Apache Thrift Changelog
0.25.0
Build Process
- THRIFT-2208 - Thrift package for chocolatey
- THRIFT-6077 - improve CHANGES.md generator section assignment
- THRIFT-6170 - Add a GitHub Actions CI job for the D library
- THRIFT-6171 - Add a GitHub Actions CI job for the Erlang library
- THRIFT-6172 - Dart tests are not run by make check, and no CI job builds the binding
- THRIFT-6185 - lib/d does not build against OpenSSL 3.x
- THRIFT-6189 - Add a GitHub Actions CI job for the Lua library
- THRIFT-6190 - Add a compile and test check for the JavaME library
- THRIFT-6196 - Remove the unreleased contrib thrift-maven-plugin in favour of standard Maven plugins
- THRIFT-6234 - Configure apt retries and timeouts in GitHub Actions workflows
- THRIFT-6235 - Compiler unit tests fail to link when the Go generator is disabled
- THRIFT-6237 - Shrink the MSVC Docker image: drop the unused .NET Framework base and JDK, prune Boost, pin tool versions
- THRIFT-6247 - AppVeyor jobs depend on a single fallback URL for the zlib download
- THRIFT-6250 - Clean up the warnings in the MSVC CI build
- THRIFT-6270 - Sweep for source files that no build list mentions
- THRIFT-6274 - Reject AI session and conversation links in pull request commits and text
- THRIFT-6276 - AppVeyor MINGW job fails when one MSYS2 mirror drops a signature download
- THRIFT-6277 - CHANGES draft lists tickets that are not fixed in the release
- THRIFT-6278 - CHANGES draft generator loses a whole JIRA lookup over one nonexistent ticket key
- THRIFT-6284 - Wire up source and test files that a build list misses (THRIFT-6270 follow-up)
- THRIFT-6301 - veralign.sh rewrites third-party versions in lockfiles when they match the old Thrift version
- THRIFT-6302 - veralign.sh: jsonReplace reports failures as OK, and the file loop is not sorted
- THRIFT-6305 - veralign.sh reports a JSON file that jq cannot read as a missing version
- THRIFT-6310 - Build the Thrift compiler on Windows in CI
- THRIFT-6311 - Build a Windows installer for the Thrift compiler at release time
- THRIFT-6313 - Publish the Windows Thrift compiler as a .NET tool
- THRIFT-6314 - Publish the Windows Thrift compiler through WinGet
- THRIFT-6315 - Stale msvc2017 paths in the Windows Docker documentation
- THRIFT-6319 - lib/ts is not part of the build, so its check-local target never runs
- THRIFT-6320 - Stop asking for a static runtime when building the release compiler
- THRIFT-6324 - Cut the AppVeyor build matrix and build in parallel
- THRIFT-6325 - Let the MSVC builds use /MP again
- THRIFT-6326 - Compile the compiler sources once for the executable and the unit tests
- THRIFT-6327 - Document the credentials the release workflows need in one place
- THRIFT-6330 - Add a GitHub Actions CI job for the JavaScript library
- THRIFT-6334 - Adopt a version support policy and require PHP 8.2
- THRIFT-6349 - Drop the ubuntu-focal build image
- THRIFT-6351 - Require GLib 2.48 in configure and CMake
- THRIFT-6361 - Add a GitHub Actions CI job for the C (GLib) library
- #3945 - Bump @babel/core from 7.8.4 to 7.29.7
- #3911 - Bump brace-expansion from 2.1.0 to 2.1.7
- #3890 - Let prose-only commits skip CI
- #3816 - Cap every build workflow job at 60 minutes
- #3837 - Resolve config.h.in relative to ConfigureChecks.cmake
- #3833 - Bump js-yaml from 3.15.1 to 3.15.2 in /lib/js
- #3790 - Bump @humanfs/node from 0.16.6 to 0.16.8
- #3771 - Bump com.ncorti.ktfmt.gradle from 0.26.0 to 0.27.0 in /lib/kotlin
- #3775 - Bump actions/setup-java from 5.2.0 to 6.0.0
- #3774 - Bump actions/setup-python from 6.2.0 to 7.0.0
- #3773 - Bump shivammathur/setup-php from 2.37.1 to 2.37.2
- #3772 - Bump com.diffplug.spotless from 8.8.0 to 8.10.0 in /lib/java
- #3776 - Bump actions/setup-go from 6.5.0 to 7.0.0
- #3769 - Bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2
- #3749 - Add Zig tags to the CHANGES.md generator
- #3737 - Fix building on OpenBSD
- #3635 - Bump puma from 6.6.1 to 7.2.1 in /test/rb
- #3721 - Bump shell-quote from 1.7.3 to 1.10.0 in /lib/ts
- #3735 - Add Windows ARM64 PyPI distribution
- #3733 - Update supported go versions to 1.26+1.27
- #3734 - Update test certificates
- #3697 - Bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.2
- #3695 - Bump actions/setup-dotnet from 5.2.0 to 6.0.0
- #3698 - Bump jvm from 2.4.0 to 2.4.10 in /lib/kotlin
- #3692 - Bump com.diffplug.spotless from 8.7.0 to 8.8.0 in /lib/java
- #3693 - Bump actions/checkout from 6.0.2 to 7.0.1
- #3699 - Bump com.diffplug.spotless from 8.7.0 to 8.8.0 in /lib/kotlin
- #3696 - Bump ruby/setup-ruby from 1.314.0 to 1.321.0
- #3694 - Bump zizmorcore/zizmor-action from 0.5.6 to 0.6.1
- #3670 - Bump json from 2.19.2 to 2.19.9 in /test/rb
- #3671 - Bump json from 2.19.2 to 2.19.9 in /lib/rb
- #3661 - Bump linkify-it from 5.0.1 to 5.0.2 in /lib/js
- #3654 - Bump shell-quote from 1.8.4 to 1.10.0 in /lib/js
- #3655 - Bump System.Security.Cryptography.Xml from 10.0.7 to 10.0.10
- #3653 - Bump System.Security.Cryptography.Xml from 10.0.7 to 10.0.10
- #3636 - Bump ws from 6.2.3 to 6.2.4 in /lib/js
- #3632 - Add job timeout to Python CI jobs
- #3631 - Bump ws from 6.2.3 to 6.2.4 in /lib/ts
- #3624 - Add a make dist job to CI
C glib
- THRIFT-5881 - [Glib] The {class}_finalize method created by c_glib generator is leaking memory
- THRIFT-6066 - An error occurs when thrift_dispatch_processor_process is executed because dispatch_processor_class->dispatch_call is nullptr
- THRIFT-6166 - C (GLib): bind the read budget to the frame that carries the message
- THRIFT-6351 - Require GLib 2.48 in configure and CMake
- THRIFT-6361 - Add a GitHub Actions CI job for the C (GLib) library
- #3678 - Reject a message the protocol did not name in the c_glib multiplexed processor
- #3676 - Update the c_glib binary protocol test for non-versioned message headers
- #3668 - Link thrift_memory_buffer into the c_glib testbinaryprotocol test
C++
- THRIFT-5090 - error “TConnectedClient processing exception: Expected control char, got ‘/’” when a string argument contains a slash and JSON is used
- THRIFT-5371 - Max Message Size is eventually exceeded when using TFramedTransport
- THRIFT-6060 - C++ THttpClient does not reopen socket after server sends Connection: close
- THRIFT-6167 - PHP HTTP cross-test server omits Content-Length and breaks php-cpp HTTP cases
- THRIFT-6174 - Enable TSSLSocket to build with OpenSSL 4.0
- THRIFT-6177 - Bound the WebSocket frame payload length before it sizes the read buffer in the C++ library
- THRIFT-6178 - C++ WebSocket server drops any frame whose payload does not arrive in one read
- THRIFT-6179 - C++ WebSocket server recurses once per Ping frame with no depth bound
- THRIFT-6180 - C++ WebSocket server mis-frames empty and control frames
- THRIFT-6183 - Use the library-wide default frame size in TNonblockingServer in the C++ library
- THRIFT-6191 - C++ server sockets and TSocket resolve the same host with different getaddrinfo flags
- THRIFT-6192 - THttpServer matches a header name by prefix, and Content-Length goes through atoi
- THRIFT-6193 - The C++ HTTP transport does not hold the message body to maxMessageSize
- THRIFT-6194 - ToStringTest leaves the global locale set for the rest of the UnitTests binary
- THRIFT-6242 - Honour the transport configuration in the C++ TNonblockingServer
- THRIFT-6243 - Grow the TNonblockingServer read buffer as the payload arrives, not on the frame header
- THRIFT-6244 - TNonblockingServerTest intermittently crashes or hangs in bad_alloc_does_not_end_the_process
- THRIFT-6248 - TSSLSocket does not compile against OpenSSL 1.1.1
- THRIFT-6250 - Clean up the warnings in the MSVC CI build
- THRIFT-6271 - C++: readAll on a concrete TWebSocketServer bypasses WebSocket framing
- #3858 - Make the narrowing of TUuid::size() to uint32_t explicit
- #3831 - Link the boost thread library into the C++ certificate name test
- #3831 - Use the client certificate with subjectAltNames in the SSL cross-test clients
- #3689 - Refine thrift audit compatibility options
- #3801 - Add cstddef include to fix build error with 6.3.0
- #3754 - Initialise maxFrameSize_ in the TFramedTransport configuration-only constructor
- #3738 - Replace deprecated OpenSSL API ASN1_STRING_data()
- #3675 - Measure JSON field size against the configured maximum
- #3630 - Enable C++ TLS cross-tests
Compiler (General)
- THRIFT-6076 - Compiler build fails with GCC 14 LTO
- THRIFT-6212 - Compiler loops forever on an unterminated comment at end of file
- THRIFT-6235 - Compiler unit tests fail to link when the Go generator is disabled
- THRIFT-6328 - Smalltalk: generated recv methods read the message envelope from the output protocol
- #3733 - Update supported go versions to 1.26+1.27
D
- THRIFT-6168 - Add recursion depth limit to skip() in D library
- THRIFT-6170 - Add a GitHub Actions CI job for the D library
- THRIFT-6185 - lib/d does not build against OpenSSL 3.x
- THRIFT-6230 - Port the WebSocket frame reading fixes of THRIFT-6178, THRIFT-6179 and THRIFT-6180 to the D library
- THRIFT-6241 - Use the library-wide default frame size in TNonblockingServer in the D library
- THRIFT-6245 - Grow the D TNonblockingServer read buffer as the payload arrives, not on the frame header
- THRIFT-6344 - D generator: the reserved word list has “macro “ with a trailing space
- 79dc86d55 - Build, test and install the WebSocket transport module
Dart
- THRIFT-6172 - Dart tests are not run by make check, and no CI job builds the binding
- THRIFT-6264 - Dart: TProtocol.incrementRecursionDepth and decrementRecursionDepth are never called
- THRIFT-6346 - Remove dead code from the Java ME, Dart, Mermaid and XSD generators
- 2ae9c11db - Consolidate replace_all() into t_oop_generator
Delphi
- THRIFT-6075 - Generate Equal Method for Delphi Thrift Data Classes/Interfaces
- THRIFT-6303 - Thrift.Collections: Delphi 2010 code path of TThriftDictionaryImpl.ToArray references the renamed field FDictionaly
- THRIFT-6304 - Delphi serializer test still references cDebugProtoTest_Option_AnsiStr_Binary, which is no longer generated
- 2ae9c11db - Consolidate replace_all() into t_oop_generator
Documentation
- THRIFT-5242 - Mention brew package in macOS installation instructions
- THRIFT-5415 - Github Project should link Thrift Website in About section for easier Onboarding
- THRIFT-6205 - Remove the stale MIT attribution for the removed Erlang makefile from LICENSE
- THRIFT-6291 - Align the container-size limit across the TConfiguration bindings
- THRIFT-6334 - Adopt a version support policy and require PHP 8.2
Erlang
- THRIFT-6163 - Erlang: do not send handler crash detail to the caller by default
- THRIFT-6164 - Erlang: bound the depth thrift_protocol:skip/2 will follow
- THRIFT-6171 - Add a GitHub Actions CI job for the Erlang library
- THRIFT-6184 - Erlang TLS client cannot connect on OTP 26 and later, and does not verify the server certificate on earlier releases
- THRIFT-6268 - Erlang: the HTTP transport fails with a badmatch on any non-200 reply, offers no https and buffers the body unbounded
- THRIFT-6269 - Erlang: two avoidable per-byte costs in the socket transport and the JSON protocol
- THRIFT-6279 - Erlang: the JSON protocol cannot read a message and writes binary strings unquoted
- THRIFT-6282 - Erlang: let the HTTP transport use https
- THRIFT-6283 - Erlang: bound the size of a reply the HTTP transport reads
Go
- THRIFT-2063 - Go compiler cannot create code for maps with complex/binary keys
- THRIFT-3037 - Can not build Go code when using typedef in IDL
- THRIFT-3491 - Invalid Go Code From Service Signatures With Typedef’d Structs
- THRIFT-4901 - Go fails to compile when a struct field is a typedef to a struct
- THRIFT-5420 - Go library should not depend on “testing” in the main package
- THRIFT-5463 - Incorrect and inconsistency in compiler generated go code regarding pointer types
- THRIFT-5489 - Generated Go Struct Fields Use Underlying Type Instead of Defined Type If thrift Typedef Comes After
- THRIFT-5493 - Invalid chmod command in test/go/genmock.sh
- THRIFT-5601 - Typedef after first use causes incorrect go code
- THRIFT-5806 - Inconsistent Handling of Unset Union Fields in Structs Across Languages
- THRIFT-5807 - Generated Go enums’ always appear to be for out of ranges values in enum
- THRIFT-5814 - go: Flaky test TestNoHangDuringStopFromClientNoDataSendDuringAcceptLoop
- THRIFT-5828 - ReadBinary in the binary protocol implementation over-allocates
- THRIFT-6175 - Go maps keyed by a struct use pointer identity, so decoded keys never match and Equals compares by address
- THRIFT-6176 - Go generator: struct field named isSetX collides with the generated IsSetX() accessor
- THRIFT-6195 - Go Equals is order-sensitive for set and entry-slice map fields, so equal values compare unequal
- THRIFT-6197 - Go generator mishandles typedefs, so aliased structs and forward-declared typedefs generate code that does not compile
- THRIFT-6200 - Go -remote stub qualifies enum and inherited container arguments with the wrong package when they come from an included file
- THRIFT-6204 - Go writes an unset default-requiredness struct field instead of omitting it
- THRIFT-6211 - Go: add native go test -fuzz targets and a committed seed corpus that runs in CI
- THRIFT-6262 - Go: THeaderTransport.Flush truncates the frame length instead of refusing an oversized frame
- THRIFT-6263 - Go: TZlibTransportFactory has no constructor that takes a TConfiguration
- THRIFT-6275 - Go cross-test client presents no client certificate, and Go 1.27 cannot load client_v3.crt
- THRIFT-6280 - Go: THeaderTransportFactory passes a stale TConfiguration to the factory it wraps
- THRIFT-6281 - Go: TFramedTransport.Flush writes frames larger than the configured MaxFrameSize
- THRIFT-6286 - Go: TConfiguration has no container-size limit
- #3921 - Go: write doc comments without leading, trailing or doubled empty lines
- #3777 - Migrate from deprecated golang/mock to go.uber.org/mock
- #3733 - Update supported go versions to 1.26+1.27
- #3625 - Fix Go and Rust version detection for multi-digit version numbers
Graphviz
- THRIFT-6332 - Graphviz generator crashes on struct, typedef and nested container constants
Haxe
- THRIFT-6160 - Haxe framed transport cannot read consecutive frames without an intervening flush
- THRIFT-6161 - Haxe TStreamTransport does not charge reads against MaxMessageSize
- THRIFT-6173 - Haxe TFullDuplexHttpClient is dead code: guarded by an undefined conditional and does not compile
- THRIFT-6342 - Haxe generator renders i8 and i16 constants with C-style casts
- #3756 - Stop StreamTest’s cleanup handler from masking the failure it is cleaning up after
Java
- THRIFT-3606 - TSaslClientTransport props typed too strongly
- THRIFT-5566 - migrate java tutorial from ant to gradle
- THRIFT-6165 - Java: bind the read budget to the frame that carries the message
- THRIFT-6181 - Bound the response frame size in the Java async client
- THRIFT-6182 - Wrapping a transport must not raise the configured maximum frame size (Java)
- THRIFT-6196 - Remove the unreleased contrib thrift-maven-plugin in favour of standard Maven plugins
- #3831 - Use the client certificate with subjectAltNames in the SSL cross-test clients
- #3789 - Remove obsolete thrift-maven-plugin and document standard Maven usage
- #3771 - Bump com.ncorti.ktfmt.gradle from 0.26.0 to 0.27.0 in /lib/kotlin
- #3772 - Bump com.diffplug.spotless from 8.8.0 to 8.10.0 in /lib/java
- #3733 - Update supported go versions to 1.26+1.27
- #3734 - Update test certificates
- #3698 - Bump jvm from 2.4.0 to 2.4.10 in /lib/kotlin
- #3692 - Bump com.diffplug.spotless from 8.7.0 to 8.8.0 in /lib/java
- #3699 - Bump com.diffplug.spotless from 8.7.0 to 8.8.0 in /lib/kotlin
JavaME
- THRIFT-6190 - Add a compile and test check for the JavaME library
- THRIFT-6346 - Remove dead code from the Java ME, Dart, Mermaid and XSD generators
JavaScript
- THRIFT-6316 - Fetch the test and tutorial JavaScript libraries over HTTPS
- THRIFT-6321 - lib/ts and lib/js lint their tests and generated node code at the wrong language level
- THRIFT-6322 - lib/js: the browser tests call struct read and write as plain properties
- THRIFT-6330 - Add a GitHub Actions CI job for the JavaScript library
- #3945 - Bump @babel/core from 7.8.4 to 7.29.7
- #3923 - Use the correct buffer in
read() methods
- #3911 - Bump brace-expansion from 2.1.0 to 2.1.7
- #3833 - Bump js-yaml from 3.15.1 to 3.15.2 in /lib/js
- #3790 - Bump @humanfs/node from 0.16.6 to 0.16.8
- #3746 - Update legacy JavaScript lodash dependencies
- #3724 - Update legacy JavaScript js-yaml dependencies
- #3721 - Bump shell-quote from 1.7.3 to 1.10.0 in /lib/ts
- #3720 - Update js-yaml development dependencies
- #3661 - Bump linkify-it from 5.0.1 to 5.0.2 in /lib/js
- #3654 - Bump shell-quote from 1.8.4 to 1.10.0 in /lib/js
- #3636 - Bump ws from 6.2.3 to 6.2.4 in /lib/js
- #3631 - Bump ws from 6.2.3 to 6.2.4 in /lib/ts
Kotlin
- #3771 - Bump com.ncorti.ktfmt.gradle from 0.26.0 to 0.27.0 in /lib/kotlin
- #3698 - Bump jvm from 2.4.0 to 2.4.10 in /lib/kotlin
Lua
- THRIFT-6189 - Add a GitHub Actions CI job for the Lua library
- THRIFT-6345 - Lua generator: error messages copied from the PHP generator
- THRIFT-6365 - Lua: add a container-size limit to the protocols
Mermaid
- THRIFT-6346 - Remove dead code from the Java ME, Dart, Mermaid and XSD generators
netstd
- THRIFT-6198 - CS0121 ambiguous extension methods generated for container types referencing included structs
- THRIFT-6199 - CS0121 for container extension methods shared by programs that have no include relation
- THRIFT-6202 - Drop netstandard2.0 and netstandard2.1 targets from ApacheThrift.AspNetCore
- #3658 - updated System.ServiceModel.Primitives 10.x breaks net8/net9
- #3655 - Bump System.Security.Cryptography.Xml from 10.0.7 to 10.0.10
- #3653 - Bump System.Security.Cryptography.Xml from 10.0.7 to 10.0.10
- #3624 - Fix stale EXTRA_DIST references that broke make dist
nodejs
- THRIFT-5224 - Deprecated Nodejs Buffer()
- THRIFT-6130 - Node.js library cannot load in CommonJS environments with ESM-only uuid dependency
- THRIFT-6203 - Node.js library uses url.parse(), fs.exists() and require(“constants”), all deprecated
- THRIFT-6331 - XHRConnection.read() cannot read a binary reply
- #3945 - Bump @babel/core from 7.8.4 to 7.29.7
- #3923 - Use the correct buffer in
read() methods
- #3911 - Bump brace-expansion from 2.1.0 to 2.1.7
- #3831 - Use the client certificate with subjectAltNames in the SSL cross-test clients
- #3790 - Bump @humanfs/node from 0.16.6 to 0.16.8
- #3718 - Fix GitHub Actions code scanning findings
nodets
- THRIFT-6317 - lib/ts: the browser test does not compile against the generated TypeScript declarations
- THRIFT-6318 - lib/ts: browserify 16 cannot parse the current uuid package
- THRIFT-6319 - lib/ts is not part of the build, so its check-local target never runs
- THRIFT-6321 - lib/ts and lib/js lint their tests and generated node code at the wrong language level
- #3945 - Bump @babel/core from 7.8.4 to 7.29.7
- #3911 - Bump brace-expansion from 2.1.0 to 2.1.7
- #3790 - Bump @humanfs/node from 0.16.6 to 0.16.8
- #3746 - Update legacy JavaScript lodash dependencies
- #3724 - Update legacy JavaScript js-yaml dependencies
- #3721 - Bump shell-quote from 1.7.3 to 1.10.0 in /lib/ts
- #3631 - Bump ws from 6.2.3 to 6.2.4 in /lib/ts
PHP
- THRIFT-1941 - PHP Serializer deserialize doesn’t work
- THRIFT-2151 - PHP Thrift library provides persistent socket option that cannot be recovered from network failure
- THRIFT-3874 - _TSPEC is not populated on de-serialization of type classes
- THRIFT-4244 - PHP compiler errors out if escape character is part in string constant
- THRIFT-5090 - error “TConnectedClient processing exception: Expected control char, got ‘/’” when a string argument contains a slash and JSON is used
- THRIFT-6167 - PHP HTTP cross-test server omits Content-Length and breaks php-cpp HTTP cases
- THRIFT-6309 - Remove PHP deprecations introduced in 0.24.0
- THRIFT-6323 - Fix PHPUnit deprecations and notices in PHP test suite
- THRIFT-6334 - Adopt a version support policy and require PHP 8.2
- THRIFT-6335 - Replace PHP ReflectionHelper with direct reflection
- THRIFT-6362 - PHP TCurlClient follows HTTP redirects to other origins
- #3792 - refactor(composer): normalize metadata and keep packages sorted
- #3718 - Fix GitHub Actions code scanning findings
Python
- THRIFT-5955 - Publish wheels for manylinux aarch64
- THRIFT-6081 - Add UUID support for header protocol in Python
- THRIFT-6082 - Python TProcessPoolServer test shutdown can deadlock (signal handler reenters Condition.notify())
- THRIFT-6113 - test_keyword_escape.py regression test silently skips (thrift compiler not found) in CI and local builds
- THRIFT-6114 - Python service/function names that are Python keywords generate unimportable modules and a broken -remote script
- THRIFT-6115 - Python service extends and cross-module (include) type references also skip keyword escaping
- THRIFT-6116 - Python generator still misses keyword escaping in six more spots (consts, enum-value defaults, required-field checks, type_hints/twisted/enum modes)
- THRIFT-6169 - Size containers from the payload rather than the declared count in the Python C extension
- THRIFT-6201 - Python peer address matcher does not reduce IPv4-mapped IPv6 addresses
- THRIFT-6233 - TSSLServerSocket peer-address check depends on the Python version
- THRIFT-6265 - Python: setup.py still carries the backports.ssl_match_hostname dependency for Python < 3.5
- THRIFT-6266 - Python: THttpServer accepts Content-Length values that are not valid HTTP numbers
- THRIFT-6267 - Python: TNonblockingServer rebuilds its whole read buffer on every socket read
- #3838 - Break after the operator in a Python test to satisfy flake8
- #3831 - Use the client certificate with subjectAltNames in the SSL cross-test clients
- #3735 - Add Windows ARM64 PyPI distribution
- #3677 - Fix Python process-pool test server lifecycle
- #3667 - Let Python test servers allocate ephemeral ports
- #3663 - Fix Python socket timeout test units
Ruby
- THRIFT-6045 - Limit struct read/write recursion depth in Ruby library
- THRIFT-6078 - Ruby SSL clients do not send SNI during TLS handshake
- THRIFT-6079 - Rewrite HTTP server for Ruby library as Thin and EventMachine are not supported on modern Ruby versions
- THRIFT-6098 - Ruby SSLSocket should verify peers by default
- THRIFT-6099 - Ruby MemoryBufferTransport should reject invalid read lengths
- THRIFT-6100 - Ruby MemoryBufferTransport should respect frozen destination buffers
- THRIFT-6101 - Ruby CompactProtocol should use Ruby truthiness when writing booleans
- THRIFT-6102 - Ruby CompactProtocol should report malformed headers consistently
- THRIFT-6103 - Ruby MemoryBufferTransport should return unsigned byte values
- THRIFT-6104 - Ruby native struct writing should accept Set subclasses
- THRIFT-6105 - Ruby native MemoryBufferTransport should retain partial read progress
- THRIFT-6106 - Ruby native protocol readers should decode fixed-width values without undefined shifts
- THRIFT-6109 - Ruby HTTP client transport should provide a safe endpoint label
- THRIFT-6110 - Ruby HTTP client transport should reject empty successful responses
- THRIFT-6111 - Ruby Struct equality should be symmetric across generated classes
- THRIFT-6112 - Ruby Socket should reject duplicate opens
- THRIFT-6118 - Ruby ProtocolDecorator should forward message begin arguments
- THRIFT-6119 - Ruby MultiplexedProtocol diagnostics should preserve the service name
- THRIFT-6120 - Ruby SSLServerSocket client timeout does not cover the TLS handshake
- THRIFT-6121 - Ruby HeaderProtocol emits unparseable errors for unknown protocol IDs
- THRIFT-6122 - Ruby JSONProtocol mishandles Unicode strings and surrogate pairs
- THRIFT-6123 - Ruby Serializer retains JSON protocol state after write failures
- THRIFT-6124 - Ruby deserializer retains stale values when reusing target objects
- THRIFT-6125 - Ruby client leaves transports reusable after uncertain request sends
- THRIFT-6126 - Ruby SimpleServer stops accepting clients after unknown Compact or JSON types
- THRIFT-6127 - Ruby sockets remain reusable after I/O timeouts
- THRIFT-6128 - Ruby: exclude development files from the thrift gem
- THRIFT-6129 - Enforce Ruby HeaderTransport ZLIB limit before buffering
- THRIFT-6131 - Bound Ruby HeaderTransport varint32 parsing
- THRIFT-6132 - Ruby HeaderTransport retains stale metadata after legacy frames
- THRIFT-6133 - Ruby native MemoryBufferTransport handles oversized reads consistently
- THRIFT-6136 - Stop suppressing Ruby integer conversion errors in fuzzing
- THRIFT-6137 - Ruby HeaderTransport should reject incomplete framed protocol headers
- THRIFT-6138 - Ruby MemoryBufferTransport should privately own initial buffers
- THRIFT-6139 - Ruby CompactProtocol writers should reject out-of-range integers
- THRIFT-6140 - Ruby SimpleServer stops after a short JSON UUID value
- THRIFT-6141 - Ruby HeaderTransport exposes raw ZLIB decompression errors
- THRIFT-6142 - Ruby HeaderTransport does not limit unframed messages
- THRIFT-6144 - Ruby BaseTransport read_all should report EOF when reads make no progress
- THRIFT-6145 - Validate Ruby Compact decoder varint and binary size bounds
- THRIFT-6146 - Ruby processor should validate request message types
- THRIFT-6147 - Ruby Serializer should finalize buffered protocol transports
- THRIFT-6148 - Ruby HeaderTransport should enforce limits against complete frames
- THRIFT-6149 - Ruby Binary and Compact protocols should avoid decoding skipped strings
- THRIFT-6153 - Reduce native Ruby Compact Protocol varint write overhead
- THRIFT-6154 - Drop Ruby 2.7 support
- THRIFT-6155 - Ruby SimpleServer exits on zero-length framed messages
- THRIFT-6156 - Ruby JsonProtocol leaks ArgumentError for malformed Base64 data
- THRIFT-6157 - Ruby CompactProtocol fixed-width reads differ between native and pure modes
- THRIFT-6158 - Ruby processor should classify malformed request arguments as protocol errors
- #3900 - Use a byte-string buffer that RuboCop accepts in the varint spec
- #3884 - Restore bake 0.25.0 in test/rb/Gemfile.lock
- #3831 - Use the client certificate with subjectAltNames in the SSL cross-test clients
- #3635 - Bump puma from 6.6.1 to 7.2.1 in /test/rb
- #3740 - Omit parentheses from zero-argument Ruby methods
- #3732 - Enable RuboCop Style/LineEndConcatenation
- #3731 - Enable RuboCop Lint/Void
- #3729 - Enable RuboCop Lint/UselessAssignment
- #3728 - Enable RuboCop Style/RedundantReturn
- #3727 - Enable RuboCop Style/RedundantBegin
- #3726 - Enable RuboCop redundancy rules
- #3725 - Enable RuboCop ambiguity rules
- #3723 - Enable additional RuboCop spacing rules
- #3722 - Enable RuboCop Style/UnpackFirst
- #3719 - Enforce Ruby whitespace layout rules
- #3717 - Enable multiline Ruby layout cops
- #3716 - Enforce modern Ruby hash syntax
- #3715 - Enable double-quoted Ruby string literals
- #3714 - Enable additional Ruby RuboCop rules
- #3683 - Silence Ruby native capability queries
- #3670 - Bump json from 2.19.2 to 2.19.9 in /test/rb
- #3671 - Bump json from 2.19.2 to 2.19.9 in /lib/rb
- #3627 - Skip Thin HTTP server bundle on Ruby head
Rust
- THRIFT-6097 - Rust supports TLS
- THRIFT-6159 - Rust: Use faster varint library - #3739
- THRIFT-6288 - Rust: the stale remaining-bytes TODO in check_container_size
- THRIFT-6290 - Rust: skip string/binary fields without heap-allocating
- THRIFT-6298 - Rust: split_halves_must_not_clobber_each_others_timeout fails on kernels with HZ=250
- #3831 - Use the client certificate with subjectAltNames in the SSL cross-test clients
- #3637 - Remove Rust deprecation warning
- #3625 - Fix Go and Rust version detection for multi-digit version numbers
Smalltalk
- THRIFT-6062 - Smalltalk compiler crashes (stack overflow) on recursive struct types
- THRIFT-6063 - add Smalltalk to Github CI
- THRIFT-6258 - Smalltalk: TTransport»readAll: loops forever when read: returns no bytes
- THRIFT-6300 - Smalltalk: TBinaryProtocol decodes what the transport returned without checking its length
- #3815 - Test the string length bound in the Smalltalk binary protocol
Test Suite
- THRIFT-6167 - PHP HTTP cross-test server omits Content-Length and breaks php-cpp HTTP cases
- THRIFT-6270 - Sweep for source files that no build list mentions
- THRIFT-6275 - Go cross-test client presents no client certificate, and Go 1.27 cannot load client_v3.crt
- THRIFT-6284 - Wire up source and test files that a build list misses (THRIFT-6270 follow-up)
- THRIFT-6316 - Fetch the test and tutorial JavaScript libraries over HTTPS
Tutorial
- THRIFT-6316 - Fetch the test and tutorial JavaScript libraries over HTTPS
XML/XSD
- THRIFT-6346 - Remove dead code from the Java ME, Dart, Mermaid and XSD generators
(No Section)
- #3834 - Correct LANGUAGES.md entries flagged after the matrix update
- #3820 - Update LANGUAGES.md with current versions and supported features
- #3758 - Forbid tool-internal links in commit messages and PR text
- #3707 - Update Apache Thrift DOAP metadata [skip ci]
Breaking Changes
- THRIFT-6197 - Go: a typedef of a struct, union or exception is generated as a type alias (
type Alias = Inner) instead of a defined pointer type (type Alias *Inner), and no <Name>Ptr helper is generated for it; code that held a *Inner in such an alias now holds an Inner and takes the pointer outside the alias
0.24.0
Build Process
- THRIFT-5000 - Thrift docker image publish on releases
- THRIFT-5855 - Improve fuzzing support
- THRIFT-5952 - Optimize MSVC Docker image to reduce size and speed up CI
- THRIFT-5965 - Add zizmor for GitHub Actions workflows security analysis
- THRIFT-5967 - Refactor SCA GitHub workflow for better extensibility
- THRIFT-5973 - Automated CHANGELOG creation
- THRIFT-6002 - Add netstd codegen test script and GitHub Actions CI matrix job (.NET 8/9/10)
- THRIFT-6003 - Add Haxe codegen test script and GitHub Actions CI job
- THRIFT-6077 - improve CHANGES.md generator section assignment
- #3613 - Bump rubygems/release-gem from 1.2.0 to 1.4.0
- #3616 - Bump ruby/setup-ruby from 1.310.0 to 1.314.0
- #3617 - Bump rust-lang/crates-io-auth-action from 1.0.4 to 1.0.5
- #3618 - Bump jvm from 2.3.21 to 2.4.0 in /lib/kotlin
- #3619 - Bump com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin
- #3615 - Bump actions/setup-go from 6.4.0 to 6.5.0
- THRIFT-6092 - fix off-by-ten header bounds check in readHeaderFormat
- #3593 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/js
- #3591 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/ts
- #3589 - Update MSVC CI to windows-2025-vs2026 runner and start Docker service explicitly
- #3581 - Run the Haxe library unit tests (neko) in CI
- #3576 - Bump ruby/setup-ruby from 1.306.0 to 1.310.0
- #3575 - Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6
- #3577 - Bump actions/setup-dotnet from 4.3.1 to 5.2.0
- #3574 - Bump com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin
- #3572 - Bump org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin
- #3578 - Harden the MSVC build workflow against transient Docker daemon unavailability
- #3564 - Enable Copilot reviews
- #3565 - Allow CI to fail on ruby-head
- #3517 - Bump uuid and nyc
- #3513 - Remove Ruby known failures from cross-test list
- #3501 - Fix netstd CI .NET SDK setup
- #3496 - Add generator paths to mergeable labels
- #3430 - Updated projects settings in .asf.yaml (features, merge buttons, Jira autolinking)
- #3487 - Update to setup-php 2.37.1
- #3471 - Update build.yml
- #3461 - Migration *.sln to *.slnx (except c++ libs)
- #3454 - Fixing bundler on ruby-head build
- #3440 - Removed deprecated ‘publish’ workflow
- #3439 - Pin all actions to a specific SHA consistently
- #3437 - Validate GitHub workflows against the ASF allowlist
- #3433 - Pin actions/upload-artifact to a specific SHA consistently
- #3433 - Bump actions/upload-artifact from 7.0.0 to 7.0.1
- #3434 - Bump jvm from 2.3.20 to 2.3.21 in /lib/kotlin
- #3423 - Bump uuid from 13.0.0 to 14.0.0
- #3424 - Bump json from 2.18.1 to 2.19.2 in /lib/rb
- #3404 - Cleanup Adobe Flex SDK installation following AS3 library removal
- #3400 - Bump json from 2.18.1 to 2.19.2 in /test/rb
- #3397 - Address vulnerabilities in Rack
- #3386 - Bump lodash from 4.17.23 to 4.18.1
- #2957 - Fix PHP cross-test server IPv4 binding
- #3384 - Fix ubuntu-noble Docker build: modernize NodeSource GPG setup
- #3384 - Fix ubuntu-focal Docker build: update NodeSource setup and ENV format
- #3384 - Fix ubuntu-jammy Docker build: update NodeSource and ENV format
- #3380 - Fix docker warnings on ENV format
- #3380 - Override enforcement of PEP 668
C glib
- THRIFT-5930 - thrift_server_socket() copies Unix socket paths into sockaddr_un.sun_path without bounds checking
- THRIFT-6088 - Add consumed byte tracking to ThriftZlibTransport read
- THRIFT-6091 - Widen container size precheck to 64-bit in c_glib protocols
- THRIFT-6094 - Copy buffered data not the GByteArray struct in c_glib read_slow
- #3585 - limit recursion depth in c_glib thrift_protocol_skip
- THRIFT-6086 - Add peer hostname validation to c_glib TLS client
- #3393 - Fix parent class resolution in c_glib generated dispatch_call
C++
- THRIFT-3165 - Disable unsafe TLSv1.0 and TLSv1.1 by default
- THRIFT-6021 - When C++ client with HTTP transport calls a oneway RPC method, it must not expect a response
- THRIFT-6060 - C++ THttpClient does not reopen socket after server sends Connection: close
- THRIFT-6073 - Allow injecting external SSL_CTX into C++ SSLContext
- THRIFT-6088 - Add decompressed byte tracking to C++ TZlibTransport
- THRIFT-6091 - Widen container size precheck to 64-bit in C++ protocols
- THRIFT-6093 - Read the zlib transform result directly in THeaderTransport untransform
- THRIFT-6096 - Fix info-header string bound check in THeaderTransport::readString
- THRIFT-6092 - link UnitTests against libthriftz to resolve THeaderTransport vtable
- THRIFT-6092 - fix off-by-ten header bounds check in readHeaderFormat
- #3569 - Add the cpp.ref (&) annotation to the recursive exception in Recursive.thrift
- #3519 - Preserve private_optional field order
- #3498 - change sprintf to snprintf to eliminate security warnings on OSX
- THRIFT-6087 - Enforce RFC 6125 wildcard placement in TSSLSocket hostname matching
- #3508 - Replace memory-safety asserts with unconditional throws in TBufferTransports
- #3431 - Remove another boost header from the public API
Compiler (General)
- #3529 - nodejs+compiler: Add opt-in BigInt support for int64 via js:bigint flag
- #3461 - Migration *.sln to *.slnx (except c++ libs)
- #2957 - Fix PHP cross-test server IPv4 binding
- #3372 - Fix JavaScript exception construction implementation (ES6)
D
- THRIFT-6053 - Limit struct read/write recursion depth in D library
- THRIFT-6088 - Add decompressed data size limit to D TZlibTransport
Dart
- THRIFT-6034 - Harden Dart protocol negative sizes
- THRIFT-6056 - Limit struct read/write recursion depth in Dart library
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
Delphi
- THRIFT-2462 - prevent possible stack overflow due to recursive syntax support
- THRIFT-6007 - Implement MESSAGE_SIZE_LIMIT exception type for Delphi library
- THRIFT-6091 - Compute container size precheck in 64-bit in Delphi protocols
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
Documentation
- #3520 - added thrift-threat-model.md, SECURITY.md and security section to AGENTS.md
Erlang
- THRIFT-6030 - Harden Erlang protocol negative sizes
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
- THRIFT-6366 - Bound the message size in the Erlang binary and compact protocols
Go
- THRIFT-5214 - go: Implement connection check in TSocket
- THRIFT-5969 - Introduce gofmt for Go library
- THRIFT-5996 - go: connection check should work for TLS sockets
- THRIFT-6011 - Make compiled Go code formatting compatible with gofmt
- THRIFT-6012 - Fix inverted regexp.MatchString arguments and precompile patterns in Go validator
- THRIFT-6044 - Limit struct read/write recursion depth in Go library
- THRIFT-6071 - Validate container size fits int32 range before narrowing conversion in TSimpleJSONProtocol
- THRIFT-6088 - Add decompressed data size limit to TZlibTransport
- THRIFT-6091 - Bound the container element count before the 64-bit size precheck in the Go JSON protocol
- THRIFT-6091 - widen container size precheck to 64-bit in go protocols
- #3599 - check wire-supplied size in simple json ReadMapBegin
- #3497 - Bump golang.org/x/sys to 0.0.0-20220412211240-33da011f77ad
- #3458 - Prevent concurrent calls to socketConn.Close() in Go
- #3428 - Fix range check on 32-bit architectures
- #3379 - Replace addr with factory in TServerSocket
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
- #3381 - added int range checks
Haxe
- THRIFT-5992 - Haxe generator: keyword escaping, stdlib-type renaming, typedef import and FIELD_ID fixes
- THRIFT-5993 - Haxe generator: cross-package import shadowing and Haxe base-type name collisions
- THRIFT-5994 - Haxe generator: map<bool,V>, map<double,V>, map<binary,V> and set equivalents generate invalid ObjectMap/ObjectSet
- THRIFT-6003 - Add Haxe codegen test script and GitHub Actions CI job
- THRIFT-6006 - Implement MESSAGE_SIZE_LIMIT exception type for Haxe library
- THRIFT-6065 - Haxe TMemoryStream cannot be written to (fixed-size buffer, uninitialized Position)
- THRIFT-6091 - Compute container size precheck in 64-bit in Haxe protocols
- #3571 - Add recursion-depth round-trip test for the Haxe library
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
Java
- THRIFT-6088 - Add decompressed byte tracking to Java TZlibTransport
- #3618 - Bump jvm from 2.3.21 to 2.4.0 in /lib/kotlin
- #3619 - Bump com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin
- #3605 - enforce stringLengthLimit in TCompactProtocol.readBinary
- #3574 - Bump com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin
- #3572 - Bump org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin
- THRIFT-6085 - Add message byte tracking to consumeBuffer() in Java transports
- #3434 - Bump jvm from 2.3.20 to 2.3.21 in /lib/kotlin
- #3420 - Fix Java Spotless formatting
- #3415 - Connect skip() to TConfiguration recursion limit
- #3412 - Use bounded default for maxSkipDepth in TProtocolUtil
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
- #3396 - Enable TLS hostname verification in TNonblockingSSLSocket
- #3390 - Enable TLS hostname verification in TSSLTransportFactory
JavaME
- THRIFT-6036 - Harden JavaME protocol negative sizes
- THRIFT-6055 - Limit struct read/write recursion depth in javame library
JavaScript
- THRIFT-6014 - Add recursion depth limit to skip() in JavaScript library
- THRIFT-6017 - Upgrade jsdoc from 3.6 to 4.x in lib/js and lib/ts
- THRIFT-6020 - Address remaining npm transitive dependency vulnerabilities via audit fix (minimatch, elliptic, lodash)
- THRIFT-6037 - Harden JavaScript (browser) protocol negative sizes
- THRIFT-6046 - Limit struct read/write recursion depth in js library
- #3593 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/js
- #3591 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/ts
- #3517 - Bump uuid and nyc
- #3423 - Bump uuid from 13.0.0 to 14.0.0
- #3385 - Add test for ES6 generated exception constructor
- #3386 - Bump lodash from 4.17.23 to 4.18.1
- #3372 - Fix JavaScript exception construction implementation (ES6)
Kotlin
- THRIFT-6054 - Limit struct read/write recursion depth in Kotlin library
- #3618 - Bump jvm from 2.3.21 to 2.4.0 in /lib/kotlin
- #3572 - Bump org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin
- #3434 - Bump jvm from 2.3.20 to 2.3.21 in /lib/kotlin
Lua
- THRIFT-6031 - Harden Lua protocol negative sizes
- THRIFT-6049 - Limit struct read/write recursion depth in Lua library
- #3448 - final change to make header parsing case insensitive
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
Markdown
- THRIFT-6027 - Fix UB/assertion in t_markdown_generator::str_to_id (debug build crash)
- THRIFT-6038 - Markdown generator: use .md extension by default and render @param/@return tags as table
Mermaid
netstd
- THRIFT-2462 - prevent possible stack overflow due to recursive syntax support
- THRIFT-4534 - netcore package should not depend on Microsft.AspNetCore and Microsoft.Extensions.*
- THRIFT-5997 - netstd generator: binary and uuid constants emitted as C# const instead of static readonly
- THRIFT-5998 - netstd generator: duplicate DeepCopy/Equals/GetHashCode extension methods when IDL includes other IDL files
- THRIFT-6002 - Add netstd codegen test script and GitHub Actions CI matrix job (.NET 8/9/10)
- THRIFT-6091 - Compute container size precheck in 64-bit in netstd protocols
- #3461 - Migration *.sln to *.slnx (except c++ libs)
- #3416 - netcore package upgrades
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
- #3407 - Build netstd fuzzers during make check (without instrumentation)
nodejs
- THRIFT-5802 - Inconsistent Validation for transmitted values
- THRIFT-6019 - Replace html-validator-cli with a maintained alternative in root Node.js package
- THRIFT-6020 - Address remaining npm transitive dependency vulnerabilities via audit fix (minimatch, elliptic, lodash)
- THRIFT-6040 - Switch JS/Node generator and runtime from Q to native Promise
- THRIFT-6090 - Bound receive size and amortize buffer growth in Node.js transports
- #3529 - nodejs+compiler: Add opt-in BigInt support for int64 via js:bigint flag
- #3526 - Fix WebSocket subprotocol for ws v8
- #3526 - Upgrade ws from 5.2.x to 8.21.0
- #3517 - Bump uuid and nyc
- #3389 - Add recursion depth limit to Node.js protocol skip()
- #3385 - Fix prettier formatting in generated-exceptions test
nodets
- THRIFT-6016 - lib/ts: jsdoc incorrectly listed under dependencies instead of devDependencies
- THRIFT-6017 - Upgrade jsdoc from 3.6 to 4.x in lib/js and lib/ts
- THRIFT-6018 - Remove phantom and phantomjs-prebuilt from lib/ts devDependencies
- THRIFT-6020 - Address remaining npm transitive dependency vulnerabilities via audit fix (minimatch, elliptic, lodash)
- #3591 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/ts
- #3517 - Bump uuid and nyc
OCaml
- THRIFT-6032 - Harden OCaml protocol negative sizes
- THRIFT-6051 - Limit struct read/write recursion depth in OCaml library
Perl
- THRIFT-5064 - Introduce Perl::Critic into the SCA
- THRIFT-6028 - Harden Perl protocol negative sizes
- THRIFT-6048 - Limit struct read/write recursion depth in Perl library
PHP
- THRIFT-4171 - PHP TSocket sendTimeout is being used as connectTimeout
- THRIFT-5757 - Unit tests for php lib
- THRIFT-5759 - PHP mbstring.func_overload is deprecated
- THRIFT-5929 - Fix build failure on PHP 8.5 due to removed zend_exception_get_default
- THRIFT-5951 - PHP Unit test update
- THRIFT-5956 - Bump minimum PHP version to 8.1
- THRIFT-5957 - Add phpstan static analysis with CI guardrail for the PHP runtime library
- THRIFT-5959 - Adopt PSR-12 across the PHP library and align C++ generator emission style
- THRIFT-5960 - Adopt strict_types and native parameter / return / property types in lib/php/lib/
- THRIFT-5961 - Migrate PHPUnit tests to attribute syntax
- THRIFT-5962 - Upgrade PHPUnit to 10 / 11
- THRIFT-5975 - Remove dead pre-namespace lib/php/src/{Thrift,autoload}.php
- THRIFT-5976 - Add native types to PHP library properties (PHPDoc @var → declared types)
- THRIFT-5977 - Apply constructor property promotion in PHP runtime library
- THRIFT-5978 - Apply declare(strict_types=1) in PHP runtime library
- THRIFT-5979 - Add native method types to PHP Server and Factory classes
- THRIFT-5980 - Add native method types to PHP Transport hierarchy
- THRIFT-5981 - Add native method types to PHP Protocol hierarchy
- THRIFT-5983 - Replace switch with match expression in PHP TProtocol::skip and skipBinary
- THRIFT-5984 - Cache function_exists() capability checks in PHP runtime hot paths
- THRIFT-5985 - Add native method types to PHP Exception hierarchy
- THRIFT-5986 - Emit declare(strict_types=1) in PHP generator output
- THRIFT-5987 - Fix PHP protocol type-safety bugs in readBool and popContext
- THRIFT-5988 - PHP 8.1 upgrade follow-up: float constants, README version, and TSSLServerSocket API compatibility
- THRIFT-5989 - Work around JWT-format GITHUB_TOKEN breaking composer install in CI
- THRIFT-5990 - Emit native return types on generated PHP struct methods
- THRIFT-5991 - Emit native types on generated PHP struct properties and constructor
- THRIFT-5995 - Add native method types to TBase and TException internal serialization helpers
- THRIFT-5999 - Raise PHPStan level from 1 to 5 on PHP library
- THRIFT-6000 - Add native method types to PHP JSON protocol helpers and context classes
- THRIFT-6001 - Type remaining core PHP library methods and fix TException tmethod UUID drift
- THRIFT-6004 - Emit native types on generated PHP service-level methods (Client/Interface/Processor/Rest)
- THRIFT-6005 - Raise PHPStan level from 5 to 6 on PHP library
- THRIFT-6008 - Add regression tests for recent PHP fixes (UUID exception fields, readBool container state, popContext underflow)
- THRIFT-6009 - Add PSR-3 logger support and runtime deprecation warnings to PHP transports
- THRIFT-6010 - Add PSR-18 HTTP transport (TPsrHttpClient) for PHP library
- THRIFT-6023 - Add HTTP transport support to PHP cross-tests
- THRIFT-6029 - Harden PHP protocol negative sizes
- THRIFT-6047 - Limit struct read/write recursion depth in PHP library
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
- #2957 - Fix PHP cross-test server IPv4 binding
Python
- THRIFT-5915 - Python 3.12+ is not supported due to distutils
- THRIFT-5923 - UUID support for Python
- THRIFT-6024 - Python THeaderTransport and TZlibTransport default max frame/decompressed size should be DEFAULT_MAX_FRAME_SIZE (16384000), not HARD_MAX_FRAME_SIZE (0x3FFFFFFF)
- THRIFT-6043 - Harden Python binary protocol negative sizes
- THRIFT-6067 - Python: pip install fails on setuptools < 69 due to sys.exit() in setup.py (PEP 517 build backend)
- THRIFT-6069 - suggestion for a few python perf improvements
- THRIFT-6070 - Publish Python wheel distributions to PyPI
- THRIFT-6088 - Add decompressed size limit to Python TZlibTransport
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
- #3413 - Use sslcompat hostname matcher in TSSLSocket
- #3411 - Add default recursion depth limit to TProtocol.skip()
- THRIFT-6083 - Add decompressed payload size limit to Python THeaderTransport
- #3377 - Optimize Python C extension readStruct for nested structs
- #2957 - Fix PHP cross-test server IPv4 binding
Ruby
- THRIFT-1916 - Compiled ruby code generates warning if field with name “fields” is present
- THRIFT-5310 - Ruby BinaryProtocol has invalid range checks for byte and i64
- THRIFT-5940 - Ruby generator should emit RuboCop-compliant code and SCA should lint generated Ruby
- THRIFT-5941 - Add Ruby ext cppcheck coverage
- THRIFT-5942 - Incorrect connection timeout handling in TSocket / TSSLSocket
- THRIFT-5944 - Fix protocol benchmarks for Ruby and add compact protocol support
- THRIFT-5945 - Incomplete cleanup in NonblockingServer leaks sockets
- THRIFT-5946 - Use trusted publishing for Ruby gem releases
- THRIFT-5948 - Reduce Ruby binary extension write-path overhead in native force_binary_encoding helper
- THRIFT-5949 - Ruby server sockets do not enforce write timeouts on accepted connections
- THRIFT-5950 - Add frozen_string_literal to Ruby files to reduce allocations
- THRIFT-6013 - Add recursion depth limit to skip() in Ruby library
- THRIFT-6015 - Allow multiplex processors to fall back to a default service for old clients
- THRIFT-6025 - Ruby client must validate container sizes
- THRIFT-6045 - Limit struct read/write recursion depth in Ruby library
- THRIFT-6072 - Ruby ThreadedServer and SimpleServer crash on SSL accept errors
- #3565 - Allow CI to fail on ruby-head
- #3565 - Fix Ruby lib CI: drop pry/byebug, incompatible with Ruby 4.1+
- THRIFT-6089 - Bound decompressed size for Ruby HeaderTransport ZLIB transform
- #3429 - Updated lib/rb/README.md to highlight Ruby syntax
- #3424 - Bump json from 2.18.1 to 2.19.2 in /lib/rb
- #3422 - Adjust minimum Ruby version in the gemspec to match documentation, CI, and Changelog
- #3419 - Ruby: suppress -Wdefault-const-init-field-unsafe for clang 21+
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
- #3395 - Remove unused Ruby client reply helpers
- #3400 - Bump json from 2.18.1 to 2.19.2 in /test/rb
- #3397 - Address vulnerabilities in Rack
- #3382 - Updated Gemfile.lock to fix build issues
Rust
- THRIFT-5953 - Rust codegen should support forward-compatible deserialization for union fields in structs
- THRIFT-5954 - Rust: Add read/write timeout support to TTcpChannel
- THRIFT-6057 - Limit struct read/write recursion depth in Rust library
- THRIFT-6058 - Rust codegen:
list<UnionType> deserialization generates shadowed variable and missing Box wrapping
- THRIFT-6059 - add crate_prefix option for cross-file import path
- THRIFT-6064 - Rust generator does not box recursive union variant on read
- THRIFT-6068 - Thrift release on crates.io is very stale; consider auto-publishing
- THRIFT-6095 - enforce max_string_size on non-strict binary message name
- THRIFT-6084 - Add byte-count limit to TCompactProtocol varint reader
Smalltalk
- THRIFT-6035 - Harden Smalltalk protocol negative sizes
- THRIFT-6052 - Limit struct read/write recursion depth in Smalltalk library
Swift - NO LONGER SUPPORTED
Test Suite
0.23.0
Build Process
C glib
- THRIFT-5931 - thrift_ssl_socket_get_ssl_error() can underflow its remaining-buffer counter and write past the stack buffer
- THRIFT-5871 - Improve MAX_MESSAGE_SIZE check and friends
C++
- THRIFT-5911 - Inconsistent UUID compilation for aliased types
- THRIFT-5912 - Assertion failed:
delta > 0, file ThreadManagerTests.h, line 162
- THRIFT-5880 - C++ TSocket on an IPv6-only system fails if you use a hostname of 127.0.0.1
- THRIFT-3268 - warning: token pasting of ‘,’ and
__VA_ARGS__ is a GNU extension
- THRIFT-5887 - build/cmake/ should be prepended (not appended) to CMAKE_MODULE_PATH
- THRIFT-5878 - Add UUID support for THeaderProtocol and TProtocolTap
- THRIFT-5898 - Unable to build Thrift as a shared library on Windows
Contributed
- THRIFT-5920 - Remove threadsafe warnings in thrift-maven-plugin
Delphi
- THRIFT-5939 - Replace GUID generation with stable UUID algorithm
- THRIFT-5876 - Add Delphi WinHTTP client TLS1.3 support
Go
- THRIFT-5896 - Race condition in TServerSocket.Addr() method
Java
- THRIFT-5925 - UUID implementation in JAVA is not according to the Thrift Specification
- THRIFT-5869 - Close the transport after TServerEventHandler deleteContext
- THRIFT-5863 - Make TServerTransport able to customize the max message size
- THRIFT-5774 - Add remote client’s IP address to ServerContext in TServerEventHandler
- THRIFT-4280 - Add async nonblocking ssl support in java client
- THRIFT-5879 - java and kotlin cross tests fail in the GitHub action
netstd
nodejs
- THRIFT-5937 - nodejs episodic generation does not handle extending services
- THRIFT-5924 - UUID support for nodejs and nodets
- THRIFT-4987 - TProtocolException: Bad version in readMessageBegin when using XHR client with C++ server
nodets
PHP
- THRIFT-5935 - Fix deprecated non-canonical casts for PHP 8.5 compatibility
- THRIFT-5921 - Ubuntu focal fail to run composer install
- THRIFT-5929 - Fix build failure on PHP 8.5 due to removed zend_exception_get_default
Python
- THRIFT-5927 - Cannot use reserved language keyword “None” with target language Python
- THRIFT-5885 - TBinaryProtocolAccelerated incorrectly deserializes IntEnum to None
- THRIFT-5923 - UUID support for Python
- THRIFT-5926 - TSaslClientTransport.open() crashes with DIGEST-MD5 due to None initial response
- THRIFT-5915 - Python 3.12+ is not supported due to distutils
- THRIFT-5892 - PY_SSIZE_T_CLEAN error in some environments
- THRIFT-5873 - mTLS broken with python THttpClient
- THRIFT-792 - TSocket hides underlying exceptions when open() fails
- THRIFT-5888 - declare support for free-threaded CPython in extension modules
- THRIFT-5900 - Thrift Cross Test broken in Github (Python 3.14)
Ruby
- THRIFT-5308 - implement ruby seq replyÂ
- THRIFT-5910 - Add UUID support in Ruby
- THRIFT-5906 - Remove Fixnum references to support modern Ruby versions
- THRIFT-5905 - Add base64 and logger as explicit dependencies
- THRIFT-5903 - Fixnum is no longer supported since Ruby 3.2
- THRIFT-5687 - Ruby gems deprecation warning: Gem::Specification#has_rdoc= is deprecated with no replacement
- THRIFT-4035 - Thrift ruby runtime does not send unique sequence IDs in requests according to the unit tests
- THRIFT-1911 - IOError not being caught in socket.rb
- THRIFT-4526 - Implement rubocop for ruby in the sca build, once clean into every make
- THRIFT-5273 - warning in ruby version >= 2.4
- THRIFT-5918 - Implement header protocol support for Ruby
Rust
- THRIFT-5559 - Processor can be implemented on handler trait itself
- THRIFT-5928 - skip() call on unknown binary field fails deserialization instead of graceful skipping over field
- THRIFT-5739 - set_nodelay should be enabled for TTcpChannel
Swift
- THRIFT-5864 - Remove Swift binding (compiler generator, library, tests, and tutorial)