houseme
583a23bdf2
fix(ecstore): replace panic-driven pool and set stubs ( #3753 )
...
* fix(ecstore): replace panic-driven pool and set stubs
* test(runtime): tolerate restricted local bind checks
* fix(ecstore): remove remaining trait stub placeholders
* fix(ecstore): tighten trait stub follow-up semantics
* chore: ignore local worktrees
* chore: update layer dependency baseline for resolve_* context entries
Add 7 accepted infra->app dependency entries introduced by recent
refactoring PRs (#3770 , #3771 , #3772 ) that route global state lookups
through app::context::resolve_* functions.
Co-Authored-By: heihutu <heihutu@gmail.com >
---------
Co-authored-by: heihutu <heihutu@gmail.com >
2026-06-23 12:31:17 +08:00
Zhengchao An
30559f7e1b
refactor: collapse test fuzz ecstore thin bridges ( #3765 )
2026-06-23 07:04:51 +08:00
Zhengchao An
198fd4f150
refactor(runtime): route RustFS runtime consumers through storage owner ( #3756 )
2026-06-23 05:17:56 +08:00
Zhengchao An
6da61b44e5
refactor: expose remaining external owner symbols ( #3751 )
2026-06-22 23:35:50 +08:00
Zhengchao An
88a87b3e8f
refactor: centralize external ECStore facade aliases ( #3746 )
2026-06-22 20:37:13 +08:00
Zhengchao An
d3796d6c10
refactor: remove external owner compat bridges ( #3741 )
2026-06-22 18:28:35 +08:00
Zhengchao An
539c68778d
refactor: remove standalone compat bridge modules ( #3740 )
2026-06-22 17:35:58 +08:00
安正超
cca9e83a8b
refactor: use relative standalone compat consumers ( #3734 )
2026-06-22 15:07:58 +08:00
houseme
cc6909b08b
fix(iam): verify sts temp-user persistence ( #3722 )
2026-06-22 13:54:57 +08:00
安正超
de158743c3
refactor: split compat facade imports ( #3716 )
2026-06-22 09:53:22 +08:00
安正超
d39815470e
refactor: prune consumer storage compat paths ( #3704 )
2026-06-22 02:31:30 +08:00
安正超
0985225448
refactor: consolidate ecstore public facade ( #3678 )
...
* refactor: expand ecstore compatibility facade
* test: enforce ecstore api facade imports
* refactor: hide legacy ecstore layout modules
* refactor: hide ecstore facade root modules
2026-06-21 09:09:11 +08:00
安正超
9b3fda9e30
refactor: route ecstore public surfaces through api ( #3673 )
2026-06-21 05:23:23 +08:00
安正超
08b8f58e64
refactor: prune notify ecstore object alias ( #3620 )
2026-06-19 20:11:56 +08:00
安正超
54ffbedbc8
refactor: remove ecstore operation compat facades ( #3608 )
2026-06-19 17:01:12 +08:00
安正超
b14e49e84e
refactor: narrow IAM and Swift compatibility surfaces ( #3587 )
...
* refactor: narrow IAM and Swift compatibility surfaces
* refactor: narrow heal and scanner compatibility surfaces (#3588 )
* refactor: narrow RustFS runtime compatibility surfaces (#3591 )
2026-06-19 03:06:57 +08:00
安正超
205f964dc5
refactor: tighten storage compat store_api aliases ( #3582 )
...
* refactor: collapse storage compat store_api modules
* chore: guard storage compat store_api aliases
2026-06-18 22:50:02 +08:00
安正超
c28fee0013
refactor: continue storage api contract cleanup ( #3580 )
...
* refactor: move delete object contracts to storage api
* refactor: narrow store api compatibility exports
* refactor: route table catalog test through storage compat
2026-06-18 22:42:02 +08:00
安正超
7b0cb9e725
refactor: prune storage compatibility re-export allowances ( #3579 )
...
* refactor: prune storage compatibility re-export allowances
* fix: reject whitespace-padded dot path segments
2026-06-18 21:14:24 +08:00
安正超
f3fcdd4ba2
refactor: narrow remaining storage compatibility exports ( #3578 )
2026-06-18 19:18:32 +08:00
安正超
08371a6e09
refactor: narrow storage compatibility exports ( #3576 )
2026-06-18 18:31:14 +08:00
安正超
c098184c49
refactor: clean runtime and test storage boundaries ( #3573 )
...
* refactor: clean runtime observability select boundaries
* refactor: clean test harness fuzz storage boundaries
2026-06-18 18:09:25 +08:00
安正超
0e7e2660bb
refactor: clean remaining storage DTO imports ( #3568 )
2026-06-18 14:44:46 +08:00
安正超
24443c829d
refactor: clean shared list operation consumers ( #3563 )
2026-06-18 11:57:46 +08:00
安正超
3fb4cb3d65
refactor: move list operations contract ( #3550 )
2026-06-18 08:48:18 +08:00
安正超
919deeb816
refactor: move object option helper contracts ( #3521 )
2026-06-17 22:56:10 +08:00
cxymds
5b36ef5556
fix(decommission): persist progress adaptively ( #3497 )
...
Persist decommission progress after either the existing time interval or a migrated-item threshold, and flush progress baselines after bucket and terminal-state saves.
Also stabilize the OIDC discovery mock used by the pre-commit gate.
2026-06-17 08:17:59 +08:00
cxymds
d094d91925
fix(site-replication): harden service account sync ( #3500 )
2026-06-16 21:20:13 +08:00
houseme
e8012bd1ba
refactor(logging): normalize admin telemetry and error messages ( #3430 )
2026-06-14 13:27:10 +08:00
安正超
b4524033e3
refactor(config): move global config accessors ( #3360 )
2026-06-11 19:16:02 +08:00
安正超
ca58d7f0ec
refactor(config): migrate server config consumers ( #3353 )
2026-06-11 17:04:50 +08:00
安正超
a73c90c811
security: redact IAM and target debug secrets ( #3306 )
2026-06-10 09:03:50 +08:00
Alexander Kharkevich
528c3278b7
fix(iam): allow colons and dots in STS claim policy names ( #3164 )
...
`is_safe_claim_policy_name` rejected any character other than
`[a-zA-Z0-9_-]`, silently dropping policy names containing colons.
This breaks Kubernetes workload identity where `claim_name=sub`
resolves to `system:serviceaccount:<namespace>:<sa-name>` — a valid
policy name that can be created via the admin API but is then
unreachable during STS session authorization.
Add `:` and `.` to the allowed character set. These characters are:
- Used in K8s service account `sub` claims (colons)
- Used in Java/DNS-style group names from OIDC providers (dots)
- Already accepted by the `add-canned-policy` admin API endpoint
Require at least one alphanumeric character to prevent meaningless
names (`.`, `..`, `-`, `_`, `:`, etc.) from resolving.
Still rejected: `/`, `\`, whitespace, `$`, `;`, `{`, `}` and other
chars that could enable path traversal or injection.
Signed-off-by: Alexander Kharkevich <alex@mara.com >
Co-authored-by: houseme <housemecn@gmail.com >
Co-authored-by: 安正超 <anzhengchao@gmail.com >
Co-authored-by: loverustfs <hello@rustfs.com >
Co-authored-by: GatewayJ <835269233@qq.com >
2026-06-04 03:39:50 +00:00
Alexander Kharkevich
ce6fcf39b1
feat(oidc): add HIDE_FROM_UI option to exclude providers from console login ( #3162 )
...
Add `RUSTFS_IDENTITY_OPENID_HIDE_FROM_UI[_<SUFFIX>]` setting that
removes a provider from the login page while keeping it fully
functional for STS AssumeRoleWithWebIdentity and site-replication.
Changes:
- Add `hide_from_ui: bool` to `OidcProviderConfig`
- Add `list_visible_providers()` that filters hidden providers
(used by console login and /v3/oidc/providers endpoint)
- Keep `list_providers()` unfiltered for site-replication/admin config
- Extract `normalize_provider_config(config) -> config` to deduplicate
field normalization (accepts the struct directly, not 18 parameters)
- Add `parse_enable_state()` helper for consistent EnableState parsing
- Plumb through admin API request structs (`#[serde(default)]`)
- Expose in `OidcConfigView` for admin GET config round-trip
- Persist via `upsert_persisted_provider_config()`
Note: adding `hide_from_ui` to the public `OidcProviderConfig` struct
is a source-level change for code constructing it with struct literals.
This is acceptable for the current pre-1.0 release cycle.
Signed-off-by: Alexander Kharkevich <alex@mara.com >
Co-authored-by: GatewayJ <835269233@qq.com >
2026-06-03 13:37:44 +00:00
GatewayJ
c257043b63
fix(iam): serialize IAM cache writes ( #3105 )
...
* fix(iam): serialize IAM cache writes
* fix(iam): timestamp rebuilt group memberships
* fix(iam): publish cache updates atomically
* fix(iam): reuse policy cache snapshots
* fix(iam): commit missing user notification cache updates atomically
* fix(iam): remove unused cache membership rebuild wrapper
---------
Co-authored-by: 季宏伟 <jihongwei@jihongweis-MacBook-Pro.local >
Co-authored-by: houseme <housemecn@gmail.com >
2026-05-29 08:02:42 +00:00
GatewayJ
8d20e89bf8
fix(iam): avoid stale cache replacement on walk errors ( #3094 )
...
* fix(iam): avoid stale cache replacement on walk errors
* fix(iam): guard full reload cache commits
---------
Co-authored-by: houseme <housemecn@gmail.com >
Co-authored-by: loverustfs <hello@rustfs.com >
Co-authored-by: 季宏伟 <jihongwei@jihongweis-MacBook-Pro.local >
2026-05-28 09:54:06 +00:00
houseme
3d2449872a
refactor(credentials): derive RPC secret fallback and remove IAM keygen duplication ( #3079 )
...
* refactor(credentials): derive rpc secret and remove iam keygen
* fix(credentials): reject default access key RPC secret
* test(credentials): align RPC fallback and add keygen coverage
2026-05-25 11:05:58 +00:00
安正超
8a501846f4
test(iam): cover mixed STS claim policy names ( #2932 )
2026-05-12 10:39:53 +00:00
GatewayJ
b2ba2e5bb3
iam: handle sts claim policy names ( #2902 )
...
Co-authored-by: cxymds <Cxymds@qq.com >
2026-05-12 07:10:42 +00:00
houseme
c90bfe2b23
fix(ecstore): harden runtime read-path quorum handling ( #2872 )
2026-05-08 09:56:39 +00:00
Henry Guo
03045ff2e6
fix(iam): keep error state on initial load failure ( #2846 )
...
Signed-off-by: houseme <housemecn@gmail.com >
Co-authored-by: houseme <housemecn@gmail.com >
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com >
Co-authored-by: loverustfs <hello@rustfs.com >
Co-authored-by: 安正超 <anzhengchao@gmail.com >
2026-05-08 08:26:01 +00:00
weisd
a995ec0315
fix(iam): preserve portable IAM storage and derived auth ( #2713 )
2026-04-28 05:57:10 +00:00
GatewayJ
09be06a4d2
fix(ecstore): log walk failures in IAM listing path ( #2705 )
...
Co-authored-by: GatewayJ <8352692332qq.com>
Co-authored-by: loverustfs <hello@rustfs.com >
Co-authored-by: houseme <housemecn@gmail.com >
2026-04-27 14:13:40 +00:00
安正超
159ddd5bac
fix: honor bucket-scoped ListBucket policies with s3:prefix ( #2707 )
...
Co-authored-by: houseme <housemecn@gmail.com >
2026-04-27 14:13:22 +00:00
GatewayJ
cfbd094bc4
fix(iam): propagate cache miss load failures ( #2692 )
...
Co-authored-by: GatewayJ <8352692332qq.com>
Co-authored-by: loverustfs <hello@rustfs.com >
Co-authored-by: houseme <housemecn@gmail.com >
2026-04-27 09:21:22 +00:00
houseme
59f41eb86a
feat(obs): improve metrics coverage and dashboard performance ( #2682 )
2026-04-25 18:51:29 +00:00
cxymds
8d4caeacad
fix(oidc): add federated logout flow ( #2667 )
...
Co-authored-by: GatewayJ <835269233@qq.com >
2026-04-24 06:51:31 +00:00
Andy Teijelo Pérez
989827e3b5
feat: add OTHER_AUDIENCES config ( #2605 )
...
Co-authored-by: GatewayJ <835269233@qq.com >
2026-04-21 03:48:13 +00:00
LeonWang0735
38eb0781cf
fix(iam): decouple IAM config encryption from root secret rotation ( #2558 )
...
Co-authored-by: houseme <housemecn@gmail.com >
2026-04-17 14:13:53 +00:00
GatewayJ
f255b8a9f1
fix(admin): align accountinfo policy with IAM prepare_auth for OIDC console ( #2568 )
...
Co-authored-by: GatewayJ <8352692332qq.com>
Co-authored-by: houseme <housemecn@gmail.com >
2026-04-17 05:38:18 +00:00