Skip to content

fix: preserve multipart defaults and rollback compatibility - #213

Merged
Vonng merged 1 commit into
mainfrom
codex/pr198-release-compat
Sep 16, 2026
Merged

Vonng merged 1 commit into
mainfrom
codex/pr198-release-compat

Conversation

@Vonng

@Vonng Vonng commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Contribution Licensing

AGPL-3.0-or-later, inbound=outbound; all commits carry DCO sign-off. Existing notices and PR #198 contributor credit remain intact.

Description

Preserve released multipart availability and API configuration rollback after #198. Default to legacy listing and cancellation, including before configuration initialization; strict mode requires MINIO_API_MULTIPART_LISTING=strict. Remove the new shared-config default/help entry, tolerate historical stored keys, and preserve the fully parsed API config when an invalid environment value falls back to legacy.

Legacy Abort retains released read-quorum, best-effort cleanup and pool-order behavior. Strict Abort cleans observed minority remnants and returns a retryable error when their deletion fails instead of counting empty disks as successful cleanup. Wrong-key/wrong-bucket Abort no longer evicts another upload's cache entry. Successful peer notifications retain the original request context after the distributed lock context is canceled.

Motivation and Context

An ordinary upgrade must not turn previously available listing/cancellation into 503 responses because of legacy uploads or stricter quorum rules. A process-only rollout switch must not inject a config key rejected by a released server during rollback. This is the first compatibility batch; scanner capacity and durable creation fencing remain separate work in #79.

Production scope: five files, 58 additions / 31 deletions including comments. No new dependency, persistent field, metadata encoding, upload ID, part layout, RPC, lock protocol, generic parser rule, scanner budget or stale-upload expiry change.

How to test this PR?

  • Multipart listing/cancellation/preflight/pagination regressions, including half-drive availability, multi-pool ordering, startup zero value, keyless legacy listing, failed minority deletion, unsafe IDs, wrong-target cache retention and real grid notifications after distributed unlock.
  • Race detector for the multipart suite; full non-root Linux cmd suite and internal package tests.
  • make verifiers, make build, go vet ./...; compatibility identifier baseline unchanged.
  • Real same-disk old→new→old→new runs against released 9b11dc946 and direct pre-fix: restore durable multipart listing and continuation #198 3c26a8b0: resumable uploads, complete/abort, bytes, ETags, user metadata, versions and CopyObject preserved.
  • Real config set/import/history/restart, invalid-env fallback, targeted historical-key reset, failed history restoration retention and released-server reload.
  • Two server processes/four drives: wrong-target Abort preserves the other node's cache; valid Abort removes it in both modes. The notification regression test fails with only the context-capture fix reverted.
  • Maintained mcli 20260916 and embedded Console HTML/login/bucket-list smoke tests; bilingual site make check.

Compatibility impact

Default legacy retains its known exact-key/cache listing limitations. Strict mode remains opt-in and is not a production-scale performance or terminal-cancellation guarantee. HTTP 204 remains idempotent and does not prove physical drain. Clusters that ran a development build persisting multipart_listing must follow the targeted reset procedure before rollback; other API settings and config history are preserved. This is scoped multipart/config compatibility validation, not whole-release rollback certification.

Types of changes

  • Bug fix

Checklist

Opus 5.0 max completed two read-only adversarial review rounds; the final verdict approves this scope with no code blockers. The startup zero-value defect it found is covered, and the grid notification defect found by the two-node test is fixed.

An independent Claude Code Fable 5.1 xhigh review of 82f0a9828e4d1d7b5d42d3f2ccdea9bb64d46f30 also concluded approve, with no P0/P1 findings, no required changes, and no code removable without weakening the approved guarantees. Optional follow-ups remain outside this batch. All eight GitHub PR checks passed on the same commit. No server tag, release artifact, image or deployment is created by this change.

Signed-off-by: Feng Ruohang <rh@vonng.com>
@Vonng
Vonng marked this pull request as ready for review September 16, 2026 08:33
@Vonng
Vonng merged commit f99ed82 into main Sep 16, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant