chore(deps): update cloudamqp/lavinmq docker tag to v2.9.3 #305

Merged
renovate merged 1 commits from renovate/cloudamqp-lavinmq-2.x into main 2026-09-12 15:07:52 +00:00
Owner

This PR contains the following updates:

Package Update Change
cloudamqp/lavinmq patch 2.9.2 → 2.9.3

Release Notes

cloudamqp/lavinmq (cloudamqp/lavinmq)

v2.9.3

Compare Source

This patch release fixes MQTT persistent sessions losing their subscriptions on restart, a segfault when dead-lettering races a purge or queue delete, and slow restarts with many delayed messages. It enforces the vhost max-connections and max-queues limits for MQTT, stops PROXY protocol connections from counting as loopback for the default user, and corrects several message statistics, stream policy, API and management UI issues.

Fixed
  • MQTT persistent sessions lost their subscriptions on restart: the MQTT exchange was created after the definitions were loaded, and its bindings were never written to the definitions file #​2159
  • Segfault (use after munmap) when dead-lettering a message raced a purge or a queue delete on the source queue #​2184
  • O(N²) insert in the delayed message store made broker restarts hang and publishing to a large delayed exchange queue progressively slower; replaced with a min-heap #​2175
  • Per-vhost message_stats no longer over-counts published messages by the fan-out factor; cumulative message counters are read from the vhost's own counters instead of summing per-queue #​2092
  • Prometheus and HTTP API counters (global_messages_*, churn *_total, /api/overview, /api/nodes) no longer decrease when a queue or vhost is deleted, which previously made rate()/increase() fabricate spikes #​2093
  • return_unroutable was only counted per channel and always reported 0 in per-vhost message_stats, /api/overview and Prometheus; it is now aggregated to the vhost and exposed as lavinmq_global_messages_unroutable_returned_total #​2203
  • The vhost max-connections limit is now enforced for MQTT connections #​2222
  • MQTT sessions now respect the vhost max-queues limit; a SUBSCRIBE that would create a session beyond the cap is answered with failure return codes instead of exceeding the limit #​2223
  • A connection with a PROXY protocol header never counts as loopback for default_user_only_loopback, including through a cluster follower. The default user can only connect directly on the broker host #​2224
  • A stream queue that got max-age only from a policy ignored policy edits that increased max-age until restart #​2152
  • The broker failed to start when users.json contained an unknown key, for example after a downgrade b9f03d90
  • HTTP shovels could not be created through the API, config validation demanded a destination queue or exchange that an HTTP destination has no use for #​2215
  • GET and DELETE /api/vhosts/:vhost return 404 instead of 403 for a non-existent vhost when the user is an administrator #​2147
  • MQTT connections were missing host, port, peer_host and peer_port in lavinmqctl list_connections, the management UI and /api/connections #​2138
  • MQTT 3.1 connections were reported as MQTT 3.1.1 in connection details #​2139
  • Management UI: a failed API request no longer resets form values or reloads the table; the error is shown and the form keeps its input #​2214
  • Management UI: the vhost page no longer raises an error when the limits request fails on page load #​2225
  • Management UI: table links overlapped other elements because of a stray z-index #​2135
Changed
  • CC and BCC headers are removed from dead-lettered messages when x-dead-letter-routing-key is set, instead of being preserved, matching RabbitMQ #​1993
  • Deprecated config options are handled the same way for INI and CLI options, with a warning at startup #​2059
  • MQTT sessions are decoupled from AMQP queues as part of separating protocol-specific queue/session handling #​1920
  • Follower full sync logs progress as compared/total files #​2169
  • Use mqtt-protocol 0.3.1 #​2157
  • No RPM packages are built for Fedora 42, which is end of life 9d686861

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [cloudamqp/lavinmq](https://github.com/cloudamqp/lavinmq) | patch | `2.9.2` → `2.9.3` | --- ### Release Notes <details> <summary>cloudamqp/lavinmq (cloudamqp/lavinmq)</summary> ### [`v2.9.3`](https://github.com/cloudamqp/lavinmq/releases/tag/v2.9.3) [Compare Source](https://github.com/cloudamqp/lavinmq/compare/v2.9.2...v2.9.3) This patch release fixes MQTT persistent sessions losing their subscriptions on restart, a segfault when dead-lettering races a purge or queue delete, and slow restarts with many delayed messages. It enforces the vhost `max-connections` and `max-queues` limits for MQTT, stops PROXY protocol connections from counting as loopback for the default user, and corrects several message statistics, stream policy, API and management UI issues. ##### Fixed - MQTT persistent sessions lost their subscriptions on restart: the MQTT exchange was created after the definitions were loaded, and its bindings were never written to the definitions file [#&#8203;2159](https://github.com/cloudamqp/lavinmq/pull/2159) - Segfault (use after munmap) when dead-lettering a message raced a purge or a queue delete on the source queue [#&#8203;2184](https://github.com/cloudamqp/lavinmq/pull/2184) - O(N²) insert in the delayed message store made broker restarts hang and publishing to a large delayed exchange queue progressively slower; replaced with a min-heap [#&#8203;2175](https://github.com/cloudamqp/lavinmq/pull/2175) - Per-vhost `message_stats` no longer over-counts published messages by the fan-out factor; cumulative message counters are read from the vhost's own counters instead of summing per-queue [#&#8203;2092](https://github.com/cloudamqp/lavinmq/issues/2092) - Prometheus and HTTP API counters (`global_messages_*`, churn `*_total`, `/api/overview`, `/api/nodes`) no longer decrease when a queue or vhost is deleted, which previously made `rate()`/`increase()` fabricate spikes [#&#8203;2093](https://github.com/cloudamqp/lavinmq/issues/2093) - `return_unroutable` was only counted per channel and always reported 0 in per-vhost `message_stats`, `/api/overview` and Prometheus; it is now aggregated to the vhost and exposed as `lavinmq_global_messages_unroutable_returned_total` [#&#8203;2203](https://github.com/cloudamqp/lavinmq/pull/2203) - The vhost `max-connections` limit is now enforced for MQTT connections [#&#8203;2222](https://github.com/cloudamqp/lavinmq/pull/2222) - MQTT sessions now respect the vhost `max-queues` limit; a SUBSCRIBE that would create a session beyond the cap is answered with failure return codes instead of exceeding the limit [#&#8203;2223](https://github.com/cloudamqp/lavinmq/pull/2223) - A connection with a PROXY protocol header never counts as loopback for `default_user_only_loopback`, including through a cluster follower. The default user can only connect directly on the broker host [#&#8203;2224](https://github.com/cloudamqp/lavinmq/pull/2224) - A stream queue that got `max-age` only from a policy ignored policy edits that increased `max-age` until restart [#&#8203;2152](https://github.com/cloudamqp/lavinmq/pull/2152) - The broker failed to start when `users.json` contained an unknown key, for example after a downgrade [b9f03d90](https://github.com/cloudamqp/lavinmq/commit/b9f03d90) - HTTP shovels could not be created through the API, config validation demanded a destination queue or exchange that an HTTP destination has no use for [#&#8203;2215](https://github.com/cloudamqp/lavinmq/pull/2215) - `GET` and `DELETE /api/vhosts/:vhost` return 404 instead of 403 for a non-existent vhost when the user is an administrator [#&#8203;2147](https://github.com/cloudamqp/lavinmq/pull/2147) - MQTT connections were missing `host`, `port`, `peer_host` and `peer_port` in `lavinmqctl list_connections`, the management UI and `/api/connections` [#&#8203;2138](https://github.com/cloudamqp/lavinmq/pull/2138) - MQTT 3.1 connections were reported as `MQTT 3.1.1` in connection details [#&#8203;2139](https://github.com/cloudamqp/lavinmq/pull/2139) - Management UI: a failed API request no longer resets form values or reloads the table; the error is shown and the form keeps its input [#&#8203;2214](https://github.com/cloudamqp/lavinmq/pull/2214) - Management UI: the vhost page no longer raises an error when the limits request fails on page load [#&#8203;2225](https://github.com/cloudamqp/lavinmq/pull/2225) - Management UI: table links overlapped other elements because of a stray `z-index` [#&#8203;2135](https://github.com/cloudamqp/lavinmq/pull/2135) ##### Changed - CC and BCC headers are removed from dead-lettered messages when `x-dead-letter-routing-key` is set, instead of being preserved, matching RabbitMQ [#&#8203;1993](https://github.com/cloudamqp/lavinmq/pull/1993) - Deprecated config options are handled the same way for INI and CLI options, with a warning at startup [#&#8203;2059](https://github.com/cloudamqp/lavinmq/pull/2059) - MQTT sessions are decoupled from AMQP queues as part of separating protocol-specific queue/session handling [#&#8203;1920](https://github.com/cloudamqp/lavinmq/pull/1920) - Follower full sync logs progress as compared/total files [#&#8203;2169](https://github.com/cloudamqp/lavinmq/pull/2169) - Use mqtt-protocol 0.3.1 [#&#8203;2157](https://github.com/cloudamqp/lavinmq/pull/2157) - No RPM packages are built for Fedora 42, which is end of life [9d686861](https://github.com/cloudamqp/lavinmq/commit/9d686861) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC42NS41IiwidXBkYXRlZEluVmVyIjoiNDQuNjUuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
renovate added 1 commit 2026-09-12 15:07:46 +00:00
chore(deps): update cloudamqp/lavinmq docker tag to v2.9.3
renovate/stability-days Updates have met minimum release age requirement
9163022755
renovate scheduled this pull request to auto merge when all checks succeed 2026-09-12 15:07:47 +00:00
renovate merged commit d623aea047 into main 2026-09-12 15:07:52 +00:00
renovate deleted branch renovate/cloudamqp-lavinmq-2.x 2026-09-12 15:07:53 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unboundsoftware/local-k8s#305