)]}'
{
  "log": [
    {
      "commit": "861ee77ab4ab1361adc2e70f01a931362a7a88fa",
      "tree": "685a171989b2770318f2d43cc8907822eabc925d",
      "parents": [
        "8d1cbe7efcbcc4b730cd9578e84b35fa2d391f4c",
        "13a34419ba316cbacbcf76796c9d08c8f2d2fdc2"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Mon Jun 27 21:31:34 2022 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jun 28 09:56:59 2022 -0700"
      },
      "message": "Merge branch \u0027nginx\u0027 (nginx-1.23.0).\n\nChange-Id: Ib00b631b91cae593ad6bf5e3768abde319fdc0d5\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\n"
    },
    {
      "commit": "8d1cbe7efcbcc4b730cd9578e84b35fa2d391f4c",
      "tree": "49b0934747ab5895819e469c9f7226f573ded0b3",
      "parents": [
        "02c329f3d3bda2c415fd087138f5b902652bfb7b",
        "1a0408c02365ec7d0f708b80563161e8bfcc11ae"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Mon Jun 27 21:30:38 2022 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jun 28 09:55:57 2022 -0700"
      },
      "message": "Merge branch \u0027nginx\u0027 (nginx-1.21.6).\n\nChange-Id: I7d87547c33655ac46c6995f06de7663edfcb0593\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\n"
    },
    {
      "commit": "02c329f3d3bda2c415fd087138f5b902652bfb7b",
      "tree": "683e10e730655770ee9c0f7fba02896b30c948c2",
      "parents": [
        "bf4f31a4c5c80e3591964b67e403e6bf409c84f0",
        "37f533bd4e741535b8373c433ae061c70c16b7cc"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Mon Jun 27 21:29:42 2022 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jun 28 09:54:48 2022 -0700"
      },
      "message": "Merge branch \u0027nginx\u0027 (nginx-1.21.5).\n\nChange-Id: Ifbcffb4c7d21b7754cade0e639945a53fb6778df\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\n"
    },
    {
      "commit": "bf4f31a4c5c80e3591964b67e403e6bf409c84f0",
      "tree": "06fb9f3987a25dd2f413efb02aa4b7b2b7a59ec1",
      "parents": [
        "64e4716c920eca0477c2d211c06295f6d4dc820c"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Mon Jun 27 17:30:44 2022 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jun 28 16:49:07 2022 +0000"
      },
      "message": "Bazel: update zlib to v1.2.12.\n\nChange-Id: I221e8039b97e333c94a5a4c0329aec926b2745cd\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\nReviewed-on: https://nginx-review.googlesource.com/c/nginx/+/4000\nReviewed-by: Patryk Lesiewicz \u003cpatryk@google.com\u003e\n"
    },
    {
      "commit": "64e4716c920eca0477c2d211c06295f6d4dc820c",
      "tree": "ec5e6dd2d7394d0d55fd945b1630bd47381ee815",
      "parents": [
        "f49d3904a1b32abea8e4902dcc6e4c8f5efe42ca"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Mon Jun 27 17:31:32 2022 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jun 28 16:48:51 2022 +0000"
      },
      "message": "Bazel: update PCRE to v8.45.\n\nChange-Id: Ia34e2e5d75574547bd67135954bc87de2e06f801\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\nReviewed-on: https://nginx-review.googlesource.com/c/nginx/+/4001\nReviewed-by: Patryk Lesiewicz \u003cpatryk@google.com\u003e\n"
    },
    {
      "commit": "f49d3904a1b32abea8e4902dcc6e4c8f5efe42ca",
      "tree": "16ded51759d5714fc37cc9eda6b1b7dd23bd3375",
      "parents": [
        "cbc605f1be7bf0301c86dded98fc878d173906b3"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Mon Jun 27 17:32:20 2022 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jun 28 16:48:32 2022 +0000"
      },
      "message": "Bazel: update BoringSSL to 227ff6e / 62079f7 (master-with-bazel).\n\n227ff6e64 Remove unions in EC_SCALAR and EC_FELEM.\n3f180b822 Implement SSL_CTX_set_num_tickets.\ndf6311bc6 Add tests for X509_NAME_print_ex.\n735a86834 acvp: test CTR-DRBG with reseed in modulewrapper.\n25e5b06d4 Do pending `go fmt` updates.\n097ffe139 acvp: test SHA-512/256 with HMAC, RSA (PSS), and ECDSA.\n1a541d4db Add PSS to the AVCP regcap.\n82413455b Drop ACVP support for 3DES.\na56d941c4 Add function to return the name of the FIPS module.\na75bee541 Support running tests on non-NEON devices.\n9a836f784 Update delocate tests\n8b988b8b8 Tidy up how ASN1_STRING_print_ex figures out the type.\n0e0ca82b2 Remove the ASN1_TLC cache. It appears to not help performance.\n48f794765 Fix build for older CMake versions.\n15302de89 Remove code added to avoid SHA1 weakness.\n553e81e47 Update comment in light of prior change.\n53a87b7c5 ChaCha20-Poly1305 for Armv8 (AArch64)\n59e37765f Replace the last strcasecmp with OPENSSL_strcasecmp.\nf299342e3 [build] Fix build with HEAD clang.\n6686352e4 Make calls to the verify callback consistant by calling ctx-\u003everify_cb directly. This removes some temporary variables that would only be used to hold ctx-\u003everify_cb.\nf961de5c4 Try to require C11 (in non-MSVC compilers).\n493d5cbed Try to require C++14.\nedbdc240e Reject [UNIVERSAL 0] in DER/BER element parsers.\n2fc6d3839 Add CMake install rules.\nfa3fbda07 P-256 assembly optimisations for Aarch64.\nf7e1a94bd hrss: always normalize.\n27ffcc6e1 Use SHA-256 for the FIPS integrity check everywhere.\naf34f6460 Remove unused variable\n225e8d39b Use X509 certificate alias as friendlyName in PKCS12\nc9a7dd687 Retire the Windows BIO_printf workaround.\n4984e4a63 Work around another C language bug with empty spans.\nf94a7ce59 ASAN replaces malloc and free with its own implementation.\n8c8e7a683 Update fiat-crypto.\n21440764d Remove VS 2015 support.\nb99b98b6e Remove X509_TRUST_set_default.\n753435403 Replace internal use sha1 hash with sha256.\n8bbefbfee Document that |EC_KEY_generate_fips| works for both cases.\n972ab5223 Allow the integrity test to be run on demand.\nc6e8f3ed0 Add a function to return a FIPS version.\n7f4057ec1 Add a function to tell if an algorithm is FIPS approved.\ndcba84922 Add vs2019 to vs_toolchain.py.\n6378c47cb Unexport X509_CERT_AUX and remove X509_CERT_AUX.other\nd0f14f398 Document and tidy up X509_alias_get0, etc.\nc7a3c4657 Don\u0027t loop forever in BN_mod_sqrt on invalid inputs.\n933f72a0f Make a whitespace commit to trigger a build.\ne5abf588c Rust bindings: Use CARGO_MANIFEST_DIR in build.rs\nab69425a9 Remove ASN1_ADB_INTEGER.\n6196faba8 Replace an ASN1_INTEGER_get call with ASN1_INTEGER_get_uint64\nfdd526036 Correctly handle LONG_MIN in ASN1_INTEGER_get.\nde139712b Implement ASN1_INTEGER_set_uint64 with ASN1_STRING_set.\nbdc35b636 Rewrite and tighten ASN1_INTEGER encoding and decoding.\n366e88662 Deduplicate the rest of ASN1_INTEGER and ASN1_ENUMERATED.\nfa2cd1ee8 Fix theoretical overflow in ASN1_INTEGER_cmp.\nd258de724 Include rsa/internal.h for |...no_self_test| functions.\n66d856322 Limit the pthread_rwlock workaround to glibc.\n6e25e54b1 Rewrite ASN1_INTEGER tests.\ncc4333d75 Use X509V3_add_value_int in i2v_AUTHORITY_KEYID.\ne4b3e6afb Fix x509v3_bytes_to_hex when passed the empty string.\n657c69b3c Reimplement ASN1_get_object with CBS.\n7fac386a1 Add an explicit indefinite-length output to CBS_get_any_ber_asn1_element.\n8a3818418 Use ctype(3) in a more standards-conformant way.\n81502beed Linkify RFCs in more places in the docs.\n4b55af0fc Make FFDH self tests lazy.\n3053b739b Make ECC self tests lazy.\nc76da9d46 HPKE is now RFC 9180.\n6595ddb35 Include the policy document for the most recent FIPS validation.\n4d955d20d Check static CPU capabilities on x86.\n31ece98da Align rsaz_avx2_preferred with x86_64-mont5.pl.\n17c8c8110 Enable SHA-NI optimizations for SHA-256.\nec85d0ddb Update Intel SDE.\n08970b312 Include the EKU extension in bssl server\u0027s self-signed certs.\n0da6b4805 Don\u0027t call a non-test file *test.h.\n1c2e61efe Make RSA self-test lazy.\n263f48997 Add link to new Android FIPS certificate.\nb9c6d67c2 delocate: handle a new output form in Clang 13.\n8f7cb2f7c Drop, now unused, KAT value.\nea9fb94c3 Drop CAVP code.\nd04c32a3d Break FIPS tests differently.\nf8235e499 Don\u0027t forget hmac.h in self_check.h.\n9cad13eea Perform SHA-$x and HMAC KAT before integrity check.\nb0ed28e25 Add a couple of spaces to `check_test`.\n15565a898 Split FIPS KATs into fast and slow groups.\na91953977 Move DES out of the FIPS module.\n44a141fa1 acvp: don\u0027t send the Authorization header when renewing tokens\n5112b45ce Support Bazel\u0027s test-sharding protocol.\n68addd2f7 Simply CMake assembly source selection.\n351b2f8ce Rename generated assembly from \u0027mac\u0027 or \u0027ios\u0027 to \u0027apple\u0027\n0f1417ce0 Build aarch64 assembly for macOS in the bazel build.\nac3f4fb8e Fix OPENSSL_NO_ASM definition in bazel.\nc5179c693 Use @platforms in Bazel rules.\n123eaaef2 Record ClientHelloInner values in msg_callback.\n44425ddc7 Fold ssl_decode_client_hello_inner into ssl_client_hello_decrypt.\n7198d1132 Explicitly reject self-referential ech_outer_extensions.\n0fc57bef1 Simpler square-root computation for Ed25519\n0f4454c07 Condition split handshake tests on Linux in CMake.\nb90261a38 Implement PEM_read_bio_DHparams with the macro.\n387f82054 Limit _XOPEN_SOURCE to Linux.\nc03e99a59 Fix Unicode strings for C++20\n345c86b1c Switch CRYPTO_BUFFER_POOL to SipHash-2-4.\n50e7ea5f0 LSC: Apply clang-tidy\u0027s modernize-use-bool-literals to boringssl\n960ddfee4 Fix mac_arm64 builder.\nea46caf26 Put Rust binding generation behind an explicit flag and only build bindings for the targeted Arch\nbe04c566c Add ARMV8_SHA512 detection for Fuchsia.\n8d8d8f3ea Generates \"low-level\" bindings for Rust using bindgen\n36a41bf0b Add note about Gerrit account creation\nd1593f54c Make EVP_AEAD_CTX_free accept NULL.\nec476ef04 Zero out the values from the integrity check.\nf79757032 Ignore duplicates in |X509_STORE_add_*|\n0354b79d7 Don\u0027t #include \"internal.h\" twice.\n24e97fb69 Version bump: 2 -\u003e 3.\nd80f17d5c Simplify __ARM_ARCH__ definition.\na94c26778 Don\u0027t use __ARMEL__/__ARMEB__ in aarch64 assembly\n846a22700 Switch __ARM_FEATURE_CRYPTO to __ARM_FEATURE_{AES,SHA2}.\n661266ea0 Move CPU detection symbols to crypto/internal.h.\n37faa936b Move public APIs from cpu.h to crypto.h.\n295b31324 Rename CPU feature files with underscores.\n1e15682f1 Enable SHA-512 ARM acceleration when available.\naf561c221 Sync sha512-armv8.pl up to 753316232243ccbf86b96c1c51ffcb41651d9ad5.\ne90cf82ac Import sha512-armv8.pl transforms from upstream NEON code.\n9bcc12d54 Import a few test vectors from OpenSSL.\nd7936c23c Use uint16_t in TestConfig and enable -Wformat-signedness.\n203b92b70 Reorder flags to match TestConfig struct.\n8ed06e0fd Rewrite bssl_shim command-line parser.\n066469055 Fix X509_CRL_print error-handling.\n94089a8b5 Silence -Wformat-signedness when printing X.509 versions.\n866b88dfe Don\u0027t print small, negative serial numbers in decimal.\n4f1fae304 Fix the easy -Wformat-signedness errors.\ne21f272a6 Add BIO_tell and BIO_seek wrappers.\n9631bc104 Remove non-standard wildcard input DNS names.\n405c7888a Rewrite X.509 name-matching tests.\nc3c540b9a Remove non-standard X.509 DNS wildcard matching.\n2042972e8 Make X509_REVOKED opaque.\n7e2a95788 Document |SSL_set1_host| return values.\n7e7e6b693 Add |SSL_set1_host| and |SSL_set_hostflags|.\n731d6cbef Add ERR_set_error_data for compatibility.\ncd0b76749 Add BN_GENCB_new, BN_GENCB_free, and RSA_test_flags.\nd703d95b8 Remove X509_REVOKED.sequence.\n\nChange-Id: Iba486e98187a96377a5613994e8dbda60a0bfb9c\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\nReviewed-on: https://nginx-review.googlesource.com/c/nginx/+/4002\nReviewed-by: Patryk Lesiewicz \u003cpatryk@google.com\u003e\n"
    },
    {
      "commit": "cbc605f1be7bf0301c86dded98fc878d173906b3",
      "tree": "51178b87bb74bf983f7a253958e5846c54b34ec0",
      "parents": [
        "182c48a8de969ab284794afd49ab5ed900443efa"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Mon Jun 27 18:10:54 2022 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jun 28 16:48:08 2022 +0000"
      },
      "message": "Bazel: fix Brotli build with recent versions of Clang/GCC.\n\nChange-Id: I7a9f563cf1acb9007197f003dc0c025a73d57e85\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\nReviewed-on: https://nginx-review.googlesource.com/c/nginx/+/4003\nReviewed-by: Patryk Lesiewicz \u003cpatryk@google.com\u003e\n"
    },
    {
      "commit": "13a34419ba316cbacbcf76796c9d08c8f2d2fdc2",
      "tree": "33d625145c076d1917f0e08eedfdb224bc3795d3",
      "parents": [
        "22ab06d6c18723691c90fa12a037bd25afb31b3a"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 21 17:25:37 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 21 17:25:37 2022 +0300"
      },
      "message": "release-1.23.0 tag\n"
    },
    {
      "commit": "22ab06d6c18723691c90fa12a037bd25afb31b3a",
      "tree": "a526d43e069cb39def1379b702d7abfd826d3635",
      "parents": [
        "43a1224d4d9614360627cb1dd8bbd98f40956e9c"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 21 17:25:36 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 21 17:25:36 2022 +0300"
      },
      "message": "nginx-1.23.0-RELEASE\n"
    },
    {
      "commit": "43a1224d4d9614360627cb1dd8bbd98f40956e9c",
      "tree": "bf7876b3d8352cb138684e46901e79a7b1db62bb",
      "parents": [
        "10d500fbdbaf88aa188c96886184c2c059f77fbc"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 21 17:09:34 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 21 17:09:34 2022 +0300"
      },
      "message": "Updated OpenSSL used for win32 builds.\n"
    },
    {
      "commit": "10d500fbdbaf88aa188c96886184c2c059f77fbc",
      "tree": "169eec2cedca38914b7692088496a936296434dd",
      "parents": [
        "1bcbad5576ecb5f44dcd6b6e3a84701827cd0946"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Jun 20 19:30:50 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Jun 20 19:30:50 2022 +0300"
      },
      "message": "Misc: win32 sources now preserved in release tarballs.\n\nThis makes it possible to build nginx under Windows from release tarballs\ninstead of using source code repository.\n"
    },
    {
      "commit": "1bcbad5576ecb5f44dcd6b6e3a84701827cd0946",
      "tree": "fe82e73d8adbc64228c284a19cc0e9e2b605956e",
      "parents": [
        "caac259cbb90baaf73c7a9affc620a84b65d3682"
      ],
      "author": {
        "name": "Gena Makhomed",
        "email": "gmm@csdoc.com",
        "time": "Sat Jun 18 15:54:40 2022 +0300"
      },
      "committer": {
        "name": "Gena Makhomed",
        "email": "gmm@csdoc.com",
        "time": "Sat Jun 18 15:54:40 2022 +0300"
      },
      "message": "Contrib: vim syntax, update core and 3rd party module directives.\n\nList of 3rd party modules github repositories are obtained from\nhttps://github.com/freebsd/freebsd-ports/blob/main/www/nginx-devel/Makefile.extmod\n"
    },
    {
      "commit": "caac259cbb90baaf73c7a9affc620a84b65d3682",
      "tree": "b077725ec7a01b50ae37a19a033141a3a70afe5e",
      "parents": [
        "638853642a113acc85581c7e314f4833e7f02a22"
      ],
      "author": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Tue Jun 14 10:39:58 2022 +0400"
      },
      "committer": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Tue Jun 14 10:39:58 2022 +0400"
      },
      "message": "Perl: removed unused variables, forgotten in ef6a3a99a81a.\n"
    },
    {
      "commit": "638853642a113acc85581c7e314f4833e7f02a22",
      "tree": "3da6357680ee5e1211c3a737a7efcb752b075b11",
      "parents": [
        "0c0a1dfe57cd9ecd3533fcde7f27d35a4757cc98"
      ],
      "author": {
        "name": "Aleksei Bavshin",
        "email": "a.bavshin@f5.com",
        "time": "Wed Jun 01 20:17:23 2022 -0700"
      },
      "committer": {
        "name": "Aleksei Bavshin",
        "email": "a.bavshin@f5.com",
        "time": "Wed Jun 01 20:17:23 2022 -0700"
      },
      "message": "Resolver: make TCP write timer event cancelable.\n\nSimilar to 70e65bf8dfd7, the change is made to ensure that the ability to\ncancel resolver tasks is fully controlled by the caller.  As mentioned in the\nreferenced commit, it is safe to make this timer cancelable because resolve\ntasks can have their own timeouts that are not cancelable.\n\nThe scenario where this may become a problem is a periodic background resolve\ntask (not tied to a specific request or a client connection), which receives a\nresponse with short TTL, large enough to warrant fallback to a TCP query.\nWith each event loop wakeup, we either have a previously set write timer\ninstance or schedule a new one.  The non-cancelable write timer can delay or\nblock graceful shutdown of a worker even if the ngx_resolver_ctx_t-\u003ecancelable\nflag is set by the API user, and there are no other tasks or connections.\n\nWe use the resolver API in this way to maintain the list of upstream server\naddresses specified with the \u0027resolve\u0027 parameter, and there could be third-party\nmodules implementing similar logic.\n"
    },
    {
      "commit": "0c0a1dfe57cd9ecd3533fcde7f27d35a4757cc98",
      "tree": "20a4fcf8c30d097c2c7d13bcabe465a95dac1e68",
      "parents": [
        "1b902022e4e8344fa1bebe63e68fbf5a073482d8"
      ],
      "author": {
        "name": "Aleksei Bavshin",
        "email": "a.bavshin@f5.com",
        "time": "Mon May 23 11:29:44 2022 -0700"
      },
      "committer": {
        "name": "Aleksei Bavshin",
        "email": "a.bavshin@f5.com",
        "time": "Mon May 23 11:29:44 2022 -0700"
      },
      "message": "Stream: don\u0027t flush empty buffers created for read errors.\n\nWhen we generate the last_buf buffer for an UDP upstream recv error, it does\nnot contain any data from the wire. ngx_stream_write_filter attempts to forward\nit anyways, which is incorrect (e.g., UDP upstream ECONNREFUSED will be\ntranslated to an empty packet).\n\nThis happens because we mark the buffer as both \u0027flush\u0027 and \u0027last_buf\u0027, and\nngx_stream_write_filter has special handling for flush with certain types of\nconnections (see d127837c714f, 32b0ba4855a6).  The flags are meant to be\nmutually exclusive, so the fix is to ensure that flush and last_buf are not set\nat the same time.\n\nReproduction:\n\nstream {\n    upstream unreachable {\n        server     127.0.0.1:8880;\n    }\n    server {\n        listen     127.0.0.1:8998 udp;\n        proxy_pass unreachable;\n    }\n}\n\n1 0.000000000    127.0.0.1 → 127.0.0.1    UDP 47 45588 → 8998 Len\u003d5\n2 0.000166300    127.0.0.1 → 127.0.0.1    UDP 47 51149 → 8880 Len\u003d5\n3 0.000172600    127.0.0.1 → 127.0.0.1    ICMP 75 Destination unreachable (Port\nunreachable)\n4 0.000202400    127.0.0.1 → 127.0.0.1    UDP 42 8998 → 45588 Len\u003d0\n\nFixes d127837c714f.\n"
    },
    {
      "commit": "1b902022e4e8344fa1bebe63e68fbf5a073482d8",
      "tree": "c7312f07d2d6fe3e055dfd815e1f61f68843dc7f",
      "parents": [
        "65d275a46c7e8b83ba606ed18fd620f330a0b97a"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 07 21:58:52 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 07 21:58:52 2022 +0300"
      },
      "message": "Mp4: fixed potential overflow in ngx_http_mp4_crop_stts_data().\n\nBoth \"count\" and \"duration\" variables are 32-bit, so their product might\npotentially overflow.  It is used to reduce 64-bit start_time variable,\nand with very large start_time this can result in incorrect seeking.\n\nFound by Coverity (CID 1499904).\n"
    },
    {
      "commit": "65d275a46c7e8b83ba606ed18fd620f330a0b97a",
      "tree": "99d913ae524b0e67c2c97c8cd322fa319f9bfe51",
      "parents": [
        "6fa199b1601079d8885668258f0212c2e2dd9148"
      ],
      "author": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Tue Jun 07 20:08:57 2022 +0400"
      },
      "committer": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Tue Jun 07 20:08:57 2022 +0400"
      },
      "message": "Upstream: handling of certificates specified as an empty string.\n\nNow, if the directive is given an empty string, such configuration cancels\nloading of certificates, in particular, if they would be otherwise inherited\nfrom the previous level.  This restores previous behaviour, before variables\nsupport in certificates was introduced (3ab8e1e2f0f7).\n"
    },
    {
      "commit": "6fa199b1601079d8885668258f0212c2e2dd9148",
      "tree": "bb56dd34543c41b8cc92ebf52ff4b20e33273b1c",
      "parents": [
        "b3390c8cdbe5c1872623493b3b5f30d78c167992"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 07 00:07:12 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jun 07 00:07:12 2022 +0300"
      },
      "message": "Upstream: fixed X-Accel-Expires/Cache-Control/Expires handling.\n\nPreviously, if caching was disabled due to Expires in the past, nginx\nfailed to cache the response even if it was cacheable as per subsequently\nparsed Cache-Control header (ticket #964).\n\nSimilarly, if caching was disabled due to Expires in the past,\n\"Cache-Control: no-cache\" or \"Cache-Control: max-age\u003d0\", caching was not\nused if it was cacheable as per subsequently parsed X-Accel-Expires header.\n\nFix is to avoid disabling caching immediately after parsing Expires in\nthe past or Cache-Control, but rather set flags which are later checked by\nngx_http_upstream_process_headers() (and cleared by \"Cache-Control: max-age\"\nand X-Accel-Expires).\n\nAdditionally, now X-Accel-Expires does not prevent parsing of cache control\nextensions, notably stale-while-revalidate and stale-if-error.  This\nensures that order of the X-Accel-Expires and Cache-Control headers is not\nimportant.\n\nProdded by Vadim Fedorenko and Yugo Horie.\n"
    },
    {
      "commit": "b3390c8cdbe5c1872623493b3b5f30d78c167992",
      "tree": "c308d9b8745ccab841a91e5a1dac54b585817f95",
      "parents": [
        "ce4045d08ba58558b3b8ee9c0bb6566866ef8090"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue May 31 00:14:11 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue May 31 00:14:11 2022 +0300"
      },
      "message": "Upstream: fixed build without http cache (broken by cd73509f21e2).\n"
    },
    {
      "commit": "ce4045d08ba58558b3b8ee9c0bb6566866ef8090",
      "tree": "49345578053b19f88a3e3a49aa02a48e25d63d92",
      "parents": [
        "8a11d4aa62a24ba6be527258ee5536c3270a13cc"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:57 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:57 2022 +0300"
      },
      "message": "Headers filter: improved memory allocation error handling.\n"
    },
    {
      "commit": "8a11d4aa62a24ba6be527258ee5536c3270a13cc",
      "tree": "b0a01db06825a92bf1fee49495fce0c3ea48cc8c",
      "parents": [
        "5adc699f204d7fdfa6a229ca765d2611329eeaaa"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:56 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:56 2022 +0300"
      },
      "message": "Multiple WWW-Authenticate headers with \"satisfy any;\".\n\nIf a module adds multiple WWW-Authenticate headers (ticket #485) to the\nresponse, linked in r-\u003eheaders_out.www_authenticate, all headers are now\ncleared if another module later allows access.\n\nThis change is a nop for standard modules, since the only access module which\ncan add multiple WWW-Authenticate headers is the auth request module, and\nit is checked after other standard access modules.  Though this might\naffect some third party access modules.\n\nNote that if a 3rd party module adds a single WWW-Authenticate header\nand not yet modified to set the header\u0027s next pointer to NULL, attempt to\nclear such a header with this change will result in a segmentation fault.\n"
    },
    {
      "commit": "5adc699f204d7fdfa6a229ca765d2611329eeaaa",
      "tree": "381654eb0d8f4e82542dcda543f8a23d22945798",
      "parents": [
        "694553e378bdc87c81f5bebb151087d5dd5c58a4"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:54 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:54 2022 +0300"
      },
      "message": "Auth request: multiple WWW-Authenticate headers (ticket #485).\n\nWhen using auth_request with an upstream server which returns 401\n(Unauthorized), multiple WWW-Authenticate headers from the upstream server\nresponse are now properly copied to the response.\n"
    },
    {
      "commit": "694553e378bdc87c81f5bebb151087d5dd5c58a4",
      "tree": "d51961c407d50b765baba40513aac768009b6ed0",
      "parents": [
        "c71ce096a48dfe08357eb6df2d4a23fa97bc157f"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:53 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:53 2022 +0300"
      },
      "message": "Upstream: multiple WWW-Authenticate headers (ticket #485).\n\nWhen using proxy_intercept_errors and an error page for error 401\n(Unauthorized), multiple WWW-Authenticate headers from the upstream server\nresponse are now properly copied to the response.\n"
    },
    {
      "commit": "c71ce096a48dfe08357eb6df2d4a23fa97bc157f",
      "tree": "2014be061647972e4b08352b53a3d787f6eed179",
      "parents": [
        "f7b7d2a73730188cbf6ee34814fe679a2780eb8f"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:51 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:51 2022 +0300"
      },
      "message": "Upstream: handling of multiple Vary headers (ticket #1423).\n\nPreviously, only the last header value was used when caching.\n"
    },
    {
      "commit": "f7b7d2a73730188cbf6ee34814fe679a2780eb8f",
      "tree": "8d6977d66aa2966799ce728343e7e3ee0e421bc9",
      "parents": [
        "12325cdd6f4baccbd0036f2af8a122089877e085"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:49 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:49 2022 +0300"
      },
      "message": "Upstream: duplicate headers ignored or properly linked.\n\nMost of the known duplicate upstream response headers are now ignored\nwith a warning.\n\nIf syntax permits multiple headers, these are now properly linked to\nthe lists, notably Vary and WWW-Authenticate.  This makes it possible\nto further handle such lists where it makes sense.\n"
    },
    {
      "commit": "12325cdd6f4baccbd0036f2af8a122089877e085",
      "tree": "61d9ccdee35fca145d8290e8aee8ea45603c3e19",
      "parents": [
        "cc32668cca3ca42bf5ff13aa34f70a29b09cfa51"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:48 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:48 2022 +0300"
      },
      "message": "Upstream: header handlers can now return parsing errors.\n\nWith this change, duplicate Content-Length and Transfer-Encoding headers\nare now rejected.  Further, responses with invalid Content-Length or\nTransfer-Encoding headers are now rejected, as well as responses with both\nContent-Length and Transfer-Encoding.\n"
    },
    {
      "commit": "cc32668cca3ca42bf5ff13aa34f70a29b09cfa51",
      "tree": "128ba0bfd69f7e0820575831c4fe86c5990d8780",
      "parents": [
        "1a82394b172e0f77bb87f728772eaa4ef83a6920"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:46 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:46 2022 +0300"
      },
      "message": "Upstream: all known headers in u-\u003eheaders_in are linked lists now.\n"
    },
    {
      "commit": "1a82394b172e0f77bb87f728772eaa4ef83a6920",
      "tree": "e02d6b996a9a4a1876d1b569809fdffe7b033263",
      "parents": [
        "9490dd342882464861f136cd6f8ba18a6dcc8c1c"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:45 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:45 2022 +0300"
      },
      "message": "All known output headers can be linked lists now.\n\nThe h-\u003enext pointer properly provided as NULL in all cases where known\noutput headers are added.\n\nNote that there are 3rd party modules which might not do this, and it\nmight be risky to rely on this for arbitrary headers.\n"
    },
    {
      "commit": "9490dd342882464861f136cd6f8ba18a6dcc8c1c",
      "tree": "5f4e8c119c51fc1b89c4dc721e03cc5c825e5195",
      "parents": [
        "52aa52fbb09f094c9296a4977738bb7f0c7aec41"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:43 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:43 2022 +0300"
      },
      "message": "Upstream: simplified Accept-Ranges handling.\n\nThe u-\u003eheaders_in.accept_ranges field is not used anywhere and hence removed.\n"
    },
    {
      "commit": "52aa52fbb09f094c9296a4977738bb7f0c7aec41",
      "tree": "2721e4007cad13eba254967439cfc324535713a0",
      "parents": [
        "ea58a0f7f1a006009369fcea8c76199395639c13"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:42 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:42 2022 +0300"
      },
      "message": "Upstream: simplified Content-Encoding handling.\n\nSince introduction of offset handling in ngx_http_upstream_copy_header_line()\nin revision 573:58475592100c, the ngx_http_upstream_copy_content_encoding()\nfunction is no longer needed, as its behaviour is exactly equivalent to\nngx_http_upstream_copy_header_line() with appropriate offset.  As such,\nthe ngx_http_upstream_copy_content_encoding() function was removed.\n\nFurther, the u-\u003eheaders_in.content_encoding field is not used anywhere,\nso it was removed as well.\n\nFurther, Content-Encoding handling no longer depends on NGX_HTTP_GZIP,\nas it can be used even without any gzip handling compiled in (for example,\nin the charset filter).\n"
    },
    {
      "commit": "ea58a0f7f1a006009369fcea8c76199395639c13",
      "tree": "0f3fd5e6dce5df3025c9d163f49cf795ffe8d641",
      "parents": [
        "1fcc5c4fcf5f2668d07c04fcc2f1f34d2764ef9f"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:40 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:40 2022 +0300"
      },
      "message": "Upstream: style.\n"
    },
    {
      "commit": "1fcc5c4fcf5f2668d07c04fcc2f1f34d2764ef9f",
      "tree": "7cbebbd414fd26b222a8cb042643ccb047cfc2c8",
      "parents": [
        "cc7f1b29da7a1c96dc492dc9f0a060fd6000059f"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:38 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:38 2022 +0300"
      },
      "message": "Perl: combining unknown headers during $r-\u003eheader_in() lookup.\n"
    },
    {
      "commit": "cc7f1b29da7a1c96dc492dc9f0a060fd6000059f",
      "tree": "4b09c641a7dd4e012b7174d1641a8b9942e207e2",
      "parents": [
        "136c677ec48e150904d50cc8a190ff0b246c5303"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:36 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:36 2022 +0300"
      },
      "message": "Perl: all known input headers are handled identically.\n\nAs all known input headers are now linked lists, these are now handled\nidentically.  In particular, this makes it possible to access properly\ncombined values of headers not specifically handled previously, such\nas \"Via\" or \"Connection\".\n"
    },
    {
      "commit": "136c677ec48e150904d50cc8a190ff0b246c5303",
      "tree": "f0e0c1174d8da53714555b57b8864e702731f2c9",
      "parents": [
        "027d692a8bf12344ae2e5793d5852c794e8e46e2"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:35 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:35 2022 +0300"
      },
      "message": "All non-unique input headers are now linked lists.\n\nThe ngx_http_process_multi_header_lines() function is removed, as it is\nexactly equivalent to ngx_http_process_header_line().  Similarly,\nngx_http_variable_header() is used instead of ngx_http_variable_headers().\n"
    },
    {
      "commit": "027d692a8bf12344ae2e5793d5852c794e8e46e2",
      "tree": "f926dcda083c18517266b4fd1fabbbe51fbf6f5f",
      "parents": [
        "ebf77b9feb4b0cfe89ec45e2faa03c98e2fb043b"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:33 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:33 2022 +0300"
      },
      "message": "Reworked multi headers to use linked lists.\n\nMulti headers are now using linked lists instead of arrays.  Notably,\nthe following fields were changed: r-\u003eheaders_in.cookies (renamed\nto r-\u003eheaders_in.cookie), r-\u003eheaders_in.x_forwarded_for,\nr-\u003eheaders_out.cache_control, r-\u003eheaders_out.link, u-\u003eheaders_in.cache_control\nu-\u003eheaders_in.cookies (renamed to u-\u003eheaders_in.set_cookie).\n\nThe r-\u003eheaders_in.cookies and u-\u003eheaders_in.cookies fields were renamed\nto r-\u003eheaders_in.cookie and u-\u003eheaders_in.set_cookie to match header names.\n\nThe ngx_http_parse_multi_header_lines() and ngx_http_parse_set_cookie_lines()\nfunctions were changed accordingly.\n\nWith this change, multi headers are now essentially equivalent to normal\nheaders, and following changes will further make them equivalent.\n"
    },
    {
      "commit": "ebf77b9feb4b0cfe89ec45e2faa03c98e2fb043b",
      "tree": "d17f5b0dac07c8ac5d64d8fb32c574915012b12a",
      "parents": [
        "66ff40bb2fd6fa0f9a4ec04ec5fe0dfe427b7288"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:32 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:32 2022 +0300"
      },
      "message": "Combining unknown headers during variables lookup (ticket #1316).\n\nPreviously, $http_*, $sent_http_*, $sent_trailer_*, $upstream_http_*,\nand $upstream_trailer_* variables returned only the first header (with\na few specially handled exceptions: $http_cookie, $http_x_forwarded_for,\n$sent_http_cache_control, $sent_http_link).\n\nWith this change, all headers are returned, combined together.  For\nexample, $http_foo variable will be \"a, b\" if there are \"Foo: a\" and\n\"Foo: b\" headers in the request.\n\nNote that $upstream_http_set_cookie will also return all \"Set-Cookie\"\nheaders (ticket #1843), though this might not be what one want, since\nthe \"Set-Cookie\" header does not follow the list syntax (see RFC 7230,\nsection 3.2.2).\n"
    },
    {
      "commit": "66ff40bb2fd6fa0f9a4ec04ec5fe0dfe427b7288",
      "tree": "3218711c7eccf6e35b44b7deb8752aca1f1e6ec5",
      "parents": [
        "888320f13b28e8d4fe8817f7c0823a6e6f40a458"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:30 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:30 2022 +0300"
      },
      "message": "Uwsgi: combining headers with identical names (ticket #1724).\n\nThe uwsgi specification states that \"The uwsgi block vars represent a\ndictionary/hash\".  This implies that no duplicate headers are expected.\n\nFurther, provided headers are expected to follow CGI specification,\nwhich also requires to combine headers (RFC 3875, section \"4.1.18.\nProtocol-Specific Meta-Variables\"): \"If multiple header fields with\nthe same field-name are received then the server MUST rewrite them\nas a single value having the same semantics\".\n"
    },
    {
      "commit": "888320f13b28e8d4fe8817f7c0823a6e6f40a458",
      "tree": "f2d07308f9740e1e8a98a7b10b12a0d09b390445",
      "parents": [
        "3d58b9a5bcb401004bce801464fddb7dc16e41c7"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:28 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:28 2022 +0300"
      },
      "message": "SCGI: combining headers with identical names (ticket #1724).\n\nSCGI specification explicitly forbids headers with duplicate names\n(section \"3. Request Format\"): \"Duplicate names are not allowed in\nthe headers\".\n\nFurther, provided headers are expected to follow CGI specification,\nwhich also requires to combine headers (RFC 3875, section \"4.1.18.\nProtocol-Specific Meta-Variables\"): \"If multiple header fields with\nthe same field-name are received then the server MUST rewrite them\nas a single value having the same semantics\".\n"
    },
    {
      "commit": "3d58b9a5bcb401004bce801464fddb7dc16e41c7",
      "tree": "cf35530032c5eea4e7cd15fb893fe9ddd0e46730",
      "parents": [
        "b2151b3413d65662c6f4cb14eeb1aa0b9fdad080"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:27 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:27 2022 +0300"
      },
      "message": "FastCGI: combining headers with identical names (ticket #1724).\n\nFastCGI responder is expected to receive CGI/1.1 environment variables\nin the parameters (see section \"6.2 Responder\" of the FastCGI specification).\nObviously enough, there cannot be multiple environment variables with\nthe same name.\n\nFurther, CGI specification (RFC 3875, section \"4.1.18. Protocol-Specific\nMeta-Variables\") explicitly requires to combine headers: \"If multiple\nheader fields with the same field-name are received then the server MUST\nrewrite them as a single value having the same semantics\".\n"
    },
    {
      "commit": "b2151b3413d65662c6f4cb14eeb1aa0b9fdad080",
      "tree": "1a0f9233db35e8fb780bbf48632a5c643ba5be74",
      "parents": [
        "a02adc859f84d33e9e2eba81b93899a725437785"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:25 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 21:25:25 2022 +0300"
      },
      "message": "Perl: fixed $r-\u003eheader_in(\"Connection\").\n\nPreviously, the r-\u003eheader_in-\u003econnection pointer was never set despite\nbeing present in ngx_http_headers_in, resulting in incorrect value returned\nby $r-\u003eheader_in(\"Connection\") in embedded perl.\n"
    },
    {
      "commit": "a02adc859f84d33e9e2eba81b93899a725437785",
      "tree": "0944308c4fe671172ff9260251ecc1fbec1e9dc2",
      "parents": [
        "72a0adef89a5666388dc3f349dbd6f9ba64d24cc"
      ],
      "author": {
        "name": "Marcus Ball",
        "email": "marcus.ball@live.com",
        "time": "Mon May 30 02:38:07 2022 +0300"
      },
      "committer": {
        "name": "Marcus Ball",
        "email": "marcus.ball@live.com",
        "time": "Mon May 30 02:38:07 2022 +0300"
      },
      "message": "Fixed runtime handling of systems without EPOLLRDHUP support.\n\nIn 7583:efd71d49bde0 (nginx 1.17.5) along with introduction of the\nioctl(FIONREAD) support proper handling of systems without EPOLLRDHUP\nsupport in the kernel (but with EPOLLRDHUP in headers) was broken.\n\nBefore the change, rev-\u003eavailable was never set to 0 unless\nngx_use_epoll_rdhup was also set (that is, runtime test for EPOLLRDHUP\nintroduced in 6536:f7849bfb6d21 succeeded).  After the change,\nrev-\u003eavailable might reach 0 on systems without runtime EPOLLRDHUP\nsupport, stopping further reading in ngx_readv_chain() and ngx_unix_recv().\nAnd, if EOF happened to be already reported along with the last event,\nit is not reported again by epoll_wait(), leading to connection hangs\nand timeouts on such systems.\n\nThis affects Linux kernels before 2.6.17 if nginx was compiled\nwith newer headers, and, more importantly, emulation layers, such as\nDigitalOcean\u0027s App Platform\u0027s / gVisor\u0027s epoll emulation layer.\n\nFix is to explicitly check ngx_use_epoll_rdhup before the corresponding\nrev-\u003epending_eof tests in ngx_readv_chain() and ngx_unix_recv().\n"
    },
    {
      "commit": "72a0adef89a5666388dc3f349dbd6f9ba64d24cc",
      "tree": "829c811da09eab0f846062d55a8a3d1789947144",
      "parents": [
        "2a3ad920471a4ffa52f4f14fca3619d820fc6463"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 02:37:59 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon May 30 02:37:59 2022 +0300"
      },
      "message": "Version bump.\n"
    },
    {
      "commit": "2a3ad920471a4ffa52f4f14fca3619d820fc6463",
      "tree": "5dd4d25be3e43a55b0d359b67450fb384f45f2d4",
      "parents": [
        "942fccd4d1d8e5afae2c00e3c1da82572127e8ce"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue May 24 02:51:49 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue May 24 02:51:49 2022 +0300"
      },
      "message": "Updated OpenSSL and zlib used for win32 builds.\n"
    },
    {
      "commit": "942fccd4d1d8e5afae2c00e3c1da82572127e8ce",
      "tree": "45cb448f57bea1332356f4ad9b0cccc7e05a1dbd",
      "parents": [
        "ab8b107e0f47c29967c0b0fc53eef1d9489b39bf"
      ],
      "author": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Fri Apr 29 17:38:01 2022 +0400"
      },
      "committer": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Fri Apr 29 17:38:01 2022 +0400"
      },
      "message": "Configure: recognize arm64 machine name as a synonym for aarch64.\n\nIn particular, this sets a reasonable cacheline size on FreeBSD and macOS,\nwhich prefer to use this name and both lack _SC_LEVEL1_DCACHE_LINESIZE.\n"
    },
    {
      "commit": "ab8b107e0f47c29967c0b0fc53eef1d9489b39bf",
      "tree": "ccbad227be9d94f0c760fac61b460655837e380a",
      "parents": [
        "7546b8be84381ab40eb2025d8161342edd76c235"
      ],
      "author": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Tue Feb 08 17:35:27 2022 +0300"
      },
      "committer": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Tue Feb 08 17:35:27 2022 +0300"
      },
      "message": "SSL: logging level of \"application data after close notify\".\n\nSuch fatal errors are reported by OpenSSL 1.1.1, and similarly by BoringSSL,\nif application data is encountered during SSL shutdown, which started to be\nobserved on the second SSL_shutdown() call after SSL shutdown fixes made in\n09fb2135a589 (1.19.2).  The error means that the client continues to send\napplication data after receiving the \"close_notify\" alert (ticket #2318).\nPreviously it was reported as SSL_shutdown() error of SSL_ERROR_SYSCALL.\n"
    },
    {
      "commit": "7546b8be84381ab40eb2025d8161342edd76c235",
      "tree": "6f29363e530b15b3791c8c20b8f179fef78353b3",
      "parents": [
        "c782ca004ae43af236d67bfb206f22b573edd0a1"
      ],
      "author": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Fri Feb 04 13:29:31 2022 +0300"
      },
      "committer": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Fri Feb 04 13:29:31 2022 +0300"
      },
      "message": "Year 2022.\n"
    },
    {
      "commit": "c782ca004ae43af236d67bfb206f22b573edd0a1",
      "tree": "c4c08967742632d6b9056bcd94ff6461b993a35c",
      "parents": [
        "1bcc8d43d2eed997a5e4c3430459adf63c7657d8"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Feb 03 22:46:01 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Feb 03 22:46:01 2022 +0300"
      },
      "message": "HTTP/2: fixed closed_nodes overflow (ticket #1708).\n\nWith large http2_max_concurrent_streams or http2_max_concurrent_pushes, more\nthan 255 ngx_http_v2_node_t structures might be allocated, eventually leading\nto h2c-\u003eclosed_nodes overflow when closing corresponding streams.  This will\nin turn result in additional allocations in ngx_http_v2_get_node_by_id().\n\nWhile mostly harmless, it can result in excessive memory usage by a HTTP/2\nconnection, notably in configurations with many keepalive_requests allowed.\nFix is to use ngx_uint_t for h2c-\u003eclosed_nodes instead of unsigned:8.\n"
    },
    {
      "commit": "1bcc8d43d2eed997a5e4c3430459adf63c7657d8",
      "tree": "e6aab7e3d18b95394d72b099486542b09068a46f",
      "parents": [
        "70e2f1d4fa02274a7ee85e09f7befa783391681b"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Feb 03 01:44:38 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Feb 03 01:44:38 2022 +0300"
      },
      "message": "HTTP/2: made it possible to flush response headers (ticket #1743).\n\nResponse headers can be buffered in the SSL buffer.  But stream\u0027s fake\nconnection buffered flag did not reflect this, so any attempts to flush\nthe buffer without sending additional data were stopped by the write filter.\n\nIt does not seem to be possible to reflect this in fc-\u003ebuffered though, as\nwe never known if main connection\u0027s c-\u003ebuffered corresponds to the particular\nstream or not.  As such, fc-\u003ebuffered might prevent request finalization\ndue to sending data on some other stream.\n\nFix is to implement handling of flush buffers when the c-\u003eneed_flush_buf\nflag is set, similarly to the existing last buffer handling.  The same\nflag is now used for UDP sockets in the stream module instead of explicit\nchecking of c-\u003etype.\n"
    },
    {
      "commit": "70e2f1d4fa02274a7ee85e09f7befa783391681b",
      "tree": "5d852421041b3ccc512d80a96825fe07b5978317",
      "parents": [
        "d843d75e9e3037056c5a39d9f9affe798763aa8d"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Feb 01 16:29:28 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Feb 01 16:29:28 2022 +0300"
      },
      "message": "Cache: fixed race in ngx_http_file_cache_forced_expire().\n\nDuring configuration reload two cache managers might exist for a short\ntime.  If both tried to delete the same cache node, the \"ignore long locked\ninactive cache entry\" alert appeared in logs.  Additionally,\nngx_http_file_cache_forced_expire() might be also called by worker\nprocesses, with similar results.\n\nFix is to ignore cache nodes being deleted, similarly to how it is\ndone in ngx_http_file_cache_expire() since 3755:76e3a93821b1.  This\nwas somehow missed in 7002:ab199f0eb8e8, when ignoring long locked\ncache entries was introduced in ngx_http_file_cache_forced_expire().\n"
    },
    {
      "commit": "d843d75e9e3037056c5a39d9f9affe798763aa8d",
      "tree": "8614cbab22ccea37275cbd297007a5f7c4bf04d2",
      "parents": [
        "e98a4bd9cfc156276fc810b2096f004100900d6f"
      ],
      "author": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Wed Jan 26 20:40:00 2022 +0300"
      },
      "committer": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Wed Jan 26 20:40:00 2022 +0300"
      },
      "message": "Core: added autotest for UDP segmentation offloading.\n"
    },
    {
      "commit": "1a0408c02365ec7d0f708b80563161e8bfcc11ae",
      "tree": "8aca37797f891deaee957a2bae807315d71c85bc",
      "parents": [
        "901d6a0696a1892e98fcf4a8e862f6c7313c95c2"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jan 25 18:03:52 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jan 25 18:03:52 2022 +0300"
      },
      "message": "release-1.21.6 tag\n"
    },
    {
      "commit": "901d6a0696a1892e98fcf4a8e862f6c7313c95c2",
      "tree": "f14c59749bd10604513af9ae2a9ebecf36701215",
      "parents": [
        "59f287ae4c7057ec0aa1ebf94e87ccb76247bddf"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jan 25 18:03:51 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jan 25 18:03:51 2022 +0300"
      },
      "message": "nginx-1.21.6-RELEASE\n"
    },
    {
      "commit": "e98a4bd9cfc156276fc810b2096f004100900d6f",
      "tree": "3fc1e6c02d9220f8d5b50b4718c3e2bc68a99507",
      "parents": [
        "4b045e37ef8505f1b7b7ae87f27586390251a3c8"
      ],
      "author": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Tue Jan 25 15:48:58 2022 +0300"
      },
      "committer": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Tue Jan 25 15:48:58 2022 +0300"
      },
      "message": "Core: added function for local source address cmsg.\n"
    },
    {
      "commit": "4b045e37ef8505f1b7b7ae87f27586390251a3c8",
      "tree": "674a0706600984a697f37fa15ddfd3646889f986",
      "parents": [
        "26d8788650c130575578cab430279a0b3e3d814e"
      ],
      "author": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Tue Jan 25 15:48:56 2022 +0300"
      },
      "committer": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Tue Jan 25 15:48:56 2022 +0300"
      },
      "message": "Core: made the ngx_sendmsg() function non-static.\n\nThe NGX_HAVE_ADDRINFO_CMSG macro is defined when at least one of methods\nto deal with corresponding control message is available.\n"
    },
    {
      "commit": "26d8788650c130575578cab430279a0b3e3d814e",
      "tree": "26593a44a3e1606653cb9a22cd2198f2dc537605",
      "parents": [
        "cbf9626fb34b506fd53bd6bd52607dd7302f00ff"
      ],
      "author": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Tue Jan 25 15:41:48 2022 +0300"
      },
      "committer": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Tue Jan 25 15:41:48 2022 +0300"
      },
      "message": "Core: the ngx_event_udp.h header file.\n"
    },
    {
      "commit": "cbf9626fb34b506fd53bd6bd52607dd7302f00ff",
      "tree": "7f4945eb7f7f60d82b6f3690bf88803b17032704",
      "parents": [
        "1a0408c02365ec7d0f708b80563161e8bfcc11ae"
      ],
      "author": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Thu Jan 27 13:44:09 2022 +0300"
      },
      "committer": {
        "name": "Vladimir Homutov",
        "email": "vl@nginx.com",
        "time": "Thu Jan 27 13:44:09 2022 +0300"
      },
      "message": "Version bump.\n"
    },
    {
      "commit": "59f287ae4c7057ec0aa1ebf94e87ccb76247bddf",
      "tree": "10e4f33352cb32e0019a6eeccbfb1ec02e6486a7",
      "parents": [
        "9e05f769887baea31ed67d3f16ee6ae7b22d3370"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Jan 24 17:18:50 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Jan 24 17:18:50 2022 +0300"
      },
      "message": "SSL: always renewing tickets with TLSv1.3 (ticket #1892).\n\nChrome only uses TLS session tickets once with TLS 1.3, likely following\nRFC 8446 Appendix C.4 recommendation.  With OpenSSL, this works fine with\nbuilt-in session tickets, since these are explicitly renewed in case of\nTLS 1.3 on each session reuse, but results in only two connections being\nreused after an initial handshake when using ssl_session_ticket_key.\n\nFix is to always renew TLS session tickets in case of TLS 1.3 when using\nssl_session_ticket_key, similarly to how it is done by OpenSSL internally.\n"
    },
    {
      "commit": "9e05f769887baea31ed67d3f16ee6ae7b22d3370",
      "tree": "4fd4d5a150379a8b4bc3d11c3c58995f878ea2f7",
      "parents": [
        "53899e6c33c1198cd2520cc0cad8c284f3af2f4b"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Jan 22 00:28:51 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Jan 22 00:28:51 2022 +0300"
      },
      "message": "Contrib: vim syntax adjusted to save cpoptions (ticket #2276).\n\nLine continuation as used in the syntax file might be broken if \"compatible\"\nis set or \"C\" is added to cpoptions.  Fix is to set the \"cpoptions\" option\nto vim default value at script start and restore it later, see\n\":help use-cpo-save\".\n"
    },
    {
      "commit": "53899e6c33c1198cd2520cc0cad8c284f3af2f4b",
      "tree": "4575dbb897d11ab184d8dbf1458cb6c3f0f6fb47",
      "parents": [
        "d550bc0eebc55079157fe2574bfdb0104d29225d"
      ],
      "author": {
        "name": "Pavel Pautov",
        "email": "p.pautov@f5.com",
        "time": "Wed Jan 19 17:37:34 2022 -0800"
      },
      "committer": {
        "name": "Pavel Pautov",
        "email": "p.pautov@f5.com",
        "time": "Wed Jan 19 17:37:34 2022 -0800"
      },
      "message": "Core: simplify reader lock release.\n"
    },
    {
      "commit": "d550bc0eebc55079157fe2574bfdb0104d29225d",
      "tree": "e8ebdec7baf835bdf8af72b6f9403abfea94ea7a",
      "parents": [
        "9ba1985c9c91e07e968508f8fba6a092c556e327"
      ],
      "author": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Mon Jan 17 17:05:12 2022 +0300"
      },
      "committer": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Mon Jan 17 17:05:12 2022 +0300"
      },
      "message": "SSL: free pkey on SSL_CTX_set0_tmp_dh_pkey() failure.\n\nThe behaviour was changed in OpenSSL 3.0.1:\nhttps://git.openssl.org/?p\u003dopenssl.git;a\u003dcommitdiff;h\u003dbf17b7b\n"
    },
    {
      "commit": "182c48a8de969ab284794afd49ab5ed900443efa",
      "tree": "ed983e8d2575c3ec2af2f51e887572e7e01a5c76",
      "parents": [
        "8890881744360d84ee8a044b8331ce6b28abaf0b"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jan 11 22:50:56 2022 -0800"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Jan 12 07:20:33 2022 +0000"
      },
      "message": "Bazel: fix link for PCRE, now that ftp.pcre.org is gone.\n\nChange-Id: If201af2869f4745fc3beec8ce30ff71cb824b5c8\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\nReviewed-on: https://nginx-review.googlesource.com/c/nginx/+/3980\nReviewed-by: Patryk Lesiewicz \u003cpatryk@google.com\u003e\n"
    },
    {
      "commit": "8890881744360d84ee8a044b8331ce6b28abaf0b",
      "tree": "b8b798458328434f633c6bafa5a55f9c1bcce308",
      "parents": [
        "15ed70ebe92c481130e1d7a0399efddd67e33475"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Jan 11 22:49:40 2022 -0800"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Jan 12 07:20:22 2022 +0000"
      },
      "message": "Bazel: update BoringSSL to 3a667d1 / b9232f9 (master-with-bazel).\n\n3a667d10e Binary tag bump: 1 -\u003e 2\ne7fc7a737 Export PKCS12_DEFAULT_ITER.\nb3ed071ec Add SSL_has_pending.\nea57bcbd6 Update HPKE test vectors.\n16a94930a Add various OpenSSL compatibility functions.\n27a675574 Add PKCS7_bundle_raw_certificates function which takes CRYPTO_BUFFERs\na9670a8b4 No-op change to test the bots.\nba20a754e Remove outdated comment in ECDSA implementation.\n703cb721e Add missing assert.h include.\ncf8d3ad3c Check tag class and constructed bit in d2i_ASN1_OBJECT.\n414a0f86e Don\u0027t parse constructed BIT STRINGs in crypto/bytestring\n13c67c99d Enforce DER rules for BIT STRING values.\nee510f588 Remove support for indefinite lengths in crypto/asn1.\na70edd47a Remove support for constructed strings in crypto/asn1.\n491af1036 Check for trailing data in extensions.\n16b3af7d2 Update tools.\n9fd163756 Fold x509v3/pcy_int.h into x509v3/internal.h.\n91b892496 Switch kModuleDigestSize to a macro.\n17c38b39e Switch DEPS actions on bots to Python 3.\n69030a0ce Match OPENSSL_EXPORT in ssl/internal.h friend declarations.\nc2827d3b5 Add a function to express the desired record version protocol.\n7cac8faff Add CRYPTO_BUFFER_new_from_static_data_unsafe.\n28c48e38a Finish documenting asn1.h.\n2cbc39a3c Trim some undocumented symbols from asn1.h.\n89386ac89 Add magic tag to BoringSSL binaries.\n1dcdbdad9 Document and const-correct multi-string types.\ne1049fd88 Fully unexport X509_VAL.\nd2d1d3c6a Document ASN1_OBJECT, i2c, and c2i functions.\na259a5484 Unexport ASN1_OBJECT_new.\nefab69bf7 Return 0x80 in all ASN1_get_object error paths.\n471e631f4 Document low-level encoding functions in asn1.h.\n08dee19b7 Use C preprocessor comments in assembly headers.\n45608a1b9 Document and const-correct ASN1_TYPE functions.\n686d05aaa Fix error-handling for i2a_ASN1_OBJECT.\nae274a25a Document i2a_ASN1_* functions.\n2dc2f1093 Fold i2a_ASN1_ENUMERATED into i2a_ASN1_INTEGER.\na7e807481 Fix BIT STRING comparison in ASN1_STRING_cmp.\n4298fce7d Rewrite ASN1_item_pack and ASN1_item_unpack.\n141472c21 Document some more ASN1_ITEM-associated functions.\n7c1f40f2f Reword ASN1_BOOLEAN exception.\nbb88f5226 Move M_ASN1_* to the deprecated section.\n8a5ec7255 Fix up some doc.go nits in asn1.h.\n370a3c2e2 Document new/free/d2i/i2d for singly-typed ASN1_STRINGs.\na78e3240c Document ASN1_NULL.\nc11fcb06e Const-correct the low-level ASN1 i2d functions.\nb4156026a Start documenting ASN1_ITEM.\n7a4df8e97 Tidy up SSLTest.SetVersion.\ncfafcd454 Deduplicate d2i and i2d documentation.\n\nChange-Id: If85ac4b4130ea9c8df77ea84ac09ef3498782cf7\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\nReviewed-on: https://nginx-review.googlesource.com/c/nginx/+/3961\nReviewed-by: Patryk Lesiewicz \u003cpatryk@google.com\u003e\n"
    },
    {
      "commit": "9ba1985c9c91e07e968508f8fba6a092c556e327",
      "tree": "914d8155937fb36d83372cc9a6e961994316aa7d",
      "parents": [
        "24669b398f92bcebb9adfea245d3a05bcaf092fb"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jan 11 02:23:49 2022 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Jan 11 02:23:49 2022 +0300"
      },
      "message": "Avoid sending \"Connection: keep-alive\" when shutting down.\n\nWhen a worker process is shutting down, keepalive is not used: this is checked\nbefore the ngx_http_set_keepalive() call in ngx_http_finalize_connection().\nYet the \"Connection: keep-alive\" header was still sent, even if we know that\nthe worker process is shutting down, potentially resulting in additional\nrequests being sent to the connection which is going to be closed anyway.\nWhile clients are expected to be able to handle asynchronous close events\n(see ticket #1022), it is certainly possible to send the \"Connection: close\"\nheader instead, informing the client that the connection is going to be closed\nand potentially saving some unneeded work.\n\nWith this change, we additionally check for worker process shutdown just\nbefore sending response headers, and disable keepalive accordingly.\n"
    },
    {
      "commit": "24669b398f92bcebb9adfea245d3a05bcaf092fb",
      "tree": "b723bd96fa33a0aeb570cbbfd6121d0b94289193",
      "parents": [
        "10ebf4fd91bdde2c2f774b9cd8f75aa2d9984a7c"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Dec 30 01:08:46 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Dec 30 01:08:46 2021 +0300"
      },
      "message": "Events: fixed balancing between workers with EPOLLEXCLUSIVE.\n\nLinux with EPOLLEXCLUSIVE usually notifies only the process which was first\nto add the listening socket to the epoll instance.  As a result most of the\nconnections are handled by the first worker process (ticket #2285).  To fix\nthis, we re-add the socket periodically, so other workers will get a chance\nto accept connections.\n"
    },
    {
      "commit": "10ebf4fd91bdde2c2f774b9cd8f75aa2d9984a7c",
      "tree": "2469fabe81e62333f55e01a2b44104c9c8a2e7f1",
      "parents": [
        "37f533bd4e741535b8373c433ae061c70c16b7cc"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Wed Dec 29 22:59:53 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Wed Dec 29 22:59:53 2021 +0300"
      },
      "message": "Version bump.\n"
    },
    {
      "commit": "37f533bd4e741535b8373c433ae061c70c16b7cc",
      "tree": "1402226aacb194d56f889b91699e2c73f304f2a2",
      "parents": [
        "4d2d9752f930276e6d9685302754a6626b3e323f"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Dec 28 18:28:38 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Dec 28 18:28:38 2021 +0300"
      },
      "message": "release-1.21.5 tag\n"
    },
    {
      "commit": "4d2d9752f930276e6d9685302754a6626b3e323f",
      "tree": "6873a092a30b97568a6d734a394707ed70c2622d",
      "parents": [
        "adc8a50ab9aa3ddc860949d653fbf7e649a09b16"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Dec 28 18:28:37 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Dec 28 18:28:37 2021 +0300"
      },
      "message": "nginx-1.21.5-RELEASE\n"
    },
    {
      "commit": "adc8a50ab9aa3ddc860949d653fbf7e649a09b16",
      "tree": "8033a4db7e5622eaea211ff0cf6093fdf03a5cd9",
      "parents": [
        "568ac3f94703cf73901909abbd9bffe513629746"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Dec 28 17:56:16 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Dec 28 17:56:16 2021 +0300"
      },
      "message": "Updated OpenSSL and PCRE used for win32 builds.\n"
    },
    {
      "commit": "568ac3f94703cf73901909abbd9bffe513629746",
      "tree": "70456837095468405c238636c3e1aa1e63373110",
      "parents": [
        "d9d0799a7ff3569c8fbeb0f6ead98a8caee05ae0"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Dec 27 19:49:26 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Dec 27 19:49:26 2021 +0300"
      },
      "message": "Support for sendfile(SF_NOCACHE).\n\nThe SF_NOCACHE flag, introduced in FreeBSD 11 along with the new non-blocking\nsendfile() implementation by glebius@, makes it possible to use sendfile()\nalong with the \"directio\" directive.\n"
    },
    {
      "commit": "d9d0799a7ff3569c8fbeb0f6ead98a8caee05ae0",
      "tree": "948a3adf557d6c070e9d7160c3105c0d02044fb6",
      "parents": [
        "d161231abf18b45c60436f2f221fe01890d0e0bf"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Dec 27 19:48:42 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Dec 27 19:48:42 2021 +0300"
      },
      "message": "SSL: SSL_sendfile(SF_NODISKIO) support.\n"
    },
    {
      "commit": "d161231abf18b45c60436f2f221fe01890d0e0bf",
      "tree": "a26a95bdb97e61c0832d893a1dc037741ccb475a",
      "parents": [
        "e83c2aa81dba9a1a9f66a4d27b7b7183143e2b0a"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Dec 27 19:48:33 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Dec 27 19:48:33 2021 +0300"
      },
      "message": "Simplified sendfile(SF_NODISKIO) usage.\n\nStarting with FreeBSD 11, there is no need to use AIO operations to preload\ndata into cache for sendfile(SF_NODISKIO) to work.  Instead, sendfile()\nhandles non-blocking loading data from disk by itself.  It still can, however,\nreturn EBUSY if a page is already being loaded (for example, by a different\nprocess).  If this happens, we now post an event for the next event loop\niteration, so sendfile() is retried \"after a short period\", as manpage\nrecommends.\n\nThe limit of the number of EBUSY tolerated without any progress is preserved,\nbut now it does not result in an alert, since on an idle system event loop\niteration might be very short and EBUSY can happen many times in a row.\nInstead, SF_NODISKIO is simply disabled for one call once the limit is\nreached.\n\nWith this change, sendfile(SF_NODISKIO) is now used automatically as long as\nsendfile() is enabled, and no longer requires \"aio on;\".\n"
    },
    {
      "commit": "e83c2aa81dba9a1a9f66a4d27b7b7183143e2b0a",
      "tree": "19ca55535e87de3ba76ab7707f7cc4d4a52a0a4d",
      "parents": [
        "9b329558e9ab1a663054e9a4c8475fb06413d191"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Dec 27 19:47:05 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Mon Dec 27 19:47:05 2021 +0300"
      },
      "message": "Removed \"aio sendfile\", deprecated since 1.7.11.\n"
    },
    {
      "commit": "9b329558e9ab1a663054e9a4c8475fb06413d191",
      "tree": "7d0190e2d6e53af3944da7b25d3aa3d9d118b9de",
      "parents": [
        "57c4a825e5e45a57264b4631c81346b49c0d766a"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:18 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:18 2021 +0300"
      },
      "message": "Core: added NGX_REGEX_MULTILINE for 3rd party modules.\n\nNotably, NAXSI is known to misuse ngx_regex_compile() with rc.options set\nto PCRE_CASELESS | PCRE_MULTILINE.  With PCRE2 support, and notably binary\ncompatibility changes, it is no longer possible to set PCRE[2]_MULTILINE\noption without using proper interface.  To facilitate correct usage,\nthis change adds the NGX_REGEX_MULTILINE option.\n"
    },
    {
      "commit": "57c4a825e5e45a57264b4631c81346b49c0d766a",
      "tree": "546ca4eff7cdd6918e2efb5283eb60c96c0f30c5",
      "parents": [
        "4e6581b231f2fc49f6a7f5e72b0eb17408997958"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:16 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:16 2021 +0300"
      },
      "message": "PCRE2 and PCRE binary compatibility.\n\nWith this change, dynamic modules using nginx regex interface can be used\nregardless of the variant of the PCRE library nginx was compiled with.\n\nIf a module is compiled with different PCRE library variant, in case of\nngx_regex_exec() errors it will report wrong function name in error\nmessages.  This is believed to be tolerable, given that fixing this will\nrequire interface changes.\n"
    },
    {
      "commit": "4e6581b231f2fc49f6a7f5e72b0eb17408997958",
      "tree": "2ac67a198959d1bf38efc6179bebee93f8b627e6",
      "parents": [
        "a93847dff2de71c03511712e6449cb4235516d28"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:15 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:15 2021 +0300"
      },
      "message": "PCRE2 library support.\n\nThe PCRE2 library is now used by default if found, instead of the\noriginal PCRE library.  If needed for some reason, this can be disabled\nwith the --without-pcre2 configure option.\n\nTo make it possible to specify paths to the library and include files\nvia --with-cc-opt / --with-ld-opt, the library is first tested without\nany additional paths and options.  If this fails, the pcre2-config script\nis used.\n\nSimilarly to the original PCRE library, it is now possible to build PCRE2\nfrom sources with nginx configure, by using the --with-pcre\u003d option.\nIt automatically detects if PCRE or PCRE2 sources are provided.\n\nNote that compiling PCRE2 10.33 and later requires inttypes.h.  When\ncompiling on Windows with MSVC, inttypes.h is only available starting\nwith MSVC 2013.  In older versions some replacement needs to be provided\n(\"echo \u0027#include \u003cstdint.h\u003e\u0027 \u003e pcre2-10.xx/src/inttypes.h\" is good enough\nfor MSVC 2010).\n\nThe interface on nginx side remains unchanged.\n"
    },
    {
      "commit": "a93847dff2de71c03511712e6449cb4235516d28",
      "tree": "349a1c793ad831b719d86b92d28bdcc3fbc966dd",
      "parents": [
        "14909a398934682166c409ebab0553b10b7d7cef"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:14 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:14 2021 +0300"
      },
      "message": "Configure: simplified PCRE compilation.\n\nRemoved ICC-specific PCRE optimizations which tried to link with PCRE\nobject files instead of the library.  Made compiler-specific code\nminimal.\n"
    },
    {
      "commit": "14909a398934682166c409ebab0553b10b7d7cef",
      "tree": "038d40952d8a77f1aae1400cb7dd86c4b85c718b",
      "parents": [
        "7ab9ea34efb76fdc93a46f63ce7f6c29449f90be"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:12 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:12 2021 +0300"
      },
      "message": "Core: ngx_regex.c style cleanup.\n\nNotably, ngx_pcre_pool and ngx_pcre_studies are renamed to ngx_regex_pool\nand ngx_regex_studies, respectively.\n"
    },
    {
      "commit": "7ab9ea34efb76fdc93a46f63ce7f6c29449f90be",
      "tree": "c286e2a53afe4d252f1c7911ff7ff286cac65f7e",
      "parents": [
        "d35dfe22ced7ae3682b98ab0d66d54cc0f50f6dd"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:10 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Dec 25 01:07:10 2021 +0300"
      },
      "message": "Core: fixed ngx_pcre_studies cleanup.\n\nIf a configuration parsing fails for some reason, ngx_regex_module_init()\nis not called, and ngx_pcre_studies remained set despite the fact that\nthe pool it was allocated from is already freed.  This might result in\na segmentation fault during runtime regular expression compilation, such\nas in SSI, for example, in the single process mode, or if a worker process\ndied and was respawned from a master process in such an inconsistent state.\n\nFix is to clear ngx_pcre_studies from the pool cleanup handler (which is\nanyway used to free JIT-compiled patterns).\n"
    },
    {
      "commit": "d35dfe22ced7ae3682b98ab0d66d54cc0f50f6dd",
      "tree": "96b09e11f52821d4e54fb33543abb0af443f042e",
      "parents": [
        "ad9b508c869245d36bc0cb1d0dac527c1aacfebd"
      ],
      "author": {
        "name": "Ruslan Ermilov",
        "email": "ru@nginx.com",
        "time": "Tue Dec 21 07:54:16 2021 +0300"
      },
      "committer": {
        "name": "Ruslan Ermilov",
        "email": "ru@nginx.com",
        "time": "Tue Dec 21 07:54:16 2021 +0300"
      },
      "message": "Moved Huffman coding out of HTTP/2.\n\nngx_http_v2_huff_decode.c and ngx_http_v2_huff_encode.c are renamed\nto ngx_http_huff_decode.c and ngx_http_huff_encode.c.\n"
    },
    {
      "commit": "ad9b508c869245d36bc0cb1d0dac527c1aacfebd",
      "tree": "e97caeb4a80b1d674bd35a9dc99b7363d191c498",
      "parents": [
        "155c24a16838fbb15e08e0e171361110b1c7656e"
      ],
      "author": {
        "name": "Gena Makhomed",
        "email": "gmm@csdoc.com",
        "time": "Mon Dec 20 20:02:48 2021 +0200"
      },
      "committer": {
        "name": "Gena Makhomed",
        "email": "gmm@csdoc.com",
        "time": "Mon Dec 20 20:02:48 2021 +0200"
      },
      "message": "Contrib: vim syntax, update core and 3rd party module directives.\n"
    },
    {
      "commit": "155c24a16838fbb15e08e0e171361110b1c7656e",
      "tree": "55673052e76b4d5f7002d61ae9b94db0e0f6fa41",
      "parents": [
        "353b22b448cd8611f8e09de790d8e7514bf1cbb1"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Nov 25 22:02:10 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Nov 25 22:02:10 2021 +0300"
      },
      "message": "HTTP/2: fixed sendfile() aio handling.\n\nWith sendfile() in threads (\"aio threads; sendfile on;\"), client connection\ncan block on writing, waiting for sendfile() to complete.  In HTTP/2 this\nmight result in the request hang, since an attempt to continue processing\nin thread event handler will call request\u0027s write event handler, which\nis usually stopped by ngx_http_v2_send_chain(): it does nothing if there\nare no additional data and stream-\u003equeued is set.  Further, HTTP/2 resets\nstream\u0027s c-\u003ewrite-\u003eready to 0 if writing blocks, so just fixing\nngx_http_v2_send_chain() is not enough.\n\nCan be reproduced with test suite on Linux with:\n\nTEST_NGINX_GLOBALS_HTTP\u003d\"aio threads; sendfile on;\" prove h2*.t\n\nThe following tests currently fail: h2_keepalive.t, h2_priority.t,\nh2_proxy_max_temp_file_size.t, h2.t, h2_trailers.t.\n\nSimilarly, sendfile() with AIO preloading on FreeBSD can block as well,\nwith similar results.  This is, however, harder to reproduce, especially\non modern FreeBSD systems, since sendfile() usually does not return EBUSY.\n\nFix is to modify ngx_http_v2_send_chain() so it actually tries to send\ndata to the main connection when called, and to make sure that\nc-\u003ewrite-\u003eready is set by the relevant event handlers.\n"
    },
    {
      "commit": "353b22b448cd8611f8e09de790d8e7514bf1cbb1",
      "tree": "b7981c366e436e5a110d414e150f22f5750cfeac",
      "parents": [
        "5458465d33ba39800289b27d002e103f2be4de9c"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Nov 25 22:02:05 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Thu Nov 25 22:02:05 2021 +0300"
      },
      "message": "HTTP/2: fixed \"task already active\" with sendfile in threads.\n\nWith sendfile in threads, \"task already active\" alerts might appear in logs\nif a write event happens on the main HTTP/2 connection, triggering a sendfile\nin threads while another thread operation is already running.  Observed\nwith \"aio threads; aio_write on; sendfile on;\" and with thread event handlers\nmodified to post a write event to the main HTTP/2 connection (though can\nhappen without any modifications).\n\nSimilarly, sendfile() with AIO preloading on FreeBSD can trigger duplicate\naio operation, resulting in \"second aio post\" alerts.  This is, however,\nharder to reproduce, especially on modern FreeBSD systems, since sendfile()\nusually does not return EBUSY.\n\nFix is to avoid starting a sendfile operation if other thread operation\nis active by checking r-\u003eaio in the thread handler (and, similarly, in\naio preload handler).  The added check also makes duplicate calls protection\nredundant, so it is removed.\n"
    },
    {
      "commit": "15ed70ebe92c481130e1d7a0399efddd67e33475",
      "tree": "93648b1273d85507ad05b078b9dcd2e7e02dba0d",
      "parents": [
        "fd71400026676f5366e90c999acd6b0e9fc58c75",
        "20b99034de094b69c5dd3c5ec473925026ab5627"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Nov 02 16:25:30 2021 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Tue Nov 02 16:25:30 2021 -0700"
      },
      "message": "Merge branch \u0027nginx\u0027 (nginx-1.21.4).\n\nChange-Id: I536c3df3620b3fc2f904d920d07bea71cd5d70e4\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\n"
    },
    {
      "commit": "20b99034de094b69c5dd3c5ec473925026ab5627",
      "tree": "216892427ca43d9630bb7e2df94b4fa98e74e078",
      "parents": [
        "8d178fc358a789c3ff812c4c6b5c9546125bff39"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Nov 02 17:49:22 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Nov 02 17:49:22 2021 +0300"
      },
      "message": "release-1.21.4 tag\n"
    },
    {
      "commit": "8d178fc358a789c3ff812c4c6b5c9546125bff39",
      "tree": "fda6af4bc7856f2550739ce7dae1e233fc394247",
      "parents": [
        "84241aba000e2c20b90b3e4d22497249bd78cfe0"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Nov 02 17:49:22 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Nov 02 17:49:22 2021 +0300"
      },
      "message": "nginx-1.21.4-RELEASE\n"
    },
    {
      "commit": "5458465d33ba39800289b27d002e103f2be4de9c",
      "tree": "b6eaa157a50bb89e75ba60e4f4dd768c9a79021e",
      "parents": [
        "eaa0a009180712770cf4bd2eb2ad0aa562f53c8f"
      ],
      "author": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Mon Nov 01 18:09:34 2021 +0300"
      },
      "committer": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Mon Nov 01 18:09:34 2021 +0300"
      },
      "message": "SSL: $ssl_curve (ticket #2135).\n\nThe variable contains a negotiated curve used for the handshake key\nexchange process.  Known curves are listed by their names, unknown\nones are shown in hex.\n\nNote that for resumed sessions in TLSv1.2 and older protocols,\n$ssl_curve contains the curve used during the initial handshake,\nwhile in TLSv1.3 it contains the curve used during the session\nresumption (see the SSL_get_negotiated_group manual page for\ndetails).\n\nThe variable is only meaningful when using OpenSSL 3.0 and above.\nWith older versions the variable is empty.\n"
    },
    {
      "commit": "eaa0a009180712770cf4bd2eb2ad0aa562f53c8f",
      "tree": "220e7cc1f66f31a509303d20da6b072384ada49b",
      "parents": [
        "20b99034de094b69c5dd3c5ec473925026ab5627"
      ],
      "author": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Tue Nov 23 12:52:43 2021 +0300"
      },
      "committer": {
        "name": "Sergey Kandaurov",
        "email": "pluknet@nginx.com",
        "time": "Tue Nov 23 12:52:43 2021 +0300"
      },
      "message": "Version bump.\n"
    },
    {
      "commit": "84241aba000e2c20b90b3e4d22497249bd78cfe0",
      "tree": "410c73dc78269f3371d9bd67aee3bd5843bf0fcf",
      "parents": [
        "4536113ad3ae6f16d1638aa4e4d81c94e1e6b357"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Oct 30 02:39:19 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Sat Oct 30 02:39:19 2021 +0300"
      },
      "message": "Changed ngx_chain_update_chains() to test tag first (ticket #2248).\n\nWithout this change, aio used with HTTP/2 can result in connection hang,\nas observed with \"aio threads; aio_write on;\" and proxying (ticket #2248).\n\nThe problem is that HTTP/2 updates buffers outside of the output filters\n(notably, marks them as sent), and then posts a write event to call\noutput filters.  If a filter does not call the next one for some reason\n(for example, because of an AIO operation in progress), this might\nresult in a state when the owner of a buffer already called\nngx_chain_update_chains() and can reuse the buffer, while the same buffer\nis still sitting in the busy chain of some other filter.\n\nIn the particular case a buffer was sitting in output chain\u0027s ctx-\u003ebusy,\nand was reused by event pipe.  Output chain\u0027s ctx-\u003ebusy was permanently\nblocked by it, and this resulted in connection hang.\n\nFix is to change ngx_chain_update_chains() to skip buffers from other\nmodules unconditionally, without trying to wait for these buffers to\nbecome empty.\n"
    },
    {
      "commit": "4536113ad3ae6f16d1638aa4e4d81c94e1e6b357",
      "tree": "50c16e7e52b07684b77f908dd4fadc7a11ffe4f4",
      "parents": [
        "d77bd28ea7be4edd1f5dfde600f96368ccce55e4"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:57 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:57 2021 +0300"
      },
      "message": "Changed default value of sendfile_max_chunk to 2m.\n\nThe \"sendfile_max_chunk\" directive is important to prevent worker\nmonopolization by fast connections.  The 2m value implies maximum 200ms\ndelay with 100 Mbps links, 20ms delay with 1 Gbps links, and 2ms on\n10 Gbps links.  It also seems to be a good value for disks.\n"
    },
    {
      "commit": "d77bd28ea7be4edd1f5dfde600f96368ccce55e4",
      "tree": "90b050a7621ba3a9595e96a8c5d6b29723752895",
      "parents": [
        "e2e3a5eb52641e9224444a47f7540ae7fe4f631f"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:54 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:54 2021 +0300"
      },
      "message": "Upstream: sendfile_max_chunk support.\n\nPreviously, connections to upstream servers used sendfile() if it was\nenabled, but never honored sendfile_max_chunk.  This might result\nin worker monopolization for a long time if large request bodies\nare allowed.\n"
    },
    {
      "commit": "e2e3a5eb52641e9224444a47f7540ae7fe4f631f",
      "tree": "cbb6329257bcf64c2060b7744fc5094716b355d4",
      "parents": [
        "f832b67df4cc1d47b40bca1dbb69336d1178a645"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:51 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:51 2021 +0300"
      },
      "message": "Fixed sendfile() limit handling on Linux.\n\nOn Linux starting with 2.6.16, sendfile() silently limits all operations\nto MAX_RW_COUNT, defined as (INT_MAX \u0026 PAGE_MASK).  This incorrectly\ntriggered the interrupt check, and resulted in 0-sized writev() on the\nnext loop iteration.\n\nFix is to make sure the limit is always checked, so we will return from\nthe loop if the limit is already reached even if number of bytes sent is\nnot exactly equal to the number of bytes we\u0027ve tried to send.\n"
    },
    {
      "commit": "f832b67df4cc1d47b40bca1dbb69336d1178a645",
      "tree": "d3f1c433c7a65a55220c42d8ed064561d00306cf",
      "parents": [
        "717df913ea56c4c372895eb9c2dbdb9a1fa383f9"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:48 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:48 2021 +0300"
      },
      "message": "Simplified sendfile_max_chunk handling.\n\nPreviously, it was checked that sendfile_max_chunk was enabled and\nalmost whole sendfile_max_chunk was sent (see e67ef50c3176), to avoid\ndelaying connections where sendfile_max_chunk wasn\u0027t reached (for example,\nwhen sending responses smaller than sendfile_max_chunk).  Now we instead\ncheck if there are unsent data, and the connection is still ready for writing.\nAdditionally we also check c-\u003ewrite-\u003edelayed to ignore connections already\ndelayed by limit_rate.\n\nThis approach is believed to be more robust, and correctly handles\nnot only sendfile_max_chunk, but also internal limits of c-\u003esend_chain(),\nsuch as sendfile() maximum supported length (ticket #1870).\n"
    },
    {
      "commit": "717df913ea56c4c372895eb9c2dbdb9a1fa383f9",
      "tree": "aa669395d898888cbd06c93ebf1a8aa57a6952e2",
      "parents": [
        "e5eb81d599e4a689c01e7e40ce3e445ea231723b"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:43 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Fri Oct 29 20:21:43 2021 +0300"
      },
      "message": "Switched to using posted next events after sendfile_max_chunk.\n\nPreviously, 1 millisecond delay was used instead.  In certain edge cases\nthis might result in noticeable performance degradation though, notably on\nLinux with typical CONFIG_HZ\u003d250 (so 1ms delay becomes 4ms),\nsendfile_max_chunk 2m, and link speed above 2.5 Gbps.\n\nUsing posted next events removes the artificial delay and makes processing\nfast in all cases.\n"
    },
    {
      "commit": "e5eb81d599e4a689c01e7e40ce3e445ea231723b",
      "tree": "71fa1760f10835fd9855251b584c985308877a47",
      "parents": [
        "4714ca0e97153b0bc00737dd92b106cf7987f9d7"
      ],
      "author": {
        "name": "Roman Arutyunyan",
        "email": "arut@nginx.com",
        "time": "Thu Oct 28 14:14:25 2021 +0300"
      },
      "committer": {
        "name": "Roman Arutyunyan",
        "email": "arut@nginx.com",
        "time": "Thu Oct 28 14:14:25 2021 +0300"
      },
      "message": "Mp4: mp4_start_key_frame directive.\n\nThe directive enables including all frames from start time to the most recent\nkey frame in the result.  Those frames are removed from presentation timeline\nusing mp4 edit lists.\n\nEdit lists are currently supported by popular players and browsers such as\nChrome, Safari, QuickTime and ffmpeg.  Among those not supporting them properly\nis Firefox[1].\n\nBased on a patch by Tracey Jaquith, Internet Archive.\n\n[1] https://bugzilla.mozilla.org/show_bug.cgi?id\u003d1735300\n"
    },
    {
      "commit": "4714ca0e97153b0bc00737dd92b106cf7987f9d7",
      "tree": "d4119c887b13bcf748f2b019fbf75771735eb8c6",
      "parents": [
        "2deb7bd7b58deb58e1e1572ee0eb7d8e2638f314"
      ],
      "author": {
        "name": "Roman Arutyunyan",
        "email": "arut@nginx.com",
        "time": "Thu Oct 28 13:11:31 2021 +0300"
      },
      "committer": {
        "name": "Roman Arutyunyan",
        "email": "arut@nginx.com",
        "time": "Thu Oct 28 13:11:31 2021 +0300"
      },
      "message": "Mp4: added ngx_http_mp4_update_mdhd_atom() function.\n\nThe function updates the duration field of mdhd atom.  Previously it was\nupdated in ngx_http_mp4_read_mdhd_atom().  The change makes it possible to\nalter track duration as a result of processing track frames.\n"
    },
    {
      "commit": "fd71400026676f5366e90c999acd6b0e9fc58c75",
      "tree": "bed4dec86ba9c36288f14db6d34eef0dcd29790f",
      "parents": [
        "92c0a876ea1174b8771e8bd2ea3a83ed312a181a"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Oct 20 17:10:09 2021 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Thu Oct 21 00:34:52 2021 +0000"
      },
      "message": "Bazel: update BoringSSL to f6ef1c5 / 95b3ed1 (master-with-bazel).\n\nf6ef1c560 Check tag class and constructed bit in d2i_ASN1_BOOLEAN.\n2f8bf102e Use typedefs in i2d and d2i_ASN1_BOOLEAN.\n45c8be91f Forward-declare SSL_CLIENT_HELLO.\n052453852 Fix BN_CTX usage in BN_mod_sqrt malloc error paths.\na406ad76a Make ASN1_NULL an opaque pointer.\nf5e601275 Remove remnants of ASN.1 print function generators.\nc31a8a6f0 Fold x509_vfy.h into x509.h.\nf61997b4d Make ASN1_STRING_TABLE_add thread-safe and document.\n38890fdef Test ASN1_STRING_set_by_NID with custom NIDs.\ndb93c2524 Test ASN1_STRING_set_by_NID with built-in NIDs.\na50f24c85 Test that built-in ASN1_STRING_TABLEs are sorted.\nfa6ced951 Extract common rotl/rotr functions.\n523d6c74c Remove X509_STORE_set0_additional_untrusted.\n8f5eb80b8 Enable X509_V_FLAG_TRUSTED_FIRST by default.\n2bde9365f Switch x509_test.cc to modify the existing X509_VERIFY_PARAM.\n87f316d77 Add note to HMAC test vectors from NIST\ncc509bdb7 Add log tag for Trusty.\n551ccd7e9 Fix CRYPTO_malloc, etc., definitions.\n03cae7a2b Keep EVP_CIPHER/EVP_MD lookup and do_all functions in sync\ndedd23e59 aarch64: Add missing LR validation in \u0027vpaes_cbc_encrypt\u0027\n66e61c577 Allow PKCS7_sign to work for signing kernel modules.\nf958727f7 Speed up constant-time base64 decoding.\n4937f05cc Unwind remnants of ASN1_TFLG_NDEF.\nf3e594151 acvptool: add CS3 support.\n41adb341b Ignore SIGPIPE in the bssl tool.\n1c2473eba Add FIPS counters for AES-GCM in EVP_AEAD.\ncd32fd37d Refresh fuzzer corpus for ECH draft-13.\n27a3328a3 Fix the TLS fuzzers for ECH draft-13.\n62c4f1547 Clarify that TLS sessions are not application sessions.\n019cc625b Fix BN_prime_checks_for_validation to align with false-positive rate.\n0446b5942 Add maskHash to RSA_PSS_PARAMS for compat\ned5f4e82e Remove ASN1_OP_I2D_* callbacks.\nafed9f762 Don\u0027t read it-\u003efuncs without checking it-\u003eitype.\n866cccc54 Reject missing required fields in i2d functions.\nc9b75aff2 Reject -1 types in ASN1_TYPE and MSTRINGs when encoding.\n6e70be0f8 Correctly handle invalid ASN1_OBJECTs when encoding.\n248ab8176 Check for invalid CHOICE selectors in i2d functions.\n3b6cebb1e Fix x509_name_ex_i2d error-handling.\n27b31cfc5 Correctly propagate errors in i2d functions.\n25773430c acvptool: add hmacDRBG support\na03c34c6d Check for __TRUSTY__ instead of TRUSTY.\n0fa3030e1 Update comment for ECH draft-13.\nc0fcb4e24 Silence a GCC false positive warning.\n1a668b39d Switch to the new, simpler WHATWG URL formulation.\nb49b78ef3 Revert \"Guard use of sdallocx with BORINGSSL_SDALLOCX\"\n19fe7943c Fix calculation of draft-13 ECH confirmation signal.\n18b6836b2 Update to draft-ietf-tls-esni-13.\n37a3c70c0 Reword SSL_get0_ech_name_override documentation.\n07b365f63 Remove SSL_set_verify_result.\ndddb60eb9 Make most of crypto/x509 opaque.\n59aff62ca Remove V_ASN1_APP_CHOOSE.\n6b7525a9f Rewrite ASN1_PRINTABLE_type and add tests.\n31f462a1e Include SHA512-256 in EVP_get_digestbyname and EVP_MD_do_all.\n96181288c NUL is not printable.\nc65543b7a Make RSA_check_key more than 2x as fast.\n417010f9b Benchmark RSA private key parsing.\nc6d3fd1d0 Work around yet another MSVC 2015 SFINAE bug.\nd55f450c4 Avoid re-hashing the transcript multiple times.\na75027b04 Make ssl_parse_extensions a little easier to use.\ne2cb42376 Deduplicate our three ServerHello parsers.\n61f320874 Merge in OpenSSL\u0027s X.509 corpus.\n6038ac5ce Run X509_print in the certificate fuzzer.\ncdfc2595b Fix some error-handling in i2v functions.\n4bf0a19ac Fix typo.\n5984cfe8e OPENSSL_strndup should not return NULL given {NULL, 0}.\nb27438e12 Rewrite name constraints matching with CBS.\n04601b026 Add some tests for name constraints.\n2d10c18b3 Fix i2v_GENERAL_NAME to not assume NUL terminated strings\n4f9a7ba47 Do not rely on ASN1_STRING being NUL-terminated.\n954506271 Add a CBB_add_zeros helper.\n047ff6428 Linkify RFCs in documentation.\n8648c5369 Refer to RFCs consistently.\n16c3e3ae0 runner: Test session IDs over 32 bytes.\n05ce773ca Process the TLS 1.3 cipher suite in one place.\n80df7398c Guard use of sdallocx with BORINGSSL_SDALLOCX\na603c828d Bump minimum GCC version and note impending VS2015 deprecation.\n006f20ad7 Add Span::first() and Span::last().\n2e68a05c9 Simplify built-in BIOs slightly.\n69ec7c8de Fix some error returns from SSL_read and SSL_write.\nb9ee7b143 Fix negative ENUMERATED values in multi-strings.\n1b2db8c7c Add a test for ASN1_mbstring_copy and clean up.\neb17de499 Remove ASN1_TFLG_SET_ORDER.\nb319e3b89 Fix ASN1_STRING_print_ex with negative integers.\ne3a365554 Check i2d_ASN1_TYPE\u0027s return value in ASN1_STRING_print_ex.\n4c993da66 Document ASN.1 printing functions.\n07a6628e4 Move some ASN1 printing functions to crypto/asn1.\n0dcbc6e14 Move a_strex.c back to asn1, split X509_NAME bits out.\n1201c9ad8 Unwind io_ch abstraction in print functions.\n7a6066ca6 Implement ASN1_STRING_print_ex_fp, etc., with file BIOs.\nb9ec9dee5 Remove OPENSSL_NO_FP_API ifdefs.\n28d7252d2 Move X509_ALGOR to x509.h.\n8627e9743 Unexport BIT_STRING_BITNAME.\n11a24ae02 Unexport ub_* constants.\nf8b3961b0 Always use an ASN1_STRING_TABLE global mask of UTF8String.\n6d8456980 Document ASN1_mbstring_copy.\n47c5f9d2f Update ghashv8-armx.pl from upstream.\n549e4e799 Align with upstream on \u0027close STDOUT\u0027 lines.\n7e265971c Avoid double-expanding variables in CMake.\nead57c300 Reject years outside 0000-9999 in ASN1_GENERALIZEDTIME_adj.\n46e0523ea Add some tests for time_t to ASN1_TIME conversions.\n046fc130d Remove ASN1_STRING_FLAG_MSTRING.\n116d9250a Document another batch of functions.\ne9fae77c0 Clarify BIO_new_mum_buf\u0027s lifetime rules.\n0768d42c2 generate_ech.cc: include needed headers\nf1d153dc3 Don\u0027t overread in poly_Rq_mul\n5799ebfe5 acvp: recognise another style of JSON.\nd422d2c4a Revert \"Revert \"Revert \"Disable check that X.509 extensions implies v3.\"\"\"\nc1571feb5 acvp: add HKDF support.\n7a817f48b Add \u0027generate-ech\u0027 command to bssl tool\ne38cf79cd Don\u0027t enable atomics in NO_THREADS configurations.\n17be3872a Check strtoul return for overflow error in GetUnsigned()\n897a2ca3f Add convenience functions to malloc EVP_HPKE_CTX and EVP_HPKE_KEY.\n6191cc95a Document that SSL_PRIVATE_KEY_METHOD should configure signing prefs.\n519c2986c Always have CRYPTO_sysrand_for_seed.\n715301301 hrss: use less stack space.\n94a608a1f Make X509_EXTENSION opaque.\na5a9b54d8 Make X509_CRL opaque.\nb86dcfefe Switch another malloc to bssl::Array.\necc301ca0 Add a pointer alignment helper function.\n268a4a6ff Remove unused field in X509_NAME_ENTRY.\n61a21e7ec Fix sign bit in BN_div if numerator and quotient alias.\nad5db9658 Handle the server case in SSL_get0_ech_name_override.\n62d6ed60d Remove -2 return value from X509*_get_*_by_NID.\n2cf7a2cde Remove X509at_get0_data_by_OBJ.\n957f23d2c Document a batch of extension-related functions in x509.h.\n7ada84669 conf: fix getting keys from the default section.\n919a97393 conf: don\u0027t crash when parsing.\nae7c17868 Add some OpenSSL compatibility aliases.\n170045f49 Make ASN1_OBJECT opaque.\ne3a7bd0a8 Rename asn1_locl.h to internal.h.\n5514476c4 Update hpke_test.go.\nc220b5fa6 Decorate x509v3_a2i_ipadd declaration as its definition.\n25d501c77 SHA-256 is used on AArch64, even if NO_ASM.\nb90cdddcd swtb is another AArch64 magic tweak.\nba423c9a1 Implement ClientHelloOuter handshakes.\nca7ef8c85 runner: Add a convenience function for base64 flags.\na10017c54 Reduce bouncing on the cache lock in ssl_update_cache.\n10a76acb0 Only clear not_resumable after the handshake.\nafa867be8 runner: Test that clients actually use renewed tickets.\n5d224a559 runner: Clean up test logic.\nc41a3a937 runner: Fix process exit timeout.\n479adf98d Remove old ASN.1 SET macros.\nb147c99dd Document some ASN1_INTEGER and ASN1_ENUMERATED functions.\n87be65922 Document ASN1_STRING_to_UTF8.\n5f8c681d7 Const-correct ASN1_item_verify a bit more.\n520678284 Compute ASN.1 BIT STRING sizes more consistently.\ncafb99211 Remove lh_FOO_doall.\nec8c67dfb Prefix internal LHASH functions.\n7f85116be Unexport almost all of LHASH.\nec552cab8 Rename t1_lib.cc to extensions.cc.\nf25ada3a7 Prefix and unexport a2i_ipadd.\nf315a86df Fix a -Wdeprecated-copy warning.\n9cbe737ec Validate ECH public names.\n869bf9f3a Fold X509_VERIFY_PARAM_ID into X509_VERIFY_PARAM.\n58abd2e6f Make X509_VERIFY_PARAM opaque.\n36ea4d113 Move crypto/x509/vpm_int.h into internal.h.\n6d3d0690f Reformat x509_vfy.h and convert comments.\n\nChange-Id: I77e07130a3c3fdd777579f2789b8506cc2e0c275\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\nReviewed-on: https://nginx-review.googlesource.com/c/nginx/+/3943\nReviewed-by: Wayne Zhang \u003cqiwzhang@google.com\u003e\n"
    },
    {
      "commit": "92c0a876ea1174b8771e8bd2ea3a83ed312a181a",
      "tree": "ed4f881ea2eacfbf28907b0cd27054bb1303fd9d",
      "parents": [
        "a0ec130fd46f134d45ce5bc2d0c11a69c3a9a1bf",
        "375b6a1ffeed906614a34005422117fbac8ab739"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Oct 20 16:59:55 2021 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Oct 20 16:59:55 2021 -0700"
      },
      "message": "Merge branch \u0027nginx\u0027 (nginx-1.21.3).\n\nChange-Id: I6187c1805b0cba41ca9aa0abfe66b21b793a3772\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\n"
    },
    {
      "commit": "a0ec130fd46f134d45ce5bc2d0c11a69c3a9a1bf",
      "tree": "882102adb36c6edd562d54cdcb71c0e87c087074",
      "parents": [
        "6d26b92867444bac056bc113488bbb44c8f06a93",
        "c74816b0ff4b25b7a2cf7eabf37fdb551937673b"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Oct 20 16:45:04 2021 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Oct 20 16:45:04 2021 -0700"
      },
      "message": "Merge branch \u0027nginx\u0027 (nginx-1.21.2).\n\nChange-Id: Id7b704a389afccf96a9d219955393ac8ca01b360\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\n"
    },
    {
      "commit": "6d26b92867444bac056bc113488bbb44c8f06a93",
      "tree": "1914f31b99034eb79ccfcbbd65d74ffe3b0ecb63",
      "parents": [
        "2bb5830cb3512a85909d92f0eba6313a231bb15d"
      ],
      "author": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Oct 20 15:32:39 2021 -0700"
      },
      "committer": {
        "name": "Piotr Sikora",
        "email": "piotrsikora@google.com",
        "time": "Wed Oct 20 23:28:42 2021 +0000"
      },
      "message": "Bazel: update package version.\n\nMissed in 0110ca8d63f697bb662a5727e1de42c211a989ac.\n\nChange-Id: Ia6d7f9c33b1a228d4ea7ea61d5f8a0b5fa8e40f1\nSigned-off-by: Piotr Sikora \u003cpiotrsikora@google.com\u003e\nReviewed-on: https://nginx-review.googlesource.com/c/nginx/+/3940\n"
    },
    {
      "commit": "375b6a1ffeed906614a34005422117fbac8ab739",
      "tree": "63b8c4aea673576beae1018d640848da65404fea",
      "parents": [
        "00a6b69038fa3889ca3b4a6352eceeef844f004a"
      ],
      "author": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Sep 07 18:21:03 2021 +0300"
      },
      "committer": {
        "name": "Maxim Dounin",
        "email": "mdounin@mdounin.ru",
        "time": "Tue Sep 07 18:21:03 2021 +0300"
      },
      "message": "release-1.21.3 tag\n"
    }
  ],
  "next": "00a6b69038fa3889ca3b4a6352eceeef844f004a"
}
