Repository navigation
v26.45.0 release notes - #39477
Open
bosconi wants to merge 4 commits into
Open
v26.45.0 release notes#39477bosconi wants to merge 4 commits into
bosconi wants to merge 4 commits into
Conversation
Adds the `## v26.45.0` section to doc/user/content/releases/_index.md — 7 Improvements, 1 Agent Skills entry, 7 Bug Fixes — and the `v26.45` row to the self-managed operator compatibility table. Dates are provisional: Cloud 2026-10-08, Self-Managed 2026-10-09, derived from the first Thursday strictly after the `v26.45.0-rc.1` tag's commit date (2026-10-02T02:23:01Z) plus one day. The final snapshot sets the real dates. Draft with PR links and the full review record: data/mz-release-notes/v26.45.0/rc.1/ in MaterializeInc/mz-skills.
Adds the v26.45.0-rc.2 increment to the assembled v26.45.0 section: one bug fix (zero-downtime cut-over fencing against a large catalog audit log). Provisional dates are unchanged from rc.1 (Cloud 2026-10-08, Self-Managed 2026-10-09), so the operator-compatibility row needs no edit in this snapshot.
Adds the v26.45.0-rc.3 increment to the assembled v26.45.0 section: - New improvement: quieter logins with identity-provider group sync. - Amends, in place, rc.1's subject-alternative-name improvement with the exact-match pinned-CA carve-out. This replaces that bullet rather than adding a second one: the follow-up repairs a regression introduced earlier in this same unreleased train, so no released version ever showed the failure, and leaving rc.1's sentence as written would overstate the action users must take. Provisional dates are unchanged from rc.1 (Cloud 2026-10-08, Self-Managed 2026-10-09), so the operator-compatibility row needs no edit in this snapshot.
The rc.4 increment is two items, both omitted, so this snapshot adds no entry to the assembled `## v26.45.0` section and the provisional dates are unchanged (Cloud 2026-10-08, Self-Managed 2026-10-09). - #39549 pins jemalloc's allocator page back to 4 KiB on aarch64-unknown-linux-gnu, repairing a 64 KiB-page regression that #39339 introduced earlier in this same unreleased train. No released version ever ran the 64 KiB page, so a user upgrading from v26.44.0 sees the same allocator page before and after; #39339 was itself omitted at rc.1 as a dependency bump, so nothing published describes the behavior and there is no bullet to amend. Recorded as borderline in the snapshot's omitted.md. - `ba9b30921` is the materialize-bot version bump for the candidate. The one agent-skills PR in the window, MaterializeInc/agent-skills#88, is an automated `mz-docs` regeneration and is omitted as it was at rc.1. This empty commit records rc.4 as applied; v26.39.0 rc.3 is the precedent for a zero-entry RC on this layout.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The v26.45.0 release-note train, one commit per snapshot. Dates in RC snapshots are provisional until the release ships; the final snapshot sets the real dates.
rc.1 adds the
## v26.45.0section — 7 Improvements, 1 Agent Skills entry, 7 Bug Fixes (15 published entries from 16 PRs) — and thev26.45row in the self-managed operator compatibility table. No Features section: nothing in this snapshot's 229 in-scope PRs rises to one. The closest candidate issum/avgoverinterval, which fills the last gap in the aggregate surface for a core type rather than adding a capability worth its own heading.rc.2 adds 1 Bug Fix from 1 PR in scope — zero-downtime cut-overs stalling for hours when the incoming
environmentdre-consolidated its whole catalog snapshot before every fence attempt and so lost the race against the serving instance's advancing frontier (#39482). Nothing omitted, nothing Borderline.rc.3 adds 1 Improvement and amends another, from 2 PRs in scope. New: quieter logins with identity-provider group sync (#39434). Amended in place: rc.1's subject-alternative-name bullet now carries the exact-match pinned-CA carve-out (#39459) and cites both PRs — see the reviewer check below for why that is a replacement rather than a second bullet. Nothing omitted, nothing Borderline.
rc.4 adds nothing, and its commit is intentionally empty. The increment is two items — #39549 (borderline, omitted; see the reviewer check below) and the
materialize-botversion-bump commitba9b30921— and the provisional dates are unchanged, so there is no edit to make to either file. An RC whose whole increment is a within-train repair is a legitimate outcome rather than a gap; v26.39.0rc.3is the precedent for a zero-entry snapshot on this layout, landed the same way. The empty commit is what records rc.4 as applied, so please keep it on any rebase — the commit subject is the ledger that stops a later run re-applying the snapshot.Provisional dates: Cloud 2026-10-08, Self-Managed 2026-10-09 — the first Thursday strictly after the
v26.45.0-rc.1tag's commit date (2026-10-02T02:23:01Z, a Friday), plus one day. Anchored on rc.1, so rc.2, rc.3 and rc.4 introduce no drift and none of them touches the compatibility YAML. Expect the final snapshot to move these one day earlier: both of the last two trains shipped on the Wednesday before the estimate (v26.43.0 on 2026-09-23 against 2026-09-24; v26.44.0 on 2026-09-30 against 2026-10-01). The estimate is kept as the rule specifies rather than pre-corrected. Note that the train has now run four candidates across a weekend — rc.4 was cut Monday 2026-10-05 at 14:28:59Z, 2 d 15 h after rc.3 and by far the widest gap of this train — so the Thursday target is tighter than it was at rc.1.aarch64-unknown-linux-gnu(one line in.cargo/config.toml), repairing a regression #39339 introduced inside this same unreleased train when it bumped jemalloc 5.3.0 → 5.3.1 and silently took the default aarch64 Linux allocator page to 64 KiB. The measured effect is large — at equal post-restart age against v26.44.0,environmentdactive-minus-allocated 55 MB → 490 MB and 84 MB → 558 MB on two us-east-1 canaries, the largest canaryclusterdpods 0.19 GB → 1.70 GB, local VmRSS 32% higher onenvironmentd— which is why this is filed Borderline rather than as a plain build omit. It is nonetheless omitted because no released version ever ran the 64 KiB page: build(deps): bump the jemalloc crates #39339 was itself omitted at rc.1 as a dependency bump, so nothing published describes the behaviour, and a user upgrading from v26.44.0 sees the same allocator page before and after. Publishing it would mean writing a bullet asserting that memory use is unchanged from v26.44.0 — a non-statement. If the release owner wants the work visible, an internal sign-off note is the right vehicle, not a release note. Separately worth an eye: this was caught by a release sign-off sweep rather than by CI, and @antiguru confirmed on the PR that "moving to 64kb page size was not a deliberate choice" — a dependency bump that silently changes allocator behaviour may deserve a follow-up guard.SSL CERTIFICATE AUTHORITYneeds no reissue. The narrower alternative, if a reviewer prefers one bullet per snapshot: revert to rc.1's wording and accept a published caveat broader than the shipped behaviour — the safe-direction error, but still wrong. build: pin jemalloc's page size to 4 KiB on aarch64 Linux #39549 above is the same family with a cleaner resolution: there the causing PR was never published, so there was no bullet to amend.oidc_group_role_sync_enabledreadsfalseat the tag (src/adapter-types/src/dyncfgs.rs:203-208) and is inKNOWN_CROSS_ENV_DIVERGENCES, notKNOWN_MISSING_FROM_LD— so an LD flag exists and its served value knowingly differs by environment, which is consistent with a per-customer opt-in but is not proof the feature is on. It is published on four grounds: the flag is environment-scoped, v26.40.0 rc.1 already published a fix on this same gated path (#38410), the capability was announced GA one release earlier, and the PR ships the new behaviour in the publishedsync-idp-groups.mddocs page in the same diff. This confirmation is still owed by the release owner as of rc.4; if it comes back negative, that is the entry to cut — the certificate entry is unaffected.COPY FROMsubject-alternative-name requirement (#39415 + #39459) both sit in Improvements, phrased around the action a user must take. A reviewer may want them moved or called out more loudly. Related and omitted: #39351 moves all S3/AWS traffic onto rustls and webpki — if the same SAN strictness applies to a custom S3 endpoint in a Self-Managed deployment, it belongs in the same note; the PR does not say either way.final. Also deliberately unpublished on catalog: skip consolidation on syncs that apply no updates #39482: it is a regression since v26.22.0 by the author's own statement, and the fix does not cover syncs that do apply updates (DDL issued during takeover still consolidates the full snapshot) — the PR gives no measurement of that residual, so it is not claimed.enable_metric_sink, which readsfalseat this tag. Confirm with the release owner: if the flag is on in v26.45.0, publish #39332 (clearest candidate — it also removes theunattributableseries from the metric's label set), #38910, and #39337. #39337 deserves a second look even if metric sinks stay off — the coordinator panic it fixes is reachable by any superuser viaALTER SYSTEM SET disabled_metric_sinks = '', a plain system variable with no feature-flag check.test/kafka-auth, SS-115) — no customer report, nodatabase-issuesreference. It is published because the defect is in shipped code on a shipped path (librdkafka leaves a stale OpenSSL error on the tokio worker's error queue). If a reviewer wants only customer-observed fixes published, this is the entry to cut.SELECTclause, which is the softer of the two claims.enable_compute_correction_v2istrue) with real figures — 3503 ms → 1897 ms, 1.6x–2.0x — but every one is a bench of the buffer's owninsertpath, not of materialized-view ingest. If the compute team can supply a hydration or lag number, publish these as one Improvement; the per-clause provenance is already drafted in the review notes.environmentdwith the exactInvalid Parquet file. Corrupt footerdefect that #39115 fixes and this release publishes. Same call as #39125 in v26.44.0 rc.1. If a reviewer restores it, it is a Bug Fix._index.mdhere jumps from## v26.45.0straight to## v26.43.0— the v26.44.0 section is absent because that train's PR (#39138) has not merged, and the same holds for thev26.44row in the operator-compatibility YAML. Whichever PR merges second needs the rebase to get the sections and rows into version order.materialize-docs→mz-docsrename, whose user-visible half shipped in v26.44.0). Accounted for inomitted.mdunder "Already published in an earlier release".Inclusion rate: rc.1 is 7.0% (16/229), inside the usual 5–15% band; rc.2 is 1/1, rc.3 is 2/2 and rc.4 is 0/2, which is the expected shape for a late RC — the set is cherry-picks a release manager has already filtered down, and at a denominator of one or two the percentage carries no signal. rc.1's denominator is dominated by automation: 125 of the 225 materialize PRs are dependency bumps, 65 of them a single Dependabot fan-out of the
materialize-terraform-self-managedmodules from 13.10.0 to 13.12.1 across fivetest/terraformdirectories — #39282 groups future Terraform releases into one PR so it does not recur. Strip the dependency bumps and rc.1's materialize side is 15 included out of 100 (15%). A further 22 PRs are CI/test-harness repair and 14 are documentation.The agent-skills windows for rc.2
(2026-10-02T02:23:01Z, 2026-10-02T22:33:36Z]and rc.3(2026-10-02T22:33:36Z, 2026-10-02T23:08:27Z]are both empty, re-checked against a widened query. MaterializeInc/agent-skills#88 (an automatedmz-docsregeneration, omitted as every prior run of that workflow was) lands in rc.4's window(2026-10-02T23:08:27Z, 2026-10-05T14:28:59Z], notfinal's — rc.2 and rc.3 both predictedfinalon the assumption that rc.3 was the last candidate, and rc.4 being cut opened a window first. The windows still abut exactly and nothing is double-counted. MaterializeInc/agent-skills#79 merged 15 min 26 s after rc.4's upper bound and falls tofinal; the margin is small enough that a date-only window would have wrongly pulled it in, so full ISO timestamps were used.Snapshot drafts (with PR links) in mz-skills:
Borderline PRs omitted: rc.1: 12 — review borderline calls, rc.2: 0 — none, rc.3: 0 — none, rc.4: 1 — review borderline call