Files
minio/CHANGELOG.md
T
Feng Ruohang 1cf529ce8a fix(storage): reconcile ordinary version DELETE across pools
Delete every copy of an explicitly addressed UUID, null version or delete
marker under the pool lock. Preserve retention and replication callbacks,
report unreadable pools and cleanup failures, and keep movement, incoming
replication, expiration and free-version cleanup on their existing paths.

Retain the separately developed general DELETE repair and replace its
access-mover-only coverage with a real interrupted rebalance copy followed
by HTTP deletion. Cover unqualified directory-marker DELETE and document
the existing pool-order-dependent 503 behavior that this makes consistent.

Signed-off-by: Feng Ruohang <rh@vonng.com>
2026-09-15 11:27:01 +08:00

5.4 KiB

Changelog

Unreleased — main as of 2026-09-13

The coordinated source is merged through 5d955b5b7444f8a3ab550ce92713607998f89c0d. The latest published Server remains 20260903. These changes are not in its binaries, packages or images. See the component matrix and complete commit range.

Authorization and security

  • Reject unsigned x-amz-* request headers that could turn a signed PUT into a copy of another object accessible to the signer (SN-2026-011). The latest public Server is affected; the fix is on main. See the advisory ledger.
  • Align signed request fields with policy conditions and enforce header-only presigned payload checksums. See the signed-header review.
  • Breaking policy semantics: separate self-service admin:ChangeMyPassword from admin:CreateUser. Built-in read-only policies follow the split. Preserve both denies if the previous combined restriction must survive upgrades or rollback. Saved policies are not rewritten. Deploy with the matching Console and pkg; see the migration guide.

Object storage and replication

  • Reconcile ordinary single-object version DELETE across all pools, including null versions, delete markers and unqualified directory-marker DELETE. This prevents movement leftovers from surviving a successful response. Unreadable pools now consistently return 503 instead of depending on pool traversal order; this extends the existing failure surface. Retry after recovery. Cleanup failures also return an error. Batch deletion already fans out across pools; replication and scanner cleanup keep their existing contracts. See scope and limitations.

  • Remove the opt-in GET-frequency pool-tiering feature from PR #60, including its tracker, mover, scanner hooks, configuration, XML actions and metrics. Accept and ignore retired configuration/XML and preserve ordinary statistics when reading v9 caches. See migration notes.

  • Preserve the independent multi-pool write, metadata, healing and conditional deletion fixes from PR #178, including shared remote-tier reference protection.

  • Enforce If-Match on DELETE, preserve retention and independently ordered Object Lock/tag updates, and correctly retransmit encrypted replicas.

  • Preserve plaintext part sizes and raw SSE-C replicas; prevent SSE-C compression, honor key-rotation checksums, and complete attributes pagination.

  • Repair federated CopyObject checksums, destination timestamps, reserved metadata, encrypted-object forwarding, legal hold and KMS context.

  • Make resync counters, target selection, cancellation and worker lifetimes reflect actual work; complete delete-marker purges and report bounded MRF drops.

  • Converge bucket metadata with deterministic source state, deletion tombstones, creation time recovery and diagnostics. The mixed-version export gate requires coordinated upgrades before tombstones are exported. See the #77 record.

  • Include per-bucket CORS in metadata export/import, close metadata publication and logger races, and report effective bucket quotas in metrics.

Console, dependencies and delivery

  • Restore embedded Console login over loopback TLS, trusted-proxy handling and all four WebSocket connection limits. Preserve Go TLS defaults across transports.
  • Directly require github.com/pgsty/silo-pkg/v3 v3.14.0; select Console v0.0.0-20260913015128-417559bb2c97 and MC v0.0.0-20260913012246-4f609a4da3bb with explicit PGSTY replacements.
  • Pin upstream minio-go v7.3.1-0.20260910142817-60bd07042d49; refresh Go x/* modules and security fixes including bounded AMQP frame handling. Keep Go 1.27.1 and go-systemd v22.6.0's NetBSD compatibility replacement.
  • Refresh container base digests and build static curl 8.22.0 from verified source for both Linux architectures. Pin the actual mcli 20260913 archives and hashes. Helm's client image follows that release; its Server image still names the latest published Server 20260903.

The dependency update passed the final candidate's Go, vulnerability and Test Release workflows; native curl builds passed on both architectures. A local ARM64 image passed startup, health, S3 transfer and embedded Console checks. These checks do not publish a Server tag or production image and do not replace cluster upgrade/rollback acceptance for the next release. Dated investigations retain the exact source and runtime boundaries they tested.

RELEASE.2026-09-03T13-18-01Z

Published source: 9b11dc9469e650815b775cb47b039610644f5da4. Complete release notes · GitHub release

This release ships Go 1.27.1, silo-pkg v3.13.2, upstream minio-go 0e78d3f18efe, mcli 20260903 and embedded Console source 464a59d73ada (v2.3.0 version identity). Installing the newer standalone mcli or Console does not replace components inside this existing Server binary or image.

Earlier releases: release archive.