diff --git a/CHANGELOG b/CHANGELOG index 7493453..2bfe936 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -1,18 +1,13 @@ -3proxy-0.9.9 Released August, 20 2026 +3proxy-1.0.0 Released August, 22 2026 -! Fix: DNS replies are validated now: a reply from an address other than the nameserver the query was sent to, and a reply with a question section not matching the query, are dropped; both were accepted before -! Fix: socket leak with SOCKSv5 UDP ASSOCIATE through a parent proxy, sockets were accumulated in CLOSE_WAIT state until descriptors ran out -! Fix: file descriptor leak in HTTP proxy on the ftp:// request path -! Fix: crash with illegal instruction on some platforms (e.g. some musl based Linux builds), caused by a memcpy on overlapping buffers -! Fix: extip and ha (HAProxy PROXY protocol) parents are applied to SOCKSv5 UDP ASSOCIATE now -! Fix: only socks5 and socks5+ parents are tried for UDP ASSOCIATE, other parent types can not be used for UDP -! Fix: udppm through a SOCKSv5 parent did not work -! Fix: -Ne and -Ni options were never applied, the option letter was not parsed; -Ne is not applied to the UDP ASSOCIATE reply anymore, -Ni is applied to it -! Fix: -4 / -6 handling for UDP in socks; a single UDP association can use both IPv4 and IPv6 destinations now -! Fix: a datagram with a null destination address is dropped now -! Fix: DNS over TCP: a reply which did not fit a single read was never processed -! Documentation: "How to apply ACLs to UDP traffic" added to HOWTO; authentication cache, ACL and UDP notes added to "Optimizing 3proxy for High Load" and to security recommendations -+ SOCKSv5 UDP: the destination of every datagram is authorized, so ACLs limiting the destination address, host name or port apply to UDP traffic now; the parent proxy and the external address are selected for the destination of the datagram and not for the UDP ASSOCIATE request -+ socks: -U option to control what happens when the destination changes within an UDP association: log it, authorize it, both (default) or neither -+ -C option (for TCP services) to terminate the session as soon as any of the sides closes the connection; by default the session is kept until both sides close it (TCP half-close) -+ timeouts: LINGER value added (11th, default 5), used to deliver buffered data after one of the sides has closed its sending side and as SO_LINGER value on outgoing connections +No changes in 3proxy code, this release only changes how packages are built, signed and published. + +! Fix: TLS, PCRE2 and PAM support was silently left out when 3proxy was built on a system whose /bin/sh is not dash, which is every RPM based distribution and macOS; the library checks built their test program with echo and escape sequences, which only dash expands, so every check failed and the features were dropped without a diagnostic +! Fix: rpm packages were built on Ubuntu and required glibc 2.38, libssl.so.3 and libpcre2-8, which no RPM based distribution provides, so they could not be installed anywhere; they are built against AlmaLinux 8, 9 and 10 now and carry an el8, el9 or el10 tag, covering RHEL, AlmaLinux, Rocky and CentOS Stream of the same version +! Fix: the rpm package depended on its own interpreter, /bin/3proxy, taken from the first line of the installed configuration file, and could not be installed on el9 or el10 because rpm resolves that dependency to /usr/bin/3proxy +! Fix: deb packages required glibc 2.38 and libssl3t64 and installed on Ubuntu 24.04 and newer only; they are built against Ubuntu 22.04 now and install on Ubuntu 22.04 and later as well as Debian 12 and later ++ Signed apt and dnf repositories are published at https://3proxy.org/repo/ in two channels: current, built from the master branch, and lts, built from the 0.9 branch; packages and repository metadata are both signed ++ Release binaries are published with SHA256 checksums, an OpenPGP signature and a GitHub build provenance attestation; docker images are signed and attested as well ++ The release signing key is an RSA-4096 key published as 3proxy-release-key.asc in the repository; rpm 4.14 and earlier can not import an Ed25519 key at all, which would leave RHEL 8 and its derivatives unable to verify anything ++ Packages are reproducible: rebuilding a release produces byte identical deb and rpm files, every timestamp is derived from the build date recorded for the release +- 32-bit ARM (armhf) is published as a deb package only, Enterprise Linux has no 32-bit ARM build diff --git a/CHANGELOG.rus b/CHANGELOG.rus index a1e3587..b560fa7 100644 --- a/CHANGELOG.rus +++ b/CHANGELOG.rus @@ -1,18 +1,13 @@ -3proxy-0.9.9 Вышел 20 Августа 2026 +3proxy-1.0.0 Вышел 22 Августа 2026 -! Исправление: ответы DNS теперь проверяются: ответ с адреса, отличного от адреса сервера имён, которому был отправлен запрос, а также ответ с секцией вопроса, не совпадающей с запросом, отбрасываются; ранее оба принимались -! Исправление: утечка сокетов при SOCKSv5 UDP ASSOCIATE через вышестоящий прокси, сокеты накапливались в состоянии CLOSE_WAIT до исчерпания дескрипторов -! Исправление: утечка файловых дескрипторов в HTTP-прокси на пути обработки запроса ftp:// -! Исправление: аварийное завершение с недопустимой инструкцией на некоторых платформах (например, в некоторых сборках Linux на основе musl) из-за memcpy на перекрывающихся буферах -! Исправление: родители типа extip и ha (HAProxy PROXY protocol) теперь применяются к SOCKSv5 UDP ASSOCIATE -! Исправление: для UDP ASSOCIATE используются только родители socks5 и socks5+, остальные типы для UDP неприменимы -! Исправление: udppm через вышестоящий прокси SOCKSv5 не работал -! Исправление: опции -Ne и -Ni никогда не применялись, буква опции не разбиралась; -Ne больше не применяется к ответу на UDP ASSOCIATE, -Ni применяется к нему -! Исправление: обработка -4 / -6 для UDP в socks; одна UDP-ассоциация теперь может использовать адреса назначения и IPv4, и IPv6 -! Исправление: датаграмма с нулевым адресом назначения теперь отбрасывается -! Исправление: DNS поверх TCP: ответ, не помещавшийся в одно чтение, никогда не обрабатывался -! Документация: в HOWTO добавлен раздел "Как применять ACL к UDP-трафику"; в "Optimizing 3proxy for High Load" и в рекомендации по безопасности добавлены заметки о кэше аутентификации, ACL и UDP -+ SOCKSv5 UDP: адрес назначения каждой датаграммы авторизуется, поэтому ACL, ограничивающие адрес назначения, имя хоста или порт, теперь применяются к UDP-трафику; вышестоящий прокси и внешний адрес выбираются для адреса назначения датаграммы, а не для запроса UDP ASSOCIATE -+ socks: опция -U для управления тем, что происходит при смене адреса назначения в рамках UDP-ассоциации: журналировать, авторизовать, и то и другое (по умолчанию) или ничего -+ Опция -C (для TCP-сервисов) завершает сессию, как только любая из сторон закрывает соединение; по умолчанию сессия сохраняется, пока соединение не закроют обе стороны (полузакрытие TCP) -+ timeouts: добавлено значение LINGER (11-е, по умолчанию 5), используется для доставки буферизованных данных после того, как одна из сторон закрыла свою передающую сторону, а также как значение SO_LINGER для исходящих соединений +Изменений в коде 3proxy нет, этот выпуск меняет только сборку, подписывание и публикацию пакетов. + +! Исправление: поддержка TLS, PCRE2 и PAM молча не включалась при сборке в системах, где /bin/sh не dash, то есть во всех дистрибутивах на основе RPM и в macOS; проверки наличия библиотек формировали тестовую программу через echo с escape-последовательностями, которые раскрывает только dash, поэтому все проверки завершались неудачно и возможности отключались без каких-либо сообщений +! Исправление: пакеты rpm собирались в Ubuntu и требовали glibc 2.38, libssl.so.3 и libpcre2-8, которых нет ни в одном дистрибутиве на основе RPM, поэтому установить их было невозможно нигде; теперь они собираются в AlmaLinux 8, 9 и 10 и содержат метку el8, el9 или el10, что покрывает RHEL, AlmaLinux, Rocky и CentOS Stream соответствующей версии +! Исправление: пакет rpm зависел от собственного интерпретатора /bin/3proxy, взятого из первой строки устанавливаемого файла конфигурации, и не устанавливался в el9 и el10, поскольку rpm приводит эту зависимость к /usr/bin/3proxy +! Исправление: пакеты deb требовали glibc 2.38 и libssl3t64 и устанавливались только в Ubuntu 24.04 и новее; теперь они собираются в Ubuntu 22.04 и устанавливаются в Ubuntu 22.04 и новее, а также в Debian 12 и новее ++ Подписанные репозитории apt и dnf публикуются на https://3proxy.org/repo/ в двух каналах: current, собираемый из ветки master, и lts, собираемый из ветки 0.9; подписываются и пакеты, и метаданные репозитория ++ Двоичные файлы релиза публикуются с контрольными суммами SHA256, подписью OpenPGP и подтверждением происхождения сборки GitHub (build provenance attestation); образы docker также подписываются и снабжаются подтверждением ++ Ключ подписи релизов — RSA-4096, опубликован в репозитории как 3proxy-release-key.asc; rpm версии 4.14 и более ранние вообще не могут импортировать ключ Ed25519, что лишило бы RHEL 8 и производные от него возможности проверки ++ Пакеты воспроизводимы: повторная сборка релиза даёт побайтово идентичные файлы deb и rpm, все отметки времени берутся из даты сборки, записанной для релиза +- Для 32-битной ARM (armhf) публикуется только пакет deb, в Enterprise Linux нет сборки для 32-битной ARM diff --git a/RELEASE b/RELEASE index 6f060dc..afaf360 100644 --- a/RELEASE +++ b/RELEASE @@ -1 +1 @@ -0.9.9 \ No newline at end of file +1.0.0 \ No newline at end of file diff --git a/doc/changelog/1/0/0 b/doc/changelog/1/0/0 new file mode 100644 index 0000000..9db5b39 --- /dev/null +++ b/doc/changelog/1/0/0 @@ -0,0 +1,11 @@ +No changes in 3proxy code, this release only changes how packages are built, signed and published. + +! Fix: TLS, PCRE2 and PAM support was silently left out when 3proxy was built on a system whose /bin/sh is not dash, which is every RPM based distribution and macOS; the library checks built their test program with echo and escape sequences, which only dash expands, so every check failed and the features were dropped without a diagnostic +! Fix: rpm packages were built on Ubuntu and required glibc 2.38, libssl.so.3 and libpcre2-8, which no RPM based distribution provides, so they could not be installed anywhere; they are built against AlmaLinux 8, 9 and 10 now and carry an el8, el9 or el10 tag, covering RHEL, AlmaLinux, Rocky and CentOS Stream of the same version +! Fix: the rpm package depended on its own interpreter, /bin/3proxy, taken from the first line of the installed configuration file, and could not be installed on el9 or el10 because rpm resolves that dependency to /usr/bin/3proxy +! Fix: deb packages required glibc 2.38 and libssl3t64 and installed on Ubuntu 24.04 and newer only; they are built against Ubuntu 22.04 now and install on Ubuntu 22.04 and later as well as Debian 12 and later ++ Signed apt and dnf repositories are published at https://3proxy.org/repo/ in two channels: current, built from the master branch, and lts, built from the 0.9 branch; packages and repository metadata are both signed ++ Release binaries are published with SHA256 checksums, an OpenPGP signature and a GitHub build provenance attestation; docker images are signed and attested as well ++ The release signing key is an RSA-4096 key published as 3proxy-release-key.asc in the repository; rpm 4.14 and earlier can not import an Ed25519 key at all, which would leave RHEL 8 and its derivatives unable to verify anything ++ Packages are reproducible: rebuilding a release produces byte identical deb and rpm files, every timestamp is derived from the build date recorded for the release +- 32-bit ARM (armhf) is published as a deb package only, Enterprise Linux has no 32-bit ARM build