Apache HTTPD 2.4.69 release candidate ships for testing
A stabilization release that hardens HTTP/2, quietly disables a status flag by default, and moves the test suite from Perl to Python.
Apache's battle-tested web server has a new release candidate, and now the community is being asked to try hard to break it. Eric Covener tagged Apache HTTP Server 2.4.69-rc1-candidate, kicking off the first freeze-window for what will become the next stable point release on the 2.4.x branch.
A release candidate is the moment a version stops being a moving target. The feature set is locked. From here on it's just bug hunting. Testers worldwide compile it, run it against real workloads, and file problems before the Apache Software Foundation declares it "best available."
The changes that matter
The standout behavioral fix lives in mod_http2. The module used to drop an in-flight response the moment a client sent a graceful GOAWAY with error code 0, even while streams it opened were still being processed. Now the session drains those open streams instead of tearing down immediately, which puts it in line with RFC 9113, the current HTTP/2 standard.
This actually matters. HTTP/2 multiplexes dozens of streams over a single connection, so abandoning half of them mid-request corrupts legitimate traffic. The CHANGES note is blunt about why this slipped through before: async MPMs now "hit far more than event," meaning modern threaded configurations silently lost responses in the wild.
There's more hardening buried here. The core now rejects control characters in the reason phrase of informational responses and accepts only a space as the status separator, closing a vector for response splitting. mod_substitute picked up two fixes, one for oversized SubstituteMaxLineLength values and one for a crash triggered by a missing closing delimiter. A fixup crash in mod_dir and an unsafe atoi() call in mod_lbmethod_heartbeat's heartbeat balancing got the same treatment.
Then there's the quiet-by-default shift operators probably won't notice until they need it. mod_md now disables MDServerStatus out of the box, trimming the amount of certificate-management status exposed through server-status. It's a security-by-default move, and it's exactly the kind of change that stops leaking infrastructure details without anyone filing a ticket.
Legacy code is being pruned too. mod_auth_digest drops the weak RFC 2069 digest algorithm entirely, rewriting its shared-memory and client-nonce handling to match modern expectations. OpenSSL 4 compatibility work is being folded into both mod_ssl and mod_md so the server keeps working against the newest crypto line, while mod_ssl gains compatibility macros for X509_get0_notBefore and friends when building against older material.
The most interesting change for contributors, honestly, is the infrastructure one. The decades-old Perl-based test suite has been fully ported to Python and pytest, now living under a ./test directory in the source tree. It won't change how you run the server tomorrow, but it should make integration testing faster and easier to extend down the line. Head here to the source tree to take a look.
Head here to grab the 2.4.69-rc1-candidate source or follow the full CHANGES file on GitHub.
