Enterprise SDK changelog
A Tarantool Enterprise SDK version consists of two parts:
<TARANTOOL_BASE_VERSION>-r<REVISION>
For example: 2.11.1-0-gc42d9735b-r589.
TARANTOOL_BASE_VERSIONis the Enterprise version.REVISIONis the SDK revision. Besides Tarantool itself, it includes thettutility, a set of open and closed source modules, and examples. Learn more from Package contents.
This release updates the platform’s key dependencies: Tarantool 2.11.9, a bugfix release of the 2.11 branch focused on
improving stability and predictability. It also improves diagnostics and error handling for WAL failures, fixes hangs and
WAL maintenance issues in Core, and delivers a large set of fixes in LuaJIT and the Datetime module. In addition, major
ecosystem components (crud, vshard, metrics, tt-ee, cartridge, http) have been updated and refined,
including safer behavior during rebalancing, fault-tolerant reads, and changes to HTTP TLS/mTLS configuration.
This is a bugfix release: 34 issues have been fixed since 2.11.8 (r702).
- The 2.x series is the previous stable branch; upgrading to 3.x is recommended.
- To upgrade from Tarantool 2.x to 3.x, see the upgrade procedure.
When upgrading the SDK, it is recommended to:
- before starting the upgrade, ensure that all replica sets are healthy and in a consistent state;
- perform the upgrade sequentially, verifying the cluster state after upgrading each component;
- do not run data rebalancing while passing through CRUD 1.7.0 until the upgrade is fully completed.
Added:
- A new built-in system event
box.wal_errorthat is emitted every time Tarantool fails to commit a transaction to the write-ahead log (WAL) (gh-9405).
Fixed:
- An issue where SSL errors were logged incorrectly when a client connection was closed.
- A bug that could cause Tarantool to hang when using
box.watch(gh-9632). - A bug where
.xlog.inprogressfiles were not removed automatically on server startup whenwal_dirwas set and differed from the default (gh-12081). - A bug where a local space could not be truncated if the
_truncatespace was configured as synchronous (gh-12585).
- If an
ER_WAL_IOerror occurs while writing to WAL, the current leader steps down immediately on the first such error.
Added:
- Support for
ffi.abi("dualnum")to detect LuaJIT mode (dual-number: distinguishing int64 integers from double). - New flags
misc.memprof.availableandmisc.sysprof.availableto detect whether the corresponding profiler is available in the current build. See LuaJIT memory profiler and LuaJIT platform profiler for details.
Fixed:
- Incorrect
IR_TBARgeneration on aarch64. - Stack overflow handling when exiting a trace.
- Dangling references to
CType. - VM state shutdown after early OOM.
IR_MULgeneration on x86/x64.- Incorrect merging of
stp/ldpinstructions on aarch64. - SCEV record invalidation when returning to a lower frame.
- Build on macOS 15 / Clang 16.
IR_HREFKgeneration on aarch64.- Stack checks in varargs calls in GC64 builds.
- Stack checks in
pcall()/xpcall()in GC64 builds. - Allocation limit in non-JIT builds.
- OOM handling when growing the stack in
coroutine.resume()andlua_checkstack(). - Recording loops with step
-0or control valuesNaN. - Error message generation when an error occurs while handling another error.
- Dangling reference for an FFI callback.
BC_UNMfor argument-0indual-numbermode.- Unary minus narrowing in
dual-numbermode. - Recording of
string.byte(),string.sub(), andstring.find(). - Missing type conversion for
BC_FORIslots indual-numbermode. - Various corner cases in
VM events. - Recording of constructor index resolution in the JIT compiler.
- UBSan warning in
unpack().
Fixed:
- A crash due to an
assertwhen parsing an ambiguous date: when the input contains both the day of year (yday, which implicitly defines month and day of month) and a calendar month (without day of month). Such cases are now detected and reported as an error. tzoffsetcalculations for cases likenew({timestamp=x, tz='Zone'}).- An inconsistency between dates created with
new({tzoffset=x})andd:set({tzoffset=x})whend.tz ~= ''precedesset(). datetime.new()anddatetime_object:set()now validate thattimestampis within the allowed range.timestamptype checking inset().
For backward compatibility, the option compat.datetime_setfn_timestamp_type_check has been added. It is disabled by default (the “old” behavior), meaning no type check is performed. The “new” behavior with type checking is planned to become the default in 4.x.
Note
The modules listed below have changes in this release. If a module is not listed, it was not updated.
Note
Starting with CRUD 1.6.0, a vulnerability that allowed performing operations without sufficient privileges has been fixed. CRUD now strictly enforces access rights: a user can perform only the actions allowed by their privileges. If the application needs access to service spaces, the corresponding privileges must be granted explicitly.
See details in Reading and writing data with CRUD.
Safe mode and rolling-upgrade compatibility details are described in Upgrading the crud module (see Compatibility limitation during upgrade and Upgrade order).
Added:
crud.locate()to determine where a tuple is stored (memtx or vinyl). Works for spaces managed by the enterprise modulecooler.crud.lennow supports options:mode,balance,prefer_replica,request_timeout.- Safe mode to prevent writing data to the wrong replica set during vshard rebalancing.
- Metric
tnt_crud_router_cache_clear_tsto help properly disable safe mode in a cluster. - Automatic switch to safe mode when rebalancing starts.
- Ability to manually switch back to fast mode (
fast mode). - Metric
tnt_crud_storage_nil_bucket_id_compat_totalto track operations performed withoutbucket_ref(compatibility mode with older routers).
Fixed:
- Read-only operations (
get,select,pairs,count,min,max) are now executed via healthy replicas even if all master nodes in the cluster are unavailable. - Storage compatibility with routers < 1.7.0:
bucket_id = nilis now handled correctly inget,update, anddelete. In this case, storage skips bucket referencing and logs a rate-limited warning about reduced rebalancing safety during rolling upgrades. bucket_referrors incrud.*_manymethods are now returned as an array.bucket_unrefwas moved out of the transaction.- Prevented duplicate metrics from being created on repeated
initcalls. - Prevented duplicate triggers on the
_crud_settings_localspace on repeatedinitcalls. - A deadlock in
crud.schema()after a schema reload error. - Removed metric
tnt_crud_storage_safe_mode_enabledfrom the router. - Removed
wrap_box_space_func_resultwrapper to reduce allocations and speed up storage calls. - Optimize
crud.select()andcrud.pairs()pagination withaftercursor by using nativeafteroption on Tarantool 2.10+ for O(1) cursor positioning.
Changed:
- When switching to safe mode, the practice of marking/stopping iproto fibers in fast mode was discontinued; operation correctness on storage is validated via
yield_checksin tests. - Switching to safe mode was moved from the
on_committrigger toon_replace. - Vinyl spaces always operate in safe mode.
Version 0.1.40 is fully compatible with previous vshard versions.
Added:
- Ability to disable the log rate limiter via the
constsmodule. - Calling
vshard.router.info()andvshard.storage.info()is now allowed even when the router or storage is disabled. The functions now also return a new boolean field:is_enabled. - Improved logging for rebalancer and recovery related activities.
Fixed:
- An issue where the old master node could not discover the new master instance within a replica set.
- Connection leak: connections were not released by the garbage collector after reconfiguration or reload.
- Transaction limitation when working with
_bucket: previously, theon_committrigger on_bucketblocked writes to other spaces within the same transaction (for example, fromon_replacetriggers). Such scenarios are now allowed:on_commitskips changes related to “foreign” spaces. - An issue where a user error was masked by the
Transaction is active...error when calling a persistent function that throws an error and does not close a transaction on Tarantool versions earlier than 3.0.0-beta1-18. Now, vshard automatically closes such transactions and returns the original user error. - An issue where a connection to a replica was not automatically restored when it was closed either by vshard or by the user.
graphite: added support for sending metrics to multiple servers.- Removing a replica via
box.space._cluster:delete()does not remove that replica’s information from metrics; it disappears only after a cluster restart. - Backward compatibility with the previous plugin version is preserved.
- Behavior changes:
initnow assigns a unique name to the createdfiberbased on the inputgraphite serveroptions (if provided).- Added
stop()to stop allfibersstarted by the plugin.
Added:
tt pack: added support for nested.packignorefiles in the root of a tt environment.tt status: added the--formatoption to output status in JSON and YAML formats (machine-readable output).
Changed:
tt export: changed the default behavior for compound fields (arrays and maps): they are now exported in JSON format by default. To restore the previous behavior, use--compound-value-format=ignore.
Fixed:
- Integrity checking for an application using the Cartridge directory layout (a single application whose root directory is the environment root).
- An issue with Tarantool 3.5+: the instance did not stop when the periodic integrity check failed.
- Minor fixes identified by the Svacer static analyzer and CVE scanners.
Changed:
- Do not expand the file tree by default on the code page.
- Update vshard dependency to 0.1.40.
- Update membership dependency to 2.5.3.
- Update cartridge-metrics-role dependency to 0.1.3.
- Update graphql dependency to 0.3.1.
- Update http dependency to 1.9.0.
Fixed:
- Refactor synchronous spaces monitoring to consider the actual failover mode.
Sync spaces warning is now logged when failover is configured in a mode that doesn’t support them (eventual, stateful without
synchro_mode), instead of unconditionally at instance startup. - Added
is_sync_spaces_supported()function tocartridge.failover module. - Sync spaces are now detected dynamically, allowing detection of spaces added at runtime.
The release introduces a new ssl_verify_client option and changes default behavior with provided ca_file parameter.
Also a few bugs were fixed.
Added:
- New
ssl_verify_clientoption.
Fixed:
- Do not recreate server if it’s address and port were not changed.
- Server doesn’t change after updating parameters on config reload.
Breaking change:
Mutual TLS with ca_file option enabled by default.
Module http documentation.
- Added manual trigger job to run tests to generate
certificate of compliance. Ready for Astra Linux.
- Bumped Cartridge version to 2.16.0.
- Bumped Cartridge version to 2.15.4.
- Bumped Kafka version to 1.6.10.
- Bumped Cartridge version to 2.15.3.
- Bumped Cartridge version to 2.15.1.
- Bumped
tt-eeversion to v2.8.1. - Bumped
vshard-eeversion to 0.1.32.
- Bumped Cartridge version to 2.15.0.
- Bumped
membershipversion to 2.5.1. - Bumped
expirationd-eeversion to 1.8.0.
- Bumped
tarantool-2.11series to 2.11.6. - Bumped
tt-eeversion to v2.8.0. - Bumped
migrations-eeversion to 1.3.1.
- Bumped
tarantool-2.11series to 2.11.5. - Bumped
tt-eeversion to v2.5.2. - Updated Kafka to 1.6.9.
- Bumped
tt-eeversion to v2.5.1. - Bumped
tt-eeversion to v2.5.0.
- Moved
cartridge-auth-extensionto stable directory. - Bumped
crud-eeversion to 1.7.1. - Bumped
migrations-eeversion to 1.3.0.
- Bumped
tarantool-2.11series to 2.11.4. - Bumped Cartridge version to 2.12.3.
- Bumped
tt-eeversion to v2.4.0. - Bumped
queueversion to 1.4.2. - Added Migration Guide to bundle.
- Moved to Enterprise Edition modules.
- Fixed Docker image due to CentOS 7 EOL.
- Fixed CI/CD workflows running inside CentOS 7.
- Bumped
tt-eeversion to v2.3.1. - Enabled
ttbash completion. - Updated Kafka to 1.6.8.
- Updated Docker image.
- Updated CMake to 3.20.6.
- Installed dependencies for building OpenSSL.
- Fixed installation of Python 3.6.
- Updated CRUD to 1.5.1.
- Updated
sideserviceto 0.2.1. - Updated
httpgoto 0.2.2. - Updated
httpgo-crudto 0.1.1.
- Updated
cartridge-clito 2.12.12. ttused instead oftarantoolctlfor build/test routines.- Made Tarantool and bundle versions correct.
- Bumped
tarantool-2.11to 2.11.3.
- Updated
cartridge-clito 2.12.9. - Updated
tt-eeto 1.3.1.
- Updated
cartridge-clito 2.12.7. - Updated
tarantool-2.11to 2.11.1.
- Added
vshard0.1.22.
- Fixed non-interactive installation of the
brewpackage. - Changed the owner of the
/usr/local/bindirectory. - Installed
awscli@1instead ofawsclisince it takes much less time.
- Added
expirationd1.3.1.
- Added CRUD 1.0.0.
- Refactored the way that GC64 builds are defined in the build workflow. There are no changes to the composition of resulting bundles.
- Added alerting failures in builds on stable branches and integration testing to VK Teams chats.
- Added Cartridge 2.7.7.
Release SDK by tags:
- Run workflow in SDK docker container.
- Uploaded SDK files for 1.10, 2.8, 2.10 versions to release folder.
- Added consistency check for all versions.
- Removed support of Tarantool 2.7.
- Started using
tarantool/actions/prepare-checkoutto make builds more stable.
- Remove the local registry and setup using GitHub registry.
- Sync rocks cache to S3 and back.
- Setup using shared runners.
- Refactor and format
ci-linux.ymlandci-macos.yml.
- Removed Kafka 1.5.0 due to a build issue with Tarantool 2.10.3 and higher.
- Updated Kafka to version 1.6.2.
- Updated
tuple-keydefto version 0.0.3.
- Updated Tarantool to 2.10.3.
- Added a readable error for the case when the flight recoder fails
to write data due to insufficient free space on the disk device.
Previously, it was sending a
SIGBUSerror. - Fixed a crash in the flight recorder caused by non-thread-safe log recording from multiple threads.
- Updated Tarantool to 2.10.2.
- Increased resolution of stored entries in flight recorder.
- Fixed a bug in the flight recorder that resulted in skipping log entries in case
box.cfg.log_levelis less thanflightrec_log_level.
- Updated Tarantool to 2.10.1.
- Updated Cyrus SASL to version 2.1.28.
- Updated OpenLDAP to version 2.5.13.
- Updated LZ4 to version 1.9.3. Fixed CVE-2021-3520.
- Fixed replication reconnect failure after disabling SSL encryption.
- Fixed a crash that occurred while tyring to start an instance that has
a compressed
memtxspace. - Fixed CVE-2022-29242 in GOST SSL engine.
- Fixed a bug in the flight recorder reader implementation that resulted in a hang or error while trying to open an empty section.
- Implemented user-defined audit events. Now it’s possible to log custom messages to the audit log from Lua.
- [Breaking change] Switched the default audit log format to CSV. The
format can be switched back to JSON using the new
box.cfg.audit_formatconfiguration option. - Implemented the audit log filter. Now, it’s possible to enable logging only
for a subset of all audit events using the new
box.cfg.audit_filterconfiguration option.
- Implement constraints and foreign keys. Now a user can create function constraints and foreign key relations (gh-6436).
- Changed log level of some information messages from critical to info (gh-4675).
- Added predefined system events:
box.status,box.id,box.electionandbox.schema(gh-6260). - Introduced transaction isolation levels in Lua and IPROTO (gh-6930).
- Disabled the deferred DELETE optimization in Vinyl to avoid possible
performance degradation of secondary index reads. Now, to enable the
optimization, one has to set the
defer_deletesflag in space options (gh-4501).
- Added support of console autocompletion for
net.boxobjectsstreamandfuture(gh-6305).
- Added bundling of GNU libunwind to support backtrace feature on AARCH64 architecture and distributives that don’t provide libunwind package.
- Re-enabled backtrace feature for all RHEL distributions by default, except for AARCH64 architecture and ancient GCC versions, which lack compiler features required for backtrace (gh-4611).
- Disabled audit log unless explicitly configured. Before this change,
audit events were written to stderr if
box.cfg.audit_logwasn’t set. Now, audit log is disabled in this case. - Disabled audit logging of replicated events. Now, replicated events (for example, user creation) are logged only on the origin, never on a replica.
- Banned DDL operations in space on_replace triggers, since they could lead to a crash (gh-6920).
- Fixed a bug due to which all fibers created with
fiber_attr_setstacksize()leaked until the thread exit. Their stacks also leaked except whenfiber_set_joinable(..., true)was used. - Fixed a crash in mvcc connected with secondary index conflict (gh-6452).
- Fixed a bug which resulted in wrong space count (gh-6421).
- Select in RO transaction now reads confirmed data, like a standalone (auotcommit) select does (gh-6452).
- Fixed potential obsolete data write in synchronous replication due to race in accessing terms while disk write operation is in progress and not yet completed.
- Fixed replicas failing to bootstrap when master is just re-started (gh-6966).
- Fixed the behavior of tarantool console on SIGINT. Now Ctrl+C discards the current input and prints the new prompt (gh-2717).
Intervals received after datetime arithmetic operations may be improperly normalized if result was negative
tarantool> date.now() - date.now() --- - -1.000026000 seconds ...
I.e. 2 immediately called
date.now()produce very close values, whose difference should be close to 0, not 1 second (gh-6882).
- Changed the type of the error returned by net.box on timeout
from
ClientErrortoTimedOut(gh-6144).
- Added binary protocol encryption.
- Added tuple field compression.