Skip to content

v0.3.18

Choose a tag to compare

@github-actions github-actions released this 05 Oct 13:30
· 185 commits to master since this release
76ce2ef

修正

  • メールサーバの EHLO の応答に UTF-8 でないバイトや多バイト文字が混ざると、STARTTLS の接続のタスクが panic で落ちていたのを直しました(ファジングで見つかりました)。
  • match の式を深く入れ子にするとスタックがあふれてプロセス全体が落ちていたのを直しました(#180)。入れ子は 32 段まで、1 つの式の条件は 256 個までで、超えると設定の誤り(API は 400、起動・読み直し・--check-config でも誤り)になります。
  • 時間の値(rate_limit の期間、タイムアウト、health_check、retry、circuit_breaker、CrowdSec の update_interval など)にとても大きな値を書くと、あふれて小さな値になったり、プロセスが落ちたりしていたのを直しました。365 日(8760h)を超える値は設定の誤りになります。

追加

  • GET /capabilities が rproxy-api のバージョン(version)を返すようになりました。管理 UI がバージョンを表示し、組み合わせを確かめるのに使います。

変更

  • rproxy-api と管理 UI のバージョン番号は、それぞれ別に進めるようにしました(docs/RELEASING.md)。組み合わせは UI の画面で確かめられます。

UI の最新: TCP-UDP-rproxy-ui v0.3.18


Fixed

  • A STARTTLS connection task panicked when the mail server's EHLO reply contained non-UTF-8 bytes or multi-byte characters (found by fuzzing).
  • Deeply nested match expressions overflowed the stack and aborted the whole process (#180). Nesting is now limited to 32 levels and an expression to 256 matchers; beyond that it is a configuration error (400 from the API, and an error at startup, on reload and from --check-config).
  • Very large durations (rate_limit periods, timeouts, health_check, retry, circuit_breaker, CrowdSec update_interval, …) could overflow to small values or crash the process. Durations over 365 days (8760h) are now configuration errors.

Added

  • GET /capabilities now returns the rproxy-api version. The management UI shows it and uses it to check compatibility.

Changed

  • rproxy-api and the management UI now have independent version numbers (docs/en/RELEASING.md). The UI shows whether they fit together.

Latest UI: TCP-UDP-rproxy-ui v0.3.18