-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
5.6.10 release notes #594
5.6.10 release notes #594
Conversation
docs/release_notes_128t_5.6.md
Outdated
|
||
- **The following CVE's have been identified and addressed in this release:** I95-51758, I95-52495, I95-52497, I95-52509. | ||
------ | ||
- **I95-51336 App-ID stats entry leaked in some session building exceptions:** Resolved an issue where the `app-id stats` entry was not added to the `Expiring` list to be cleaned up. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
While the Jira talks about "stats entries are being leaked", this really amount to a memory leak.
I95-51336 App-ID memory leak for some uncommon cases, such a duplicate flow: Resolved an issue where the app-id stats
entry was not added to the Expiring
list to be cleaned up.
docs/release_notes_128t_5.6.md
Outdated
------ | ||
- **I95-51800 Radius authentication failure - Incorrect NAS IP address:** The ability to specify the NAS-IP-Address and NAS-Identifier has been added to the data model for configuring these Radius options per node. This can be used in cases where the Radius server is configured to use an identifier, or in cases where it is necessary to match the source IP address of the Radius requests behind SSR or NAT. | ||
------ | ||
- **I9552208 Queries return incomplete data with FIPS enabled:** Resolved an issue where a FIPS-incompatible hashing function was causing missing or incomplete metrics data. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What queries? Also, missing hyphen
**I95-52208 metrics queries return incomplete data when FIPS is enabled: Resolved an issue where a FIPS-incompatible hashing function was causing missing or incomplete metrics data.
docs/release_notes_128t_5.6.md
Outdated
- **The following CVE's have been identified and addressed in this release:** I95-51758, I95-52495, I95-52497, I95-52509. | ||
- **The following CVE's have been identified and addressed in this release:** I95-51758, I95-52495, I95-52496, I95-52497, I95-52509, I95-52625. | ||
------ | ||
- **I95-41386/I95-52114 HA pair device interface's redundancy status stays non-redundant even though the interface operational status is up:** Resolved an issue where zookeepper enters a leaderless state when a disconnection occurs right after an electorate ephemeral node is created, and before running a success callback. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Suggested rewording
- I95-41386/I95-52114 HA pair device interface's redundancy status stays non-redundant even though the interface operational status is up after both nodes simultaneously come online, as in the case of power failures: Resolved a race condition where zookeepper enters a leaderless state when a disconnection occurs right after an electorate ephemeral node is created, and before running a success callback.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- "zookeeper" is misspelled as "zookeepper" in both the original and your rewording.
- Do these internal details about zookeeper and such really mean anything to customers?
docs/release_notes_128t_5.6.md
Outdated
------ | ||
- **I95-52626 Forwarding plane control message bursts create exception, causing a packet buffer leak:** Resolved a condition where backpressure from fastlane caused the messaging mechanism between highway manager and fastlane to drop mbufs. Proper handling of exception now prevents buffer leaks. Additionally, increased the control buffer capacity to better handle bursts as part of the resolution. | ||
------ | ||
- **I95-52650 Create a cache of the common file root hash calculation:** An optimization was made to an internal calculation and improve the speed at which synchronization requests are processed. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Suggested rewording:
- I95-52650 Asset state transition on conductor is slow for deployments with greater than 250 routers: An optimization was made to an internal calculation and improve the speed at which synchronization requests are processed.
docs/release_notes_128t_5.6.md
Outdated
|
||
### New Features | ||
|
||
- **I95-52198 Handle incoming public keys from peer conductor node:** Added functionality to allow conductor nodes to share the authorized keys of managed routers between each other. If the SSH public key is retrieved from a managed router by one conductor node then it will be automatically shared with it's conductor peer node. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
the word "it's" at the end of the paragraph should be "its".
docs/release_notes_128t_5.6.md
Outdated
------ | ||
- **I95-52402 Router stuck in `Upgrading` state:** Resolved an issue with `conductor-only` mode, where the conductor was attempting to download the installer before the software access proxies were in place, preventing an update to the installer. | ||
------ | ||
- **I95-52626 Forwarding plane control message bursts create exception, causing a packet buffer leak:** Resolved a condition where backpressure from fastlane caused the messaging mechanism between highway manager and fastlane to drop mbufs. Proper handling of exception now prevents buffer leaks. Additionally, increased the control buffer capacity to better handle bursts as part of the resolution. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
again, I'm not sure we should be documenting this level of internal details, which are not meaningful to customers.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Still need to make requested changes.
… Added the Configuration Command Guide, a generated file listing all the configuration pcli commands. This is a complete listing of all the config commands.
docs/release_notes_128t_5.6.md
Outdated
|
||
- **The following CVE's have been identified and addressed in this release:** I95-51758, I95-52495, I95-52496, I95-52497, I95-52509, I95-52625. | ||
------ | ||
- **I95-41386/I95-52114 HA pair device interface's redundancy status stays non-redundant even though the interface operational status is up:** Resolved a race condition where a disconnection occurs right after an electorate ephemeral node is created, and before running a success callback. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This resolution isn't meaningful to customers; I suggest it be:
"Resolved a race condition when selecting the active components between HA nodes."
docs/release_notes_128t_5.6.md
Outdated
------ | ||
- **I95-52305 Compacting rate limit exceeded:** Resolved memory and CPU issues resulting from attempting to compact very large application identification documents. | ||
------ | ||
- **I95-52316 Enhancements to Overlapping FIB Services:** When creating FIB entries, we now consider services that match the route update but do not have the best match service address. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I believe this requires setting an authority-wide configuration knob, no?
docs/release_notes_128t_5.6.md
Outdated
------ | ||
- **I95-52402 Router stuck in `Upgrading` state:** Resolved an issue with `conductor-only` mode, where the conductor was attempting to download the installer before the software access proxies were in place, preventing an update to the installer. | ||
------ | ||
- **I95-52626 Forwarding plane control message bursts create exception, causing a packet buffer leak:** Resolved a condition where backpressure caused the messaging mechanism to develop buffer leaks. Proper handling of exceptions now prevents buffer leaks. Additionally, increased the control buffer capacity to better handle bursts as part of the resolution. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would remove the "Additionally, ..." last sentence.
@@ -275,6 +275,7 @@ module.exports = { | |||
], | |||
"CLI and Element Reference": [ | |||
"cli_reference", | |||
"config_command_guide", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This was missing before? Secret file?
No description provided.