fix: preserve multipart defaults and rollback compatibility - #213
Merged
Merged
Conversation
Signed-off-by: Feng Ruohang <rh@vonng.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Contribution Licensing
AGPL-3.0-or-later, inbound=outbound; all commits carry DCO sign-off. Existing notices and PR #198 contributor credit remain intact.
Description
Preserve released multipart availability and API configuration rollback after #198. Default to legacy listing and cancellation, including before configuration initialization; strict mode requires
MINIO_API_MULTIPART_LISTING=strict. Remove the new shared-config default/help entry, tolerate historical stored keys, and preserve the fully parsed API config when an invalid environment value falls back to legacy.Legacy Abort retains released read-quorum, best-effort cleanup and pool-order behavior. Strict Abort cleans observed minority remnants and returns a retryable error when their deletion fails instead of counting empty disks as successful cleanup. Wrong-key/wrong-bucket Abort no longer evicts another upload's cache entry. Successful peer notifications retain the original request context after the distributed lock context is canceled.
Motivation and Context
An ordinary upgrade must not turn previously available listing/cancellation into 503 responses because of legacy uploads or stricter quorum rules. A process-only rollout switch must not inject a config key rejected by a released server during rollback. This is the first compatibility batch; scanner capacity and durable creation fencing remain separate work in #79.
Production scope: five files, 58 additions / 31 deletions including comments. No new dependency, persistent field, metadata encoding, upload ID, part layout, RPC, lock protocol, generic parser rule, scanner budget or stale-upload expiry change.
How to test this PR?
make verifiers,make build,go vet ./...; compatibility identifier baseline unchanged.9b11dc946and direct pre-fix: restore durable multipart listing and continuation #1983c26a8b0: resumable uploads, complete/abort, bytes, ETags, user metadata, versions and CopyObject preserved.make check.Compatibility impact
Default legacy retains its known exact-key/cache listing limitations. Strict mode remains opt-in and is not a production-scale performance or terminal-cancellation guarantee. HTTP 204 remains idempotent and does not prove physical drain. Clusters that ran a development build persisting
multipart_listingmust follow the targeted reset procedure before rollback; other API settings and config history are preserved. This is scoped multipart/config compatibility validation, not whole-release rollback certification.Types of changes
Checklist
make verifiers, relevant tests, build and vetOpus 5.0 max completed two read-only adversarial review rounds; the final verdict approves this scope with no code blockers. The startup zero-value defect it found is covered, and the grid notification defect found by the two-node test is fixed.
An independent Claude Code Fable 5.1 xhigh review of
82f0a9828e4d1d7b5d42d3f2ccdea9bb64d46f30also concluded approve, with no P0/P1 findings, no required changes, and no code removable without weakening the approved guarantees. Optional follow-ups remain outside this batch. All eight GitHub PR checks passed on the same commit. No server tag, release artifact, image or deployment is created by this change.