** Description changed:

  This bug tracks an update for the HAProxy package in the following Ubuntu
  releases to the versions below:
  
  * resolute 26.04: HAProxy 3.2.25 (from 3.2.9-1ubuntu2.2)
  * noble 24.04: HAProxy 2.8.30 (from 2.8.16-0ubuntu0.24.04.3)
  
  These updates include bugfixes only following the SRU policy exception defined
  at 
https://documentation.ubuntu.com/sru/en/latest/reference/exception-HAProxy-Updates
  
  [Upstream changes]
  (only major bugs listed, for others see the changelog link)
  
  - for 26.04 - 3.2: https://www.haproxy.org/download/3.2/src/CHANGELOG
-     - BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
-     - BUG/MAJOR: h3: reject H3 truncated frames
-     - BUG/MAJOR: htx: Check the header/trailer length limits when one is 
updated
-     - BUG/MAJOR: mux_quic: fix leak on RESET_STREAM reception
+     - BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
+     - BUG/MAJOR: h3: reject H3 truncated frames
+     - BUG/MAJOR: htx: Check the header/trailer length limits when one is 
updated
+     - BUG/MAJOR: mux_quic: fix leak on RESET_STREAM reception
      - BUG/MAJOR: ssl/ocsp: lock the OCSP response around reads in the 
stapling callback
      - BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error
      - BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in 
h2c_dec_hdrs()
      - BUG/MAJOR: http: forbid comma character in authority value
      - BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based 
normalization
      - BUG/MAJOR: mux-h1: Deal with true 64-bits integer to emit chunks size
      - BUG/MAJOR: slz: always make sure to limit fixed output to less than 
worst case literals
      - BUG/MAJOR: sched: protect task->expire on 32-bit platforms
      - BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well
      - BUG/MAJOR: h3: check body size with content-length on empty FIN
      - BUG/MAJOR: qpack: unchecked length passed to huffman decoder
      - BUG/MAJOR: fcgi: Fix param decoding by properly checking its size
      - BUG/MAJOR: resolvers: Properly lowered the names found in DNS response
      - BUG/MAJOR: Revert "MEDIUM: mux-quic: add BUG_ON if sending on locally 
closed QCS"
      - BUG/MAJOR: applet: Don't call I/O handler if the applet was shut
      - BUG/MAJOR: quic: reject invalid token
      - BUG/MAJOR: quic: fix parsing frame type
  
  - for noble - 2.8: https://www.haproxy.org/download/2.8/src/CHANGELOG
-     - BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
-     - BUG/MAJOR: h3: reject H3 truncated frames
-     - BUG/MAJOR: htx: Check the header/trailer length limits when one is 
updated
-     - BUG/MAJOR: mux_quic: fix leak on RESET_STREAM reception
+     - BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
+     - BUG/MAJOR: h3: reject H3 truncated frames
+     - BUG/MAJOR: htx: Check the header/trailer length limits when one is 
updated
+     - BUG/MAJOR: mux_quic: fix leak on RESET_STREAM reception
      - BUG/MAJOR: ssl/ocsp: lock the OCSP response around reads in the 
stapling callback
      - BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error
      - BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in 
h2c_dec_hdrs()
      - BUG/MAJOR: http: forbid comma character in authority value
      - BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based 
normalization
      - BUG/MAJOR: slz: always make sure to limit fixed output to less than 
worst case literals
      - BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well
      - BUG/MAJOR: h3: check body size with content-length on empty FIN
      - BUG/MAJOR: qpack: unchecked length passed to huffman decoder
      - BUG/MAJOR: fcgi: Fix param decoding by properly checking its size
      - BUG/MAJOR: resolvers: Properly lowered the names found in DNS response
      - BUG/MAJOR: stream: Force channel analysis on successful synchronous send
      - BUG/MAJOR: quic: use ncbmbuf for CRYPTO handling
  
  [Test Plan]
  
- TODO: link to the upstream CI pipelines demonstrating all tests are passing
- TODO: if there are any non passing tests - explain why that is ok in this case
+ GitHub Actions runs:
+ https://github.com/TheJJ/haproxy/tree/verify-2.8.30
+ 70dae8f09d58bd05c28a761d9b47136895b679d3
+ - testsuite needed pcre header fix (my commit 
413f957846e5ff0aca155749aa0fb4e15a5ececc)
+ - all tests pass, except openssl=4.1.0-beta1 (which is not in noble)
+ - autopkgtest results:
+   cli                  PASS
+   proxy-localhost      PASS
+   proxy-ssl-termination PASS
+   proxy-ssl-pass-through PASS
  
- TODO: add results of a local autopkgtest run against all the new HAProxy
- versions
+ https://github.com/TheJJ/haproxy/tree/verify-3.2.25 
70469d33ba0edc5503e292518ddf3e5df7aa9605
+ - testsuite also needs pcre header fix (commit 
e20cb386df653848c5f43e6259805a6fafe2cdb9)
+ - all tests pass except openssl=4.1.0-beta1 (which is not in resolute)
+ - autopkgtest results:
+   cli                  PASS
+   proxy-localhost      PASS
+   proxy-ssl-termination PASS
+   proxy-ssl-pass-through PASS
+ 
  
  [Regression Potential]
  
- HAProxy itself does not have many reverse dependencies, however, any upgrade 
is
- a risk to introduce some breakage to other packages. Whenever a test failure 
is
- detected, we will be on top of it and make sure it doesn't affect existing
- users.
- 
- TODO: consider any other regression potential specific to the version being
- updated and list if any.
+ HAProxy itself does not have many reverse dependencies, however, any
+ upgrade is a risk to introduce some breakage to other packages. Whenever
+ a test failure is detected, we will be on top of it and make sure it
+ doesn't affect existing users.

** Also affects: haproxy (Ubuntu Noble)
   Importance: Undecided
       Status: New

** Also affects: haproxy (Ubuntu Resolute)
   Importance: Undecided
       Status: New

** Changed in: haproxy (Ubuntu Noble)
       Status: New => In Progress

** Changed in: haproxy (Ubuntu Resolute)
       Status: New => In Progress

** Changed in: haproxy (Ubuntu Noble)
     Assignee: (unassigned) => Jonas Jelten (jj)

** Changed in: haproxy (Ubuntu Resolute)
     Assignee: (unassigned) => Jonas Jelten (jj)

** Changed in: haproxy (Ubuntu)
       Status: In Progress => Invalid

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153485

Title:
  Backport haproxy for stonking cycle

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/haproxy/+bug/2153485/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to