Repository navigation
v5.1.4
Security release. Released together with 5.2.2, 5.1.4, 5.0.10, 4.3.7 and 3.2.13: with a namespace, a retried request could read or write a different key (GHSA-m252-9cgf-vx2w); completes the fixes for GHSA-wr87-m4jw-29x5 and GHSA-w39f-xq2m-4g8x from 5.1.3, and fixes regressions from that release. Upgrading is strongly recommended.
Security:
- Keep the caller's key when retrying a request (GHSA-m252-9cgf-vx2w)
- With a
namespace, a request retried after a transient network error (a timeout, or a connection closed by memcached or a proxy) applied the namespace a second time, so a retried read could return a different key's value and a retried write could overwrite a different key - Affects single-key operations since 5.0.3, single-server
get_multisince 5.1.0, andget_with_metadataandfetch_with_locksince 4.1.0; fixed in 5.2.2, 5.1.4, 5.0.10 and 4.3.7. Clients without a namespace aren't affected
- With a
- Complete the fix for per-request
raw: trueon reads (GHSA-wr87-m4jw-29x5)- A read made with
raw: truedoesn't ask for flags, but a reply carrying them anyway (from a proxy or a hostile server) still had its value deserialized. Raw reads now ignore flags in the reply - Affects 5.1.3 and earlier; fixed in 5.2.2, 5.1.4, 5.0.10, 4.3.7 and 3.2.13
- A read made with
Bug fixes:
get_with_metadataandfetch_with_lockretried the final error raised when a server is marked down, so withdown_retry_delay: 0they retried an unresponsive server forever. They now retry only retryable errors, like other operations- Fix a regression in 5.1.3: a
get_multithat didn't finish withinsocket_timeoutcounted towardsocket_max_failures, so two slowget_multicalls in a row marked a healthy server down. It now just closes the connection - Fix a regression in 5.1.3: over TLS, every request buffered in a
quietblock was sent as its own TLS record and system call (2.5 times slower for a block of 2000 deletes). Each flush is one write again - Handle malformed replies from a broken or hostile server or proxy: a negative value size, a hit with no key, or a hit with no
sflag could leave the connection out of step or raise a non-Dalli error - With
decompressed_max_bytesin effect, data after the end of a compressed value's stream was returned as part of the value. It's now ignored, as without the limit - With a
digest_classwhose digests aren't short hex strings, shortening a long key could loop forever. It now raisesArgumentError
Development:
- Run the Tests, RuboCop and Profiles workflows on pushes to
mainand the*-stablebranches only, so a pull request's branch isn't tested twice (backport of #1198) - Fix flaky failover tests: move their ports out of Linux's ephemeral port range, and wait for memcached to accept connections after starting it (backport of #1184)