UPSTREAM FIX

magento2-40656: Adds more tracking parameters to the Varnish VCL and page cache strip lists

Community fix magento2-40656 merged into magento/magento2 on 2026-10-07, not in a release yet.

Adds more tracking parameters to the Varnish VCL and page cache strip lists edited

Pull request title
fix(pagecache): expand Varnish tracking parameter strip list
Pull request
magento/magento2#40656
Issues
#40760 pr-derived, #40815 pr-derived
Author
@lbajsarowicz
Merged
2026-10-07
Fixed in
no release yet
Reported on
—
Categories
—
Components
magento/framework, magento/module-page-cache

Labels

Area
—
Component
—
Priority
P3
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

The upstream issue and pull request have no structured description.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 file-missing 2.4.6-p1 file-missing 2.4.6-p2 file-missing 2.4.6-p3 file-missing 2.4.6-p4 file-missing 2.4.6-p5 file-missing 2.4.6-p6 file-missing 2.4.6-p7 file-missing 2.4.6-p8 file-missing 2.4.6-p9 file-missing 2.4.6-p10 file-missing 2.4.6-p11 file-missing 2.4.6-p12 file-missing 2.4.6-p13 file-missing 2.4.6-p14 file-missing 2.4.6-p15 file-missing
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 file-missing 2.4.7-p1 file-missing 2.4.7-p2 file-missing 2.4.7-p3 file-missing 2.4.7-p4 file-missing 2.4.7-p5 file-missing 2.4.7-p6 file-missing 2.4.7-p7 file-missing 2.4.7-p8 file-missing 2.4.7-p9 file-missing 2.4.7-p10 file-missing
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 conflict 2.4.8-p1 conflict 2.4.8-p2 conflict 2.4.8-p3 conflict 2.4.8-p4 conflict 2.4.8-p5 conflict
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflict
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 24.9%. Probability it is security relevant: 1.0%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindfeaturefeature 67.6%, bugfix 18.6%, refactor 5.5%, cleanup 5.4%, tests_only 1.3%, dependency 0.9%, docs_only 0.7%41.5%
Areaframeworkframework 91.3%, other 3.9%, frontend 1.7%81.3%
Reported versionunspecifiedunspecified 22.2%, 2.4.8 2.7%, 2.4.7 2.7%4.9%
Scope1.44 of 22 56.3%, 1 31.5%, 0 12.3%14.6%
Risk0.67 of 21 55.8%, 0 38.7%, 2 5.5%19.6%
Worth backporting0.94 of 21 40.6%, 0 32.9%, 2 26.6%1.5%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40656/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

No checked release lacks this fix with a clean code match, so no bundle is offered.

Bundle README (what the ZIP ships)
# magento2-40656

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40656
Issue: https://github.com/magento/magento2/issues/40760
Issue: https://github.com/magento/magento2/issues/40815
Author: @lbajsarowicz
Source commit: 2d1b9ee53f858fa8a80886f36aa1e0d996b14108
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.