Update dependency erlang to v29 #13
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/erlang-29.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
28.4.3→29.1.1Release Notes
erlang/otp (erlang)
v29.1.1: OTP 29.1.1Compare Source
Check out the git tag OTP-29.1.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
POTENTIAL INCOMPATIBILITIES
Fixed a vulnerability where the
max_channelsdaemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit.The default value of the max_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting
{max_channels, infinity}.The default value of the max_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting
{max_sessions, infinity}.Own Id: OTP-20287
Application(s): ssh
Related Id(s): GH-SA-qhcm-px9c-rvfh, PR-11523, CVE-2026-68956
asn1-5.5.2
The asn1-5.5.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a denial-of-service attack in asn1, where abnormally large OID components (arcs) could cause resource exhaustion.
Own Id: OTP-20272
Related Id(s): PR-11655, CVE-2026-65634
The JER backend will no longer break certain values (true, false, null) when they are typed as ENUMERATED, they will now be encoded as strings as required by the standard.
Own Id: OTP-20355
Related Id(s): ERIERL-1355, PR-11559
compiler-10.0.6
The compiler-10.0.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Certain uses of funs could crash the compiler. For example:
This has been corrected.
Own Id: OTP-20386
Related Id(s): GH-11619, PR-11638
public_key-1.21.7
The public_key-1.21.7 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Handle that policy qualifiers are optional.
Own Id: OTP-20393
Related Id(s): PR-11630
ssh-6.0.6
The ssh-6.0.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a vulnerability where the
max_channelsdaemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit.The default value of the max_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting
{max_channels, infinity}.The default value of the max_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting
{max_sessions, infinity}.Own Id: OTP-20287
Related Id(s): GH-SA-qhcm-px9c-rvfh, PR-11523, CVE-2026-68956
*** POTENTIAL INCOMPATIBILITY ***
The SSH daemon no longer rejects a
subsystemrequest that is preceded byenvorpty-reqrequest on the same channel.Own Id: OTP-20371
Related Id(s): ERIERL-1363, GH-11586, PR-11616
ssl-11.7.7
Note! The ssl-11.7.7 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Reject unsolicited TLS-1.3 pre_shared_key in client.
Own Id: OTP-20388
Related Id(s): PR-11641, CVE-2026-89422
Security and robustness hardening returning RFC mandated alert reasons, narrowing/correcting length checks.
Correct signature algorithm handling that slightly mixed up signature algorithms and signature algorithms cert in TLS-1.2.
Add missing TLS-1.3 Brainpool groups support. (Not relevant in 27 patch)
Enhanced/corrected documentation and spec errors/deviations.
Own Id: OTP-20390
Related Id(s): PR-11651
Thanks to
Alan Duffield
v29.1: OTP 29.1Compare Source
Check out the git tag OTP-29.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
POTENTIAL INCOMPATIBILITIES
When
beam_libreturns an error tuple, the filename in the information tuple is now a list of characters instead of an atom.Example:
The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the
beam_liberrors (not recommended) will need to be updated.Own Id: OTP-20118
Application(s): stdlib
Related Id(s): PR-11167
OTP-29.1
Improvements and New Features
A new
versionsmodule has been added to theruntime_toolsapplication containing functions for, e.g., comparing, versions that adhere to the OTP Versions Scheme.The documentation of the OTP Versions Scheme has also been improved.
Own Id: OTP-20352
Related Id(s): PR-11556, PR-11600
asn1-5.5.1
The asn1-5.5.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The modern representation of BITSTRINGs is now always supported for encoding, regardless of any legacy options given. The JER backend would not support the modern representation when any legacy option was given.
Own Id: OTP-20145
Related Id(s): PR-11097
The
make cleancommand did not remove all generated.erlfiles.Own Id: OTP-20295
Related Id(s): PR-11375
common_test-1.31.2
The common_test-1.31.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The internal
cte_trackevent handler now correctly displays the suite name for suites without aninit_per_suite/1callback.Own Id: OTP-20316
Related Id(s): PR-11501
compiler-10.0.5
The compiler-10.0.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a native record crash in the
sys_core_foldcompiler pass.Own Id: OTP-20254
Related Id(s): GH-11351, PR-11359
The compiler could crash when compiling a map comprehension.
Own Id: OTP-20255
Related Id(s): GH-11352, PR-11363
Fixed a crash when the key pattern in a map comprehension was a bitstring.
Own Id: OTP-20262
Related Id(s): GH-11367, PR-11379
Fixed an issue that could crash the compiler when compiling comprehensions with the
compr_assignfeature enabled.Own Id: OTP-20267
Related Id(s): GH-11366, PR-11390
Code that called
erlang:0()inside a fun could crash the compiler.Own Id: OTP-20280
Related Id(s): GH-11414, PR-11424
Fixed an internal error when
lists:keyfind/3is called with an argument that exceeds system limits.Own Id: OTP-20291
Related Id(s): GH-11413, PR-11444
An incorrect
useless_buildingwarning has been eliminated.Own Id: OTP-20304
Related Id(s): GH-11472, PR-11477
In rare circumstances, the type analysis pass of the compiler could run for many minutes.
Own Id: OTP-20365
Related Id(s): GH-11534, PR-11566
crypto-5.10
The crypto-5.10 application can be applied independently of other applications on a full OTP 29 installation.
Improvements and New Features
The documentation of the
cryptomodule now contains runnable examples for most functions. The examples are verified by the crypto test suite, so they always match actual behavior.Own Id: OTP-20373
Related Id(s): PR-11170
dialyzer-6.0.3
The dialyzer-6.0.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed Dialyzer crash when overriding built-in types.
Own Id: OTP-19631
Related Id(s): GH-11093, PR-11096
Typer crashed when multiple functions were written in the same line. For example:
Own Id: OTP-20297
Related Id(s): PR-11466
erts-17.1
The erts-17.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed bug in
ets:member/2forset,bagandduplicate_bag. The bug could (maybe) lead toets:memberspuriously returning false for a value which is actually a member for a table that faces high insert load.Own Id: OTP-20152
Related Id(s): PR-11115
Fixed crashing bug caused by race between timer creating process and suspending receiver of the timer. Only seen to cause crash one time by extremely provoking test case. Bug exists only since OTP 29.0.
Own Id: OTP-20175
Related Id(s): PR-11196
Fixed bug in
enif_realloc_binarywhen called with a read-only binary. Instead of returning false at out-of-memory failure, it returned true and did nothing.Own Id: OTP-20187
Related Id(s): PR-11133
Fixed alternate signal stack sizing on musl (Alpine) running on CPUs whose Linux kernel reports large signal frames (AVX-512/AMX). It caused emulator to abort during startup with "Failed to set alternate signal stack".
Own Id: OTP-20213
Related Id(s): GH-11248, PR-11249
For
socket:recvmmsg/6, the buffer length was not handled correctly when the OS network stack truncated the received message, so garbage data with incorrect length could be delivered to the calling process. This bug has been corrected.Own Id: OTP-20246
Related Id(s): PR-11335
binary_to_term/1will now reject an external native record with duplicated fields.Own Id: OTP-20276
Related Id(s): GH-11398, PR-11410
Fixed a crash upon starting the emulator on systems with a very large minimum signal stack size.
Own Id: OTP-20292
Related Id(s): GH-11349, PR-11376
Fixed lock order violation during crash dump due to export table exhaustion. Only problem for debug emulator.
Own Id: OTP-20305
Related Id(s): PR-11460
Fixed rounding errors when converting large integers to floating point numbers, explicitly with
float/1or implicitly in arithmetic such as1.0 * N. Integers with absolute values larger than 64 bits that could not be represented exactly as a float could be rounded to the second nearest float instead of the nearest. For example,float(428654966685883400000)returned4.2865496668588343e20instead of the correct4.286549666858834e20, which is whatbinary_to_float/1returns for the same number.Own Id: OTP-20317
Related Id(s): PR-11391
An error check in
prim_inethas been fixed. This manifested itself asfile:sendfile/*sometimes crashing instead of returning an error when the remote end closes the socket during initialization.Own Id: OTP-20356
Related Id(s): PR-11438
Improvements and New Features
Fairness of code permission locks have been improved to avoid long latencies for code loading and trace operations.
Own Id: OTP-20188
Related Id(s): PR-11144
The BIFs that convert strings to integers (for example
binary_to_integer/1) are now much faster for huge input strings. On a modern computer, even a string with more than a million decimal digits should finish in less than a second.The
divandremoperators are now also much faster for large operands.Own Id: OTP-20209
Related Id(s): PR-11074, PR-11324
Arithmetic operations on large integers will now increase the reduction count for the process, causing context switches to occur more frequently when doing arithmetic on large integers.
Own Id: OTP-20211
Related Id(s): PR-11274
inets-9.8
The inets-9.8 application can be applied independently of other applications on a full OTP 29 installation.
Improvements and New Features
OPTIONS is now accepted for HTTP/1.x requests and routed through the normal module pipeline like other standard methods. Requests that no module handles still receive a 501 (Not Implemented) response, so behavior is unchanged for deployments that do not add explicit OPTIONS handling.
Own Id: OTP-20249
Related Id(s): GH-11119, PR-11316
kernel-11.0.4
The kernel-11.0.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed incorrect TOS format when using
gen_udpwith thesocketbackend.Own Id: OTP-20131
Related Id(s): GH-10968, OTP-20102
Decoding of names in
inet_reshas been tightened to not allow names longer than 255 octets, as according to RFC 1035.Decoding has also been made more strict by only allowing compression pointers to lower positions in the message.
A few bugs when decoding malformed truncated DNS messages have also been fixed, as well as handling broken UTF-8 content in NAPTR RR:s regular expressions field.
Own Id: OTP-20228
Related Id(s): PR-11300
When using the
socketbackend ingen_tcp, the default value for theread_aheadoption was incorrect and has been corrected, according the documentation, to betrue.Own Id: OTP-20238
Related Id(s): PR-11284
A field in
net_kernel's internal state was not cleaned up in some cases for failed connections could cause the state to grow indefinitely over time. This has now been fixed.Own Id: OTP-20265
Related Id(s): GH-11308, PR-11388
Fixed
pg:which_groups/1to not include empty groups where all members have leaved. Bug existed since OTP 29.0.Own Id: OTP-20303
Related Id(s): GH-11360, PR-11361
mnesia-4.27
The mnesia-4.27 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed
mnesia:force_load_table/1getting stuck when the remote node becomes unreachable during table loading. When a network loader is aborted due to sender node going down and a user has forced a table load, we now retry loading from disc instead. Additionally, for disc_only_copies tables, the process actually loading the table is the dets server process, not the mnesia loader, so it would not receive the abort notification and would hang indefinitely. Now it correctly receives the notification and aborts table loading.Own Id: OTP-20256
Related Id(s): GH-11344, PR-11426
Fixed incorrect results from
mnesia:select_reverse/2,3onordered_settables inside a transaction that had already written to or deleted from the same table. Deleted records could reappear, updated records could appear twice, and the descending order was not preserved.Own Id: OTP-20364
Related Id(s): PR-11563
Improvements and New Features
The documentation of the
mnesiamodule now contains runnable examples for most functions. The examples are verified by the mnesia test suite, so they always match actual behavior.Own Id: OTP-20374
Related Id(s): PR-11216
odbc-2.17.1
The odbc-2.17.1 application can be applied independently of other applications on a full OTP 29 installation.
Improvements and New Features
Added the
max_long_column_sizeoption to limit buffer allocation size preventing memory exhaustion.Own Id: OTP-20328
Related Id(s): GH-9302, PR-10297
public_key-1.21.6
The public_key-1.21.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Added missing
no_cacerts_foundclauses so that the intended{failed_load_cacerts, no_cacerts_found}error is raised and formatted properly.Own Id: OTP-20318
Related Id(s): PR-11378
Align moduli and pubkey_moduli.hrl to state on OTP-28 and newer.
Own Id: OTP-20367
Related Id(s): PR-11574
Improvements and New Features
Worked around domain component using wrong ASN-1
PrintableStringencoding instead ofIA5Stringencoding.Own Id: OTP-20338
Related Id(s): GH-10879, PR-11226
ASN.1 files are now compiled sequentially to guarantee reproducible builds.
Own Id: OTP-20362
Related Id(s): GH-4417, PR-11396
runtime_tools-2.5
The runtime_tools-2.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed bug if a process that called
dbg:session/2exits beforedbg:session_destroy/1is called. An error report was logged and any trace messages lost and not delivered.Own Id: OTP-20218
Related Id(s): PR-11260
Improvements and New Features
A new
versionsmodule has been added to theruntime_toolsapplication containing functions for, e.g., comparing, versions that adhere to the OTP Versions Scheme.The documentation of the OTP Versions Scheme has also been improved.
Own Id: OTP-20352
Related Id(s): PR-11556, PR-11600
ssl-11.7.6
Note! The ssl-11.7.6 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Undecodable
certificate_authoritiesnames are now skipped, as they are just a hint.Own Id: OTP-20327
Related Id(s): GH-11338, PR-11356
Corrected generated keylog information generated from the
keylog_hsoption in the corner case that it was invoked after the client had reached its connection state, but the server closed the connection before it reached its connection state.Own Id: OTP-20358
Related Id(s): ERIERL-1356, PR-11570
Improvements and New Features
Added TLS-1.3
selected_grouptossl:connection_information/2.Own Id: OTP-20326
Related Id(s): PR-11440
The ECDHE-PSK Chacha20-Poly1305 cipher suites are now supported. This is relevant for TLS-1.2 (and lower).
Own Id: OTP-20331
Related Id(s): PR-11345
stdlib-8.1
The stdlib-8.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
When
beam_libreturns an error tuple, the filename in the information tuple is now a list of characters instead of an atom.Example:
The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the
beam_liberrors (not recommended) will need to be updated.Own Id: OTP-20118
Related Id(s): PR-11167
*** POTENTIAL INCOMPATIBILITY ***
The default seed in the
randmodule has been improved to spread out its entropy over all three seed words.This avoids identical first random numbers from two successive seeds on machines with low system time resolution.
Own Id: OTP-20158
Related Id(s): PR-11165
Fixed
unicode:characters_to_binary/2to handle incomplete utf-32 sequences without crashing.Also fixed a performance regression in
unicode:characters_to_nfkd_list/1.Own Id: OTP-20169
Related Id(s): PR-11130
The
arraymodule has been improved.array:slice/3now raisesbadargfor negative lengths.The performance of
array:mapfoldl/3andarray:sparse_mapfoldl/3has been improved.The documentation has been clarified regarding array growth/shrink behavior and how
concat/1,2handles mixed arrays.Own Id: OTP-20177
Related Id(s): PR-11159
Added more checks in the linter for badly formed
{Name,Arity}attributesOwn Id: OTP-20277
Related Id(s): GH-11397, PR-11422
Fixed return value of
zip:zip_get/2. When a file was extracted to a directory, the function returned a map instead of a file name.Own Id: OTP-20298
Related Id(s): PR-11313
When
compr_assignis enabled, the linter will correctly check for unbounded variables after block expressions in comprehensions.Own Id: OTP-20309
Related Id(s): GH-11406, PR-11567
When compiling a module with a triple-quoted string with escape sequences and a chunk boundary happened to fall just after an escape character, that character was not passed to the reentrancy continuation, so the scanner interpreted the following characters as not an escape sequence.
This bug has now been fixed.
Own Id: OTP-20320
Related Id(s): GH-11423, PR-11505
Fixed some errors in examples in the documentation for the
stringanduri_stringmodules.Own Id: OTP-20322
Related Id(s): PR-11446
Linter will emit better error messages when a behaviour attribute has a bad module name.
Own Id: OTP-20354
Related Id(s): GH-11401, PR-11552
Improvements and New Features
uri_string:parse/1now reports the actual offending character in error tuples instead of reporting a misleading cascade-failure position.Previously, when parsing a URI containing an invalid character (such as
|or non-ASCII characters likeö), the error tuple would point to the:character — the position where the parser's final backtracking attempt failed — rather than the character that actually violated the URI grammar. For example,uri_string:parse("http://localhost/A|B")returned{error,invalid_uri,":"}instead of the more helpful{error,invalid_uri,"|"}Own Id: OTP-20235
Related Id(s): GH-7862, PR-11129
Fixed a guard precedence bug in
uri_string:compose_query/2that caused inconsistent error handling depending on the encoding option.When
compose_query/2was called with invalid input (e.g. an atom instead of a string) and{encoding, unicode}, it would crash with** exception error: bad argumentinstead of returning the expected{error, invalid_input, Term}tuple. The same call with{encoding, utf8}correctly returned the error tuple. Both encoding options now consistently return{error, invalid_input, Term}for invalid input.Own Id: OTP-20236
Related Id(s): PR-11128
syntax_tools-4.1.1
The syntax_tools-4.1.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed exception when the epp_dodger AST contains macro-named record.
Own Id: OTP-20180
Related Id(s): GH-11155, PR-11203
Any caller who passed a single syntax tree that was not a form_list (e.g.
erl_recomment:recomment_forms(erl_syntax:atom(foo), Cs)or any expression/function tree) would get a hard crash instead of the documented result. This issue has been fixed.Own Id: OTP-20290
Related Id(s): PR-11442
tools-4.2.3
The tools-4.2.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The
tags.erlmodule is used to generateTAGSfiles for Emacs. There was a case where single quote items starting in position 0 would crash the scanner. This use case can potentially happen in docstrings, although not too common. This fix makes the scanner to handle such cases instead of crashing.Own Id: OTP-20293
Related Id(s): PR-11447
Updated the Emacs skeleton to reflect latest
format_statuscallback handling.Own Id: OTP-20339
Related Id(s): PR-11507
wx-2.7
The wx-2.7 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
A large set of correctness and robustness fixes were applied across the
wxapplication, addressing issues found by static analysis of both the Erlang and C/C++ sources.Own Id: OTP-20335
Related Id(s): PR-11530
Improvements and New Features
Removed configure checks that prevented cross compilation of wx. Note that cross compilation is not tested and may require manual configuration.
Own Id: OTP-20189
Related Id(s): PR-11137
Thanks to
Alois Vitasek, Anton Thomasson, ausimian, Bernhard M. Wiedemann, Cole Christensen, Dmitri Vereshchagin, Dmytro Lytovchenko, Eric Meadows-Jönsson, haoxian, Jianbo He, João Henrique Ferreira de Freitas, Johan Bevemyr, John Downey, Jonatan Männchen, Julian Doherty, kagetora66, k-patrik, Louis Pilfold, Lukasz Samson, Luke Bakken, Maria Scott, Mikael Pettersson, Paul Guyot, Renato Ceolin, ruslandoga, Scott Wiggins, Stanislav Yaglo, Thomas Arts, Thomas Cioppettini, Zeke Dou, zmstone
v29.0.6: OTP 29.0.6Compare Source
Check out the git tag OTP-29.0.6, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
compiler-10.0.4
The compiler-10.0.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
compiler: Fix bug in
beam_types:subtract/2for bitstringsOwn Id: OTP-20312
Related Id(s): GH-11494, PR-11503
crypto-5.9.3
The crypto-5.9.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed type mismatch between
ErlNifUInt64anduint64_tin crypto NIF that caused incompatible-pointer warnings on macOS arm64 when passing DH parameters to OpenSSL.Own Id: OTP-20333
Related Id(s): GH-11511, PR-11513
eldap-1.3.1
The eldap-1.3.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
eldap referral URL parsing now rejects a port component longer than 5 digits instead of attempting to convert an arbitrarily large digit string to an integer.
Own Id: OTP-20345
Related Id(s): PR-11538 CVE-2026-70409
erl_interface-5.8.2
The erl_interface-5.8.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
erl_interface: Fix buffer leak and state corruption on
ei_x_buffrealloc failureOwn Id: OTP-20324
Related Id(s): PR-11492
erts-17.0.6
The erts-17.0.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
No-suspend port command signals (i.e. port command signals sent using the
erlang:port_command/3BIF or theerlang:send/3BIF with thenosuspendoption) were not aborted properly in all scenarios which could leave the port queue in a busy state indefinitely. Also asynchronously sent no-suspend command signals (i.e, port command signals sent using theerlang:send/3BIF with thenosuspendoption) could sometimes be delivered even though the port was busy.Own Id: OTP-20135
Related Id(s): GH-11052, PR-11463
erts: Fix missing exit_status caused by SIGCHLD race
Own Id: OTP-20274
Related Id(s): GH-11278, PR-11298
erts: Fix bug in
is_in_rangeinstruction for x86 JITOwn Id: OTP-20278
Related Id(s): GH-11419, PR-11429
Fixed bug in
binary_to_termthat could cause emulator crash for specific terms in specific process states (reductions left).Own Id: OTP-20281
Related Id(s): GH-11404, PR-11425
erts: Fix crash with
term_to_iovec/2for large binaryOwn Id: OTP-20282
Related Id(s): PR-11428
A distributed
prioritysend larger than 32 KiB to a process alias caused the receiving runtime system to crash.Own Id: OTP-20286
Related Id(s): GH-11416, PR-11417
Priority message queue markers were sometimes installed in the message queue even when no priority messages could be received. As a result, the two markers had to be traversed unnecessarily when scanning the message queue, introducing a small but avoidable overhead.
Own Id: OTP-20300
Related Id(s): PR-11485
A monitor of
time_offsetco-created with a process alias (monitor(time_offset, clock_service, [{alias, UnaliasOpt}])) either crashed the runtime system or did not work. This bug was introduced in OTP 25.0.Own Id: OTP-20319
Related Id(s): PR-11509
A process alias was erroneously created when a remote
spawn_request()operation with a{monitor, [{alias, explicit_unalias}]}option failed withnoconnectionreason.Own Id: OTP-20330
Related Id(s): PR-11521
A
gen_tcpsocket using the inet driver and{packet,4}had a bug if receiving a packet with size just below INT_MAX.That packet size wrapped in size calculations and made the received data overwrite its allocation and trash allocator metadata and subsequent block(s), causing the VM to crash.
This made it possible for anyone to remotely crash an Erlang node that used
{packet,4}on a reachable socket.This bug has been corrected.
Own Id: OTP-20334
Related Id(s): PR-11533, CVE-2026-75538
inets-9.7.2
The inets-9.7.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The
detsandmnesiamod_authbackends used a key that did not include the directory path, so allrequire_user/require_grouprecords collapsed into one per-listener namespace. A user authorized for one protected directory could authenticate against any other protected directory served by the same listener.{path, Directory}is now included in the auth backend key, scoping records per directory as documented.Own Id: OTP-20264
Related Id(s): PR-11546 CVE-2026-74994
Requests specifying both
Transfer-EncodingandContent-Lengthheaders are now rejected with400 Bad Request, per RFC 9112 Section 6.3. Previously such requests could be used for CL.TE request-smuggling/desync attacks against reverse proxies in front ofhttpd.Own Id: OTP-20268
Related Id(s): PR-11547 CVE-2026-73812
httpdaccepted the obsolete header line-folding syntax (RFC 9112 Section 5.2, a continuation line beginning with space/tab), silently treating the folded continuation as a separate header. This allowed CL.TE-style request smuggling whenhttpdwas placed behind a folding-aware proxy. Such requests are now rejected with400 Bad Request.Own Id: OTP-20269
Related Id(s): PR-11544 CVE-2026-66357
A header such as
Content-Length : 6(whitespace before the colon) was previously silently dropped, causing the content length to default to 0 and the body bytes to be misinterpreted as a pipelined request (CL.0 smuggling). Per RFC 7230 Section 3.2.4, such headers are now rejected with400 Bad Request.Own Id: OTP-20270
Related Id(s): PR-11545 CVE-2026-73276
A new httpd option
request_timeout(default 60 seconds, renamed from the interimmax_body_read_timeout) bounds the idle time between reads of a request body/message. The server now also sends408 Request Timeoutwhen themin_bytes_per_secondfloor is hit, andkeep_alive_timeoutmeasurement was corrected so the timer is cancelled as soon as new data arrives rather than only after full header parsing;keep_alive_timeoutandrequest_timeoutnow also acceptinfinityto disable the timeout.Own Id: OTP-20271
Related Id(s): PR-11543 CVE-2026-71380
mod_auth,mod_security, andmod_getcompared resolved filesystem paths against configured protected-directory patterns without normalizing repeated slashes or filesystem case. On case-insensitive filesystems (macOS, Windows) or with repeated slashes, a request could resolve to a protected resource while evading the directory match. Paths are now canonicalized (slash-collapsed, and case-normalized when the filesystem is case-insensitive) before the authorization decision.Own Id: OTP-20279
Related Id(s): PR-11542 CVE-2026-73270 CVE-2026-66835
A request with an invalid chunked transfer-encoding chunk size previously caused the httpd connection handler to hang indefinitely without requiring further input from the client. This leaked a process per request and could be used to exhaust server resources (denial of service). Invalid chunk sizes are now rejected immediately with an error response, and the connection is closed.
Own Id: OTP-20306
Related Id(s): PR-11539 CVE-2026-69664
max_body_sizewas previously enforced only after a complete chunk had been received, allowing a single oversized chunk to be buffered in full before the limit was checked — undermining the memory-exhaustion protection the option is meant to provide. The limit is now enforced incrementally as chunk data arrives, rejecting the request as soon as the configured size is exceeded.Own Id: OTP-20307
Related Id(s): PR-11540 CVE-2026-74835
The documented default of 150 for the
max_clientsoption was not applied by the implementation, allowing an unbounded number of concurrent clients to connect regardless of configuration. The default is now correctly enforced.Own Id: OTP-20308
Related Id(s): PR-11541 CVE-2026-70399
Fixed a bug where httpd failed to start when configured with {socket_type, {ip_comm, SockOpts}} and a fixed (non-zero) port.
Own Id: OTP-20342
Related Id(s): PR-11548
httpcnow enforces a limit on the total size of response headers and response body, preventing unbounded memory allocation when connecting to a malicious or malfunctioning server. The new max_header_size and max_body_size request options can be used to override the default limit (10240 bytes for headers). Additionally, httpc now validates that the Content-Length header contains only digits before use, avoiding a crash on malformed responses.Own Id: OTP-20343
Related Id(s): PR-11538 CVE-2026-55951 CVE-2026-71562
megaco-4.9.2
The megaco-4.9.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Numeric fields in megaco text-encoded messages are now validated for digit-string length before integer conversion, improving robustness of the text decoder. Per-field digit limits based on the H.248.1 ASN.1 type constraints are enforced (e.g., 10 digits for UINT32, 2 digits for timer values), along with a 100 KB overall message size cap at the scanner entry point. The binary (BER/PER) codec is not affected.
Own Id: OTP-20234
Related Id(s): PR-11325
mnesia-4.26.2
The mnesia-4.26.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
A transaction iterating a table (first/1, last/1, next/2, prev/2, select, select_reverse on non-ordered_set) leaked a safe_fixtable hold when the coordinator was killed by an external signal. The table remained fixed for the lifetime of the node, preventing space reclamation of deleted objects.
Own Id: OTP-20347
Related Id(s): PR-11517
Fixed a race condition where mnesia_controller could crash if a table was deleted while
mnesia:set_master_nodes/2was being processed.Own Id: OTP-20351
Related Id(s): PR-11554
public_key-1.21.5
The public_key-1.21.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Retain lost CommonName length relaxation.
Own Id: OTP-20321
Related Id(s): GH-11240, PR-11358
snmp-5.20.5
The snmp-5.20.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The SNMP PDU decoder now bounds the byte length accepted for INTEGER, Counter32, Gauge32/Unsigned32, TimeTicks, and Counter64 values during decoding (4, 5, 5, 5, and 9 bytes respectively, matching the SMIv2 value ranges), instead of accepting an arbitrarily large byte string and converting it to an integer.
Own Id: OTP-20346
Related Id(s): PR-11538 CVE-2026-70405
ssh-6.0.5
The ssh-6.0.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a bug where multiple subsystem requests could succeed on same ssh channel which is forbidden by RFC 4254 §6.5
Own Id: OTP-20284
Related Id(s): PR-11437
ssl-11.7.5
Note! The ssl-11.7.5 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Debugging keylog_hs callback used for logging handshake secrets on failed connections swapped the argument order in logging function confusing server and client side. The bug was introduced in OTP 28.5
Own Id: OTP-20350
Related Id(s): ERIERL-1354, PR-11553
Improvements and New Features
Hardening improvements of the ssl application.
TLS distribution now defaults to TLS-1.3 instead of TLS-1.2 (TLS-1.2 is kept as fallback for rolling upgrades).
TLS-1.2 server with {verify, verify_peer} now defaults reuse_sessions to false to mitigate the Triple Handshake attack (RFC 7627). Set {reuse_sessions, true} explicitly to restore previous behavior.
Various missing or faulty sanity checks added and TLS alerts adjusted to comply with RFC MUST requirements, including: signature algorithm validation for intermediate certificates, TLS-1.3 session_id echo, pre_shared_key extension ordering, and renegotiation_info enforcement.
Hardened and improved CRL support. Introduces new option allowed_hosts for the optional CRL HTTP fetching feature to restrict which hosts may be contacted. Internal/loopback IPs are now blocked by default (SSRF protection).
TLS-1.3 client ticket handling is more robust (locked tickets are released on client crash). Server TLS-1.3 ticket handling and anti-replay Bloom filter performance are optimized.
DTLS duplicate ChangeCipherSpec handling simplified, fixing potential state machine confusion (GH-11075).
Process state formatting no longer leaks secrets in crash logs.
Own Id: OTP-20289
Related Id(s): PR-11478
stdlib-8.0.4
The stdlib-8.0.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a bug in
unicode_util:gc/1where the grapheme cluster segmentation of$\r(not followed by$\n) would decompose binary continuations into mixed chardata. This causedstring:trim/3(andstring:chomp/1) to return incorrect results or crash when trimming strings containing binaries followed by another list element.Own Id: OTP-20296
Related Id(s): GH-11380, PR-11464
record_info/2will now mark tuple records as used.Own Id: OTP-20301
Related Id(s): ERIERL-1345, PR-11470
uri_string:parse/1now rejects URIs with an unreasonably long port component (more than 5 digits) instead of attempting to convert an arbitrarily large digit string to an integer.Own Id: OTP-20344
Related Id(s): PR-11538 CVE-2026-59696
tools-4.2.2
The tools-4.2.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
tools: fixes tprof not stopping tracing
A call to
tprof:enable_trace(new|existing)starts tracing processes. To stop it, one callstprof:disable_trace(new|existing). However, the guard to stop tracing was matching onnew_processes | existing_processes. The return happens to say0processes are traced now, but the tracing did not stop. This issue has been fixed.Own Id: OTP-20302
Related Id(s): PR-11481
Thanks to
Andrew Bennett, ausimian, Laurynas Četyrkinas, ruslandoga, Thomas Cioppettini
v29.0.5: OTP 29.0.5Compare Source
Check out the git tag OTP-29.0.5, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
erts-17.0.5
The erts-17.0.5 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a regression in the previous patch release that prevented epmd from binding to localhost.
Own Id: OTP-20275
Related Id(s): GH-11402, PR-11409
ssh-6.0.4
The ssh-6.0.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The SSH client and server now reject incoming packets not aligned to the cipher block size as required by RFC 4253 §6. For CBC ciphers, a timing-safe "packet discard" mechanism (CVE-2008-5161 mitigation) ensures structural errors are indistinguishable from MAC failures before disconnecting. AEAD and encrypt-then-MAC modes disconnect immediately.
Own Id: OTP-20137
Related Id(s): PR-11110
v29.0.4: OTP 29.0.4Compare Source
Check out the git tag OTP-29.0.4, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
POTENTIAL INCOMPATIBILITIES
Mitigated a denial of service attack in epmd.
Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.
Own Id: OTP-20136
Application(s): erts
Related Id(s): PR-11386, CVE-2026-42792
compiler-10.0.3
The compiler-10.0.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
compiler: Fix an internal consistency check failure with
setelementOwn Id: OTP-20261
Related Id(s): GH-11368, PR-11374
crypto-5.9.2
The crypto-5.9.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed crash in
crypto:macN/5when suppliedMacLengthwas greater than length of what the underlying hash returned.Own Id: OTP-20239
Related Id(s): PR-11239
Fixed segfault in
crypto:aead_cipher_init_nifwhen argument validation fails.Own Id: OTP-20241
Related Id(s): PR-11330
Fix cipher key buffer overread for
chacha20_poly1305.Own Id: OTP-20244
Related Id(s): PR-11337
diameter-2.7.2
The diameter-2.7.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fix infinite loop in
diameter_dist:route_session/2when avp other thanSession-Idhas zero length.Own Id: OTP-20242
Related Id(s): PR-11331
Fix crash in
diameter_dist:route_session/2whenSession-Id(code: 263) avp has zero length.Own Id: OTP-20243
Related Id(s): PR-11333
erts-17.0.4
The erts-17.0.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Mitigated a denial of service attack in epmd.
Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.
Own Id: OTP-20136
Related Id(s): PR-11386, CVE-2026-42792
*** POTENTIAL INCOMPATIBILITY ***
Fixed heap corruption when an invalidly encoded tuple with an arity of 2^31 or larger is decoded from Erlang's External Term Format (binary_to_term).
Own Id: OTP-20214
Related Id(s): PR-11297, CVE-2026-55737
When send_timeout is set and send_timeout_close is set to true, a 'tcp_closed' message is expected when the timeout occurs, but that (message) was not delivered. This has now been fixed.
Own Id: OTP-20257
Related Id(s): GH-11319
A crafted External Term Format (ETF) payload could crash the runtime system.
Thanks to Paul Guyot for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.
Own Id: OTP-20259
Related Id(s): PR-11386, CVE-2026-54890
Fixed a rounding error in 16-bit float conversion.
Own Id: OTP-20260
Related Id(s): GH-11332, PR-11334
megaco-4.9.1
The megaco-4.9.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a buffer overflow in the megaco flex scanner C driver. A property parm name exceeding 452 bytes in a text-encoded H.248 message could overflow a fixed-size error buffer, crashing the VM. The sprintf calls have been replaced with bounded snprintf.
Own Id: OTP-20237
Related Id(s): GH-SA-7xgh-gmgf-q2g7, PR-11323
public_key-1.21.4
The public_key-1.21.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad_cert, policy_tree_exceeded}.
Own Id: OTP-20251
Related Id(s): GH-SA-622p-qfh6-c352, PR-11372
ssh-6.0.3
The ssh-6.0.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
DH key exchange now enforces strict bounds (1 < e/f < p-1, 1 < K < p-1) on all paths, matching OpenSSH and Go. No interop impact.
Own Id: OTP-20229
Related Id(s): PR-11303
Validate DH group parameters (P, G) received from the server during DH-GEX key exchange. The client now rejects groups where P is smaller than 2048 bits or G is not in the range (1, P-1). The default minimum in dh_gex_limits has been raised to 2048 on both client and server.
Own Id: OTP-20258
Related Id(s): ERIERL-1341, PR-11369
ssl-11.7.4
Note! The ssl-11.7.4 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Add pre TLS-1.3 client side validation of servers algorithm selection being part of clients offered algorithms, preventing in worst case MITM circumventing validation of server certificate tricking the client to trust the malicious MITM as it was a valid server. Note this check is already performed for TLS-1.3 clients.
Own Id: OTP-20240
Related Id(s): PR-11336, CVE-2026-55953
Prevent invalid cert chains to create cycles in chain building code used to handle chains that could be unordered or contain extraneous certs. This avoids a DoS attack possibility.
Own Id: OTP-20245
Related Id(s): PR-11343, CVE-2026-58227
Clarify that rsa_psk and anonymous key exchange algorithms are considered legacy. Also harden rsa_psk in same way as normal rsa key exchange.
Own Id: OTP-20248
Related Id(s): PR-11341
Harden SSL application to conform with best practice and RFC's. This will mostly improve error messages and conserve memory usage.
Own Id: OTP-20250
Related Id(s): PR-27944
A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad_cert, policy_tree_exceeded}.
Own Id: OTP-20251
Related Id(s): GH-SA-622p-qfh6-c352, PR-11372
stdlib-8.0.3
The stdlib-8.0.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a bug where zip:unzip/1,2 and zip:extract/1,2 were vulnerable to a relative path traversal attack. A crafted zip archive containing entry names such as ../x/y could have caused files to be written outside the intended extraction directory.
Thanks to Jonatan Männchen and Zhang Delong for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.
Own Id: OTP-20143
Related Id(s): PR-11386, CVE-2026-47078
Thanks to
a1x-an, Jonatan Männchen
v29.0.3: OTP 29.0.3Compare Source
Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
common_test-1.31.1
The common_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a crash in ct_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation.
Own Id: OTP-20191
Related Id(s): ERIERL-1333, PR-11230
compiler-10.0.2
The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.
Own Id: OTP-20222
Related Id(s): PR-11219
crypto-5.9.1
The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
crypto:compute_key/4foreddhandcrypto:generate_key/2,3foreddh/eddsanow raise anerror:{notsup, Info, Description}exception instead of returning the atomnotsupwhen the underlying cryptolib lacks support.Own Id: OTP-20215
Related Id(s): PR-11302
dialyzer-6.0.2
The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fix a bug with native record sets in
erl_types.erlOwn Id: OTP-20201
erts-17.0.3
The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed an undefined behavior in the internal
erts_qsort()function, which could have been the cause of a beam crash seen when updating large maps.Own Id: OTP-20185
Related Id(s): PR-11215
Calculating
bxorof the largest supported positive integer (erlang:system_info(max_integer)) and-1would return[]instead of a raising asystem_limitexception.Own Id: OTP-20208
Related Id(s): PR-11269
Fix possible race between
ets:delete/1and terminating process with a fixation on the same table.Own Id: OTP-20217
Related Id(s): PR-11283
A few code generation issues for the JIT on AArch64 (ARM64) have been fixed.
For all platforms, the loader will reject some invalid BEAM files earlier.
Own Id: OTP-20226
Related Id(s): PR-11299
On 32-bit computers, the
md5BIFs would return an incorrect MD5 checksum for data of size 4GiB or more.Own Id: OTP-20227
Related Id(s): PR-11289
kernel-11.0.3
The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
inet:info/1 could crash when calling for a closing (port) socket.
Own Id: OTP-20173
Handling of the truncation bit in
inet_reshas been fixed so it properly falls back to querying over TCP after a truncated UDP reply.This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails.
Own Id: OTP-20199
Related Id(s): PR-11247
public_key-1.21.3
The public_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding.
Own Id: OTP-20197
Related Id(s): PR-11239
ssh-6.0.2
The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a path-existence oracle in the SFTP server where
SSH_FXP_REALPATHrequests with..components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem.Own Id: OTP-20183
Related Id(s): GH-SA-h9pw-h5w4-h976, PR-11294, CVE-2026-53422
Fixed an infinite loop in the SFTP server triggered when receiving
SSH_MSG_CHANNEL_EXTENDED_DATAon an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue.Own Id: OTP-20186
Related Id(s): GH-SA-7wp4-pc27-2vj9, PR-11295, CVE-2026-54886
Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification.
Own Id: OTP-20196
Related Id(s): PR-11209
Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent.
Own Id: OTP-20198
Related Id(s): PR-11244
The SFTP server now caps the read length in
SSH_FXP_READrequests to 255 KiB (matching OpenSSH'sSFTP_MAX_READ_LENGTH), preventing excessive memory allocation when clients request large reads.Own Id: OTP-20200
Related Id(s): PR-11259
Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade.
Own Id: OTP-20206
Related Id(s): PR-11268
ssl-11.7.3
Note! The ssl-11.7.3 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown.
Own Id: OTP-20190
Related Id(s): PR-11250
Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window.
Own Id: OTP-20194
Related Id(s): PR-11271, CVE-2026-54887
Guard TLS client for MITM injection of application data during "plain-text-window" during handshake.
Own Id: OTP-20207
Related Id(s): PR-11270, CVE-2026-54891
Improve error handling of TLS PSK sending ILLIGAL_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs.
Own Id: OTP-20216
Related Id(s): PR-11282, CVE-2026-55952
Fix race condition that could be used to DoS attack DTLS servers.
Own Id: OTP-20220
Related Id(s): PR-11306, CVE-2026-55950
A TLS-1.3 stateless session ticket with obfuscated_ticket_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value.
Own Id: OTP-20230
Related Id(s): PR-11307
TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4
Own Id: OTP-20231
Related Id(s): PR-11309
A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used.
Own Id: OTP-20232
Related Id(s): PR-11311
Correct spec for CRL API
Own Id: OTP-20233
Related Id(s): PR-11281
stdlib-8.0.2
The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.
Own Id: OTP-20222
Related Id(s): PR-11219
Thanks to
Cole Christensen, Nick Krichevsky, Stefan Grundmann
v29.0.2: OTP 29.0.2Compare Source
Check out the git tag OTP-29.0.2, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
dialyzer-6.0.1
The dialyzer-6.0.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fix native record bugs in Dialyzer
Own Id: OTP-20178
Related Id(s): PR-11199
diameter-2.7.1
The diameter-2.7.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed return value documentation of
diameter:service_info(SvcName, statistics)Own Id: OTP-20150
Related Id(s): GH-11105, PR-11146
erl_interface-5.8.1
The erl_interface-5.8.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed stack overflow in
ei_s_print_termfor very big integer terms (> 2000 hexadecimal digits long).Own Id: OTP-20160
Related Id(s): GH-SA-xcxj-5pg2-v72j, PR-11193, CVE-2026-49760
erts-17.0.2
The erts-17.0.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
A buffer overflow error when parsing SCTP ERROR or ABORT chunks has been fixed.
This could lead to stack corruption and VM crash, but ultimately with hard work by an attacker be refined into maybe even remote code execution.
Own Id: OTP-20165
Related Id(s): GH-SA-6f4f-chj5-5g97, PR-1234, CVE-2026-49759
ftp-1.2.6
The ftp-1.2.6 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
FTP client default connections that use the so called passive mode of FTP fails to properly validating the response IP of the server, hence a malicious or compromised FTP server could redirect the data connection to an arbitrary host, enabling s server-side request forgery (SSRF) and FTP bounce attacks.
Own Id: OTP-20166
Related Id(s): GH-SA-24cv-hwgr-37fq, PR-11186, CVE-2026-48858
inets-9.7.1
The inets-9.7.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
The HTTP client (httpc) now removes Authorization, Proxy-Authorization, Cookie, Referer, and Origin headers when following a redirect to a different host or port. Previously these headers were forwarded verbatim, potentially leaking credentials to unintended targets.
This follows the requirements of RFC 9110 §15.4.
Own Id: OTP-20155
Related Id(s): GH-SA-m75x-4vwg-ggjh, PR-11212, CVE-2026-48856
kernel-11.0.2
The kernel-11.0.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
gen_tcp_socket accept should explicitly inherit the same options as plain gen_tcp.
Own Id: OTP-20057
mnesia-4.26.1
The mnesia-4.26.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed docs of
mnesia:write/3to clarify when a transaction can terminate.Own Id: OTP-20149
Related Id(s): GH-11104, PR-11145
public_key-1.21.2
The public_key-1.21.2 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Add missing macro reference for legacy algorithms md5 and sha224. This mainly improves error handling.
Own Id: OTP-20172
Related Id(s): PR-11195
ssh-6.0.1
The ssh-6.0.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a timing-based username enumeration vulnerability during password authentication with the user_passwords option. A dummy PBKDF2 computation is now performed for invalid usernames to match the response time of valid ones.
Own Id: OTP-20153
Related Id(s): GH-SA-3w6p-vwhf-wvp4, PR-11157, CVE-2026-48859
Fixed SSH_FXP_READLINK handler in ssh_sftpd to strip the backend root prefix from symlink targets before returning them to the client, preventing disclosure of the server's absolute filesystem path when the root option is configured.
Own Id: OTP-20162
Related Id(s): GH-SA-pv7g-pjrq-x2fh, PR-11192, CVE-2026-48855
Fixed a race condition where SSH keep-alive responses could consume pending channel open requests, causing channel setup to fail silently.
Own Id: OTP-20181
Related Id(s): PR-11205
ssl-11.7.2
Note! The ssl-11.7.2 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
Fix miscellanies issues that could cause unnecessary memory consumption and in some less common scenarios or configurations cause connection failures.
Own Id: OTP-20154
Related Id(s): PR-11148
Erlang distribution over TLS run with the kernel 'check_ip' flag now properly enforce connecting nodes to be on the same LAN.
Own Id: OTP-20156
Related Id(s): GH-SA-gp7x-mfv6-52cv, PR-11181, CVE-2026-48860
Enhance error message, by fixing typo of atom in new error message related to `public_key` CVE-2026-42790 solution.
Own Id: OTP-20161
Related Id(s): PR-11148
Corrected SNI handling for TLS-1.3 only server, could cause connection failures if supported signature algorithms where changed by SNI option update.
Own Id: OTP-20174
Related Id(s): PR-27384
stdlib-8.0.1
The stdlib-8.0.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fix a bug where a tuple record operation within a native record anonymous update can crash.
Own Id: OTP-20151
Related Id(s): PR-11141
Fixed some bugs in
io_lib:bformat/2and native record printing.Own Id: OTP-20170
Related Id(s): PR-11154
tools-4.2.1
The tools-4.2.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Xref could crash instead of returning an appropriate error tuple when asked to open a BEAM file without debug information but with a
moduledoc(false)attribute.Own Id: OTP-20163
Related Id(s): GH-11152, PR-11168
Thanks to
John Downey, Jonatan Männchen
v29.0.1: OTP 29.0.1Compare Source
Check out the git tag OTP-29.0.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
POTENTIAL INCOMPATIBILITIES
'public_key', Adhere to RFC 9525, and remove support for legacy fallback to check hostname against subject common name. Also improve error handling creating two separate errors for name constraint check for subject names and subject alternative names.
'ssl'. Error handling is slightly changed to better reflect public_key behaviour.
Own Id: OTP-20130
Application(s): public_key, ssl
Related Id(s): PR-11124, CVE-2026-42790
compiler-10.0.1
The compiler-10.0.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
In rare circumstances, optimization of boolean expressions could invert the boolean value.
Own Id: OTP-20140
Related Id(s): GH-11088, PR-11089
The compiler could crash when compiling code using native records in certain ways.
Own Id: OTP-20146
Related Id(s): PR-11135
erts-17.0.1
The erts-17.0.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Comparison of two native records could return an incorrect result or crash the runtime system.
Own Id: OTP-20139
Related Id(s): PR-11107
kernel-11.0.1
The kernel-11.0.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
SCTP peeloff of an IPv6 socket, the peeled-off socket does not inherit the parent options as expected.
Own Id: OTP-20134
Related Id(s): PR-11007
public_key-1.21.1
The public_key-1.21.1 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
OCSP responder certificates are now checked for expiration before being accepted as authorized responders. Previously, expired or not-yet-valid responder certificates were incorrectly accepted when verifying OCSP responses.
Own Id: OTP-20112
Related Id(s): PR-11136
Corrected basic constraint path validation check in accordance to RFC 5280.
Own Id: OTP-20129
Related Id(s): PR-11123, CVE-2026-42789
'public_key', Adhere to RFC 9525, and remove support for legacy fallback to check hostname against subject common name. Also improve error handling creating two separate errors for name constraint check for subject names and subject alternative names.
'ssl'. Error handling is slightly changed to better reflect public_key behaviour.
Own Id: OTP-20130
Related Id(s): PR-11124, CVE-2026-42790
*** POTENTIAL INCOMPATIBILITY ***
snmp-5.20.4
The snmp-5.20.4 application can be applied independently of other applications on a full OTP 29 installation.
Fixed Bugs and Malfunctions
Fixed a bug in snmpm_usm:generate_outgoing_msg/5 that caused a badmatch crash when constructing an error response for an unknown user/engineID combination.
Own Id: OTP-20138
Related Id(s): ERIERL-1321, PR-11100
ssl-11.7.1
Note! The ssl-11.7.1 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.
Fixed Bugs and Malfunctions
'public_key', Adhere to RFC 9525, and remove support for legacy fallback to check hostname against subject common name. Also improve error handling creating two separate errors for name constraint check for subject names and subject alternative names.
'ssl'. Error handling is slightly changed to better reflect public_key behaviour.
Own Id: OTP-20130
Related Id(s): PR-11124, CVE-2026-42790
*** POTENTIAL INCOMPATIBILITY ***
Could cause server to terminate a connection without an alert towards a bad client.
Own Id: OTP-20141
Related Id(s): PR-11125
Thanks to
Martin Hässler, Paul Guyot
v29.0: OTP 29.0Compare Source
Check out the git tag OTP-29.0, and build a full OTP system including documentation.
HIGHLIGHTS
The JIT now generates better code for matching or creating binaries with multiple little-endian segments.
Own Id: OTP-19747
Application(s): erts
Related Id(s): PR-10126
In the documentation for the
compilemodule, a section has been added with recommendations for implementors of languages running on the BEAM. Documentation has also been added for theto_abstr,to_exp, andfrom_abstroptions.The documentation for erlc now lists
.abstras one of the supported options.When compiling with the
to_abstroption, the resulting.abstrfile now retains any-docattributes present in the source code.Own Id: OTP-19784
Application(s): compiler, erts
Related Id(s): PR-10230, PR-10234
Native records as described in EEP-79 has been implemented.
A native record is a data structure similar to the traditional tuple-based records, except that is a true data type.
Native records are considered experimental in Erlang/OTP 29 and possibly also in Erlang/OTP 30, meaning that their behavior may change, potentially requiring updates to applications that use them.
Own Id: OTP-19785
Application(s): compiler, debugger, dialyzer, erts, stdlib
Related Id(s): PR-10617
The guard BIF
is_integer/3has been added. It follows the design of the original EEP-16, only changing the name fromis_betweentois_integer. This BIF takes in 3 parameters,Term,LowerBound, andUpperBound.It returns
trueifTerm,LowerBound, andUpperBoundare all integers, andLowerBound =< Term =< UpperBound; otherwise, it returns false.Example:
Own Id: OTP-19809
Application(s): compiler, dialyzer, erts
Related Id(s): PR-10276
There are new functions for random permutation of a list:
rand:shuffle/1andrand:shuffle_s/2. They are inspired by a suggestion and discussion on ErlangForums.Own Id: OTP-19826
Application(s): stdlib
Related Id(s): PR-10281
In the default code path for the Erlang system, the current working directory (
.) is now in the last position instead of the first.Own Id: OTP-19842
Application(s): erts, kernel
*** POTENTIAL INCOMPATIBILITY ***
Function application is now left associative. That means one can now write:
instead of:
Own Id: OTP-19866
Application(s): compiler
Related Id(s): PR-9223
The old-style type tests in guards (
integer,atom, and so on) have been scheduled for removal in Erlang/OTP 30. They have been deprecated for a long time.Own Id: OTP-19887
Application(s): otp
Related Id(s): PR-10417
There will now be a warning when exporting variables out of a subexpression. For example:
To avoid the warning, this can be rewritten to:
The warning can be suppressed by giving option
nowarn_export_var_subexprto the compiler.Own Id: OTP-19898
Application(s): compiler, stdlib
Related Id(s): PR-9134
There is a new option
warn_obsolete_bool_opthat instruct the compiler to emit warnings for theandandoroperators. It is recommended to instead use the modernandalsoandorelseoperators, or,and;in guards.Own Id: OTP-19918
Application(s): compiler
Related Id(s): PR-9115
graphis a new module that is a functional equivalent of thedigraphanddigraph_utilsmodules.Own Id: OTP-19922
Application(s): stdlib
Related Id(s): PR-10532
Before Erlang/OTP 29, attempting to bind variables in a comprehension would compile successfully but fail at runtime. Example:
In Erlang/OTP 29, attempting to bind a variable in a comprehension will fail by default:
However, this example will work as expected if the
compr_assignfeature is enabled when starting the runtime system:Here is another example how
compr_assigncan be used:Own Id: OTP-19927
Application(s): compiler, stdlib
Related Id(s): PR-9153
*** POTENTIAL INCOMPATIBILITY ***
There will now be a warning when using the
catchoperator, which has been deprecated for a long time.It is recommended to instead use
try...catch...endbut is also possible to disable the warning by using thenowarn_deprecated_catchoption.Own Id: OTP-19938
Application(s): compiler, stdlib
Related Id(s): PR-10421
Multi-valued comprehensions according to EEP 78 has been implemented.
Example:
Own Id: OTP-19942
Application(s): compiler, debugger, stdlib, syntax_tools
Related Id(s): PR-9374
There will now be a warning for matches that unify constructors, such as the following:
Such a match can be rewritten to:
The compiler option
nowarn_match_alias_patscan be used to disable the warning.Own Id: OTP-19943
Application(s): compiler, stdlib
Related Id(s): PR-10433
There is no longer a 32-bit Erlang/OTP build for Windows.
Own Id: OTP-19960
Application(s): otp
While the iteration order for maps is undefined, it is now guaranteed that all ways of iterating over maps provides the elements in the same order. That is, all of the following ways of iterating will produce the elements in the same order:
maps:keys/1maps:values/1maps:to_list/1maps:to_list(maps:iterator(M))[{K,V} || K := V <- M]Own Id: OTP-19963
Application(s): erts, stdlib
Related Id(s): PR-10626
The default key exchange algorithm is now mlkem768x25519-sha256, a hybrid quantum-resistant algorithm combining ML-KEM-768 with X25519. This provides protection against both classical and quantum computer attacks while maintaining backward compatibility through automatic fallback to other algorithms when peers don't support it.
Own Id: OTP-19965
Application(s): ssh
Related Id(s): PR-10656
*** POTENTIAL INCOMPATIBILITY ***
The compiler now generates more efficient code for map comprehensions with constant values that don't depend on the generator, such as the following:
Own Id: OTP-19968
Application(s): compiler
Related Id(s): PR-10646
The SSH daemon now defaults to disabled for shell and exec services, implementing the "secure by default" principle. This prevents authenticated users from executing arbitrary Erlang code unless explicitly configured.
Applications requiring shell or exec functionality must now explicitly enable:
Own Id: OTP-19969
Application(s): ssh
Related Id(s): ERIERL-1319, PR-10970, PR-11080
*** POTENTIAL INCOMPATIBILITY ***
The
odbcapplication is now deprecated and is planned to be removed in Erlang/OTP 30.The
ftpandct_ftpmodules are now deprecated and are planned to be removed in Erlang/OTP 30.Own Id: OTP-19980
Application(s): ftp, odbc
Related Id(s): PR-10804
The
arraymodule have been extended with several new functions. The internal representation have been changed to allow the new functionality and optimizations. Arrays serialized withterm_to_binary/1in previous releases are not compatible.Own Id: OTP-20004
Application(s): stdlib
Related Id(s): PR-10578
*** POTENTIAL INCOMPATIBILITY ***
Added support for socket functions
recvmmsg()andsendmmsg().Own Id: OTP-20015
Application(s): erts, kernel
Related Id(s): PR-10564
m:erl_tarwill use less memory when extracting large tar entries to disk. Instead of reading each tar entry into memory,erl_tarwill now stream data in chunks of 64KB. The chunk size is settable using the new{chunks,ChunkSize}option.The new
{max_size,Size}option will set a limit on the total size of extracted data to protect against filling up the disk.Checking of symlinks has been improved. Some symlinks that were safe (such as
dir/link -> ../file) used to be rejected.Own Id: OTP-20023
Application(s): stdlib
Related Id(s): PR-10814, PR-10818, PR-10821
Added a new module called
io_ansithat allows the user to emit Virtual Terminal Sequences (a.k.a. ANSI sequences) to the terminal in order to add colors/styling to text or create fully-fledged terminal applications.io_ansiuses the local terminfo database in order to be as cross-platform compatible as possible.It also works across nodes so that if functions on a remote node call
io_ansi:fwrite/1it will use the destination terminal's terminfo database to determine which sequences to emit. In practice, this means that you can call functions in a remote shell session that useio_ansiand it will properly detect the terminal sequences the target terminal can handle and will print using them correctly.Own Id: OTP-20028
Application(s): kernel, stdlib
Related Id(s): PR-10905, PR-9940
The
ignore_xrefattribute has been handled as a post-analysis filter by build tools such as Rebar3. In this release,xrefitself does the filtering, ensuring that all tooling that callsxreffor any purpose can rely on these declarations to just work.Own Id: OTP-20032
Application(s): tools
Related Id(s): PR-10592
New in this release is
ct_doctest, a module that allows the user to test documentation examples in Erlang module docs and documentation files.ct_doctest allows you to:
edoc,asciidoc, and others can also be tested.See the documentation for more details.
Own Id: OTP-20034
Application(s): common_test
Related Id(s): PR-10824, PR-9315
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Application(s): asn1, common_test, compiler, crypto, debugger, dialyzer, diameter, edoc, eunit, inets, kernel, megaco, mnesia, observer, odbc, os_mon, otp, parsetools, public_key, reltool, runtime_tools, sasl, ssh, ssl, stdlib, syntax_tools, tftp, tools, wx, xmerl
Related Id(s): PR-10839
The post-quantum hybrid algorithm x25519mlkem768 is now the most preferred key exchange group in the default configuration.
Post-quantum hybrid algorithms secp384r1mlkem1024 and secp256r1mlkem768 are supported but have to be configured. The same goes for the plain post-quantum algorithms mlkem1024, mlkem768, and mlkem512.
The most preferred signature algorithms is now post-quantum algorithms ML-DSA followed by the fastest SLH-DSA (slh_dsa_sha2_256f) algorithm, if such a certificate is available in the configuration. Other SLH-DSA variants are also supported but are added to the end of the preferred list.
All these algorithms were available in OTP-28.4 but none of them were preferred and some of them changed default status.
Own Id: OTP-20070
Application(s): ssl
Related Id(s): PR-10949
*** POTENTIAL INCOMPATIBILITY ***
The
jsonmodule now encodes and decodes quoted strings faster. Improvements of up to 55 percent has been measured when decoding JSON data with long strings.The
string:length/1,string:slice/2, andstring:slice/3functions have been optimized. For some strings, they can be up to twice as fast.Own Id: OTP-20072
Application(s): stdlib
Related Id(s): PR-10938, PR-10948
The SFTP subsystem is no longer enabled by default when starting an SSH daemon. To enable it, add the subsystems option explicitly:
Own Id: OTP-20078
Application(s): ssh
Related Id(s): PR-10970
*** POTENTIAL INCOMPATIBILITY ***
The runtime system now supports generating encrypted crash dumps. See the description of
--enable-encrypted-crash-dumpsin Building and Installing Erlang/OTP.Own Id: OTP-20085
Application(s): crypto, erts, public_key, tools
Related Id(s): PR-10993
There is a new Hardening guide giving guidelines on how to strengthen the security for the
sslapplication.Own Id: OTP-20087
Application(s): ssl
Related Id(s): PR-11019
There is a new Hardening guide with advice for configuring Inets to be more secure.
Own Id: OTP-20133
Application(s): inets
Related Id(s): PR-11073
POTENTIAL INCOMPATIBILITIES
Fixed (
inet) module selection when calling (gen_tcp) listen and connect and (gen_udp) open. Depending on the order of the options, the module option (tcp_moduleorudp_module) was sometimes ignored.Own Id: OTP-19695
Application(s): kernel
Related Id(s): GH-9822, PR-10013
ssh:stop_deamonnow usessupervisor:stopfor shutting down daemons. With this change, the scenario whenssh:stop_daemonis called for a non-existing process results in calling process exiting. Previously an error tuple was returned (which was not documented).Own Id: OTP-19801
Application(s): ssh
Related Id(s): PR-10253
The
mnesia_registrymodule has been removed.Own Id: OTP-19807
Application(s): mnesia
Related Id(s): PR-7315
In the default code path for the Erlang system, the current working directory (
.) is now in the last position instead of the first.Own Id: OTP-19842
Application(s): erts, kernel
*** HIGHLIGHT ***
Before Erlang/OTP 29, attempting to bind variables in a comprehension would compile successfully but fail at runtime. Example:
In Erlang/OTP 29, attempting to bind a variable in a comprehension will fail by default:
However, this example will work as expected if the
compr_assignfeature is enabled when starting the runtime system:Here is another example how
compr_assigncan be used:Own Id: OTP-19927
Application(s): compiler, stdlib
Related Id(s): PR-9153
*** HIGHLIGHT ***
The default key exchange algorithm is now mlkem768x25519-sha256, a hybrid quantum-resistant algorithm combining ML-KEM-768 with X25519. This provides protection against both classical and quantum computer attacks while maintaining backward compatibility through automatic fallback to other algorithms when peers don't support it.
Own Id: OTP-19965
Application(s): ssh
Related Id(s): PR-10656
*** HIGHLIGHT ***
The SSH daemon now defaults to disabled for shell and exec services, implementing the "secure by default" principle. This prevents authenticated users from executing arbitrary Erlang code unless explicitly configured.
Applications requiring shell or exec functionality must now explicitly enable:
Own Id: OTP-19969
Application(s): ssh
Related Id(s): ERIERL-1319, PR-10970, PR-11080
*** HIGHLIGHT ***
Changed
ets:update_counter/4andets:update_element/4to always reject default tuples smaller than thekeyposof the table. Such keyless tuples are now rejected even if the key exists in the table and the default tuple would not be used. This is a subtle semantic change but is a nicer behavior for development and testing as it will detect faulty default tuple arguments earlier.Own Id: OTP-19975
Application(s): erts
Related Id(s): PR-10674
Added explicit size validation guards for pre-authentication SSH messages to improve defense-in-depth against DoS attacks. Messages now have per-field size limits based on RFC specifications:
This change enhances the existing 256KB global packet size limit with granular per-message validation. Compliant implementations are not affected.
Own Id: OTP-19995
Application(s): ssh
Related Id(s): PR-10739
The
arraymodule have been extended with several new functions. The internal representation have been changed to allow the new functionality and optimizations. Arrays serialized withterm_to_binary/1in previous releases are not compatible.Own Id: OTP-20004
Application(s): stdlib
Related Id(s): PR-10578
*** HIGHLIGHT ***
The SFTP subsystem
rootoption now properly rejects relative paths at daemon startup. Previously, relative paths would cause unpredictable behavior as file operations resolved relative to the Erlang VM's current working directory. The option now requires an absolute path or empty string.Own Id: OTP-20019
Application(s): ssh
Related Id(s): PR-10820
The
gb_sets:from_ordset/1andgb_trees:from_orddict/1functions would trust their inputs. If the input contained duplicates or was not properly sorted, the resulting gb_set or gb_tree would be invalid, and any number of interesting problems could occur.In this release, these functions will raise an exception if their input is not valid. That could mean that incorrect programs that seemed to work could now stop working altogether.
There is also a new
gb_trees:from_list/1function for directly creating a gb_tree from a list.Own Id: OTP-20061
Application(s): stdlib
Related Id(s): PR-10910
The post-quantum hybrid algorithm x25519mlkem768 is now the most preferred key exchange group in the default configuration.
Post-quantum hybrid algorithms secp384r1mlkem1024 and secp256r1mlkem768 are supported but have to be configured. The same goes for the plain post-quantum algorithms mlkem1024, mlkem768, and mlkem512.
The most preferred signature algorithms is now post-quantum algorithms ML-DSA followed by the fastest SLH-DSA (slh_dsa_sha2_256f) algorithm, if such a certificate is available in the configuration. Other SLH-DSA variants are also supported but are added to the end of the preferred list.
All these algorithms were available in OTP-28.4 but none of them were preferred and some of them changed default status.
Own Id: OTP-20070
Application(s): ssl
Related Id(s): PR-10949
*** HIGHLIGHT ***
The old Tcl-based implementation of
erl_errno_id()has been replaced by our own implementation now supporting moreerrnovalues on modern operating systems. It also returns the string"errno_<ERRNO_INTEGER>"corresponding to the integer given as argument if theerrnointeger is unknown instead of as previously just return the string"unknown".The result of
erl_errno_id()is often converted into an atom and passed as an error from a driver or a NIF.Own Id: OTP-20076
Application(s): erts
Related Id(s): PR-10958, PR-10969
The SFTP subsystem is no longer enabled by default when starting an SSH daemon. To enable it, add the subsystems option explicitly:
Own Id: OTP-20078
Application(s): ssh
Related Id(s): PR-10970
*** HIGHLIGHT ***
Secure renegotiation for TLS-1.2 specified in RFC 5746 from 2010 is now always used. The interoperability fallback option
{secure_renegotiate,SecureRenegotiate}is no longer needed.Own Id: OTP-20080
Application(s): ssl
Related Id(s): PR-10979
The
erlang:suspend_process/1anderlang:suspend_process/2BIFs now also suspend BIF timers that will send messages to the process if the timer was created using the PID of the process as destination. Timers created using registered names are not affected.Own Id: OTP-20095
Application(s): erts
Related Id(s): PR-10619, PR-11004
The TOS handling on socket has been significantlyupdated and improved. Socket did not properly handle set, get and recv (cmsg) of TOS.
Note that the returned TOS value has been changed. It was previously an atom or an integer. Now it is a map with different interpretations of the TOS octet. See the documentation.
Own Id: OTP-20102
Application(s): erts, kernel
Related Id(s): GH-10968, PR-11059
OTP-29.0
Fixed Bugs and Malfunctions
The
start_erlscript will now work on embedded systems.Own Id: OTP-20111
Related Id(s): GH-10342, PR-10346
Improvements and New Features
Vendor dependencies and OpenVEX statements in the
otprepository is now scanned for vulnerabilities. It is verified that OTP security issues reported at Github exist in the published OpenVEX statements, and issues are automatically opened in theotprepository if vendor vulnerabilities are detected.Own Id: OTP-19763
Related Id(s): PR-10145, PR-10166, PR-10168, PR-10189, PR-10193, PR-10195, PR-10197, PR-10202, OTP-19652, OTP-19775, OTP-19779
Documentation about how to validate the SBOM using sigstore has been added.
Own Id: OTP-19766
Related Id(s): GH-10151, PR-10187
The old-style type tests in guards (
integer,atom, and so on) have been scheduled for removal in Erlang/OTP 30. They have been deprecated for a long time.Own Id: OTP-19887
Related Id(s): PR-10417
*** HIGHLIGHT ***
Removed the undocumented
dyn_erlutility.Own Id: OTP-19933
Related Id(s): PR-10573
There is no longer a 32-bit Erlang/OTP build for Windows.
Own Id: OTP-19960
*** HIGHLIGHT ***
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
The Upcoming Potential Incompatibilities page has been updated to note that in Erlang/OTP 30,
erlang:fun_info(Fun, pid)will no longer retrieve a pid, but will raise abadargexception.Own Id: OTP-20092
Related Id(s): PR-10998
Add security improvements to GitHub Actions workflows based on findings from
zizmor, a GitHub Actions security linter.Own Id: OTP-20103
Related Id(s): PR-11000
Improve mermaid diagram rending in documentation.
Own Id: OTP-20132
Related Id(s): PR-11047
asn1-5.5
Improvements and New Features
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
common_test-1.31
Fixed Bugs and Malfunctions
Improved support for QuickCheck when writing property tests.
Own Id: OTP-20010
Related Id(s): PR-10783
Improvements and New Features
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
'EXIT'messages are now formatted in the same way asbadmatcherrors.Own Id: OTP-19910
Related Id(s): PR-10277
Error notifications now contain the name of the source file in which the error occurred.
Own Id: OTP-19925
Related Id(s): GH-10260, PR-10269
New in this release is
ct_doctest, a module that allows the user to test documentation examples in Erlang module docs and documentation files.ct_doctest allows you to:
edoc,asciidoc, and others can also be tested.See the documentation for more details.
Own Id: OTP-20034
Related Id(s): PR-10824, PR-9315
*** HIGHLIGHT ***
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
compiler-10.0
Fixed Bugs and Malfunctions
For a function such as the following:
the compiler would keep all of the calls to
setelement/3and emit extra unnecessaryset_tuple_elementinstructions.This has been corrected so that the compiler will never emit code that uses the
set_tuple_elementinstruction. In a future release, support for theset_tuple_elementwill be removed from the runtime system.Own Id: OTP-19751
Related Id(s): GH-10125, PR-10144
beam_lib:strip/1will now retain the Beam debug information chunk produced by thebeam_debug_infooption. The chunk will also be retained when combing thebeam_debug_infooption with the undocumentedslimoption.The runtime system will no longer crash when attempting to load modules that have been compiled with
beam_debug_infobut lack the actual Beam debug info chunk.Own Id: OTP-19991
Related Id(s): GH-10557, PR-10735
Improvements and New Features
In comprehensions, a generator that builds a list with a single element will now be optimized to avoid building and matching the list. Example:
Own Id: OTP-19672
Related Id(s): PR-9934
In the documentation for the
compilemodule, a section has been added with recommendations for implementors of languages running on the BEAM. Documentation has also been added for theto_abstr,to_exp, andfrom_abstroptions.The documentation for erlc now lists
.abstras one of the supported options.When compiling with the
to_abstroption, the resulting.abstrfile now retains any-docattributes present in the source code.Own Id: OTP-19784
Related Id(s): PR-10230, PR-10234
*** HIGHLIGHT ***
Native records as described in EEP-79 has been implemented.
A native record is a data structure similar to the traditional tuple-based records, except that is a true data type.
Native records are considered experimental in Erlang/OTP 29 and possibly also in Erlang/OTP 30, meaning that their behavior may change, potentially requiring updates to applications that use them.
Own Id: OTP-19785
Related Id(s): PR-10617
*** HIGHLIGHT ***
The guard BIF
is_integer/3has been added. It follows the design of the original EEP-16, only changing the name fromis_betweentois_integer. This BIF takes in 3 parameters,Term,LowerBound, andUpperBound.It returns
trueifTerm,LowerBound, andUpperBoundare all integers, andLowerBound =< Term =< UpperBound; otherwise, it returns false.Example:
Own Id: OTP-19809
Related Id(s): PR-10276
*** HIGHLIGHT ***
Function application is now left associative. That means one can now write:
instead of:
Own Id: OTP-19866
Related Id(s): PR-9223
*** HIGHLIGHT ***
There will now be a warning when exporting variables out of a subexpression. For example:
To avoid the warning, this can be rewritten to:
The warning can be suppressed by giving option
nowarn_export_var_subexprto the compiler.Own Id: OTP-19898
Related Id(s): PR-9134
*** HIGHLIGHT ***
There is a new option
warn_obsolete_bool_opthat instruct the compiler to emit warnings for theandandoroperators. It is recommended to instead use the modernandalsoandorelseoperators, or,and;in guards.Own Id: OTP-19918
Related Id(s): PR-9115
*** HIGHLIGHT ***
Before Erlang/OTP 29, attempting to bind variables in a comprehension would compile successfully but fail at runtime. Example:
In Erlang/OTP 29, attempting to bind a variable in a comprehension will fail by default:
However, this example will work as expected if the
compr_assignfeature is enabled when starting the runtime system:Here is another example how
compr_assigncan be used:Own Id: OTP-19927
Related Id(s): PR-9153
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
There will now be a warning when using the
catchoperator, which has been deprecated for a long time.It is recommended to instead use
try...catch...endbut is also possible to disable the warning by using thenowarn_deprecated_catchoption.Own Id: OTP-19938
Related Id(s): PR-10421
*** HIGHLIGHT ***
Multi-valued comprehensions according to EEP 78 has been implemented.
Example:
Own Id: OTP-19942
Related Id(s): PR-9374
*** HIGHLIGHT ***
There will now be a warning for matches that unify constructors, such as the following:
Such a match can be rewritten to:
The compiler option
nowarn_match_alias_patscan be used to disable the warning.Own Id: OTP-19943
Related Id(s): PR-10433
*** HIGHLIGHT ***
The compiler now generates more efficient code for map comprehensions with constant values that don't depend on the generator, such as the following:
Own Id: OTP-19968
Related Id(s): PR-10646
*** HIGHLIGHT ***
Compilation times of modules with a huge number of calls to
element/2has been improved.Own Id: OTP-20020
Related Id(s): GH-10807, PR-10819
The format of the debug information stored by the
beam_debug_infooption (used by the edb debugger) has been updated to more easily extendible and to contain more information about call targets. (See the linked PR for more details.)Own Id: OTP-20048
Related Id(s): PR-9814
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
crypto-5.9
Fixed Bugs and Malfunctions
Fixed
crypto:hash_equals/2and FIPS when crypto is statically linked to the beam (with--enable-static-nifsand--disable-dynamic-ssl-lib).Own Id: OTP-20025
Related Id(s): PR-10817
Improvements and New Features
The
rand:bytes/1andrand:bytes_s/2functions have been optimized by implementing a new internal callback function thatcrypto:rand_seed_alg/1andcrypto:alg_seed_alg_s/1have been updated to use.A new algorithm
crypto_prng1, which also takes advantage of this new internal callback, has been added tocrypto:rand_seed_alg/2andcrypto:rand_seed_alg_s/2. It is much faster then the existingcrypto_aes, in particular for generating bytes.Own Id: OTP-19882
Related Id(s): PR-10453, OTP-19827
In interactive mode, application
cryptois automatically loaded when thecryptomodule is loaded. This will ensure that the correct value of configuration parameterfips_modeis used to initialize OpenSSL if modulecryptois called/loaded before the applicationcryptohas been loaded. In embedded mode, modulecryptowill fail to load if the application has not been loaded.Own Id: OTP-20035
Related Id(s): PR-10830
OpenSSL engine support has been removed on Windows.
Own Id: OTP-20036
Related Id(s): PR-10836
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
The runtime system now supports generating encrypted crash dumps. See the description of
--enable-encrypted-crash-dumpsin Building and Installing Erlang/OTP.Own Id: OTP-20085
Related Id(s): PR-10993
*** HIGHLIGHT ***
debugger-7.0
Improvements and New Features
Native records as described in EEP-79 has been implemented.
A native record is a data structure similar to the traditional tuple-based records, except that is a true data type.
Native records are considered experimental in Erlang/OTP 29 and possibly also in Erlang/OTP 30, meaning that their behavior may change, potentially requiring updates to applications that use them.
Own Id: OTP-19785
Related Id(s): PR-10617
*** HIGHLIGHT ***
Tools such as the debugger,
beam_lib, andxrefno longer support BEAM files created before OTP 13B.Own Id: OTP-19906
Related Id(s): PR-10519
Multi-valued comprehensions according to EEP 78 has been implemented.
Example:
Own Id: OTP-19942
Related Id(s): PR-9374
*** HIGHLIGHT ***
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
dialyzer-6.0
Improvements and New Features
Native records as described in EEP-79 has been implemented.
A native record is a data structure similar to the traditional tuple-based records, except that is a true data type.
Native records are considered experimental in Erlang/OTP 29 and possibly also in Erlang/OTP 30, meaning that their behavior may change, potentially requiring updates to applications that use them.
Own Id: OTP-19785
Related Id(s): PR-10617
*** HIGHLIGHT ***
The guard BIF
is_integer/3has been added. It follows the design of the original EEP-16, only changing the name fromis_betweentois_integer. This BIF takes in 3 parameters,Term,LowerBound, andUpperBound.It returns
trueifTerm,LowerBound, andUpperBoundare all integers, andLowerBound =< Term =< UpperBound; otherwise, it returns false.Example:
Own Id: OTP-19809
Related Id(s): PR-10276
*** HIGHLIGHT ***
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
diameter-2.7
Improvements and New Features
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
edoc-1.5
Improvements and New Features
Changed behavior of EDoc so that when a module defines a private type and a private function spec uses it, that type no longer gets included in the EDoc chunk.
Own Id: OTP-20030
Related Id(s): PR-10770
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
eldap-1.3
Improvements and New Features
Only minor internal changes.
Own Id: OTP-19964
erl_interface-5.8
Improvements and New Features
Improved name consistency of EPMD protocol messages in documentation and code. Renamed
PORT_PLEASE2_REQtoPORT2_REQand added prefixEPMD_.Own Id: OTP-19734
Related Id(s): GH-10071, PR-10078
Replaced embedded OpenSSL MD5 implementation.
Own Id: OTP-20045
Related Id(s): PR-10870
Known Bugs and Problems
The
eiAPI for decoding/encoding terms is not fully 64-bit compatible since terms that have a representation on the external term format larger than 2 GB cannot be handled.Own Id: OTP-16607
Related Id(s): OTP-16608
erts-17.0
Fixed Bugs and Malfunctions
For a function such as the following:
the compiler would keep all of the calls to
setelement/3and emit extra unnecessaryset_tuple_elementinstructions.This has been corrected so that the compiler will never emit code that uses the
set_tuple_elementinstruction. In a future release, support for theset_tuple_elementwill be removed from the runtime system.Own Id: OTP-19751
Related Id(s): GH-10125, PR-10144
Improved the handling of the logging directory for the start script on Unix-like systems, so that it no longer crashes when
$ROOTDIR/logis not writable.Own Id: OTP-19874
Related Id(s): GH-10341, PR-10348
The
-nocookieoption forerlis now documented.Own Id: OTP-19935
Related Id(s): PR-10549
beam_lib:strip/1will now retain the Beam debug information chunk produced by thebeam_debug_infooption. The chunk will also be retained when combing thebeam_debug_infooption with the undocumentedslimoption.The runtime system will no longer crash when attempting to load modules that have been compiled with
beam_debug_infobut lack the actual Beam debug info chunk.Own Id: OTP-19991
Related Id(s): GH-10557, PR-10735
Fixed potential symbol clashing on MacOS by passing
RTLD_LOCALtodlopen. This will make symbols to not be resolvable between subsequently loaded NIF/drivers, which is the default behavior on Linux and BSD.Own Id: OTP-20026
Related Id(s): PR-10805
The
configurescript used to callisfinite()with argument0. That could fail on some platforms. This has been changed to callisfinite()with1.0instead.Own Id: OTP-20088
Related Id(s): PR-10965
The TOS handling on socket has been significantlyupdated and improved. Socket did not properly handle set, get and recv (cmsg) of TOS.
Note that the returned TOS value has been changed. It was previously an atom or an integer. Now it is a map with different interpretations of the TOS octet. See the documentation.
Own Id: OTP-20102
Related Id(s): GH-10968, PR-11059
*** POTENTIAL INCOMPATIBILITY ***
Fixed
erlang:md5_initto always return the same deterministic context binary. Only an issue in OTP 28.5 when OTP was built with--disable-builtin-opensslor--enable-use-embedded-3pp-alternatives.Own Id: OTP-20123
Added explicit configure test for C++ function
std::to_charsif options--disable-builtin-ryuor--enable-use-embedded-3pp-alternativesis used.Own Id: OTP-20126
Related Id(s): PR-11067
Improvements and New Features
The exported name space of the
beamexecutable has been cleaned to only expose symbols of documented interfaces like NIF and driver APIs. This will avoid accidental name clashes with, for example, our statically linked variants of PCRE2 and ZSTD. NIFs and drivers that abuse undocumented internal interfaces will fail to load due to this change.Own Id: OTP-19643
Related Id(s): PR-9864
Improved name consistency of EPMD protocol messages in documentation and code. Renamed
PORT_PLEASE2_REQtoPORT2_REQand added prefixEPMD_.Own Id: OTP-19734
Related Id(s): GH-10071, PR-10078
The JIT now generates better code for matching or creating binaries with multiple little-endian segments.
Own Id: OTP-19747
Related Id(s): PR-10126
*** HIGHLIGHT ***
In the documentation for the
compilemodule, a section has been added with recommendations for implementors of languages running on the BEAM. Documentation has also been added for theto_abstr,to_exp, andfrom_abstroptions.The documentation for erlc now lists
.abstras one of the supported options.When compiling with the
to_abstroption, the resulting.abstrfile now retains any-docattributes present in the source code.Own Id: OTP-19784
Related Id(s): PR-10230, PR-10234
*** HIGHLIGHT ***
Native records as described in EEP-79 has been implemented.
A native record is a data structure similar to the traditional tuple-based records, except that is a true data type.
Native records are considered experimental in Erlang/OTP 29 and possibly also in Erlang/OTP 30, meaning that their behavior may change, potentially requiring updates to applications that use them.
Own Id: OTP-19785
Related Id(s): PR-10617
*** HIGHLIGHT ***
Task stealing between schedulers has been further optimized.
Own Id: OTP-19793
Related Id(s): PR-9984
The guard BIF
is_integer/3has been added. It follows the design of the original EEP-16, only changing the name fromis_betweentois_integer. This BIF takes in 3 parameters,Term,LowerBound, andUpperBound.It returns
trueifTerm,LowerBound, andUpperBoundare all integers, andLowerBound =< Term =< UpperBound; otherwise, it returns false.Example:
Own Id: OTP-19809
Related Id(s): PR-10276
*** HIGHLIGHT ***
Calls to
trace:info(_, {M,F,A}, Item), withItemascall_time,call_memory, orall, will no longer block all scheduler threads from running.Own Id: OTP-19811
Related Id(s): PR-10207
Full support for SCTP in
socket. Not (yet) supported for FreeBSD.Own Id: OTP-19834
In the default code path for the Erlang system, the current working directory (
.) is now in the last position instead of the first.Own Id: OTP-19842
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
Tools such as the debugger,
beam_lib, andxrefno longer support BEAM files created before OTP 13B.Own Id: OTP-19906
Related Id(s): PR-10519
Optimized ETS named table lookup scalability by replacing read locks with lockless atomic operations.
Own Id: OTP-19919
Related Id(s): PR-7118
Removed the undocumented
dyn_erlutility.Own Id: OTP-19933
Related Id(s): PR-10573
Added
zstd:flush/2for flushing compressed data without closing the compression context.Own Id: OTP-19936
Related Id(s): GH-10345, PR-10511
While the iteration order for maps is undefined, it is now guaranteed that all ways of iterating over maps provides the elements in the same order. That is, all of the following ways of iterating will produce the elements in the same order:
maps:keys/1maps:values/1maps:to_list/1maps:to_list(maps:iterator(M))[{K,V} || K := V <- M]Own Id: OTP-19963
Related Id(s): PR-10626
*** HIGHLIGHT ***
Improved the performance of code loading.
Own Id: OTP-19966
Related Id(s): PR-10615
Changed
ets:update_counter/4andets:update_element/4to always reject default tuples smaller than thekeyposof the table. Such keyless tuples are now rejected even if the key exists in the table and the default tuple would not be used. This is a subtle semantic change but is a nicer behavior for development and testing as it will detect faulty default tuple arguments earlier.Own Id: OTP-19975
Related Id(s): PR-10674
*** POTENTIAL INCOMPATIBILITY ***
Improved compatibility with systems that lack certain shell utilities.
Own Id: OTP-20002
Related Id(s): PR-10647
It was previously not possible to check on the socket nif load result. A successful load was self-evident, but a failure was only visible from the fact that most
socketfunctions failed withnotsup. This has now been improved such that the (socket nif) load result is visible in the info map (fromsocket:info/0).Own Id: OTP-20003
The default for the
configureoption--{enable,disable}-use-embedded-3pp-alternativeshas changed and the subset of embedded third-party products (3pps) affected by it has also changed. Currently this option affectszstd,zlib,ryu(withSTL). By defaultzstdandzlibavailable on the OS will be used if they fulfill the requirements. The builtinryu(withSTL) will be used by default. The 3ppsopensslandtclthat previously were present have been replaced by our own implementations.Requirements for the affected 3pps alternatives are still the same as before:
zstd- Static library and include files of at least version 1.5.6 needs to be available.zlib- Library and include files of at least version 1.2.5 needs to be available.ryu(withSTL) - A usable C++ compiler with C++17 library support.Own Id: OTP-20013
Related Id(s): PR-10894, PR-10986, OTP-20106
Added support for socket functions
recvmmsg()andsendmmsg().Own Id: OTP-20015
Related Id(s): PR-10564
*** HIGHLIGHT ***
There is a new NIF function
enif_term_size().Own Id: OTP-20016
Related Id(s): PR-10782
Call trace match specs can use
[Arg1, Arg2 | '_']syntax to match functions with at least N number of arguments.Own Id: OTP-20017
Related Id(s): PR-10754
Replaced embedded OpenSSL MD5 implementation.
Own Id: OTP-20045
Related Id(s): PR-10870
The format of the debug information stored by the
beam_debug_infooption (used by the edb debugger) has been updated to more easily extendible and to contain more information about call targets. (See the linked PR for more details.)Own Id: OTP-20048
Related Id(s): PR-9814
There are new functions
erlang:exit_signal/2,3replacing the olderlang:exit/2,3. The primary purpose is better naming to distinguish between exit exceptions and exit signals. The newexit_signalfunctions will also avoid a historical quirk when a process sends an exit signal to itself with reasonnormal.The old
erlang:exit/2,3will work as before, but it is recommended to use the newexit:signal/2,3functions for new or modified code. Deprecation oferlang:exit/2,3with a compiler warning is planned for OTP 30.Own Id: OTP-20069
Related Id(s): PR-10801
The old Tcl-based implementation of
erl_errno_id()has been replaced by our own implementation now supporting moreerrnovalues on modern operating systems. It also returns the string"errno_<ERRNO_INTEGER>"corresponding to the integer given as argument if theerrnointeger is unknown instead of as previously just return the string"unknown".The result of
erl_errno_id()is often converted into an atom and passed as an error from a driver or a NIF.Own Id: OTP-20076
Related Id(s): PR-10958, PR-10969
*** POTENTIAL INCOMPATIBILITY ***
The runtime system now supports generating encrypted crash dumps. See the description of
--enable-encrypted-crash-dumpsin Building and Installing Erlang/OTP.Own Id: OTP-20085
Related Id(s): PR-10993
*** HIGHLIGHT ***
When implementing an alternate distribution implementors can now use an alternate handshake complete fun of arity 4 if needed.
Own Id: OTP-20090
Related Id(s): PR-10478
The
erlang:suspend_process/1anderlang:suspend_process/2BIFs now also suspend BIF timers that will send messages to the process if the timer was created using the PID of the process as destination. Timers created using registered names are not affected.Own Id: OTP-20095
Related Id(s): PR-10619, PR-11004
*** POTENTIAL INCOMPATIBILITY ***
Added support for socket option SO_TIMESTAMPNS (not available on all platforms).
Own Id: OTP-20115
Related Id(s): PR-10929
et-1.8
Improvements and New Features
Only minor internal changes.
Own Id: OTP-19964
eunit-2.11
Improvements and New Features
Added
randomDelaymacro.Own Id: OTP-19997
Related Id(s): PR-10614
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
ftp-1.2.5
Fixed Bugs and Malfunctions
The
odbcapplication is now deprecated and is planned to be removed in Erlang/OTP 30.The
ftpandct_ftpmodules are now deprecated and are planned to be removed in Erlang/OTP 30.Own Id: OTP-19980
Related Id(s): PR-10804
*** HIGHLIGHT ***
inets-9.7
Fixed Bugs and Malfunctions
A call to httpd:reload_config/2 now validates the new configuration before removing the old one, leaving the server running in case of faulty config, instead of putting it in an unrecoverable state.
Own Id: OTP-20128
Related Id(s): ERIERL-1314, PR-11079
Improvements and New Features
A new option
max_connections_openhas been added to thehttpcHTTP client profile configuration. It limits the maximum number of concurrent HTTP handler processes that can be open simultaneously.When the limit is reached, new requests are queued internally and started automatically as existing handlers complete. This prevents bandwidth exhaustion in high-load scenarios where too many parallel connections cause remote servers to close sockets before transfers finish (the socket_closed_remotely error).
The option can be set via
httpc:set_options([{max_connections_open, 10}], Profile).The default value is
infinity(unlimited), preserving backward compatibility. The value must be a positive integer orinfinityand must be greater than or equal tomax_sessions.Own Id: OTP-19587
Related Id(s): GH-8841, PR-9712
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
The
mod_cgiandmod_actionsmodules are now deprecated and are scheduled to be removed in OTP 30.Own Id: OTP-20071
Related Id(s): PR-10950
There is a new Hardening guide with advice for configuring Inets to be more secure.
Own Id: OTP-20133
Related Id(s): PR-11073
*** HIGHLIGHT ***
jinterface-1.16
Improvements and New Features
The
jinterfacebuild now honorsSOURCE_DATE_EPOCHfor deterministic build ofOtpErlang.jar.Own Id: OTP-19956
Related Id(s): PR-10556
Removed prebuilt java files from source tar file to avoid issues with different version of the java runtime.
Own Id: OTP-20073
Related Id(s): PR-10951
kernel-11.0
Fixed Bugs and Malfunctions
Fixed (
inet) module selection when calling (gen_tcp) listen and connect and (gen_udp) open. Depending on the order of the options, the module option (tcp_moduleorudp_module) was sometimes ignored.Own Id: OTP-19695
Related Id(s): GH-9822, PR-10013
*** POTENTIAL INCOMPATIBILITY ***
The TCP/UDP compatibility layer has been fixed so that
inet_backend = socketnow supports socket optionsreuseportandreuseport_lbforgen_tcpandgen_udp.Own Id: OTP-19917
Related Id(s): PR-10514
Some errors in config files for the application controller would result in very cryptic crashes. Error handling has been improved to ensure that the file name and line number of the offending token are now printed.
Own Id: OTP-20054
Related Id(s): GH-10214, PR-10259
The TOS handling on socket has been significantlyupdated and improved. Socket did not properly handle set, get and recv (cmsg) of TOS.
Note that the returned TOS value has been changed. It was previously an atom or an integer. Now it is a map with different interpretations of the TOS octet. See the documentation.
Own Id: OTP-20102
Related Id(s): GH-10968, PR-11059
*** POTENTIAL INCOMPATIBILITY ***
Replaced a sleep clause in user_drv shutdown with a flush of the output buffer.
Own Id: OTP-20124
Related Id(s): PR-10808
Improvements and New Features
Added an option to set the
erl_boot_serverlisten port.Own Id: OTP-19708
Related Id(s): PR-9894
The memory footprint of some supervisors has been reduced by purging obsoleted data when the supervisor is transitioning to and from hibernation.
Own Id: OTP-19713
Related Id(s): PR-9866
Improved name consistency of EPMD protocol messages in documentation and code. Renamed
PORT_PLEASE2_REQtoPORT2_REQand added prefixEPMD_.Own Id: OTP-19734
Related Id(s): GH-10071, PR-10078
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
Refactored a
kernel_load_completedclause in theinitmodule for conciseness.Own Id: OTP-19786
Related Id(s): PR-10134
Full support for SCTP in
socket. Not (yet) supported for FreeBSD.Own Id: OTP-19834
In the default code path for the Erlang system, the current working directory (
.) is now in the last position instead of the first.Own Id: OTP-19842
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
It was previously not possible to check on the socket nif load result. A successful load was self-evident, but a failure was only visible from the fact that most
socketfunctions failed withnotsup. This has now been improved such that the (socket nif) load result is visible in the info map (fromsocket:info/0).Own Id: OTP-20003
Added support for socket functions
recvmmsg()andsendmmsg().Own Id: OTP-20015
Related Id(s): PR-10564
*** HIGHLIGHT ***
Added a new module called
io_ansithat allows the user to emit Virtual Terminal Sequences (a.k.a. ANSI sequences) to the terminal in order to add colors/styling to text or create fully-fledged terminal applications.io_ansiuses the local terminfo database in order to be as cross-platform compatible as possible.It also works across nodes so that if functions on a remote node call
io_ansi:fwrite/1it will use the destination terminal's terminfo database to determine which sequences to emit. In practice, this means that you can call functions in a remote shell session that useio_ansiand it will properly detect the terminal sequences the target terminal can handle and will print using them correctly.Own Id: OTP-20028
Related Id(s): PR-10905, PR-9940
*** HIGHLIGHT ***
Polished the documentation groups, essentially removed groups that did nothing but obscure the documentation.
Own Id: OTP-20029
Related Id(s): PR-10755
Added a new behavior,
data_publisher, for building eventually consistent, replicated data stores across distributed nodes. This is a generalization of thepgmodule.Own Id: OTP-20055
Related Id(s): PR-10426
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
When implementing an alternate distribution implementors can now use an alternate handshake complete fun of arity 4 if needed.
Own Id: OTP-20090
Related Id(s): PR-10478
Added support for socket option SO_TIMESTAMPNS (not available on all platforms).
Own Id: OTP-20115
Related Id(s): PR-10929
Added a flag
log_missed_net_ticks = true | falsethat controls whether a warning is logged for each missed sub-tick on a distribution connection. A sub-tick is missed when no data has been received from a connected node during one tick interval. A warning is emitted on every subsequent missed sub-tick until the node is declared down afternet_tickintensityconsecutive missed sub-ticks, at which point a final timeout warning is always logged regardless of this setting. Defaults tofalse.Own Id: OTP-20117
Related Id(s): PR-11031
megaco-4.9
Fixed Bugs and Malfunctions
Running Dialyzer on Windows in an Erlang repo, causes Dialyzer warnings for the megaco_flex_scanner module. This is because the flex scanner is not built on Windows. These warnings are now suppressed.
Own Id: OTP-20114
Related Id(s): PR-11025
Improvements and New Features
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
mnesia-4.26
Improvements and New Features
mnesianow has new functionsselect_reverse/1-6supporting iteration over tables in reverse order.Own Id: OTP-19611
Related Id(s): GH-8993, PR-9475
The
mnesia_registrymodule has been removed.Own Id: OTP-19807
Related Id(s): PR-7315
*** POTENTIAL INCOMPATIBILITY ***
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
observer-2.19
Improvements and New Features
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
odbc-2.17
Fixed Bugs and Malfunctions
The
odbcapplication is now deprecated and is planned to be removed in Erlang/OTP 30.The
ftpandct_ftpmodules are now deprecated and are planned to be removed in Erlang/OTP 30.Own Id: OTP-19980
Related Id(s): PR-10804
*** HIGHLIGHT ***
Improvements and New Features
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
os_mon-2.12
Improvements and New Features
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
parsetools-2.8
Improvements and New Features
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
public_key-1.21
Improvements and New Features
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
Added an option for relaxed encoding of certificates to allow some values to be empty. This may be used by other applications for interoperability reasons. This option is not used by the
sslapplication.Own Id: OTP-19822
Related Id(s): PR-10033
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
The runtime system now supports generating encrypted crash dumps. See the description of
--enable-encrypted-crash-dumpsin Building and Installing Erlang/OTP.Own Id: OTP-20085
Related Id(s): PR-10993
*** HIGHLIGHT ***
reltool-1.1
Improvements and New Features
Removed the undocumented
dyn_erlutility.Own Id: OTP-19933
Related Id(s): PR-10573
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
runtime_tools-2.4
Improvements and New Features
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
sasl-4.4
Fixed Bugs and Malfunctions
UNC paths are now handled on Windows.
Own Id: OTP-19949
Related Id(s): PR-10601
Improvements and New Features
Removed the undocumented
dyn_erlutility.Own Id: OTP-19933
Related Id(s): PR-10573
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
snmp-5.20.3
Improvements and New Features
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
ssh-6.0
Fixed Bugs and Malfunctions
Password-based authentication has been updated to follow current security best practices. Key-based authentication remains recommended for production systems.
Own Id: OTP-19982
Related Id(s): PR-10571
Added explicit size validation guards for pre-authentication SSH messages to improve defense-in-depth against DoS attacks. Messages now have per-field size limits based on RFC specifications:
This change enhances the existing 256KB global packet size limit with granular per-message validation. Compliant implementations are not affected.
Own Id: OTP-19995
Related Id(s): PR-10739
*** POTENTIAL INCOMPATIBILITY ***
The SFTP subsystem
rootoption now properly rejects relative paths at daemon startup. Previously, relative paths would cause unpredictable behavior as file operations resolved relative to the Erlang VM's current working directory. The option now requires an absolute path or empty string.Own Id: OTP-20019
Related Id(s): PR-10820
*** POTENTIAL INCOMPATIBILITY ***
Dynamic atom creation has been replaced with static lookups in
ssh_transportandssh_connection, using a dedicated OID-to-algorithm mapping function inssh_message.Own Id: OTP-20127
Related Id(s): PR-11078
Improvements and New Features
Using KEX strict extension names as specified in draft-ietf-sshm-strict-kex-00. Pre standard names are still supported.
Own Id: OTP-19709
Related Id(s): PR-10115
Added an
aliveoption to detect and terminate dead SSH connections. Functionally equivalent to OpenSSH's ClientAlive*/ServerAlive* settings.Own Id: OTP-19750
Related Id(s): PR-10372, PR-9125
ssh:stop_deamonnow usessupervisor:stopfor shutting down daemons. With this change, the scenario whenssh:stop_daemonis called for a non-existing process results in calling process exiting. Previously an error tuple was returned (which was not documented).Own Id: OTP-19801
Related Id(s): PR-10253
*** POTENTIAL INCOMPATIBILITY ***
The default key exchange algorithm is now mlkem768x25519-sha256, a hybrid quantum-resistant algorithm combining ML-KEM-768 with X25519. This provides protection against both classical and quantum computer attacks while maintaining backward compatibility through automatic fallback to other algorithms when peers don't support it.
Own Id: OTP-19965
Related Id(s): PR-10656
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
The SSH daemon now defaults to disabled for shell and exec services, implementing the "secure by default" principle. This prevents authenticated users from executing arbitrary Erlang code unless explicitly configured.
Applications requiring shell or exec functionality must now explicitly enable:
Own Id: OTP-19969
Related Id(s): ERIERL-1319, PR-10970, PR-11080
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
Added SFTP resource limits section to hardening guide covering
max_handles,max_path, andmax_fileswith deployment recommendations.Own Id: OTP-20031
Related Id(s): PR-10838
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
The SFTP subsystem is no longer enabled by default when starting an SSH daemon. To enable it, add the subsystems option explicitly:
Own Id: OTP-20078
Related Id(s): PR-10970
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
The SSH hardening guide has been improved with a timeout overview table replacing the previous image, corrected terminology ("authenticated" instead of "authorized"), and new examples for loopback binding, public key user checking, and password lockout using ETS.
Own Id: OTP-20079
Related Id(s): PR-10970
With this change usage of
zlibcompression algorithm in SSH is deprecated and scheduled for removal in OTP 30.0Own Id: OTP-20099
Related Id(s): PR-11010
Updated SSH documentation with current OTP 29 algorithm defaults, including the new mlkem768x25519-sha256 post-quantum key exchange. Fixed stale examples, typos, and improved document structure.
Own Id: OTP-20100
Related Id(s): PR-11012
ssl-11.7
Fixed Bugs and Malfunctions
Add missing clauses to ssl_handshake:extension_value/1. If an hello extension, missing a handling clause was present in a paused handshake, the handshake would fail.
Own Id: OTP-20116
Related Id(s): GH-11030, PR-11062
Improvements and New Features
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
The post-quantum hybrid algorithm x25519mlkem768 is now the most preferred key exchange group in the default configuration.
Post-quantum hybrid algorithms secp384r1mlkem1024 and secp256r1mlkem768 are supported but have to be configured. The same goes for the plain post-quantum algorithms mlkem1024, mlkem768, and mlkem512.
The most preferred signature algorithms is now post-quantum algorithms ML-DSA followed by the fastest SLH-DSA (slh_dsa_sha2_256f) algorithm, if such a certificate is available in the configuration. Other SLH-DSA variants are also supported but are added to the end of the preferred list.
All these algorithms were available in OTP-28.4 but none of them were preferred and some of them changed default status.
Own Id: OTP-20070
Related Id(s): PR-10949
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
Secure renegotiation for TLS-1.2 specified in RFC 5746 from 2010 is now always used. The interoperability fallback option
{secure_renegotiate,SecureRenegotiate}is no longer needed.Own Id: OTP-20080
Related Id(s): PR-10979
*** POTENTIAL INCOMPATIBILITY ***
There is a new Hardening guide giving guidelines on how to strengthen the security for the
sslapplication.Own Id: OTP-20087
Related Id(s): PR-11019
*** HIGHLIGHT ***
stdlib-8.0
Fixed Bugs and Malfunctions
Fixed an issue in
digraph_utils:roots/1where roots could be missed in some cases.Own Id: OTP-19932
Related Id(s): PR-10510
beam_lib:strip/1will now retain the Beam debug information chunk produced by thebeam_debug_infooption. The chunk will also be retained when combing thebeam_debug_infooption with the undocumentedslimoption.The runtime system will no longer crash when attempting to load modules that have been compiled with
beam_debug_infobut lack the actual Beam debug info chunk.Own Id: OTP-19991
Related Id(s): GH-10557, PR-10735
Fixed a crash when
zstd:compress/2was asked to compress empty data.Own Id: OTP-20001
Related Id(s): GH-10650, PR-10653
Replaced a sleep clause in user_drv shutdown with a flush of the output buffer.
Own Id: OTP-20124
Related Id(s): PR-10808
The
calendar:seconds_to_time/1function now checks the range for each of the components of a time tuple ({Hours,Minutes,Seconds}) and fail with an exception if a component is out of range.Own Id: OTP-20125
Related Id(s): PR-11069
Improvements and New Features
Error return values from functions in
zipnow also specify which file in the archive the error belongs to.Own Id: OTP-19663
Related Id(s): PR-9899
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
The undocumented and unsupported function
lists:zf/2is now deprecated.Own Id: OTP-19783
Related Id(s): PR-10161
Native records as described in EEP-79 has been implemented.
A native record is a data structure similar to the traditional tuple-based records, except that is a true data type.
Native records are considered experimental in Erlang/OTP 29 and possibly also in Erlang/OTP 30, meaning that their behavior may change, potentially requiring updates to applications that use them.
Own Id: OTP-19785
Related Id(s): PR-10617
*** HIGHLIGHT ***
The new
supervior:stop/1,2functions can be used to manage the dynamic parts of a supervisor tree in an application from outside the tree but in the same application.Own Id: OTP-19800
Related Id(s): PR-9209
Added a new constructor
array:from/2.Own Id: OTP-19815
Related Id(s): PR-10304
There are new functions for random permutation of a list:
rand:shuffle/1andrand:shuffle_s/2. They are inspired by a suggestion and discussion on ErlangForums.Own Id: OTP-19826
Related Id(s): PR-10281
*** HIGHLIGHT ***
The undocumented functions
erl_eval:extended_parse_exprs/1anderl_eval:extended_parse_term/1will now be faster when called with a long list of tokens. (These functions are used byqlcand the shell.)Own Id: OTP-19838
Related Id(s): PR-10338
The
unicodemodule now supports the Unicode 17 standard.Own Id: OTP-19853
Related Id(s): PR-10382
Added functions to
unicodefor recognizing whitespaces and identifiers.Own Id: OTP-19858
Related Id(s): PR-10387
The
rand:bytes/1andrand:bytes_s/2functions have been optimized by implementing a new internal callback function thatcrypto:rand_seed_alg/1andcrypto:alg_seed_alg_s/1have been updated to use.A new algorithm
crypto_prng1, which also takes advantage of this new internal callback, has been added tocrypto:rand_seed_alg/2andcrypto:rand_seed_alg_s/2. It is much faster then the existingcrypto_aes, in particular for generating bytes.Own Id: OTP-19882
Related Id(s): PR-10453, OTP-19827
There will now be a warning when exporting variables out of a subexpression. For example:
To avoid the warning, this can be rewritten to:
The warning can be suppressed by giving option
nowarn_export_var_subexprto the compiler.Own Id: OTP-19898
Related Id(s): PR-9134
*** HIGHLIGHT ***
There are new functions in the shell for returning process information.
The
pi/1function is shortcut forerlang:process_info/1. Thepi/3function takes the three numbers from a pid, constructs a pid, and callsprocess_info/1.Examples:
Own Id: OTP-19903
Related Id(s): PR-10422
Tools such as the debugger,
beam_lib, andxrefno longer support BEAM files created before OTP 13B.Own Id: OTP-19906
Related Id(s): PR-10519
The
calendarmodule has been updated to use the much faster than before Neri-Schneider algorithm for Gregorian calendar calculations, and been extended to handle negative years.Own Id: OTP-19912
Related Id(s): PR-10449
graphis a new module that is a functional equivalent of thedigraphanddigraph_utilsmodules.Own Id: OTP-19922
Related Id(s): PR-10532
*** HIGHLIGHT ***
Before Erlang/OTP 29, attempting to bind variables in a comprehension would compile successfully but fail at runtime. Example:
In Erlang/OTP 29, attempting to bind a variable in a comprehension will fail by default:
However, this example will work as expected if the
compr_assignfeature is enabled when starting the runtime system:Here is another example how
compr_assigncan be used:Own Id: OTP-19927
Related Id(s): PR-9153
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
Removed the undocumented
dyn_erlutility.Own Id: OTP-19933
Related Id(s): PR-10573
The functions
erl_tar:add/3anderl_tar:add/4now accepts the{mode,Mode}option for setting the permission of the file.Own Id: OTP-19934
Related Id(s): PR-10524
Added
zstd:flush/2for flushing compressed data without closing the compression context.Own Id: OTP-19936
Related Id(s): GH-10345, PR-10511
There will now be a warning when using the
catchoperator, which has been deprecated for a long time.It is recommended to instead use
try...catch...endbut is also possible to disable the warning by using thenowarn_deprecated_catchoption.Own Id: OTP-19938
Related Id(s): PR-10421
*** HIGHLIGHT ***
Multi-valued comprehensions according to EEP 78 has been implemented.
Example:
Own Id: OTP-19942
Related Id(s): PR-9374
*** HIGHLIGHT ***
There will now be a warning for matches that unify constructors, such as the following:
Such a match can be rewritten to:
The compiler option
nowarn_match_alias_patscan be used to disable the warning.Own Id: OTP-19943
Related Id(s): PR-10433
*** HIGHLIGHT ***
While the iteration order for maps is undefined, it is now guaranteed that all ways of iterating over maps provides the elements in the same order. That is, all of the following ways of iterating will produce the elements in the same order:
maps:keys/1maps:values/1maps:to_list/1maps:to_list(maps:iterator(M))[{K,V} || K := V <- M]Own Id: OTP-19963
Related Id(s): PR-10626
*** HIGHLIGHT ***
The
arraymodule have been extended with several new functions. The internal representation have been changed to allow the new functionality and optimizations. Arrays serialized withterm_to_binary/1in previous releases are not compatible.Own Id: OTP-20004
Related Id(s): PR-10578
*** HIGHLIGHT ***
*** POTENTIAL INCOMPATIBILITY ***
m:erl_tarwill use less memory when extracting large tar entries to disk. Instead of reading each tar entry into memory,erl_tarwill now stream data in chunks of 64KB. The chunk size is settable using the new{chunks,ChunkSize}option.The new
{max_size,Size}option will set a limit on the total size of extracted data to protect against filling up the disk.Checking of symlinks has been improved. Some symlinks that were safe (such as
dir/link -> ../file) used to be rejected.Own Id: OTP-20023
Related Id(s): PR-10814, PR-10818, PR-10821
*** HIGHLIGHT ***
Added a new module called
io_ansithat allows the user to emit Virtual Terminal Sequences (a.k.a. ANSI sequences) to the terminal in order to add colors/styling to text or create fully-fledged terminal applications.io_ansiuses the local terminfo database in order to be as cross-platform compatible as possible.It also works across nodes so that if functions on a remote node call
io_ansi:fwrite/1it will use the destination terminal's terminfo database to determine which sequences to emit. In practice, this means that you can call functions in a remote shell session that useio_ansiand it will properly detect the terminal sequences the target terminal can handle and will print using them correctly.Own Id: OTP-20028
Related Id(s): PR-10905, PR-9940
*** HIGHLIGHT ***
Polished the documentation groups, essentially removed groups that did nothing but obscure the documentation.
Own Id: OTP-20029
Related Id(s): PR-10755
The
gb_sets:from_ordset/1andgb_trees:from_orddict/1functions would trust their inputs. If the input contained duplicates or was not properly sorted, the resulting gb_set or gb_tree would be invalid, and any number of interesting problems could occur.In this release, these functions will raise an exception if their input is not valid. That could mean that incorrect programs that seemed to work could now stop working altogether.
There is also a new
gb_trees:from_list/1function for directly creating a gb_tree from a list.Own Id: OTP-20061
Related Id(s): PR-10910
*** POTENTIAL INCOMPATIBILITY ***
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
The
jsonmodule now encodes and decodes quoted strings faster. Improvements of up to 55 percent has been measured when decoding JSON data with long strings.The
string:length/1,string:slice/2, andstring:slice/3functions have been optimized. For some strings, they can be up to twice as fast.Own Id: OTP-20072
Related Id(s): PR-10938, PR-10948
*** HIGHLIGHT ***
syntax_tools-4.1
Fixed Bugs and Malfunctions
merl:compile_and_load/1could crash when compiling code containing comments.merl:quote/2would fail to handle literal UTF-8 encoded binaries.Own Id: OTP-20077
Related Id(s): PR-10243, PR-10962
Improvements and New Features
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
Multi-valued comprehensions according to EEP 78 has been implemented.
Example:
Own Id: OTP-19942
Related Id(s): PR-9374
*** HIGHLIGHT ***
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
tftp-1.3
Improvements and New Features
The legacy
andandoroperators have been replaced with other language constructs.Own Id: OTP-19744
Related Id(s): PR-10114, PR-10554, PR-10568, PR-10579, PR-10580, PR-10585, PR-10598, PR-10710, PR-10718, PR-10730
All use of legacy
catchin the TFTP application has been rewritten.In the process, deep return using
exit/1orthrow/1from callbacks has been changed to only work withthrow/1, as customary. This was considered a misfeature.Explicit loading of callback module or logger module has been removed, since that was against what one would expect for embedded mode.
Own Id: OTP-19996
Related Id(s): PR-10753
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
tools-4.2
Fixed Bugs and Malfunctions
Fixed "unbalanced parenthesis" issue when pressing TAB in emacs erlang shell.
Own Id: OTP-19921
Related Id(s): GH-8569, PR-10642
The minimum supported Emacs version for
erlang-modehas been raised from 24.3 to 27.1. Compatibility shims for older Emacs versions have been removed.The
erlang-modepackage version now tracks the Erlang/OTP release version (29.0) for consistent version numbers across package managers.Own Id: OTP-20059
Related Id(s): PR-10892
Improvements and New Features
Tools such as the debugger,
beam_lib, andxrefno longer support BEAM files created before OTP 13B.Own Id: OTP-19906
Related Id(s): PR-10519
The
ignore_xrefattribute has been handled as a post-analysis filter by build tools such as Rebar3. In this release,xrefitself does the filtering, ensuring that all tooling that callsxreffor any purpose can rely on these declarations to just work.Own Id: OTP-20032
Related Id(s): PR-10592
*** HIGHLIGHT ***
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
The runtime system now supports generating encrypted crash dumps. See the description of
--enable-encrypted-crash-dumpsin Building and Installing Erlang/OTP.Own Id: OTP-20085
Related Id(s): PR-10993
*** HIGHLIGHT ***
wx-2.6
Fixed Bugs and Malfunctions
The examples for
wxare now only installed in one place (indoc/examples).Own Id: OTP-20119
Related Id(s): ERIERL-1315, PR-11032
Improvements and New Features
Documentation about how to validate the SBOM using sigstore has been added.
Own Id: OTP-19766
Related Id(s): GH-10151, PR-10187
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
xmerl-2.2
Improvements and New Features
Added support for
-unsafeattributes, which is used to mark functions as unsafe to use.This is similar to but separate from deprecation, and the compiler will by default now generate warnings for calls to functions in Erlang/OTP that are known to be always unsafe.
Furthermore,
xrefcan now be used to find calls to functions in another application that lack a-docattribute (undocumented_function_calls), calls to functions in another application marked-doc false.(private_function_calls), as well as calls to unsafe functions (unsafe_function_calls).Own Id: OTP-20066
Related Id(s): PR-10839
*** HIGHLIGHT ***
Thanks to
Alexandre Rodrigues, Alex Mickelson, Andreas Hasselberg, Andrew Bennett, Ayanda Dube, Bentheburrito, Bernhard M. Wiedemann, Bozhidar Batsov, Claes Nästén, Daniel Gorin, Daniel Kukula, dependabot[bot], Eksperimental, Eric Meadows-Jönsson, erlang-bot-app[bot], felipe stival, Fernando Areias, Holger Weiß, Ievgen Pyrogov, Ilya Averyanov, ilya-klyuchnikov, Ilya Klyuchnikov, Jan Uhlig, Jérôme de Bretagne, João Henrique Ferreira de Freitas, Johannes Christ, Jonatan Männchen, José Valim, krishnadas, Loïc Hoguin, loscher, lud, Maria Scott, Marko Mindek, matt, Mend Renovate, Michael Daniels, Michał Muskała, Nelson Vides, Nick Vatamaniuc, Olexandr88, Paul Guyot, Paulo F. Oliveira, Paulo Tomé, Petr Sumbera, Preet, Radek Szymczyszyn, Rasmus Précenth, Richard Carlsson, Robert Ismo, Robin Morisset, Sam Weaver, Sébastien Saint-Sevin, Sergey Fedorov, siiky, Simon Cornish, spoo, Stefan Grundmann, Takeru Ohta, Vadim Yanitskiy, Vance Shipley, Wade Mealing, Wei Huang, williamthome, yagogarea, Zabrane, Zeyu Zhang, наб
v28.5: OTP 28.5Compare Source
Check out the git tag OTP-28.5, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.
HIGHLIGHTS
There is a new "Secure Coding Guidelines" document in Design Principles describing how to write secure Erlang code.
Own Id: OTP-20043
Application(s): otp
Related Id(s): PR-10431
OTP-28.5
Improvements and New Features
There is a new "Secure Coding Guidelines" document in Design Principles describing how to write secure Erlang code.
Own Id: OTP-20043
Related Id(s): PR-10431
*** HIGHLIGHT ***
erl_interface-5.7
The erl_interface-5.7 application can be applied independently of other applications on a full OTP 28 installation.
Improvements and New Features
A new
configureoption--{enable,disable}-use-embedded-3pp-alternativeshas been added. When enabled,configureis forced to find alternatives, to a subset, of the embedded third-party products (3pps) in the runtime system, and when disabled,configurewill use all internal embedded 3pps. Currently this option affectszstd,zlib,ryu(withSTL),opensslandtcl. The default is to use all built-in embedded 3pps except forzlibwhich by default will usezlibon the OS if available.Requirements for alternatives:
zstd- Static library and include files of at least version 1.5.6 needs to be available.zlib- Library and include files of at least version 1.2.5 needs to be available.ryu(withSTL) - A usable C++ compiler with C++17 support.openssl- No requirements. Our own MD5 implementation will be used.tcl- Thestrerrorname_np()function (introduced in glibc 2.32) mapping errno integers to symbolic names needs to be available.The argument
embedded_3ppshas been added toerlang:system_info/1. It returns a map with information about the use of embedded 3pps in the runtime system.Own Id: OTP-20106
Related Id(s): PR-11045
Known Bugs and Problems
The
eiAPI for decoding/encoding terms is not fully 64-bit compatible since terms that have a representation on the external term format larger than 2 GB cannot be handled.Own Id: OTP-16607
Related Id(s): OTP-16608
erts-16.4
The erts-16.4 application can be applied independently of other applications on a full OTP 28 installation.
Fixed Bugs and Malfunctions
Fixed bug in
enif_make_map_from_arraysfor arrays with at least 33 keys. If duplicate keys existed, instead of failing, it would skip the duplicates. If less than 33 unique keys existed, an internally inconsistent and broken map was returned.Own Id: OTP-20098
Related Id(s): PR-10976
Fixed an issue when supplying the args_file option to erl.exe on windows that did not handle unicode characters correctly.
Own Id: OTP-20101
Related Id(s): GH-10667
Improvements and New Features
A new
configureoption--{enable,disable}-use-embedded-3pp-alternativeshas been added. When enabled,configureis forced to find alternatives, to a subset, of the embedded third-party products (3pps) in the runtime system, and when disabled,configurewill use all internal embedded 3pps. Currently this option affectszstd,zlib,ryu(withSTL),opensslandtcl. The default is to use all built-in embedded 3pps except forzlibwhich by default will usezlibon the OS if available.Requirements for alternatives:
zstd- Static library and include files of at least version 1.5.6 needs to be available.zlib- Library and include files of at least version 1.2.5 needs to be available.ryu(withSTL) - A usable C++ compiler with C++17 support.openssl- No requirements. Our own MD5 implementation will be used.tcl- Thestrerrorname_np()function (introduced in glibc 2.32) mapping errno integers to symbolic names needs to be available.The argument
embedded_3ppshas been added toerlang:system_info/1. It returns a map with information about the use of embedded 3pps in the runtime system.Own Id: OTP-20106
Related Id(s): PR-11045
mnesia-4.25.3
The mnesia-4.25.3 application can be applied independently of other applications on a full OTP 28 installation.
Fixed Bugs and Malfunctions
Added documentation for
user_propertiesand functionsread_table_property/2,write_table_property/2,delete_table_property. Enhanced documentation forfrag_properties.Own Id: OTP-20038
Related Id(s): GH-10812, PR-10881
Fixed a bug where stacktrace was not returned from
mnesia:transaction/1when transaction aborts with an error exception.Own Id: OTP-20094
Related Id(s): GH-10967, PR-11002
ssl-11.6
Note! The ssl-11.6 application cannot be applied independently of other applications on an arbitrary OTP 28 installation.
Fixed Bugs and Malfunctions
Preserve inet option order, as inet_backend option must be first option. Will make inet_backend option work for ssl independently of number of inet supplied options.
Own Id: OTP-19162
Related Id(s): PR-10908
Missing conformance check for signature algorithms in TLS-1.3 could cause selection of incompatible certificate when a server is configured with more than one possible certificate.
Own Id: OTP-20082
Related Id(s): GH-10915, PR-10924
Improvements and New Features
Avoid unnecessary memory consumption for temporary processes in a supervision tree.
Own Id: OTP-19967
Related Id(s): PR-10957
Thanks to
felipe stival, Hewwho, Hugo Baraúna, Nick Vatamaniuc, Viktor Söderqvist, William Yang
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
976bde8d4b5752ac40c85752ac40c878423d4a3578423d4a3545bb709a4045bb709a40bbe943e9eabbe943e9ea93980b576a93980b576a07704faf6707704faf67c5147cf34ec5147cf34ebef1ab4ea2View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.