Timeline



09/06/21:

18:23 Ticket #2243 (grpc_socket_keepalive on; Doesn't work) created by f4nff@…
[…] After testing, turn on grpc_socket_keepalive on; the …
15:13 Ticket #2242 (DNS UDP proxy with UNIX socket is not working) updated by Maxim Dounin
Since each session needs to use an unique path, I don't think there is …
14:14 Ticket #2242 (DNS UDP proxy with UNIX socket is not working) updated by Vladislav Odintsov
Thanks for the feedback. Should we look for another solution to handle …
13:59 Changeset in nginx [8842:486c6a9be111]quic by Roman Arutyunyan <arut@…>
QUIC: store QUIC connection fd in stream fake connection. Previously …
13:19 Ticket #2242 (DNS UDP proxy with UNIX socket is not working) updated by Maxim Dounin
Status, Priority changed
For datagram unix socket to work for server-to-client communication, …
11:54 Changeset in nginx [7924:d9e009b39596] by Maxim Dounin <mdounin@…>
HTTP/2: optimized processing of small DATA frames. The request body …
11:54 Changeset in nginx [7923:4775c1d27378] by Maxim Dounin <mdounin@…>
HTTP/2: fixed timers left after request body reading. Following …
11:54 Changeset in nginx [7922:e9f402bfe37e] by Maxim Dounin <mdounin@…>
HTTP/2: fixed window updates when buffering in filters. In the body …

09/04/21:

11:50 Changeset in nginx-tests [1728:6d5ecf445e57] by Sergey Kandaurov <pluknet@…>
Tests: added HTTP/2 test with big request body. Notably, it is useful …

09/03/21:

14:19 Changeset in nginx [7920:2b2607d13fe9] by Roman Arutyunyan <arut@…>
Version bump.
12:27 Ticket #2242 (DNS UDP proxy with UNIX socket is not working) created by Vladislav Odintsov
Hi, things go in such a way, that I need to pass DNS traffic from LXC …
11:23 Changeset in nginx [8841:1f7f98638dc2]quic by Mariano Di Martino <mariano.dimartino@…>
QUIC: fixed null pointer dereference in MAX_DATA handler. If a …

09/02/21:

19:30 Changeset in nginx-tests [1727:bdefe70ae1a7] by Dmitry Volyntsev <xeioex@…>
Tests: removed negative fetch API test for HTTPS schema. HTTPS …
09:25 Changeset in nginx [7921:2245324a507a] by Roman Arutyunyan <arut@…>
Fixed debug logging.

09/01/21:

13:33 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) closed by Maxim Dounin
invalid: As previously suggested, if you need help with configuring nginx, …
13:07 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) reopened by garycnew@…
Maxim, After pouring through debug logs, which Nginx debug logs …
08:12 Changeset in nginx [8840:4d871baeacd2]quic by Sergey Kandaurov <pluknet@…>
README: HTTP/3 trailers are now supported.
07:57 Changeset in nginx [8839:fac88e160653]quic by Sergey Kandaurov <pluknet@…>
Merged with the default branch.
04:53 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by garycnew@…
@mikhail.isachenkov > We are unable to reproduce this issue with …

08/31/21:

15:57 Milestone njs-0.6.2 completed
Planned features and enhancements: * Promise.all(), …
15:56 Milestone nginx-1.21.2 completed
Status: scheduled Trunk: mainline * OpenSSL 3.0 …
15:13 Changeset in nginx [7919:b2d1a602b241] by Maxim Dounin <mdounin@…>
release-1.21.2 tag
15:13 Changeset in nginx [7918:bfbc52374adc]release-1.21.2 by Maxim Dounin <mdounin@…>
nginx-1.21.2-RELEASE
14:54 Changeset in nginx [7967:5de6a960632e]stable-1.20 by Maxim Dounin <mdounin@…>
Updated OpenSSL used for win32 builds.
14:54 Changeset in nginx [7917:f0ab1db646d5] by Maxim Dounin <mdounin@…>
Updated OpenSSL used for win32 builds.
13:44 Changeset in nginx [7916:29795b697e14] by Maxim Dounin <mdounin@…>
HTTP/2: avoid memcpy() with NULL source and zero length. Prodded by …
13:17 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by mikhail.isachenkov
Gary, We are unable to reproduce this issue with official nginx and …
13:15 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) closed by Maxim Dounin
invalid: Sorry, this is not how it works. If you need help with your …
04:46 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) reopened by garycnew@…
Maxim, Points omitted from your facts-summary: The test environment …

08/30/21:

18:16 Ticket #2238 (Difference in ssl_verify_depth and ssl_verify_client optional_no_ca ...) closed by Maxim Dounin
invalid: Thanks for confirming, closing this.
17:17 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) closed by Maxim Dounin
invalid: Thanks for the feedback. So, to summarise, the following facts are …
13:42 Changeset in nginx-tests [1726:f66266cc82c8] by Maxim Dounin <mdounin@…>
Tests: additional HTTP/2 request body tests.
13:12 Ticket #196 (Inconsistent behavior on uri's with unencoded spaces followed by H) updated by Maxim Dounin
See also #2241.
13:11 Ticket #2241 (Under special circumstances cause http code 400) closed by Maxim Dounin
duplicate: Duplicate of #196.
11:45 Changeset in nginx [7915:09d15a2dbc6b] by Sergey Kandaurov <pluknet@…>
Give GCC atomics precedence over deprecated Darwin atomic(3). This …
10:31 Ticket #2238 (Difference in ssl_verify_depth and ssl_verify_client optional_no_ca ...) updated by Malte Schmidt
Hello, I re-evaluated the configs and found that the ssl_verify_depth …
10:29 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by garycnew@…
Maxim, Is it possible to escalate this ticket to someone at Nginx …
02:09 Ticket #2241 (Under special circumstances cause http code 400) created by zhoulin1359@…
Incorrect: curl 'http://nginx.org?a=A H' normal:curl …

08/29/21:

21:22 Ticket #2240 (little endian not set when cross compilation for little endian targets) updated by Maxim Dounin
> this issue i'm reporting here is probably the cause of the #1928
20:35 Ticket #2240 (little endian not set when cross compilation for little endian targets) updated by nhed@…
but additionally - this issue i'm reporting here is probably the cause …
20:30 Ticket #2240 (little endian not set when cross compilation for little endian targets) updated by nhed@…
for context i'm building under buildroot Seeing the --crossbuild
19:22 Changeset in nginx [7914:9cf043a5d9ca] by Maxim Dounin <mdounin@…>
Request body: reading body buffering in filters. If a filter wants to …
19:21 Changeset in nginx [7913:185c86b830ef] by Maxim Dounin <mdounin@…>
Request body: introduced rb->last_saved flag. It indicates that the …
19:20 Changeset in nginx [7912:96e09beaa2cf] by Maxim Dounin <mdounin@…>
Request body: added alert to catch duplicate body saving. If due to …
19:20 Changeset in nginx [7911:d869e43643ac] by Maxim Dounin <mdounin@…>
Request body: missing comments about initialization.
19:20 Changeset in nginx [7910:1d78437dbc3f] by Maxim Dounin <mdounin@…>
HTTP/2: improved handling of preread unbuffered requests. Previously, …
19:20 Changeset in nginx [7909:f302c1096f7b] by Maxim Dounin <mdounin@…>
HTTP/2: improved handling of END_STREAM in a separate DATA frame. The …
19:20 Changeset in nginx [7908:0dcec8e5d50a] by Maxim Dounin <mdounin@…>
HTTP/2: reworked body reading to better match HTTP/1.x code. In …
19:20 Changeset in nginx [7907:51f463301f86] by Maxim Dounin <mdounin@…>
HTTP/2: improved body reading logging.
18:45 Ticket #2240 (little endian not set when cross compilation for little endian targets) closed by Maxim Dounin
invalid: Cross-compilation is not supported by nginx, and your attempts to …
04:23 Ticket #2240 (little endian not set when cross compilation for little endian targets) created by nhed@…
This causes corrupt http2 headers Default seems to be big endian and …
03:14 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by Maxim Dounin
> I believe this ticket was closed prematurely. The resets you …

08/28/21:

07:23 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) reopened by garycnew@…
07:20 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by garycnew@…
Maxim, I believe this ticket was closed prematurely. The resets you …

08/27/21:

22:08 Ticket #2238 (Difference in ssl_verify_depth and ssl_verify_client optional_no_ca ...) updated by Maxim Dounin
In OpenSSL 1.1.0, verification of certificates was changed. In …
18:55 Ticket #2239 (Unterminated string result in ngx_sock_ntop()) closed by Maxim Dounin
invalid: > ... will leave the resulting text unterminated. In nginx, strings …
16:12 Ticket #2239 (Unterminated string result in ngx_sock_ntop()) created by GregIthaca@…
I've been studying/running your code for security research, and I've …

08/26/21:

16:04 Ticket #2238 (Difference in ssl_verify_depth and ssl_verify_client optional_no_ca ...) created by Malte Schmidt
Hello, upgrading from Ubuntu 16.04 to 20.04 (meaning nginx 1.16 to …

08/25/21:

23:25 Ticket #2237 (get host in http stream) closed by Maxim Dounin
wontfix: There are no plans to implement something like this. If for some …
17:14 Ticket #2237 (get host in http stream) created by xqdoo00o@…
Hi, the code below: stream { server { listen 80; …
05:52 Ticket #2236 (Unable to reach APT repository for nginx.org) created by seanking2919@…
I'm not sure if my server is blacklisted for some reason or if this is …

08/24/21:

19:38 Ticket #2235 (Allow setting TLS handshake timeouts for http(/2)) closed by Maxim Dounin
wontfix: SSL handshake time in the HTTP module is limited by the …
19:33 Ticket #1388 (Implement TLS Dynamic Record Sizing (CloudFlare patch ready)) updated by Maxim Dounin
> Lower ssl_buffer_size (<1400 bytes) help, but are not optimal after …
17:13 Ticket #2235 (Allow setting TLS handshake timeouts for http(/2)) created by ltning@…
Currently only the stream_ssl module supports any kind of tuning of …
17:06 Ticket #1388 (Implement TLS Dynamic Record Sizing (CloudFlare patch ready)) updated by ltning@…
We run a service that is seeing traffic from devices all over the …
15:15 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) closed by Maxim Dounin
invalid: First connection attempt as seen in the nginx-to-backend dump …
03:16 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by garycnew@…
Maxim, We have uploaded the nginx-tor-tcpdumps to github as you …

08/23/21:

16:02 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by Maxim Dounin
> I'd be happy to provide the raw, unfiltered packet-traces, but your …
08:31 Changeset in nginx-tests [1725:f4c79ee52d8f] by Sergey Kandaurov <pluknet@…>
Tests: added grpcs tests with flow control (ticket #2229). The tests …
08:28 Ticket #2233 (Packages for Debian Bullseye should include 32-bit x86 binaries) updated by Laurence 'GreenReaper' Parry
Well, I can do this. It's a hassle, but little more than the kernels I …
07:05 Ticket #2233 (Packages for Debian Bullseye should include 32-bit x86 binaries) updated by thresh
Indeed, we provide no 32bit binaries for new platforms anymore - this …
05:41 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by garycnew@…
Hi Maxim! Thank you for your prompt reply to this ticket. > First of …

08/22/21:

20:56 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by Maxim Dounin
Priority changed
> There appears to be a bug with NGINX 1.19.2 immediately sending a …
03:34 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) updated by garycnew@…
Description changed
02:50 Ticket #2234 (NGINX 1.19.2 TCP RST/ACK TLSv1.0 Client Hello of Tor Relay ORPort ...) created by garycnew@…
There appears to be a bug with NGINX 1.19.2 immediately sending a TCP …

08/21/21:

04:23 Ticket #2233 (Packages for Debian Bullseye should include 32-bit x86 binaries) created by Laurence 'GreenReaper' Parry
[http://nginx.org/packages/mainline/debian/dists/bullseye/nginx/

08/20/21:

22:17 Ticket #2229 (Grpc Upstream timeout) closed by Maxim Dounin
fixed: Fix committed, thanks for reporting this.
19:15 Ticket #2229 (Grpc Upstream timeout) updated by Maxim Dounin <mdounin@…>
In [changeset:"058a67435e83cfb3bb123f6c176be8d4c453f9b6/nginx"
00:53 Changeset in nginx [7966:5d09596909c6]stable-1.20 by Maxim Dounin <mdounin@…>
Upstream: fixed timeouts with gRPC, SSL and select (ticket #2229). …
00:53 Changeset in nginx [7906:058a67435e83] by Maxim Dounin <mdounin@…>
Upstream: fixed timeouts with gRPC, SSL and select (ticket #2229). …

08/19/21:

17:51 Changeset in nginx [7943:2a7155733855] by Alexey Radkov <alexey.radkov@…>
Core: removed unnecessary restriction in hash initialization. Hash …
15:53 Milestone unit-1.25 completed
Planned features and enhancements: * additional Ruby hooks * …

08/18/21:

19:13 Ticket #2134 (ssl cipher logging for mail) closed by Maxim Dounin
fixed
14:43 Changeset in nginx-tests [1724:1522ab9d37b4] by Sergey Kandaurov <pluknet@…>
Tests: Auth-SSL-Protocol and Auth-SSL-Cipher tests (ticket #2134).
14:22 Ticket #2232 (ngx_http_auth_basic_module does not support different passwords for ...) closed by Maxim Dounin
wontfix: Unix user files are expected to contain one line per user. There are …
12:17 Ticket #2232 (ngx_http_auth_basic_module does not support different passwords for ...) created by Chupaka@…
I need to proxy some API and change "local" basic auth (with static …

08/17/21:

22:28 Ticket #2134 (ssl cipher logging for mail) updated by Rob Mueller <robm@…>
In [changeset:"13d0c1d26d47c203b1874ca1ffdb7a9ba7fd2d77/nginx"
14:33 Ticket #2217 (Requesting nginx packages for Debian Bullseye) updated by Randy Fay
Thanks so much!
12:06 Ticket #2229 (Grpc Upstream timeout) updated by xTeare@…
I was indeed able to fix the problem with your "quick-fix". I've …
10:03 Ticket #2201 (build_module.sh error cd: pkg-oss/rpm/SPECS: No such file or directory) closed by thresh
fixed: Fixed since http://hg.nginx.org/pkg-oss/rev/9e7c296dcad6 Thanks!
09:45 Ticket #2201 (build_module.sh error cd: pkg-oss/rpm/SPECS: No such file or directory) updated by thresh
Owner, Status changed
09:40 Ticket #2180 (Installation instructions fail on Ubuntu 16.04) closed by thresh
fixed: The current instructions (since …
09:35 Ticket #2217 (Requesting nginx packages for Debian Bullseye) closed by thresh
fixed: Hello, The packages for Debian 11 are published now for x86_64 and …

08/16/21:

23:01 Ticket #2035 (Can't get old SSL cert to work - ca md too weak) closed by Maxim Dounin
fixed: Fix committed, thanks for reporting this.
23:00 Ticket #2229 (Grpc Upstream timeout) updated by Maxim Dounin
I'm able to reproduce it with slightly modified grpc.t, …
21:26 Ticket #2035 (Can't get old SSL cert to work - ca md too weak) updated by Maxim Dounin <mdounin@…>
In [changeset:"419c066cb7103165fe008339d210037f68a72d4f/nginx"
19:40 Changeset in nginx [7904:419c066cb710] by Maxim Dounin <mdounin@…>
SSL: ciphers now set before loading certificates (ticket #2035). To …
13:36 Changeset in nginx [7903:f2ddd0c491bf] by Maxim Dounin <mdounin@…>
Dark mode support in welcome and 50x error pages. Prodded by Duncan Lock.
13:36 Changeset in nginx [7902:67c68cd973b8] by Maxim Dounin <mdounin@…>
Welcome and 50x error pages style. Indentation of the CSS code …
12:14 Ticket #2217 (Requesting nginx packages for Debian Bullseye) updated by Randy Fay
Debian 11 Bullseye has now been released, thanks for working on this!
08:45 Ticket #2229 (Grpc Upstream timeout) updated by xTeare@…
Do you have a rough estimate when this will get fixed ? Our …

08/14/21:

02:51 Ticket #2035 (Can't get old SSL cert to work - ca md too weak) updated by Maxim Dounin
SSL ciphers are configured by nginx after loading the certificates, so …

08/13/21:

07:57 Changeset in nginx [7905:13d0c1d26d47] by Rob Mueller <robm@…>
Mail: Auth-SSL-Protocol and Auth-SSL-Cipher headers (ticket #2134). …
01:40 Ticket #1781 (Does not build on Mac with OpenSSL) updated by Maxim Dounin
See also #2227.
01:40 Ticket #2227 (Nginx 1.21.1 source build with static openssl fails on Freebsd12) closed by Maxim Dounin
invalid: The error messages suggest there is a conflicting SSL library, likely …
00:33 Ticket #2226 (Please add cache compression) closed by Maxim Dounin
wontfix: While compression might be beneficial to reduce latency, note that …
00:02 Ticket #2164 (Unable to add `$upstream_addr` to a response header field) closed by Maxim Dounin
worksforme: Feedback timeout.

08/12/21:

23:59 Ticket #2111 (Worker dumps core with image_filter test, proxy and HTML response from ...) closed by Maxim Dounin
worksforme: Feedback timeout. Unfortunately, it is not possible to reproduce the …
21:00 Ticket #2231 (proxy_cache_bypass sets variable defined in map) closed by Maxim Dounin
invalid: The proxy_cache_bypass directive is evaluated before making a …
20:44 nginx.conf attached to Ticket #2231 by mr.oliver.nadj@…
20:44 Dockerfile attached to Ticket #2231 by mr.oliver.nadj@…
20:44 Ticket #2231 (proxy_cache_bypass sets variable defined in map) created by mr.oliver.nadj@…
When I use the combination of […] and `proxy_cache_bypass …
11:01 Ticket #2230 (pkg-oss scripts break if 'so' included in path) closed by thresh
fixed: Thanks! Fixed in http://hg.nginx.org/pkg-oss/rev/e7d65b792793.

08/11/21:

19:18 Ticket #2229 (Grpc Upstream timeout) updated by Sergey Kandaurov
Status changed
Looks like there is a bug that causes removing read event after …
18:41 nginx_soso.patch attached to Ticket #2230 by https://stackoverflow.com/users/93534/notpeter
18:40 Ticket #2230 (pkg-oss scripts break if 'so' included in path) created by https://stackoverflow.com/users/93534/notpeter
The nginx pkg-oss repo uses sed to help rename .so to -debug.so in a …
14:38 Ticket #2229 (Grpc Upstream timeout) updated by xTeare@…
Description changed
14:12 Ticket #2229 (Grpc Upstream timeout) created by xTeare@…
So, i've got these things : a client, a server, nginx. They all run on …
13:28 Ticket #2228 (SSL_write() failed...) closed by Maxim Dounin
invalid: This is a bug in OpenSSL 1.1.1. The …
10:38 Ticket #2228 (SSL_write() failed...) created by gidiwe2427
I got this in my error log: [crit] 1098#1098: *228213 SSL_write() …
08:55 Changeset in nginx-tests [1723:3581dc3c1937] by Sergey Kandaurov <pluknet@…>
Tests: added ssl test for "unexpected eof while reading". See for …

08/10/21:

20:43 Changeset in nginx [7965:f2bbbc0ccdfb]stable-1.20 by Sergey Kandaurov <pluknet@…>
SSL: use of the SSL_OP_IGNORE_UNEXPECTED_EOF option. A new behaviour …
20:43 Changeset in nginx [7901:dda421871bc2] by Sergey Kandaurov <pluknet@…>
SSL: removed use of the SSL_OP_MSIE_SSLV2_RSA_PADDING option. It has …
20:43 Changeset in nginx [7900:509b663a789c] by Sergey Kandaurov <pluknet@…>
SSL: removed export ciphers support. Export ciphers are forbidden to …
20:43 Changeset in nginx [7899:1a03af395f44] by Sergey Kandaurov <pluknet@…>
SSL: use of the SSL_OP_IGNORE_UNEXPECTED_EOF option. A new behaviour …
20:43 Changeset in nginx [7964:7b79f0944197]stable-1.20 by Sergey Kandaurov <pluknet@…>
SSL: silenced warnings when building with OpenSSL 3.0. The …
20:43 Changeset in nginx [7963:9b9299494238]stable-1.20 by Sergey Kandaurov <pluknet@…>
SSL: ERR_peek_error_line_data() compatibility with OpenSSL 3.0. …
20:43 Changeset in nginx [7962:ddfad46492b5]stable-1.20 by Sergey Kandaurov <pluknet@…>
SSL: using SSL_CTX_set0_tmp_dh_pkey() with OpenSSL 3.0 in dhparam. …
20:43 Changeset in nginx [7961:c7c6a87c068d]stable-1.20 by Sergey Kandaurov <pluknet@…>
SSL: SSL_get_peer_certificate() is deprecated in OpenSSL 3.0. Switch …
20:43 Changeset in nginx [7898:8f7107617550] by Sergey Kandaurov <pluknet@…>
SSL: silenced warnings when building with OpenSSL 3.0. The …
20:43 Changeset in nginx [7897:4195a6f0c61c] by Sergey Kandaurov <pluknet@…>
SSL: ERR_peek_error_line_data() compatibility with OpenSSL 3.0. …
20:43 Changeset in nginx [7896:1e0fabbe01c7] by Sergey Kandaurov <pluknet@…>
SSL: using SSL_CTX_set0_tmp_dh_pkey() with OpenSSL 3.0 in dhparam. …
20:43 Changeset in nginx [7895:8ebda26e4f98] by Sergey Kandaurov <pluknet@…>
SSL: SSL_get_peer_certificate() is deprecated in OpenSSL 3.0. Switch …
20:42 Changeset in nginx [7960:ec2798eb3648]stable-1.20 by Sergey Kandaurov <pluknet@…>
SSL: RSA data type is deprecated in OpenSSL 3.0. The only consumer is …
20:42 Changeset in nginx [7894:37be19a3c0ee] by Sergey Kandaurov <pluknet@…>
SSL: RSA data type is deprecated in OpenSSL 3.0. The only consumer is …

08/09/21:

15:13 Changeset in nginx-tests [1722:122002b19416] by Sergey Kandaurov <pluknet@…>
Tests: HTTP/1.0 requests with Transfer-Encoding.
15:12 Changeset in nginx [7893:7a6afd584eb4] by Sergey Kandaurov <pluknet@…>
Disabled HTTP/1.0 requests with Transfer-Encoding. The latest …
Note: See TracTimeline for information about the timeline view.