tag:github.com,2008:https://github.com/redis/redis/releasesRelease notes from redis2026-09-28T07:34:42Ztag:github.com,2008:Repository/156018/8.12-m02-int2026-09-28T07:34:42Z8.12-m02-int: Explain a test [TIMEOUT] instead of killing it silently (#15879)<p>A hung test run tells us almost nothing today. When no client has made<br>
progress for --timeout seconds, test_server_cron prints the clients'<br>
last reported state, SIGKILLs every server via force_kill_all_servers<br>
and exits; --dump-logs only fires for a failed or excepted test, never<br>
for a timeout. So a 20-minute hang costs a whole CI run and produces a<br>
few lines.</p>
<p>Collect the evidence before tearing the run down:</p>
<p>Crash-report the surviving servers. SIGSEGV makes redis log a stack<br>
trace of every one of its threads plus INFO, the client list and the<br>
config (printCrashReport) and then die. The handler runs on whichever<br>
thread takes the signal, so it works on a server whose event loop is<br>
wedged -- exactly the case we cannot diagnose from outside. kill_server<br>
already resorts to SIGSEGV for the same reason when a server won't exit,<br>
but the timeout path never reaches it. Then print each server's crash<br>
report, starting 10 lines above "REDIS BUG REPORT START" for context (or<br>
the log's tail if there is no report, since that is then the only<br>
evidence). Servers are children of the stuck client, which isn't reaping<br>
them, so a dead one is a zombie that kill -0 still reports alive; wait<br>
on is_running (via ps) instead.</p>
<p>Report where in the test each client stopped, not just its last state.<br>
Crash-reporting the servers usually unblocks a client by itself -- its<br>
connection dies, the error unwinds, and the client's existing top-level<br>
handler reports $::errorInfo, a Tcl stack trace naming the exact line --<br>
so collect that first. A client stuck on something else is poked with<br>
SIGUSR1, which it turns into a Tcl error with Tclx's "signal error":<br>
that interrupts a blocking read, a long "after" and a polling loop<br>
alike. Tclx is optional; without it a timeout simply reports no client<br>
stack trace.</p>
<p>Order matters here: the servers must be collected first, because<br>
unblocking a client makes start_server kill the very servers we wanted a<br>
report from.</p>
<p>Also: read_from_test_client threw "expected non-negative integer" once a<br>
reporting client exited, because we now pump the event loop while it<br>
does.</p>
<hr>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-info mr-2" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p><p><strong>Low Risk</strong><br>
Changes are limited to the Tcl test harness timeout path; no<br>
production server or runtime behavior is affected.</p>
<p><strong>Overview</strong><br>
When the suite hits <strong><code>--timeout</code></strong> (no client progress), it no longer<br>
tears down immediately after printing each client’s last task. The test<br>
server <strong>collects diagnostics first</strong>, then kills clients and servers as<br>
before.</p>
<p><strong>Server evidence:</strong> Still-running Redis instances from<br>
<code>::active_servers</code> get <strong>SIGCONT</strong> (if stopped) and <strong>SIGSEGV</strong> so they<br>
write a full crash report even when the event loop is wedged. Logs are<br>
located under <code>tests/tmp</code> by pid, then <strong><code>dump_crash_report</code></strong> prints<br>
the tail around <code>REDIS BUG REPORT START</code> (or the last 256KB if there is<br>
no report). <strong><code>is_running</code></strong> treats zombies as dead so waits don’t hang<br>
on unreaped children.</p>
<p><strong>Client evidence:</strong> Clients send their OS pid on <code>ready</code> and<br>
optionally advertise <strong><code>sigusr1-trace</code></strong> when Tclx is available. After<br>
server dumps, the server waits briefly for natural <strong><code>exception</code></strong>/<code>err</code><br>
unwinds, then sends <strong>SIGUSR1</strong> to remaining clients so Tclx turns it<br>
into a stack trace. <strong><code>::in_timeout_report</code></strong> suppresses re-entrant<br>
timeout cron, avoids fatal handling of those packets, and fixes<br>
<strong><code>read_from_test_client</code></strong> when a client disconnects mid-report<br>
(invalid length no longer spins or crashes the handler).</p>
<p><strong>Order:</strong> Server crash collection runs <strong>before</strong> client stack traces<br>
so unblocking a client doesn’t tear down servers before their reports<br>
are captured.</p>
<p><sup>Reviewed by <a href="https://cursor.com/bugbot" rel="nofollow">Cursor Bugbot</a> for commit<br>
<a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/redis/redis/commit/5927e7e9149ac45b2adea623ca4c4f0f4d570df6/hovercard" href="https://github.com/redis/redis/commit/5927e7e9149ac45b2adea623ca4c4f0f4d570df6"><tt>5927e7e</tt></a>. Bugbot is set up for automated<br>
code reviews on this repo. Configure<br>
<a href="https://www.cursor.com/dashboard/bugbot" rel="nofollow">here</a>.</sup></p>
</div>
<hr>
<p>Co-authored-by: Claude Opus 5.5 (1M context) <a href="mailto:noreply@anthropic.com">noreply@anthropic.com</a></p>oranagratag:github.com,2008:Repository/156018/8.10.22026-09-17T15:08:27Z8.10.2<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p>
<h3>Security fixes</h3>
<ul>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li>
<li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li>
<li>RedisSearch: KNN queries on indexes with very long vector field names could cause the server to crash</li>
<li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li>
</ul>sundbtag:github.com,2008:Repository/156018/8.8.32026-09-17T15:04:35Z8.8.3<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p>
<h3>Security fixes</h3>
<ul>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li>
<li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li>
<li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li>
</ul>sundbtag:github.com,2008:Repository/156018/8.6.72026-09-17T15:01:42Z8.6.7<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p>
<h3>Security fixes</h3>
<ul>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li>
<li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li>
<li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li>
</ul>sundbtag:github.com,2008:Repository/156018/8.4.72026-09-17T14:58:05Z8.4.7<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p>
<h3>Security fixes</h3>
<ul>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5180522741" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15673" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15673/hovercard" href="https://github.com/redis/redis/pull/15673">#15673</a> Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li>
<li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li>
<li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li>
</ul>sundbtag:github.com,2008:Repository/156018/8.2.102026-09-17T14:53:52Z8.2.10<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p>
<h3>Security fixes</h3>
<ul>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5280467408" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15722" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15722/hovercard" href="https://github.com/redis/redis/pull/15722">#15722</a> The cluster bus protocol has no authentication of its own unless <code>tls-cluster</code> is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new <code>cluster-bus-port-protected-mode</code> option (default <code>no</code>) makes refusing to run in that state an explicit choice: set it to <code>yes</code> and the node starts only when <code>tls-cluster</code> authenticates the bus</li>
<li>TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload</li>
<li>Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash</li>
</ul>sundbtag:github.com,2008:Repository/156018/8.12-m01-int2026-09-15T07:51:32Z8.12-m01-int: Add aof_cmd_duration estimate for AOF reload RTO visibility<p>Expose a best-effort AOF replay-time estimate in INFO persistence so<br>
operators can gauge reload RTO. Count time only for writes that enter<br>
the AOF, credit leftover call() time to synthetic rewrites, and skip<br>
the bookkeeping when AOF is off.</p>yinon-bittag:github.com,2008:Repository/156018/8.10.12026-08-17T16:46:02Z8.10.1<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p>
<h3>Security fixes</h3>
<ul>
<li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li>
<li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li>
<li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li>
<li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li>
<li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li>
<li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li>
<li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li>
<li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li>
</ul>YaacovHazantag:github.com,2008:Repository/156018/8.8.22026-08-17T16:41:01Z8.8.2<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p>
<h3>Security fixes</h3>
<ul>
<li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li>
<li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li>
<li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4910514260" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15478/hovercard" href="https://github.com/redis/redis/pull/15478">#15478</a> ACL key permission bypass in <code>SORT</code>, <code>GEORADIUS</code>/<code>GEORADIUSBYMEMBER</code> and <code>XREAD</code>/<code>XREADGROUP</code>: the keys validated by ACL could differ from the keys the command actually accesses</li>
<li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li>
<li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li>
<li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li>
<li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li>
<li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li>
</ul>YaacovHazantag:github.com,2008:Repository/156018/8.6.62026-08-17T16:39:37Z8.6.6<p>Update urgency: <code>SECURITY</code>: There are security fixes in the release.</p>
<h3>Security fixes</h3>
<ul>
<li>(CVE-2026-62356) Miscalculated buffer size in <code>CMSketch</code> RDB loading may lead to heap OOB write</li>
<li>Out-of-bounds access in TopK heap cleanup path (MOD-15410)</li>
<li>Use-after-free in the TLS pending-data list when a command closes another pending connection</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4910514260" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15478/hovercard" href="https://github.com/redis/redis/pull/15478">#15478</a> ACL key permission bypass in <code>SORT</code>, <code>GEORADIUS</code>/<code>GEORADIUSBYMEMBER</code> and <code>XREAD</code>/<code>XREADGROUP</code>: the keys validated by ACL could differ from the keys the command actually accesses</li>
<li>A malicious RDB payload with an out-of-range <code>SLOT_INFO</code> slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution</li>
<li>Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access</li>
<li>Vector Sets: use-after-free when <code>VREM</code> mutates the HNSW graph while background <code>VSIM</code> threads are still running</li>
<li>Vector Sets: a negative <code>hnsw_search()</code> return was treated as a huge unsigned count, reading past the end of the result arrays</li>
<li>TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070817913" data-permission-text="Title is private" data-url="https://github.com/redis/redis/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/redis/redis/pull/15594/hovercard" href="https://github.com/redis/redis/pull/15594">#15594</a> Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key</li>
</ul>YaacovHazan