Skip to content

xds/googlec2p: enable DirectPath over Interconnect support for on-prem clients - #9133

Merged
Pranjali-2501 merged 8 commits into
grpc:masterfrom
Pranjali-2501:gci-changes
Jun 9, 2026
Merged

Pranjali-2501 merged 8 commits into
grpc:masterfrom
Pranjali-2501:gci-changes

Conversation

@Pranjali-2501

@Pranjali-2501 Pranjali-2501 commented May 20, 2026 •

Copy link
Copy Markdown
Contributor

This PR add support for on-premises clients using Google Cloud Interconnect to connect to GCP services via DirectPath by enabling a forced xDS/C2P resolver path.

Changes:

  • Query Parameter Handling: Updates the google-c2p resolver to parse call target URLs for the force-xds query parameter.
  • Metadata Server Bypass: When executing off-GCP, GCE Metadata Server queries for locality zone and IPv6 capability are bypassed.
  • Bootstrap Config:
    • Omits the GCE locality zone structure from the bootstrap configuration.
    • Hardcodes the TRAFFICDIRECTOR_DIRECTPATH_C2P_IPV6_CAPABLE node metadata flag to true since Interconnect is planned exclusively for IPv6 clients.
    • Formats the xDS Client Node ID using a prefix: "C2P-non-gcp-UUID".

RELEASE NOTES:

  • xds/googlec2p: enable DirectPath over Interconnect support for on-premises clients via the force-xds query parameter in target URI.

@Pranjali-2501 Pranjali-2501 added this to the 1.82 Release milestone May 20, 2026
@Pranjali-2501 Pranjali-2501 added the Type: Behavior Change Behavior changes not categorized as bugs label May 20, 2026
@codecov

codecov Bot commented May 20, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 83.19%. Comparing base (6602080) to head (d85c45f).
⚠️ Report is 25 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #9133      +/-   ##
==========================================
- Coverage   83.20%   83.19%   -0.02%     
==========================================
  Files         414      418       +4     
  Lines       33489    33752     +263     
==========================================
+ Hits        27865    28080     +215     
- Misses       4214     4258      +44     
- Partials     1410     1414       +4     
Files with missing lines Coverage Δ
xds/googledirectpath/googlec2p.go 90.21% <100.00%> (+1.32%) ⬆️

... and 49 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@Pranjali-2501
Pranjali-2501 requested review from easwars and mbissa May 20, 2026 04:49
@easwars easwars removed their assignment May 20, 2026
@easwars

easwars commented May 20, 2026

Copy link
Copy Markdown
Contributor

Unassigning myself for the first review from @mbissa to complete.

@mbissa

mbissa commented May 22, 2026

Copy link
Copy Markdown
Contributor

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces support for non-GCE environments in the google-c2p resolver via a force-xds query parameter and updates node configuration logic to handle off-GCP scenarios. The review feedback identifies several improvement opportunities: validating the boolean value of the force-xds parameter to prevent forcing xDS when set to 'false', using buffered channels for goroutines to avoid potential leaks, and ensuring the node ID implementation aligns with the PR description's requirement for UUIDs instead of random integers.

Comment thread xds/googledirectpath/googlec2p.go Outdated
Comment thread xds/googledirectpath/googlec2p.go Outdated
Comment thread xds/googledirectpath/googlec2p.go
Comment thread xds/googledirectpath/googlec2p_test.go
Comment thread xds/googledirectpath/googlec2p_test.go
Comment thread xds/googledirectpath/googlec2p.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
@mbissa mbissa assigned Pranjali-2501 and unassigned mbissa May 26, 2026
@Pranjali-2501
Pranjali-2501 requested a review from mbissa May 26, 2026 12:27

@mbissa mbissa left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@mbissa mbissa assigned Pranjali-2501 and unassigned mbissa May 27, 2026
Comment thread xds/googledirectpath/googlec2p.go
Comment thread xds/googledirectpath/googlec2p.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go
@easwars easwars assigned Pranjali-2501 and unassigned easwars May 27, 2026
@Pranjali-2501
Pranjali-2501 requested a review from easwars May 28, 2026 16:59
@easwars easwars removed their assignment May 28, 2026
@mbissa mbissa modified the milestones: 1.82 Release, 1.83 Release Jun 5, 2026
Comment thread xds/googledirectpath/googlec2p.go Outdated
Comment thread xds/googledirectpath/googlec2p.go Outdated
Comment thread xds/googledirectpath/googlec2p.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
Comment thread xds/googledirectpath/googlec2p_test.go Outdated
@easwars easwars assigned Pranjali-2501 and unassigned easwars Jun 5, 2026
@easwars

easwars commented Jun 5, 2026

Copy link
Copy Markdown
Contributor

Also, please fix the PR description that talks about preventing timeouts.

@easwars

easwars commented Jun 5, 2026

Copy link
Copy Markdown
Contributor

And add a release note

@Pranjali-2501
Pranjali-2501 requested a review from easwars June 8, 2026 06:26
@easwars easwars assigned Pranjali-2501 and unassigned easwars Jun 8, 2026

@easwars easwars left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@easwars easwars assigned Pranjali-2501 and unassigned easwars Jun 9, 2026
@Pranjali-2501
Pranjali-2501 merged commit c76cc7f into grpc:master Jun 9, 2026
14 checks passed
goingforstudying-ctrl added a commit to goingforstudying-ctrl/grpc-go that referenced this pull request Jun 21, 2026
…m clients (grpc#9133)

This PR add support for on-premises clients using Google Cloud
Interconnect to connect to GCP services via DirectPath by enabling a
forced xDS/C2P resolver path.
  
Changes:
- **Query Parameter Handling:** Updates the `google-c2p` resolver to
parse call target URLs for the `force-xds` query parameter.
- **Metadata Server Bypass:** When executing off-GCP, GCE Metadata
Server queries for locality zone and IPv6 capability are bypassed.
  - **Bootstrap Config:**
- Omits the GCE locality zone structure from the bootstrap
configuration.
- Hardcodes the `TRAFFICDIRECTOR_DIRECTPATH_C2P_IPV6_CAPABLE` node
metadata flag to `true` since Interconnect is planned exclusively for
IPv6 clients.
- Formats the xDS Client Node ID using a prefix: `"C2P-non-gcp-UUID"`.
    
RELEASE NOTES:
- xds/googlec2p: enable DirectPath over Interconnect support for
on-premises clients via the `force-xds` query parameter in target URI.
eleboucher pushed a commit to eleboucher/runner-k8s-plugin that referenced this pull request Aug 19, 2026
…(#83)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.0` → `v1.83.1` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.83.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.82.0/v1.83.1?slim=true) |

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1

[Compare Source](grpc/grpc-go@v1.83.0...v1.83.1)

### Security

- xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#&#8203;9258](grpc/grpc-go#9258))
  - Special Thanks: [@&#8203;nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#&#8203;9258](grpc/grpc-go#9258))
  - Special Thanks: [@&#8203;nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)

### Performance

- transport: Restrict memory overhead of buffering small data frames. ([#&#8203;9331](grpc/grpc-go#9331))

### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0

[Compare Source](grpc/grpc-go@v1.82.1...v1.83.0)

### Security

- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`.
- xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields.  If present in a DENY rule, previously these would be ignored and fail-open.
- xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions.
- xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`.
- xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#&#8203;9223](grpc/grpc-go#9223))

### New Features

- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#&#8203;9133](grpc/grpc-go#9133))
- xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. ([#&#8203;9145](grpc/grpc-go#9145))
- authz: Add `OnPolicyUpdate` callback to `FileWatcherOptions` to notify when an authz policy is loaded or updated. ([#&#8203;9142](grpc/grpc-go#9142))
  - Special Thanks: [@&#8203;hnefatl](https://github.com/hnefatl)
- xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
  - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true`. ([#&#8203;9119](grpc/grpc-go#9119))
- xds: Add support for xDS-based HTTP CONNECT proxies.
  - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true`. ([#&#8203;9151](grpc/grpc-go#9151))
- xds: Add support for `contains_match` in route header matchers. ([#&#8203;9223](grpc/grpc-go#9223))

### Bug Fixes

- credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. ([#&#8203;9197](grpc/grpc-go#9197))
- grpc: Fix compilation on Plan 9 targets (`GOOS=plan9`), broken since v1.81.0. ([#&#8203;9255](grpc/grpc-go#9255))
  - Special Thanks: [@&#8203;Yusufihsangorgel](https://github.com/Yusufihsangorgel)

### [`v1.82.1`](https://github.com/grpc/grpc-go/releases/tag/v1.82.1): Release 1.82.1

[Compare Source](grpc/grpc-go@v1.82.0...v1.82.1)

### Security

- server: Stop reading from the connection when flooded by HTTP/2 frames.  The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`.
- xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields.  If present in a DENY rule, previously these would be ignored and fail-open.
- xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions.
- xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`.

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Paris)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjMxLjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInR5cGUvbWlub3IiXX0=-->

Reviewed-on: https://git.erwanleboucher.dev/eleboucher/runner-k8s-plugin/pulls/83
nschloe pushed a commit to live-clones/forgejo that referenced this pull request Sep 3, 2026
…/forgejo) (#14216)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.1` → `v1.83.1` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.83.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.82.1/v1.83.1?slim=true) |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2779) for more information.

---

### gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
[CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](GHSA-vp52-pcj8-j9qc)

<details>
<summary>More information</summary>

#### Details
##### Impact
An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation.

Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS).

##### Patches
The change to fix this issue is merged in `master` and a patch release, 1.83.1, has been published that contains this fix.

##### Workarounds
This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads.

This behavior is enabled by default. A temporary escape hatch is provided via the environment variable `GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false` to disable the feature if unforeseen issues arise, but it will be removed in a future release.

#### Severity
- CVSS Score: 8.7 / 10 (High)
- Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N`

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc)
- [https://nvd.nist.gov/vuln/detail/CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304)
- [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331)
- [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333)
- [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176)
- [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77)
- [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go)
- [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1)

This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-vp52-pcj8-j9qc) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1

[Compare Source](grpc/grpc-go@v1.83.0...v1.83.1)

### Security

- xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#&#8203;9258](grpc/grpc-go#9258))
  - Special Thanks: [@&#8203;nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#&#8203;9258](grpc/grpc-go#9258))
  - Special Thanks: [@&#8203;nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)

### Performance

- transport: Restrict memory overhead of buffering small data frames. ([#&#8203;9331](grpc/grpc-go#9331))

### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0

[Compare Source](grpc/grpc-go@v1.82.2...v1.83.0)

### Security

- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`.
- xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields.  If present in a DENY rule, previously these would be ignored and fail-open.
- xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions.
- xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`.
- xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#&#8203;9223](grpc/grpc-go#9223))

### New Features

- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#&#8203;9133](grpc/grpc-go#9133))
- xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. ([#&#8203;9145](grpc/grpc-go#9145))
- authz: Add `OnPolicyUpdate` callback to `FileWatcherOptions` to notify when an authz policy is loaded or updated. ([#&#8203;9142](grpc/grpc-go#9142))
  - Special Thanks: [@&#8203;hnefatl](https://github.com/hnefatl)
- xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
  - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true`. ([#&#8203;9119](grpc/grpc-go#9119))
- xds: Add support for xDS-based HTTP CONNECT proxies.
  - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true`. ([#&#8203;9151](grpc/grpc-go#9151))
- xds: Add support for `contains_match` in route header matchers. ([#&#8203;9223](grpc/grpc-go#9223))

### Bug Fixes

- credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. ([#&#8203;9197](grpc/grpc-go#9197))
- grpc: Fix compilation on Plan 9 targets (`GOOS=plan9`), broken since v1.81.0. ([#&#8203;9255](grpc/grpc-go#9255))
  - Special Thanks: [@&#8203;Yusufihsangorgel](https://github.com/Yusufihsangorgel)

### [`v1.82.2`](https://github.com/grpc/grpc-go/releases/tag/v1.82.2): Release 1.82.2

[Compare Source](grpc/grpc-go@v1.82.1...v1.82.2)

### Security

- server: Reject requests missing both `:authority` and `Host` headers with HTTP 400 and status `Internal`. ([#&#8203;9365](grpc/grpc-go#9365))
  - Special Thanks: [@&#8203;winklemad](https://github.com/winklemad)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC41Mi4wIiwidXBkYXRlZEluVmVyIjoiNDQuNTIuMCIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14216
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
GiteaBot pushed a commit to go-gitea/terraform-provider-gitea that referenced this pull request Sep 25, 2026
… (#211)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.1` → `v1.83.1` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.83.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.82.1/v1.83.1?slim=true) |

---

### gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
[CVE-2026-84445](https://nvd.nist.gov/vuln/detail/CVE-2026-84445) / [GHSA-2v4p-qf9q-27wj](GHSA-2v4p-qf9q-27wj) / [GO-2026-6443](https://pkg.go.dev/vuln/GO-2026-6443)

<details>
<summary>More information</summary>

#### Details
A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS).

Servers built with `xds.NewGRPCServer` install an xDS routing interceptor on every RPC. This interceptor looks up the request’s `:authority` header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither `:authority` nor `Host`. When this happened, the xDS routing interceptor attempted to access the first element of an empty slice of authorities, leading to an index out of bounds panic. Since the per-RPC goroutine does not recover from panics, the entire server process would terminate.

This panic occurs in the interceptor pipeline, meaning the transport credentials handshake (TLS, mTLS, or ALTS) and HTTP/2 connection establishment must complete successfully before the crafted request can reach this logic.
- Insecure/Standard TLS: If the server permits insecure (plaintext) connections or standard credentials (where client certs are not checked), any unauthenticated remote attacker can trigger the crash.
- mTLS / ALTS: If strict transport-level authentication is enforced at the network edge or transport layer (e.g., requiring a valid client certificate), the attacker must possess valid transport credentials to initiate the stream and trigger the panic.

##### Impact
An attacker can cause a complete outage of the gRPC server by sending a request missing both `:authority` and `Host` headers, provided they can successfully establish a transport connection.

##### Patches
The issue has been addressed in `master` (and backported to `1.83.2` and `1.82.2`). The fix updates the HTTP/2 transport layer to reject requests missing both `:authority` and `Host` headers early, maintaining consistency with and other gRPC language implementations.

#### Severity
High

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj](https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj)
- [https://github.com/grpc/grpc-go/issues/9354](https://github.com/grpc/grpc-go/issues/9354)
- [https://github.com/grpc/grpc-go/pull/9365](https://github.com/grpc/grpc-go/pull/9365)
- [https://github.com/grpc/grpc-go/pull/9366](https://github.com/grpc/grpc-go/pull/9366)
- [https://github.com/grpc/grpc-go/pull/9367](https://github.com/grpc/grpc-go/pull/9367)
- [https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7](https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7)
- [https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4](https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4)
- [https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f](https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f)
- [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go)
- [https://github.com/grpc/grpc-go/releases/tag/v1.82.2](https://github.com/grpc/grpc-go/releases/tag/v1.82.2)
- [https://github.com/grpc/grpc-go/releases/tag/v1.83.2](https://github.com/grpc/grpc-go/releases/tag/v1.83.2)

This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-2v4p-qf9q-27wj) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Server panic via missing authority or Host headers in google.golang.org/grpc
[CVE-2026-84445](https://nvd.nist.gov/vuln/detail/CVE-2026-84445) / [GHSA-2v4p-qf9q-27wj](GHSA-2v4p-qf9q-27wj) / [GO-2026-6443](https://pkg.go.dev/vuln/GO-2026-6443)

<details>
<summary>More information</summary>

#### Details
In google.golang.org/grpc, servers configured with xDS routing can panic when processing requests that lack both :authority and Host headers. The HTTP/2 transport layer accepted requests missing these headers, and the xDS server routing interceptor attempted to index the empty authority slice, causing an unhandled panic and terminating the server.

#### Severity
Unknown

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj](https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj)
- [https://github.com/grpc/grpc-go/issues/9354](https://github.com/grpc/grpc-go/issues/9354)
- [https://github.com/grpc/grpc-go/pull/9365](https://github.com/grpc/grpc-go/pull/9365)

This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6443) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
[CVE-2026-84303](https://nvd.nist.gov/vuln/detail/CVE-2026-84303) / [GHSA-qc2q-p7wx-3px3](GHSA-qc2q-p7wx-3px3) / [GO-2026-6441](https://pkg.go.dev/vuln/GO-2026-6441)

<details>
<summary>More information</summary>

#### Details
##### Summary
A vulnerability in the xDS RBAC HTTP filter implementation in grpc-go allows remote attackers to bypass authorization policies (specifically DENY rules) by using mixed-case or canonical-case header matchers (e.g., X-Role instead of x-role). Additionally, the safety guards introduced by gRFC A41 to block grpc- prefixed headers can be evaded via variations in casing (e.g., Grpc-Status).

##### Impact
When an operator defines an RBAC policy referencing headers containing uppercase letters (e.g. X-Role), grpc-go fails to match incoming metadata keys because they are unconditionally lowercased. Because of this case-sensitivity mismatch, a policy designed to block requests containing specific header values fails open: the rule is evaluated as a non-match, and traffic that should have been rejected is served.

Furthermore, gRFC A41 requires rejecting configuration schemas specifying header matchers starting with grpc-. Because this check is executed case-sensitively in grpc-go, attackers can bypass the validation by specifying titles like Grpc-Status.

##### Patches
The problem is fixed in `master` and in the 1.83.1 release.

#### Severity
- CVSS Score: 6.3 / 10 (Medium)
- Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N`

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3](https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3)
- [https://nvd.nist.gov/vuln/detail/CVE-2026-84303](https://nvd.nist.gov/vuln/detail/CVE-2026-84303)
- [https://github.com/grpc/grpc-go/pull/9332](https://github.com/grpc/grpc-go/pull/9332)
- [https://github.com/grpc/grpc-go/pull/9335](https://github.com/grpc/grpc-go/pull/9335)
- [https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8](https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8)
- [https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe](https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe)
- [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go)
- [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1)

This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-qc2q-p7wx-3px3) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
[CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](GHSA-vp52-pcj8-j9qc) / [GO-2026-6348](https://pkg.go.dev/vuln/GO-2026-6348)

<details>
<summary>More information</summary>

#### Details
##### Impact
An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation.

Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS).

##### Patches
The change to fix this issue is merged in `master` and a patch release, 1.83.1, has been published that contains this fix.

##### Workarounds
This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads.

This behavior is enabled by default. A temporary escape hatch is provided via the environment variable `GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false` to disable the feature if unforeseen issues arise, but it will be removed in a future release.

#### Severity
- CVSS Score: 8.7 / 10 (High)
- Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N`

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc)
- [https://nvd.nist.gov/vuln/detail/CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304)
- [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331)
- [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333)
- [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176)
- [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77)
- [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go)
- [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1)

This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-vp52-pcj8-j9qc) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc
[CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](GHSA-vp52-pcj8-j9qc) / [GO-2026-6348](https://pkg.go.dev/vuln/GO-2026-6348)

<details>
<summary>More information</summary>

#### Details
Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc

#### Severity
Unknown

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc)
- [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176)
- [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77)
- [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331)
- [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333)
- [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1)

This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6348) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc
[CVE-2026-84303](https://nvd.nist.gov/vuln/detail/CVE-2026-84303) / [GHSA-qc2q-p7wx-3px3](GHSA-qc2q-p7wx-3px3) / [GO-2026-6441](https://pkg.go.dev/vuln/GO-2026-6441)

<details>
<summary>More information</summary>

#### Details
In google.golang.org/grpc, the xDS RBAC HTTP filter does not lowercase header matcher names before evaluating them against incoming request metadata. When an RBAC policy defines rules (such as DENY) referencing headers with uppercase or mixed-case characters, the rule fails to match, causing authorization policies to fail open. Additionally, callers can evade gRFC A41 validation blocking "grpc-" prefixed headers and ":scheme" via variations in casing.

#### Severity
Unknown

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3](https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3)
- [https://github.com/grpc/grpc-go/pull/9332](https://github.com/grpc/grpc-go/pull/9332)

This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6441) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1

[Compare Source](grpc/grpc-go@v1.83.0...v1.83.1)

### Security

- xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#&#8203;9258](grpc/grpc-go#9258))
  - Special Thanks: [@&#8203;nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#&#8203;9258](grpc/grpc-go#9258))
  - Special Thanks: [@&#8203;nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#&#8203;9332](grpc/grpc-go#9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)

### Performance

- transport: Restrict memory overhead of buffering small data frames. ([#&#8203;9331](grpc/grpc-go#9331))

### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0

[Compare Source](grpc/grpc-go@v1.82.2...v1.83.0)

### Security

- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`.
- xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields.  If present in a DENY rule, previously these would be ignored and fail-open.
- xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions.
- xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`.
- xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#&#8203;9223](grpc/grpc-go#9223))

### New Features

- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#&#8203;9133](grpc/grpc-go#9133))
- xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. ([#&#8203;9145](grpc/grpc-go#9145))
- authz: Add `OnPolicyUpdate` callback to `FileWatcherOptions` to notify when an authz policy is loaded or updated. ([#&#8203;9142](grpc/grpc-go#9142))
  - Special Thanks: [@&#8203;hnefatl](https://github.com/hnefatl)
- xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
  - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true`. ([#&#8203;9119](grpc/grpc-go#9119))
- xds: Add support for xDS-based HTTP CONNECT proxies.
  - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true`. ([#&#8203;9151](grpc/grpc-go#9151))
- xds: Add support for `contains_match` in route header matchers. ([#&#8203;9223](grpc/grpc-go#9223))

### Bug Fixes

- credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. ([#&#8203;9197](grpc/grpc-go#9197))
- grpc: Fix compilation on Plan 9 targets (`GOOS=plan9`), broken since v1.81.0. ([#&#8203;9255](grpc/grpc-go#9255))
  - Special Thanks: [@&#8203;Yusufihsangorgel](https://github.com/Yusufihsangorgel)

### [`v1.82.2`](https://github.com/grpc/grpc-go/releases/tag/v1.82.2): Release 1.82.2

[Compare Source](grpc/grpc-go@v1.82.1...v1.82.2)

### Security

- server: Reject requests missing both `:authority` and `Host` headers with HTTP 400 and status `Internal`. ([#&#8203;9365](grpc/grpc-go#9365))
  - Special Thanks: [@&#8203;winklemad](https://github.com/winklemad)

</details>

---

Reviewed-on: https://gitea.com/gitea/terraform-provider-gitea/pulls/211
Reviewed-by: Lunny Xiao <xiaolunwen@gmail.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Jercik added a commit to Jercik/forgejo that referenced this pull request Oct 3, 2026
* [v16.0/forgejo] fix: prevent panic by returning error if dbfs file does not exist (#13697)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13649

Resolves https://codeberg.org/forgejo/forgejo/issues/13636.

Co-authored-by: Andreas Ahlenstorf <andreas@ahlenstorf.ch>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13697
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] fix: bad quoting in hook scripts allow word splitting, leading to hook script errors (#13726)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13679

Should fix #13662

Co-authored-by: erik <erik_se@posteo.de>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13726
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] fix: trigger Actions for original commits (#13706) (#13736)

Resolves https://codeberg.org/forgejo/forgejo/issues/12572.

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13706
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

(cherry picked from commit 43ced2b1c0360005e8c59ed5ab9ea326485a9ef4)

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13736
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] fix: send 401 responses when accessing endpoints that don't support session auth (#13742)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13740

Fixes #13555.

Floccus is a browser extension which supports git-based syncing.  It does not isolate its cookie jar, and so requests to the git endpoints send browser cookies.  Forgejo doesn't permit session cookies to access to git endpoints (changed in v16 https://codeberg.org/forgejo/forgejo/pulls/12715#issuecomment-15841751), but the presence of the cookies would trigger Forgejo into redirecting the request to `/user/login` rather than providing a `401 Unauthorized` response.  Floccus requires a 401 unauthorized response in order to send its configured credentials; so it would get stuck in a redirect loop even though it had credentials available, never sending them.

After manual testing, an additional change was added to prevent Floccus' behaviour from invalidating the user's perfectly valid session, which would occur when the first `401 Unauthorized` response was issued.  Now, session invalidation only occurs if session authentication was attempted.

## Testing

In addition to automated testing, this issue was reproduced interactively with the Floccus browser extension, both experiencing the problem, and testing the fix.  "Remember Me" cookie persistence was also revalidated manually by removing session cookies and reaccessing Forgejo, verifying new session cookies were provisioned.

Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13742
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] fix: error when replying to comments on removed lines-of-code in review (#13766)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13718

When a pull request review comment is placed on a `previous` line -- a line that was removed in the PR, or a line on the left-hand-side of the diff -- it is not possible to reply to the comment.  A 500 error will occur when posting the comment, and the server will log an error similar to this:

```
testlogger.go:411: 2026/07/31 14:06:54 .../repo/pull_review.go:135:CreateCodeComment() [E] CreateCodeComment: LineBlame[refs/pull/1/head, /tmp/TestPullRequestCommentPlacement1823572717/001/user2/repo-testpullrequestcommentplacement_reply_to_review_on_removed_change-f58f427a.git, file1.md, -50]: exit status 128 - fatal: bad revision ''
             - fatal: bad revision ''
```

The cause is that when creating a comment, Forgejo is attempting to fill out a variety of fields such as the commit SHA and patch for the comment, even in a reply.  Replies to positive line numbers (`proposed` lines) check for existing comments that are being replied to, and copy those fields from the original comment.  Replies to negative line numbers (`previous` lines) did not hit this code path.

The fix is to run the search for the comment being replied to in both cases.

Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13766
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* Update dependency postcss to v8.5.23 [SECURITY] (v16.0/forgejo) (#13762)

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13762
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix: exclude deleted artifacts when calculating storage consumption (#13798)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13786

Resolves https://codeberg.org/forgejo/forgejo/issues/13781.

Co-authored-by: Andreas Ahlenstorf <andreas@ahlenstorf.ch>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13798
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix: use HTML link for pull request webhook (#13802)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13692

- Resolves forgejo/forgejo#13501
- Regression of forgejo/forgejo!12643, I would argue that the webhook code should've used `HTMLURL` already instead (all the other events already do).

Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13802
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* Update dependency mermaid to v11.16.1 [SECURITY] (v16.0/forgejo) (#13809)

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13809
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* fix(ui): hashbox alignment (#13768) (#13810)

Backport: https://codeberg.org/forgejo/forgejo/pulls/13768

---

Followup to forgejo/forgejo!7822, forgejo/forgejo!8721

Fix signature part not filling the whole height, fix vertical alignment of placeholder avatar. With a little E2E test verifying just one property. We don't have any E2E coverage for hashbox, so we finally gain some as a foundation.

(cherry picked from commit a67fbbd87d07e3adc5e771fcd247bcef6f3dac14)

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13810
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix(package/pypi): response header based on PEP691 (#13816)

The response Content-Type doesn't match PEP691 so `uv` is rejecting it.

```
error: Unsupported `Content-Type` "application/json" for ...
       Expected JSON or HTML.
```

Resolves #13703

Co-authored-by: trim21 <trim21@noreply.codeberg.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13816
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix: bump minimum version to use git-replay on (#13824)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13591

While git-replay is generally available since version 2.44, until a fix
released with version 2.54 it will spawn empty commits if a commit was
already part of the base branch, instead of skipping it like git-rebase.

See https://github.com/git/git/commit/0ee71f4bd035db61342c2c5a25984e4545347c11

Co-authored-by: BtbN <btbn@btbn.de>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13824
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix: prevent Actions trigger `pull_request` from drifting (#13828)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13752

The `pull_request` Actions trigger suffers from the problem described in https://codeberg.org/forgejo/forgejo/issues/12572, too. Follow-up to https://codeberg.org/forgejo/forgejo/pulls/13706.

Co-authored-by: Andreas Ahlenstorf <andreas@ahlenstorf.ch>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13828
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>

* [v16.0/forgejo] chore: retry diff page load on TestPullRequestCommentPlacement when expected commit isn't matched (#13825)

**Backport:** #13808

Fixes #13275, an intermittent test failure.

The cause of this failure was identified in https://codeberg.org/forgejo/forgejo/issues/13275#issuecomment-20580638, but efforts to fix the queuing proved implausible at the moment (immediate mode execution caused deadlocks between multiple interacting systems).  This is a simple fix for the test failure, reloading the page if the concurrent work to sync the PR reference isn't complete yet.

Backport from `forgejo` to `v16.0/forgejo` required incorporation of diagnostic changes from #13757 which added the new parameter to `assertFilesChangedDiff`, and otherwise involved no conflicts.

(cherry picked from commit 2fdeaf24b902cca5dee56eeaae48d4e6714e8270)

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13808
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13825
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] chore: make `TestCannotCreatePrivateKey` pass in Guix container (#13836)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13794

`/dev` is writable in Guix container. Use a directory at the root of the file system, more likely to not be writable in containers.

Co-authored-by: Maxim Cournoyer <maxim@guixotic.coop>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13836
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix(api): unblock fall-through to urlencoded names in wiki (#13842)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13720

Helps with https://codeberg.org/forgejo/forgejo/issues/13719

Co-authored-by: Ben Tasker <bentasker@noreply.codeberg.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13842
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] fix: expire task logs even if there is no log file (#13851)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13839

Resolves https://codeberg.org/forgejo/forgejo/issues/13790.

Co-authored-by: Andreas Ahlenstorf <andreas@ahlenstorf.ch>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13851
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>

* [v16.0/forgejo] webhook(matrix): fix stateKey collision swallowing messages (#13862)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13820

The previous stateKey computation depended on the sent text, which could
be the same for 2 events (e.g. a user makes 2 comments on the same PR).

Fixes #13813

Co-authored-by: oliverpool <git@olivier.pfad.fr>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13862
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
Reviewed-by: oliverpool <oliverpool@noreply.codeberg.org>

* [v16.0/forgejo] fix(conda): parse null dependencies as empty array (#13871)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13865

- It's possible for the package upload to indicate there's no
  dependencies via the `null` value. However, as does Conda itself, the
  such value is still transformed to a empty array.
- Remove `omitempty` so a empty array value is stored (in the database)
  and send (to the API consumer) explicitly.
- Resolves forgejo/forgejo#13413

Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13871
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>

* [v16.0/forgejo] fix(api): mark fields for issue dependencies/blocks as required (#13872)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13864

Ref: forgejo/forgejo#13439

The description of the API routes already make it clear that this struct (as HTTP body) should used to specify the dependency/block/target issue.

Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13872
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>

* [v16.0/forgejo] fix: do not read past the last line when formatting zoekt search results (#13889)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13811

When `REPO_INDEXER_TYPE = zoekt` is used, a code search could fail if the last line of a file matches but does not include a newline.

```
PANIC: runtime error: index out of range [2] with length 2
...
    forgejo.org/modules/indexer/code/zoekt/zoekt.go:510 (0x62223da)
    forgejo.org/modules/indexer/code/search.go:76 (0x622c483)
    forgejo.org/modules/indexer/code/search.go:140 (0x622cf44)
...
```

Clamp the upper bound to the number of lines that actually exist.

Co-authored-by: nsprd <nsprd@pm.me>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13889
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix: adopt repositories from user settings (#13902)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13659

Regression of forgejo/forgejo!10287

## Test
1. Go to your forgejo's data directory, inside that the directory where the git repositories are stored.
2. Go to a directory of any user you've access to, run inside of that directory `git init --bare pr-13659.git`.
3. Navigate to `/user/settings/repos`
4. Observe that there's a repository you can adopt, and that the dialog associated with the buttons works.

Reported-by: 0ko

Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13902
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* Update go toolchain directive to v1.26.6 [SECURITY] (v16.0/forgejo) (#13915)

* Update golang.org/x/mod (indirect) to v0.40.0 [SECURITY] (v16.0/forgejo) (#13916)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/mod](https://pkg.go.dev/golang.org/x/mod) | [`v0.37.0` → `v0.40.0`](https://cs.opensource.google/go/x/mod/+/refs/tags/v0.37.0...refs/tags/v0.40.0) | ![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fmod/v0.40.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fmod/v0.37.0/v0.40.0?slim=true) |

---

### Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
[CVE-2026-56865](https://nvd.nist.gov/vuln/detail/CVE-2026-56865) / [GO-2026-6179](https://pkg.go.dev/vuln/GO-2026-6179)

<details>
<summary>More information</summary>

#### Details
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache.

This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log.

All tiles are now correctly verified against their parents.

In order to determine if you have been affected:

rm -r go.sum go.work.sum vendor/ && go mod tidy

#### Severity
Unknown

#### References
- [https://go.dev/issue/80744](https://go.dev/issue/80744)
- [https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
- [https://go.dev/cl/814960](https://go.dev/cl/814960)
- [https://go.dev/cl/815020](https://go.dev/cl/815020)

This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6179) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
[CVE-2026-56864](https://nvd.nist.gov/vuln/detail/CVE-2026-56864) / [GO-2026-6180](https://pkg.go.dev/vuln/GO-2026-6180)

<details>
<summary>More information</summary>

#### Details
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log.

This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log.

In order to determine if you have been affected:

rm -r go.sum go.work.sum vendor/ && go mod tidy

#### Severity
Unknown

#### References
- [https://go.dev/issue/80745](https://go.dev/issue/80745)
- [https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
- [https://go.dev/cl/815000](https://go.dev/cl/815000)
- [https://go.dev/cl/815020](https://go.dev/cl/815020)

This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6180) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNy4xIiwidXBkYXRlZEluVmVyIjoiNDQuMTcuMSIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13916
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>

* Update module golang.org/x/image to v0.45.0 [SECURITY] (v16.0/forgejo) (#13927)

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13927
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] i18n: translations update from Codeberg Translate

Backport: https://codeberg.org/forgejo/forgejo/pulls/13467

Translation updates that were relevant to v16 branch were picked from this commit: 17d255ae08fb883244b17feab9910c63407e8d3b

Changes to strings that are only present in the newer branches were not picked.

Below is a list of co-authors of the ported commit. It may contain co-authors who's changes were not picked due to only being relevant to newer branches.

Co-authored-by: 0ko <0ko@noreply.codeberg.org>
Co-authored-by: 20Niko10 <20niko10@noreply.codeberg.org>
Co-authored-by: Atalanttore <atalanttore@noreply.codeberg.org>
Co-authored-by: Benedikt Straub <benedikt-straub@web.de>
Co-authored-by: Codeberg Translate <translate@codeberg.org>
Co-authored-by: Cyborus <cyborus@noreply.codeberg.org>
Co-authored-by: Edgarsons <edgarsons@noreply.codeberg.org>
Co-authored-by: Elviska <elviska@noreply.codeberg.org>
Co-authored-by: ErenayDev <erenaydev@proton.me>
Co-authored-by: Erin of Yukis <ntninja@noreply.codeberg.org>
Co-authored-by: EternalAbby <eternalabby@noreply.codeberg.org>
Co-authored-by: Fjuro <fjuro@noreply.codeberg.org>
Co-authored-by: Gusted <postmaster@gusted.xyz>
Co-authored-by: Kyush <kyush@noreply.codeberg.org>
Co-authored-by: Nikolaus Delrow <github@koolych.ru>
Co-authored-by: ShutterStarTW <shutterstartw@noreply.codeberg.org>
Co-authored-by: SomeTr <sometr@noreply.codeberg.org>
Co-authored-by: Teeed <teeed@noreply.codeberg.org>
Co-authored-by: ThinkRoot <thinkroot@noreply.codeberg.org>
Co-authored-by: WKobes <wkobes@noreply.codeberg.org>
Co-authored-by: WebSpider <webspider@noreply.codeberg.org>
Co-authored-by: Wuzzy <wuzzy@disroot.org>
Co-authored-by: Zughy <zughy@noreply.codeberg.org>
Co-authored-by: admindev <admindev@noreply.codeberg.org>
Co-authored-by: artnay <artnay@noreply.codeberg.org>
Co-authored-by: bespinas <bespinas@noreply.codeberg.org>
Co-authored-by: bittin <bittin@noreply.codeberg.org>
Co-authored-by: codeeleven <codeeleven@noreply.codeberg.org>
Co-authored-by: dennis-emstone <dennis-emstone@noreply.codeberg.org>
Co-authored-by: dsonck <dsonck@noreply.codeberg.org>
Co-authored-by: dyniec <dyniec@noreply.codeberg.org>
Co-authored-by: fbausch <fbausch@noreply.codeberg.org>
Co-authored-by: gallegonovato <gallegonovato@noreply.codeberg.org>
Co-authored-by: itscrystalline <itscrystalline@noreply.codeberg.org>
Co-authored-by: joxeankoret <joxeankoret@noreply.codeberg.org>
Co-authored-by: jsyoon <jsyoon@noreply.codeberg.org>
Co-authored-by: kaua <kaua@noreply.codeberg.org>
Co-authored-by: kdh8219 <kdh8219@monamo.dev>
Co-authored-by: khangreat <khangreat@noreply.codeberg.org>
Co-authored-by: kzzzl <kzzzl@noreply.codeberg.org>
Co-authored-by: lapor <lapor@noreply.codeberg.org>
Co-authored-by: leiho-kristal-herdoilduak <leiho-kristal-herdoilduak@noreply.codeberg.org>
Co-authored-by: m4rc3l <m4rc3l@noreply.codeberg.org>
Co-authored-by: markinosags <markinosags@noreply.codeberg.org>
Co-authored-by: menneske <menneske@noreply.codeberg.org>
Co-authored-by: ommrianxo <ommrianxo@noreply.codeberg.org>
Co-authored-by: pixelcode <pixelcode@noreply.codeberg.org>
Co-authored-by: pkkim <pkkim@noreply.codeberg.org>
Co-authored-by: sinsky <sinsky@noreply.codeberg.org>
Co-authored-by: vmtj <vmtj@noreply.codeberg.org>
Co-authored-by: woolhat <woolhat@noreply.codeberg.org>
Co-authored-by: xtex <xtexchooser@duck.com>
Co-authored-by: yitian <yitian@noreply.codeberg.org>

* fix: public-only and repo-specific access to /repos/{owner}/{repo}/pulls/{index}/update

* fix: expand local reusable workflows from base branch w/ pull_request_target

* fix: disallow owner as collaboration access mode

An repository admin could (self-)escalate to repository owner
permissions. A higher permission mode than a repository admin.

* chore: add integration test

* Update go toolchain directive to v1.26.7 (v16.0/forgejo) (#13992)

* [v16.0/forgejo] fix(security): prevent unauthorized access to draft release attachments (#14024)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13934

The `GetReleaseAttachment` API endpoint (`GET /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id}`) and the web attachment download route (`ServeAttachment`, `GET /attachments/{uuid}`) did not check whether the release is a draft. Users holding only repository **read** permission (including unauthenticated callers on public repositories) could enumerate release/attachment IDs and retrieve the metadata and the full contents of attachments belonging to draft releases that are otherwise hidden from them.

`GetRelease` and `ListReleaseAttachments` already return 404 for draft releases when the caller lacks write permission on the releases unit (added in the 2026-06-10 security patches), but these two endpoints were missed. This is the same class of issue fixed upstream by Gitea in [CVE-2026-27660](https://nvd.nist.gov/vuln/detail/CVE-2026-27660) and [GHSA-q9pg-jj6x-j9p6](https://github.com/go-gitea/gitea/security/advisories/GHSA-q9pg-jj6x-j9p6).

Co-authored-by: trim21 <trim21@noreply.codeberg.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14024
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] fix: organization team set as 'admin' is granted 'owner' permission over related repositories (#14034)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14032

Fixes #13983.  An organization team that is configured as an "Administrator access" is actually being granted Owner access over the repositories associated with the team, rather than Administrator access, allowing access to transfer ownership and related owner functionality.  The intended mechanism for this access to be granted is through the owner team.  (While that's somewhat inflexible as it grants owner access to all repositories, this applies to a small subset of capability differences between Admin and Owner access.)

Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14034
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] fix: Add title and org name to org project header (#14065)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13586

Fixes #13585.

Signed-off-by: Nils Philippsen <nils@redhat.com>
Co-authored-by: Nils Philippsen <nils@redhat.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14065
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] chore(ci): use oci/ci:3 instead of oci/playwright:latest for e2e (#14066)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13941

- oci/ci:3 now also have the packages playwright need pre-installed
- add a cache for the browsers so they are only downloaded when needed (over 1GB)

Co-authored-by: limiting-factor <limiting-factor@posteo.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14066
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix: codepaths where git repos are not closed correctly, may relate to leaking `git cat-file --batch[-check]` commands (#14089)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14080

While investigating the Codeberg results from #13778, I found two places where git repositories are opened by Forgejo and not closed:
- When generating the error response `could not find '%s' to be a commit, branch or tag in the head repository %s/%s` from compare API calls.  As a request-bound repository, it is unlikely to have a leaking impact.
- When executing post-receive hook.  As an internal API which has no timeout and is bound to the process's hammer context, it is suspicious for meeting multiple criteria for a problem identified in #13778, but without a complete explanation of how it would work.  (see https://codeberg.org/forgejo/forgejo/pulls/13778#issuecomment-21663806 for more detailed analysis)

Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14089
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* Update module code.forgejo.org/xorm/xorm to v1.4.1 (v16.0/forgejo) (#14098)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [code.forgejo.org/xorm/xorm](https://code.forgejo.org/xorm/xorm) | `v1.4.0` → `v1.4.1` | ![age](https://developer.mend.io/api/mc/badges/age/go/code.forgejo.org%2fxorm%2fxorm/v1.4.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/code.forgejo.org%2fxorm%2fxorm/v1.4.0/v1.4.1?slim=true) |

---

### Release Notes

<details>
<summary>xorm/xorm (code.forgejo.org/xorm/xorm)</summary>

### [`v1.4.1`](https://code.forgejo.org/xorm/xorm/releases/tag/v1.4.1)

[Compare Source](https://code.forgejo.org/xorm/xorm/compare/v1.4.0...v1.4.1)

<!--start release-notes-assistant-->

<!--URL:https://code.forgejo.org/xorm/xorm-->

- bug fixes
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/167): <!--number 167 --><!--line 0 --><!--description Zml4OiB1c2UgYGRyaXZlci5WYWx1ZXJgIHRvIHNlcmlhbGl6ZSBgT3B0aW9uW1RdYCBpbiBgQWxsQ29scygpYA==-->fix: use `driver.Valuer` to serialize `Option[T]` in `AllCols()`<!--description-->
- other
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/166): <!--number 166 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL2dvbGFuZ2NpL2dvbGFuZ2NpLWxpbnQvdjIvY21kL2dvbGFuZ2NpLWxpbnQgdG8gdjIuMTMuMQ==-->Update module github.com/golangci/golangci-lint/v2/cmd/golangci-lint to v2.13.1<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/165): <!--number 165 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL3N0cmV0Y2hyL3Rlc3RpZnkgdG8gdjEuMTIuMQ==-->Update module github.com/stretchr/testify to v1.12.1<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/164): <!--number 164 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNw==-->Update go toolchain directive to v1.26.7<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/163): <!--number 163 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL3N0cmV0Y2hyL3Rlc3RpZnkgdG8gdjEuMTIuMA==-->Update module github.com/stretchr/testify to v1.12.0<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/162): <!--number 162 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNTA=-->Update module github.com/mattn/go-sqlite3 to v1.14.50<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/161): <!--number 161 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNg==-->Update go toolchain directive to v1.26.6<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/160): <!--number 160 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDk=-->Update module github.com/mattn/go-sqlite3 to v1.14.49<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/159): <!--number 159 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBtdmRhbi5jYy9nb2Z1bXB0IHRvIHYwLjExLjA=-->Update module mvdan.cc/gofumpt to v0.11.0<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/156): <!--number 156 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvY2hlY2tvdXQgdG8gdjYuMS4w-->Update actions/checkout to v6.1.0<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/158): <!--number 158 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZy5vcmcveC90ZXh0IChpbmRpcmVjdCkgdG8gdjAuMzkuMCBbU0VDVVJJVFld-->Update golang.org/x/text (indirect) to v0.39.0 \[SECURITY]<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/157): <!--number 157 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZy5vcmcveC9uZXQgKGluZGlyZWN0KSB0byB2MC41Ni4wIFtTRUNVUklUWV0=-->Update golang.org/x/net (indirect) to v0.56.0 \[SECURITY]<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/155): <!--number 155 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDg=-->Update module github.com/mattn/go-sqlite3 to v1.14.48<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/154): <!--number 154 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTMuNA==-->Update <https://data.forgejo.org/actions/forgejo-release> action to v2.13.4<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/153): <!--number 153 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNQ==-->Update go toolchain directive to v1.26.5<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/152): <!--number 152 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvc2V0dXAtZ28gdG8gdjYuNS4w-->Update actions/setup-go to v6.5.0<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/151): <!--number 151 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDc=-->Update module github.com/mattn/go-sqlite3 to v1.14.47<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/150): <!--number 150 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDY=-->Update module github.com/mattn/go-sqlite3 to v1.14.46<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/149): <!--number 149 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvZm9yZ2Vqby1yZWxlYXNlIHRvIHYyLjEzLjE=-->Update actions/forgejo-release to v2.13.1<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/148): <!--number 148 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL2phY2tjL3BneC92NSB0byB2NS4xMC4w-->Update module github.com/jackc/pgx/v5 to v5.10.0<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/147): <!--number 147 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvZm9yZ2Vqby1yZWxlYXNlIHRvIHYyLjEzLjA=-->Update actions/forgejo-release to v2.13.0<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/146): <!--number 146 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDU=-->Update module github.com/mattn/go-sqlite3 to v1.14.45<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/145): <!--number 145 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/144): <!--number 144 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/143): <!--number 143 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/142): <!--number 142 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/139): <!--number 139 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/141): <!--number 141 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/140): <!--number 140 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/138): <!--number 138 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZyBwYWNrYWdlcyB0byB2MS4yNi40-->Update golang packages to v1.26.4<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/132): <!--number 132 --><!--line 0 --><!--description Y2k6IHJ1biBhbGwgeG9ybSB0ZXN0cyBvbiBhcm02NA==-->ci: run all xorm tests on arm64<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/137): <!--number 137 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTIuMQ==-->Update <https://data.forgejo.org/actions/forgejo-release> action to v2.12.1<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/136): <!--number 136 --><!--line 0 --><!--description Y2hvcmUoZGVwcyk6IHdvcmthcm91bmQgYW1iaWd1b3VzIHJlZmVyZW5jZSBlcnJvciBpbiBjYXNjYWRpbmctcHI=-->chore(deps): workaround ambiguous reference error in cascading-pr<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/135): <!--number 135 --><!--line 0 --><!--description Y2hvcmUoZGVwcyk6IFVwZ3JhZGUgY2FzY2FkaW5nLXByIHYyLjMuMg==-->chore(deps): Upgrade cascading-pr v2.3.2<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/134): <!--number 134 --><!--line 0 --><!--description UmVwbGFjZSBOb2RlLmpzIHdpdGggZGF0YS5mb3JnZWpvLm9yZy9vY2kvbm9kZSAyNC10cml4aWU=-->Replace Node.js with data.forgejo.org/oci/node 24-trixie<!--description-->
  - [PR](https://code.forgejo.org/xorm/xorm/pulls/133): <!--number 133 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZy5vcmcveC9uZXQgKGluZGlyZWN0KSB0byB2MC41NS4wIFtTRUNVUklUWV0=-->Update golang.org/x/net (indirect) to v0.55.0 \[SECURITY]<!--description-->

<!--end release-notes-assistant-->

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zOS4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMyIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->

Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14098

* [v16.0/forgejo] fix(ci): semgrep duplicate id (#14102)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14085

In addtion, use validate before --test otherwise validation errors may be very cryptic. For instance:

```sh
$ semgrep validate .semgrep/config
[00.03][WARNING]: invalid rule .semgrep.config.unit-test-missing-setup-function, .semgrep/config/unit-test.yaml:9:9: Expected a string value for .semgrep.config.unit-test-missing-setup-function
```

versus:

```sh
$ semgrep --test .semgrep/tests/ --config .semgrep/config/
...
-------------------------------------------------------------------------------
The following config files produced errors:
	.semgrep/config/unit-test.yaml: Traceback (most recent call last):
  File "/usr/lib/python3.12/site-packages/semgrep/test.py", line 313, in invoke_semgrep_multi
    output = semgrep.run_scan.run_scan_and_return_json(
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/python3.12/site-packages/semgrep/run_scan.py", line 1757, in run_scan_and_return_json
    ) = run_scan(
        ^^^^^^^^^
  File "/usr/lib/python3.12/site-packages/semgrep/telemetry.py", line 468, in inner
    return f(*args, **kwargs)
           ^^^^^^^^^^^^^^^^^^
  File "/usr/lib/python3.12/site-packages/semgrep/simple_profiling.py", line 100, in wrapper
    result = func(*args, **kwargs)
             ^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/python3.12/site-packages/semgrep/run_scan.py", line 1447, in run_scan
    sanity_check_resolved_config(real_config_errors, configs_obj)
  File "/usr/lib/python3.12/site-packages/semgrep/run_scan.py", line 201, in sanity_check_resolved_config
    raise SemgrepError(
semgrep.error.SemgrepError: invalid configuration file found (1 configs were invalid)
```

### Compliance

- [x] I confirm that I make this contribution in accordance with [Forgejo's AI Agreement](https://codeberg.org/forgejo/governance/src/commit/9084720dc6a7fbf1d3f358919d46bd6adfb55287/AIAgreement.md).

Co-authored-by: limiting-factor <limiting-factor@posteo.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14102
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>

* [v16.0/forgejo] fix: add line wrapping to webhook ms teams card (#14115)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14058

Co-authored-by: nightfurysl2001 <nightfurysl2001@outlook.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14115
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] chore(tests): increase doRepoWikiGitOperationInner from 2 to 60 seconds (#14109)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14105

There is no benefit in requiring part of a test (a git command in this case) runs under 2 seconds as it makes it sensitive to high loads. What matters is to have a timeout in case it blocks forever.

Co-authored-by: limiting-factor <limiting-factor@posteo.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14109
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>

* [v16.0/forgejo] fix(ui): fix hashbox design in commit based review (#14118)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14116

In addition remove unused class variable from commits list

Regression of 4392dee96d7437ca3d47ed156883b43cb02385d3

Co-authored-by: Beowulf <beowulf@beocode.eu>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14118
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* Update forgejo go-chi packages (v16.0/forgejo) (#14146)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [code.forgejo.org/go-chi/captcha](https://code.forgejo.org/go-chi/captcha) | `v1.0.2` → `v1.0.3` | ![age](https://developer.mend.io/api/mc/badges/age/go/code.forgejo.org%2fgo-chi%2fcaptcha/v1.0.3?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/code.forgejo.org%2fgo-chi%2fcaptcha/v1.0.2/v1.0.3?slim=true) |
| [code.forgejo.org/go-chi/session](https://code.forgejo.org/go-chi/session) | `v1.0.4` → `v1.1.0` | ![age](https://developer.mend.io/api/mc/badges/age/go/code.forgejo.org%2fgo-chi%2fsession/v1.1.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/code.forgejo.org%2fgo-chi%2fsession/v1.0.4/v1.1.0?slim=true) |

---

### Release Notes

<details>
<summary>go-chi/captcha (code.forgejo.org/go-chi/captcha)</summary>

### [`v1.0.3`](https://code.forgejo.org/go-chi/captcha/releases/tag/v1.0.3)

[Compare Source](https://code.forgejo.org/go-chi/captcha/compare/v1.0.2...v1.0.3)

<!--start release-notes-assistant-->

<!--URL:https://code.forgejo.org/go-chi/captcha-->

- other
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/65): <!--number 65 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9nb2xhbmdjaS9nb2xhbmdjaS1saW50LWFjdGlvbiBhY3Rpb24gdG8gdjkuMy4w-->Update <https://data.forgejo.org/golangci/golangci-lint-action> action to v9.3.0<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/68): <!--number 68 --><!--line 0 --><!--description Y2k6IHB1Ymxpc2ggYXV0b21hdGVkIHJlbGVhc2Vz-->ci: publish automated releases<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/66): <!--number 66 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNQ==-->Update go toolchain directive to v1.26.5<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/63): <!--number 63 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/64): <!--number 64 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ29sYW5nY2kvZ29sYW5nY2ktbGludCB0byB2Mi4xMi4y-->Update dependency golangci/golangci-lint to v2.12.2<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/62): <!--number 62 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNCBbU0VDVVJJVFld-->Update go toolchain directive to v1.26.4 \[SECURITY]<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/60): <!--number 60 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL2NoZWNrb3V0IGFjdGlvbiB0byB2Ng==-->Update <https://code.forgejo.org/actions/checkout> action to v6<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/59): <!--number 59 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjY=-->Update dependency go to v1.26<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/58): <!--number 58 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ29sYW5nY2kvZ29sYW5nY2ktbGludCB0byB2Mi4xMS40-->Update dependency golangci/golangci-lint to v2.11.4<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/57): <!--number 57 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjExLjM=-->Update module golangci-lint to v2.11.3<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/55): <!--number 55 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjExLjI=-->Update module golangci-lint to v2.11.2<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/53): <!--number 53 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjExLjE=-->Update module golangci-lint to v2.11.1<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/50): <!--number 50 --><!--line 0 --><!--description UmVwbGFjZSBOb2RlLmpzIHdpdGggZGF0YS5mb3JnZWpvLm9yZy9vY2kvbm9kZSAyNC10cml4aWU=-->Replace Node.js with data.forgejo.org/oci/node 24-trixie<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/51): <!--number 51 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuOA==-->Update dependency go to v1.25.8<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/49): <!--number 49 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjEwLjE=-->Update module golangci-lint to v2.10.1<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/48): <!--number 48 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuNw==-->Update dependency go to v1.25.7<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/47): <!--number 47 --><!--line 0 --><!--description UmVwbGFjZSBodHRwczovL2dpdGh1Yi5jb20vZ29sYW5nY2kvZ29sYW5nY2ktbGludC1hY3Rpb24gYWN0aW9uIHdpdGggaHR0cHM6Ly9kYXRhLmZvcmdlam8ub3JnL2dvbGFuZ2NpL2dvbGFuZ2NpLWxpbnQtYWN0aW9uIHY5-->Replace <https://github.com/golangci/golangci-lint-action> action with <https://data.forgejo.org/golangci/golangci-lint-action> v9<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/46): <!--number 46 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuNg==-->Update dependency go to v1.25.6<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/45): <!--number 45 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjguMA==-->Update module golangci-lint to v2.8.0<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/44): <!--number 44 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjcuMg==-->Update module golangci-lint to v2.7.2<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/43): <!--number 43 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjcuMQ==-->Update module golangci-lint to v2.7.1<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/42): <!--number 42 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuNQ==-->Update dependency go to v1.25.5<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/41): <!--number 41 --><!--line 0 --><!--description UmVwbGFjZSBOb2RlLmpzIHdpdGggZGF0YS5mb3JnZWpvLm9yZy9vY2kvbm9kZSAyNC1ib29rd29ybQ==-->Replace Node.js with data.forgejo.org/oci/node 24-bookworm<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/40): <!--number 40 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjYuMg==-->Update module golangci-lint to v2.6.2<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/38): <!--number 38 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZ2l0aHViLmNvbS9nb2xhbmdjaS9nb2xhbmdjaS1saW50LWFjdGlvbiBhY3Rpb24gdG8gdjk=-->Update <https://github.com/golangci/golangci-lint-action> action to v9<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/39): <!--number 39 --><!--line 0 --><!--description VXBkYXRlIE5vZGUuanMgdG8gdjI0-->Update Node.js to v24<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/37): <!--number 37 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuNA==-->Update dependency go to v1.25.4<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/36): <!--number 36 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjYuMQ==-->Update module golangci-lint to v2.6.1<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/35): <!--number 35 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjYuMA==-->Update module golangci-lint to v2.6.0<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/34): <!--number 34 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZyBwYWNrYWdlcyB0byB2MS4yNSAobWlub3Ip-->Update golang packages to v1.25 (minor)<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/32): <!--number 32 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuOA==-->Update dependency go to v1.24.8<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/30): <!--number 30 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL2NoZWNrb3V0IGFjdGlvbiB0byB2NQ==-->Update <https://code.forgejo.org/actions/checkout> action to v5<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/31): <!--number 31 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWdvIGFjdGlvbiB0byB2Ng==-->Update <https://code.forgejo.org/actions/setup-go> action to v6<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/29): <!--number 29 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjUuMA==-->Update module golangci-lint to v2.5.0<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/28): <!--number 28 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuNw==-->Update dependency go to v1.24.7<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/27): <!--number 27 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjQuMA==-->Update module golangci-lint to v2.4.0<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/25): <!--number 25 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuNg==-->Update dependency go to v1.24.6<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/24): <!--number 24 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjMuMQ==-->Update module golangci-lint to v2.3.1<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/23): <!--number 23 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjMuMA==-->Update module golangci-lint to v2.3.0<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/22): <!--number 22 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjIuMg==-->Update module golangci-lint to v2.2.2<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/21): <!--number 21 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuNQ==-->Update dependency go to v1.24.5<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/20): <!--number 20 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjIuMQ==-->Update module golangci-lint to v2.2.1<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/19): <!--number 19 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjIuMA==-->Update module golangci-lint to v2.2.0<!--description-->
  - [PR](https://code.forgejo.org/go-chi/captcha/pulls/18): <!--number 18 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuNA==-->Update dependency go to v1.24.4<!--description-->

<!--end release-notes-assistant-->

</details>

<details>
<summary>go-chi/session (code.forgejo.org/go-chi/session)</summary>

### [`v1.1.0`](https://code.forgejo.org/go-chi/session/compare/v1.0.4...v1.1.0)

[Compare Source](https://code.forgejo.org/go-chi/session/compare/v1.0.4...v1.1.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zOS4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMyIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14146
Reviewed-by: Gusted <gusted@noreply.codeberg.org>

* [v16.0/forgejo] fix: simplify concurrency in `GetContributorStats` (#14159)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14149

There's a bug in the current implementation of `GetContributorStats`
that has to do with concurrency. The function is fairly simple, if
there's no generated resulted (in the cache) then start a goroutine that
generates this. Wait for up to 5 seconds to get the result, otherwise
indicate to the client that generation has started but have to call
again later to get the result (or get told it's still busy).

This behavior of waiting up to 5 seconds is being done by passing a
channel to the goroutine. When the goroutine successfully generated the
data and stored it in the cache, it does a blocking send to the channel
to indicate it's done. However, if this happened after the 5 seconds
there was no goroutine/code reading from that channel and the goroutine
gets stuck.

Simplify this by removing this 'waiting up to x seconds' behavior and
always tell the client to come back later if there's nothing in the
cache. This does increases network traffic, but the current client (the
web UI which we control) checks every second and no heavy database
operations or cache operations has to be executed to return that there's
no data yet. I feel this is preferred over fixing this concurrency bug,
as it makes reasoning about this behavior quite easier (and as well
testing).

This bug caused `git cat-file` processes from lingering, ref: forgejo/forgejo#12970

Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14159
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* [v16.0/forgejo] chore: improve reliability of TestPullRequestCommentPlacement on force push tests (#14207)

**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14201

There are a few test cases in `TestPullRequestCommentPlacement` which do force pushes, and the test code currently doesn't access their commit ID after the force push.  This prevented them from having the reliability fix from https://codeberg.org/forgejo/forgejo/issues/13808 applied to them, and has now been fixed.

Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14207
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* Update module golang.org/x/crypto to v0.56.0 [SECURITY] (v16.0/forgejo) (#14224)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/crypto](https://pkg.go.dev/golang.org/x/crypto) | [`v0.55.0` → `v0.56.0`](https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.55.0...refs/tags/v0.56.0) | ![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fcrypto/v0.56.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fcrypto/v0.55.0/v0.56.0?slim=true) |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2779) for more information.

---

### Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
[CVE-2026-78662](https://nvd.nist.gov/vuln/detail/CVE-2026-78662) / [GO-2026-6354](https://pkg.go.dev/vuln/GO-2026-6354)

<details>
<summary>More information</summary>

#### Details
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.

Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

#### Severity
Unknown

#### References
- [https://go.dev/issue/81316](https://go.dev/issue/81316)
- [https://go.dev/cl/826504](https://go.dev/cl/826504)
- [https://groups.google.com/g/golang-announce/c/1y3fb2np35U](https://groups.google.com/g/golang-announce/c/1y3fb2np35U)

This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6354) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
[CVE-2026-56855](https://nvd.nist.gov/vuln/detail/CVE-2026-56855) / [GO-2026-6355](https://pkg.go.dev/vuln/GO-2026-6355)

<details>
<summary>More information</summary>

#### Details
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.

Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

#### Severity
Unknown

#### References
- [https://go.dev/issue/81317](https://go.dev/issue/81317)
- [https://go.dev/cl/826524](https://go.dev/cl/826524)
- [https://groups.google.com/g/golang-announce/c/1y3fb2np35U](https://groups.google.com/g/golang-announce/c/1y3fb2np35U)

This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6355) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC41Mi4wIiwidXBkYXRlZEluVmVyIjoiNDQuNTIuMCIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14224
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>

* Update google.golang.org/grpc (indirect) to v1.83.1 [SECURITY] (v16.0/forgejo) (#14216)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.1` → `v1.83.1` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.83.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.82.1/v1.83.1?slim=true) |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2779) for more information.

---

### gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
[CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](https://github.com/advisories/GHSA-vp52-pcj8-j9qc)

<details>
<summary>More information</summary>

#### Details
##### Impact
An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation.

Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS).

##### Patches
The change to fix this issue is merged in `master` and a patch release, 1.83.1, has been published that contains this fix.

##### Workarounds
This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads.

This behavior is enabled by default. A temporary escape hatch is provided via the environment variable `GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false` to disable the feature if unforeseen issues arise, but it will be removed in a future release.

#### Severity
- CVSS Score: 8.7 / 10 (High)
- Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N`

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc)
- [https://nvd.nist.gov/vuln/detail/CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304)
- [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331)
- [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333)
- [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176)
- [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77)
- [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go)
- [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1)

This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-vp52-pcj8-j9qc) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1

[Compare Source](https://github.com/grpc/grpc-go/compare/v1.83.0...v1.83.1)

### Security

- xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#&#8203;9258](https://github.com/grpc/grpc-go/issues/9258))
  - Special Thanks: [@&#8203;nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#&#8203;9258](https://github.com/grpc/grpc-go/issues/9258))
  - Special Thanks: [@&#8203;nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#&#8203;9332](https://github.com/grpc/grpc-go/issues/9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#&#8203;9332](https://github.com/grpc/grpc-go/issues/9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#&#8203;9332](https://github.com/grpc/grpc-go/issues/9332))
  - Special Thanks: [@&#8203;alimony](https://github.com/alimony)

### Performance

- transport: Restrict memory overhead of buffering small data frames. ([#&#8203;9331](https://github.com/grpc/grpc-go/issues/9331))

### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0

[Compare Source](https://github.com/grpc/grpc-go/compare/v1.82.2...v1.83.0)

### Security

- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`.
- xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields.  If present in a DENY rule, previously these would be ignored and fail-open.
- xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions.
- xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`.
- xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#&#8203;9223](https://github.com/grpc/grpc-go/issues/9223))

### New Features

- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#&#8203;9133](https://github.com/grpc/grpc-go/issues/9133))
- xds: Enable xDS configura…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Type: Behavior Change Behavior changes not categorized as bugs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants