Dev News Daily ENDE

Caddy 2.11.7 fixes an HTTP/2 crash and SSE streams cut at 60 seconds, both from 2.11.6

The Caddy web server released version 2.11.7 on 3 October, a patch release that fixes regressions introduced by 2.11.6. The maintainers write that anyone on 2.11.6 is recommended to upgrade.

What went wrong. Version 2.11.6 introduced default idle read and write timeouts, and several problems followed:

  • the request body's idle deadline could outlive the handler that set it. Over HTTP/2, Caddy could then panic with a nil pointer dereference when the reverse proxy was still reading a request body after the handler had returned;
  • over HTTP/1.1, streaming responses to requests that had a body, such as server-sent-event clients that open the stream with a POST, were cut off exactly 60 seconds after the body was read;
  • over HTTP/2, streaming responses that paused between writes for longer than write_idle, one minute by default, such as quiet SSE streams, were reset with a stream error. As documented, only a write that stalls should count. All three are fixed. A separate 2.11.6 regression made placeholders for missing cookies, and TLS placeholders on plain HTTP requests, appear literally in output such as respond headers; they are empty again.

New: the Incremental header. Caddy now supports the Incremental header field from RFC 10036, described in the notes as the standard replacement for nginx's proprietary X-Accel-Buffering. An upstream response marked Incremental: ?1 is forwarded immediately by reverse_proxy and streamed rather than held back by encode. If buffering options would prevent that, Caddy answers 501 Not Implemented, as the RFC requires, and a new proxy_status_name option can explain why in a Proxy-Status header.

Smaller changes. Certificate lookup during TLS handshakes is about twice as fast when nothing subscribes to certificate events and debug logging is off. Unix sockets abandoned by a reload now close at once instead of hanging clients for about two minutes. Multiple Set-Cookie values in a JSON config are sent as separate headers, and caddy fmt no longer deletes an opening brace at the very end of the input.

Caddy 2.11.7 fixes an HTTP/2 crash and SSE streams cut at 60 seconds, both from 2.11.6
Caddy 2.11.7 fixes an HTTP/2 crash and SSE streams cut at 60 seconds, both from 2.11.6 — Dev News Daily

What it means

Anyone running 2.11.6 in front of streaming applications, server-sent events, long polls, AI token streams, should treat this as an urgent update: the 60-second cut-off looks like a client or application bug and is easy to misdiagnose. The Incremental header is the longer-term gain, giving applications a standard way to ask any proxy not to buffer.