RabbitMQ v4.3.2

v4.3.2

RabbitMQ 4.3.2

Added 3
  • Several new rabbitmq.conf keys now support encrypted values
  • A one-time warning is now logged when the HSTS or CSP headers are disabled
  • The timestamp of the oldest message in a stream is now displayed on the stream page
Changed 3
  • The per-node channel limit (channel_max_per_node) is now also enforced for channels opened on direct Erlang client connections used by the Shovel and Federation plugins
  • Modules are now loaded in parallel early on node boot, reducing node startup time
  • Stream metadata queries now contact cluster nodes concurrently, subscription lookups use a more efficient data structure, and frame processing short-circuits when a connection reaches a terminal state
Fixed 12
  • Enabling the tie_binding_to_dest_with_keep_while_cond feature flag could fail in some rare cases
  • Users created without a password or a password hash over the HTTP API are now stored correctly, exactly like users whose password was cleared with rabbitmqctl clear_password
  • Consumer activity status of classic queue consumers was not always correctly updated and reported when single active consumer was enabled
  • The values of the x-consumer-timeout and x-consumer-disconnected-timeout optional arguments are now validated at queue declaration time
  • Default queue type validation now treats empty strings the same way as a missing value by falling back to the default
  • Feature flag operations now avoid unnecessary work by excluding flags already enabled on all cluster nodes from synchronization
Security 2
  • Validate access-control-request-headers values and reject wildcard (*) origin header value
  • Definitions import now limits the size of multipart upload bodies and definitions export download filenames are restricted to a safe character set

RabbitMQ 4.3.2 is a maintenance release in the 4.3.x release series.

It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0.

Minimum Supported Erlang Version

RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ.

Nodes will fail to start on older Erlang releases.

Changes Worth Mentioning

Release notes can be found on GitHub at rabbitmq-server/release-notes.

Core Server
Bug Fixes
  • Enabling the tie_binding_to_dest_with_keep_while_cond feature flag could fail in some rare cases.

    GitHub issue: #16587

  • Users created without a password or a password hash (for example, those that rely on X.509 certificate-based authentication) over the HTTP API are now stored correctly, exactly like the users whose password was cleared with rabbitmqctl clear_password.

    GitHub issues: #16629, #16633

  • Consumer activity status of classic queue consumers was not always correctly updated and reported when single active consumer was enabled.

    GitHub issues: #16532, #16450

  • The values of the x-consumer-timeout and x-consumer-disconnected-timeout optional arguments are now validated at queue declaration time.

    GitHub issue: #16557

  • Default queue type (DQT) validation now treats empty strings the same way as a missing value: by falling back. to the default (classic queues).

    GitHub issues: #16481, #16488

  • Feature flag operations now avoid unnecessary work: flags that are already enabled on all cluster nodes are excluded from synchronization, and enabling an empty set of flags is a no-op.

    GitHub issue: #16497

  • Configuration changes for deprecated features are now honored when possible.

    GitHub issue: #16500

Enhancements
  • The per-node channel limit (channel_max_per_node) is now also enforced for channels opened on direct Erlang client connections used by the Shovel and Federation plugins, matching the behavior enforced for "regular" AMQP 0-9-1 clients.

    GitHub issues: #16616, #16618

  • Modules are now loaded in parallel early on node boot, reducing node startup time.

    GitHub issue: #16479

  • Several new rabbitmq.conf keys now supports encrypted values.

    GitHub issue: #16632

CLI Tools
Bug Fixes
  • rabbitmqctl set_topic_permissions now validates target user and exchange for existence.

    GitHub issue: #16590

  • rabbitmqctl add_vhost now validates the provided default queue type value.

    GitHub issue: #16481

Stream Plugin
Bug Fixes
  • Fixed a frame assembly performance regression in the stream protocol reader.

    GitHub issue: #16588

Enhancements
  • Several stream protocol reader optimizations: stream metadata queries now contact cluster nodes concurrently, subscription lookups use a more efficient data structure, and frame processing short-circuits when a connection reaches a terminal state.

    GitHub issue: #16588

Management Plugin
Bug Fixes
  • CORS hardening: access-control-request-headers values are now validated and a wildcard (*) origin header value is rejected.

    GitHub issue: #16544

  • Definitions import now limits the size of multipart upload bodies, and definitions export download filenames are restricted to a safe character set.

    GitHub issue: #16544

  • HTTP API 500 responses no longer include internal error details in the response body.

    GitHub issue: #16544

  • Several HTTP response headers are now consistently lowercase, and a previously missing content-type header was added to certain responses.

    GitHub issue: #16544

Enhancements
  • A one-time warning is now logged when the HSTS or CSP headers are disabled.

    GitHub issue: #16544

  • The timestamp of the oldest message in a stream is now displayed on the stream page.

    GitHub issue: #15412

  • The queue list page can now display a "Delayed" message count column, for example, for quorum queues that have a retry policy configured.

    GitHub issue: #16639

Prometheus Plugin
Enhancements
  • More plugin configuration keys, such as prometheus.ssl.password, now support encrypted values in rabbitmq.conf.

    GitHub issues: #16516, #16521

MQTT Plugin
Bug Fixes
  • mqtt.tcp_listen_options.* settings in rabbitmq.conf did not take effect due to a configuration translation issue.

    GitHub issue: #16529

Dependency Changes
  • cuttlefish was upgraded to 3.9.1
  • cowboy was upgraded to 2.16.0
  • cowlib was upgraded to 2.17.0
  • gun was upgraded to 2.4.0
View original

Upgraded? How did it go?

Discussion