Skip to content

Http3FrameCodec handle fragmented payloads when skipping unknown frames - #16960

Merged
normanmaurer merged 1 commit into
netty:4.2from
skyguard1:fix_http3_skip_frame_issue
Jun 16, 2026
Merged

normanmaurer merged 1 commit into
netty:4.2from
skyguard1:fix_http3_skip_frame_issue

Conversation

@skyguard1

Copy link
Copy Markdown
Contributor

Motivation:
The Http3FrameCodec#skipBytes is used to discard the payload of unknown (and non-reserved) HTTP/3 frame types. The current implementation unconditionally calls in.skipBytes(payLoadLength):

private static int skipBytes(ByteBuf in, int payLoadLength) {
    in.skipBytes(payLoadLength);
    return payLoadLength;
}

It is invoked from two places in decodeFrame(...):
The longType > Integer.MAX_VALUE && !Http3CodecUtils.isReservedFrameType(longType) branch.
The default branch when !Http3CodecUtils.isReservedFrameType(longType).
Neither call site verifies that in.readableBytes() >= payLoadLength (unlike the reserved-frame path which explicitly returns 0 when the payload is not yet fully available). As a result, when the payload of an unknown frame is fragmented across multiple inbound reads, ByteBuf#skipBytes throws IndexOutOfBoundsException and breaks the connection, although HTTP/3 explicitly requires unknown frame types to be ignored (see draft-ietf-quic-http 7.2.8 and grease frame types).
Modifications:
Make Http3FrameCodec#skipBytes skip only what is currently readable and return the number of bytes actually consumed:

int length = Math.min(in.readableBytes(), payLoadLength);
in.skipBytes(length);
return length;

This is consistent with the existing partial-consume contract of decodeFrame(...): the caller in decode(...) already handles read < payLoadLength by decrementing payLoadLength and resuming on the next invocation, keeping type set so the same skip path is taken again until the whole payload has been discarded.
Add Http3FrameCodecTest#testSkipFragmentedUnknown, a regression test that:
writes an unknown, non-reserved frame type (4611686018427387903L, which hits the longType > Integer.MAX_VALUE branch) with a declared payload length of 10;
feeds only 3 bytes of payload first, then the remaining 7 in a second writeInbound;
asserts that no exception is thrown, no frame is emitted, and the channel finishes cleanly.
Result:
Http3FrameCodec no longer throws IndexOutOfBoundsException when the payload of an unknown (non-reserved) HTTP/3 frame is delivered across multiple reads. Unknown frames are correctly skipped as required by the HTTP/3 specification.

@normanmaurer normanmaurer added this to the 4.2.16.Final milestone Jun 16, 2026
@normanmaurer normanmaurer added the needs-cherry-pick-5.0 This PR should be cherry-picked to 5.0 once merged. label Jun 16, 2026
@normanmaurer

Copy link
Copy Markdown
Member

@skyguard1 great catch!

@normanmaurer
normanmaurer merged commit b408626 into netty:4.2 Jun 16, 2026
21 checks passed
@netty-project-bot

Copy link
Copy Markdown
Contributor

Auto-port PR for 5.0: #16962

@github-actions github-actions Bot removed the needs-cherry-pick-5.0 This PR should be cherry-picked to 5.0 once merged. label Jun 16, 2026
normanmaurer pushed a commit that referenced this pull request Jun 16, 2026
…ng unknown frames (#16962)

Auto-port of #16960 to 5.0
Cherry-picked commit: b408626

---
Motivation:
The Http3FrameCodec#skipBytes is used to discard the payload of unknown
(and non-reserved) HTTP/3 frame types. The current implementation
unconditionally calls in.skipBytes(payLoadLength):
```
private static int skipBytes(ByteBuf in, int payLoadLength) {
    in.skipBytes(payLoadLength);
    return payLoadLength;
}
```
It is invoked from two places in decodeFrame(...):
The longType > Integer.MAX_VALUE &&
!Http3CodecUtils.isReservedFrameType(longType) branch.
The default branch when !Http3CodecUtils.isReservedFrameType(longType).
Neither call site verifies that in.readableBytes() >= payLoadLength
(unlike the reserved-frame path which explicitly returns 0 when the
payload is not yet fully available). As a result, when the payload of an
unknown frame is fragmented across multiple inbound reads,
ByteBuf#skipBytes throws IndexOutOfBoundsException and breaks the
connection, although HTTP/3 explicitly requires unknown frame types to
be ignored (see draft-ietf-quic-http 7.2.8 and grease frame types).
Modifications:
Make Http3FrameCodec#skipBytes skip only what is currently readable and
return the number of bytes actually consumed:
```
int length = Math.min(in.readableBytes(), payLoadLength);
in.skipBytes(length);
return length;
```
This is consistent with the existing partial-consume contract of
decodeFrame(...): the caller in decode(...) already handles read <
payLoadLength by decrementing payLoadLength and resuming on the next
invocation, keeping type set so the same skip path is taken again until
the whole payload has been discarded.
Add Http3FrameCodecTest#testSkipFragmentedUnknown, a regression test
that:
writes an unknown, non-reserved frame type (4611686018427387903L, which
hits the longType > Integer.MAX_VALUE branch) with a declared payload
length of 10;
feeds only 3 bytes of payload first, then the remaining 7 in a second
writeInbound;
asserts that no exception is thrown, no frame is emitted, and the
channel finishes cleanly.
Result:
Http3FrameCodec no longer throws IndexOutOfBoundsException when the
payload of an unknown (non-reserved) HTTP/3 frame is delivered across
multiple reads. Unknown frames are correctly skipped as required by the
HTTP/3 specification.

Co-authored-by: skyguard1 <[email protected]>
mergify Bot added a commit to ArcadeData/arcadedb that referenced this pull request Jul 8, 2026
…l [skip ci]

Bumps [io.netty:netty-all](https://github.com/netty/netty) from 4.2.15.Final to 4.2.16.Final.
Release notes

*Sourced from [io.netty:netty-all's releases](https://github.com/netty/netty/releases).*

> netty-4.2.16.Final
> ------------------
>
> What's Changed
> --------------
>
> * Document Java 9 requirement for io\_uring by [`@​jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904)
> * Add BlockHound exception for DnsQueryIdSpace by [`@​violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896)
> * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901)
> * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766)
> * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808)
> * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909)
> * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910)
> * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919)
> * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905)
> * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848)
> * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@​wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739)
> * Avoid logging exceptions that tests ignore by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891)
> * Reject control characters at the boundary of HTTP method names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723)
> * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929)
> * Try to fix/stabilize a number of flaky tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934)
> * Fix propagation of startTls for client SslContext handlers by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931)
> * Update to latest tcnative release by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936)
> * Move test to shared testsuite by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928)
> * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927)
> * Make permessage-deflate server window size and memLevel configurable by [`@​fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809)
> * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950)
> * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952)
> * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951)
> * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960)
> * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@​hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932)
> * Strictly validate MQTT UTF-8 Encoded String by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939)
> * Stop DateFormatter trailing token from running past the parse end by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958)
> * IpFilter: Deprecate constructor which use accept by default by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961)
> * Add RFC 10008 QUERY Method support by [`@​desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966)
> * Correctly release and fail queued traffic-shaping writes on close by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959)
> * Reject control characters at the boundary of the HTTP version token by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971)
> * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@​schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949)
> * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979)
> * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@​husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982)
> * Fix typo in AbstractSniHandler Javadoc by [`@​coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988)
> * Fix client/server inconsistency in SslCredential support matrix by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990)
> * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@​gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947)
> * Use Ticker in Http2MaxRstFrameListener for testability by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993)
> * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@​vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991)
> * FastLz: Guard decompression against truncated input by [`@​yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000)
> * Reject non-token characters in HTTP/2 header names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762)
> * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029)
> * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027)
> * Implement Adaptive Cumulator by [`@​shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731)
> * Allow WebSocket extension negotiation to be disabled per response by [`@​mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030)
> * Support QPACK sensitivity detector for Never Indexed header fields by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026)
> * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037)
> * Pin github actions to reduce risk by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043)

... (truncated)


Commits

* [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final
* [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters
* [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain
* [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063))
* [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061))
* [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043))
* [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037))
* [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026))
* [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030))
* [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731))
* Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final)
  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=io.netty:netty-all&package-manager=maven&previous-version=4.2.15.Final&new-version=4.2.16.Final)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
mergify Bot added a commit to ArcadeData/arcadedb that referenced this pull request Jul 8, 2026
…ip ci]

Bumps `netty.version` from 4.2.15.Final to 4.2.16.Final.
Updates `io.netty:netty-transport` from 4.2.15.Final to 4.2.16.Final
Release notes

*Sourced from [io.netty:netty-transport's releases](https://github.com/netty/netty/releases).*

> netty-4.2.16.Final
> ------------------
>
> What's Changed
> --------------
>
> * Document Java 9 requirement for io\_uring by [`@​jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904)
> * Add BlockHound exception for DnsQueryIdSpace by [`@​violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896)
> * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901)
> * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766)
> * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808)
> * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909)
> * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910)
> * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919)
> * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905)
> * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848)
> * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@​wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739)
> * Avoid logging exceptions that tests ignore by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891)
> * Reject control characters at the boundary of HTTP method names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723)
> * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929)
> * Try to fix/stabilize a number of flaky tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934)
> * Fix propagation of startTls for client SslContext handlers by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931)
> * Update to latest tcnative release by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936)
> * Move test to shared testsuite by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928)
> * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927)
> * Make permessage-deflate server window size and memLevel configurable by [`@​fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809)
> * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950)
> * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952)
> * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951)
> * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960)
> * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@​hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932)
> * Strictly validate MQTT UTF-8 Encoded String by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939)
> * Stop DateFormatter trailing token from running past the parse end by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958)
> * IpFilter: Deprecate constructor which use accept by default by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961)
> * Add RFC 10008 QUERY Method support by [`@​desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966)
> * Correctly release and fail queued traffic-shaping writes on close by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959)
> * Reject control characters at the boundary of the HTTP version token by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971)
> * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@​schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949)
> * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979)
> * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@​husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982)
> * Fix typo in AbstractSniHandler Javadoc by [`@​coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988)
> * Fix client/server inconsistency in SslCredential support matrix by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990)
> * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@​gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947)
> * Use Ticker in Http2MaxRstFrameListener for testability by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993)
> * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@​vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991)
> * FastLz: Guard decompression against truncated input by [`@​yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000)
> * Reject non-token characters in HTTP/2 header names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762)
> * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029)
> * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027)
> * Implement Adaptive Cumulator by [`@​shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731)
> * Allow WebSocket extension negotiation to be disabled per response by [`@​mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030)
> * Support QPACK sensitivity detector for Never Indexed header fields by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026)
> * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037)
> * Pin github actions to reduce risk by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043)

... (truncated)


Commits

* [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final
* [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters
* [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain
* [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063))
* [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061))
* [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043))
* [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037))
* [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026))
* [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030))
* [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731))
* Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final)
  
Updates `io.netty:netty-codec` from 4.2.15.Final to 4.2.16.Final
Release notes

*Sourced from [io.netty:netty-codec's releases](https://github.com/netty/netty/releases).*

> netty-4.2.16.Final
> ------------------
>
> What's Changed
> --------------
>
> * Document Java 9 requirement for io\_uring by [`@​jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904)
> * Add BlockHound exception for DnsQueryIdSpace by [`@​violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896)
> * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901)
> * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766)
> * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808)
> * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909)
> * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910)
> * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919)
> * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905)
> * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848)
> * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@​wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739)
> * Avoid logging exceptions that tests ignore by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891)
> * Reject control characters at the boundary of HTTP method names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723)
> * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929)
> * Try to fix/stabilize a number of flaky tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934)
> * Fix propagation of startTls for client SslContext handlers by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931)
> * Update to latest tcnative release by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936)
> * Move test to shared testsuite by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928)
> * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927)
> * Make permessage-deflate server window size and memLevel configurable by [`@​fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809)
> * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950)
> * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952)
> * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951)
> * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960)
> * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@​hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932)
> * Strictly validate MQTT UTF-8 Encoded String by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939)
> * Stop DateFormatter trailing token from running past the parse end by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958)
> * IpFilter: Deprecate constructor which use accept by default by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961)
> * Add RFC 10008 QUERY Method support by [`@​desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966)
> * Correctly release and fail queued traffic-shaping writes on close by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959)
> * Reject control characters at the boundary of the HTTP version token by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971)
> * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@​schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949)
> * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979)
> * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@​husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982)
> * Fix typo in AbstractSniHandler Javadoc by [`@​coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988)
> * Fix client/server inconsistency in SslCredential support matrix by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990)
> * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@​gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947)
> * Use Ticker in Http2MaxRstFrameListener for testability by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993)
> * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@​vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991)
> * FastLz: Guard decompression against truncated input by [`@​yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000)
> * Reject non-token characters in HTTP/2 header names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762)
> * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029)
> * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027)
> * Implement Adaptive Cumulator by [`@​shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731)
> * Allow WebSocket extension negotiation to be disabled per response by [`@​mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030)
> * Support QPACK sensitivity detector for Never Indexed header fields by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026)
> * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037)
> * Pin github actions to reduce risk by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043)

... (truncated)


Commits

* [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final
* [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters
* [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain
* [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063))
* [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061))
* [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043))
* [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037))
* [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026))
* [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030))
* [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731))
* Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final)
  
Updates `io.netty:netty-handler` from 4.2.15.Final to 4.2.16.Final
Release notes

*Sourced from [io.netty:netty-handler's releases](https://github.com/netty/netty/releases).*

> netty-4.2.16.Final
> ------------------
>
> What's Changed
> --------------
>
> * Document Java 9 requirement for io\_uring by [`@​jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904)
> * Add BlockHound exception for DnsQueryIdSpace by [`@​violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896)
> * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901)
> * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766)
> * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808)
> * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909)
> * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910)
> * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919)
> * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905)
> * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@​franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848)
> * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@​wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739)
> * Avoid logging exceptions that tests ignore by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891)
> * Reject control characters at the boundary of HTTP method names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723)
> * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@​dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929)
> * Try to fix/stabilize a number of flaky tests by [`@​chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934)
> * Fix propagation of startTls for client SslContext handlers by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931)
> * Update to latest tcnative release by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936)
> * Move test to shared testsuite by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928)
> * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927)
> * Make permessage-deflate server window size and memLevel configurable by [`@​fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809)
> * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950)
> * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952)
> * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951)
> * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960)
> * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@​hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932)
> * Strictly validate MQTT UTF-8 Encoded String by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939)
> * Stop DateFormatter trailing token from running past the parse end by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958)
> * IpFilter: Deprecate constructor which use accept by default by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961)
> * Add RFC 10008 QUERY Method support by [`@​desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966)
> * Correctly release and fail queued traffic-shaping writes on close by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959)
> * Reject control characters at the boundary of the HTTP version token by [`@​HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971)
> * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@​schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949)
> * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979)
> * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@​husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982)
> * Fix typo in AbstractSniHandler Javadoc by [`@​coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988)
> * Fix client/server inconsistency in SslCredential support matrix by [`@​jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990)
> * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@​gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947)
> * Use Ticker in Http2MaxRstFrameListener for testability by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993)
> * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@​vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991)
> * FastLz: Guard decompression against truncated input by [`@​yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000)
> * Reject non-token characters in HTTP/2 header names by [`@​daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762)
> * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@​netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029)
> * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@​sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027)
> * Implement Adaptive Cumulator by [`@​shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731)
> * Allow WebSocket extension negotiation to be disabled per response by [`@​mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030)
> * Support QPACK sensitivity detector for Never Indexed header fields by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026)
> * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@​skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037)
> * Pin github actions to reduce risk by [`@​normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043)

... (truncated)


Commits

* [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final
* [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters
* [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain
* [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063))
* [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061))
* [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043))
* [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037))
* [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026))
* [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030))
* [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731))
* Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final)
  
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants