Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[backport -> release/3.4.x] chore(deps): bump openresty from 1.21.4.1 to 1.21.4.3 #11966

Merged
merged 3 commits into from
Nov 15, 2023

Conversation

samugi
Copy link
Member

@samugi samugi commented Nov 9, 2023

Summary

backport of:

to release/3.4.x

In order to enable upgrading lua-kong-nginx-module to 0.8.0 and backport the request_id feature

related PR (EE): https://github.com/Kong/kong-ee/pull/7206

Checklist

  • (no) The Pull Request has tests
  • (no) A changelog file has been created under changelog/unreleased/kong or skip-changelog label added on PR if changelog is unnecessary. README.md
  • (no) There is a user-facing docs PR against https://github.com/Kong/docs.konghq.com - PUT DOCS PR HERE

Full changelog

  • [Implement ...]

Issue reference

KAG-3040

@samugi samugi marked this pull request as draft November 9, 2023 09:06
@samugi samugi force-pushed the cherry-pick/request-id-11624 branch 2 times, most recently from bd3146c to 183b89d Compare November 9, 2023 09:17
@pull-request-size pull-request-size bot added size/S and removed size/XS labels Nov 9, 2023
@samugi samugi force-pushed the cherry-pick/request-id-11624 branch from 183b89d to a397231 Compare November 9, 2023 09:29
@samugi samugi force-pushed the cherry-pick/request-id-11624 branch from a397231 to f133169 Compare November 9, 2023 09:33
@samugi samugi changed the title [backport -> release/3.4.x] feat(request-id): introduce Request ID [backport -> release/3.4.x] chore(deps): bump openresty from 1.21.4.1 to 1.21.4.2 Nov 9, 2023
@samugi samugi force-pushed the cherry-pick/request-id-11624 branch from 010999d to 76ad311 Compare November 9, 2023 10:16
@samugi samugi force-pushed the cherry-pick/request-id-11624 branch from 76ad311 to 3747231 Compare November 9, 2023 11:18
@chronolaw
Copy link
Contributor

Should we upgrade to 1.21.4.3?

@samugi
Copy link
Member Author

samugi commented Nov 9, 2023

Should we upgrade to 1.21.4.3?

yes, I'm doing this one step at a time to make troubleshooting easier if any tests start failing in #11970. I'll bump to 1.21.4.3 once green, leaving as draft in the meantime.

@samugi samugi changed the title [backport -> release/3.4.x] chore(deps): bump openresty from 1.21.4.1 to 1.21.4.2 [backport -> release/3.4.x] chore(deps): bump openresty from 1.21.4.1 to 1.21.4.3 Nov 9, 2023
@samugi samugi marked this pull request as ready for review November 9, 2023 15:28
@samugi samugi requested review from bungle and chronolaw November 9, 2023 15:33
@tzssangglass
Copy link
Member

just curious, I noticed this PR deleted some patches, it has been included in the new version of OpenResty?

@samugi
Copy link
Member Author

samugi commented Nov 10, 2023

yes @tzssangglass you can see this for example in: #11952 (that this PR is backporting)

dndx
dndx previously requested changes Nov 13, 2023
changelog/unreleased/kong/bump-openresty-1.21.4.3.yml Outdated Show resolved Hide resolved
@samugi samugi force-pushed the cherry-pick/request-id-11624 branch from 124843e to dc360a0 Compare November 13, 2023 09:03
@samugi samugi requested a review from dndx November 13, 2023 09:04
@samugi samugi force-pushed the cherry-pick/request-id-11624 branch from dc360a0 to 50a1d75 Compare November 13, 2023 09:09
@samugi samugi requested a review from nowNick November 14, 2023 10:09
See: https://openresty.org/en/ann-1021004002.html

Signed-off-by: Aapo Talvensaari <aapo.talvensaari@gmail.com>
Without this I get:
```
Hunk #1 succeeded at 121 (offset 8 lines).
Hunk #2 succeeded at 143 (offset 8 lines).
```

When applying the `ldp_stp_fusion` patch.

Signed-off-by: Aapo Talvensaari <aapo.talvensaari@gmail.com>
### Summary

- bugfix: applied the patch for security advisory to NGINX cores. (CVE-2023-44487).

Kong already had the patch, but well, now that it is packaged, we can remove ours,
and get to the latest OpenResty

KAG-3033

Signed-off-by: Aapo Talvensaari <aapo.talvensaari@gmail.com>
@samugi samugi force-pushed the cherry-pick/request-id-11624 branch from 50a1d75 to f3e5fb1 Compare November 14, 2023 17:36
@samugi samugi dismissed dndx’s stale review November 15, 2023 08:41

change applied

@samugi samugi merged commit a94ecb7 into release/3.4.x Nov 15, 2023
24 checks passed
@samugi samugi deleted the cherry-pick/request-id-11624 branch November 15, 2023 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants