Skip to content

Tags: Replication

  • Replica Metadata Normalization: What a Trusted Copy May Not Re-Inject

    In Design

    DesignReplicationS3Review

    Replica Metadata Normalization: What a Trusted Copy May Not Re-Inject

    This page records the repair of how a trusted replication receiver restores metadata for a replica, merged into Server main as PR #194 (fix 4fcdf37ce, merged as 9f3037e941). As of 2026-09-16: the fix is on verified main 40220bd836cb. It is not in the …

    This page records the repair of how a trusted replication receiver restores metadata for a replica, merged into Server main as PR #194 (fix 4fcdf37ce, merged as 9f3037e941). As of 2026-09-16: the fix is on verified main 40220bd836cb. It is not in the …

  • Replicated Tag Ordering: Revision Timestamps, Tombstones, and Resurrection

    In Design

    DesignReplicationS3Review

    Replicated Tag Ordering: Revision Timestamps, Tombstones, and Resurrection

    This page records the analysis and repair of two defects in how object tags keep their ordering across replication, merged into Server main as PR #193 (fix 03027727d) and PR #196 (fix 680eac66e). As of 2026-09-16: both fixes are on verified main …

    This page records the analysis and repair of two defects in how object tags keep their ordering across replication, merged into Server main as PR #193 (fix 03027727d) and PR #196 (fix 680eac66e). As of 2026-09-16: both fixes are on verified main …

  • Bucket Configuration Replication: Source Times, Deletions, and Deterministic Convergence

    In Design

    DesignReplicationS3Review

    Bucket Configuration Replication: Source Times, Deletions, and Deterministic Convergence

    #77 is a reproduced site-replication correctness defect. A receiver replaces source time with arrival time and may then reject a genuinely newer deletion. Some configuration types stop exporting their timestamp after deletion, preventing heal from …

    #77 is a reproduced site-replication correctness defect. A receiver replaces source time with arrival time and may then reject a genuinely newer deletion. Some configuration types stop exporting their timestamp after deletion, preventing heal from …

  • Replication Reliability: Delete Completion, MRF Visibility, and Resync Cancellation

    In Design

    DesignReplicationS3Review

    Replication Reliability: Delete Completion, MRF Visibility, and Resync Cancellation

    This page records the analysis, design choices, review, and implementation of #153, #152, and #137. They belong to the same replication reliability series, but affect operation classification, recovery visibility, and task lifecycle respectively. One …

    This page records the analysis, design choices, review, and implementation of #153, #152, and #137. They belong to the same replication reliability series, but affect operation classification, recovery visibility, and task lifecycle respectively. One …

  • SILO 20260903 Security Notes: SN-2026-006 through 010

    In Security

    SecurityS3SSE-CReplicationIAM

    SILO 20260903 Security Notes: SN-2026-006 through 010

    Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …

    Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …

  • No I/O Before Auth, No Privilege From Headers

    In Design

    DesignSecurityCORSReplicationSSE-CCompatibility

    No I/O Before Auth, No Privilege From Headers

    Release check (2026-09-16): the original repair described here is included in Server 20260903. Dated review and test accounts below record their original evidence, not a still-pending release or acceptance of a particular production installation. …

    Release check (2026-09-16): the original repair described here is included in Server 20260903. Dated review and test accounts below record their original evidence, not a still-pending release or acceptance of a particular production installation. …

  • CVE-2026-34204: Replication Metadata Injection

    In Security

    SecurityReplication

    CVE-2026-34204: Replication Metadata Injection

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …