安正超
434b71e569
feat(extension): add admin views ( #3386 )
2026-06-12 15:54:42 +08:00
安正超
1e7c376586
feat(targets): add extension schema adapter ( #3385 )
2026-06-12 15:27:55 +08:00
安正超
7d6d56a547
feat(extension): add schema contracts ( #3384 )
2026-06-12 15:07:17 +08:00
安正超
249a0b56ea
feat(targets): require plugin artifact attestations ( #3383 )
2026-06-12 14:13:41 +08:00
安正超
8df38ea12c
ci(docker): add release image scan report ( #3382 )
2026-06-12 13:11:59 +08:00
安正超
212a0913be
ci(release): emit sbom and provenance assets ( #3381 )
2026-06-12 12:56:02 +08:00
cxymds
4f954397d7
fix: support regular users in access key info ( #3285 )
...
* fix: support regular users in access key info
* refactor: extract access key identity helpers
* refactor: add typed access key identity model
* test: cover info access key identity contract
* test: cover derived access key response contracts
* fix: remove needless borrow in access key test
* fix: block fallback on explicit admin deny
* fix: restrict service account access key fallback
* fix: correct info access key identity handling
2026-06-12 12:02:43 +08:00
安正超
99e68f82a2
ci(audit): report unpinned workflow actions ( #3379 )
2026-06-12 11:33:23 +08:00
安正超
fc32b76c0e
fix: avoid mutating signed request headers ( #3378 )
2026-06-12 11:13:34 +08:00
安正超
559bf9d9d7
ci(audit): wire cargo deny supply-chain gate ( #3377 )
2026-06-12 11:11:40 +08:00
安正超
08c586d843
security(admin): reject unknown JSON ingress fields ( #3376 )
2026-06-12 10:21:50 +08:00
wood
9904a4f9eb
fix(obs): fix grafana layout and wrong version of tempo ( #3368 )
...
* fix(obs): fix grafana dashboard layout errors
Signed-off-by: w0od <dingboning02@163.com >
* fix(docker): align the correct tempo version
Signed-off-by: w0od <dingboning02@163.com >
---------
Signed-off-by: w0od <dingboning02@163.com >
Co-authored-by: houseme <housemecn@gmail.com >
2026-06-12 09:27:32 +08:00
Henry Guo
19ff378e9b
fix(scanner): preserve newer usage snapshots ( #3370 )
...
* fix(scanner): preserve newer usage snapshots
* fix(table-catalog): require namespace locking backend
---------
Co-authored-by: Henry Guo <marshawcoco@users.noreply.github.com >
2026-06-12 07:06:08 +08:00
Henry Guo
51ef87ed19
fix(heal): recover renewed disk health checks ( #3366 )
...
* fix(heal): recover renewed disk health checks
* test(heal): cover replaced remote disk rebuild
---------
Co-authored-by: Henry Guo <marshawcoco@users.noreply.github.com >
Co-authored-by: houseme <housemecn@gmail.com >
2026-06-12 07:05:52 +08:00
安正超
c3055f9335
security(kms): require explicit dev defaults opt-in ( #3369 )
...
* security(kms): require explicit dev defaults opt-in
* test(kms): satisfy clippy dev defaults checks
2026-06-12 07:05:20 +08:00
安正超
a85cc0354c
refactor(storage-api): remove namespace lock from StorageAPI ( #3365 )
...
* refactor(storage-api): remove namespace lock from StorageAPI
* test(scanner): wait for runtime budget cancellation
---------
Co-authored-by: loverustfs <hello@rustfs.com >
2026-06-11 22:42:12 +08:00
houseme
82af181dcf
refactor(logging): unify governance runtime events ( #3367 )
2026-06-11 22:26:02 +08:00
GatewayJ
b5676dcc8e
fix(table-catalog): support PyIceberg REST commits ( #3342 )
...
Co-authored-by: houseme <housemecn@gmail.com >
2026-06-11 22:22:13 +08:00
安正超
7146c893cb
refactor(storage-api): remove legacy bucket DTO re-export ( #3364 )
2026-06-11 21:24:56 +08:00
houseme
0a987d870b
refactor(logging): reduce runtime noise ( #3363 )
2026-06-11 19:49:01 +08:00
安正超
a0b6636b61
refactor(config): remove legacy accessor re-export ( #3362 )
2026-06-11 19:32:57 +08:00
Henry Guo
2e3c777307
fix(heal): skip transient usage cache heal errors ( #3359 )
2026-06-11 19:16:32 +08:00
安正超
b4524033e3
refactor(config): move global config accessors ( #3360 )
2026-06-11 19:16:02 +08:00
安正超
ed3851782c
refactor(config): remove legacy model re-export ( #3357 )
2026-06-11 18:09:01 +08:00
houseme
f6137f9f77
refactor(auth): tighten startup log redaction ( #3358 )
2026-06-11 18:08:41 +08:00
安正超
69549634ea
refactor(config): migrate scanner config consumer ( #3356 )
2026-06-11 17:30:26 +08:00
houseme
704c95a22d
refactor(server): consolidate request transport logs ( #3354 )
2026-06-11 17:07:02 +08:00
安正超
ca58d7f0ec
refactor(config): migrate server config consumers ( #3353 )
2026-06-11 17:04:50 +08:00
安正超
2205991180
refactor(config): extract server config model ( #3351 )
2026-06-11 16:11:17 +08:00
houseme
7d38b0cf90
refactor(obs): unify local and otlp log output ( #3352 )
...
wip(obs): start lg-002 output unification
2026-06-11 16:10:54 +08:00
houseme
8d337c4e87
feat(obs): add logging redaction guard rails ( #3349 )
...
* feat(obs): add logging redaction guard rails
* chore(docs): keep logging plans out of lg-001 pr
* test(obs): guard against unmasked access key logs
* test(obs): enforce masked access key log patterns
2026-06-11 15:24:32 +08:00
安正超
dd50359161
refactor(storage): narrow table catalog bounds ( #3350 )
2026-06-11 14:32:28 +08:00
安正超
2ead90d31b
fix(security): add authorization check to ListRemoteTargetHandler (GHSA-796f-j7xp-hwf4) ( #3346 )
...
fix(security): add authorization check to ListRemoteTargetHandler
ListRemoteTargetHandler only verified that request credentials existed
but did not check whether the caller has replication or administrator
permissions. This allowed any authenticated user to list remote
replication target configuration, potentially leaking remote target
credentials (accessKey, secretKey, sessionToken).
Add validate_replication_admin_request() call with
GetBucketTargetAction, consistent with the other replication admin
handlers that already perform this check.
Fixes: GHSA-796f-j7xp-hwf4
Co-authored-by: houseme <housemecn@gmail.com >
2026-06-11 05:50:14 +00:00
安正超
d60deba9b6
fix(security): add IAM authorization to FTP read/metadata/cwd handlers (GHSA-3g29-xff2-92vp) ( #3347 )
...
fix(security): add IAM authorization to FTP read/metadata/cwd handlers
The FTP frontend's get() (RETR), metadata() (SIZE/MDTM), and cwd()
(CWD) handlers dispatched directly to the storage backend without
calling authorize_operation(). This allowed any authenticated FTP user,
including those with explicit Deny policies, to read arbitrary objects
and probe bucket existence regardless of IAM policy.
Add authorize_operation() calls matching the pattern used by the
write-path handlers (put, del, list, rmd) and the WebDAV driver:
- get(): S3Action::GetObject
- metadata() for files: S3Action::HeadObject
- metadata() for directories: S3Action::HeadBucket
- cwd(): S3Action::HeadBucket
Fixes: GHSA-3g29-xff2-92vp
Co-authored-by: houseme <housemecn@gmail.com >
2026-06-11 05:48:53 +00:00
安正超
d4ee44f49f
refactor(scanner): narrow cache storage bounds ( #3348 )
2026-06-11 13:52:35 +08:00
安正超
2f7cc7cb9e
refactor(storage): narrow resync metadata bounds ( #3345 )
2026-06-11 04:41:15 +00:00
houseme
ee96e194a3
build(deps): bump s3s for header parsing fix ( #3344 )
2026-06-11 04:28:36 +00:00
houseme
a49c6b4c2e
fix(logging): clarify recovery and metacache warn messages ( #3341 )
...
* fix(logging): clarify recovery and metacache warn messages
Clarify cached gRPC connection eviction messages so they describe automatic reconnection instead of implying a persistent cluster fault.
Retitle metacache resolution logs to remove the misleading decommission_pool prefix and demote routine reconciliation traces to debug while preserving actionable warning paths.
* fix(logging): avoid overpromising reconnect success
2026-06-11 04:19:22 +00:00
Henry Guo
7191a3abae
docs(scanner): document runtime scanner controls ( #3339 )
...
* docs(scanner): document runtime scanner controls
* docs(scanner): split English and Chinese README
---------
Co-authored-by: Henry Guo <marshawcoco@users.noreply.github.com >
Co-authored-by: majinghe <42570491+majinghe@users.noreply.github.com >
2026-06-11 12:04:34 +08:00
安正超
686068d8bd
refactor(storage): narrow metadata bounds ( #3343 )
2026-06-11 12:04:02 +08:00
安正超
6b86e3875c
refactor(storage): remove old admin surfaces ( #3340 )
2026-06-11 11:28:09 +08:00
安正超
87968275a7
refactor(storage): route maintenance inventory reads ( #3337 )
2026-06-11 10:32:48 +08:00
安正超
f325b9f714
refactor(ecstore): route admin read internals ( #3336 )
2026-06-11 08:43:42 +08:00
安正超
94c53af264
refactor(storage): use admin API for observability reads ( #3335 )
2026-06-11 08:13:15 +08:00
安正超
8ae0cad667
refactor(admin): use storage admin reads ( #3334 )
2026-06-11 07:48:38 +08:00
安正超
b48d7b1fa5
refactor(admin): use storage admin info ( #3333 )
2026-06-11 07:12:35 +08:00
安正超
8a90bda16a
refactor(admin): use storage admin drive counts ( #3332 )
2026-06-11 06:36:18 +08:00
安正超
4b1714438e
feat(storage-api): bind ecstore admin contract ( #3331 )
2026-06-11 05:49:14 +08:00
Henry Guo
474fab5097
fix(table-catalog): validate committed metadata identity ( #3327 )
...
* fix(table-catalog): validate committed metadata identity
* fix(table-catalog): preserve legacy metadata identity commits
---------
Co-authored-by: Henry Guo <marshawcoco@users.noreply.github.com >
2026-06-10 16:49:06 +00:00
Henry Guo
91f80a5585
feat(scanner): expose lifecycle transition status ( #3326 )
...
Co-authored-by: Henry Guo <marshawcoco@users.noreply.github.com >
2026-06-10 16:45:02 +00:00