postgresql: the script for verifying/updating collation versions on service
start now works correctly with special database names that need "quoting"
in SQL statements (PL-133030).
webproxy: The default.vcl configuration mechanism for varnish is here to
stay. We decided to un-deprecate this as it is useful and we will be
integrating it with the newer mechanism in the near future (PL-132174).
This platform release includes a very new Linux kernel release (6.11) that
gets activated in our DEV and WHQ locations as well as on all
non-production VMs. Selected production VMs will be updated as well .
However, customers affected by this on a production VM will be notified
individually with an in-depth briefing. This Linux release includes a fix
for a bug that has been stopping us from updating past the 5.15 LTS branch
since last year – but 5.15 is considered ancient by now. The upstream
developers are confident that this release fixes the bug and will provide a
backport to an LTS release at a later point. However, due to the shy nature
of the bug our part in fixing it is to help gather evidence that this bug
does not reappear. We expect to be running this for at least 4-8 weeks for
valid evidence (PL-132972).
Pull upstream NixOS changes, security fixes and package updates (PL-133043):
asterisk: 20.9.2 -> 20.9.3
cacert: 3.101 -> 3.104
calibre: add patches for CVE-2024-6781, CVE-2024-6782, CVE-2024-7008, CVE-2024-7009
The default.vcl configuration mechanism for varnish is here to stay. We
decided to un-deprecate this as it is useful and we will be integrating
it with the newer mechanism in the near future. (PL-132174)