From 9dc34353f64fd7e88cc328c3df313ef29f148a18 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 2 Oct 2026 07:18:50 +0000 Subject: [PATCH 1/4] v26.45.0 release notes (rc.1) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds the `## v26.45.0` section to doc/user/content/releases/_index.md — 7 Improvements, 1 Agent Skills entry, 7 Bug Fixes — and the `v26.45` row to the self-managed operator compatibility table. Dates are provisional: Cloud 2026-10-08, Self-Managed 2026-10-09, derived from the first Thursday strictly after the `v26.45.0-rc.1` tag's commit date (2026-10-02T02:23:01Z) plus one day. The final snapshot sets the real dates. Draft with PR links and the full review record: data/mz-release-notes/v26.45.0/rc.1/ in MaterializeInc/mz-skills. --- doc/user/content/releases/_index.md | 25 +++++++++++++++++++ .../self_managed_operator_compatibility.yml | 5 ++++ 2 files changed, 30 insertions(+) diff --git a/doc/user/content/releases/_index.md b/doc/user/content/releases/_index.md index facc616006a91..7fe6b15f0155a 100644 --- a/doc/user/content/releases/_index.md +++ b/doc/user/content/releases/_index.md @@ -20,6 +20,31 @@ Starting with the v26.1.0 release, Materialize releases on a weekly schedule for both Cloud and Self-Managed. See [Release schedule](/releases/schedule) for details. {{}} +## v26.45.0 +*Released to Materialize Cloud: 2026-10-08*
+*Released to Materialize Self-Managed: 2026-10-09*
+ +### Improvements {#v26.45-improvements} +- **`sum` and `avg` over `interval`**: `sum(interval)` and `avg(interval)` now work and return `interval`, matching PostgreSQL — `sum` accumulates months, days, and microseconds independently, so `interval '1 month' + interval '40 days'` sums to `1 mon 40 days` rather than being normalized, `avg` carries each fractional component down into the next finer one, and a grouped `sum` whose components exceed the `interval` field widths raises `interval out of range` instead of wrapping silently. +- **Improved compatibility with PostgreSQL ODBC clients**: `expr OPERATOR(pg_catalog.=) expr` and the prefix form `OPERATOR(pg_catalog.-) 1` now parse, so queries psqlODBC routinely generates no longer fail with `Expected operator, found equals sign`; as in PostgreSQL, a function named `operator` must now be quoted. +- **Lower memory for `MIN` and `MAX`**: A materialized view or index computing a single `MIN` or `MAX` over an input that receives updates or deletes no longer keeps an extra copy of its input in memory — for a `MAX` over 100,000 rows in 1,000 groups, the view's arrangements fell from 16.8 MB to 12.8 MB and the first reduction stage from 100,000 records to none under the default bucketing. +- **Lower `SUBSCRIBE` and query latency from introspection logging**: The compute introspection logging dataflow now drains its input in bounded chunks rather than processing a whole interval of events in one uninterruptible call, which on a 4-worker replica serving 1,000 `SUBSCRIBE` timestamps per second took p99 latency for results waiting on the subscribe frontier from 78–86 ms to 9–14 ms and halved the worst per-second index `SELECT` latency. +- **Stricter Kubernetes API server certificate verification in Self-Managed deployments**: The Materialize operator, `environmentd`, and `mz-debug` now verify the Kubernetes API server certificate with rustls rather than OpenSSL, which requires the certificate to carry a subject alternative name matching the address used to reach the API server and rejects a certificate that names the host only in its common name, so clusters with hand-issued API server certificates should confirm their subject alternative names before upgrading; EKS, GKE, AKS, and kind are unaffected. +- **Schema registry and `COPY FROM` server certificates must carry a subject alternative name**: Confluent Schema Registry connections, `COPY FROM` URLs, and the OIDC issuer fetch now reject a server certificate that identifies its host only by common name, so reissue any such certificate with a matching subject alternative name before upgrading. +- **Kubernetes events from the Materialize operator**: The operator now publishes Kubernetes events on `Materialize`, `Balancer`, and `Console` resources when it fails to reconcile them, and on each `Materialize` rollout phase, so `kubectl describe` shows why a resource is not progressing; its ClusterRole gains `create` and `patch` on `events.k8s.io` events. + +### Agent Skills {#v26.45-agent-skills} +- **`mz-demo-data`**: A new skill that stands up continuously-updating, realistic synthetic data inside a running Materialize instance using nothing but views over `mz_now()` — no Kafka, no external load generator, and no seed scripts — in a dedicated `materialize_demo` schema that one `DROP SCHEMA` removes. + +### Bug Fixes {#v26.45-bug-fixes} +- Fixed connection poolers losing track of session variables across `DISCARD ALL`, which now reports `ParameterStatus` for every reportable parameter whose value it changed, as `RESET` and PostgreSQL do; with pgbouncer and `server_reset_query_always=1` this had left every client's `application_name` empty. +- Fixed hedged reads from object storage staying disabled for the lifetime of any process that started while the object store or its credential service was unavailable, which was observed during a regional AWS STS outage; the hedge connection is now opened in the background with retries, so it arms once the store recovers, and process startup no longer waits on it. +- Fixed `Invalid Parquet file. Corrupt footer` crashes when reading a large object from an S3-compatible object store that does not return a part count on a part request, and added a length check that turns a short read from any store into a retried failure rather than corrupt data downstream. +- Fixed cluster replicas from an earlier generation being left running during a zero-downtime deployment, where continuous DDL could repeatedly restart the read-only `environmentd` before it finished cleaning up orphaned replicas. +- Fixed `environmentd` and `clusterd` aborting when a MySQL connection, including during connection purification and `VALIDATE CONNECTION`, reached a server that switched authentication to MariaDB `parsec`; the client panic is now returned as a connection error. +- Fixed sporadic schema registry TLS failures caused by a stale OpenSSL error left on the worker thread after creating a Kafka client that reads certificates from `ssl.ca.pem`. +- Fixed the Console reporting different cluster utilization on the cluster list, the cluster detail page, and the utilization charts, which now all show the most recent sample from the same view; fixed memory and CPU readings on multi-process replica sizes (`2xlarge` and larger), which were reported per process rather than merged across processes; and fixed a cluster metrics gauge labeled "Heap Utilization" that showed memory and `0 B` on deployments that run without a heap limit. + ## v26.43.0 *Released to Materialize Cloud: 2026-09-23*
*Released to Materialize Self-Managed: 2026-09-24*
diff --git a/doc/user/data/self_managed/self_managed_operator_compatibility.yml b/doc/user/data/self_managed/self_managed_operator_compatibility.yml index 558526986305c..031eaca67d01e 100644 --- a/doc/user/data/self_managed/self_managed_operator_compatibility.yml +++ b/doc/user/data/self_managed/self_managed_operator_compatibility.yml @@ -5,6 +5,11 @@ columns: - column: Release date - column: Notes rows: + - Materialize Operator: v26.45 + orchestratord version: v26.45 + environmentd version: v26.45 + Release date: "2026-10-09" + Notes: "See [v26.45 release notes](/releases/#v26450)" - Materialize Operator: v26.43 orchestratord version: v26.43 environmentd version: v26.43 From fe7fa8cc6d48214d5126d294677058b51b99b2db Mon Sep 17 00:00:00 2001 From: Claude Date: Sat, 3 Oct 2026 01:21:38 +0000 Subject: [PATCH 2/4] v26.45.0 release notes (rc.2) Adds the v26.45.0-rc.2 increment to the assembled v26.45.0 section: one bug fix (zero-downtime cut-over fencing against a large catalog audit log). Provisional dates are unchanged from rc.1 (Cloud 2026-10-08, Self-Managed 2026-10-09), so the operator-compatibility row needs no edit in this snapshot. --- doc/user/content/releases/_index.md | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/user/content/releases/_index.md b/doc/user/content/releases/_index.md index 7fe6b15f0155a..f97e25a00a4fd 100644 --- a/doc/user/content/releases/_index.md +++ b/doc/user/content/releases/_index.md @@ -37,6 +37,7 @@ both Cloud and Self-Managed. See [Release schedule](/releases/schedule) for deta - **`mz-demo-data`**: A new skill that stands up continuously-updating, realistic synthetic data inside a running Materialize instance using nothing but views over `mz_now()` — no Kafka, no external load generator, and no seed scripts — in a dedicated `materialize_demo` schema that one `DROP SCHEMA` removes. ### Bug Fixes {#v26.45-bug-fixes} +- Fixed zero-downtime deployment cut-overs stalling for hours on environments with a large catalog audit log, where the incoming `environmentd` re-consolidated its entire catalog snapshot before every attempt to fence the serving instance — about 1.1 s against the largest production catalog's 7.4 million audit entries — and so lost the race against that instance's advancing frontier each time, leaving one cut-over waiting 3 h 11 min over roughly 1,700 attempts; a sync that applies no updates now skips the redundant pass. - Fixed connection poolers losing track of session variables across `DISCARD ALL`, which now reports `ParameterStatus` for every reportable parameter whose value it changed, as `RESET` and PostgreSQL do; with pgbouncer and `server_reset_query_always=1` this had left every client's `application_name` empty. - Fixed hedged reads from object storage staying disabled for the lifetime of any process that started while the object store or its credential service was unavailable, which was observed during a regional AWS STS outage; the hedge connection is now opened in the background with retries, so it arms once the store recovers, and process startup no longer waits on it. - Fixed `Invalid Parquet file. Corrupt footer` crashes when reading a large object from an S3-compatible object store that does not return a part count on a part request, and added a length check that turns a short read from any store into a retried failure rather than corrupt data downstream. From 92f90f71561c6334da5cc2e9453ece58c1aa4287 Mon Sep 17 00:00:00 2001 From: Claude Date: Sat, 3 Oct 2026 01:21:52 +0000 Subject: [PATCH 3/4] v26.45.0 release notes (rc.3) Adds the v26.45.0-rc.3 increment to the assembled v26.45.0 section: - New improvement: quieter logins with identity-provider group sync. - Amends, in place, rc.1's subject-alternative-name improvement with the exact-match pinned-CA carve-out. This replaces that bullet rather than adding a second one: the follow-up repairs a regression introduced earlier in this same unreleased train, so no released version ever showed the failure, and leaving rc.1's sentence as written would overstate the action users must take. Provisional dates are unchanged from rc.1 (Cloud 2026-10-08, Self-Managed 2026-10-09), so the operator-compatibility row needs no edit in this snapshot. --- doc/user/content/releases/_index.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/doc/user/content/releases/_index.md b/doc/user/content/releases/_index.md index f97e25a00a4fd..03f53425c43de 100644 --- a/doc/user/content/releases/_index.md +++ b/doc/user/content/releases/_index.md @@ -25,12 +25,13 @@ both Cloud and Self-Managed. See [Release schedule](/releases/schedule) for deta *Released to Materialize Self-Managed: 2026-10-09*
### Improvements {#v26.45-improvements} +- **Quieter logins with identity-provider group sync**: A login whose token carries organization groups with no matching database role no longer sends the client a `NOTICE` for each one, since roles are now created in Materialize rather than mirrored from the identity provider and unmatched groups are expected; notices for groups that map to reserved role names, and for sync errors in fail-open mode, are unchanged. - **`sum` and `avg` over `interval`**: `sum(interval)` and `avg(interval)` now work and return `interval`, matching PostgreSQL — `sum` accumulates months, days, and microseconds independently, so `interval '1 month' + interval '40 days'` sums to `1 mon 40 days` rather than being normalized, `avg` carries each fractional component down into the next finer one, and a grouped `sum` whose components exceed the `interval` field widths raises `interval out of range` instead of wrapping silently. - **Improved compatibility with PostgreSQL ODBC clients**: `expr OPERATOR(pg_catalog.=) expr` and the prefix form `OPERATOR(pg_catalog.-) 1` now parse, so queries psqlODBC routinely generates no longer fail with `Expected operator, found equals sign`; as in PostgreSQL, a function named `operator` must now be quoted. - **Lower memory for `MIN` and `MAX`**: A materialized view or index computing a single `MIN` or `MAX` over an input that receives updates or deletes no longer keeps an extra copy of its input in memory — for a `MAX` over 100,000 rows in 1,000 groups, the view's arrangements fell from 16.8 MB to 12.8 MB and the first reduction stage from 100,000 records to none under the default bucketing. - **Lower `SUBSCRIBE` and query latency from introspection logging**: The compute introspection logging dataflow now drains its input in bounded chunks rather than processing a whole interval of events in one uninterruptible call, which on a 4-worker replica serving 1,000 `SUBSCRIBE` timestamps per second took p99 latency for results waiting on the subscribe frontier from 78–86 ms to 9–14 ms and halved the worst per-second index `SELECT` latency. - **Stricter Kubernetes API server certificate verification in Self-Managed deployments**: The Materialize operator, `environmentd`, and `mz-debug` now verify the Kubernetes API server certificate with rustls rather than OpenSSL, which requires the certificate to carry a subject alternative name matching the address used to reach the API server and rejects a certificate that names the host only in its common name, so clusters with hand-issued API server certificates should confirm their subject alternative names before upgrading; EKS, GKE, AKS, and kind are unaffected. -- **Schema registry and `COPY FROM` server certificates must carry a subject alternative name**: Confluent Schema Registry connections, `COPY FROM` URLs, and the OIDC issuer fetch now reject a server certificate that identifies its host only by common name, so reissue any such certificate with a matching subject alternative name before upgrading. +- **Schema registry and `COPY FROM` server certificates must carry a subject alternative name**: Confluent Schema Registry connections, `COPY FROM` URLs, and the OIDC issuer fetch now reject a server certificate that identifies its host only by common name, so reissue any such certificate with a matching subject alternative name before upgrading; a schema registry server certificate byte-for-byte identical to the one configured as its `SSL CERTIFICATE AUTHORITY` stays trusted and is still matched on its common name when the pinned certificate carries no DNS or IP subject alternative name, but `COPY FROM` and the OIDC issuer fetch have no such exception. - **Kubernetes events from the Materialize operator**: The operator now publishes Kubernetes events on `Materialize`, `Balancer`, and `Console` resources when it fails to reconcile them, and on each `Materialize` rollout phase, so `kubectl describe` shows why a resource is not progressing; its ClusterRole gains `create` and `patch` on `events.k8s.io` events. ### Agent Skills {#v26.45-agent-skills} From 411ba8e57d5fc883dd0cd077269c05de74b3f814 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 5 Oct 2026 19:03:31 +0000 Subject: [PATCH 4/4] v26.45.0 release notes (rc.4) The rc.4 increment is two items, both omitted, so this snapshot adds no entry to the assembled `## v26.45.0` section and the provisional dates are unchanged (Cloud 2026-10-08, Self-Managed 2026-10-09). - #39549 pins jemalloc's allocator page back to 4 KiB on aarch64-unknown-linux-gnu, repairing a 64 KiB-page regression that #39339 introduced earlier in this same unreleased train. No released version ever ran the 64 KiB page, so a user upgrading from v26.44.0 sees the same allocator page before and after; #39339 was itself omitted at rc.1 as a dependency bump, so nothing published describes the behavior and there is no bullet to amend. Recorded as borderline in the snapshot's omitted.md. - `ba9b30921` is the materialize-bot version bump for the candidate. The one agent-skills PR in the window, MaterializeInc/agent-skills#88, is an automated `mz-docs` regeneration and is omitted as it was at rc.1. This empty commit records rc.4 as applied; v26.39.0 rc.3 is the precedent for a zero-entry RC on this layout.