Bug fixes
-
Fixed :py:attr:
~aiohttp.web.StreamResponse.last_modifiedrounding a
:class:datetime.datetimewith a fractional second down.Related issues and pull requests on GitHub:
#5303. -
Fixed resolving
localhoston Windows to fall back withoutAI_ADDRCONFIG
when the first lookup fails, solocalhoststill works without an active
network.Related issues and pull requests on GitHub:
#5357. -
Rejected multipart body parts whose
Content-Lengthheader is not a
plain sequence of digits (e.g.+5,-1,1_0), matching the
strictness of the main request parser per :rfc:9110#section-8.6
-- by :user:dxbjavid.Related issues and pull requests on GitHub:
#12794. -
Fixed
GunicornWebWorkerendlessly reloading when app fails during startup -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#12879. -
Fixed some inconsistent case sensitivity on request methods -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
#12931. -
Fixed
IndexError: string index out of rangeinparse_content_disposition
when a header parameter has an empty value (e.g.filename=).
-- by :user:JSap0914.Related issues and pull requests on GitHub:
#12948. -
Fixed the
sock_readtimeout being re-armed on a keep-alive connection after
it had been returned to the pool. An idle pooled connection could be left with a
pending read timeout that fired and poisoned it, so the next request reusing the
connection failed immediately with :exc:aiohttp.SocketTimeoutError. The read
timeout is now only rescheduled when resuming a transport that was actually
paused -- by :user:daragok. -
Fixed the client decompressing frames when
permessage-deflatewas not negotiated -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#12976. -
Fixed
DigestAuthMiddlewareraising anIndexErroron empty domain -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#12983. -
Fixed :class:
~aiohttp.DigestAuthMiddlewarecorrupting theDigest
challenge when aWWW-Authenticateresponse offered more than one
authentication scheme -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#12984. -
Fixed client not closing cleanly after an exception -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
#12985. -
Fixed control frames breaking fragmented WebSocket messages -- by :user:
arshsmith1.Related issues and pull requests on GitHub:
#12988. -
Fixed
parse_content_dispositionrejecting otherwise-valid
Content-Dispositionheader values that contain optional whitespace (OWS)
around the disposition type (e.g."form-data ; name=\"field\"").
The disposition type is now stripped before token validation, consistent with
how parameter keys are already handled -- by :user:JSap0914.Related issues and pull requests on GitHub:
#12996. -
Fixed an :exc:
IndexErrorin the pure-Python HTTP parser -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#13001. -
Fixed parsing optional whitespace in Content-Disposition -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
#13002. -
Fixed request body not being read on rejected WebSocket upgrades -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
#13016. -
Fixed :exc:
LookupError(and an unguarded :exc:UnicodeDecodeError) escaping
Content-Dispositionparsing when a multipart part supplies an extended
parameter with an unknown charset
-- by :user:arshsmith1.Related issues and pull requests on GitHub:
#13042. -
Fixed
escape_quotesin the Digest authentication middleware not escaping
backslashes, so aWWW-Authenticatechallenge value containing a backslash
could break out of its quoted-string in the generatedAuthorizationheader
-- by :user:dxbjavid.Related issues and pull requests on GitHub:
#13054. -
Fixed Python parser not rejecting a bare
LFin the request line -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#13136. -
Fixed the C HTTP parser folding the fragment into the query string for an
origin-form request target with an empty query (e.g./path?#frag),
which diverged from the pure-Python parser -- by :user:GiulioDER.Related issues and pull requests on GitHub:
#13171. -
Fixed the C parser reporting newer HTTP methods such as
QUERYas<unknown>;
the method table is now derived from the vendored llhttp instead of a hand-maintained count
-- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#13174.
Packaging updates and notes for downstreams
-
Upgraded
llhttpto v9.4.2 -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#12956.
Contributor-facing changes
-
Added admin documentation on incident response and on running reproducer code
safely, covering security vulnerability handling and supply-chain, account, and
CI/infrastructure compromise -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
#12914.