From: Daniel Stenberg Date: Thu, 30 Jul 2026 07:12:28 +0000 (+0200) Subject: RELEASE-NOTES: synced X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=33a967318c74c681fbb0ceee7f079a5aa2df0b97;p=thirdparty%2Fcurl.git RELEASE-NOTES: synced --- diff --git a/RELEASE-NOTES b/RELEASE-NOTES index b750535fa1..8c709a35d3 100644 --- a/RELEASE-NOTES +++ b/RELEASE-NOTES @@ -4,15 +4,17 @@ curl and libcurl 8.22.0 Command line options: 278 curl_easy_setopt() options: 312 Public functions in libcurl: 100 - Authors: 1500 - Contributors: 3753 + Authors: 1502 + Contributors: 3756 This release includes the following changes: o gssapi: add support for Apple GSS Framework [72] o hardening: add API guards [64] o RFC 9421 HTTP Message Signatures support [108] + o spnego: block NTLM fallback in SPNEGO negotiation [151] o TLS: drop support for TLS-SRP [71] + o vquic: add option to use Apple fast UDP [137] This release includes the following bugfixes: @@ -23,6 +25,7 @@ This release includes the following bugfixes: o build: enable thread-safe `getaddrinfo()` for OpenBSD [35] o cd2nroff: fix backslashes for 4-space indent lines [104] o cd2nroff: stricter checks for asterisks for italics [73] + o cf-ngtcp2-cmn: de-duplicate `ngtcp2_conn_client_new()` call code [156] o cf-ngtcp2-cmn: initialize new callback ptr for ngtcp2 1.24.0+ [52] o cfilters: fix event-based connection shutdown [91] o cmake: dedupe expressions into local vars in `cmake_uninstall.in.cmake` [9] @@ -38,19 +41,25 @@ This release includes the following bugfixes: o configure: remove double check for GnuTLS [21] o configure: set ldap lib to no by default for non-finds [18] o conncache: apply multi limits to transfers using a shared pool [41] + o conncache: conn upkeep/alive: move and enhance [152] o conncache: connection alive checks intervals [20] o connect: connection close tweaks [112] o content_encoding: give a clear error on multi-member gzip [46] o CREDENTIALS.md: remove comment about empty user/pass [50] o ctype: exclude control bytes from ISPRINT and ISGRAPH [119] + o curl_gssapi: document/update feature availability [145] o curl_ws_meta.md: polish and better vocabulary [19] o CURLOPT_HEADERFUNCTION.md: document folded header unfolding [53] o CURLOPT_SSH_*_KEYFILE: used for setting up, then no more [48] o CURLOPT_UNRESTRICTED_AUTH.md: 'Authorization', not 'Authentication' [74] o CURLSHOPT_(UN)SHARE.md: do not modify shares while in use [44] + o dnsd: fix bounds check in `read_https_alpn_part()` [143] + o docs/INTERNALS.md -> docs/DEPENDENCIES.md [127] o FTP: fix TLS session reuse on the data connection [80] o ftp: reject control bytes in ACCT and alternative-to-user [26] o gopher: reject CR and LF in the selector [1] + o h2: bootstrap max streams from multi handle if in use [132] + o HISTORY: add when c-ares support was introduced (2004) o hostip: only cache negative resolves for authoritative answers [16] o http: avoid length underflow in Curl_compareheader [78] o http: fix non-tunneling proxy hostname use [116] @@ -60,8 +69,10 @@ This release includes the following bugfixes: o idn: restore `MultiByteToWideChar()` `MB_ERR_INVALID_CHARS` flag [103] o INSTALL.md: add building-from-source overview section [29] o INTERNALS.md: require quiche 0.20.0+ [101] + o ldap: support empty username and password [106] o ldap: support insecure mode for Windows native LDAP [3] o lib1587: fix gcc `-Wconversion` with LibreSSL on Windows, test in CI [6] + o lib2405: adjust for non-threaded builds [149] o lib: add "Curl_" prefix to two global functions [84] o lib: add multi_wakeup_internal [86] o lib: fix 'ns' -> 'us' in trace messages [57] @@ -81,30 +92,42 @@ This release includes the following bugfixes: o openssl: drop unused pre-OpenSSL3 `ctx_option_t` typedef [8] o openssl: prefer modern API flavors for `EVP_MD_CTX` new/free [47] o openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` [27] + o pytest: update two H3 tests for nghttp3 1.18.0+ [158] o quiche: set the max field section size [100] o runtests: allow comments in `setenv` section, merge sections in test433 [89] o runtests: fix `mode="warn"` tests passing unconditionally, fix test 1752 [66] o runtests: flush cached test parts when (re)loading a file [95] o runtests: restore `-k` option and actively process as no-op [32] o sasl: fix zero-length response encoding [36] + o schannel: fix error check logic in `get_client_cert()` file reader [144] o schannel: shut off experimental TLS 1.3 support for Win 10 [25] + o scorecard: fix `max_upload` init value in `ul_parallel()` [142] + o scripts/badwords.txt: do not recommend using 'will' in rewrites [141] o scripts: replace/extend `--` with `--end-of-options` in git commands [128] o scripts: use end-of-options marker in `cd`, `mkdir`, `mv`, `sha256sum` commands [34] o setopt: error for CURLOPT_SHARE when easy handle is used [68] o setopt: return OK earlier for the deprecated h2 dep options [77] o smtp: reject CR and LF in the envelope address [37] o spacecheck: cap number of lines per file [111] + o src: safely clear certain buffers [125] o ssls: fix potential memory leak on import [96] o sws: allow connection-monitor to log all disconnects [2] + o sws: log the exact closing reason better, to help debugging tests [85] o terminal: Enhance terminal size detection for multiple outputs [115] o test 1560: test RFC4291 style IPv6 IPv4-mapped addresses [40] o test1560: allow to build and run without LDAP support [109] o test798: force IPv4 to avoid cross-runner port aliasing [97] o test: adjust test_06_13 for 0100::/64 being blackholed [13] + o tests: address mutable class vars and naive datetime in Python code + o tests: change whitespace and comments in Python test code o tests: fix the FTP check for unexpected RST [117] o tests: fix type promotion on 32-bit arches in http test code [88] + o tests: improve exception handling in Python test code o tests: remove test1701 [58] + o tests: simplify by removing unneeded Python code o tests: skip test 311 for wolfSSL 5.9.2 [63] + o tests: target Python 3.8 as the minimum Python version + o tests: use simpler constructions in Python code o thrdpool: retry failed thread starts while items wait [62] o tidy-up: `TEXT()` vs `_TEXT()` vs `_T()` use (Windows) [102] o tidy-up: drop redundant includes [110] @@ -114,22 +137,29 @@ This release includes the following bugfixes: o tool: do not flush on out-null [38] o tool: fix memory use in parallel mode [59] o tool: init progress bar on demand [39] + o tool: remove duplicate setopts [94] o tool_cb_hdr: de-duplicate filename setter [24] o tool_cb_prg: avoid integer overflows [93] o tool_doswin: add stdin relay auth [130] o tool_operate: remove call to abort() [23] o tool_xattr: add support for Windows alternate data stream [129] + o typecheck-gcc: allow passing `char[]` as callback data [153] o uint-spbset: reused empty chunks [67] o unit3214: fix to pass on systems with >=128-bit pointers [107] o url: reject control codes in credentials set via CURLOPT [70] o urlapi: allow URLs to not have userauth (hostname) [92] + o urlapi: clear password buffer on error path [121] o urlapi: do not keep an internal port string [31] + o urlapi: improved return codes [148] o urlapi: preserve empty markers in relative URLs [61] o vms: fix symbol typo and missing closing quotes in `config_h.com` [124] o vquic: add Curl_ prefix to some global functions [76] o vquic: initialize new callback slot for nghttp3 v1.18.0+ [87] + o vquic: silence `-Wmissing-field-initializers` for nghttp3/ngtcp2 callback tables [159] + o vquic: use ngtcp2 v1.25.0 new close2 callback [154] o vssh: keyfile use cleanups [83] o VULN-DISCLOSURE-POLICY.md: issues that should be found by tests are LOW [5] + o websocket: pause writing and meta data fix [135] o wolfssl: fix build for wolfssl without bio chain support [75] o ws: pause/unpause write handling [55] @@ -154,16 +184,18 @@ advice from friends like these: 11soda11, AlanKingPL, Alb3e3, Alhuda Khan, Bartel Sielski, Bigtang on hackerone, Bill Mill, Bryan Henderson, - Carlos Henrique Lima Melara, Christian Ullrich, Christoph Reiter, - Collin Funk, Dan Fandrich, Daniel Stenberg, dependabot[bot], + Carlos Henrique Lima Melara, CatboxParadox, Christian Ullrich, + Christoph Reiter, claudex on github, Collin Funk, Dan Fandrich, + Daniel Gustafsson, Daniel Stenberg, dependabot[bot], ed0d2b2ce19451f2 on github, Emmanuel Ugwu, Eunsoo Kim, firexinghe on github, Graham Campbell, Hendrik Hübner, HwangRock, itzTanos29, Joel Depooter, - Keng-Yu Lin, Laurent Sabourin, Memduh Çelik, Patrick Monnerat, Pavel Sobolev, + Johannes Schindelin, Keng-Yu Lin, kit-ty-kate on github, Laurent Sabourin, + Matthew John Cheetham, Memduh Çelik, Patrick Monnerat, Pavel Sobolev, pszemus on github, Ray Satiro, renovate[bot], RMMoreton on github, Roger Leigh, Ross Burton, Sameeh Jubran, Sam James, Samuel Dainard, Sergei Zimmerman, smaeljaish on hackerone, Stefan Eissing, stze on hackerone, - Viktor Szakats, xmoezzz on github - (44 contributors) + Viktor Szakats, xmoezzz on github, Yoshiro Yoneya + (51 contributors) References to bug reports and discussions on issues: @@ -249,6 +281,7 @@ References to bug reports and discussions on issues: [82] = https://curl.se/bug/?i=22248 [83] = https://curl.se/bug/?i=22243 [84] = https://curl.se/bug/?i=22245 + [85] = https://curl.se/bug/?i=22431 [86] = https://curl.se/bug/?i=22272 [87] = https://curl.se/bug/?i=22399 [88] = https://curl.se/bug/?i=22210 @@ -257,6 +290,7 @@ References to bug reports and discussions on issues: [91] = https://curl.se/bug/?i=22282 [92] = https://curl.se/bug/?i=22279 [93] = https://curl.se/bug/?i=22316 + [94] = https://curl.se/bug/?i=22433 [95] = https://curl.se/bug/?i=22319 [96] = https://curl.se/bug/?i=22323 [97] = https://curl.se/bug/?i=22318 @@ -267,6 +301,7 @@ References to bug reports and discussions on issues: [103] = https://curl.se/bug/?i=22326 [104] = https://curl.se/bug/?i=22393 [105] = https://curl.se/bug/?i=22320 + [106] = https://curl.se/bug/?i=22162 [107] = https://curl.se/bug/?i=22299 [108] = https://curl.se/bug/?i=22386 [109] = https://curl.se/bug/?i=22312 @@ -280,10 +315,30 @@ References to bug reports and discussions on issues: [118] = https://curl.se/bug/?i=22330 [119] = https://curl.se/bug/?i=22371 [120] = https://curl.se/bug/?i=22380 + [121] = https://curl.se/bug/?i=21637 [122] = https://curl.se/bug/?i=22377 [123] = https://curl.se/bug/?i=22376 [124] = https://curl.se/bug/?i=22375 + [125] = https://curl.se/bug/?i=21637 [126] = https://curl.se/bug/?i=22363 + [127] = https://curl.se/bug/?i=22430 [128] = https://curl.se/bug/?i=22369 [129] = https://curl.se/bug/?i=22354 [130] = https://curl.se/bug/?i=21467 + [132] = https://curl.se/bug/?i=22418 + [135] = https://curl.se/bug/?i=22413 + [137] = https://curl.se/bug/?i=22341 + [141] = https://curl.se/bug/?i=22422 + [142] = https://curl.se/bug/?i=22421 + [143] = https://curl.se/bug/?i=22420 + [144] = https://curl.se/bug/?i=22415 + [145] = https://curl.se/bug/?i=22419 + [148] = https://curl.se/bug/?i=22337 + [149] = https://curl.se/bug/?i=22414 + [151] = https://curl.se/bug/?i=21315 + [152] = https://curl.se/bug/?i=21806 + [153] = https://curl.se/bug/?i=22409 + [154] = https://curl.se/bug/?i=22270 + [156] = https://curl.se/bug/?i=22401 + [158] = https://curl.se/bug/?i=22397 + [159] = https://curl.se/bug/?i=22400