Skip to content

Bump puma from 3.10.0 to 5.4.0

Milan requested to merge dependabot/bundler/puma-5.4.0 into master

Bumps puma from 3.10.0 to 5.4.0.

Release notes

Sourced from puma's releases.

5.4.0 - Super Flight

CasiopeaSuperFlightalbumcover

  • Features

    • Better/expanded names for threadpool threads (#2657)
    • Allow pkg_config for OpenSSL (#2648, #1412)
    • Add rack_url_scheme to Puma::DSL, allows setting of rack.url_scheme header (#2586, #2569)
  • Bugfixes

    • Binder#parse - allow for symlinked unix path, add create_activated_fds debug ENV (#2643, #2638)
    • Fix deprecation warning: minissl.c - Use Random.bytes if available (#2642)
    • Client certificates: set session id context while creating SSLContext (#2633)
  • Refactor

    • Replace IO.select with IO#wait_* when checking a single IO (#2666)

5.3.2

  • Bugfixes
    • Gracefully handle Rack not accepting CLI options (#2630, #2626)
    • Fix sigterm misbehavior (#2629)
    • Improvements to keepalive-connection shedding (#2628)

This version was released 2021-05-21.

5.3.1

  • Security
    • Close keepalive connections after the maximum number of fast inlined requests (#2625)

5.3.0 - Sweetnighter

5.3.0 / 2021-05-07

Contributor @MSP-Greg codenamed this release "Sweetnighter".

  • Features

    • Add support for Linux's abstract sockets (#2564, #2526)
    • Add debug to worker timeout and startup (#2559, #2528)
    • Print warning when running one-worker cluster (#2565, #2534)
    • Don't close systemd activated socket on pumactl restart (#2563, #2504)
  • Bugfixes

    • systemd - fix event firing (#2591, #2572)
    • Immediately unlink temporary files (#2613)
    • Improve parsing of HTTP_HOST header (#2605, #2584)
    • Handle fatal error that has no backtrace (#2607, #2552)
    • Fix timing out requests too early (#2606, #2574)
    • Handle segfault in Ruby 2.6.6 on thread-locals (#2567, #2566)
    • Server#closed_socket? - parameter may be a MiniSSL::Socket (#2596)
    • Define UNPACK_TCP_STATE_FROM_TCP_INFO in the right place (#2588, #2556)

... (truncated)

Changelog

Sourced from puma's changelog.

5.4.0 / 2021-07-28

  • Features

    • Better/expanded names for threadpool threads (#2657)
    • Allow pkg_config for OpenSSL (#2648, #1412)
    • Add rack_url_scheme to Puma::DSL, allows setting of rack.url_scheme header (#2586, #2569)
  • Bugfixes

    • Binder#parse - allow for symlinked unix path, add create_activated_fds debug ENV (#2643, #2638)
    • Fix deprecation warning: minissl.c - Use Random.bytes if available (#2642)
    • Client certificates: set session id context while creating SSLContext (#2633)
    • Fix deadlock issue in thread pool (#2656)
  • Refactor

    • Replace IO.select with IO#wait_* when checking a single IO (#2666)

5.3.2 / 2021-05-21

  • Bugfixes
    • Gracefully handle Rack not accepting CLI options (#2630, #2626)
    • Fix sigterm misbehavior (#2629)
    • Improvements to keepalive-connection shedding (#2628)

5.3.1 / 2021-05-11

  • Security
    • Close keepalive connections after the maximum number of fast inlined requests (CVE-2021-29509) (#2625)

5.3.0 / 2021-05-07

  • Features

    • Add support for Linux's abstract sockets (#2564, #2526)
    • Add debug to worker timeout and startup (#2559, #2528)
    • Print warning when running one-worker cluster (#2565, #2534)
    • Don't close systemd activated socket on pumactl restart (#2563, #2504)
  • Bugfixes

    • systemd - fix event firing (#2591, #2572)
    • Immediately unlink temporary files (#2613)
    • Improve parsing of HTTP_HOST header (#2605, #2584)
    • Handle fatal error that has no backtrace (#2607, #2552)
    • Fix timing out requests too early (#2606, #2574)
    • Handle segfault in Ruby 2.6.6 on thread-locals (#2567, #2566)
    • Server#closed_socket? - parameter may be a MiniSSL::Socket (#2596)
    • Define UNPACK_TCP_STATE_FROM_TCP_INFO in the right place (#2588, #2556)
    • request.rb - fix chunked assembly for ascii incompatible encodings, add test (#2585, #2583)
  • Performance

    • Reset peerip only if remote_addr_header is set (#2609)
    • Reduce puma_parser struct size (#2590)

... (truncated)

Commits

Merge request reports

Loading