v26.45.0 release notes - #39477
Open
bosconi wants to merge 3 commits into
Open
v26.45.0 release notes#39477bosconi wants to merge 3 commits into
bosconi wants to merge 3 commits into
Conversation
Adds the `## v26.45.0` section to doc/user/content/releases/_index.md — 7 Improvements, 1 Agent Skills entry, 7 Bug Fixes — and the `v26.45` row to the self-managed operator compatibility table. Dates are provisional: Cloud 2026-10-08, Self-Managed 2026-10-09, derived from the first Thursday strictly after the `v26.45.0-rc.1` tag's commit date (2026-10-02T02:23:01Z) plus one day. The final snapshot sets the real dates. Draft with PR links and the full review record: data/mz-release-notes/v26.45.0/rc.1/ in MaterializeInc/mz-skills.
Adds the v26.45.0-rc.2 increment to the assembled v26.45.0 section: one bug fix (zero-downtime cut-over fencing against a large catalog audit log). Provisional dates are unchanged from rc.1 (Cloud 2026-10-08, Self-Managed 2026-10-09), so the operator-compatibility row needs no edit in this snapshot.
Adds the v26.45.0-rc.3 increment to the assembled v26.45.0 section: - New improvement: quieter logins with identity-provider group sync. - Amends, in place, rc.1's subject-alternative-name improvement with the exact-match pinned-CA carve-out. This replaces that bullet rather than adding a second one: the follow-up repairs a regression introduced earlier in this same unreleased train, so no released version ever showed the failure, and leaving rc.1's sentence as written would overstate the action users must take. Provisional dates are unchanged from rc.1 (Cloud 2026-10-08, Self-Managed 2026-10-09), so the operator-compatibility row needs no edit in this snapshot.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The v26.45.0 release-note train, one commit per snapshot. Dates in RC snapshots are provisional until the release ships; the final snapshot sets the real dates.
rc.1 adds the
## v26.45.0section — 7 Improvements, 1 Agent Skills entry, 7 Bug Fixes (15 published entries from 16 PRs) — and thev26.45row in the self-managed operator compatibility table. No Features section: nothing in this snapshot's 229 in-scope PRs rises to one. The closest candidate issum/avgoverinterval, which fills the last gap in the aggregate surface for a core type rather than adding a capability worth its own heading.rc.2 adds 1 Bug Fix from 1 PR in scope — zero-downtime cut-overs stalling for hours when the incoming
environmentdre-consolidated its whole catalog snapshot before every fence attempt and so lost the race against the serving instance's advancing frontier (#39482). Nothing omitted, nothing Borderline.rc.3 adds 1 Improvement and amends another, from 2 PRs in scope. New: quieter logins with identity-provider group sync (#39434). Amended in place: rc.1's subject-alternative-name bullet now carries the exact-match pinned-CA carve-out (#39459) and cites both PRs — see the reviewer check below for why that is a replacement rather than a second bullet. Nothing omitted, nothing Borderline.
Provisional dates: Cloud 2026-10-08, Self-Managed 2026-10-09 — the first Thursday strictly after the
v26.45.0-rc.1tag's commit date (2026-10-02T02:23:01Z, a Friday), plus one day. Anchored on rc.1, so rc.2 and rc.3 introduce no drift and neither touches the compatibility YAML. Expect the final snapshot to move these one day earlier: both of the last two trains shipped on the Wednesday before the estimate (v26.43.0 on 2026-09-23 against 2026-09-24; v26.44.0 on 2026-09-30 against 2026-10-01). The estimate is kept as the rule specifies rather than pre-corrected.SSL CERTIFICATE AUTHORITYneeds no reissue. The narrower alternative, if a reviewer prefers one bullet per snapshot: revert to rc.1's wording and accept a published caveat broader than the shipped behaviour — the safe-direction error, but still wrong.oidc_group_role_sync_enabledreadsfalseat the tag (src/adapter-types/src/dyncfgs.rs:203-208) and is inKNOWN_CROSS_ENV_DIVERGENCES, notKNOWN_MISSING_FROM_LD— so an LD flag exists and its served value knowingly differs by environment, which is consistent with a per-customer opt-in but is not proof the feature is on. It is published on four grounds: the flag is environment-scoped, v26.40.0 rc.1 already published a fix on this same gated path (#38410), the capability was announced GA one release earlier, and the PR ships the new behaviour in the publishedsync-idp-groups.mddocs page in the same diff. Confirm with the release owner; if it comes back negative, that is the entry to cut — the certificate entry is unaffected.COPY FROMsubject-alternative-name requirement (#39415 + #39459) both sit in Improvements, phrased around the action a user must take. A reviewer may want them moved or called out more loudly. Related and omitted: #39351 moves all S3/AWS traffic onto rustls and webpki — if the same SAN strictness applies to a custom S3 endpoint in a Self-Managed deployment, it belongs in the same note; the PR does not say either way.final. Also deliberately unpublished on catalog: skip consolidation on syncs that apply no updates #39482: it is a regression since v26.22.0 by the author's own statement, and the fix does not cover syncs that do apply updates (DDL issued during takeover still consolidates the full snapshot) — the PR gives no measurement of that residual, so it is not claimed.enable_metric_sink, which readsfalseat this tag. Confirm with the release owner: if the flag is on in v26.45.0, publish #39332 (clearest candidate — it also removes theunattributableseries from the metric's label set), #38910, and #39337. #39337 deserves a second look even if metric sinks stay off — the coordinator panic it fixes is reachable by any superuser viaALTER SYSTEM SET disabled_metric_sinks = '', a plain system variable with no feature-flag check.test/kafka-auth, SS-115) — no customer report, nodatabase-issuesreference. It is published because the defect is in shipped code on a shipped path (librdkafka leaves a stale OpenSSL error on the tokio worker's error queue). If a reviewer wants only customer-observed fixes published, this is the entry to cut.SELECTclause, which is the softer of the two claims.enable_compute_correction_v2istrue) with real figures — 3503 ms → 1897 ms, 1.6x–2.0x — but every one is a bench of the buffer's owninsertpath, not of materialized-view ingest. If the compute team can supply a hydration or lag number, publish these as one Improvement; the per-clause provenance is already drafted in the review notes.environmentdwith the exactInvalid Parquet file. Corrupt footerdefect that #39115 fixes and this release publishes. Same call as #39125 in v26.44.0 rc.1. If a reviewer restores it, it is a Bug Fix._index.mdhere jumps from## v26.45.0straight to## v26.43.0— the v26.44.0 section is absent because that train's PR (#39138) has not merged, and the same holds for thev26.44row in the operator-compatibility YAML. Whichever PR merges second needs the rebase to get the sections and rows into version order.materialize-docs→mz-docsrename, whose user-visible half shipped in v26.44.0). Accounted for inomitted.mdunder "Already published in an earlier release".Inclusion rate: rc.1 is 7.0% (16/229), inside the usual 5–15% band; rc.2 is 1/1 and rc.3 is 2/2, which is the expected shape for a late RC — the set is cherry-picks a release manager has already filtered down. rc.1's denominator is dominated by automation: 125 of the 225 materialize PRs are dependency bumps, 65 of them a single Dependabot fan-out of the
materialize-terraform-self-managedmodules from 13.10.0 to 13.12.1 across fivetest/terraformdirectories — #39282 groups future Terraform releases into one PR so it does not recur. Strip the dependency bumps and rc.1's materialize side is 15 included out of 100 (15%). A further 22 PRs are CI/test-harness repair and 14 are documentation.The agent-skills windows for rc.2
(2026-10-02T02:23:01Z, 2026-10-02T22:33:36Z]and rc.3(2026-10-02T22:33:36Z, 2026-10-02T23:08:27Z]are both empty, re-checked against a widened query; MaterializeInc/agent-skills#88 merged 83 minutes after rc.3's upper bound and falls to thefinalsnapshot.Snapshot drafts (with PR links) in mz-skills:
Borderline PRs omitted: rc.1: 12 — review borderline calls, rc.2: 0 — none, rc.3: 0 — none