chore(deps): update dependency erlang to v29 - #122
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
from
May 14, 2026 17:38
02839b2 to
be4941c
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
2 times, most recently
from
May 27, 2026 11:56
e81e6ee to
5cff8d4
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
3 times, most recently
from
June 10, 2026 12:13
5a45b48 to
2c3543e
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
from
June 23, 2026 17:13
2c3543e to
d068d96
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
from
July 2, 2026 16:47
d068d96 to
ce752a1
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
from
July 27, 2026 14:39
ce752a1 to
6b6fc75
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
2 times, most recently
from
August 4, 2026 23:10
c0eb877 to
4162d9a
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
2 times, most recently
from
September 1, 2026 12:12
02305ff to
7f18cdf
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
from
September 16, 2026 16:50
7f18cdf to
ac10772
Compare
renovate
Bot
force-pushed
the
renovate/erlang-29.x
branch
from
September 22, 2026 22:34
ac10772 to
0e367e8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
27.3.4→29.1.127.3.4→29.1.1Release Notes
erlang/otp (erlang)
v29.1.1: OTP 29.1.1Compare Source
Check out the git tag OTP-29.1.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
POTENTIAL INCOMPATIBILITIES
Fixed a vulnerability where the
max_channelsdaemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit.The default value of the max_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting
{max_channels, infinity}.The default value of the max_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting
{max_sessions, infinity}.Own Id: OTP-20287
Application(s): ssh
Related Id(s): GH-SA-qhcm-px9c-rvfh, PR-11523, CVE-2026-68956
asn1-5.5.2
The asn1-5.5.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a denial-of-service attack in asn1, where abnormally large OID components (arcs) could cause resource exhaustion.
Own Id: OTP-20272
Related Id(s): PR-11655, CVE-2026-65634
The JER backend will no longer break certain values (true, false, null) when they are typed as ENUMERATED, they will now be encoded as strings as required by the standard.
Own Id: OTP-20355
Related Id(s): ERIERL-1355, PR-11559
compiler-10.0.6
The compiler-10.0.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Certain uses of funs could crash the compiler. For example:
This has been corrected.
Own Id: OTP-20386
Related Id(s): GH-11619, PR-11638
public_key-1.21.7
The public_key-1.21.7 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Handle that policy qualifiers are optional.
Own Id: OTP-20393
Related Id(s): PR-11630
ssh-6.0.6
The ssh-6.0.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a vulnerability where the
max_channelsdaemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit.The default value of the max_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting
{max_channels, infinity}.The default value of the max_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting
{max_sessions, infinity}.Own Id: OTP-20287
Related Id(s): GH-SA-qhcm-px9c-rvfh, PR-11523, CVE-2026-68956
*** POTENTIAL INCOMPATIBILITY ***
The SSH daemon no longer rejects a
subsystemrequest that is preceded byenvorpty-reqrequest on the same channel.Own Id: OTP-20371
Related Id(s): ERIERL-1363, GH-11586, PR-11616
ssl-11.7.7
Note! The ssl-11.7.7 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Reject unsolicited TLS-1.3 pre_shared_key in client.
Own Id: OTP-20388
Related Id(s): PR-11641, CVE-2026-89422
Security and robustness hardening returning RFC mandated alert reasons, narrowing/correcting length checks.
Correct signature algorithm handling that slightly mixed up signature algorithms and signature algorithms cert in TLS-1.2.
Add missing TLS-1.3 Brainpool groups support. (Not relevant in 27 patch)
Enhanced/corrected documentation and spec errors/deviations.
Own Id: OTP-20390
Related Id(s): PR-11651
Thanks to
Alan Duffield
v29.1: OTP 29.1Compare Source
Check out the git tag OTP-29.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
POTENTIAL INCOMPATIBILITIES
When
beam_libreturns an error tuple, the filename in the information tuple is now a list of characters instead of an atom.Example:
The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the
beam_liberrors (not recommended) will need to be updated.Own Id: OTP-20118
Application(s): stdlib
Related Id(s): PR-11167
OTP-29.1
Improvements and New Features
A new
versionsmodule has been added to theruntime_toolsapplication containing functions for, e.g., comparing, versions that adhere to the OTP Versions Scheme.The documentation of the OTP Versions Scheme has also been improved.
Own Id: OTP-20352
Related Id(s): PR-11556, PR-11600
asn1-5.5.1
The asn1-5.5.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The modern representation of BITSTRINGs is now always supported for encoding, regardless of any legacy options given. The JER backend would not support the modern representation when any legacy option was given.
Own Id: OTP-20145
Related Id(s): PR-11097
The
make cleancommand did not remove all generated.erlfiles.Own Id: OTP-20295
Related Id(s): PR-11375
common_test-1.31.2
The common_test-1.31.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The internal
cte_trackevent handler now correctly displays the suite name for suites without aninit_per_suite/1callback.Own Id: OTP-20316
Related Id(s): PR-11501
compiler-10.0.5
The compiler-10.0.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a native record crash in the
sys_core_foldcompiler pass.Own Id: OTP-20254
Related Id(s): GH-11351, PR-11359
The compiler could crash when compiling a map comprehension.
Own Id: OTP-20255
Related Id(s): GH-11352, PR-11363
Fixed a crash when the key pattern in a map comprehension was a bitstring.
Own Id: OTP-20262
Related Id(s): GH-11367, PR-11379
Fixed an issue that could crash the compiler when compiling comprehensions with the
compr_assignfeature enabled.Own Id: OTP-20267
Related Id(s): GH-11366, PR-11390
Code that called
erlang:0()inside a fun could crash the compiler.Own Id: OTP-20280
Related Id(s): GH-11414, PR-11424
Fixed an internal error when
lists:keyfind/3is called with an argument that exceeds system limits.Own Id: OTP-20291
Related Id(s): GH-11413, PR-11444
An incorrect
useless_buildingwarning has been eliminated.Own Id: OTP-20304
Related Id(s): GH-11472, PR-11477
In rare circumstances, the type analysis pass of the compiler could run for many minutes.
Own Id: OTP-20365
Related Id(s): GH-11534, PR-11566
crypto-5.10
The crypto-5.10 application can be applied independently of other applications on a full OTP 29 installation.
Improvements and New Features
The documentation of the
cryptomodule now contains runnable examples for most functions. The examples are verified by the crypto test suite, so they always match actual behavior.Own Id: OTP-20373
Related Id(s): PR-11170
dialyzer-6.0.3
The dialyzer-6.0.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed Dialyzer crash when overriding built-in types.
Own Id: OTP-19631
Related Id(s): GH-11093, PR-11096
Typer crashed when multiple functions were written in the same line. For example:
Own Id: OTP-20297
Related Id(s): PR-11466
erts-17.1
The erts-17.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed bug in
ets:member/2forset,bagandduplicate_bag. The bug could (maybe) lead toets:memberspuriously returning false for a value which is actually a member for a table that faces high insert load.Own Id: OTP-20152
Related Id(s): PR-11115
Fixed crashing bug caused by race between timer creating process and suspending receiver of the timer. Only seen to cause crash one time by extremely provoking test case. Bug exists only since OTP 29.0.
Own Id: OTP-20175
Related Id(s): PR-11196
Fixed bug in
enif_realloc_binarywhen called with a read-only binary. Instead of returning false at out-of-memory failure, it returned true and did nothing.Own Id: OTP-20187
Related Id(s): PR-11133
Fixed alternate signal stack sizing on musl (Alpine) running on CPUs whose Linux kernel reports large signal frames (AVX-512/AMX). It caused emulator to abort during startup with "Failed to set alternate signal stack".
Own Id: OTP-20213
Related Id(s): GH-11248, PR-11249
For
socket:recvmmsg/6, the buffer length was not handled correctly when the OS network stack truncated the received message, so garbage data with incorrect length could be delivered to the calling process. This bug has been corrected.Own Id: OTP-20246
Related Id(s): PR-11335
binary_to_term/1will now reject an external native record with duplicated fields.Own Id: OTP-20276
Related Id(s): GH-11398, PR-11410
Fixed a crash upon starting the emulator on systems with a very large minimum signal stack size.
Own Id: OTP-20292
Related Id(s): GH-11349, PR-11376
Fixed lock order violation during crash dump due to export table exhaustion. Only problem for debug emulator.
Own Id: OTP-20305
Related Id(s): PR-11460
Fixed rounding errors when converting large integers to floating point numbers, explicitly with
float/1or implicitly in arithmetic such as1.0 * N. Integers with absolute values larger than 64 bits that could not be represented exactly as a float could be rounded to the second nearest float instead of the nearest. For example,float(428654966685883400000)returned4.2865496668588343e20instead of the correct4.286549666858834e20, which is whatbinary_to_float/1returns for the same number.Own Id: OTP-20317
Related Id(s): PR-11391
An error check in
prim_inethas been fixed. This manifested itself asfile:sendfile/*sometimes crashing instead of returning an error when the remote end closes the socket during initialization.Own Id: OTP-20356
Related Id(s): PR-11438
Improvements and New Features
Fairness of code permission locks have been improved to avoid long latencies for code loading and trace operations.
Own Id: OTP-20188
Related Id(s): PR-11144
The BIFs that convert strings to integers (for example
binary_to_integer/1) are now much faster for huge input strings. On a modern computer, even a string with more than a million decimal digits should finish in less than a second.The
divandremoperators are now also much faster for large operands.Own Id: OTP-20209
Related Id(s): PR-11074, PR-11324
Arithmetic operations on large integers will now increase the reduction count for the process, causing context switches to occur more frequently when doing arithmetic on large integers.
Own Id: OTP-20211
Related Id(s): PR-11274
inets-9.8
The inets-9.8 application can be applied independently of other applications on a full OTP 29 installation.
Improvements and New Features
OPTIONS is now accepted for HTTP/1.x requests and routed through the normal module pipeline like other standard methods. Requests that no module handles still receive a 501 (Not Implemented) response, so behavior is unchanged for deployments that do not add explicit OPTIONS handling.
Own Id: OTP-20249
Related Id(s): GH-11119, PR-11316
kernel-11.0.4
The kernel-11.0.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed incorrect TOS format when using
gen_udpwith thesocketbackend.Own Id: OTP-20131
Related Id(s): GH-10968, OTP-20102
Decoding of names in
inet_reshas been tightened to not allow names longer than 255 octets, as according to RFC 1035.Decoding has also been made more strict by only allowing compression pointers to lower positions in the message.
A few bugs when decoding malformed truncated DNS messages have also been fixed, as well as handling broken UTF-8 content in NAPTR RR:s regular expressions field.
Own Id: OTP-20228
Related Id(s): PR-11300
When using the
socketbackend ingen_tcp, the default value for theread_aheadoption was incorrect and has been corrected, according the documentation, to betrue.Own Id: OTP-20238
Related Id(s): PR-11284
A field in
net_kernel's internal state was not cleaned up in some cases for failed connections could cause the state to grow indefinitely over time. This has now been fixed.Own Id: OTP-20265
Related Id(s): GH-11308, PR-11388
Fixed
pg:which_groups/1to not include empty groups where all members have leaved. Bug existed since OTP 29.0.Own Id: OTP-20303
Related Id(s): GH-11360, PR-11361
mnesia-4.27
The mnesia-4.27 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed
mnesia:force_load_table/1getting stuck when the remote node becomes unreachable during table loading. When a network loader is aborted due to sender node going down and a user has forced a table load, we now retry loading from disc instead. Additionally, for disc_only_copies tables, the process actually loading the table is the dets server process, not the mnesia loader, so it would not receive the abort notification and would hang indefinitely. Now it correctly receives the notification and aborts table loading.Own Id: OTP-20256
Related Id(s): GH-11344, PR-11426
Fixed incorrect results from
mnesia:select_reverse/2,3onordered_settables inside a transaction that had already written to or deleted from the same table. Deleted records could reappear, updated records could appear twice, and the descending order was not preserved.Own Id: OTP-20364
Related Id(s): PR-11563
Improvements and New Features
The documentation of the
mnesiamodule now contains runnable examples for most functions. The examples are verified by the mnesia test suite, so they always match actual behavior.Own Id: OTP-20374
Related Id(s): PR-11216
odbc-2.17.1
The odbc-2.17.1 application can be applied independently of other applications on a full OTP 29 installation.
Improvements and New Features
Added the
max_long_column_sizeoption to limit buffer allocation size preventing memory exhaustion.Own Id: OTP-20328
Related Id(s): GH-9302, PR-10297
public_key-1.21.6
The public_key-1.21.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Added missing
no_cacerts_foundclauses so that the intended{failed_load_cacerts, no_cacerts_found}error is raised and formatted properly.Own Id: OTP-20318
Related Id(s): PR-11378
Align moduli and pubkey_moduli.hrl to state on OTP-28 and newer.
Own Id: OTP-20367
Related Id(s): PR-11574
Improvements and New Features
Worked around domain component using wrong ASN-1
PrintableStringencoding instead ofIA5Stringencoding.Own Id: OTP-20338
Related Id(s): GH-10879, PR-11226
ASN.1 files are now compiled sequentially to guarantee reproducible builds.
Own Id: OTP-20362
Related Id(s): GH-4417, PR-11396
runtime_tools-2.5
The runtime_tools-2.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed bug if a process that called
dbg:session/2exits beforedbg:session_destroy/1is called. An error report was logged and any trace messages lost and not delivered.Own Id: OTP-20218
Related Id(s): PR-11260
Improvements and New Features
A new
versionsmodule has been added to theruntime_toolsapplication containing functions for, e.g., comparing, versions that adhere to the OTP Versions Scheme.The documentation of the OTP Versions Scheme has also been improved.
Own Id: OTP-20352
Related Id(s): PR-11556, PR-11600
ssl-11.7.6
Note! The ssl-11.7.6 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Undecodable
certificate_authoritiesnames are now skipped, as they are just a hint.Own Id: OTP-20327
Related Id(s): GH-11338, PR-11356
Corrected generated keylog information generated from the
keylog_hsoption in the corner case that it was invoked after the client had reached its connection state, but the server closed the connection before it reached its connection state.Own Id: OTP-20358
Related Id(s): ERIERL-1356, PR-11570
Improvements and New Features
Added TLS-1.3
selected_grouptossl:connection_information/2.Own Id: OTP-20326
Related Id(s): PR-11440
The ECDHE-PSK Chacha20-Poly1305 cipher suites are now supported. This is relevant for TLS-1.2 (and lower).
Own Id: OTP-20331
Related Id(s): PR-11345
stdlib-8.1
The stdlib-8.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
When
beam_libreturns an error tuple, the filename in the information tuple is now a list of characters instead of an atom.Example:
The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the
beam_liberrors (not recommended) will need to be updated.Own Id: OTP-20118
Related Id(s): PR-11167
*** POTENTIAL INCOMPATIBILITY ***
The default seed in the
randmodule has been improved to spread out its entropy over all three seed words.This avoids identical first random numbers from two successive seeds on machines with low system time resolution.
Own Id: OTP-20158
Related Id(s): PR-11165
Fixed
unicode:characters_to_binary/2to handle incomplete utf-32 sequences without crashing.Also fixed a performance regression in
unicode:characters_to_nfkd_list/1.Own Id: OTP-20169
Related Id(s): PR-11130
The
arraymodule has been improved.array:slice/3now raisesbadargfor negative lengths.The performance of
array:mapfoldl/3andarray:sparse_mapfoldl/3has been improved.The documentation has been clarified regarding array growth/shrink behavior and how
concat/1,2handles mixed arrays.Own Id: OTP-20177
Related Id(s): PR-11159
Added more checks in the linter for badly formed
{Name,Arity}attributesOwn Id: OTP-20277
Related Id(s): GH-11397, PR-11422
Fixed return value of
zip:zip_get/2. When a file was extracted to a directory, the function returned a map instead of a file name.Own Id: OTP-20298
Related Id(s): PR-11313
When
compr_assignis enabled, the linter will correctly check for unbounded variables after block expressions in comprehensions.Own Id: OTP-20309
Related Id(s): GH-11406, PR-11567
When compiling a module with a triple-quoted string with escape sequences and a chunk boundary happened to fall just after an escape character, that character was not passed to the reentrancy continuation, so the scanner interpreted the following characters as not an escape sequence.
This bug has now been fixed.
Own Id: OTP-20320
Related Id(s): GH-11423, PR-11505
Fixed some errors in examples in the documentation for the
stringanduri_stringmodules.Own Id: OTP-20322
Related Id(s): PR-11446
Linter will emit better error messages when a behaviour attribute has a bad module name.
Own Id: OTP-20354
Related Id(s): GH-11401, PR-11552
Improvements and New Features
uri_string:parse/1now reports the actual offending character in error tuples instead of reporting a misleading cascade-failure position.Previously, when parsing a URI containing an invalid character (such as
|or non-ASCII characters likeö), the error tuple would point to the:character — the position where the parser's final backtracking attempt failed — rather than the character that actually violated the URI grammar. For example,uri_string:parse("http://localhost/A|B")returned{error,invalid_uri,":"}instead of the more helpful{error,invalid_uri,"|"}Own Id: OTP-20235
Related Id(s): GH-7862, PR-11129
Fixed a guard precedence bug in
uri_string:compose_query/2that caused inconsistent error handling depending on the encoding option.When
compose_query/2was called with invalid input (e.g. an atom instead of a string) and{encoding, unicode}, it would crash with** exception error: bad argumentinstead of returning the expected{error, invalid_input, Term}tuple. The same call with{encoding, utf8}correctly returned the error tuple. Both encoding options now consistently return{error, invalid_input, Term}for invalid input.Own Id: OTP-20236
Related Id(s): PR-11128
syntax_tools-4.1.1
The syntax_tools-4.1.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed exception when the epp_dodger AST contains macro-named record.
Own Id: OTP-20180
Related Id(s): GH-11155, PR-11203
Any caller who passed a single syntax tree that was not a form_list (e.g.
erl_recomment:recomment_forms(erl_syntax:atom(foo), Cs)or any expression/function tree) would get a hard crash instead of the documented result. This issue has been fixed.Own Id: OTP-20290
Related Id(s): PR-11442
tools-4.2.3
The tools-4.2.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The
tags.erlmodule is used to generateTAGSfiles for Emacs. There was a case where single quote items starting in position 0 would crash the scanner. This use case can potentially happen in docstrings, although not too common. This fix makes the scanner to handle such cases instead of crashing.Own Id: OTP-20293
Related Id(s): PR-11447
Updated the Emacs skeleton to reflect latest
format_statuscallback handling.Own Id: OTP-20339
Related Id(s): PR-11507
wx-2.7
The wx-2.7 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
A large set of correctness and robustness fixes were applied across the
wxapplication, addressing issues found by static analysis of both the Erlang and C/C++ sources.Own Id: OTP-20335
Related Id(s): PR-11530
Improvements and New Features
Removed configure checks that prevented cross compilation of wx. Note that cross compilation is not tested and may require manual configuration.
Own Id: OTP-20189
Related Id(s): PR-11137
Thanks to
Alois Vitasek, Anton Thomasson, ausimian, Bernhard M. Wiedemann, Cole Christensen, Dmitri Vereshchagin, Dmytro Lytovchenko, Eric Meadows-Jönsson, haoxian, Jianbo He, João Henrique Ferreira de Freitas, Johan Bevemyr, John Downey, Jonatan Männchen, Julian Doherty, kagetora66, k-patrik, Louis Pilfold, Lukasz Samson, Luke Bakken, Maria Scott, Mikael Pettersson, Paul Guyot, Renato Ceolin, ruslandoga, Scott Wiggins, Stanislav Yaglo, Thomas Arts, Thomas Cioppettini, Zeke Dou, zmstone
v29.0.6: OTP 29.0.6Compare Source
Check out the git tag OTP-29.0.6, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
compiler-10.0.4
The compiler-10.0.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
compiler: Fix bug in
beam_types:subtract/2for bitstringsOwn Id: OTP-20312
Related Id(s): [GH-11494], [PR-11503]
crypto-5.9.3
The crypto-5.9.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed type mismatch between
ErlNifUInt64anduint64_tin crypto NIF that caused incompatible-pointer warnings on macOS arm64 when passing DH parameters to OpenSSL.Own Id: OTP-20333
Related Id(s): [GH-11511], [PR-11513]
eldap-1.3.1
The eldap-1.3.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
eldap referral URL parsing now rejects a port component longer than 5 digits instead of attempting to convert an arbitrarily large digit string to an integer.
Own Id: OTP-20345
Related Id(s): [PR-11538]
erl_interface-5.8.2
The erl_interface-5.8.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
erl_interface: Fix buffer leak and state corruption on
ei_x_buffrealloc failureOwn Id: OTP-20324
Related Id(s): [PR-11492]
erts-17.0.6
The erts-17.0.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
No-suspend port command signals (i.e. port command signals sent using the
erlang:port_command/3BIF or theerlang:send/3BIF with thenosuspendoption) were not aborted properly in all scenarios which could leave the port queue in a busy state indefinitely. Also asynchronously sent no-suspend command signals (i.e, port command signals sent using theerlang:send/3BIF with thenosuspendoption) could sometimes be delivered even though the port was busy.Own Id: OTP-20135
Related Id(s): [GH-11052], [PR-11463]
erts: Fix missing exit_status caused by SIGCHLD race
Own Id: OTP-20274
Related Id(s): [GH-11278], [PR-11298]
erts: Fix bug in
is_in_rangeinstruction for x86 JITOwn Id: OTP-20278
Related Id(s): [GH-11419], [PR-11429]
Fixed bug in
binary_to_termthat could cause emulator crash for specific terms in specific process states (reductions left).Own Id: OTP-20281
Related Id(s): [GH-11404], [PR-11425]
erts: Fix crash with
term_to_iovec/2for large binaryOwn Id: OTP-20282
Related Id(s): [PR-11428]
A distributed
prioritysend larger than 32 KiB to a process alias caused the receiving runtime system to crash.Own Id: OTP-20286
Related Id(s): [GH-11416], [PR-11417]
Priority message queue markers were sometimes installed in the message queue even when no priority messages could be received. As a result, the two markers had to be traversed unnecessarily when scanning the message queue, introducing a small but avoidable overhead.
Own Id: OTP-20300
Related Id(s): [PR-11485]
A monitor of
time_offsetco-created with a process alias (monitor(time_offset, clock_service, [{alias, UnaliasOpt}])) either crashed the runtime system or did not work. This bug was introduced in OTP 25.0.Own Id: OTP-20319
Related Id(s): [PR-11509]
A process alias was erroneously created when a remote
spawn_request()operation with a{monitor, [{alias, explicit_unalias}]}option failed withnoconnectionreason.Own Id: OTP-20330
Related Id(s): [PR-11521]
A
gen_tcpsocket using the inet driver and{packet,4}had a bug if receiving a packet with size just below INT_MAX.That packet size wrapped in size calculations and made the received data overwrite its allocation and trash allocator metadata and subsequent block(s), causing the VM to crash.
This made it possible for anyone to remotely crash an Erlang node that used
{packet,4}on a reachable socket.This bug has been corrected.
Own Id: OTP-20334
Related Id(s): [PR-11533], [CVE-2026-75538]
inets-9.7.2
The inets-9.7.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The
detsandmnesiamod_authbackends used a key that did not include the directory path, so allrequire_user/require_grouprecords collapsed into one per-listener namespace. A user authorized for one protected directory could authenticate against any other protected directory served by the same listener.{path, Directory}is now included in the auth backend key, scoping records per directory as documented.Own Id: OTP-20264
Related Id(s): [PR-11546]
Requests specifying both
Transfer-EncodingandContent-Lengthheaders are now rejected with400 Bad Request, per RFC 9112 Section 6.3. Previously such requests could be used for CL.TE request-smuggling/desync attacks against reverse proxies in front ofhttpd.Own Id: OTP-20268
Related Id(s): [PR-11547]
httpdaccepted the obsolete header line-folding syntax (RFC 9112 Section 5.2, a continuation line beginning with space/tab), silently treating the folded continuation as a separate header. This allowed CL.TE-style request smuggling whenhttpdwas placed behind a folding-aware proxy. Such requests are now rejected with400 Bad Request.Own Id: OTP-20269
Related Id(s): [PR-11544]
A header such as
Content-Length : 6(whitespace before the colon) was previously silently dropped, causing the content length to default to 0 and the body bytes to be misinterpreted as a pipelined request (CL.0 smuggling). Per RFC 7230 Section 3.2.4, such headers are now rejected with400 Bad Request.Own Id: OTP-20270
Related Id(s): [PR-11545]
A new httpd option
request_timeout(default 60 seconds, renamed from the interimmax_body_read_timeout) bounds the idle time between reads of a request body/message. The server now also sends408 Request Timeoutwhen themin_bytes_per_secondfloor is hit, andkeep_alive_timeoutmeasurement was corrected so the timer is cancelled as soon as new data arrives rather than only after full header parsing;keep_alive_timeoutandrequest_timeoutnow also acceptinfinityto disable the timeout.Own Id: OTP-20271
Related Id(s): [PR-11543]
mod_auth,mod_security, andmod_getcompared resolved filesystem paths against configured protected-directory patterns without normalizing repeated slashes or filesystem case. On case-insensitive filesystems (macOS, Windows) or with repeated slashes, a request could resolve to a protected resource while evading the directory match. Paths are now canonicalized (slash-collapsed, and case-normalized when the filesystem is case-insensitive) before the authorization decision.Own Id: OTP-20279
Related Id(s): [PR-11542]
A request with an invalid chunked transfer-encoding chunk size previously caused the httpd connection handler to hang indefinitely without requiring further input from the client. This leaked a process per request and could be used to exhaust server resources (denial of service). Invalid chunk sizes are now rejected immediately with an error response, and the connection is closed.
Own Id: OTP-20306
Related Id(s): [PR-11539]
max_body_sizewas previously enforced only after a complete chunk had been received, allowing a single oversized chunk to be buffered in full before the limit was checked — undermining the memory-exhaustion protection the option is meant to provide. The limit is now enforced incrementally as chunk data arrives, rejecting the request as soon as the configured size is exceeded.Own Id: OTP-20307
Related Id(s): [PR-11540]
The documented default of 150 for the
max_clientsoption was not applied by the implementation, allowing an unbounded number of concurrent clients to connect regardless of configuration. The default is now correctly enforced.Own Id: OTP-20308
Related Id(s): [PR-11541]
Fixed a bug where httpd failed to start when configured with {socket_type, {ip_comm, SockOpts}} and a fixed (non-zero) port.
Own Id: OTP-20342
Related Id(s): [PR-11548]
httpcnow enforces a limit on the total size of response headers and response body, preventing unbounded memory allocation when connecting to a malicious or malfunctioning server. The new max_header_size and max_body_size request options can be used to override the default limit (10240 bytes for headers). Additionally, httpc now validates that the Content-Length header contains only digits before use, avoiding a crash on malformed responses.Own Id: OTP-20343
Related Id(s): [PR-11538]
megaco-4.9.2
The megaco-4.9.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Numeric fields in megaco text-encoded messages are now validated for digit-string length before integer conversion, improving robustness of the text decoder. Per-field digit limits based on the H.248.1 ASN.1 type constraints are enforced (e.g., 10 digits for UINT32, 2 digits for timer values), along with a 100 KB overall message size cap at the scanner entry point. The binary (BER/PER) codec is not affected.
Own Id: OTP-20234
Related Id(s): [PR-11325]
mnesia-4.26.2
The mnesia-4.26.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
A transaction iterating a table (first/1, last/1, next/2, prev/2, select, select_reverse on non-ordered_set) leaked a safe_fixtable hold when the coordinator was killed by an external signal. The table remained fixed for the lifetime of the node, preventing space reclamation of deleted objects.
Own Id: OTP-20347
Related Id(s): [PR-11517]
Fixed a race condition where mnesia_controller could crash if a table was deleted while
mnesia:set_master_nodes/2was being processed.Own Id: OTP-20351
Related Id(s): [PR-11554]
public_key-1.21.5
The public_key-1.21.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Retain lost CommonName length relaxation.
Own Id: OTP-20321
Related Id(s): [GH-11240], [PR-11358]
snmp-5.20.5
The snmp-5.20.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The SNMP PDU decoder now bounds the byte length accepted for INTEGER, Counter32, Gauge32/Unsigned32, TimeTicks, and Counter64 values during decoding (4, 5, 5, 5, and 9 bytes respectively, matching the SMIv2 value ranges), instead of accepting an arbitrarily large byte string and converting it to an integer.
Own Id: OTP-20346
Related Id(s): [PR-11538]
ssh-6.0.5
The ssh-6.0.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a bug where multiple subsystem requests could succeed on same ssh channel which is forbidden by RFC 4254 §6.5
Own Id: OTP-20284
Related Id(s): [PR-11437]
ssl-11.7.5
Note! The ssl-11.7.5 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Debugging keylog_hs callback used for logging handshake secrets on failed connections swapped the argument order in logging function confusing server and client side. The bug was introduced in OTP 28.5
Own Id: OTP-20350
Related Id(s): ERIERL-1354, [PR-11553]
Improvements and New Features
Hardening improvements of the ssl application.
TLS distribution now defaults to TLS-1.3 instead of TLS-1.2 (TLS-1.2 is kept as fallback for rolling upgrades).
TLS-1.2 server with {verify, verify_peer} now defaults reuse_sessions to false to mitigate the Triple Handshake attack (RFC 7627). Set {reuse_sessions, true} explicitly to restore previous behavior.
Various missing or faulty sanity checks added and TLS alerts adjusted to comply with RFC MUST requirements, including: signature algorithm validation for intermediate certificates, TLS-1.3 session_id echo, pre_shared_key extension ordering, and renegotiation_info enforcement.
Hardened and improved CRL support. Introduces new option allowed_hosts for the optional CRL HTTP fetching feature to restrict which hosts may be contacted. Internal/loopback IPs are now blocked by default (SSRF protection).
TLS-1.3 client ticket handling is more robust (locked tickets are released on client crash). Server TLS-1.3 ticket handling and anti-replay Bloom filter performance are optimized.
DTLS duplicate ChangeCipherSpec handling simplified, fixing potential state machine confusion (GH-11075).
Process state formatting no longer leaks secrets in crash logs.
Own Id: OTP-20289
Related Id(s): [PR-11478]
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.