Skip to content

Update dependency 3proxy/3proxy to v1 - #101

Merged
tarampampam merged 2 commits into
masterfrom
renovate/3proxy-3proxy-1.x
Sep 1, 2026
Merged

tarampampam merged 2 commits into
masterfrom
renovate/3proxy-3proxy-1.x

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
3proxy/3proxy libraries major 0.9.7 → 1.0.0

Release Notes

3proxy/3proxy (3proxy/3proxy)

v1.0.0: 3proxy-1.0.0

Compare Source

This release starts a split into two branches.
current is the master branch, which this release comes from.
lts is 0.9 branch with bugfixes only

Docker images and the package repository follow the same names: lts tags
and the lts channel are built from 0.9, latest tags and the current channel
from master.

No changes in 3proxy code since 0.9.9, this release only changes how packages are built, signed and published.

! Fix: TLS, PCRE2 and PAM support was silently left out when 3proxy was built on a system whose /bin/sh is not dash, which is every RPM based distribution and macOS; the library checks built their test program with echo and escape sequences, which only dash expands, so every check failed and the features were dropped without a diagnostic
! Fix: rpm packages were built on Ubuntu and required glibc 2.38, libssl.so.3 and libpcre2-8, which no RPM based distribution provides, so they could not be installed anywhere; they are built against AlmaLinux 8, 9 and 10 now and carry an el8, el9 or el10 tag, covering RHEL, AlmaLinux, Rocky and CentOS Stream of the same version
! Fix: the rpm package depended on its own interpreter, /bin/3proxy, taken from the first line of the installed configuration file, and could not be installed on el9 or el10 because rpm resolves that dependency to /usr/bin/3proxy
! Fix: deb packages required glibc 2.38 and libssl3t64 and installed on Ubuntu 24.04 and newer only; they are built against Ubuntu 22.04 now and install on Ubuntu 22.04 and later as well as Debian 12 and later
+ Signed apt and dnf repositories are published at https://3proxy.org/repo/ in two channels: current, built from the master branch, and lts, built from the 0.9 branch; packages and repository metadata are both signed
+ Release binaries are published with SHA256 checksums, an OpenPGP signature and a GitHub build provenance attestation; docker images are signed and attested as well
+ The release signing key is an RSA-4096 key published as 3proxy-release-key.asc in the repository; rpm 4.14 and earlier can not import an Ed25519 key at all, which would leave RHEL 8 and its derivatives unable to verify anything
+ Packages are reproducible: rebuilding a release produces byte identical deb and rpm files, every timestamp is derived from the build date recorded for the release
- 32-bit ARM (armhf) is published as a deb package only, Enterprise Linux has no 32-bit ARM build

3proxy-1.0.0-x64.zip             - Win64 version
3proxy-1.0.0-x86.zip             - Win32 version
3proxy-1.0.0-arm64.zip           - Windows for ARM64 (ARMv8) version
3proxy-1.0.0-lite.zip            - Win32 binaries for older Windows version (Windows Vista and below)
3proxy-1.0.0.x86_64.deb          - x86 64 bit (amd64) DEB package
3proxy-1.0.0.arm64.deb           - 64 bit ARM (ARMv8, aarch64) DEB package
3proxy-1.0.0.arm.deb             - 32 bit ARM (ARMv7, armhf) DEB package
3proxy-1.0.0.el8.x86_64.rpm      - x86 64 bit RPM for EL8 (RHEL/AlmaLinux/Rocky 8)
3proxy-1.0.0.el9.x86_64.rpm      - x86 64 bit RPM for EL9
3proxy-1.0.0.el10.x86_64.rpm     - x86 64 bit RPM for EL10
3proxy-1.0.0.el8.aarch64.rpm     - 64 bit ARM RPM for EL8
3proxy-1.0.0.el9.aarch64.rpm     - 64 bit ARM RPM for EL9
3proxy-1.0.0.el10.aarch64.rpm    - 64 bit ARM RPM for EL10

3proxy_1.0.0-r1_mipsel_24kc.ipk               - OpenWrt, MediaTek MT7620/MT7621 (ramips)
3proxy_1.0.0-r1_mips_24kc.ipk                 - OpenWrt, Atheros/QCA (ath79)
3proxy_1.0.0-r1_arm_cortex-a7_neon-vfpv4.ipk  - OpenWrt, 32 bit ARM (ipq40xx)
3proxy_1.0.0-r1_aarch64_cortex-a53.ipk        - OpenWrt, 64 bit ARM (mediatek filogic)

SHA256SUMS-*      - checksums for each build
SHA256SUMS-*.asc  - OpenPGP signature of the checksums

Verify with the release key 3proxy-release-key.asc in the repository, see SECURITY.md.

The OpenWrt packages are built against OpenWrt 24.10 and depend on its
libopenssl and libpcre2. Install with opkg install ./<file>.ipk. The
package ships a UCI configuration in /etc/config/3proxy and a procd init
script; no service is enabled until you enable it there.

v0.9.9: 3proxy-0.9.9

Compare Source

+ SOCKSv5 UDP: the destination of every datagram is authorized, so ACLs limiting the destination address, host name or port apply to UDP traffic now; the parent proxy and the external address are selected for the destination of the datagram and not for the UDP ASSOCIATE request
+ socks: -U option to control what happens when the destination changes within an UDP association: log it, authorize it, both (default) or neither
+ -C option (for TCP services) to terminate the session as soon as any of the sides closes the connection; by default the session is kept until both sides close it (TCP half-close)
+ timeouts: LINGER value added (11th, default 5), used to deliver buffered data after one of the sides has closed its sending side and as SO_LINGER value on outgoing connections
! Fix: DNS replies are validated now: a reply from an address other than the nameserver the query was sent to, and a reply with a question section not matching the query, are dropped; both were accepted before
! Fix: socket leak with SOCKSv5 UDP ASSOCIATE through a parent proxy, sockets were accumulated in CLOSE_WAIT state until descriptors ran out
! Fix: file descriptor leak in HTTP proxy on the ftp:// request path
! Fix: crash with illegal instruction on some platforms (e.g. some musl based Linux builds), caused by a memcpy on overlapping buffers
! Fix: extip and ha (HAProxy PROXY protocol) parents are applied to SOCKSv5 UDP ASSOCIATE now
! Fix: only socks5 and socks5+ parents are tried for UDP ASSOCIATE, other parent types can not be used for UDP
! Fix: udppm through a SOCKSv5 parent did not work
! Fix: -Ne and -Ni options were never applied, the option letter was not parsed; -Ne is not applied to the UDP ASSOCIATE reply anymore, -Ni is applied to it
! Fix: -4 / -6 handling for UDP in socks; a single UDP association can use both IPv4 and IPv6 destinations now
! Fix: a datagram with a null destination address is dropped now
! Fix: DNS over TCP: a reply which did not fit a single read was never processed
! Documentation: "How to apply ACLs to UDP traffic" added to HOWTO; authentication cache, ACL and UDP notes added to "Optimizing 3proxy for High Load" and to security recommendations

3proxy-0.9.9-x64.zip - Win64 version
3proxy-0.9.9-x86.zip - Win32 version
3proxy-0.9.9-arm64.zip - Windows for ARM64 (ARMv8) version
3proxy-0.9.9-lite.zip - Win32 binaries for older Windows version (Windows
Vista and below)
3proxy-0.9.9.x86_64.deb - x86 64 bit (amd64) DEB package
3proxy-0.9.9.arm64.deb - 64 bit ARM (ARMv8, aarch64) DEB package
3proxy-0.9.9.arm.deb - 32 bit ARM (ARMv7, armhf) DEB package
3proxy-0.9.9.x86_64.rpm - x86 64 bit (amd64) RPM package
3proxy-0.9.9.arm64.rpm - 64 bit ARM (ARMv8, aarch64) RPM package
3proxy-0.9.9.arm.rpm - 32 bit ARM (ARMv7, armhf) RPM package

v0.9.8: 3proxy-0.9.8

Compare Source

!! Fix: use-after-free on the ftp:// request path in HTTP proxy, a request buffer reallocation left a stale pointer; heap corruption, requires authenticated access
!! Fix: buffer overflow in radsend() with an oversized request hostname; RADIUS is experimental, log radius or auth radius with fakeresolve is required to reach it
!! Fix: buffer overflow in smtpp when relaying AUTH LOGIN credentials to a server which offers AUTH PLAIN only; requires authorised access to smtpp
!! Fix: out-of-bounds read in tlspr on a malformed TLS ClientHello
!! Fix: LDAP injection and unsafe counter file names in LdapPlugin; the plugin is unsupported and is not built with 3proxy
!! Fix: password and hash comparison in strong authentication is constant-time now
!! Fix: bounds validation and match/depth limits in pcre filters
+ imapp: IMAPv4 proxy added, supports LOGIN command, AUTH PLAIN and AUTH LOGIN
+ STARTTLS support for smtpp, pop3p, imapp and tlspr, on both client and server side; -x option to disable
+ wolfSSL is supported as an alternative TLS backend, WOLFSSL_CHECK=true selects it (wolfSSL must be built with --enable-opensslextra)
+ Chunked Transfer-Encoding from client is supported by HTTP proxy
+ dnspr: -F option added, fake resolve to redirect traffic
+ ucrt64 build support; static libraries support in Makefile.win
+ minimal and busybox Docker images switched to musl + wolfSSL
- splice() support is not built by default anymore, it is slower than the read/write path for most traffic; add -DWITHSPLICE to build it
! Fix: hashtable item was added with wrong index on table grow; with large username/password tables it could cause a single record to be missing
! Fix: race conditions; stack overflow on FreeBSD
! Fix: generated certificates are X.509 v3 with basicConstraints CA:FALSE and extendedKeyUsage serverAuth, required by Apple TLS stack and by Chrome on macOS/iOS
! Fix: dnspr was broken since udppm rewrite
! Fix: short cleartext passwords failed authentication
! Fix: support PROXY (HAProxy) protocol for intermediate servers
! Fix: maxchild dropped to 100 on config reload if not set explicitly
! Fix: builds for legacy Linux / MacOS version
! Multiple minor bugfixes and code cleanup

Thanks to Tristan for reporting the buffer overflow in radsend(), and to Calif.io in
collaboration with Anthropic for reporting the use-after-free on the ftp:// request path.

3proxy-0.9.8-x64.zip - Win64 version
3proxy-0.9.8-x86.zip - Win32 version
3proxy-0.9.8-arm64.zip - Windows for ARM64 (ARMv8) version
3proxy-0.9.8-lite.zip - Win32 binaries for older Windows version (Windows
Vista and below)
3proxy-0.9.8.x86_64.deb - x86 64 bit (amd64) DEB package
3proxy-0.9.8.arm64.deb - 64 bit ARM (ARMv8, aarch64) DEB package
3proxy-0.9.8.arm.deb - 32 bit ARM (ARMv7, armhf) DEB package
3proxy-0.9.8.x86_64.rpm - x86 64 bit (amd64) RPM package
3proxy-0.9.8.arm64.rpm - 64 bit ARM (ARMv8, aarch64) RPM package
3proxy-0.9.8.arm.rpm - 32 bit ARM (ARMv7, armhf) RPM package


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "monthly"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 1, 2026
@renovate
renovate Bot requested a review from tarampampam as a code owner September 1, 2026 02:01
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 1, 2026
@renovate
renovate Bot force-pushed the renovate/3proxy-3proxy-1.x branch from 1ab49ec to a9d99c0 Compare September 1, 2026 08:28
@renovate

renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@tarampampam
tarampampam merged commit 3f72537 into master Sep 1, 2026
11 checks passed
@tarampampam
tarampampam deleted the renovate/3proxy-3proxy-1.x branch September 1, 2026 08:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant