Skip to content

chore: bump APISIX-Runtime to 1.3.18 - #13890

Merged
nic-6443 merged 1 commit into
apache:masterfrom
nic-6443:chore/bump-apisix-runtime-1.3.18
Aug 31, 2026
Merged

nic-6443 merged 1 commit into
apache:masterfrom
nic-6443:chore/bump-apisix-runtime-1.3.18

Conversation

@nic-6443

Copy link
Copy Markdown
Member

Description

Bumps APISIX_RUNTIME to 1.3.18, with the version guard and the two apisix-runtime-debug checksums in ci/linux-install-openresty.sh.

The only component that moves is ngx_multi_upstream_module 1.3.3 → 1.3.4 (api7/ngx_multi_upstream_module#22), a use-after-free that crashes the worker. ngx_http_multi_upstream_connection_close() destroyed c->pool and then called ngx_close_connection(c), which still logs through c->log — and for these upstream connections c->log lives in the pool that was just released, so ngx_reusable_connection() reads a freed ngx_log_t:

#0  ngx_write_fd (fd=<error reading variable: Cannot access memory ...>)
#1  ngx_log_error_core (fmt="reusable connection: %ui")
#2  ngx_reusable_connection (c=..., reusable=0)
#3  ngx_close_connection (c=...)
#4  ngx_http_multi_upstream_connection_close (c=...)

It surfaces here as an intermittent SIGSEGV in t/plugin/dubbo-proxy/upstream.t TEST 1, which took out the t/plugin/[a-k]*.t shard once during #13863. Running that file five times locally: 2 crashes on 1.3.17, 0 on 1.3.18.

Checksums were taken from the published release artifacts:

0d7cbe27cd0303c6f6b3cad27338a697cf2e2e809ceeac9a57b2d1fb78a3a20e  apisix-runtime-debug_1.3.18-0.debianbookworm-slim_amd64.deb
a7cf5040837e4d34f456e97ff9b858ce64bf95e3b2f647f5d3021de5a9770741  apisix-runtime-debug_1.3.18-0.debianbookworm-slim_arm64.deb

Which issue(s) this PR fixes:

N/A

Checklist

  • I have explained the need for this PR and the problem it solves
  • I have explained the changes or the new features added to this PR
  • I have added tests corresponding to this change
  • I have updated the documentation to reflect this change
  • I have verified that this change is backward compatible (If not, please discuss on the APISIX mailing list first)

The whole suite runs against the new runtime, which is the coverage a version bump can have; the crash it fixes has no APISIX-side surface to assert on beyond the dubbo test that already exercises it.

1.3.18 builds against ngx_multi_upstream_module 1.3.4
(api7/ngx_multi_upstream_module#22), which fixes a worker SIGSEGV in
`ngx_http_multi_upstream_connection_close()`: it destroyed the connection
pool before `ngx_close_connection()`, which still logs through `c->log`
living in that pool.
Copilot AI lite review requested due to automatic review settings August 27, 2026 06:59
@dosubot dosubot Bot added size:XS This PR changes 0-9 lines, ignoring generated files. dependencies Pull requests that update a dependency file labels Aug 27, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@membphis membphis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nic-6443
nic-6443 merged commit 9037ee5 into apache:master Aug 31, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants