--- snapshot-1789251324+++ snapshot-1789424903@@ -2,7 +2,11 @@ Release notes from rabbitmq-server -2026-08-14T00:46:15Z tag:github.com,2008:Repository/924551/v4.3.5 2026-08-17T21:42:00Z +2026-09-14T07:16:01Z tag:github.com,2008:Repository/924551/v4.3.6 2026-09-14T07:26:21Z + +RabbitMQ 4.3.6 + +
RabbitMQ 4.3.6 is a maintenance release in the 4.3.x release series.
It is strongly recommended that you read 4.3.0 release notes
in detail if upgrading from a version prior to 4.3.0.
The minimum supported Erlang version for this release series is 27.0.
RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ.
Nodes will fail to start on older Erlang releases.
Release notes can be found on GitHub at rabbitmq-server/release-notes.
Deleting an exchange did not delete the bindings that pointed to it as a destination.
A few related cases around auto-delete exchanges, transient queue cleanup and
virtual host deletion were fixed along the way.
Quorum queue continuous membership reconciliation could add more replicas than
the configured target.
Certain malformed urn:uuid: correlation or message ID caused exceptions during message format conversion.
Such values are now rejected.
GitHub issue: #17328
An operation that refers to an unknown queue type now fails with a
precondition_failed channel exception instead of an exception and abrupt channel termination.
GitHub issue: #17327
Classic queue recovery counted some message store references more than once.
GitHub issue: #17351
x-max-age values are now compared as durations, so redeclaring a stream
with 1D when it was declared with 24h no longer fails with a
PRECONDITION_FAILED (non-equivalent argument) exception.
With contributions from @Vishal-770.
AMQP 1.0 SQL filters: the value matched by a LIKE pattern with several
wildcards is now bounded independently of the message size limit.
GitHub issue: #17332
Direct connections (used by the shovel and federation plugins) now enforce channel_max_per_node
the same way network connections do.
Contributed by @Ayanda-D.
GitHub issue: #16610
New rabbitmq.conf setting: channel_tx_message_max. It bounds the number of publishes a channel
buffers in an open AMQP 0-9-1 transaction, and defaults to 10,000. Going over the limit
results in a precondition_failed channel exception.
Most applications won't be affected by this change and likely will not have to
increase the default limit.
GitHub issue: #17331
New rabbitmq.conf setting: listeners.startup_delay. It delays the start of client connection
listeners by the specified number of seconds, for environments where applications
begin connecting as soon as a port is open, before the node has finished booting.
Contributed by @Vishal-770.
Several channel interceptors can now be registered for the same AMQP 0-9-1 operation,
as long as they use different priorities. Previously, if two enabled plugins intercepted
the same operation, for example basic.publish, channels could not be opened at all.
Priorities are set per interceptor module in rabbitmq.conf. Lower values run first,
and omitted interceptors are assumed to have the priority of 0:
channel_interceptor.priorities.rabbit_timestamp_interceptor = 1 channel_interceptor.priorities.rabbit_routing_node_stamp_interceptor = 2 channel_interceptor.priorities.rabbit_sharding_interceptor = 3Contributed by @Ayanda-D.
GitHub issue: #17182
Shovels now support a new AMQP URI query parameter, customize_hostname_check,
that controls how the target hostname is matched against the server certificate,
for example with wildcard certificates.
Contributed by @jiangranwang.
GitHub issue: #17221
rabbitmq-diagnostics check_certificate_expiration now handles certificate files
that cannot be read, and certificates that use the RFC 5280 UTCTime format,
the same way the HTTP API health check does.
Contributed by @Vishal-770.
Two new commands, rabbitmqctl list_channel_interceptors and
rabbitmqctl set_channel_interceptor_priorities, list the active channel interceptors
and adjust their priorities at runtime. Priorities set this way are not persisted
and do not survive a node restart.
Contributed by @Ayanda-D.
GitHub issue: #17182
During a rolling upgrade, a stream metadata request could leave out a peer node
that ran a different version.
GitHub issue: #17333
The publishers and consumers listing now verifies virtual host access like
other comparable HTTP API endpoints.
The channels list and individual channel pages now display basic information
when management statistics are disabled, instead of returning a 400 Bad Request.
Several HTTP API endpoints returned a 500 instead of a 400 for invalid
range parameters or an invalid timeout header: GET /api/nodes/{node},
GET /api/healthchecks/node[/{node}], GET /api/federation-links,
GET /api/health/checks/alarms and GET /api/health/checks/local-alarms.
The certificate expiration health check no longer responds with a 500
for certificate files that cannot be read, or for certificates that use the
RFC 5280 UTCTime format.
Contributed by @Vishal-770.
Optional argument (x-*) values are no longer coerced to strings in the management UI.
GitHub issue: #17177
Consumers on protocols without channels (for example, AMQP 1.0 and MQTT)
now link directly to their connection in the management UI.
Contributed by @vampirebyte.
GitHub issue: #17206
Shovel types provided by plugins can now be used as src-protocol and dest-protocol values.
A local shovel with src-delete-after set to a number could in some cases
transfer more messages than that number.
GitHub issue: #17209
The retained message store now has per-virtual host limits on both the number of messages
and their total size: mqtt.retained_message_store.max_messages (defaults to 100000)
and mqtt.retained_message_store.max_size_bytes (defaults to 1 GiB).
GitHub issue: #17189
STOMP and Web STOMP connections now enforce credential expiry (for example, of OAuth 2 tokens)
the same way other protocols do.
GitHub issue: #17244
web_mqtt.ssl.* and web_stomp.ssl.* now accept more TLS keys in rabbitmq.conf,
including verify and fail_if_no_peer_cert.
DN escaping introduced in an earlier release was too strict for certain Active Directory
setups, for example when the client provides a full DN that contains a backslash.
Escaping is now applied to DN template values only.
Active Directory down-level logon names (DOMAIN\username) can be used to log in again.
Contributed by @jiangranwang.
GitHub issue: #17220
The trust store now also covers the HTTP API, Web MQTT
and Web STOMP listeners.
GitHub issue: #17303
A 404 response from the Consul API no longer stops node boot; peer discovery is retried instead.
cowboy was upgraded to 2.19.0cowlib was upgraded to 2.20.0gun was upgraded to 2.6.0khepri was upgraded to 0.18.1ranch was upgraded to 2.3.0RabbitMQ 4.3.0 is a new feature release.
Since only 4.2.x clusters can upgrade to 4.3.0 in place, this
won't be a breaking change for nearly all instalations but it will affect community
plugins that use Mnesia.
All partition handling-related keys in rabbitmq.conf will be
accepted by 4.3.0 nodes but won't have any effect:
cluster_partition_handlingcluster_partition_handling.pause_if_all_down.recovercluster_partition_handling.pause_if_all_down.nodes.$nameTeam RabbitMQ recommends removing the above keys from rabbitmq.conf before or shortly after upgrading.
A number of deprecated features are now disabled
by default and require the user to opt-in in order to use them.
This includes non-durable (transient) non-exclusive queues:
attempts to declare a queue with such property combination will be rejected by default.
Use durable queues, transient exclusive queues, or durable queues with a queue TTL instead.
To explicitly allow transient non-exclusive queues, make sure that
all nodes in the cluster include the following rabbitmq.conf key
and were restarted so that all nodes have a consistent view of the deprecated
feature settings:
# Enables deprecated non-durable (transient) non-exclusive queues # (disabled by default as of RabbitMQ `4.3.0`, will be removed in a later version). # # Must be effective on all cluster nodes BEFORE # the cluster is upgraded to `4.3.0`. # If only some nodes have the setting configured, it will not have the desired effect. deprecated_features.permit.transient_nonexcl_queues = trueIf only some nodes have setting configured, it will not have the desired effect.
This release removes the original classic queue storage implementation these days
known as CQv1. A 2nd generation implementation called CQv2 has been adopted
as the default starting with 4.2.0.
This means that attempts to declare a queue using the following optional queue arguments will fail:
x-queue-mode set to any valuex-queue-version set to 1Existing classic queues upgraded to CQv2 during an earlier upgrade to 4.2.x will continue
operating as usual.
This release moves consumer timeout handling responsibility into the queues
themselves. Also, all protocols (except for the stream protocol) now evaluate
consumer timeout for queue types that support them. Classic queues and streams
never evaluate consumer timeouts as their use cases largely avoid the need for
such as feature.
As of this release, Khepri is the only metadata store supported
by RabbitMQ: Mnesia was removed completely.
In practical operational terms, this means that
This release upgrades the Ra dependency to 3.x and introduces
a new (8th) version of the quorum queue state machine with several new features and optimisations:
rabbit_fifo_index usageSee the Upgrading guide for documentation on upgrades and GitHub releases
for release notes of individual releases.
This release series supports upgrades from 4.2.x. Upgrades from earlier series are not supported:
users must upgrade to the latest available 4.2.x patch release before upgrading to 4.3.0.
All feature flags introduced in 4.2.0 and earlier are required, including the following:
rabbitmq_4.2.0rabbitmq_4.1.0rabbitmq_4.0.0khepri_dbquorum_queue_non_votersmessage_containers_deaths_v2Enable all required feature flags before upgrading to 4.3.0.
If your RabbitMQ cluster had plugin rabbitmq_amqp1_0 enabled in RabbitMQ 3.13.x (and your cluster still serves AMQP 1.0 client connections in 4.x), your cluster should do at least one rolling update after enabling feature flag rabbitmq_4.0.0 but before upgrading to 4.3.0.
In 4.3.0 the deprecation phase of the following features advanced from permitted_by_default to denied_by_default:
amqp_address_v1amqp_filter_set_bugglobal_qosqueue_master_locatortransient_nonexcl_queuesAnd the deprecated feature ram_node_type has been removed.
RabbitMQ 4.3.0 nodes can run alongside 4.2.x in the same cluster.
Mixed version clusters are a mechanism that allows rolling upgrades and are not meant to be run for extended
periods of time (no more than a few hours).
This version does not require any additional post-upgrade procedures
compared to other versions.
When a message is rejected by a queue, RabbitMQ now provides the queue name and rejection reason to AMQP 1.0 publishers
in the Rejected outcome. This is particularly useful when multiple queues are bound to an exchange, as it allows
publishers to identify which specific queue out of several target queues rejected the message and why
(e.g., maximum queue length reached or queue unavailable). Previously, publishers had no way to determine which queue
rejected their message or the reason for rejection.
The queue name and reason are included in the info field of the Rejected outcome's error field:
queue: reason: maxlen | unavailableGitHub issue: #15075
Quorum queues now support strict priority queues with per-priority message counts,
correct redelivery ordering across priorities, and priority-aware message expiration scans.
GitHub issue: #13885
Quorum queues now support delayed retry with configurable backoff based on delivery count. When messages
are returned (via reject, nack, or modify), they can be held in a delayed state before becoming
available again. The delay is based on delivery count: min(min_delay * delivery_count, max_delay).
Configuration is available via queue arguments (x-delayed-retry-type, x-delayed-retry-min,
x-delayed-retry-max) or policy keys (delayed-retry-type, delayed-retry-min,
delayed-retry-max). The retry type can be set to disabled, all, failed, or returned.
GitHub issue: #13885
Quorum queues now support a configurable consumer timeout. When a consumer holds unacknowledged
messages beyond the timeout, the messages are returned to the queue. For AMQP 1.0 clients,
timed-out deliveries are released via DISPOSITION(state=released) instead of detaching the link,
allowing the consumer to recover without re-attaching. MQTT consumers are also supported.
The timeout can be set via the x-consumer-timeout consumer argument, queue argument, consumer-timeout
policy key, or the global consumer_timeout setting in rabbitmq.conf.
GitHub issue: #13885
A new consumer_disconnected_timeout setting controls how long quorum queues wait before returning
messages when a consumer's node becomes unreachable due to a network partition. The default is 60 seconds.
Configurable via consumer_disconnected_timeout in rabbitmq.conf, the consumer-disconnected-timeout
policy key, or the x-consumer-disconnected-timeout queue argument.
GitHub issue: #13885
Quorum queue recovery snapshots reduce recovery time after a member restart by avoiding
the need to replay all enqueue commands from the log.
GitHub issue: #13885
Quorum queue snapshot throttling now uses WAL fill ratio and reclaimable byte tracking
to make smarter snapshotting decisions, yielding roughly one snapshot per queue per WAL cycle
instead of excessive snapshots in shallow, fast-flowing queues.
GitHub issue: #13885
Quorum queue memory optimisations: message references now use a compact packed integer
representation ("compact" means up to 59-bit) when possible, halving per-message
memory overhead in many scenarios. The rabbit_fifo_index module is no longer used by the
main state machine.
GitHub issue: #13885
Quorum queues now allow unlimited explicit message returns. The delivery limit is based on
delivery-count rather than acquired-count, so messages can be explicitly returned to the
queue without counting towards the delivery limit.
GitHub issue: #13885
The x-modulus-hash exchange type, previously provided by the sharding plugin, was moved
into the core and reworked to provide stable message routing (distribution)
assuming a stable set of bindings, including between node restarts.
GitHub issue: #15849
When quorum queue members (replicas) are deleted from a node, either manually
via rabbitmq-queues shrink or as part of rabbitmqctl forget_cluster_node,
the members are stopped in parallel.
GitHub issue: #15081
Purging a quorum queue now also removes at-least-once dead-lettered messages that were pending delivery.
GitHub issue: #13885
AMQP 0-9-1: when a connection's credentials are refreshed, the permissions cache is now
cleared and consumer permissions are re-validated immediately
GitHub issue: #16092
Quorum queue delivery limit can now be changed via policy without queue redeclaration
GitHub issue: #16035
Khepri topic exchange routing projection (v4): replaced the internal representation with a trie
backed by an ordered_set ETS table, significantly improving routing performance
for topic exchanges with many bindings
GitHub issue: #15619
Quorum queues notify AMQP 1.0 clients of Single Active Consumer state changes
GitHub issue: #15736
More rabbitmq.conf keys now accept tagged values (e.g., encrypted:...)
GitHub issue: #15808
Startup banner no longer includes the Erlang cookie hash
GitHub issue: #16087
Optimised AMQP 1.0 message container annotation handling during modify outcomes
GitHub issue: #15743
Bulk queue delete with Khepri has been optimized
GitHub issue: #14902
Optimised quorum queue message expiry scanning
GitHub issue: #15846
AMQP 0-9-1: configure permission checks now apply to passive queue and exchange declarations,
matching the behavior of their regular counterparts
GitHub issue: #16085
Khepri snapshot interval is now configurable in rabbitmq.conf
GitHub issue: #16011
Quorum queue Raft settings: additional configuration settings are now exposed in rabbitmq.conf,
including maximum segment size
GitHub issue: #15962
If a quorum queue with a large backlog terminated abnormally, node memory
footprint could spike.
GitHub issue: #15837
rabbitmqctl forget_cluster_node now removes all quorum queue and stream members (replicas)
before proceeding to leave the metadata store cluster.
This order minimizes the risk of some replicas being left behind on the leaving node.
GitHub issue: #15729
Quorum queue at-most-once dead lettering for the overflow behaviour drop-head now happens in the correct order.
GitHub issue: #14926
Feature flag state in the registry and on disk were not consistent for a period of time during node boot.
GitHub issue: #14943
Classic queues now implement AMQP 1.0 delivery-count and first-acquirer headers properly.
GitHub issue: #15020
Quorum queues returned an incorrect consumer count in the response to a passive
queue.declare operation
GitHub issue: #16185
Classic queue shared store could leave stale index entries after segment removal or rollover,
causing unnecessary disk space usage
GitHub issue: #16142
Bindings targeting Direct Reply-to pseudo-queues are now rejected instead of
being silently accepted without any functional effect
GitHub issue: #15935
AMQP 1.0 sessions could grant too many credits in certain failure and recovery scenarios
GitHub issue: #15883
Quorum queues: acquired-count is now correctly preserved when dead-lettering
GitHub issue: #16039
AMQP 1.0: attaching with a link handle already in use on the same session is now rejected
with a handle-in-use session error, as required by the specification
GitHub issue: #16039
Quorum queues: Single Active Consumer could incorrectly report multiple active consumers
in certain timing scenarios
GitHub issue: #15733
Quorum queues: consumer timeout could fail to trigger under certain conditions
GitHub issue: #15805
The channel limit exceeded error message now correctly identifies the per-user limit
as the source of the constraint
GitHub issue: #15750
stream.read_ahead is a new setting that controls how much data is prefetched from disk
for stream reads (consumption).
GitHub issue: #14948
Stream deletion is now more resilient and can handle certain mid-deletion failure scenarios.
GitHub issue: #14852
new_stream coordinator command is now idempotent. Previously, concurrent or retried
stream declarations could produce spurious errors even though the stream was created
successfully
GitHub issue: #15706
/metrics/detailed endpoint now supports filtering queue metrics by queue name
GitHub issue: #15689
The dashboards were updated for the most recent RabbitMQ release series.
Replaced explicit rate intervals with $__rate_interval for better
compatibility across different scrape intervals
GitHub issue: #15978
GET /api/queues/{vhost} requests no longer perform unnecessary virtual host permission checks
and log less (at debug level) as a result.
GitHub issue: #14923
Quorum queue delayed retry configuration and status, per-priority message counts, and consumer
timeout state are now displayed in the management UI.
GitHub issue: #13885
GET /users/{user}/queues has been added.
GitHub issue: #15074
HTTP API displays static connection info (peer address, TLS details, auth mechanism)
even when stats collection is disabled via rabbitmq.conf
GitHub issue: #16009
effective_policy_definition in HTTP API responses now returns an empty JSON object
(not an array or empty string) when no policy applies to a queue
GitHub issue: #16017
Management UI: OAuth 2 used side by side with Basic Auth could fail to reload provider
configuration correctly
GitHub issue: #15793
Management UI: preference cookie expiry now respects the configured session timeout
setting rather than using a hardcoded value
GitHub issue: #15814
Management UI: users were presented with a 401 error after changing their own password
via the UI. The session is now refreshed automatically
GitHub issue: #15730
The deprecated, unused GET /api/auth endpoint was removed.
It has been out of use since 3.11 but never removed.
GitHub issue: #16083
POST /api/users/bulk-delete now respects the protected_users configuration,
matching the behavior of the single-user DELETE /api/users/:name endpoint
GitHub issue: #16143
For MQTT 5.0 publishers, when a message is rejected because the target queue's maximum length is exceeded,
RabbitMQ now returns a Quota exceeded reason code in the PUBACK packet. This provides publishers with
actionable information about why their message was rejected.
GitHub issue: #15075
MQTT QoS 0 queue type now reports member information in management API responses
GitHub issue: #15656
A default max_frame_size is now set on WebSocket connections, bounding decompressed frame sizes.
The limit starts at mqtt.max_packet_size_unauthenticated and is raised after successful CONNECT
GitHub issue: #16180
A login_timeout is now enforced for WebSocket connections, matching the TCP listener behavior
GitHub issue: #16120
WebSocket Origin header will be validated web_mqtt.allow_origins
GitHub issue: #16158
For certain destinations that previously used non-durable (transient) queues,
STOMP subscriptions now use exclusive queues, as non-exclusive transient queues
are a deprecated property combination disabled by default as of this release
GitHub issue: #13016
WebSocket Origin header validation is now available via web_stomp.allow_origins
GitHub issue: #16158
Federation links and their connections are now stopped in parallel.
This significantly improves shutdown time for nodes with many (into thousands) federation links.
GitHub issue: #15271
Federation links no longer restart during plugin or node shutdown.
For nodes with hundreds or thousands of federation links, link recovery could
significantly delay node shutdown.
GitHub issue: #15258
Federation link restart operations now require the policymaker tag
GitHub issue: #16051
src-consumer-name property can be specified to define the consumer tagamqp091 and local src-protocol) or link identifier (amqp10 protocol)Improved target node resource alarm handling for AMQP 1.0 and local shovels.
GitHub issue: #14886
Local shovels could run into an exception that would cause a shovel restart.
GitHub issue: #14872
AMQP 1.0 shovels ignored the sasl URI parameter.
GitHub issue: #14867
Shovel management: DELETE operations now require the policymaker tag, matching the
federation plugin counterpart
GitHub issue: #16051
A usability improvement allows the plugin to automatically load the trusted system x.509 (TLS) certificates.
GitHub issue: #14927
The auth cache backend now correctly delegates token expiry timestamps to the wrapped backend,
ensuring connections are closed when tokens expire
GitHub issue: #16100
LDAP queries, including multi-line ones, can now be specified in rabbitmq.conf.
GitHub issue: #14868
A usability improvement allows the plugin to automatically load the trusted system certificates
when the user only enables TLS for the LDAP client but does not configure any other settings.
GitHub issue: #14937
DN values are now handled per RFC 4514
GitHub issue: #16101
The HTTP Auth Backend can now optionally provide a custom authorization denial reason to AMQP clients.
To opt in, return deny (instead of only deny) in the HTTP response body of your HTTP auth backend and set the following in your rabbitmq.conf file:
auth_http.authorization_failure_disclosure = trueSee the README for more information.
GitHub issue: #14641
The x-modulus-hash exchange type, previously provided by the sharding plugin, was moved
into the core and reworked to provide stable message routing (distribution)
assuming a stable set of bindings, including between node restarts.
GitHub issue: #15849
Refactored certificate identification to avoid (unlikely) conflicts
GitHub issue: #16116
The plugin now provides CLI commands for trust store certificate management have been introduced
GitHub issue: #15746
Rejected certificates are now logged with additional diagnostic details
GitHub issue: #15889
Trace file downloads now set the charset to UTF-8 when serving trace files.
GitHub issue: #13952
ra was upgraded to 3.1.6khepri was upgraded to 0.18.0osiris was upgraded to 1.3.1gen_batch_server was upgraded to 0.9.2cuttlefish was upgraded to 3.6.0To obtain source code of the entire distribution, please download the archive named rabbitmq-server-4.3.0.tar.xz
instead of the source tarball produced by GitHub.
RabbitMQ 4.2.6 is a maintenance release in the 4.2.x release series.
It is strongly recommended that you read 4.2.0 release notes
in detail if upgrading from a version prior to 4.2.0.
RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ.
Nodes will fail to start on older Erlang releases.
Release notes can be found on GitHub at rabbitmq-server/release-notes.
Quorum queues: get_checked_out aux command could return messages in incorrect order
GitHub issue: #16008
rabbitmqctl forget_cluster_node now removes all quorum queue and stream members (replicas)
before proceeding to leave the metadata store cluster.
This order minimizes the risk of some replicas being left behind on the leaving node.
GitHub issue: #15729
The channel limit exceeded error message now correctly identifies the per-user limit
as the reason
GitHub issue: #15750
AMQP 0-9-1: configure permission checks now apply to passive queue and exchange declarations,
matching the behavior of their regular counterparts
Khepri: missing keys are now correctly distinguished from errors in certain internal operations,
avoiding spurious error-level log messages
GitHub issue: #15942
Bindings targeting Direct Reply-to pseudo-queues are now rejected instead of
being silently accepted without any functional effect
GitHub issue: #15935
More rabbitmq.conf keys now accept tagged values (e.g., encrypted:...)
GitHub issue: #15808
When quorum queue members (replicas) are deleted from a node, either manually
via rabbitmq-queues shrink or as part of rabbitmqctl forget_cluster_node,
the members are stopped in parallel
GitHub issue: #15081
AMQP 0-9-1: configure permission checks now apply to passive queue and exchange declarations,
matching the behavior of their regular counterparts
GitHub issue: #16085
AMQP 0-9-1: when a connection's credentials are refreshed, the permissions cache is now
cleared and consumer permissions are re-validated immediately
GitHub issue: #16092
effective_policy_definition in HTTP API responses now returns an empty JSON object
(not an array or empty string) when no policy applies to a queue
GitHub issue: #16017
Management UI: OAuth 2 combined with basic_auth could fail to reload provider
configuration correctly
GitHub issue: #15858
Management UI: preference cookie expiry now respects the configured session timeout
setting rather than using a hardcoded value
GitHub issue: #15814
Management UI: users were presented with a 401 error after changing their own password
via the UI. The session is now refreshed automatically
GitHub issue: #15730
The deprecated, unused GET /api/auth endpoint was removed
It has been out of use since 3.11 but never removed.
GitHub issue: #16083
POST /api/users/bulk-delete now respects the protected_users configuration,
matching the behavior of the single-user DELETE /api/users/:name endpoint
GitHub issue: #16143
Quorum queue status and stream tracking endpoints now enforce virtual host
access checks, consistent with all other vhost-scoped endpoints
GitHub issue: #16104
HTTP API displays static connection info (peer address, TLS details, auth mechanism)
even when stats collection is disabled via rabbitmq.conf
GitHub issue: #16009
Super stream creation via HTTP API now verifies configure permission, matching
the stream protocol code path
GitHub issue: #16099
Management API regex filters (?name=...&use_regex=true) now enforce match limits,
preventing pathological patterns from consuming excessive CPU time
GitHub issue: #16074
Fixed a timing-sensitive issue around Last Will message delivery and session expiration
GitHub issue: #15999
MQTT QoS 0 queue type now reports member information in management API responses
GitHub issue: #15656
A default max_frame_size is now set on WebSocket connections, bounding decompressed frame sizes.
The limit starts at mqtt.max_packet_size_unauthenticated and is raised after successful CONNECT
GitHub issue: #16180
A login_timeout is now enforced for WebSocket connections, matching the TCP listener behavior
GitHub issue: #16120
WebSocket Origin header validation is now available via web_mqtt.allow_origins
GitHub issue: #16158
A default max_frame_size is now set on WebSocket connections. A smaller pre-authentication
limit is raised after successful STOMP CONNECT, matching the Web MQTT pattern
GitHub issue: #16180
A login_timeout is now enforced for WebSocket connections, matching the TCP listener behavior
GitHub issue: #16120
WebSocket Origin header validation is now available via web_stomp.allow_origins
GitHub issue: #16158
AMQP 1.0 shovels now properly detach links when closing connections, preventing
spurious error log entries during shutdown
GitHub issue: #15603
AMQP 1.0 shovel status no longer includes full connection URIs in API responses
and CLI output
GitHub issue: #16108
DELETE operations now require the policymaker tag, matching the
federation plugin counterpart
GitHub issue: #16051
Federation link restart operations now require the policymaker tag
GitHub issue: #16051
The auth cache backend now correctly delegates token expiry timestamps to the wrapped backend,
ensuring connections are closed when tokens expire
GitHub issue: #16100
OAuth 2 management UI: improved provider configuration loading and rendering
GitHub issue: #15858
DN values are now handled per RFC 4514
GitHub issue: #16101
Refactored certificate identification to avoid (unlikely) conflicts
GitHub issue: #16116
Proper CLI commands for trust store certificate management have been introduced
GitHub issue: #15746
Rejected certificates are now logged with additional diagnostic details
GitHub issue: #15889
Binding weights above 10,000 are now rejected. Previously, extremely large weights could cause
excessive memory allocation
GitHub issue: #16118
RabbitMQ 4.3.0 is a new feature release.
Since only 4.2.x clusters can upgrade to 4.3.0 in place, this
won't be a breaking change for nearly all instalations but it will affect community
plugins that use Mnesia.
All partition handling-related keys in rabbitmq.conf will be
accepted by 4.3.0 nodes but won't have any effect:
cluster_partition_handlingcluster_partition_handling.pause_if_all_down.recovercluster_partition_handling.pause_if_all_down.nodes.$nameTeam RabbitMQ recommends removing the above keys from rabbitmq.conf before or shortly after upgrading.
A number of deprecated features are now disabled
by default and require the user to opt-in in order to use them.
This includes non-durable (transient) non-exclusive queues:
attempts to declare a queue with such property combination will be rejected by default.
Use durable queues, transient exclusive queues, or durable queues with a queue TTL instead.
To explicitly allow transient non-exclusive queues, make sure that
all nodes in the cluster include the following rabbitmq.conf key
and were restarted so that all nodes have a consistent view of the deprecated
feature settings:
# Enables deprecated non-durable (transient) non-exclusive queues # (disabled by default as of RabbitMQ `4.3.0`, will be removed in a later version). # # Must be effective on all cluster nodes BEFORE # the cluster is upgraded to `4.3.0`. # If only some nodes have the setting configured, it will not have the desired effect. deprecated_features.permit.transient_nonexcl_queues = trueIf only some nodes have setting configured, it will not have the desired effect.
This release removes the original classic queue storage implementation these days
known as CQv1. A 2nd generation implementation called CQv2 has been adopted
as the default starting with 4.2.0.
This means that attempts to declare a queue using the following optional queue arguments will fail:
x-queue-mode set to any valuex-queue-version set to 1Existing classic queues upgraded to CQv2 during an earlier upgrade to 4.2.x will continue
operating as usual.
This release moves consumer timeout handling responsibility into the queues
themselves. Also, all protocols (except for the stream protocol) now evaluate
consumer timeout for queue types that support them. Classic queues and streams
never evaluate consumer timeouts as their use cases largely avoid the need for
such as feature.
As of this release, Khepri is the only metadata store supported
by RabbitMQ: Mnesia was removed completely.
In practical operational terms, this means that
This release upgrades the Ra dependency to 3.x and introduces
a new (8th) version of the quorum queue state machine with several new features and optimisations:
rabbit_fifo_index usageSee the Upgrading guide for documentation on upgrades and GitHub releases
for release notes of individual releases.
This release series supports upgrades from 4.2.x. Upgrades from earlier series are not supported:
users must upgrade to the latest available 4.2.x patch release before upgrading to 4.3.0.
All feature flags introduced in 4.2.0 and earlier are required, including the following:
rabbitmq_4.2.0rabbitmq_4.1.0rabbitmq_4.0.0khepri_dbquorum_queue_non_votersmessage_containers_deaths_v2Enable all required feature flags before upgrading to 4.3.0.
If your RabbitMQ cluster had plugin rabbitmq_amqp1_0 enabled in RabbitMQ 3.13.x (and your cluster still serves AMQP 1.0 client connections in 4.x), your cluster should do at least one rolling update after enabling feature flag rabbitmq_4.0.0 but before upgrading to 4.3.0.
In 4.3.0 the deprecation phase of the following features advanced from permitted_by_default to denied_by_default:
amqp_address_v1amqp_filter_set_bugglobal_qosqueue_master_locatortransient_nonexcl_queuesAnd the deprecated feature ram_node_type has been removed.
RabbitMQ 4.3.0 nodes can run alongside 4.2.x in the same cluster.
Mixed version clusters are a mechanism that allows rolling upgrades and are not meant to be run for extended
periods of time (no more than a few hours).
This version does not require any additional post-upgrade procedures
compared to other versions.
When a message is rejected by a queue, RabbitMQ now provides the queue name and rejection reason to AMQP 1.0 publishers
in the Rejected outcome. This is particularly useful when multiple queues are bound to an exchange, as it allows
publishers to identify which specific queue out of several target queues rejected the message and why
(e.g., maximum queue length reached or queue unavailable). Previously, publishers had no way to determine which queue
rejected their message or the reason for rejection.
The queue name and reason are included in the info field of the Rejected outcome's error field:
queue: reason: maxlen | unavailableGitHub issue: #15075
Quorum queues now support strict priority queues with per-priority message counts,
correct redelivery ordering across priorities, and priority-aware message expiration scans.
GitHub issue: #13885
Quorum queues now support delayed retry with configurable backoff based on delivery count. When messages
are returned (via reject, nack, or modify), they can be held in a delayed state before becoming
available again. The delay is based on delivery count: min(min_delay * delivery_count, max_delay).
Configuration is available via queue arguments (x-delayed-retry-type, x-delayed-retry-min,
x-delayed-retry-max) or policy keys (delayed-retry-type, delayed-retry-min,
delayed-retry-max). The retry type can be set to disabled, all, failed, or returned.
GitHub issue: #13885
Quorum queues now support a configurable consumer timeout. When a consumer holds unacknowledged
messages beyond the timeout, the messages are returned to the queue. For AMQP 1.0 clients,
timed-out deliveries are released via DISPOSITION(state=released) instead of detaching the link,
allowing the consumer to recover without re-attaching. MQTT consumers are also supported.
The timeout can be set via the x-consumer-timeout consumer argument, queue argument, consumer-timeout
policy key, or the global consumer_timeout setting in rabbitmq.conf.
GitHub issue: #13885
A new consumer_disconnected_timeout setting controls how long quorum queues wait before returning
messages when a consumer's node becomes unreachable due to a network partition. The default is 60 seconds.
Configurable via consumer_disconnected_timeout in rabbitmq.conf, the consumer-disconnected-timeout
policy key, or the x-consumer-disconnected-timeout queue argument.
GitHub issue: #13885
Quorum queue recovery snapshots reduce recovery time after a member restart by avoiding
the need to replay all enqueue commands from the log.
GitHub issue: #13885
Quorum queue snapshot throttling now uses WAL fill ratio and reclaimable byte tracking
to make smarter snapshotting decisions, yielding roughly one snapshot per queue per WAL cycle
instead of excessive snapshots in shallow, fast-flowing queues.
GitHub issue: #13885
Quorum queue memory optimisations: message references now use a compact packed integer
representation ("compact" means up to 59-bit) when possible, halving per-message
memory overhead in many scenarios. The rabbit_fifo_index module is no longer used by the
main state machine.
GitHub issue: #13885
Quorum queues now allow unlimited explicit message returns. The delivery limit is based on
delivery-count rather than acquired-count, so messages can be explicitly returned to the
queue without counting towards the delivery limit.
GitHub issue: #13885
The x-modulus-hash exchange type, previously provided by the sharding plugin, was moved
into the core and reworked to provide stable message routing (distribution)
assuming a stable set of bindings, including between node restarts.
GitHub issue: #15849
When quorum queue members (replicas) are deleted from a node, either manually
via rabbitmq-queues shrink or as part of rabbitmqctl forget_cluster_node,
the members are stopped in parallel.
GitHub issue: #15081
Purging a quorum queue now also removes at-least-once dead-lettered messages that were pending delivery.
GitHub issue: #13885
AMQP 0-9-1: when a connection's credentials are refreshed, the permissions cache is now
cleared and consumer permissions are re-validated immediately
GitHub issue: #16092
Quorum queue delivery limit can now be changed via policy without queue redeclaration
GitHub issue: #16035
Khepri topic exchange routing projection (v4): replaced the internal representation with a trie
backed by an ordered_set ETS table, significantly improving routing performance
for topic exchanges with many bindings
GitHub issue: #15619
Quorum queues notify AMQP 1.0 clients of Single Active Consumer state changes
GitHub issue: #15736
More rabbitmq.conf keys now accept tagged values (e.g., encrypted:...)
GitHub issue: #15808
Startup banner no longer includes the Erlang cookie hash
GitHub issue: #16087
Optimised AMQP 1.0 message container annotation handling during modify outcomes
GitHub issue: #15743
Bulk queue delete with Khepri has been optimized
GitHub issue: #14902
Optimised quorum queue message expiry scanning
GitHub issue: #15846
AMQP 0-9-1: configure permission checks now apply to passive queue and exchange declarations,
matching the behavior of their regular counterparts
GitHub issue: #16085
Khepri snapshot interval is now configurable in rabbitmq.conf
GitHub issue: #16011
Quorum queue Raft settings: additional configuration settings are now exposed in rabbitmq.conf,
including maximum segment size
GitHub issue: #15962
If a quorum queue with a large backlog terminated abnormally, node memory
footprint could spike.
GitHub issue: #15837
rabbitmqctl forget_cluster_node now removes all quorum queue and stream members (replicas)
before proceeding to leave the metadata store cluster.
This order minimizes the risk of some replicas being left behind on the leaving node.
GitHub issue: #15729
Quorum queue at-most-once dead lettering for the overflow behaviour drop-head now happens in the correct order.
GitHub issue: #14926
Feature flag state in the registry and on disk were not consistent for a period of time during node boot.
GitHub issue: #14943
Classic queues now implement AMQP 1.0 delivery-count and first-acquirer headers properly.
GitHub issue: #15020
Quorum queues returned an incorrect consumer count in the response to a passive
queue.declare operation
GitHub issue: #16185
Classic queue shared store could leave stale index entries after segment removal or rollover,
causing unnecessary disk space usage
GitHub issue: #16142
Bindings targeting Direct Reply-to pseudo-queues are now rejected instead of
being silently accepted without any functional effect
GitHub issue: #15935
AMQP 1.0 sessions could grant too many credits in certain failure and recovery scenarios
GitHub issue: #15883
Quorum queues: acquired-count is now correctly preserved when dead-lettering
GitHub issue: #16039
AMQP 1.0: attaching with a link handle already in use on the same session is now rejected
with a handle-in-use session error, as required by the specification
GitHub issue: #16039
Quorum queues: Single Active Consumer could incorrectly report multiple active consumers
in certain timing scenarios
GitHub issue: #15733
Quorum queues: consumer timeout could fail to trigger under certain conditions
GitHub issue: #15805
The channel limit exceeded error message now correctly identifies the per-user limit
as the source of the constraint
GitHub issue: #15750
stream.read_ahead is a new setting that controls how much data is prefetched from disk
for stream reads (consumption).
GitHub issue: #14948
Stream deletion is now more resilient and can handle certain mid-deletion failure scenarios.
GitHub issue: #14852
new_stream coordinator command is now idempotent. Previously, concurrent or retried
stream declarations could produce spurious errors even though the stream was created
successfully
GitHub issue: #15706
/metrics/detailed endpoint now supports filtering queue metrics by queue name
GitHub issue: #15689
The dashboards were updated for the most recent RabbitMQ release series.
Replaced explicit rate intervals with $__rate_interval for better
compatibility across different scrape intervals
GitHub issue: #15978
GET /api/queues/{vhost} requests no longer perform unnecessary virtual host permission checks
and log less (at debug level) as a result.
GitHub issue: #14923
Quorum queue delayed retry configuration and status, per-priority message counts, and consumer
timeout state are now displayed in the management UI.
GitHub issue: #13885
GET /users/{user}/queues has been added.
GitHub issue: #15074
HTTP API displays static connection info (peer address, TLS details, auth mechanism)
even when stats collection is disabled via rabbitmq.conf
GitHub issue: #16009
effective_policy_definition in HTTP API responses now returns an empty JSON object
(not an array or empty string) when no policy applies to a queue
GitHub issue: #16017
Management UI: OAuth 2 used side by side with Basic Auth could fail to reload provider
configuration correctly
GitHub issue: #15793
Management UI: preference cookie expiry now respects the configured session timeout
setting rather than using a hardcoded value
GitHub issue: #15814
Management UI: users were presented with a 401 error after changing their own password
via the UI. The session is now refreshed automatically
GitHub issue: #15730
The deprecated, unused GET /api/auth endpoint was removed.
It has been out of use since 3.11 but never removed.
GitHub issue: #16083
POST /api/users/bulk-delete now respects the protected_users configuration,
matching the behavior of the single-user DELETE /api/users/:name endpoint
GitHub issue: #16143
For MQTT 5.0 publishers, when a message is rejected because the target queue's maximum length is exceeded,
RabbitMQ now returns a Quota exceeded reason code in the PUBACK packet. This provides publishers with
actionable information about why their message was rejected.
GitHub issue: #15075
MQTT QoS 0 queue type now reports member information in management API responses
GitHub issue: #15656
A default max_frame_size is now set on WebSocket connections, bounding decompressed frame sizes.
The limit starts at mqtt.max_packet_size_unauthenticated and is raised after successful CONNECT
GitHub issue: #16180
A login_timeout is now enforced for WebSocket connections, matching the TCP listener behavior
GitHub issue: #16120
WebSocket Origin header will be validated web_mqtt.allow_origins
GitHub issue: #16158
For certain destinations that previously used non-durable (transient) queues,
STOMP subscriptions now use exclusive queues, as non-exclusive transient queues
are a deprecated property combination disabled by default as of this release
GitHub issue: #13016
WebSocket Origin header validation is now available via web_stomp.allow_origins
GitHub issue: #16158
Federation links and their connections are now stopped in parallel.
This significantly improves shutdown time for nodes with many (into thousands) federation links.
GitHub issue: #15271
Federation links no longer restart during plugin or node shutdown.
For nodes with hundreds or thousands of federation links, link recovery could
significantly delay node shutdown.
GitHub issue: #15258
Federation link restart operations now require the policymaker tag
GitHub issue: #16051
src-consumer-name property can be specified to define the consumer tagamqp091 and local src-protocol) or link identifier (amqp10 protocol)Improved target node resource alarm handling for AMQP 1.0 and local shovels.
GitHub issue: #14886
Local shovels could run into an exception that would cause a shovel restart.
GitHub issue: #14872
AMQP 1.0 shovels ignored the sasl URI parameter.
GitHub issue: #14867
Shovel management: DELETE operations now require the policymaker tag, matching the
federation plugin counterpart
GitHub issue: #16051
A usability improvement allows the plugin to automatically load the trusted system x.509 (TLS) certificates.
GitHub issue: #14927
The auth cache backend now correctly delegates token expiry timestamps to the wrapped backend,
ensuring connections are closed when tokens expire
GitHub issue: #16100
LDAP queries, including multi-line ones, can now be specified in rabbitmq.conf.
GitHub issue: #14868
A usability improvement allows the plugin to automatically load the trusted system certificates
when the user only enables TLS for the LDAP client but does not configure any other settings.
GitHub issue: #14937
DN values are now handled per RFC 4514
GitHub issue: #16101
The HTTP Auth Backend can now optionally provide a custom authorization denial reason to AMQP clients.
To opt in, return deny (instead of only deny) in the HTTP response body of your HTTP auth backend and set the following in your rabbitmq.conf file:
auth_http.authorization_failure_disclosure = trueSee the README for more information.
GitHub issue: #14641
The x-modulus-hash exchange type, previously provided by the sharding plugin, was moved
into the core and reworked to provide stable message routing (distribution)
assuming a stable set of bindings, including between node restarts.
GitHub issue: #15849
Refactored certificate identification to avoid (unlikely) conflicts
GitHub issue: #16116
The plugin now provides CLI commands for trust store certificate management have been introduced
GitHub issue: #15746
Rejected certificates are now logged with additional diagnostic details
GitHub issue: #15889
Trace file downloads now set the charset to UTF-8 when serving trace files.
GitHub issue: #13952
ra was upgraded to 3.1.6khepri was upgraded to 0.18.0osiris was upgraded to 1.3.1gen_batch_server was upgraded to 0.9.2cuttlefish was upgraded to 3.6.0To obtain source code of the entire distribution, please download the archive named rabbitmq-server-4.3.0.tar.xz
instead of the source tarball produced by GitHub.