Feng Ruohang 236e163c0b fix: repair an undecodable SSE-C replica on retransmit
PutObjectHandler's precondition callback ran DecryptObjectInfo on the
stored object before checkPreconditionsPUT, so an authenticated raw
SSE-C replica overwrite was rejected when the stored version could not
decrypt. A replica a pre-fix destination (issue #109) left as
compress(ciphertext) or a re-encrypted body has an invalid decrypted
length, so DecryptObjectInfo returned errObjectTampered and the
retransmission that repairs it never ran -- the version stayed damaged
through resync. #134's raw-replica exemption only covered the
version/ETag duplicate check inside checkPreconditionsPUT, one step too
late.

Skip the stored object's decryption precondition only for a PURE raw
SSE-C replica overwrite (a trusted SSE-C replica write with no public
precondition), keyed on the incoming request's restored SSE-C metadata,
the same predicate checkPreconditionsPUT uses. Such a write fully
replaces the object, so requiring the damaged stored version to decrypt
is both wrong and unnecessary. A conditional request keeps the check:
DecryptObjectInfo also normalizes the stored sealed ETag to the
client-visible one, and If-Match/If-None-Match must compare against
that, not the sealed ETag -- skipping it for every replica inverted both
conditions. Ordinary writes and non-SSE-C replicas are unchanged.

Adds red/green regressions: a raw retransmit over a version staged as an
undecodable body returns 500 XMinioObjectTampered before this change and
200 with full customer-key recovery after; and a conditional replica PUT
(If-Match / If-None-Match) on the client-visible ETag is honoured rather
than inverted. Fixes the single-PUT compression-damage recovery gap in

Signed-off-by: Feng Ruohang <rh@vonng.com>
#120.
2026-09-07 00:11:04 +08:00
2021-04-23 11:58:53 -07:00
2026-09-04 19:21:26 +08:00

Silo

S3-compatible object storage — a MinIO fork maintained by PGSTY

Website · Documentation · Download · Release Notes · Compatibility · Manifesto · Security · 中文

Website GitHub Release Docker Pulls Go Version License

Important

PGSTY Silo (hereinafter “Silo”) is an independent, community-maintained fork of the open-source MinIO server, published by Pigsty from pgsty/silo. It is not affiliated with, endorsed by, or sponsored by MinIO, Inc. “MinIO” is used only to identify the upstream project and compatibility lineage.

Note

Renamed from pgsty/minio to pgsty/silo, default branch mastermain, on 2026-08-06. Artifacts under the original MinIO identity stay published on the archived minio branch and in releases up to RELEASE.2026-08-04T00-00-00Z.

Overview

PGSTY SILO keeps one maintained release line of the open-source MinIO server alive after upstream ended community distribution: builds, packages, multi-arch images, security fixes, and the full web console. Pigsty runs it in production as its PostgreSQL backup repository.

It follows one rule — the product and its delivery surfaces are renamed; the protocol and your data are not. Everything else lives on silo.pgsty.com.

Related: pgsty/mc client (shipped as mcli) · pgsty/silo-console · pgsty/silo-pkg · pgsty/pigsty

Silo Console

Quick Start

docker run -d --name silo -p 9000:9000 -p 9001:9001 \
  -e MINIO_ROOT_USER=minioadmin \
  -e MINIO_ROOT_PASSWORD=change-me-long-password \
  -v "$PWD/data:/data" \
  docker.io/pgsty/silo:latest server /data --console-address ":9001"

Silo Console

Console on http://localhost:9001, S3 API on http://localhost:9000. The image bundles the client as mcli:

docker exec silo mcli alias set local http://127.0.0.1:9000 minioadmin change-me-long-password
docker exec silo mcli mb local/demo && docker exec silo mcli ls local

Warning

For production, pin a release, use unique credentials and TLS, monitor the service, keep independent backups, and test recovery. Start from the documentation.

Install

Method Where
Container pgsty/silo, multi-arch for linux/amd64 and linux/arm64
Binaries GitHub Releases — Linux, macOS, Windows on amd64 and arm64
Packages RPM, DEB, and APK, also via the Pigsty repository
Kubernetes Helm chart, see Download & Install
Source go build -o silo . && ./silo --version

Every release ships checksums, SPDX SBOMs, Sigstore-signed manifests, and GitHub build attestations. Installation methods and verification commands are documented at Download & Install; migrating from upstream MinIO — taking over an existing minio.service and its /etc/default/minio, and keeping data ownership stable with a /etc/systemd/system/silo.service.d/10-legacy-user.conf drop-in — is covered by the migration guide and the binary & service notes.

Compatibility

The S3 API, MINIO_* variables, minio_* metrics, x-minio-* headers, /minio/* routes, the github.com/minio/* import paths, and the on-disk format (including .minio.sys) are preserved and held in place by a CI compatibility check. Only Silo-owned delivery surfaces change: the silo executable, package, service, Helm chart, and container image — no minio binary alias is installed.

Every divergence from upstream is listed in the code-verified compatibility audit. Treat each release as a downstream upgrade: pin versions, read the release notes, and keep a rollback path.

Security & Contributing

Report vulnerabilities privately as described in SECURITY.md; every fix ships with a public advisory. Contributions are accepted inbound=outbound under AGPL-3.0-or-later with no CLA — only DCO sign-off (git commit -s) is required; see CONTRIBUTING.md.

Contributors

The cards highlight community changes merged into main; the avatar wall includes every other community member who has opened an issue or pull request.

h5vx
@h5vx

Per-bucket CORS · #71
ycjlin
@ycjlin

Missing-bucket listing · #37
Dansyuqri
@Dansyuqri

Multipart checksum type · #57
pinginfo
@pinginfo

Notification streaming · #34
ZouhairCharef
@ZouhairCharef

CVE-2026-34986 · #18
mfredenhagen
@mfredenhagen

CVE-2026-39883 · #19
waterkip
@waterkip

Documentation links · #41

magicxor davinkevin lem21h sulin37392 metaneutrons mrjavadseydi mosesdd Xavier-777 jiadzh TLINDEN AntonOfTheWoods zylpsrs nsanitate makinikm spaceg00se-r heroes1412 vampywiz17 chalukyaj cbornet jvasile Kesavaambati redfoxfox kuldeep-link11 meesudzu pmezhuev kh0mka bagutzu liuhaodongliu990-cmyk sargarass mumu-lab

GitHub does not generate a contributor graph for forks, so CONTRIBUTORS.md — not the Insights page — is this project's attribution record. It names all 37 community contributors alongside the change or report they contributed.

Background

Upstream wound down its community edition: the web console was cut back to a stub, prebuilt community binaries stopped, and the community repository was archived. Silo exists to keep those deployments running. The fork is a means, not an identity — if upstream restores its community edition, we will narrow our scope and offer the fixes back.

The Manifesto is the project's public commitment in eleven articles, under one discipline: every article is either something already done with public evidence, or something explicitly refused. In short:

  • Compatibility contract — the protocol and your data do not change, and every release documents its tested rollback target and path.
  • The license cannot change — AGPLv3, no CLA, no copyright aggregation; nobody here, ourselves included, holds enough copyright to relicense on everyone else's behalf.
  • The never list, append-only — no paywalling existing features, no registration wall on downloads, no telemetry (upstream's phone-home paths are removed outright), no CLA, no license change, no trademark enforcement against normal use.
  • Security and release discipline — a public advisory for every fix, and a release every one to two months, at most a quarter apart. Judge both against the public record.

Essays: MinIO Is Dead · Who Takes Over? · Long Live MinIO · Promise Kept

License & Trademark

Silo is AGPL-3.0-or-later, derived from minio/minio with upstream copyright and third-party notices preserved in NOTICE and CREDITS. MinIO is a trademark of MinIO, Inc.; the name is used here only to identify the upstream project and compatibility lineage.

Details: license · attribution · trademark

S
Description
No description provided
Readme AGPL-3.0 145 MiB
Languages
Go 98.8%
Shell 1%
Makefile 0.1%