Repository navigation
v0.3.18
·
185 commits
to master
since this release
修正
- メールサーバの EHLO の応答に UTF-8 でないバイトや多バイト文字が混ざると、STARTTLS の接続のタスクが panic で落ちていたのを直しました(ファジングで見つかりました)。
matchの式を深く入れ子にするとスタックがあふれてプロセス全体が落ちていたのを直しました(#180)。入れ子は 32 段まで、1 つの式の条件は 256 個までで、超えると設定の誤り(API は 400、起動・読み直し・--check-configでも誤り)になります。- 時間の値(
rate_limitの期間、タイムアウト、health_check、retry、circuit_breaker、CrowdSec のupdate_intervalなど)にとても大きな値を書くと、あふれて小さな値になったり、プロセスが落ちたりしていたのを直しました。365 日(8760h)を超える値は設定の誤りになります。
追加
GET /capabilitiesが rproxy-api のバージョン(version)を返すようになりました。管理 UI がバージョンを表示し、組み合わせを確かめるのに使います。
変更
- rproxy-api と管理 UI のバージョン番号は、それぞれ別に進めるようにしました(docs/RELEASING.md)。組み合わせは UI の画面で確かめられます。
UI の最新: TCP-UDP-rproxy-ui v0.3.18
Fixed
- A STARTTLS connection task panicked when the mail server's EHLO reply contained non-UTF-8 bytes or multi-byte characters (found by fuzzing).
- Deeply nested
matchexpressions overflowed the stack and aborted the whole process (#180). Nesting is now limited to 32 levels and an expression to 256 matchers; beyond that it is a configuration error (400 from the API, and an error at startup, on reload and from--check-config). - Very large durations (
rate_limitperiods, timeouts,health_check,retry,circuit_breaker, CrowdSecupdate_interval, …) could overflow to small values or crash the process. Durations over 365 days (8760h) are now configuration errors.
Added
GET /capabilitiesnow returns the rproxy-apiversion. The management UI shows it and uses it to check compatibility.
Changed
- rproxy-api and the management UI now have independent version numbers (docs/en/RELEASING.md). The UI shows whether they fit together.
Latest UI: TCP-UDP-rproxy-ui v0.3.18