Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESRABBITMQVERIFIED

PUBLISHER UPDATE · RABBITMQ-4.3.5

RABBITMQ-4.3.5 release notes and known issues

RabbitMQ 4.3.5

Scope: RabbitMQ. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

RabbitMQ 4.3.5 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version The minimum supported Erlang version for this release series is 27.0 . RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes With direct reply-to , a message routed to multiple targets that resolved to the same process could be delivered to it more than once. GitHub issue: #17071 Quorum queue recovery from a recovery checkpoint could leave a part of the queue's internal state only partially initialized. GitHub issue: #17012 In clusters that run a mix of 4.2.x and 4.3.x nodes during a rolling upgrade, local quorum queue queries now fall back to the previous state machine version instead of failing. GitHub issue: #17128 A malformed AMQP 1.0 frame now results in a framing error returned to the client instead of an exception. GitHub issue: #17101 The AMQP 1.0 message parser now validates message sections more strictly and decodes certain types of arrays more efficiently. GitHub issue: #17049 Topic exchanges now limit the number of multi-segment ( # ) wildcards a binding key can use to two. The # wildcard is meant to be used as the final segment, that is, just once. GitHub issue: #17039 When connection credentials are refreshed (for example, when an OAuth 2 token is renewed), the user's tags are now updated instead of being carried over from the original state. GitHub issue: #17029 Definition import from an HTTPS endpoint no longer fails when a password-protected TLS (HTTPS) client certificate is used. Contributed by @Pyolar . GitHub issue: #16973 The AMQP 1.0 Erlang client no longer logs an exception when a link is already detached. Workloads that use short lived links could produce a substantial amount of log noise. GitHub issue: #17124 Enhancements Authentication events are now logged under a new logging category, user . Successful logins are logged at the info level, failed login attempts at the warning level. GitHub issue: #16907 CLI Tools Enhancements rabbitmqctl hash_password now supports more password hashing functions. GitHub issues: #14215 , #17108 Stream Plugin Bug Fixes A stream protocol connection can have at most 256 publishers and 256 subscriptions, a limit that comes from the protocol's wire format. Attempts to go over these limits are now rejected early with a clear error instead of failing later with an unrelated one. GitHub issue: #17123 Enhancements Before a stream client connection completes authentication and authorization (that is, before a successful open ), the server now enforces a low frame_max ceiling instead of the full configured value. The default, 8192 bytes, is high enough to accommodate realistic JWT tokens used with SASL PLAIN authentication, and mirrors a mechanism already in place for AMQP 0-9-1 connections. It can be adjusted with the new stream.initial_frame_max setting. GitHub issue: #17053 New setting: stream.max_uncompressed_sub_entry_batch_size . It bounds the declared uncompressed size of a published sub-entry batch, and defaults to 67108864 (64 MiB), the same default already used by the Java client's maxUncompressedSubEntryBatchSize . The broker and any client publishing to it should be configured with the same value. GitHub issue: #17103 Management Plugin Bug Fixes HTTP API endpoints that accept a node name, including the federation and tracing related ones, now validate that the target node is a cluster member. GitHub issues: #17106 , #17118 The management UI no longer displays certain alert messages twice. GitHub issue: #17127 Enhancements When management.credential_encryption_secret is configured, the management UI login endpoint ( POST /api/login )

Improvements and security content

  • RabbitMQ 4.3.5 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version The minimum supported Erlang version for this release series is 27.0 . RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes With direct reply-to , a message routed to multiple targets that resolved to the same process could be delivered to it more than once. GitHub issue: #17071 Quorum queue recovery from a recovery checkpoint could leave a part of the queue's internal state only partially initialized. GitHub issue: #17012 In clusters that run a mix of 4.2.x and 4.3.x nodes during a rolling upgrade, local quorum queue queries now fall back to the previous state machine version instead of failing. GitHub issue: #17128 A malformed AMQP 1.0 frame now results in a framing error returned to the client instead of an exception. GitHub issue: #17101 The AMQP 1.0 message parser now validates message sections more strictly and decodes certain types of arrays more efficiently. GitHub issue: #17049 Topic exchanges now limit the number of multi-segment ( # ) wildcards a binding key can use to two. The # wildcard is meant to be used as the final segment, that is, just once. GitHub issue: #17039 When connection credentials are refreshed (for example, when an OAuth 2 token is renewed), the user's tags are now updated instead of being carried over from the original state. GitHub issue: #17029 Definition import from an HTTPS endpoint no longer fails when a password-protected TLS (HTTPS) client certificate is used. Contributed by @Pyolar . GitHub issue: #16973 The AMQP 1.0 Erlang client no longer logs an exception when a link is already detached. Workloads that use short lived links could produce a substantial amount of log noise. GitHub issue: #17124 Enhancements Authentication events are now logged under a new logging category, user . Successful logins are logged at the info level, failed login attempts at the warning level. GitHub issue: #16907 CLI Tools Enhancements rabbitmqctl hash_password now supports more password hashing functions. GitHub issues: #14215 , #17108 Stream Plugin Bug Fixes A stream protocol connection can have at most 256 publishers and 256 subscriptions, a limit that comes from the protocol's wire format. Attempts to go over these limits are now rejected early with a clear error instead of failing later with an unrelated one. GitHub issue: #17123 Enhancements Before a stream client connection completes authentication and authorization (that is, before a successful open ), the server now enforces a low frame_max ceiling instead of the full configured value. The default, 8192 bytes, is high enough to accommodate realistic JWT tokens used with SASL PLAIN authentication, and mirrors a mechanism already in place for AMQP 0-9-1 connections. It can be adjusted with the new stream.initial_frame_max setting. GitHub issue: #17053 New setting: stream.max_uncompressed_sub_entry_batch_size . It bounds the declared uncompressed size of a published sub-entry batch, and defaults to 67108864 (64 MiB), the same default already used by the Java client's maxUncompressedSubEntryBatchSize . The broker and any client publishing to it should be configured with the same value. GitHub issue: #17103 Management Plugin Bug Fixes HTTP API endpoints that accept a node name, including the federation and tracing related ones, now validate that the target node is a cluster member. GitHub issues: #17106 , #17118 The management UI no longer displays certain alert messages twice. GitHub issue: #17127 Enhancements When management.credential_encryption_secret is configured, the management UI login endpoint ( POST /api/login )

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • RabbitMQ

Affected versions

  • 4.3.5
  • 4.3
  • 4.3.0
  • 27.0
  • 4.2
  • 1.0

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence