cloudflare/pingora
 Watch   
 Star   
 Fork   
22 days ago
pingora

Pingora 0.9.0

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

  • Allow sharing backends across load-balancing selectors.
  • Add graceful-upgrade signalling between old and new processes.
  • Add per-listener L4 buffer configuration and socket send/receive buffer settings.
  • Add Tokio blocking-pool configuration, poll-time histograms, and an alternative timer runtime knob.
  • Allow proxy services to override runtime options.
  • Add a working-directory option for daemon mode.
  • Enable adding user context between sessions on the same connection with HttpPersistentSettings.
  • Add socket-cookie access and TCP/TLS establishment timing fields.
  • Make HTTP/2 stream and connection windows configurable.

🚀 Features — Caching (alpha)

  • Add deferred cache-admission policy hooks.
  • Implement DCZ dictionary compression and vary on available-dictionary.
  • Add CacheMeta freshness updates and expiration-at-time support.
  • Support optionally flooring fractional delta-seconds for RFC 9111 handling.
  • Preserve Vary provenance across stale refreshes.
  • Make cache-lock retries configurable and bounded.
  • Add an opt-in purge mode that expires an asset while retaining its body for conditional revalidation and stale serving.
  • Use power-of-two selection for eviction balancing.
  • Add peek_lru, update_or_admit, and non-promoting set_weight operations in lru.
  • Allow adjusting LRU weight limits and reserving capacity.

🔒 Security & Hardening

  • HTTP ambiguity hardening: centralize raw request-target classification so path and authority validation share one parser; reject ambiguous request authorities on ingress and egress; reject forbidden CR/LF bytes in HTTP/2 :path; and reject delimiter bytes in request lines as defense in depth.
  • Sanitize hop-by-hop upstream request headers.
  • Preserve non-origin-form request targets without mangling the URI.
  • Normalize forwarded responses with obsolete HTTP/1.1 response-header line folding.
  • Bound default HTTP/2 server limits to reduce memory-exhaustion exposure.
  • Avoid a process abort while appending oversized header maps by returning an InvalidHTTPHeader error.
  • Fix some unchecked integer conversions.
  • Explicitly prevent reuse of HTTP/1 connections after incomplete responses.
  • Update Prometheus for a security advisory.
  • Replaced unmaintained daemonize crate with daemonix and updated nix to 0.31.x.

🐛 Bug Fixes

  • Fix connection-pool and PoolNode race windows and remove empty entries.
  • Fixed a potential stall on HTTP/1 response-header reads upon forwarding request bodies via a cancel safety fix.
  • Stop waiting on HTTP/2 upstream work after the downstream ends and close timed-out HTTP/2 connections.
  • Drain in-flight HTTP/2 streams during shutdown and retry stream creation on a fresh connection when appropriate.
  • Prevent HTTP/1 upstream reuse after failed writes or incomplete responses.
  • Discard retry buffers after truncation and avoid unnecessary HTTP/2 accept allocations.
  • Skip h2c preface detection on TLS streams.
  • Do not initialize a body reader for HEAD informational responses.
  • Correct HTTP/1 session body-byte accounting.
  • Fix listener-fd inheritance and close transfer sockets during graceful upgrade; mark received listener fds close-on-exec.
  • Remove the duplicate graceful-shutdown sleep and improve load-balancer shutdown responsiveness.
  • Shard proxy shutdown notifications to reduce lock contention and close a lost-wakeup race during graceful shutdown.

⚙️ Miscellaneous

  • pingora-timeout now uses Tokio timeouts for (configurably) long intervals to avoid memory accumulation.
  • Split pingora-prometheus into a separate crate.
  • Forward WriteBuf::chunks_vectored to the wrapped buffer.
  • Replace custom ASCII-trimming helpers with stabilized standard-library methods.
  • Update the MSRV lane and use cargo check for MSRV validation.
  • Improve documentation examples for connection tracing and basic setup.
  • Preserve bound ports in digests after TLS failures.
  • Return an error for divergent multipart cache progress and remove a panic from maybe_cache_meta.
  • Various flaky test fixes.
2026-06-05 03:28:02
pingora

Pingora 0.8.1

0.8.1 - 2026-06-04

🔒 Security

  • Bound default HTTP/2 server limits to mitigate memory exhaustion.
  • Upgrade Rustls-related dev-dependencies to address rustls-webpki security advisories.

⚙️ Miscellaneous Tasks

  • Pin tracing dependencies to preserve Rust 1.84 compatibility.
  • Use cargo check for MSRV verification instead of compiling dev-dependencies during tests.
  • Update the Semgrep OSS scanning workflow.
  • Use valid paths in header serialization tests.
  • Gate HTTP/1 CONNECT tests on patched HTTP/1 support.
2026-03-03 05:36:52
pingora

Pingora 0.8.0

0.8.0 - 2026-03-02

🚀 Features

  • Add support for client certificate verification in mTLS configuration.
  • Add upstream_write_pending_time to Session for upload diagnostics.
  • Pipe subrequests utility: creates a state machine to treat subrequests as a "pipe," enabling direct sending of request body and writing of response tasks, with a handler for error propagation and support for reusing a preset or captured input body for chained subrequests.
  • Add the ability to limit the number of times a downstream connection can be reused
  • Add a system for specifying and using service-level dependencies
  • Add a builder for pingora proxy service, e.g. to specify ServerOptions.

🐛 Bug Fixes

  • Fix various Windows compiler issues.
  • Handle custom ALPNs in s2n impl of ALPN::to_wire_protocols() to fix s2n compile issues.
  • Fix: don't use “all” permissions for socket.
  • Fix a bug with the ketama load balancing where configurations were not persisted after updates.
  • Ensure http1 downstream session is not reused on more body bytes than expected.
  • Send RST_STREAM CANCEL on application read timeouts for h2 client.
  • Start close-delimited body mode after 101 is received for WebSocket upgrades. UpgradedBody is now an explicit HttpTask.
  • Avoid close delimit mode on http/1.0 req.
  • Reject invalid content-length http/1 requests to eliminate ambiguous request framing.
  • Validate invalid content-length on http/1 resp by default, and removes content-length from the response if transfer-encoding is present, per RFC.
  • Correct the custom protocol code for shutdown: changed the numeric code passed on shutdown to 0 to indicate an explicit shutdown rather than a transport error.

⚙️ Miscellaneous Tasks

  • Remove CacheKey::default impl, users of caching should implement cache_key_callback themselves
  • Allow server bootstrapping to take place in the context of services with dependents and dependencies
  • Don't consider "bytes=" a valid range header: added an early check for an empty/whitespace-only range-set after the bytes= prefix, returning 416 Range Not Satisfiable, consistent with RFC 9110 14.1.2.
  • Strip {content, transfer}-encoding from 416s to mirror the behavior for 304 Not Modified responses.
  • Disable CONNECT method proxying by default, with an option to enable via server options; unsupported requests will now be automatically rejected.
2026-01-31 05:14:48
pingora

Pingora 0.7.0

0.7.0 - 2026-01-30

Highlights

  • Extensible SslDigest to save user-defined TLS context
  • Add ConnectionFilter trait for early TCP connection filtering

🚀 Features

  • Add ConnectionFilter trait for early TCP connection filtering
  • Introduce a virtual L4 stream abstraction
  • Add support for verify_cert and verify_hostname using rustls
  • Exposes the HttpProxy struct to allow external crates to customize the proxy logic.
  • Exposes a new_mtls method for creating a HttpProxy with a client_cert_key to enable mtls peers.
  • Add SSLKEYLOGFILE support to rustls connector
  • Allow spawning background subrequests from main session
  • Allow Extensions in cache LockCore and user tracing
  • Add body-bytes tracking across H1/H2 and proxy metrics
  • Allow setting max_weight on MissFinishType::Appended
  • Allow adding SslDigestExtensions on downstream and upstream
  • Add Custom session support for encapsulated HTTP

🐛 Bug Fixes

  • Use write timeout consistently for h2 body writes
  • Prevent downstream error prior to header from canceling cache fill
  • Fix debug log and new tests
  • Fix size calculation for buffer capacity
  • Fix cache admission on header only misses
  • Fix duplicate zero-size chunk on cache hit
  • Fix chunked trailer end parsing
  • Lock age timeouts cause lock reacquisition
  • Fix transfer fd compile error for non linux os

Sec

  • Removed atty
  • Upgrade lru to >= 0.16.3 crate version because of RUSTSEC-2026-0002

Everything Else

  • Add tracing to log reason for not caching an asset on cache put
  • Evict when asset count exceeds optional watermark
  • Remove trailing comma from Display for HttpPeer
  • Make ProxyHTTP::upstream_response_body_filter return an optional duration for rate limiting
  • Restore daemonize STDOUT/STDERR when error log file is not specified
  • Log task info when upstream header failed to send
  • Check cache enablement to determine cache fill
  • Update meta when revalidating before lock release
  • Add ForceFresh status to cache hit filter
  • Pass stale status to cache lock
  • Bump max multipart ranges to 200
  • Downgrade Expires header warn to debug log
  • CI and effective msrv bump to 1.83
  • Add default noop custom param to client Session
  • Use static str in ErrorSource or ErrorType as_str
  • Use bstr for formatting byte strings
  • Tweak the implementation of and documentation of connection_filter feature
  • Set h1.1 when proxying cacheable responses
  • Add or remove accept-ranges on range header filter
  • Update msrv in github ci, fixup .bleep
  • Override request keepalive on process shutdown
  • Add shutdown flag to proxy session
  • Add ResponseHeader in pingora_http crate's prelude
  • Add a configurable upgrade for pingora-ketama that reduces runtime cpu and memory
  • Add to cache api spans
  • Increase visibility of multirange items
  • Use seek_multipart on body readers
  • Log read error when reading trailers end
  • Re-add the warning about cache-api volatility
  • Default to close on downstream response before body finish
  • Ensure idle_timeout is polled even if idle_timeout is unset so notify events are registered for h2 idle pool, filter out closed connections when retrieving from h2 in use pool.
  • Add simple read test for invalid extra char in header end
  • Allow customizing lock status on Custom NoCacheReasons
  • Close h1 conn by default if req header unfinished
  • Add configurable retries for upgrade sock connect/accept
  • Deflake test by increasing write size
  • Make the version restrictions on rmp and rmp-serde more strict to prevent forcing consumers to use 2024 edition
  • Rewind preread bytes when parsing next H1 response
  • Add epoch and epoch_override to CacheMeta
2025-08-16 04:35:33
pingora

Pingora 0.6.0

0.6.0 - 2025-08-15

Highlights

  • This release bumps the minimum h2 crate dependency to guard against the MadeYouReset H2 attack

🚀 Features

  • Log runtime names during Server shutdown
  • Enabling tracking the execution phase of a server
  • Allow using in-memory compression dicts
  • Make H2Options configurable at HttpServer, HttpProxy Also adds HttpServerOptions to the HttpServer implementation, and updates the HttpEchoApp to use HttpServer for easier adhoc testing.

🐛 Bug Fixes

  • Fix: read body without discard

Everything Else

  • Try loading each LRU shard individually and warn on errors
  • Update LRU save to disk to be atomic
  • Allow cache to spawn_async_purge
  • Pass hit handler in hit filter
  • Cache hit filter can mutate cache, allow resetting cache lock
  • Persist keepalive_timeout between requests on same stream
  • Properly check for H2 io ReadError retry types
  • Add cache lock wait timeout for readers
  • Fix CacheLock status timeout conditions
  • Handle close on partial chunk head
  • Allow optional to reset session timeouts
  • Clippy fixes for 1.87, add 1.87 to GitHub CI
  • Run range_{header,body}_filter after disabling cache
  • Convert InterpretCacheControl members to Duration
  • Disable downstream ranging on max file size
  • Allow explicit infinite keepalive timeout to be respected Note that a necessary follow up is to refactor the infinite keepalive timeout to only apply to first read between requests on reused conns.
  • Add method to disable keepalive if downstream is unfinished
  • Discard extra upstream body and disable keepalive
  • Explicitly disable keepalive on upstream connection when excess body (content-length) is detected.
  • Add brief sleep to shutdown signal tests to avoid flake
  • Allow override of cache lock timeouts
  • Allow arbitrary bytes in CacheKey instead of just Strings
  • Corrects out-of-order data return after multiple peek calls with different buffer sizes.
  • Mark previously too large chunked assets as cacheable
  • Boring/OpenSSL load cert chain from connector options
  • Add initial support for multipart range requests
  • Adds a callback to HttpHealthCheck for collecting detailed backend summary information
  • Multipart range filter state fixes

Docs

  • Explanation of request_body_filter phase
2025-05-10 05:49:43
pingora

Pingora 0.5.0

0.5.0 - 2025-05-09

🚀 Features

🐛 Bug Fixes

Everything Else

2024-07-13 02:24:29
pingora

Pingora 0.3.0

0.3.0 - 2024-07-12

🚀 Features

  • Add support for HTTP modules. This feature allows users to import modules written by 3rd parties.
  • Add request_body_filter. Now request body can be inspected and modified.
  • Add H2c support.
  • Add TCP fast open support.
  • Add support for server side TCP keep-alive.
  • Add support to get TCP_INFO.
  • Add support to set DSCP.
  • Add or_err()/or_err_with API to convert Options to pingora::Error.
  • Add or_fail() API to convert impl std::error::Error to pingora::Error.
  • Add the API to track socket read and write pending time.
  • Compression: allow setting level per algorithm.

🐛 Bug Fixes

  • Fixed a panic when using multiple H2 streams in the same H2 connection to upstreams.
  • Pingora now respects the Connection header it sends to upstream.
  • Accept-Ranges header is now removed when response is compressed.
  • Fix ipv6_only socket flag.
  • A new H2 connection is opened now if the existing connection returns GOAWAY with graceful shutdown error.
  • Fix a FD mismatch error when 0.0.0.0 is used as the upstream IP

⚙️ Changes and Miscellaneous Tasks

  • Dependency: replace structopt with clap
  • Rework the API of HTTP modules
  • Optimize remove_header() API call
  • UDS parsing now requires the path to have unix: prefix. The support for the path without prefix is deprecated and will be removed on the next release.
  • Other minor API changes
2024-04-06 03:53:35
pingora

Pingora 0.1.1

0.1.1 - 2024-04-05

🚀 Features

  • Server::new now accepts Into<Option<T>>
  • Implemented client HttpSession::get_keepalive_values for Keep-Alive parsing
  • Expose ListenFds and Fds to fix a voldemort types issue
  • Expose config options in ServerConf, provide new Server constructor
  • upstream_response_filter now runs on upstream 304 responses during cache revalidation
  • Added server_addr and client_addr APIs to Session
  • Allow body modification in response_body_filter
  • Allow configuring grace period and graceful shutdown timeout
  • Added TinyUFO sharded skip list storage option

🐛 Bug Fixes

  • Fixed build failures with the boringssl feature
  • Fixed compile warnings with nightly Rust
  • Fixed an issue where Upgrade request bodies might not be handled correctly
  • Fix compilation to only include openssl or boringssl rather than both
  • Fix OS read errors so they are reported as ReadError rather than ReadTimeout when reading http/1.1 response headers

⚙️ Miscellaneous Tasks

  • Performance improvements in pingora-ketama
  • Added more TinyUFO benchmarks
  • Added tests for pingora-cache purge
  • Limit buffer size for InvalidHTTPHeader error logs
  • Example code: improvements in pingora client, new LB cluster example
  • Typo fixes and clarifications across comments and docs
2024-04-06 02:26:47
pingora

Pingora 0.1.0

Highlights

  • First Public Release of Pingora 🎉