You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Part of the coordinated 26.7.1 release train (autobahn -> zlmdb -> crossbar)
Release Autobahn|Python 26.7.1
Why
Cut the 26.7.1 stable release. Master carries the completed WebSocket/RawSocket
payload size-limit security epic (#1907) plus the musllinux wheel track, none
of which has reached users yet — the tree is at 26.7.1.dev1.
The musllinux work in particular is merged but unpublished: the user who
asked for Alpine wheels (#1877) gets nothing until this release ships.
FlatBuffers: version() reliable on installed wheels (#1891).
Steps
Branch fix_<issue-number> off master.
just prep-release — finalises 26.7.1.dev1 -> 26.7.1 (pyproject + _version.py).
Do not hand-edit the version. (autobahn does not track uv.lock, so no relock.)
Follow-up PR: just bump-dev to reopen the dev cycle.
Gotchas
softprops@v2 finalize can break the release via the discussion category
("valid category name"); workaround = lowercase category + re-run, durable fix =
SHA-pin. Re-running a release reuses the OLD workflow file.
Part of the coordinated 26.7.1 release train (autobahn -> zlmdb -> crossbar)
Release Autobahn|Python 26.7.1
Why
Cut the 26.7.1 stable release. Master carries the completed WebSocket/RawSocket
payload size-limit security epic (#1907) plus the musllinux wheel track, none
of which has reached users yet — the tree is at
26.7.1.dev1.The musllinux work in particular is merged but unpublished: the user who
asked for Alpine wheels (#1877) gets nothing until this release ships.
What's in it
Security (epic #1907, advisory GHSA-hxp9-w8x3-p566):
max_message_sizecap silently truncates and corrupts messages (missingunconsumed_taildrain) #1908 — permessage-deflatemax_message_sizecap silently truncated anover-limit message and raised a zlib error instead of rejecting it cleanly.
maxMessagePayloadSizeis enforced against compressed size, bypassed after permessage-deflate inflation #1909 —maxMessagePayloadSizewas enforced against the compressed wirelength, so a small compressed frame could inflate past the limit and reach the
application (decompression-bomb DoS; same class as CVE-2016-10544). Now enforced
against the uncompressed reassembled size, failing with close code 1009.
Behaviour change: such messages are now rejected where they previously passed.
max_output_len), sosnappy/bzip2/brotli reach parity with deflate and a frame no longer inflates
unbounded into memory before the size check.
setProtocolOptions), unlike the Twisted backend #1911 — asyncio RawSocket receive limit made configurable(
setProtocolOptions(maxMessagePayloadSize=...)), at parity with Twisted.Wheels / build: musllinux (Alpine/musl) CPython wheels (#1877), aarch64 cp314
GIL-ABI fix (#1875),
.cicdABI-tag matching (wamp-cicd #11), ruff ANN/UP/TCHgate (#1840), CalVer version recipes (#1894).
FlatBuffers:
version()reliable on installed wheels (#1891).Steps
fix_<issue-number>off master.just prep-release— finalises26.7.1.dev1->26.7.1(pyproject +_version.py).Do not hand-edit the version. (autobahn does not track
uv.lock, so no relock.)docs/changelog.rst26.7.1 section is complete and accurate (it alreadycarries the Security section for [BUG] permessage-deflate
max_message_sizecap silently truncates and corrupts messages (missingunconsumed_taildrain) #1908/[BUG] WebSocketmaxMessagePayloadSizeis enforced against compressed size, bypassed after permessage-deflate inflation #1909/[BUG] Backend-agnostic bounded decompression for permessage-compress (snappy / bzip2 / brotli parity with deflate) #1910/[BUG] asyncio RawSocket receive size limit is hardcoded to 16 MB (nosetProtocolOptions), unlike the Twisted backend #1911).v26.7.1, push tag -> release workflow runs -> approve themanual
pypienvironment gate -> published to PyPI.x86_64 + aarch64) + PyPy + sdist. The
check-release-filesetgate enforces this.just bump-devto reopen the dev cycle.Gotchas
softprops@v2finalize can break the release via the discussion category("valid category name"); workaround = lowercase category + re-run, durable fix =
SHA-pin. Re-running a release reuses the OLD workflow file.
Alpine images; no official PyPA musllinux PyPy image).
Blocks / blocked by
autobahn>=26.7.1+ relocks).reply; CVE requested but not yet assigned).
This work is being completed with AI assistance (Claude Code).