Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
166 commits
Select commit Hold shift + click to select a range
dd857dc
Add changelog generation tool for GitHub milestones
cmcfarlen Apr 6, 2026
4237219
Update release process docs to use new changelog tool
cmcfarlen Apr 6, 2026
a7a5535
fix python formatting
cmcfarlen Apr 8, 2026
cd07fa5
remove old changelog.pl script
cmcfarlen Apr 22, 2026
1b48d9d
copilot review
cmcfarlen Apr 22, 2026
d0e1feb
Clarify HostDBInfo state (#13092)
masaori335 Apr 22, 2026
33f6c9c
slice: Fix a crash caused by use-after-free (#13113)
maskit Apr 22, 2026
5fd94e0
Fix HTTP/3 crash in HQTransaction::_signal_event (#13093)
bneradt Apr 22, 2026
245d07d
Add support for TLS Certificate Compression (RFC 8879) (#13088)
maskit Apr 22, 2026
d860785
Relocate HostDB tests and benchmark to standard directories (#13115)
masaori335 Apr 22, 2026
c42b437
Fix lock-order inversion deadlock in Diags::tag_activated (#13106)
bneradt Apr 23, 2026
a2a69b7
Cap uncompressed length in TLS Certificate Compression (#13117)
maskit Apr 24, 2026
ffef15f
Support per-remap geo DB handles in header_rewrite (#13042)
cmcfarlen Apr 27, 2026
e93d1a5
Remove unused error page template (#13122)
maskit Apr 28, 2026
6260982
Propagate PROXY-Protocol src to outbound surfaces (#13120)
bneradt Apr 28, 2026
e96202d
Remove virtual dispatch from LogData (#13123)
bneradt Apr 29, 2026
a8270b4
Fix index issue with records in HostDBRecord::select_best_srv (#13132)
cmcfarlen May 4, 2026
ddf4834
Improve config reload error reporting with severity-aware task logs (…
brbzull0 May 5, 2026
e261114
Add `_reload` directive support for config reload framework. (#13110)
brbzull0 May 5, 2026
da9ab88
Update dependencies for h3 tools (#13136)
maskit May 5, 2026
8d4a1b5
Parallelize dir-sync on graceful shutdowns (#12996)
zwoop May 6, 2026
52c3171
hrw4u: Add AST for static analysis and codegen (#13126)
juanthropic May 7, 2026
b7dcab3
Fix XPACK relative index underflow (#13144)
bneradt May 8, 2026
d26986f
Fix combo paths with embedded colons (#13143)
bneradt May 11, 2026
344be9d
Turn off ASAN leak detection running tscore/CompileParseRules during …
cmcfarlen May 11, 2026
60c0aa2
Remove cache alternate vector detach (#13138)
bneradt May 12, 2026
e0caf9a
Fix bg fill teardown crash in update_size_and_time_stats (#13114)
bneradt May 12, 2026
7b9d820
Update dockerfile (#13153)
cmcfarlen May 12, 2026
5848a87
Fix AIO callback from_api completion lifetime (#13151)
bneradt May 12, 2026
87812bb
Honor RECA_NO_ACCESS in record lookup RPC encoder (#13141)
brbzull0 May 13, 2026
dd8c93e
mgmt/rpc: refuse RECA_READ_ONLY/RECA_NO_ACCESS writes (#13142)
brbzull0 May 13, 2026
fdc6056
Avoid confusing AIO callback lifetime test (#13159)
bneradt May 13, 2026
a7d07f6
Quiet regex_map_yaml escape warnings (#13163)
bneradt May 14, 2026
0159141
nexthop health status don't overflow fail count (#13164)
traeak May 14, 2026
5669435
Restore a shortcut in hot loop in _mime_hdr_field_list_search_by_stri…
masaori335 May 14, 2026
ba8b4a9
Fix undercount of cp_list_len (#13161)
masaori335 May 14, 2026
1b35a2e
hrw4u: add --error-format flag with pluggable formatters (#13147)
samtes May 15, 2026
aba9451
Limit regex remap substitutions (#13139)
bneradt May 15, 2026
f18f108
Fix use-of-uninitialized-value problem from fuzzing (#13140)
shukitchan May 17, 2026
0beb455
Zero hdrtoken heap to fix use-of-uninitialized-value (#13172)
shukitchan May 18, 2026
919cbf5
Add cache key hash logging field and public API (#13134)
zwoop May 18, 2026
b298841
Fix RangeTransform on stale-revalidate (#13158)
masaori335 May 19, 2026
37f4603
Allow DNS search_default_domains mode 2 (#13176)
bneradt May 19, 2026
24d31c7
Update AGENTS.md and clarify SECURITY.md plugin scope (#13179)
bryancall May 19, 2026
f57ad1f
Validate m_frag_offset_count and offset during cache unmarshal (#13165)
traeak May 20, 2026
04381a4
Enable code review settings in .asf.yaml (#13183)
ezelkow1 May 20, 2026
e13b958
yaml-cpp-0.9.0 (#13192)
bneradt May 22, 2026
70c856d
GCC 16: Regex header integer includes (#13193)
bneradt May 22, 2026
2006f86
Update H3 dependency build scripts (#13190)
bneradt May 22, 2026
8703778
Stabilize parallel AuTest helpers (#13182)
bneradt May 23, 2026
c2929fd
Single source of truth for Proxy Verifier metadata (#13200)
bneradt May 26, 2026
571b680
Fedora 44 test fixes (#13198)
bneradt May 27, 2026
1ee304f
Slice: Add prefetch deduplication and freelist (#12949)
zwoop May 28, 2026
f5ef7b0
slice: Avoid redundant prefetch re-scheduling (#13215)
zwoop May 29, 2026
06f75ca
Minor fixes to make Cripts building better (#13211)
zwoop May 29, 2026
4a35a0c
Proxy Verifier v3.1.3 (#13217)
bneradt May 29, 2026
cc82da9
tscore: fix out-of-bounds read in ats_base64_decode (#13210)
phongn Jun 1, 2026
a6bb1b3
Update cert compression reporting (#13197)
bneradt Jun 1, 2026
cf85d4e
proxy.config.ssl.client.CA.cert.filename: overridable (#13174)
bneradt Jun 1, 2026
45c741d
Quiet ESI streaming gunzip zero-output logs (#13171)
bneradt Jun 1, 2026
772a217
Rename: PreTransactionLogData -> NonHttpSmLogData (#13154)
bneradt Jun 1, 2026
a5e55e6
Add length check in Doc::data_len() (#13133)
masaori335 Jun 2, 2026
24715a6
cripts: shrink Context from 3408 to 1920 bytes, expand data[] to 16 (…
zwoop Jun 2, 2026
acd6e34
Update codeql.yml (#13221)
ezelkow1 Jun 2, 2026
4fedca9
Fix flaky Fedora 44 AuTest helpers (#13220)
bneradt Jun 2, 2026
db5cf36
curl 8.20 test update: curl PROXY destination changes (#13239)
bneradt Jun 4, 2026
9beb678
fedora:44: Trim remap ACL reload waits (#13237)
bneradt Jun 4, 2026
4d380c0
Adds metrics and log fields for tracking TLS handshake bytes (#12763)
zwoop Jun 4, 2026
d65d667
Fix build: TLS log fields use m_data, not m_http_sm (#13241)
zwoop Jun 5, 2026
bfea6ee
Fix the memory-pressure throttle and its RSS metric (#13219)
moonchen Jun 5, 2026
29fca28
Clamp HTTP3 frame type buf size to reader bytes (#13242)
JosiahWI Jun 8, 2026
17d451c
Emit type-default for custom log fields with no transaction (#13243)
maskit Jun 8, 2026
2a294f8
Gate PP allowlist by header preface (#13125)
bneradt Jun 8, 2026
b0f7d01
Correct records.yaml record drift (#13177)
bneradt Jun 8, 2026
d9eec9a
add bypass header config option to maxmind_acl plugin (#13160)
traeak Jun 8, 2026
9903f67
Fix mismatched sINT/dINT log field types (#13223)
masaori335 Jun 8, 2026
e0e0ccb
Sync CacheDir on shutdown (#13232)
masaori335 Jun 8, 2026
125f952
Cleanup serving stale while origin server down (#13083)
masaori335 Jun 8, 2026
9000703
Fix HTTP/2 stream (transaction) inactivity timeout (#13130)
masaori335 Jun 8, 2026
509cba3
Move some directory helpers to `Directory` (#13245)
JosiahWI Jun 9, 2026
4e565f8
slice: fix stpcpy off-by-one for header value extraction (#13181)
traeak Jun 9, 2026
5de8c2b
Reduce TLS write-path overhead (#13202)
zwoop Jun 9, 2026
97ec7ff
Reduce TLS handshake contention on SSLCertContext (#13098)
c-taylor Jun 9, 2026
ea22d0a
ocsp: add single-cert stapling fast path and certinfo RAII (#13229)
c-taylor Jun 9, 2026
b11ab0f
Fix compilation under `LOOP_CHECK_MODE` (#13250)
JosiahWI Jun 10, 2026
c653a23
authproxy: Release client request handle in StateAuthorized (#13258)
maskit Jun 11, 2026
b0cc713
Fix truncated HTTP version in log field unmarshalling (#13236)
masaori335 Jun 14, 2026
0f3a810
Remove unused EThread members (#13268)
JosiahWI Jun 15, 2026
a3c80e2
Fix mismatched log field types more (#13256)
masaori335 Jun 16, 2026
91dbe5e
Fix bounds check in CacheVC::scanObject (#13263)
traeak Jun 16, 2026
b812bf7
Enable probes in Fedora C++20 CI (#13280)
bneradt Jun 16, 2026
9662e47
Fix tsapi build with ENABLE_PROBES=ON (#13276)
Clendenin Jun 16, 2026
1708310
Remove TsBuffer.h (#13281)
JosiahWI Jun 16, 2026
dde788b
Fix hdrHeap/hdrStrHeap allocator inuse metric underflow (#13218)
moonchen Jun 16, 2026
784e2a5
Fix connect attempt retries (#13102)
masaori335 Jun 16, 2026
8f07fce
Fix incorrect errno short names on FreeBSD/macOS in bwf::Errno (#13240)
bryancall Jun 17, 2026
f399186
Fix txn_box unused find result (#13291)
bneradt Jun 18, 2026
e9dda86
Cripts: make URL::Query copyable via deep-copy of _state (#13269)
serrislew Jun 18, 2026
4bd2f63
ProxyProtocol: free pp_info heap on NetVConnection recycle (#13293)
moonchen Jun 18, 2026
589b3ac
traffic_crashlog: fix false-positive crash logs on clean shutdown (#1…
masaori335 Jun 18, 2026
12c811b
Add `Test.AddConfigReload()` autest extension (#13075)
brbzull0 Jun 19, 2026
9c86523
logging: add a marshalled-bytes counter (#13277)
moonchen Jun 19, 2026
9bc5537
TLS: count handshake signatures by key type (#13289)
moonchen Jun 19, 2026
28ccf73
tests: give cripts ATS startup a longer readiness window (#13304)
moonchen Jun 20, 2026
ca9db0d
header_rewrite: Fix a leak and truncation in set-body-from (#13303)
moonchen Jun 20, 2026
886df74
tools/clang-format.sh: cache clang-format in the common git dir (#13302)
moonchen Jun 20, 2026
7d5f79e
header_rewrite: count operators and conditions run (#13286)
moonchen Jun 20, 2026
68e1ddd
net: count application bytes in read_bytes for TLS (#13282)
moonchen Jun 20, 2026
a3ca9ba
compress: count uncompressed input bytes (#13287)
moonchen Jun 21, 2026
f85edc1
Add unit tests for `Continuation` logic (#13283)
JosiahWI Jun 22, 2026
8d35564
cache: apply per-volume settings on first start after clear (#13252)
masaori335 Jun 22, 2026
592a3bc
dns: destruct HostEnt on free to fix SRV vector leak (#13307)
moonchen Jun 22, 2026
38860f0
Add per-plugin workload counters (#13278)
moonchen Jun 22, 2026
a968959
ci: modernize the coverage helper script (#13305)
moonchen Jun 23, 2026
f138469
Test TLS async without ENGINE (#13264)
bneradt Jun 23, 2026
4a25d04
Downgrade H2 stream error log (#13298)
bneradt Jun 23, 2026
d558bfb
Fix server entry cleanup after request tunnel setup (#13295)
bneradt Jun 23, 2026
e8d26cb
header_rewrite: Improve URL Error messages (#13261)
bneradt Jun 23, 2026
caa6316
Add TSMutex lock guard (#13188)
bneradt Jun 23, 2026
c545a08
redo_cache_lookup: move to examples; fix `fallback` lifetime (#13209)
bneradt Jun 23, 2026
86c14d4
Add cache mechanism to certificate compression (#13284)
maskit Jun 23, 2026
38e86a4
Use fixture listener in test_EventSystem (#13308)
JosiahWI Jun 23, 2026
c8c0c7f
Fix pending HostDB DNS queue removal race (#13294)
bneradt Jun 23, 2026
9824703
Revert "Downgrade H2 stream error log (#13298)" (#13315)
bneradt Jun 23, 2026
c3f1542
Fix set-status crash inside if/endif at remap time (#13052)
moonchen Jun 23, 2026
a173480
Add S3-FIFO RAM cache eviction algorithm (ram_cache.algorithm = 2) (#…
phongn Jun 23, 2026
31667bf
Update FastLZ to b1342da (#13230)
phongn Jun 23, 2026
2ebf2c2
Fix LRU RAM cache seen filter never engaging below 100% full (#13234)
phongn Jun 23, 2026
65aeac4
Add in a vendor copy of Google Highway (#13228)
phongn Jun 23, 2026
a1a7720
Introduce Clang Thread Safety Analysis, and apply it to two subsystem…
moonchen Jun 24, 2026
cc3fc03
Fix redirected cache write without write VC (#13309)
bneradt Jun 24, 2026
891fc90
Use ls-hpack's fast Huffman decoder for HPACK/QPACK strings (#13259)
phongn Jun 24, 2026
d6d64aa
pqsi-pqsp.test.py: address log order flakiness (#13321)
bneradt Jun 25, 2026
319547d
HttpSM.cc: fix cache read end milestone order (#13325)
bneradt Jun 25, 2026
554b4e6
Fix stale_response FORCE_SIE enum (#13326)
bneradt Jun 25, 2026
ffc662c
Clarify HttpSM cache action cleanup (#13327)
bneradt Jun 25, 2026
77528d5
TLS: Fix memory leaks in cert load and OCSP stapling (#13318)
moonchen Jun 25, 2026
5174f73
slice_prefetch.test.py: address cache.log flakiness (#13322)
bneradt Jun 25, 2026
798d5b6
Downgrade inbound H2 stream error log (#13316)
bneradt Jun 25, 2026
9ce8ed6
tests: add TLS gold tests (#13306)
moonchen Jun 25, 2026
ed4f43b
Annotate BRAVO locks for thread-safety analysis (#13330)
masaori335 Jun 25, 2026
e2b93e3
Self-Describing Binary Log Format (v3) (#13231)
masaori335 Jun 25, 2026
920c725
Expand client IP debug logging test coverage (#13290)
bneradt Jun 27, 2026
419ddbd
USDT: normalize names for STATE_ENTER (#13346)
moonchen Jun 29, 2026
0120ce8
Avoid JSONRPC client write spins (#13329)
bneradt Jun 29, 2026
1e13f67
Throttle OCSP cert-status error instead of logging on every handshake…
ezelkow1 Jul 1, 2026
3932622
Fix Proxy-Protocol log field symbols (#13345)
masaori335 Jul 2, 2026
8fb672a
Cleanup: remove unused functions related connect attempts (#13357)
masaori335 Jul 2, 2026
a6273e9
traffic_crashlog: emit a well-formed report when the backtrace is emp…
moonchen Jul 5, 2026
1a8b3a5
docs: add call condition note for TSUrlHostGet (#13313)
mmustafasenoglu Jul 6, 2026
90bffc2
rate_limit: don't update metrics when a selector has no `metrics:` bl…
moonchen Jul 6, 2026
3293881
Add USDT to iocore/net, iocore/cache, http, http2 (#13344)
moonchen Jul 6, 2026
ea16767
Track remaining length while decoding qpack header block (#13361)
dxbjavid Jul 7, 2026
e1d8470
Restore cqssrt log field dropped by the 11-Dev merge (#13337)
masaori335 Jul 7, 2026
c17e3f9
tls_renegotiation autest: gate the detection-line check to OpenSSL (#…
moonchen Jul 8, 2026
3fe3c1d
jax_fingerprint: Reduce allocations and gate methods at build time (#…
maskit Jul 9, 2026
1dcf523
authproxy: strip request-body framing from auth sub-requests (#13333)
moonchen Jul 12, 2026
6ab1275
autest: skip async handshake test when plugin is absent (#13372)
maskit Jul 13, 2026
ed3d117
docs: document the wipe_field_value logging filter (#13374)
maskit Jul 13, 2026
ad24b36
stale_response.test.py: address log wait flakiness (#13323)
bneradt Jul 13, 2026
3978fa4
Refresh default TLS context on secret update (#13342)
bneradt Jul 13, 2026
826eb58
Fix CLFUS RAM cache value metric broken by integer division (#13233)
phongn Jul 13, 2026
69a68a8
Use ts::bravo::shared_mutex for host status lock (#13367)
masaori335 Jul 14, 2026
1032e13
cripts: build against fmt 11+ (incl. 12.x) (#13375)
zwoop Jul 14, 2026
e90dedb
Reject over-long unix socket paths in server_ports (#13356)
moonchen Jul 14, 2026
060a524
Add git range support to generate changelog from commits without PR o…
cmcfarlen Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .asf.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,9 @@ github:
- lzx404243
- phongn
- jasmine-nahrain
copilot_code_review:
enabled: true
review_on_push: true
protected_branches:
master:
required_status_checks:
Expand Down
16 changes: 10 additions & 6 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,16 +23,17 @@ jobs:
name: Analyze
runs-on: ubuntu-latest
permissions:
packages: read
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'cpp' ]
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
# Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support
include:
- language: c-cpp
build-mode: manual

steps:
- name: Checkout repository
Expand All @@ -43,9 +44,10 @@ jobs:
sudo apt install libmagick++-dev libncurses-dev libpcre2-dev libbrotli-dev libluajit-5.1-dev luajit libjansson-dev libcjose-dev libmaxminddb-dev libgeoip-dev ninja-build cmake libpcre3-dev
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.
Expand All @@ -65,11 +67,13 @@ jobs:
# If the Autobuild fails above, remove it and uncomment the following three lines.
# modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.

- run: |
- name: Run manual build steps
shell: bash
run: |
echo "Run, Build Application using script"
cmake -B build --preset ci
cmake --build build -v
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
uses: github/codeql-action/analyze@v4
with:
category: "/language:${{matrix.language}}"
12 changes: 12 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -123,6 +123,13 @@ regularly).
using the Proxy Verifier format. This is simpler, more maintainable, and
parseable by tools.

**Python conventions for test and helper scripts:**
- Launch Python helpers with `{sys.executable}` rather than a hardcoded `python3`,
so the test runs under the same interpreter the harness uses.
- Prefer f-strings over `str.format()` when building command lines, config lines,
and `Testers` expressions.
- Add type annotations to helper functions.

**For complete details on writing autests, see:**
- `doc/developer-guide/testing/autests.en.rst` - Comprehensive guide to autest
- Proxy Verifier format: https://github.com/yahoo/proxy-verifier
Expand Down Expand Up @@ -383,6 +390,11 @@ MIOBuffer *buffer = (MIOBuffer*)malloc(sizeof(MIOBuffer));
- `src/proxy/http/remap/RemapConfig.cc` - URL remapping logic
- `include/ts/ts.h` - Plugin API

## Security

See [SECURITY.md](SECURITY.md) for the project's security policy, threat model,
scope, and vulnerability reporting process.

## Resources

- Official docs: https://trafficserver.apache.org/
Expand Down
46 changes: 44 additions & 2 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -166,9 +166,12 @@ option(ENABLE_AUTEST_UDS "Setup autest with curl using UDS (default OFF)")
option(ENABLE_BENCHMARKS "Build benchmarks (default OFF)")
option(EXTERNAL_YAML_CPP "Use external yaml-cpp (default OFF)")
option(EXTERNAL_LIBSWOC "Use external libswoc (default OFF)")
option(EXTERNAL_HWY "Use external highway (default OFF)")
option(LINK_PLUGINS "Link core libraries to plugins (default OFF)")
option(ENABLE_PROBES "Enable ATS SystemTap probes (default OFF)")
option(ENABLE_VERIFY_PLUGINS "Enable plugin verification tests (default ON)" ON)
option(ENABLE_THREAD_SAFETY_ANALYSIS "Enable Clang -Wthread-safety analysis (Clang only, default ON)" ON)
option(THREAD_SAFETY_ANALYSIS_AS_ERROR "Treat thread-safety findings as errors; for CI gating (default OFF)")

# Setup user
# NOTE: this is the user trafficserver runs as
Expand Down Expand Up @@ -358,6 +361,35 @@ elseif(ENABLE_TSAN)
add_link_options(-g -fsanitize=thread)
endif()

# Clang Thread Safety Analysis. The TS_* annotations (tsutil/ts_thread_safety.h)
# compile to nothing on GCC, and the flag is Clang-only on purpose (GCC does not
# know -Wthread-safety and would itself error if passed it), so this whole block
# is a no-op for GCC builds.
#
# On Clang it is on by default but only a WARNING: -Wno-error=thread-safety keeps
# it a warning even in builds that otherwise use -Werror, so an in-progress
# annotation never blocks a developer's build. CI sets
# THREAD_SAFETY_ANALYSIS_AS_ERROR=ON to promote findings to errors and gate
# merges.
#
# Skip FreeBSD: its libc annotates the pthread primitives themselves, so
# -Wthread-safety there flags ATS's existing hand-rolled mutex wrappers
# (tscore/ink_mutex.h, ink_rwlock, ...) tree-wide, not just newly-annotated code.
# Enabling it on FreeBSD needs those legacy wrappers made analysis-clean first.
# Elsewhere the platform leaves the pthread primitives un-annotated, so only
# annotated code is analyzed and this stays quiet until a real violation.
if(ENABLE_THREAD_SAFETY_ANALYSIS
AND CMAKE_CXX_COMPILER_ID MATCHES "Clang"
AND NOT CMAKE_SYSTEM_NAME STREQUAL "FreeBSD"
)
add_compile_options(-Wthread-safety)
if(THREAD_SAFETY_ANALYSIS_AS_ERROR)
add_compile_options(-Werror=thread-safety)
else()
add_compile_options(-Wno-error=thread-safety)
endif()
endif()

if(ENABLE_PROBES)
add_compile_options("-DENABLE_SYSTEMTAP_PROBES")
endif()
Expand Down Expand Up @@ -415,6 +447,11 @@ if(EXTERNAL_LIBSWOC)
find_package(libswoc REQUIRED)
endif()

if(EXTERNAL_HWY)
message(STATUS "Looking for external highway")
find_package(HWY "1.4.0" CONFIG REQUIRED)
endif()

include(Check128BitCas)
include(ConfigureTransparentProxy)

Expand Down Expand Up @@ -541,6 +578,8 @@ check_symbol_exists(SSL_error_description "openssl/ssl.h" HAVE_SSL_ERROR_DESCRIP
check_symbol_exists(SSL_CTX_set_ciphersuites "openssl/ssl.h" TS_USE_TLS_SET_CIPHERSUITES)
check_symbol_exists(SSL_CTX_set_keylog_callback "openssl/ssl.h" TS_HAS_TLS_KEYLOGGING)
check_symbol_exists(SSL_CTX_set_tlsext_ticket_key_cb "openssl/ssl.h" HAVE_SSL_CTX_SET_TLSEXT_TICKET_KEY_CB)
check_symbol_exists(SSL_CTX_add_cert_compression_alg "openssl/ssl.h" HAVE_SSL_CTX_ADD_CERT_COMPRESSION_ALG)
check_symbol_exists(SSL_CTX_set1_cert_comp_preference "openssl/ssl.h" HAVE_SSL_CTX_SET1_CERT_COMP_PREFERENCE)
check_symbol_exists(SSL_get_all_async_fds openssl/ssl.h TS_USE_TLS_ASYNC)
check_symbol_exists(OSSL_PARAM_construct_end "openssl/params.h" HAVE_OSSL_PARAM_CONSTRUCT_END)
check_symbol_exists(TLS1_3_VERSION "openssl/ssl.h" TS_USE_TLS13)
Expand Down Expand Up @@ -674,8 +713,11 @@ if(ENABLE_AUTEST)
# the autest command. The original AUTEST_OPTIONS string is used in the
# autest.sh script.
separate_arguments(AUTEST_OPTIONS_LIST UNIX_COMMAND "${AUTEST_OPTIONS}")
set(PROXY_VERIFIER_VERSION "v3.1.2")
set(PROXY_VERIFIER_HASH "SHA1=0a60c646cbc9326abb2fbc397cb9efa8c08a807a")
file(READ "${CMAKE_SOURCE_DIR}/tests/proxy-verifier-version.txt" PROXY_VERIFIER_VERSION)
string(STRIP "${PROXY_VERIFIER_VERSION}" PROXY_VERIFIER_VERSION)
file(READ "${CMAKE_SOURCE_DIR}/tests/proxy-verifier-checksum.txt" PROXY_VERIFIER_SHA1)
string(STRIP "${PROXY_VERIFIER_SHA1}" PROXY_VERIFIER_SHA1)
set(PROXY_VERIFIER_HASH "SHA1=${PROXY_VERIFIER_SHA1}")
include(proxy-verifier)
endif()

Expand Down
11 changes: 4 additions & 7 deletions CMakePresets.json
Original file line number Diff line number Diff line change
Expand Up @@ -125,6 +125,8 @@
"cacheVariables": {
"CMAKE_BUILD_TYPE": "Debug",
"CMAKE_COMPILE_WARNING_AS_ERROR": "ON",
"ENABLE_THREAD_SAFETY_ANALYSIS": "ON",
"THREAD_SAFETY_ANALYSIS_AS_ERROR": "ON",
"ENABLE_CCACHE": "ON",
"BUILD_EXPERIMENTAL_PLUGINS": "ON",
"ENABLE_WASM_WAMR": "OFF",
Expand Down Expand Up @@ -194,13 +196,9 @@
"name": "ci-fedora-cxx20",
"displayName": "CI Fedora c++20",
"description": "CI Pipeline config for Fedora Linux compiled with c++20",
"inherits": ["ci"],
"inherits": ["ci-fedora"],
"cacheVariables": {
"opentelemetry_ROOT": "/opt",
"CURL_ROOT": "/opt",
"wamr_ROOT": "/opt",
"CMAKE_CXX_STANDARD": "20",
"ENABLE_CRIPTS": "ON"
"CMAKE_CXX_STANDARD": "20"
}
},
{
Expand Down Expand Up @@ -450,4 +448,3 @@
}
]
}

15 changes: 15 additions & 0 deletions NOTICE
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,7 @@ https://github.com/jbeder/yaml-cpp
~~

fastlz: an ANSI C/C90 implementation of Lempel-Ziv 77 algorithm (LZ77) of lossless data compression.
Copyright (C) 2005-2020 Ariya Hidayat (MIT License)
https://github.com/ariya/FastLZ

~~
Expand All @@ -118,3 +119,17 @@ LS-HPACK provides functionality to encode and decode HTTP headers using
HPACK compression mechanism specified in RFC 7541.
Copyright (c) 2018 - 2023 LiteSpeed Technologies Inc, (MIT License)
https://github.com/litespeedtech/ls-hpack.git

~~

S3-FIFO: A simple, scalable FIFO-based algorithm with three static queues
Copyright 2023, Carnegie Mellon University (Apache-2.0)

Website: https://s3fifo.com/
Paper: http://dx.doi.org/10.1145/3600006.3613147
Reference implementation: https://github.com/Thesys-lab/sosp23-s3fifo

~~

Highway is a C++ library that provides portable SIMD/vector intrinsics.
https://github.com/google/highway
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,6 +143,7 @@ trafficserver ............. Top src dir
├── lib ................... Third-party libraries
│ ├── Catch2 ............ Unit testing framework
│ ├── fastlz ............ Fast compression library
│ ├── highway ........... Portable SIMD/vector intrinsics
│ ├── ls-hpack .......... HPACK compression for HTTP/2
│ ├── swoc .............. Solid Wall of Code utility library
│ ├── systemtap ......... SystemTap integration
Expand Down
8 changes: 6 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,11 @@ Administrative users are always considered to be trusted. Reports for vulnerabil

Security-sensitive information may be logged with modified logging configurations, particularly if debug logging is enabled.

Experimental features and plugins are known unstable and not supposed to be used on production. We do not consider
vulnerabilities in those as security issues. You may report vulnerabilities in those publicly on our public lists or GitHub. However, please
Experimental features are known unstable and not supposed to be used on production. We do not consider
vulnerabilities in those as security issues. This explicitly includes HTTP/3 and QUIC support, which remain
experimental. You may report vulnerabilities in those publicly on our public lists or GitHub. However, please
contact us privately, if you believe the vulnerabilities you find are serious, or if you are not sure whether you should report the
vulnerabilities publicly.

Plugins shipped with Traffic Server, including those under `plugins/experimental/`, are in scope for security
reporting. Please report vulnerabilities in those through the private security mailing list following the process above.
Loading