Skip to content

Stop DateFormatter trailing token from running past the parse end - #16958

Merged
normanmaurer merged 2 commits into
netty:4.2from
daguimu:fix/dateformatter-substring-trailing-token
Jun 17, 2026
Merged

normanmaurer merged 2 commits into
netty:4.2from
daguimu:fix/dateformatter-substring-trailing-token

Conversation

@daguimu

@daguimu daguimu commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Problem

DateFormatter.parseHttpDate(txt, start, end) is documented to parse only the [start, end) substring. Its tokenizer loop correctly stops at end, but the trailing token — the one still open when the loop finishes — was terminated at txt.length() instead of end:

// terminate trailing token
return tokenStart != -1 && parseToken(txt, tokenStart, txt.length());

When end < txt.length() and the date's last token is the one that completes the parse, the trailing token swallows the bytes after end and fails to parse.

This is reachable in practice through cookies. A Set-Cookie header like foo=bar; Expires=<date>; Path=/ makes ClientCookieDecoder call parseHttpDate(header, start, end) with end pointing at the ; before Path. RFC 6265 §5.1.1 cookie-date tokens are order-independent, so a valid date whose year (or day) is the last token — e.g. Sun 08:49:37 06 Nov 1994 — parses fine in isolation but returns null as a substring, silently dropping the expiry and downgrading the cookie to a session cookie.

Standard Sun, 06 Nov 1994 08:49:37 GMT ordering does not trigger it (the time token completes the parse mid-loop, before the trailing GMT), which is why existing tests miss it.

Fix

Terminate the trailing token at end rather than txt.length(). Since end <= txt.length() always, this only ever shrinks the trailing token to the intended bound; the full-string parseHttpDate(txt) path (where end == txt.length()) is unaffected.

Added a DateFormatterTest case that parses such a date both in isolation and as a substring and asserts they agree.

Result

parseHttpDate honours the end bound for the trailing token; valid order-independent cookie dates followed by other attributes now parse correctly. Full DateFormatterTest (14) passes.

Motivation:

DateFormatter.parseHttpDate(txt, start, end) is documented to parse only
the [start, end) substring, and its tokenizer loop correctly stops at end.
But the trailing token (the one still open when the loop ends) was
terminated at txt.length() instead of end. When end < txt.length() — e.g.
a cookie "Expires" value that is followed by more attributes — and the
date's last token is the one that completes the parse (RFC 6265 cookie-date
tokens are order-independent, so the year or day may come last), the
trailing token swallowed the bytes after end and failed to parse. Through
ClientCookieDecoder this silently dropped the expiry and downgraded the
cookie to a session cookie.

Modification:

Terminate the trailing token at end rather than txt.length(). Add a
DateFormatterTest case parsing such a date as a substring.

Result:

parseHttpDate honours the end bound for the trailing token; valid
order-independent cookie dates followed by other attributes parse
correctly.
@normanmaurer normanmaurer added this to the 4.2.16.Final milestone Jun 16, 2026
@normanmaurer normanmaurer added needs-cherry-pick-4.1 This PR should be cherry-picked to 4.1 once merged. needs-cherry-pick-5.0 This PR should be cherry-picked to 5.0 once merged. labels Jun 16, 2026
Comment thread codec-base/src/main/java/io/netty/handler/codec/DateFormatter.java Outdated
Comment thread codec-base/src/test/java/io/netty/handler/codec/DateFormatterTest.java Outdated
Address review nit: the multi-line comments were verbose; collapse each to
a single line.
@daguimu

daguimu commented Jun 17, 2026

Copy link
Copy Markdown
Contributor Author

Good call — collapsed both comments to one-liners in 434cbf4. Thanks @bryce-anderson!

@normanmaurer
normanmaurer merged commit 692d23f into netty:4.2 Jun 17, 2026
18 of 19 checks passed
@netty-project-bot

Copy link
Copy Markdown
Contributor

Auto-port PR for 4.1: #16968

@github-actions github-actions Bot removed the needs-cherry-pick-4.1 This PR should be cherry-picked to 4.1 once merged. label Jun 17, 2026
@netty-project-bot

Copy link
Copy Markdown
Contributor

Auto-port PR for 5.0: #16969

@github-actions github-actions Bot removed the needs-cherry-pick-5.0 This PR should be cherry-picked to 5.0 once merged. label Jun 17, 2026
normanmaurer pushed a commit that referenced this pull request Jun 18, 2026
…e parse end (#16969)

Auto-port of #16958 to 5.0
Cherry-picked commit: 692d23f

---
## Problem

`DateFormatter.parseHttpDate(txt, start, end)` is documented to parse
only the `[start, end)` substring. Its tokenizer loop correctly stops at
`end`, but the **trailing token** — the one still open when the loop
finishes — was terminated at `txt.length()` instead of `end`:

```java
// terminate trailing token
return tokenStart != -1 && parseToken(txt, tokenStart, txt.length());
```

When `end < txt.length()` and the date's *last* token is the one that
completes the parse, the trailing token swallows the bytes after `end`
and fails to parse.

This is reachable in practice through cookies. A `Set-Cookie` header
like `foo=bar; Expires=<date>; Path=/` makes `ClientCookieDecoder` call
`parseHttpDate(header, start, end)` with `end` pointing at the `;`
before `Path`. RFC 6265 §5.1.1 cookie-date tokens are
**order-independent**, so a valid date whose year (or day) is the last
token — e.g. `Sun 08:49:37 06 Nov 1994` — parses fine in isolation but
returns `null` as a substring, silently dropping the expiry and
downgrading the cookie to a session cookie.

Standard `Sun, 06 Nov 1994 08:49:37 GMT` ordering does not trigger it
(the time token completes the parse mid-loop, before the trailing
`GMT`), which is why existing tests miss it.

## Fix

Terminate the trailing token at `end` rather than `txt.length()`. Since
`end <= txt.length()` always, this only ever shrinks the trailing token
to the intended bound; the full-string `parseHttpDate(txt)` path (where
`end == txt.length()`) is unaffected.

Added a `DateFormatterTest` case that parses such a date both in
isolation and as a substring and asserts they agree.

## Result

`parseHttpDate` honours the `end` bound for the trailing token; valid
order-independent cookie dates followed by other attributes now parse
correctly. Full `DateFormatterTest` (14) passes.

Co-authored-by: Guimu <[email protected]>
normanmaurer added a commit that referenced this pull request Jun 18, 2026
…e parse end (#16968)

Auto-port of #16958 to 4.1
Cherry-picked commit: 692d23f

---
## Problem

`DateFormatter.parseHttpDate(txt, start, end)` is documented to parse
only the `[start, end)` substring. Its tokenizer loop correctly stops at
`end`, but the **trailing token** — the one still open when the loop
finishes — was terminated at `txt.length()` instead of `end`:

```java
// terminate trailing token
return tokenStart != -1 && parseToken(txt, tokenStart, txt.length());
```

When `end < txt.length()` and the date's *last* token is the one that
completes the parse, the trailing token swallows the bytes after `end`
and fails to parse.

This is reachable in practice through cookies. A `Set-Cookie` header
like `foo=bar; Expires=<date>; Path=/` makes `ClientCookieDecoder` call
`parseHttpDate(header, start, end)` with `end` pointing at the `;`
before `Path`. RFC 6265 §5.1.1 cookie-date tokens are
**order-independent**, so a valid date whose year (or day) is the last
token — e.g. `Sun 08:49:37 06 Nov 1994` — parses fine in isolation but
returns `null` as a substring, silently dropping the expiry and
downgrading the cookie to a session cookie.

Standard `Sun, 06 Nov 1994 08:49:37 GMT` ordering does not trigger it
(the time token completes the parse mid-loop, before the trailing
`GMT`), which is why existing tests miss it.

## Fix

Terminate the trailing token at `end` rather than `txt.length()`. Since
`end <= txt.length()` always, this only ever shrinks the trailing token
to the intended bound; the full-string `parseHttpDate(txt)` path (where
`end == txt.length()`) is unaffected.

Added a `DateFormatterTest` case that parses such a date both in
isolation and as a substring and asserts they agree.

## Result

`parseHttpDate` honours the `end` bound for the trailing token; valid
order-independent cookie dates followed by other attributes now parse
correctly. Full `DateFormatterTest` (14) passes.

Co-authored-by: Guimu <[email protected]>
Co-authored-by: Norman Maurer <[email protected]>
mergify Bot added a commit to ArcadeData/arcadedb that referenced this pull request Jul 8, 2026
…l [skip ci]

Bumps [io.netty:netty-all](https://github.com/netty/netty) from 4.2.15.Final to 4.2.16.Final.
Release notes

*Sourced from [io.netty:netty-all's releases](https://github.com/netty/netty/releases).*

> netty-4.2.16.Final
> ------------------
>
> What's Changed
> --------------
>
> * Document Java 9 requirement for io\_uring by [`@​jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904)
> * Add BlockHound exception for DnsQueryIdSpace by [`@​violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896)
> * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901)
> * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766)
> * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808)
> * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909)
> * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910)
> * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919)
> * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905)
> * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848)
> * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@​wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739)
> * Avoid logging exceptions that tests ignore by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891)
> * Reject control characters at the boundary of HTTP method names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723)
> * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929)
> * Try to fix/stabilize a number of flaky tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934)
> * Fix propagation of startTls for client SslContext handlers by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931)
> * Update to latest tcnative release by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936)
> * Move test to shared testsuite by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928)
> * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927)
> * Make permessage-deflate server window size and memLevel configurable by [`@​fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809)
> * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950)
> * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952)
> * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951)
> * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960)
> * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@​hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932)
> * Strictly validate MQTT UTF-8 Encoded String by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939)
> * Stop DateFormatter trailing token from running past the parse end by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958)
> * IpFilter: Deprecate constructor which use accept by default by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961)
> * Add RFC 10008 QUERY Method support by [`@​desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966)
> * Correctly release and fail queued traffic-shaping writes on close by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959)
> * Reject control characters at the boundary of the HTTP version token by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971)
> * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@​schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949)
> * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979)
> * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@​husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982)
> * Fix typo in AbstractSniHandler Javadoc by [`@​coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988)
> * Fix client/server inconsistency in SslCredential support matrix by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990)
> * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@​gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947)
> * Use Ticker in Http2MaxRstFrameListener for testability by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993)
> * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@​vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991)
> * FastLz: Guard decompression against truncated input by [`@​yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000)
> * Reject non-token characters in HTTP/2 header names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762)
> * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029)
> * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027)
> * Implement Adaptive Cumulator by [`@​shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731)
> * Allow WebSocket extension negotiation to be disabled per response by [`@​mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030)
> * Support QPACK sensitivity detector for Never Indexed header fields by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026)
> * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037)
> * Pin github actions to reduce risk by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043)

... (truncated)


Commits

* [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final
* [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters
* [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain
* [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063))
* [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061))
* [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043))
* [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037))
* [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026))
* [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030))
* [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731))
* Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final)
  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=io.netty:netty-all&package-manager=maven&previous-version=4.2.15.Final&new-version=4.2.16.Final)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
mergify Bot added a commit to ArcadeData/arcadedb that referenced this pull request Jul 8, 2026
…ip ci]

Bumps `netty.version` from 4.2.15.Final to 4.2.16.Final.
Updates `io.netty:netty-transport` from 4.2.15.Final to 4.2.16.Final
Release notes

*Sourced from [io.netty:netty-transport's releases](https://github.com/netty/netty/releases).*

> netty-4.2.16.Final
> ------------------
>
> What's Changed
> --------------
>
> * Document Java 9 requirement for io\_uring by [`@​jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904)
> * Add BlockHound exception for DnsQueryIdSpace by [`@​violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896)
> * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901)
> * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766)
> * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808)
> * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909)
> * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910)
> * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919)
> * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905)
> * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848)
> * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@​wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739)
> * Avoid logging exceptions that tests ignore by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891)
> * Reject control characters at the boundary of HTTP method names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723)
> * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929)
> * Try to fix/stabilize a number of flaky tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934)
> * Fix propagation of startTls for client SslContext handlers by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931)
> * Update to latest tcnative release by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936)
> * Move test to shared testsuite by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928)
> * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927)
> * Make permessage-deflate server window size and memLevel configurable by [`@​fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809)
> * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950)
> * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952)
> * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951)
> * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960)
> * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@​hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932)
> * Strictly validate MQTT UTF-8 Encoded String by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939)
> * Stop DateFormatter trailing token from running past the parse end by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958)
> * IpFilter: Deprecate constructor which use accept by default by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961)
> * Add RFC 10008 QUERY Method support by [`@​desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966)
> * Correctly release and fail queued traffic-shaping writes on close by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959)
> * Reject control characters at the boundary of the HTTP version token by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971)
> * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@​schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949)
> * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979)
> * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@​husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982)
> * Fix typo in AbstractSniHandler Javadoc by [`@​coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988)
> * Fix client/server inconsistency in SslCredential support matrix by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990)
> * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@​gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947)
> * Use Ticker in Http2MaxRstFrameListener for testability by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993)
> * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@​vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991)
> * FastLz: Guard decompression against truncated input by [`@​yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000)
> * Reject non-token characters in HTTP/2 header names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762)
> * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029)
> * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027)
> * Implement Adaptive Cumulator by [`@​shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731)
> * Allow WebSocket extension negotiation to be disabled per response by [`@​mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030)
> * Support QPACK sensitivity detector for Never Indexed header fields by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026)
> * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037)
> * Pin github actions to reduce risk by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043)

... (truncated)


Commits

* [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final
* [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters
* [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain
* [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063))
* [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061))
* [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043))
* [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037))
* [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026))
* [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030))
* [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731))
* Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final)
  
Updates `io.netty:netty-codec` from 4.2.15.Final to 4.2.16.Final
Release notes

*Sourced from [io.netty:netty-codec's releases](https://github.com/netty/netty/releases).*

> netty-4.2.16.Final
> ------------------
>
> What's Changed
> --------------
>
> * Document Java 9 requirement for io\_uring by [`@​jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904)
> * Add BlockHound exception for DnsQueryIdSpace by [`@​violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896)
> * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901)
> * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766)
> * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808)
> * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909)
> * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910)
> * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919)
> * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905)
> * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848)
> * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@​wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739)
> * Avoid logging exceptions that tests ignore by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891)
> * Reject control characters at the boundary of HTTP method names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723)
> * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929)
> * Try to fix/stabilize a number of flaky tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934)
> * Fix propagation of startTls for client SslContext handlers by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931)
> * Update to latest tcnative release by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936)
> * Move test to shared testsuite by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928)
> * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927)
> * Make permessage-deflate server window size and memLevel configurable by [`@​fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809)
> * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950)
> * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952)
> * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951)
> * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960)
> * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@​hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932)
> * Strictly validate MQTT UTF-8 Encoded String by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939)
> * Stop DateFormatter trailing token from running past the parse end by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958)
> * IpFilter: Deprecate constructor which use accept by default by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961)
> * Add RFC 10008 QUERY Method support by [`@​desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966)
> * Correctly release and fail queued traffic-shaping writes on close by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959)
> * Reject control characters at the boundary of the HTTP version token by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971)
> * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@​schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949)
> * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979)
> * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@​husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982)
> * Fix typo in AbstractSniHandler Javadoc by [`@​coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988)
> * Fix client/server inconsistency in SslCredential support matrix by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990)
> * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@​gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947)
> * Use Ticker in Http2MaxRstFrameListener for testability by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993)
> * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@​vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991)
> * FastLz: Guard decompression against truncated input by [`@​yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000)
> * Reject non-token characters in HTTP/2 header names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762)
> * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029)
> * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027)
> * Implement Adaptive Cumulator by [`@​shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731)
> * Allow WebSocket extension negotiation to be disabled per response by [`@​mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030)
> * Support QPACK sensitivity detector for Never Indexed header fields by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026)
> * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037)
> * Pin github actions to reduce risk by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043)

... (truncated)


Commits

* [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final
* [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters
* [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain
* [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063))
* [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061))
* [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043))
* [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037))
* [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026))
* [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030))
* [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731))
* Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final)
  
Updates `io.netty:netty-handler` from 4.2.15.Final to 4.2.16.Final
Release notes

*Sourced from [io.netty:netty-handler's releases](https://github.com/netty/netty/releases).*

> netty-4.2.16.Final
> ------------------
>
> What's Changed
> --------------
>
> * Document Java 9 requirement for io\_uring by [`@​jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904)
> * Add BlockHound exception for DnsQueryIdSpace by [`@​violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896)
> * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901)
> * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766)
> * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808)
> * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909)
> * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910)
> * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919)
> * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905)
> * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848)
> * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@​wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739)
> * Avoid logging exceptions that tests ignore by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891)
> * Reject control characters at the boundary of HTTP method names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723)
> * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929)
> * Try to fix/stabilize a number of flaky tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934)
> * Fix propagation of startTls for client SslContext handlers by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931)
> * Update to latest tcnative release by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936)
> * Move test to shared testsuite by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928)
> * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927)
> * Make permessage-deflate server window size and memLevel configurable by [`@​fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809)
> * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950)
> * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952)
> * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951)
> * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960)
> * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@​hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932)
> * Strictly validate MQTT UTF-8 Encoded String by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939)
> * Stop DateFormatter trailing token from running past the parse end by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958)
> * IpFilter: Deprecate constructor which use accept by default by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961)
> * Add RFC 10008 QUERY Method support by [`@​desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966)
> * Correctly release and fail queued traffic-shaping writes on close by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959)
> * Reject control characters at the boundary of the HTTP version token by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971)
> * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@​schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949)
> * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979)
> * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@​husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982)
> * Fix typo in AbstractSniHandler Javadoc by [`@​coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988)
> * Fix client/server inconsistency in SslCredential support matrix by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990)
> * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@​gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947)
> * Use Ticker in Http2MaxRstFrameListener for testability by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993)
> * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@​vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991)
> * FastLz: Guard decompression against truncated input by [`@​yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000)
> * Reject non-token characters in HTTP/2 header names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762)
> * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029)
> * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027)
> * Implement Adaptive Cumulator by [`@​shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731)
> * Allow WebSocket extension negotiation to be disabled per response by [`@​mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030)
> * Support QPACK sensitivity detector for Never Indexed header fields by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026)
> * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037)
> * Pin github actions to reduce risk by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043)

... (truncated)


Commits

* [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final
* [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters
* [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain
* [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063))
* [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061))
* [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043))
* [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037))
* [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026))
* [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030))
* [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731))
* Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final)
  
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants