR: haproxy: Add `-cc` argument Miroslav Zagorac (3): BUILD/MINOR: opentracing: fixed build when using clang Revert "BUG/MINOR: opentracing: initialization after establishing daemon mode" BUG/MEDIUM: opentracing: initialization before establishing daemon and/or chroot mode Remi Tricot-Le Breton (51): CLEANUP: ssl: Move ssl_store related code to ssl_ckch.c MINOR: ssl: Allow duplicated entries in the cafile_tree MEDIUM: ssl: Chain ckch instances in ca-file entries MINOR: ssl: Add reference to default ckch instance in bind_conf MINOR: ssl: Add helper functions to create/delete cafile entries MEDIUM: ssl: Add a way to load a ca-file content from memory MINOR: ssl: Add helper function to add cafile entries MINOR: ssl: Ckch instance rebuild and cleanup factorization in CLI handler MEDIUM: ssl: Add "set+commit ssl ca-file" CLI commands REGTESTS: ssl: Add new ca-file update tests MINOR: ssl: Add "abort ssl ca-file" CLI command MINOR: ssl: Add a cafile_entry type field MINOR: ssl: Refactorize the "show certificate details" code MEDIUM: ssl: Add "show ssl ca-file" CLI command MEDIUM: ssl: Add "new ssl ca-file" CLI command MINOR: ssl: Add "del ssl ca-file" CLI command REGTESTS: ssl: Add "new/del ssl ca-file" tests DOC: ssl: Add documentation about CA file hot update commands DOC: internals: update the SSL architecture schema MINOR: ssl: Chain instances in ca-file entries MEDIUM: ssl: Add "set+commit ssl crl-file" CLI commands MEDIUM: ssl: Add "new+del crl-file" CLI commands MINOR: ssl: Add "abort ssl crl-file" CLI command MEDIUM: ssl: Add "show ssl crl-file" CLI command REGTESTS: ssl: Add "new/del ssl crl-file" tests REGTESTS: ssl: Add "set/commit ssl crl-file" test DOC: ssl: Add documentation about CRL file hot update commands BUILD/MINOR: ssl: Fix compilation with SSL enabled BUILD/MINOR: ssl: Fix compilation with OpenSSL 1.0.2 CLEANUP: ssl: Fix coverity issues found in CA file hot update code BUG/MEDIUM: ebtree: Invalid read when looking for dup entry BUG/MINOR: server: Missing calloc return value check in srv_parse_source BUG/MINOR: peers: Missing calloc return value check in peers_register_table BUG/MINOR: ssl: Missing calloc return value check in ssl_init_single_engine BUG/MINOR: http: Missing calloc return value check in parse_http_req_capture BUG/MINOR: proxy: Missing calloc return value check in proxy_parse_declare BUG/MINOR: proxy: Missing calloc return value check in proxy_defproxy_cpy BUG/MINOR: http: Missing calloc return value check while parsing tcp-request/tcp-response BUG/MINOR: http: Missing calloc return value check while parsing tcp-request rule BUG/MINOR: compression: Missing calloc return value check in comp_append_type/algo BUG/MINOR: worker: Missing calloc return value check in mworker_env_to_proc_list BUG/MINOR: http: Missing calloc return value check while parsing redirect rule BUG/MINOR: http: Missing calloc return value check in make_arg_list BUG/MINOR: proxy: Missing calloc return value check in chash_init_server_tree BUG/MINOR: ssl: OCSP stapling does not work if expire too far in the future MINOR: ssl: Keep the actual key length in the certificate_ocsp structure MINOR: ssl: Add new "show ssl ocsp-response" CLI command MINOR: ssl: Add the OCSP entry key when displaying the details of a certificate MINOR: ssl: Add the "show ssl cert foo.pem.ocsp" CLI command REGTESTS: ssl: Add "show ssl ocsp-response" test BUILD: ssl: Fix compilation with BoringSSL Tim Duesterhus (6): MINOR: cfgparse: Fail when encountering extra arguments in macro CLEANUP: reg-tests: Remove obsolete no-htx parameter for reg-tests CLEANUP: cfgparse: Remove duplication of `MAX_LINE_ARGS + 1` CI: Make matrix.py executable and add shebang REGTESTS: Remove REQUIRE_VERSION=1.6 from all tests REGTESTS: Remove REQUIRE_VERSION=1.7 from all tests William Lallemand (4): BUILD: fix compilation for OpenSSL-3.0.0-alpha17 CI: github actions: -Wno-deprecated-declarations with OpenSSL 3.0.0 BUILD: make tune.ssl.keylog available again REGTESTS: ssl: show_ssl_ocspresponce.vtc is broken with BoringSSL Willy Tarreau (21): CLEANUP: backend: fix incorrect comments on locking conditions for lb functions SCRIPTS: opentracing: enable parallel builds in build-ot.sh BUG/MINOR: pools: fix a possible memory leak in the lockless pool_flush() BUG/MINOR: pools: make DEBUG_UAF always write to the to-be-freed location MINOR: pools: do not maintain the lock during pool_flush() MINOR: pools: call malloc_trim() under thread isolation MEDIUM: pools: use a single pool_gc() function for locked and lockless BUG/MAJOR: pools: fix possible race with free() in the lockless variant CLEANUP: pools: remove now unused seq and pool_free_list MEDIUM: pools: remove the locked pools implementation BUG/MEDIUM: errors: include missing obj_type file MINOR: config: remove support for deprecated option "tune.chksize" MINOR: config: completely remove support for "no option http-use-htx" MINOR: log: remove the long-deprecated early log-format tags MINOR: http: remove the long deprecated "set-cookie()" sample fetch function MINOR: config: reject long-deprecated "option forceclose" MINOR: config: remove deprecated option "http-tunnel" MEDIUM: proxy: remove the deprecated "grace" keyword MAJOR: config: remove parsing of the global "nbproc" directive BUILD: init: remove initialization of multi-process thread mappings BUILD: log: remove unused fmt_directive()