唐小鸭
3b404e56c0
fix(replication): forward single-part object checksums as headers ( #7313 )
2026-09-07 01:17:24 +00:00
唐小鸭
4d1ce9618a
fix(scanner): pass dirty scopes to distributed scope resolution ( #7329 )
2026-09-07 07:42:17 +08:00
唐小鸭
14c99a994c
fix(filemeta): keep data dir of a version awaiting purge replication ( #7307 )
2026-09-07 05:30:44 +08:00
houseme
f6c2a9bfe0
test(scanner): cover overflow service cohort rotation ( #7324 )
2026-09-07 05:29:59 +08:00
houseme
640d7e0e3c
test(heal): cover MRF snapshot recovery bounds ( #7327 )
2026-09-07 05:29:25 +08:00
houseme
409ac3de66
test(scanner): cover reset cleanup process crash boundaries ( #7326 )
2026-09-07 05:29:14 +08:00
唐小鸭
2a63fcbea6
fix(replication): stop duplicate re-drives on own-version-id targets ( #7323 )
2026-09-07 05:29:00 +08:00
houseme
f4049598e4
feat(scanner): send scoped dirty usage acknowledgements ( #7322 )
2026-09-07 05:28:50 +08:00
cxymds
85849788af
chore(tier): remove remaining blanket lint allowances ( #7306 )
2026-09-07 05:27:29 +08:00
Henry Guo
975983abdd
feat(scanner): reuse clean local bucket prefixes ( #7208 )
2026-09-07 05:26:56 +08:00
唐小鸭
cf1c45eb91
test(replication): pin directory-marker null version and replication ( #7315 )
2026-09-06 19:26:09 +00:00
houseme
7de6ac82e1
test(scanner): cover reset cleanup across store reopen ( #7317 )
...
Add a real ECStore reopen regression for scanner usage-state reset cleanup boundaries. The fixture seeds each partially completed cleanup state, recreates the store, then verifies the reset resumes without rewriting the bootstrap intent or deleting unrelated metadata.
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 23:40:31 +08:00
houseme
1b1e590df7
test(scanner): verify quota state across reset and owner restart ( #7303 )
...
* test(scanner): verify quota state across reset and owner restart
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix: restore ILM transition and lifecycle validation (#7312 )
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
---------
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 23:26:01 +08:00
houseme
086ee8e48a
fix(scanner): require root publication proof before dirty ack ( #7297 )
...
* fix(scanner): require root publication proof before dirty ack
Bind ACK expectations to validated scan candidates and confirm the actual primary-root revision and readback. Retain saved outcomes and dirty responsibility when stronger evidence is unavailable. Isolate CAS attempt confirmation and invalidate proof after scope mutations.
Revalidate observed candidate reuse before issuing a new publication proof, preserve the exact validated authoritative baseline work digest, and settle fixture commit tails before stable maintenance scans. Keep scoped ACK production disabled.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix: restore ILM transition and lifecycle validation (#7316 )
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
---------
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 23:25:40 +08:00
Zhengchao An
22bff27aee
fix(storage): derive multipart identity from stored parts ( #7305 )
2026-09-06 22:04:15 +08:00
houseme
8a20498705
fix(heal): retain completed reports during clock rollback ( #7299 )
...
Treat a negative wall-clock age as zero without bypassing count or byte eviction. Cover canonical and alias queries, terminal outcomes, exact TTL expiry, and capacity limits during rollback.
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 21:28:22 +08:00
Zhengchao An
2baba1bda7
fix(scanner): preserve verified maintenance digest ( #7293 )
...
Co-authored-by: houseme <housemecn@gmail.com >
2026-09-06 21:20:58 +08:00
Zhengchao An
bf2ca9113f
test(scanner): settle fixture writes before activity baseline ( #7290 )
2026-09-06 21:20:46 +08:00
Zhengchao An
f474ea30d4
fix(admin): preserve decommission readiness error ( #7285 )
2026-09-06 21:20:32 +08:00
cxymds
002ac9544c
feat(ilm): add immutable legacy recovery exports ( #7283 )
...
* feat(ilm): add immutable legacy recovery exports
* feat(ilm): add legacy recovery disposition records (#7292 )
* fix(ilm): stabilize legacy recovery decode errors
* fix(admin): route recovery auth errors through gateway
* fix(ilm): resolve recovery disposition clippy errors
* fix(ilm): remove redundant recovery test clones
2026-09-06 21:20:16 +08:00
Zhengchao An
d74d970e24
fix(ecstore): retain namespace ownership during multipart commit ( #7282 )
2026-09-06 21:20:02 +08:00
Zhengchao An
cc15eae479
fix(lifecycle): allow multiple filter predicates without And wrapper ( #7298 )
2026-09-06 21:09:11 +08:00
Henry Guo
3d46ed312a
feat(scanner): reuse complete observed scan candidates ( #7206 )
2026-09-06 17:52:52 +08:00
Zhengchao An
3496277e7c
test(ecstore): drain source writes before corrupting shards ( #7291 )
2026-09-06 17:51:07 +08:00
cxymds
0b72f39023
fix(tier): avoid re-fencing published mutations ( #7274 )
2026-09-06 16:57:03 +08:00
Zhengchao An
30a0937a7d
fix(ecstore): retain single-delete physical namespace ownership ( #7287 )
2026-09-06 16:56:24 +08:00
houseme
5b962b6c58
feat(heal): expose compatible canonical v3 outcomes ( #7256 )
...
* feat(heal): expose compatible canonical v3 outcomes
Serialize the existing canonical heal outcome, retain the v3 summary vocabulary, and reject or conservatively adapt contradictory peer success responses. Preserve progress and bounded result cursors without treating legacy storage responses as repair proof.
Add optional SDK outcome and cursor support with shared Rust fixtures, pinned legacy Go decoder and mc polling checks, and explicit compatibility limits.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(madmin): box heal stop task status outcome
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
---------
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 16:46:42 +08:00
houseme
0ee5408b94
feat(scanner): preserve bounded bootstrap admission fairness ( #7260 )
...
feat(scanner): retain bounded bootstrap admission fairness
Keep a leader-local bounded cohort across scanner retries and preserve
waiting bucket priority during dirty arrivals and capacity overflow.
Order source permits in the dispatcher without changing result identity,
parent budgets, explicit cycle timing, or persistent coverage evidence.
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 16:45:57 +08:00
houseme
cb3100a252
fix(scanner): visit compacted subtrees during deep scans ( #7270 )
...
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 16:45:17 +08:00
houseme
3a4afe9b38
fix(heal): bound cross-page object retry delays ( #7273 )
...
Retain failed identities in an execution-local count and byte bounded window so healthy later pages can advance. Preserve retry jitter, deadlines, terminal accounting and pressure pacing, with deterministic head-of-line and capacity regressions.
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 16:44:59 +08:00
houseme
71859ff83c
fix(scanner): resume committed cleanup when scanning is disabled ( #7281 )
...
Run one supervised cleanup attempt for an existing operator reset, with
strict phase and revision checks under the original leader lock. Keep v3
reset authorization and responses unchanged, report deferred status, and
bound probe and shutdown waits without aborting in-flight reset ownership.
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 16:44:45 +08:00
houseme
cb72df269a
fix(heal): retain hints without verified repair receipts ( #7275 )
...
Stop task completion and legacy notices from discharging scanner retry hints. Preserve existing hints and their retry due time across admission observations, bound retry scheduling, and synchronize changed batches once even on cancellation.
Exercise the production MRF consumer, manager, event channel and scanner ledger. Document producer durability gaps without enabling successor activation or garbage collection.
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
2026-09-06 16:44:30 +08:00
houseme
1dddf357cd
test(scanner): add bounded cache cost microprofile ( #7261 )
2026-09-06 14:14:07 +08:00
houseme
395ba797fc
fix(admin): bound peer probe retries to one round deadline ( #7257 )
2026-09-06 14:13:47 +08:00
houseme
51893abfbf
feat(heal): pace running admin work at safe boundaries ( #7255 )
2026-09-06 14:13:35 +08:00
cxymds
f17f31a3df
feat(ilm): persist recovery controls for legacy tier journals ( #7252 )
2026-09-06 14:13:09 +08:00
Zhengchao An
1a88870809
fix(odm): preserve cursor compatibility and native source semantics ( #7238 )
2026-09-06 14:12:56 +08:00
唐小鸭
760c9d65be
fix(replication): close IAM snapshot, marker purge and broadcast gaps ( #7195 )
2026-09-06 14:12:25 +08:00
houseme
08283d1fdc
test(scanner): verify default scoped entry fallback walks ( #7241 )
2026-09-06 14:11:45 +08:00
houseme
6a323c3e91
test(heal): cover start retry and deadline outcome contracts ( #7242 )
2026-09-06 14:11:24 +08:00
Zhengchao An
1650f3c2a6
test(odm): verify global disable across restarts ( #7268 )
...
* test(odm): cover global disable across restarts
* test(odm): accept omitted V1 next marker
* test(odm): gate backfill GET until the crash completes
* test(odm): remove unused fault action import
* test(odm): assert GET gate suspension without network races
* test(odm): refresh verified Darwin E2E selection
2026-09-06 13:54:59 +08:00
Zhengchao An
d44244f60f
fix(admin): preserve metadata during export and target repair ( #7258 )
...
* fix(admin): reject incomplete metadata backups
* fix(admin): repair remote targets from locked disk state
* test(admin): fence target repair against source changes
* fix(admin): report unreadable XML in metadata exports
* test(admin): enable loopback in target repair fixtures
* refactor(admin): remove unused metadata getter forwards
* test(admin): box direct target repair futures
* test(admin): box target repair scenarios at env boundary
2026-09-06 12:18:00 +08:00
cxymds
3df39ef4d7
fix(scanner): separate write retries from movement backlog ( #7249 )
2026-09-06 10:51:46 +08:00
Zhengchao An
b0c73c1224
fix(ecstore): retain namespace owners through local disk completion ( #7245 )
...
* fix(ecstore): retain namespace owners through local physical tails
(cherry picked from commit a2f242463316e87604feadbdac5e4148140e72c0)
* test(ecstore): expose stale fsync group cleanup
* fix(ecstore): capture complete fsync worker guard
(cherry picked from commit 1dc90bb836e20ea9ee45d0a629a9201e20d231c4)
* fix(ecstore): preserve successor fsync group registration
(cherry picked from commit c7dfaad90526052e56c57dafffa4813bdcde46ca)
* test(ecstore): mark physical owner fixtures as inline
* test(ecstore): wait for namespace owner release before asserting
The namespace owner tests decided that ownership had ended when the Weak probe stopped upgrading or when the mutation lease could be reacquired. Both signals fire before the owner guard's Drop decrements the pending counter: Arc releases its strong count before running Drop, and the lease drops its locks before its owner field. The rio-v2 lane hit that window in undo_fresh_version_keeps_physical_namespace_owner_after_timeout.
Extend every drain wait to also require namespace_commits_pending() to be false, so the assertions observe the completed release instead of racing it.
2026-09-06 10:51:38 +08:00
houseme
54c11ef28b
test(scanner): bound segment observation diagnostics ( #7240 )
...
* test(scanner): bound segment observation diagnostics
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(scanner): observe committed fixture changes during walks
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(scanner): validate segment fixture metadata and off state
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
---------
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
Co-authored-by: overtrue <anzhengchao@gmail.com >
2026-09-06 10:51:30 +08:00
houseme
e99c41a9bf
test(scanner): verify restart evidence against tested builds ( #7232 )
...
* chore(deps): refresh scanner heal batch dependency baseline
Regenerate compatible lockfile selections before the next implementation
batch. Cargo upgrade leaves direct requirements unchanged.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(ecstore): remove duplicate local rename implementation
Keep the canonical commit module after concurrent storage changes merged.
The control-write and rollback changes are already present there.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* chore(deps): refresh profiling dependencies for the next batch
Update hotpath and its macro crate to the compatible patch release before
the next dependency-ready implementation tasks.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(deps): preserve supported hotpath focus expressions
Keep the profiler runtime before its regex-lite compatibility regression.
Track the opt-in validation required to remove this constraint in backlog.
Refs rustfs/backlog#2302 .
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(scanner): add bounded ABBA validation harness
Refs rustfs/backlog#2266 and rustfs/backlog#2240 .
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(scanner): verify real restart evidence before release gates
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(test): bind scanner evidence to execution and build identity
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* docs(test): use the nextest workspace report directory
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(test): reap ABBA leaders only after process-group cleanup
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(test): preserve inclusive ABBA thresholds
Use decimal boundary comparisons for ABBA ratio checks and cover exact documented p99, throughput, and P1 limits.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
---------
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
Co-authored-by: overtrue <anzhengchao@gmail.com >
2026-09-06 10:51:22 +08:00
houseme
fddecf0afe
test(scanner): diagnose raw enumeration across restarts ( #7228 )
...
* test(scanner): diagnose raw enumeration across process restarts
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(scanner): observe the canonical synthetic disk path
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(scanner): reject unobserved enumeration budget evidence
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(scanner): remove redundant disk path clone
* fix(app): keep list-through header import test-only
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
---------
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
Co-authored-by: overtrue <anzhengchao@gmail.com >
2026-09-06 10:51:14 +08:00
houseme
55fd73ed48
feat(heal): add pending legacy MRF migration staging ( #7219 )
...
* chore(deps): refresh scanner heal batch dependency baseline
Regenerate compatible lockfile selections before the next implementation
batch. Cargo upgrade leaves direct requirements unchanged.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(ecstore): remove duplicate local rename implementation
Keep the canonical commit module after concurrent storage changes merged.
The control-write and rollback changes are already present there.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* chore(deps): refresh profiling dependencies for the next batch
Update hotpath and its macro crate to the compatible patch release before
the next dependency-ready implementation tasks.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(deps): preserve supported hotpath focus expressions
Keep the profiler runtime before its regex-lite compatibility regression.
Track the opt-in validation required to remove this constraint in backlog.
Refs rustfs/backlog#2302 .
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* feat(heal): add explicit committed MRF snapshot reader
Refs rustfs/backlog#2263 and rustfs/backlog#2240 .
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* docs(heal): register legacy MRF inspection cleanup
State the compatibility removal condition on the source marker and in
the architecture cleanup register.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(heal): cover ambiguous complete legacy MRF replicas
Cover complete subset replicas, differing sets and unknown scope in both
disk orders, preserving all original journal evidence during inspection.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* feat(heal): stage conservative legacy MRF migration evidence
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(heal): reject incomplete migration lineage before staging
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(heal): validate migration retries against complete lineage
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(heal): keep reused MRF migration slots retryable
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* test(heal): cover source-change retry on reused MRF slots
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(heal): retain unmatched migration manifest evidence
---------
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
Co-authored-by: overtrue <anzhengchao@gmail.com >
2026-09-06 10:51:04 +08:00
houseme
1ae80c41ec
feat(heal): record canonical object and task outcomes ( #7218 )
...
* chore(deps): refresh scanner heal batch dependency baseline
Regenerate compatible lockfile selections before the next implementation
batch. Cargo upgrade leaves direct requirements unchanged.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(ecstore): remove duplicate local rename implementation
Keep the canonical commit module after concurrent storage changes merged.
The control-write and rollback changes are already present there.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* chore(deps): refresh profiling dependencies for the next batch
Update hotpath and its macro crate to the compatible patch release before
the next dependency-ready implementation tasks.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(deps): preserve supported hotpath focus expressions
Keep the profiler runtime before its regex-lite compatibility regression.
Track the opt-in validation required to remove this constraint in backlog.
Refs rustfs/backlog#2302 .
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* feat(heal): record bounded canonical object and task outcomes
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(heal): preserve cancellation and retry only failed listing pages
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(heal): preserve compatible listing EOF outcomes
Keep truncated heal listings without continuation tokens as complete compatibility EOFs and assert the canonical task outcome.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
* fix(heal): drop test locks before awaits
Limit synchronous mock mutex guards to pre-await scopes in canonical outcome tests.
Co-Authored-By: heihutu <heihutu@gmail.com >
Co-Authored-By: zhi22915 <qiuzgang@gmail.com >
---------
Co-authored-by: heihutu <heihutu@gmail.com >
Co-authored-by: zhi22915 <qiuzgang@gmail.com >
Co-authored-by: Zhengchao An <anzhengchao@gmail.com >
2026-09-06 10:50:56 +08:00
GatewayJ
9fc9b5e69c
fix(ecstore): align platform and test helper compilation ( #7214 )
...
Co-authored-by: Zhengchao An <anzhengchao@gmail.com >
2026-09-06 10:50:48 +08:00