Symptoms
Issue #2336 reports these lines after upgrading stable-11031 to stable-11248. Failed negotiation does not prove the Java processes exited. [S1]
JVB: [S1]
jvb-1 | org.jivesoftware.smack.XMPPException$StreamErrorException: undefined-condition You can read more about the meaning of this stream error at http://xmpp.org/rfcs/rfc6120.html#streams-error-conditions
jvb-1 | <stream:error><undefined-condition xmlns='urn:ietf:params:xml:ns:xmpp-streams'/><text>No stream features to proceed with</text></stream:error>Jicofo: [S1]
jicofo-1 | org.jivesoftware.smack.XMPPException$StreamErrorException: undefined-condition You can read more about the meaning of this stream error at http://xmpp.org/rfcs/rfc6120.html#streams-error-conditions
jicofo-1 | <stream:error><undefined-condition xmlns='urn:ietf:params:xml:ns:xmpp-streams'/><text>No stream features to proceed with</text></stream:error>Prosody logs were not supplied in #2336. These warning bodies come from a separate stable-7577 report, not confirmed stable-11248 output: [S3]
No available SASL mechanisms, verify that the configured authentication module 'token' is loaded and configured correctly
No stream features to offer on secure session. Check authentication settings.Cause
The root cause remains unknown. The report uses JITSI_IMAGE_VERSION=stable; a maintainer asked to remove it so the release Compose file controls the version. A moving tag makes the tested build uncertain, but the thread does not prove mixed images caused this failure. [S2]
For stable-11248, distinguish these candidates: [S2][S5][S6]
| Candidate | Evidence and limitation |
|---|---|
| Stale configuration or mounts | Maintainers asked about the new directories. Runtime config is regenerated, but copied input files and extra conf.d files can persist. Do not assume deleting the whole volume is required. [S2][S5] |
| Mixed releases | Confirm Compose defaults, overrides and created containers. stable is not a specific release pin. [S2][S7] |
| Authentication | Prosody and clients use JVB_AUTH_PASSWORD and JICOFO_AUTH_PASSWORD. Missing values have explicit startup errors. Wrong credentials or an unavailable auth mechanism require their own evidence. [S5][S6] |
| Prosody limits | Bandwidth limits and optional login/session rate limits are different mechanisms. No limiter error was shown in #2336. [S5][S8] |
PR #2309 adds ::1 to the rate-limit whitelist and is included in stable-11248. It is already present in that release, not a later fix for #2336. PROSODY_ENABLE_RATE_LIMITS defaults to 0 in the site template. Do not attribute every stream error to this limiter. [S4][S5]
Fix
Docker: stable-11248 diagnostic procedure
-
Capture all three services together. Run from your deployment project, using your normal Compose overlays: [S7]
Terminaldocker compose logs --since 10m --tail 200 prosody jicofo jvb docker compose images docker compose config --imagesKeep the earlier Prosody messages preceding the disconnect. Image lists do not expose service passwords; full rendered configuration can, so avoid publishing it unredacted. [S7]
-
Align files and images. Download the stable-11248 release archive and merge its Compose files with your local changes. Comment out
JITSI_IMAGE_VERSION=stableas the maintainer requested, or explicitly selectJITSI_IMAGE_VERSION=stable-11248. Inspect service-level image overrides too. stable-11248 remains the latest release checked on 2026-10-05. [S2][S4][S7]Expected core image references from
docker compose config --images, order may differ: [S7]Textghcr.io/jitsi/web:stable-11248 ghcr.io/jitsi/prosody:stable-11248 ghcr.io/jitsi/jicofo:stable-11248 ghcr.io/jitsi/jvb:stable-11248 -
Check the migrated directories. For upgrades from before stable-11146, create the handbook directories under your actual
CONFIGpath. Default path,~/.jitsi-meet-cfg: [S9]Terminalmkdir -p ~/.jitsi-meet-cfg/{web,prosody/config,prosody/prosody-plugins-custom,jicofo,jvb,jigasi,jibri,transcriber} mkdir -p ~/.jitsi-meet-cfg/storage/{jibri,prosody,transcripts,web} mkdir -p ~/.jitsi-meet-cfg/tmp/{web-crontabs,web-load-test} sudo chown -R 1000:1000 ~/.jitsi-meet-cfg/storage ~/.jitsi-meet-cfg/tmpWritable storage must be accessible to UID 1000. Prosody accounts now live under
${CONFIG}/storage/prosody, mounted at/var/lib/prosody; old accounts are copied only when that destination is empty. Preserve both account stores during diagnosis. [S5][S9] -
Check configuration and authentication. Inspect the generated files locally, not an old host-side generated file: [S5][S6]
Terminaldocker compose exec prosody ls -l /config /run/prosody/config/conf.d docker compose exec prosody prosodyctl --config /run/prosody/config/prosody.cfg.lua check configReview extra input configuration against the new template. The internal auth host, normally
auth.meet.jitsi, usesauthentication = "internal_hashed". Check that the JVB/Jicofo auth domain matches it. Preserve the existing service secrets in.env; verify each matches the corresponding client’s configuration and Prosody account. Do not rotate all passwords as an unexplained repair. [S5][S6]Missing passwords produce these exact Prosody startup messages: [S5]
TextFATAL ERROR: Jicofo auth password must be set FATAL ERROR: JVB auth password must be set -
Inspect limits only when supported by logs. Review
PROSODY_C2S_LIMIT,PROSODY_DISABLE_C2S_LIMIT,PROSODY_ENABLE_RATE_LIMITSand any local whitelist changes. Check the generated configuration against stable-11248, including::1. No proven replacement limit value or blanket disabling workaround exists for #2336. [S4][S5][S8] -
Apply the corrections in a maintenance window. Validate, pull and recreate the stack: [S7]
Terminaldocker compose config -q docker compose pull docker compose up -d --force-recreate docker compose imagesIn the last command, every core service’s
TAGshould bestable-11248. This checks created containers, whereasconfig --imageschecks intended configuration. [S7]
Debian/Ubuntu packages
For the package layout reviewed at release 11248, Docker image selectors and rootless volume migration do not apply. The package installer uses /etc/prosody/conf.avail/meet.example.com.cfg.lua for that domain. Inspect its auth host and modules, and correlate Prosody logs with the clients. [S10]
sudo prosodyctl check config
sudo tail -n 200 /var/log/prosody/prosody.logThe log path is Prosody’s documented file-logging example; confirm your configured sink before using it. Validate local changes before restarting through your system’s service manager. No Debian/Ubuntu package fix version was established by #2336. [S1][S11]
Verify
For stable-11248 Docker, repeat the image checks, then read fresh logs: [S7]
docker compose logs --since 5m prosody jicofo jvbOn successful service-account creation, the upstream registration script emits: [S6]
[register-setup] Focus user registered successfully
[register-setup] JVB user registered successfullyThese prove that registration commands succeeded, not that clients authenticated and stayed connected. Existing accounts can produce different registration output. Confirm no recurring stream failures and test a meeting at https://meet.example.com with three participants, which exercises the bridge. There is no universal success line established by #2336. [S1][S6][S12]
If it still fails
For stable-11248 Docker, temporarily set LOG_LEVEL=debug in .env, recreate Prosody and gather correlated logs. Restore the previous level afterwards. The template sends that level to the console. [S5][S7]
Provide image tags, redacted environment settings, mount locations and the earliest Prosody warning. State whether failure precedes authentication or follows a successful connection. These candidates need evidence before being called causes. [S1][S2][S5]
FAQ
Is stable-11248 definitely broken?
The upgrade failure is reported, but no general release defect was established. #2336 is open as of 2026-10-05. [S1]
Does the ::1 whitelist fix solve this?
It is already included in stable-11248. The thread does not link its failure to that limiter. [S4]
Should I delete the config volume?
No such fix was confirmed. Review copied configuration while preserving Prosody accounts and other persistent state. [S5][S9]
Does undefined-condition mean a wrong password?
Not by itself. The accompanying text and Prosody’s preceding messages are needed; an older report showed unavailable authentication mechanisms. [S1][S3]
Sources
[S1] Issue #2336, opened 2026-10-01, checked 2026-10-05, community report, still open.
[S2] Maintainer discussion, 2026-10-01, maintainer comments on Compose, directories and image selection.
[S3] Issue #1358, 2022-08-08, community report on stable-7577, historical Prosody warnings.
[S4] stable-11248 notes, latest release API, and PR #2309, August/September 2026, checked 2026-10-05, release note and source code.
[S5] stable-11248 Prosody startup, global template, site template, checked 2026-10-05, source code.
[S6] stable-11248 registration, JVB, Jicofo, checked 2026-10-05, source code.
[S7] stable-11248 Compose; Docker CLI config, images, logs, exec, pull, up, checked 2026-10-05, source code and official doc.
[S8] Prosody mod_limits, checked 2026-10-05, official doc.
[S9] Docker handbook, updating, and Coreutils manual, checked 2026-10-05, official doc.
[S10] Package Prosody installer, release 11248, checked 2026-10-05, source code.
[S11] Prosody checks and logging, checked 2026-10-05, official doc.
[S12] Jitsi Meet config.js, release 11248, checked 2026-10-05, source code, three-participant bridge switching.
Open questions
No confirmed root cause, Prosody log excerpt or successful repair was posted in #2336 by 2026-10-05. Mixed images, stale input, limits and passwords remain checks, not proven explanations. Source-reviewed; not tested on a live Jitsi server. [S1][S2]