NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2673 most downloaded on PyPI
Highly-optimized, pure-python HTTP server
Last release 11 months ago
07 Nov 2025
Release timing varies
gaps range from 8 days to 1.4 years
Nearly every release is documented
notes for 60 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
13 years old
82 releases · first in 2014
📦 PyPI page: https://pypi.org/project/cheroot/11.1.2
📦 PyPI page: https://pypi.org/project/cheroot/11.1.2
🌱 v11.1.2 is marked as a stable release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/19175006509
(2025-11-07)
The "service unavailable" thread is now turn down properly when the
server is shut down -- by @itamarst.
This fixes a regression in Cheroot originally introduced in v11.0.0
that would manifest itself under Python 3.12 and older. In certain
conditions like under CherryPy, it would also lead to hangs on
tear-down.
One column per quarter.
📦 PyPI page: https://pypi.org/project/cheroot/11.1.1
📦 PyPI page: https://pypi.org/project/cheroot/11.1.1
🌱 v11.1.1 is marked as a stable release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/19050434787
(2025-11-03)
The packaging configuration has been fixed to ensure that only
cheroot package will be installed into site-packages/ -- by
@webknjaz.
This fixes a regression introduced in version 11.1.0.
Related issues and pull requests on GitHub: #790.
Related commits on GitHub:
d286d1a.
📦 PyPI page: https://pypi.org/project/cheroot/11.1.0
📦 PyPI page: https://pypi.org/project/cheroot/11.1.0
🌱 v11.1.0 is marked as a stable release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/19020536310
(2025-11-03)
Added optional private key password argument to SSL adapters to
support password-protected private keys -- by @jatalahd.
Related issues and pull requests on GitHub: #752.
Added missing __all__ and IS_WINDOWS definitions to .pyi stub
files for mypy.
-- by @julianz-
Related issues and pull requests on GitHub: #774.
Made test_http_over_https_error compatible with Solaris -- by
@mtelka.
Related issues and pull requests on GitHub: #776.
Increased timeout values test_client.server_instance.timeout and
http_request_timeout to make related tests more stable.
Related issues and pull requests on GitHub: #777.
(2025-11-03)
Added optional private key password argument to SSL adapters to support password-protected private keys -- by jatalahd.
Related issues and pull requests on GitHub: 752.
Added missing __all__ and IS_WINDOWS definitions to .pyi stub files for mypy.
-- by julianz-
Related issues and pull requests on GitHub: 774.
Made test_http_over_https_error compatible with Solaris -- by mtelka.
Related issues and pull requests on GitHub: 776.
Increased timeout values test_client.server_instance.timeout and http_request_timeout to make related tests more stable.
Related issues and pull requests on GitHub: 777.
Removals and backward incompatible breaking changes
📦 PyPI page: https://pypi.org/project/cheroot/11.0.0
🌱 v11.0.0 is marked as a stable release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/17894178348
(2025-09-21)
When load is too high, Cheroot now responds with a 503 Service
Unavailable HTTP error. Previously it silently closed the connection.
-- by @itamarst
Related issues and pull requests on GitHub: #745.
Cheroot dropped support for Python 3.6 and 3.7. It now requires Python
3.8 or later.
-- by @jaraco
Related issues and pull requests on GitHub: #565, #633.
Related commits on GitHub:
437863ee.
Declared Python 3.12 and Python 3.13 as supported officially -- by
@webknjaz.
Related issues and pull requests on GitHub: #696.
Related commits on GitHub:
5db4f634.
The minimum version of the setuptools-scm build dependency has been
set to 7. The Git archives are now produced by it natively, instead of
relying on a third party plugin which is no longer being used.
-- by @serhii73
Related issues and pull requests on GitHub: #628.
The packaging metadata has been migrated to the pyproject.toml-based
621 declaration -- by @jaraco and @webknjaz.
As a part of this update, the minimum version of the setuptools
build backend was bumped to 61.2. Moreover, any compatibility shims
that existed in setup.cfg and setup.py have been removed for good.
Related issues and pull requests on GitHub: #690.
The test infrastructure has been updated to stop using the
pytest-forked plugin -- by @jaraco and @webknjaz.
This plugin was causing problems with upgrading to modern versions of
Pytest and it is not going to be fixed anytime soon.
It was used in a test that interacts with the system resource limits
under *NIX environments in hopes to isolate the side effects caused
by the preparatory code.
It is possible that this will have an effect on the test sessions and
we may have to look for alternative solutions for test process
isolation.
Related issues and pull requests on GitHub: #502, #511, #680,
#681, #703.
The test infrastructure has been updated to start using the upstream
reusable workflow reusable-tox.yml from tox-dev/workflow -- by
@webknjaz.
This chance allows us to de-duplicate the commonly used CI shape.
Related issues and pull requests on GitHub: #743.
Removals and backward incompatible breaking changes
📦 PyPI page: https://pypi.org/project/cheroot/11.0.0rc1
🚧 v11.0.0rc1 is marked as a pre-release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/17892222955
(2025-09-21)
When load is too high, Cheroot now responds with a 503 Service
Unavailable HTTP error. Previously it silently closed the connection.
-- by @itamarst
Related issues and pull requests on GitHub: #745.
Cheroot dropped support for Python 3.6 and 3.7. It now requires Python
3.8 or later.
-- by @jaraco
Related issues and pull requests on GitHub: #565, #633.
Related commits on GitHub:
437863ee.
Declared Python 3.12 and Python 3.13 as supported officially -- by
@webknjaz.
Related issues and pull requests on GitHub: #696.
Related commits on GitHub:
5db4f634.
The minimum version of the setuptools-scm build dependency has been
set to 7. The Git archives are now produced by it natively, instead of
relying on a third party plugin which is no longer being used.
-- by @serhii73
Related issues and pull requests on GitHub: #628.
The packaging metadata has been migrated to the pyproject.toml-based
621 declaration -- by @jaraco and @webknjaz.
As a part of this update, the minimum version of the setuptools
build backend was bumped to 61.2. Moreover, any compatibility shims
that existed in setup.cfg and setup.py have been removed for good.
Related issues and pull requests on GitHub: #690.
The test infrastructure has been updated to stop using the
pytest-forked plugin -- by @jaraco and @webknjaz.
This plugin was causing problems with upgrading to modern versions of
Pytest and it is not going to be fixed anytime soon.
It was used in a test that interacts with the system resource limits
under *NIX environments in hopes to isolate the side effects caused
by the preparatory code.
It is possible that this will have an effect on the test sessions and
we may have to look for alternative solutions for test process
isolation.
Related issues and pull requests on GitHub: #502, #511, #680,
#681, #703.
The test infrastructure has been updated to start using the upstream
reusable workflow reusable-tox.yml from tox-dev/workflow -- by
@webknjaz.
This chance allows us to de-duplicate the commonly used CI shape.
Related issues and pull requests on GitHub: #743.
Removals and backward incompatible breaking changes
📦 PyPI page: https://pypi.org/project/cheroot/11.0.0rc0
🚧 v11.0.0rc0 is marked as a pre-release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/8713203309
(2024-04-16)
Fixed a flaw where internally unhandled exceptions could crash the
worker threads and eventually starve the server of its processing
resources. It is no longer and issue and the unhandled errors are
now logged and suppressed except for a few expected exceptions that
are used for normal interruption requests.
-- by @cameronbrunner and @webknjaz
Related issues and pull requests on GitHub: #310, #346, #354,
#358, #365, #375, #599, #641, #649.
Fixed compatibility with Python 3.8 in the built-in TLS adapter that
relies on :pypython:ssl.
Modern Python versions communicate specialized exceptions
:pyssl.SSLEOFError and :pyssl.SSLZeroReturnError where the older
versions errored out in a very generic way.
Cheroot dropped support for Python 3.6 and 3.7. It now requires
Python 3.8 or later.
-- by @jaraco
Started signing the package distribution artifacts in CI/CD with
Sigstore and uploading them to GitHub Releases -- by @webknjaz.
The minimum version of the setuptools-scm build dependency has
been set to 7. The Git archives are now produced by it natively,
instead of relying on a third party plugin which is no longer being
used.
-- by @serhii73
Related issues and pull requests on GitHub: #628.
The changelog management is now implemented through the
:stdTowncrier <towncrier:index> tool -- by @webknjaz.
The contributors are now expected to :stdinclude change log fragment files in their pull requests <adding change notes with your prs>.
These news snippets can link one or more issues or pull requests,
and be of one or more of the following categories:
bugfix: A bug fix for something we deemed an improperfeature: A new behavior, public APIs. That sort of stuff.deprecation: A declaration of future API removals and breakingbreaking: When something public gets removed in a breakingdoc: Notable updates to the documentation structure or buildpackaging: Notes for downstreams about unobvious side effectscontrib: Stuff that affects the contributor experience. e.g.misc: Changes that are hard to assign to any of the aboveRelated issues and pull requests on GitHub: #654.
Started type-checking the project with MyPy against a range of
versions instead of just one — Python 3.8–3.12 -- by @webknjaz.
The project how has a .git-blame-ignore-revs letting GitHub know
which auto-formatting revisions to ignore. It is also possible to
integrate it locally, if one wants to do so.
-- by @webknjaz
The project adopted the autopep8 tool to assist with automatic
code formatting. It is chosen over black because it is less
intrusive which is important to the maintainer as it promotes
inclusivity. autopep8 is integrated into the pre-commit check
runner and is configured to only correct 8 violations, avoiding
changes to compliant snippets.
-- by @webknjaz
Related commits on GitHub:
65ba7e69.
The continuous integration and pull request merges have been set up
to only merge pull requests through merge queues -- by @webknjaz.
Related commits on GitHub:
a7149e0c.
Documented the upgraded :stdrelease process <contributing/release_guide> -- by @webknjaz.
Related commits on GitHub:
df0d1a08.
The changelog management is now implemented through the
:stdTowncrier <towncrier:index> tool -- by @webknjaz.
The contributors are now expected to :stdinclude change log fragment files in their pull requests <adding change notes with your prs>.
These news snippets can link one or more issues or pull requests,
and be of one or more of the following categories:
bugfix: A bug fix for something we deemed an improperfeature: A new behavior, public APIs. That sort of stuff.deprecation: A declaration of future API removals and breakingbreaking: When something public gets removed in a breakingdoc: Notable updates to the documentation structure or buildpackaging: Notes for downstreams about unobvious side effectscontrib: Stuff that affects the contributor experience. e.g.misc: Changes that are hard to assign to any of the aboveRelated issues and pull requests on GitHub: #654.
Removals and backward incompatible breaking changes
📦 PyPI page: https://pypi.org/project/cheroot/11.0.0b3
🚧 v11.0.0b3 is marked as a pre-release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/8623097213
(2024-04-09)
Cheroot requires Python 3.8 or later.
Related issues and pull requests on GitHub: #565.
Nothing published for this version
Removals and backward incompatible breaking changes
📦 PyPI page: https://pypi.org/project/cheroot/11.0.0b1
🚧 v11.0.0b1 is marked as a pre-release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/8615981862
(2024-04-09)
Cheroot requires Python 3.8 or later.
Related issues and pull requests on GitHub: #565.
📦 PyPI page: https://pypi.org/project/cheroot/11.0.0b0
📦 PyPI page: https://pypi.org/project/cheroot/11.0.0b0
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/8608000378
(2024-04-08)
Cheroot requires Python 3.8 or later.
Related issues and pull requests on GitHub: #565.
deprecation : A declaration of future API removals and breaking changes in behavior.
📦 PyPI page: https://pypi.org/project/cheroot/10.0.1
🌱 v10.0.1 is marked as a stable release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/8786461123
(2024-04-22)
Fixed a flaw where internally unhandled exceptions could crash the
worker threads and eventually starve the server of its processing
resources. It is no longer and issue and the unhandled errors are
now logged and suppressed except for a few expected exceptions that
are used for normal interruption requests.
-- by @cameronbrunner and @webknjaz
Related issues and pull requests on GitHub: #310, #346, #354,
#358, #365, #375, #599, #641, #649.
Fixed compatibility with Python 3.8 in the built-in TLS adapter that
relies on :pypython:ssl.
Modern Python versions communicate specialized exceptions
:pyssl.SSLEOFError and :pyssl.SSLZeroReturnError where the older
versions errored out in a very generic way.
Started signing the package distribution artifacts in CI/CD with
Sigstore and uploading them to GitHub Releases -- by @webknjaz.
The changelog management is now implemented through the
:stdTowncrier <towncrier:index> tool -- by @webknjaz.
The contributors are now expected to :stdinclude change log fragment files in their pull requests <adding change notes with your prs>.
These news snippets can link one or more issues or pull requests,
and be of one or more of the following categories:
bugfix: A bug fix for something we deemed an improperfeature: A new behavior, public APIs. That sort of stuff.deprecation: A declaration of future API removals and breakingbreaking: When something public gets removed in a breakingdoc: Notable updates to the documentation structure or buildpackaging: Notes for downstreams about unobvious side effectscontrib: Stuff that affects the contributor experience. e.g.misc: Changes that are hard to assign to any of the aboveRelated issues and pull requests on GitHub: #654.
Started type-checking the project with MyPy against a range of
versions instead of just one — Python 3.8–3.12 -- by @webknjaz.
The project how has a .git-blame-ignore-revs letting GitHub know
which auto-formatting revisions to ignore. It is also possible to
integrate it locally, if one wants to do so.
-- by @webknjaz
The project adopted the autopep8 tool to assist with automatic
code formatting. It is chosen over black because it is less
intrusive which is important to the maintainer as it promotes
inclusivity. autopep8 is integrated into the pre-commit check
runner and is configured to only correct 8 violations, avoiding
changes to compliant snippets.
-- by @webknjaz
Related commits on GitHub:
65ba7e69.
The continuous integration and pull request merges have been set up
to only merge pull requests through merge queues -- by @webknjaz.
Related commits on GitHub:
a7149e0c.
Documented the upgraded :stdrelease process <contributing/release_guide> -- by @webknjaz.
Related commits on GitHub:
df0d1a08.
The changelog management is now implemented through the
:stdTowncrier <towncrier:index> tool -- by @webknjaz.
The contributors are now expected to :stdinclude change log fragment files in their pull requests <adding change notes with your prs>.
These news snippets can link one or more issues or pull requests,
and be of one or more of the following categories:
bugfix: A bug fix for something we deemed an improperfeature: A new behavior, public APIs. That sort of stuff.deprecation: A declaration of future API removals and breakingbreaking: When something public gets removed in a breakingdoc: Notable updates to the documentation structure or buildpackaging: Notes for downstreams about unobvious side effectscontrib: Stuff that affects the contributor experience. e.g.misc: Changes that are hard to assign to any of the aboveRelated issues and pull requests on GitHub: #654.
deprecation : A declaration of future API removals and breaking changes in behavior.
📦 PyPI page: https://pypi.org/project/cheroot/10.0.1rc0
🚧 v10.0.1rc0 is marked as a pre-release.
🔗 This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/8725529391
(2024-04-17)
Fixed a flaw where internally unhandled exceptions could crash the
worker threads and eventually starve the server of its processing
resources. It is no longer and issue and the unhandled errors are
now logged and suppressed except for a few expected exceptions that
are used for normal interruption requests.
-- by @cameronbrunner and @webknjaz
Related issues and pull requests on GitHub: #310, #346, #354,
#358, #365, #375, #599, #641, #649.
Fixed compatibility with Python 3.8 in the built-in TLS adapter that
relies on :pypython:ssl.
Modern Python versions communicate specialized exceptions
:pyssl.SSLEOFError and :pyssl.SSLZeroReturnError where the older
versions errored out in a very generic way.
Started signing the package distribution artifacts in CI/CD with
Sigstore and uploading them to GitHub Releases -- by @webknjaz.
The changelog management is now implemented through the
:stdTowncrier <towncrier:index> tool -- by @webknjaz.
The contributors are now expected to :stdinclude change log fragment files in their pull requests <adding change notes with your prs>.
These news snippets can link one or more issues or pull requests,
and be of one or more of the following categories:
bugfix: A bug fix for something we deemed an improperfeature: A new behavior, public APIs. That sort of stuff.deprecation: A declaration of future API removals and breakingbreaking: When something public gets removed in a breakingdoc: Notable updates to the documentation structure or buildpackaging: Notes for downstreams about unobvious side effectscontrib: Stuff that affects the contributor experience. e.g.misc: Changes that are hard to assign to any of the aboveRelated issues and pull requests on GitHub: #654.
Started type-checking the project with MyPy against a range of
versions instead of just one — Python 3.8–3.12 -- by @webknjaz.
The project how has a .git-blame-ignore-revs letting GitHub know
which auto-formatting revisions to ignore. It is also possible to
integrate it locally, if one wants to do so.
-- by @webknjaz
The project adopted the autopep8 tool to assist with automatic
code formatting. It is chosen over black because it is less
intrusive which is important to the maintainer as it promotes
inclusivity. autopep8 is integrated into the pre-commit check
runner and is configured to only correct 8 violations, avoiding
changes to compliant snippets.
-- by @webknjaz
Related commits on GitHub:
65ba7e69.
The continuous integration and pull request merges have been set up
to only merge pull requests through merge queues -- by @webknjaz.
Related commits on GitHub:
a7149e0c.
Documented the upgraded :stdrelease process <contributing/release_guide> -- by @webknjaz.
Related commits on GitHub:
df0d1a08.
The changelog management is now implemented through the
:stdTowncrier <towncrier:index> tool -- by @webknjaz.
The contributors are now expected to :stdinclude change log fragment files in their pull requests <adding change notes with your prs>.
These news snippets can link one or more issues or pull requests,
and be of one or more of the following categories:
bugfix: A bug fix for something we deemed an improperfeature: A new behavior, public APIs. That sort of stuff.deprecation: A declaration of future API removals and breakingbreaking: When something public gets removed in a breakingdoc: Notable updates to the documentation structure or buildpackaging: Notes for downstreams about unobvious side effectscontrib: Stuff that affects the contributor experience. e.g.misc: Changes that are hard to assign to any of the aboveRelated issues and pull requests on GitHub: #654.
This release is published to https://pypi.org/project/cheroot/10.0.0.
This release is published to https://pypi.org/project/cheroot/10.0.0.
This release has been produced by the following workflow run: https://github.com/cherrypy/cheroot/actions/runs/5032474797.
(2023-05-20)
504 via 505: Cheroot now accepts a reuse_port parameter on the HTTPServer object. Subclasses overriding prepare_socket will no longer work and will need to adapt to the new interface.
Set worker thread names as str by @jarus in https://github.com/cherrypy/cheroot/pull/503
str by @jarus in https://github.com/cherrypy/cheroot/pull/503_compat.py by @kasium in https://github.com/cherrypy/cheroot/pull/491Full Diff: https://github.com/cherrypy/cheroot/compare/v8.6.0...v9.0.0
(2022-11-19)
252 via 339: Cheroot now requires Python 3.6 or later. Python 3.5 and Python 2.7 are still supported by the maint/8.x branch and stabilizing bugfixes will be accepted to that branch.
PR #401 (related to the PR #352 effort): Started reusing the the expriration_interval setting in the low-level `select.select()` invocation, effective
#384 via PR #385, PR #406: Exposed type stubs with annotations for public API -- by @kasium.
PR #401 (related to the PR #352 effort): Started reusing the
the expriration_interval setting in the low-level
select.select() invocation,
effectively reducing the system
load under the Windows OS when idle, that is noticeable on low-end
hardware systems -- by :user:MichaIng.
(2022-01-03)
Significant improvements:
384 via 385, 406: Exposed type stubs with annotations for public API -- by kasium.
401 (related to the 352 effort): Started reusing the the expriration_interval setting as timeout in the low-level ~select.select invocation, effectively reducing the system load when idle, that is noticeable on low-end hardware systems. On Windows OS, due to different ~select.select behavior, the effect is less significant and comes with a theoretically decreased performance on quickly repeating requests, which has however found to be not significant in real world scenarios. -- by MichaIng.
Internal changes:
Implemented a manual-trigger-based release workflow.
Integrated publishing GitHub Releases into the workflow.
Migrated the docs theme to Furo (created by pradyunsg).
Attempted to improve the stability of testing.
Configured the CI to test the same distribution as will be shipped.
Improved the linting setup and contributor checklists.
Stopped running tests under Ubuntu 16.04.
Tweaked the distribution packages metadata to satisfy strict checks.
Implemented distribution build reproducibility using a pip constraints lock-file.
Added per-environment lock-files into the tox test environments.
358 via 359: Fixed a regression from 199 that made the worker threads exit on invalid connection attempts and could make the whole server unresponsive
(2021-01-18)
358 via 359: Fixed a regression from 199 that made the worker threads exit on invalid connection attempts and could make the whole server unresponsive once there was no workers left. -- by cameronbrunner.
cherrypy/cherrypy#1873 via 340: Resurrected an unintentionally removed feature of interrupting a server main thread by externally assigning an excepti
(2020-12-12)
cherrypy/cherrypy#1873 via 340: Resurrected an unintentionally removed feature of interrupting a server main thread by externally assigning an exception to the HTTPServer.interrupt property -- by liamstask.
350: Fixed the incarnation of an earlier regression of not resetting the serving state on ~signal.SIGINT originally fixed by 322 and 331 but reintroduced by the changes in 311 -- by liamstask.
305 via 311: In class:~cheroot.connections.ConnectionManager, process connections as they become active rather than waiting for a tick event, addressi
(2020-12-05)
305 via 311: In ~cheroot.connections.ConnectionManager, process connections as they become active rather than waiting for a tick event, addressing performance degradation introduced in v8.1.0 -- by liamstask.
341 via 342: Suppress legitimate OS errors expected on shutdown -- by webknjaz.
(2020-12-05)
#305 via #311 : In ConnectionManager , process connections as they become active rather than waiting for a tick event, addressing performance degradation introduced in v8.1.0 – by @liamstask .
#341 via #342 : Suppress legitimate OS errors expected on shutdown – by @webknjaz .
317 via 337: Fixed a regression in 8.4.5 where the connections dictionary would change size during iteration, leading to a exc:RuntimeError raised in
(2020-11-24)
317 via 337: Fixed a regression in 8.4.5 where the connections dictionary would change size during iteration, leading to a RuntimeError raised in the logs -- by liamstask.
334: Started filtering out TLS/SSL errors when the version requested by the client is unsupported -- by sanderjo and Safihre.
(2020-11-15)
334: Started filtering out TLS/SSL errors when the version requested by the client is unsupported -- by sanderjo and Safihre.
328 via 322 and 331: Fixed a regression introduced in the earlier refactoring in v8.4.4 via 309 that caused the meth:~cheroot.server.\ HTTPServer.serv
(2020-11-15)
328 via 322 and 331: Fixed a regression introduced in the earlier refactoring in v8.4.4 via 309 that caused the ~cheroot.server.HTTPServer.serve method to skip setting serving=False on ~signal.SIGINT and ~signal.SIGTERM -- by marc1n and cristicbz.
(2020-11-15)
#328 via #322 and #331 : Fixed a regression introduced in the earlier refactoring in v8.4.4 via #309 that caused the serve() method to skip setting serving=False on SIGINT and SIGTERM – by @marc1n and @cristicbz .
* #312 via #313: Fixed a regression introduced in the earlier refactoring in v8.4.4 via #309 that caused the connection manager to modify the selector
cheroot.connections.ConnectionManager.get_conn to ensure more stability — by @cyraxjoe.(2020-08-24)
312 via 313: Fixed a regression introduced in the earlier refactoring in v8.4.4 via 309 that caused the connection manager to modify the selector map while looping over it -- by liamstask.
312 via 316: Added a regression test for the error handling in ~cheroot.connections.ConnectionManager.get_conn to ensure more stability -- by cyraxjoe.
* #304 via #309: Refactored cheroot.connections.ConnectionManager to use selectors.BaseSelector.get_map and reorganized the readable connection tracki
cheroot.connections.ConnectionManager to use selectors.BaseSelector.get_map and reorganized the readable connection tracking — by @liamstask.(2020-08-12)
304 via 309: Refactored ~cheroot.connections.ConnectionManager to use ~selectors.BaseSelector.get_map and reorganized the readable connection tracking -- by liamstask.
304 via 309: Fixed the server shutdown sequence to avoid race condition resulting in accepting new connections while it is being terminated -- by liamstask.
(2020-08-12)
#304 via #309 : Refactored ConnectionManager to use get_map() and reorganized the readable connection tracking – by @liamstask .
#304 via #309 : Fixed the server shutdown sequence to avoid race condition resulting in accepting new connections while it is being terminated – by @liamstask .
This change populates the Keep-Alive header exposing the timeout value for persistent HTTP/1.1 connections which helps mitigate such race conditions b
#282: Fixed a race condition happening when an HTTP client attempts to reuse a persistent HTTP connection after it's been discarded on the server in cheroot.server.HTTPRequest but no TCP FIN packet has been received yet over the wire — by @meaksh.
This change populates the Keep-Alive header exposing the timeout value for persistent HTTP/1.1 connections which helps mitigate such race conditions by letting the client know not to reuse the connection after that time interval.
Fixed a significant performance regression introduced in v8.1.0 (#305 via #308) - by @mar10.
Fixed a significant performance regression introduced in v8.1.0 (#305 via #308) - by @mar10.
The issue turned out to add 0.1s delay on new incoming connection processing. We've lowered that delay to mitigate the problem short-term, better fix is yet to come.
(2020-07-28)
Fixed a significant performance regression introduced in v8.1.0 (305 via 308) - by mar10.
The issue turned out to add 0.1s delay on new incoming connection processing. We've lowered that delay to mitigate the problem short-term, better fix is yet to come.
Prevent `ConnectionAbortedError` traceback from being printed out to the terminal output during the app start-up on Windows when built-in TLS adapter
ConnectionAbortedError traceback from being printed
out to the terminal output during the app start-up on Windows
when built-in TLS adapter is used (#302 via PR #306) - by @mxii-ca.(2020-07-26)
Prevent ConnectionAbortedError traceback from being printed out to the terminal output during the app start-up on Windows when built-in TLS adapter is used (302 via 306) - by mxii-ca.
Converted management from low-level `select()` to high-level `selectors` (#249 via PR #301) - by @tommilligan.
Converted management from low-level select() to high-level selectors (#249 via PR #301) - by @tommilligan.
This change also introduces a conditional dependency on selectors2 as a fall-back for legacy Python interpreters.
(2020-07-23)
Converted management from low-level ~select.select to high-level selectors (249 via 301) - by tommilligan.
This change also introduces a conditional dependency on selectors2 as a fall-back for legacy Python interpreters.
Fixed TLS socket related unclosed resource warnings (PR #291 and PR #298).
(2020-07-13)
Fixed TLS socket related unclosed resource warnings (291 and 298).
Made terminating keep-alive connections more graceful (263 via 277).
cherrypy/cherrypy#910 via #243: Provide TLS-related details via WSGI environment interface.
--bind CLI option
for abstract UNIX sockets.(2020-02-09)
cherrypy/cherrypy#910 via 243: Provide TLS-related details via WSGI environment interface.
248: Fix parsing of the --bind CLI option for abstract UNIX sockets.
cherrypy/cherrypy#1818: Restore support for None default argument to WebCase.getPage().
None
default argument to WebCase.getPage().(2019-10-17)
cherrypy/cherrypy#1818: Restore support for None default argument to WebCase.getPage().
(2019-10-17)
1818: Restore support for None default argument to WebCase.getPage().
Deprecated use of negative timeouts as an alias for infinite timeouts in ThreadPool.stop.
ThreadPool.stop.(2019-10-14)
Deprecated use of negative timeouts as alias for infinite timeouts in ThreadPool.stop.
cherrypy/cherrypy#1662 via 74: For OPTION requests, bypass URI as path if it does not appear absolute.
Workers are now request-based, addressing the long-standing issue with keep-alive connections (#91 via #199).
(2019-10-09)
Workers are now request-based, addressing the long-standing issue with keep-alive connections (91 via 199).
- #231 via #232: Remove custom setup.cfg parser handling, allowing the project (including sdist) to build/run on setuptools 41.4. Now building cheroot
setup.cfg
parser handling, allowing the project (including sdist)
to build/run on setuptools 41.4. Now building cheroot
requires setuptools 30.3 or later (for declarative
config support) and preferably 34.4 or later (as
indicated in pyproject.toml).- #224: Refactored "open URL" behavior in cheroot.test.webtest to rely on retry_call. Callers can no longer pass raise_subcls or ssl_context positiona
cheroot.test.webtest to
rely on retry_call.
Callers can no longer pass raise_subcls or ssl_context
positionally, but must pass them as keyword arguments.(2019-09-26)
#224 : Refactored “open URL” behavior in webtest to rely on retry_call . Callers can no longer pass raise_subcls or ssl_context positionally, but must pass them as keyword arguments.
Revisit #85 under #221. Now backports.functools_lru_cache is only required on Python 3.2 and earlier.
backports.functools_lru_cache is only
required on Python 3.2 and earlier.(2019-09-25)
Revisit 85 under 221. Now backports.functools_lru_cache is only required on Python 3.2 and earlier.
1206 via 204: Fix race condition in threadpool shrink code.
- #222 via 621f4ee: Fix socket.SO_PEERCRED constant fallback value under PowerPC.
socket.SO_PEERCRED constant fallback value
under PowerPC.(2019-09-05)
222 via 621f4ee: Fix socket.SO_PEERCRED constant fallback value under PowerPC.
(2019-09-05)
#222 via @621f4ee : Fix socket.SO_PEERCRED constant fallback value under PowerPC.
Improve post Python 3.9 compatibility checks.
#198 via 9f7affe: Fix race condition when toggling stats counting in the middle of request processing.
Improve post Python 3.9 compatibility checks.
Fix support of abstract namespace sockets.
(2019-09-03)
198 via 9f7affe: Fix race condition when toggling stats counting in the middle of request processing.
Improve post Python 3.9 compatibility checks.
Fix support of abstract namespace sockets.
- #218 via #219: Fix HTTP parser to return 400 on invalid major-only HTTP version in Request-Line.
(2019-08-19)
218 via 219: Fix HTTP parser to return 400 on invalid major-only HTTP version in Request-Line.
https://github.com/cherrypy/cherrypy/issues/1618 via #180: Ignore OpenSSL's 1.1+ Error 0 under any Python while wrapping a socket.
#99 via #186: Sockets now collect statistics (bytes read and written) on Python 3 same as Python 2.
https://github.com/cherrypy/cherrypy/issues/1618 via #180: Ignore OpenSSL's 1.1+ Error 0 under any Python while wrapping a socket.
(2019-04-25)
99 via 186: Sockets now collect statistics (bytes read and written) on Python 3 same as Python 2.
cherrypy/cherrypy#1618 via 180: Ignore OpenSSL's 1.1+ Error 0 under any Python while wrapping a socket.
Avoid deprecation warning with class:OpenSSL.SSL.Connection.
#113: Fix cheroot.ssl.pyopenssl under Python 3.
#154 via #159: Remove custom license field from dist metadata.
#95: Fully integrate trustme into all TLS tests. Also remove all hardcoded TLS certificates.
#42: Remove traces of unittest and ddt usage.
Fix invalid input processing in cheroot._compat.extract_bytes.
Fix returning error explanation over plain HTTP for PyOpenSSL.
Add a fallback for os.lchmod where it's missing.
Avoid traceback for invalid client cert with builtin ssl adapter.
Avoid deprecation warning with OpenSSL.SSL.Connection.
Fix socket wrapper in PyOpenSSL adapter.
Improve tests coverage:
Client TLS certificate tests
cheroot._compat.extract_bytes
Peercreds lookup
- #149: Make SCRIPT_NAME optional per PEP 333.
SCRIPT_NAME optional per PEP 333.(2018-12-20)
149: Make SCRIPT_NAME optional per PEP 333.
- #6 via #109: Fix import of mod:cheroot.ssl.pyopenssl by refactoring and separating mod:cheroot.makefile's stream wrappers. - #95 via #109: Add initi
#6 via #109: Fix import of cheroot.ssl.pyopenssl by refactoring and separating cheroot.makefile's stream wrappers.
#95 via #109: Add initial tests for SSL layer with use of trustme
- #93 via #110: Improve UNIX socket fs access mode in meth:cheroot.server.HTTPServer.prepare on a file socket when starting to listen to it.
#93 via #110: Improve UNIX socket fs access mode in cheroot.server.HTTPServer.prepare on a file socket when starting to listen to it.
(2018-09-02)
93 via 110: Improve UNIX socket FS access mode in cheroot.server.HTTPServer.prepare on a file socket when starting to listen to it.
cherrypy/cherrypy#1001 via #52 and #108: Add support for validating client certificates.
(2018-08-29)
cherrypy/cherrypy#1001 via 52 and 108: Add support for validating client certificates.
(2018-08-29)
1001 via 52 and 108: Add support for validating client certificates.
68 via 98: Factor out parts of meth:cheroot.server.HTTPServer.start into meth:prepare() and meth:serve()
68 via 98: Factor out parts of cheroot.server.HTTPServer.start into prepare() and serve()
(2018-08-01)
68 via 98: Factor out parts of cheroot.server.HTTPServer.start into prepare() and serve()
Fix bug with returning empty result in meth:cheroot.ssl.builtin.BuiltinSSLAdapter.wrap
Fix bug with returning empty result in cheroot.ssl.builtin.BuiltinSSLAdapter.wrap
(2018-07-10)
Fix bug with returning empty result in cheroot.ssl.builtin.BuiltinSSLAdapter.wrap
New metadata with info about Python 3.7 support
New metadata with info about Python 3.7 support
100 via 101: Respond with HTTP 400 to malicious Content-Length in request headers.
:issue:100 via :pr:101: Respond with HTTP 400 to malicious Content-Length in request headers.
(2018-06-16)
100 via 101: Respond with HTTP 400 to malicious Content-Length in request headers.
:cp-issue:1618: Ignore OpenSSL's 1.0+ Error 0 under Python 2 while wrapping a socket.
1618: Ignore OpenSSL's 1.0+ Error 0 under Python 2 while
wrapping a socket.(2018-05-21)
cherrypy/cherrypy#1618: Ignore OpenSSL's 1.1+ Error 0 under Python 2 while wrapping a socket.
(2018-05-21)
1618: Ignore OpenSSL's 1.1+ Error 0 under Python 2 while wrapping a socket.
87: Add cheroot command and runpy launcher to launch a WSGI app from the command-line.
87: Add cheroot command and runpy launcher to
launch a WSGI app from the command-line.(2018-05-17)
87: Add cheroot command and runpy launcher to launch a WSGI app from the command-line.
Fix missing resolve_peer_creds argument in class:cheroot.wsgi.Server being bypassed into class:cheroot.server.HTTPServer.
Fix missing resolve_peer_creds argument in cheroot.wsgi.Server being bypassed into cheroot.server.HTTPServer.
85: Revert conditional dependencies. System packagers should honor the dependencies as declared by cheroot, which are defined intentionally.
85: Skip installing dependencies from backports namespace under Python 3.
85: Skip installing dependencies from backports namespace under Python 3.(2018-04-14)
85: Skip installing dependencies from backports namespace under Python 3.
84 (:cp-issue:1704): Fix regression, causing exc:ModuleNotFoundError under cygwin.
84 (:cp-issue:1704): Fix regression, causing
:py:exc:ModuleNotFoundError under cygwin.(2018-04-14)
84 (cherrypy/cherrypy#1704): Fix regression, causing ModuleNotFoundError under cygwin.
(2018-04-14)
84 (1704): Fix regression, causing ModuleNotFoundError under cygwin.
83: Fix regression, caused by inverted check for Windows OS.
(2018-04-10)
83: Fix regression, caused by inverted check for Windows OS.
Add more URLs to distribution metadata
37: Implement PEERCRED lookup over UNIX-socket HTTP connection.
37: Implement PEERCRED lookup over UNIX-socket HTTP connection.
Discover connected process' PID/UID/GID
Respect server switches: peercreds_enabled and
peercreds_resolve_enabled
get_peer_creds and resolve_peer_creds methods on connection
peer_pid, peer_uid, peer_gid, peer_user and peer_group
properties on connection
X_REMOTE_PID, X_REMOTE_UID, X_REMOTE_GID, X_REMOTE_USER
(REMOTE_USER) and X_REMOTE_GROUP WSGI environment variables when
enabled and supported
Per-connection caching to reduce lookup cost
81: Fix regression introduced by 80.
81: Fix regression introduced by 80. * Restore storing bound socket in Windows broken by use of
socket.AF_UNIX
(2018-04-08)
81: Fix regression introduced by 80.
Restore storing bound socket in Windows broken by use of socket.AF_UNIX
80: Fix regression introduced by 68a5769.
Get back support for socket.AF_UNIX in stored bound address in
cheroot.server.HTTPServer.bind_addr
(2018-04-07)
80: Fix regression introduced by 68a5769.
Get back support for socket.AF_UNIX in stored bound address in cheroot.server.HTTPServer.bind_addr
67: Refactor testsuite to completely rely on pytest.
:pr:67: Refactor testsuite to completely rely on pytest.
Integrate pytest-testmon and pytest-watch
Stabilise testing
:cp-issue:1664 via :pr:66: Implement input termination flag support as
suggested by @mitsuhiko <https://github.com/mitsuhiko>_ in his
wsgi.input_terminated Proposal <https://gist.github.com/mitsuhiko/5721547>_.
:issue:73: Fix SSL error bypassing.
:issue:77 via :pr:78: Fix WSGI documentation example to support Python 3.
:pr:76: Send correct conditional HTTP error in helper function.
:cp-issue:1404 via :pr:75: Fix headers being unsent before request
closed. Now we double check that they've been sent.
Minor docs improvements.
Minor refactoring.
(2018-04-05)
67: Refactor test suite to completely rely on pytest.
Integrate pytest-testmon and pytest-watch
Stabilize testing
cherrypy/cherrypy#1664 via 66: Implement input termination flag support as suggested by @mitsuhiko in his wsgi.input_terminated Proposal.
73: Fix SSL error bypassing.
77 via 78: Fix WSGI documentation example to support Python 3.
76: Send correct conditional HTTP error in helper function.
cherrypy/cherrypy#1404 via 75: Fix headers being unsent before request closed. Now we double check that they've been sent.
Minor docs improvements.
Minor refactoring.
Drop support for Python 2.6, 3.1, 3.2, and 3.3.
(2017-12-04)
Drop support for Python 2.6, 3.1, 3.2, and 3.3.
Also drop built-in SSL support for Python 2.7 earlier than 2.7.9.
CherryPy #1621: To support webtest applications that feed absolute URIs to getPage but expect the scheme/host/port to be ignored (as cheroot 5.8 and e
strip_netloc helper and recipe for calling it in a subclass.(2017-12-04)
cherrypy/cherrypy#1621: To support ~cheroot.test.webtest applications that feed absolute URIs to ~cheroot.test.webtest.WebCase.getPage but expect the scheme/host/port to be ignored (as cheroot 5.8 and earlier did), provide a strip_netloc helper and recipe for calling it in a subclass.
Your coding agent can read these notes before it upgrades. Set up the MCP server →