# Core 2.5.5 / module 2.7.7 release Status: released September 7, 2026. This release supersedes the withheld 2.5.4 installer candidate; every published 2.5.4 immutable file remains unchanged. The release pairs core **2.5.5**, module **2.7.7**, and ModSecurity artifacts **2.5.4** (engine 3.0.15). Module and WAF binaries are byte-identical to the prior accepted build. The core CLI and custom HTTP identity now both identify 2.5.5. ## Changes - Import Plesk PHP handlers from `` as well as ``. Recognize the actual Plesk nesting inside the document-root Directory and IfModule blocks. A PHP 8.3 site and a PHP 8.4 site keep their selected versions. - Resolve each PHP-FPM pool's complete socket path, including its `$pool` prefix and relative `listen = php-fpm.sock`. Shared socket basenames and conflicting declarations cannot select another domain's named PHP runtime. - Limit promotion to the exact document root. Subdirectory, parent, unrelated, and differently cased directory paths do not change the whole site's PHP handler. Retain existing direct version hints and Ubuntu/cPanel absolute pools. - Finish worker cleanup before reporting the last worker as stopped. This fixes the shutdown race found by the sanitizer suite during stop followed by deletion. - Give the Plesk Apache wrapper sole systemd ownership of OLS. Stop and disable the competing native unit; route extension and Apache-shim lifecycle actions through the owning unit, and stop it before uninstall restores Apache/nginx. - Pin standalone, Plesk, and CyberPanel stable/development consumers to one checksum-verified bundle, with complete backup and rollback behavior. This release includes the core and module improvements described in [the preceding 2.5.4 source archive](https://cyberpanel.net/openlitespeed-2.5.4-source.tar.gz), including transactional rewrite reloads, request-local PHP settings, header/environment behavior, and threaded POST fixes. License enforcement and the paired LSI header/ABI marker are unchanged. ## Validation - Four native core builds each passed 244 framework tests. The full AddressSanitizer run also passed 244. Each suite reported 11 GeoIP fixture self-skips; those missing-data paths are not claimed as covered. Address checking was enabled; LeakSanitizer was disabled for existing process-lifetime caches. - Threaded POST tests passed 14/14 in each normal, debug and ASan build, with full payload checks through 2 GB and unchanged timeouts. Five unlicensed native core/module/WAF suites passed 75/75 combined. - Public module/consumer tests passed 37/37. CyberPanel stable and development consumer tests each passed 20/20, including corrupt-download rollback checks. - WordPress on Ubuntu 26 passed upgrade, full rollback and reapply, two corrupt downloads, HTTP 23/23 and 200/200 mixed requests with four workers. Configs and worker health remained stable with no additional error-log bytes. - The actual Chromium browser passed 18/18 ordinary checks, including 48 mixed requests, REST, permalinks, image bytes/decode, and a fresh HTTP/2 response. The first run recorded both HTTP/2 and HTTP/3; its only failure was a test requiring exactly HTTP/2 after the browser switched to HTTP/3. That result is preserved, and the corrected check reports and accepts either actual protocol. - Gutenberg visual paragraph selection and keyboard input, Save, the Post updated notification, and the public final revision were verified in native Chrome. These browser checks make no licensed feature assertions. - A fresh Plesk 18.0.80 / Ubuntu 24.04 fixture passed all nine lifecycle gates, 201/201 assertions: fresh install, systemd/Plesk reconfiguration, ports, TLS, PHP 8.3/8.4 mapping, extension restart/stop/start, stock restoration, reinstall, and restart plus 100 trusted HTTPS requests with stable workers. The final log check scans only bytes appended during that gate; an old informational “Core dump is enabled” line had caused the preserved initial false failure. Six focused harness tests retain detection of actual crash diagnostics. - Ordinary wget downloads of the final Plesk core/module/WAF binaries and their three sidecars returned HTTPS 200 and matched all six expected hashes. The earlier core 2.5.4/module 2.7.7 pair passed the 99-check licensed browser catalog, the 84-case licensed compatibility matrix, six PHP isolation checks and 512 concurrent requests. Those are preserved historical results, not runs on core 2.5.5. The temporary test license was cancelled normally after those checks; 2.5.5 WordPress and browser testing keeps that key and its cache absent. The failed first 2.5.5 candidate, its live PHP response, its successful rollback, and the sanitizer failure are preserved. They are not counted as accepted final results. The parser's old-code negative control reproduces the nested Plesk bug. ## Sources and artifacts Frozen core source: `90b858f11c01b17bf698e7c12ec8c64029fd1e19`. [Download the complete core source](https://cyberpanel.net/openlitespeed-2.5.5-source.tar.gz), SHA256 `6bf6fb7ebe544f444d6ff5bf6054ab5408d2853c2a8a0040e0d5de6e0474a4cb`. The archive contains the pinned recursive dependencies and no Git history. Ubuntu core/module target Ubuntu 22/24/26; Ubuntu 26 uses its separate WAF binary. Other pairs target RHEL-compatible 8, 9 and 10. All downloads below have a matching `.sha256` sidecar. The core CLI reports 2.5.5; its inherited BUILD timestamp is August 18, 2026, not the September 7 build date. | Artifact | SHA256 | |---|---| | [cyberpanel_ols-2.7.7-x86_64-rhel10.so](https://cyberpanel.net/cyberpanel_ols-2.7.7-x86_64-rhel10.so) | `edc783f288ba4d5baf4a51748900ddd8f13ccb147ed88ffee73e4fb559b20db2` | | [cyberpanel_ols-2.7.7-x86_64-rhel8.so](https://cyberpanel.net/cyberpanel_ols-2.7.7-x86_64-rhel8.so) | `c28caa4c0d8ef4c021ae347079481db5d21ed52eb60a7edffe3d2cf8239f6733` | | [cyberpanel_ols-2.7.7-x86_64-rhel9.so](https://cyberpanel.net/cyberpanel_ols-2.7.7-x86_64-rhel9.so) | `7a4d92b6050581e17585cb7be9369d6e7d0496e051fa158a65c049c78db8aedb` | | [cyberpanel_ols-2.7.7-x86_64-ubuntu.so](https://cyberpanel.net/cyberpanel_ols-2.7.7-x86_64-ubuntu.so) | `41ae567f45931691e34facf1914bf78bb95236d9f8b1ee75d455cbbc19ca6d8b` | | [mod_security-2.5.4-x86_64-rhel10.so](https://cyberpanel.net/mod_security-2.5.4-x86_64-rhel10.so) | `a7d8131bf7fa9b14286a088a1a9eb8f0bca15de991c79d6173ac0f274dcd9bcf` | | [mod_security-2.5.4-x86_64-rhel8.so](https://cyberpanel.net/mod_security-2.5.4-x86_64-rhel8.so) | `cfdf61bb3e0115fbcd172a5dd55fe107a8e17888711a31eec25d34b94df3bb6c` | | [mod_security-2.5.4-x86_64-rhel9.so](https://cyberpanel.net/mod_security-2.5.4-x86_64-rhel9.so) | `eb67cce467b29b73f70f798db8e5097b13e8c264a83b146bac601bbd62399b0f` | | [mod_security-2.5.4-x86_64-ubuntu.so](https://cyberpanel.net/mod_security-2.5.4-x86_64-ubuntu.so) | `0714c9e43781d51ffab5ee4faf2b4506b68cc0f9483285bfa8a8d334d0f96172` | | [mod_security-2.5.4-x86_64-ubuntu26.so](https://cyberpanel.net/mod_security-2.5.4-x86_64-ubuntu26.so) | `5f2f285b667611a6fd3dcb91f5790ead0b096afc43ca5f5507345dd05f2bd8a5` | | [openlitespeed-2.5.5-x86_64-rhel10](https://cyberpanel.net/openlitespeed-2.5.5-x86_64-rhel10) | `e51b81234ab46452268449cb8a694dee09898cfd2eadc252b176b87cd4039ab1` | | [openlitespeed-2.5.5-x86_64-rhel8](https://cyberpanel.net/openlitespeed-2.5.5-x86_64-rhel8) | `d12b66fe05fa483f61d3833d86053bb1c81c4cd3421a9be5ef610dffd3a87949` | | [openlitespeed-2.5.5-x86_64-rhel9](https://cyberpanel.net/openlitespeed-2.5.5-x86_64-rhel9) | `1a6b9338d5dcc3153f15302f5a057faa0a369a90b6d850d72d07bfe3a41cb5be` | | [openlitespeed-2.5.5-x86_64-ubuntu](https://cyberpanel.net/openlitespeed-2.5.5-x86_64-ubuntu) | `736eeb47bd3dc7b2a7206b95106dd735a80b3386118d0b4b17f39f9fa5324f8c` | LSQUIC is 4.9.3 at `19547405c24f60c4537478d38f4214e990be1f95`, with pinned recursive dependencies. The paired `include/ls.h` SHA256 remains `a969e1bacc9eb842bd88f476654d1c849604b2dfd087656fd701523a123344cc`. The module runtime sources remain byte-identical to build workspace `adabeb500cbf9fc1993e2c2f13fcb508d0c68149`; later edits concern consumers, tests and documentation. ## Deployment scope The selected mutable downloads are [the standalone installer](https://cyberpanel.net/install_module.sh) and [the Plesk extension](https://cyberpanel.net/cyberpanel-ols.zip). The standalone installer requires an existing OLS installation and preserves existing licensed state when no new key is supplied. The cPanel installer/plugin rollout is deferred and its 39 source files and public downloads retain their preceding versions. The universal `ols-install.sh` entry point remains unchanged: its Plesk route downloads the current ZIP and its cPanel route continues using the prior cPanel release. CyberPanel stable and maintained-development changes are narrow consumer backports. No whole development branch is merged into stable. Maintainers should use `--consumer-scope standalone-plesk` with `tools/pin_release_checksums.py` and the complete artifact directory. The default `all` scope deliberately rejects the older cPanel pins until that separate rollout is completed. ## Upgrade instructions For an existing OLS installation, download and run the standalone installer: ```bash curl -fSLo install_module.sh https://cyberpanel.net/install_module.sh bash install_module.sh ``` For Plesk, upload `cyberpanel-ols.zip` in Extensions, or use the existing universal entry point, which detects Plesk and downloads the current ZIP: ```bash bash <(curl -fsSL https://cyberpanel.net/ols-install.sh) ``` Allow a maintenance window for the service restart. The Plesk extension's normal uninstall restores the original Apache/nginx stack. The cPanel route continues its previous release and is outside this update. ## Compatibility limits Nested RequireAll/RequireAny composition and forward-confirmed hostname authorization remain unsupported. ErrorDocument only has the early filesystem 404 helper, which returns its target with HTTP 200; custom 403, inline and application-generated error responses remain unsupported. Configuration uses nearest applicable policy per feature rather than every Apache merge rule. New .htaccess files can take up to the existing five-second negative-cache TTL to appear; rewrite reloads watch the top-level file, not changes to nested includes independently. No full Apache/Nginx equivalence is claimed.