v2.10.28

nats-io/nats-serverv2.10.28Apr 25, 2025by github-actions[bot]

AI Summary

This is a patch release (v2.10.28) for NATS Server that includes various improvements and bug fixes, particularly around JetStream performance and stability. However, the release note indicates this version contains a regression and advises users to upgrade to v2.10.29 instead.

Key Highlights

  • Important security improvement: auth tokens are now redacted in trace-level logs
  • JetStream purge performance significantly improved, especially for KV PurgeDeletes calls
  • GOMAXPROCS and GOMEMLIMIT now reported in both statsz and varz for better monitoring
  • Servers that have been peer-removed can now be re-admitted automatically after 5 minutes without restart
  • Multiple JetStream bug fixes including consumer state preservation, memory leak fixes, and filestore corruption prevention

New Features

  • Publish permissions cache now more aggressively pruned to stay under max allowed size
  • Service imports can now import the same subject from multiple different accounts
  • Updating account claims with reduced max connection count no longer causes internal clients to be closed
  • Trapped signals now logged at notice level instead of debug
  • Improved replicated asset creation performance by campaigning for group leadership more quickly
  • Filestore tombstones for purges now written asynchronously where possible
  • Improved checking for streams that overlap with JS API or system subjects

Full Release Notes

> [!IMPORTANT]
> This version contains a regression that has since been fixed in 2.10.29. Please upgrade to that version instead.

## Changelog

Refer to the [2.10 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_210) for backwards compatibility notes with 2.9.x.

### Go Version

- 1.24.2

### Dependencies

- github.com/nats-io/nats.go v1.41.2 (#6805)
- github.com/nats-io/nkeys v0.4.11 (#6805)
- golang.org/x/crypto v0.37.0 (#6805)
- golang.org/x/sys v0.32.0 (#6805)
- github.com/nats-io/jwt/v2 v2.7.4 (#6813)

### Improved

General

- The publish permissions cache should now remain under the max allowed size more aggressively with improved pruning (#6674)
- It is now possible with service imports to import the same subject from multiple different accounts (#6704)
- Updating an account claim with a reduced max connection count no longer causes internal clients to be closed, fixing cases where JetStream assets could become unavailable (#6785)
- `GOMAXPROCS` and `GOMEMLIMIT` are now reported in both `statsz` and `varz` (#6791)
- Auth tokens are now redacted in trace-level logs for enhanced security (#6808)
- Trapped signals are now logged at notice level instead of debug (#6800)

JetStream

- Improved purge performance, particularly for KV `PurgeDeletes` calls, with optimised code paths for finding last sequences and reducing allocations (#6801)
- Improved replicated asset creation performance by campaigning for group leadership more quickly (#6697)
- Improved the debug log message when resetting a group WAL after failing to truncate (#6705)
- Improved checking for streams that overlap with JS API or system subjects, so that badly-configured streams should not be able to break the API (#6786)
- Servers that have been `peer-remove`'d can now be re-admitted automatically after 5 minutes without a server restart (#6815)
- Filestore tombstones for purges are now written asynchronously where possible, improving performance (#6825)

### Fixed

General

- Fix a possible panic when a subject transform has missing tokens (#6612)
- Fix a possible panic when adding dedicated routes during a configuration reload (#6668)
- Data race when shutting down eventing has been resolved (#6620)
- A deadlock when updating account claims with service imports/exports has now been fixed (#6726)
- The `jsz` monitoring endpoint now correctly paginates with `offset` (#6794, #6816)

JetStream

- JetStream is no longer incorrectly disabled when specifying `--js` and `--store_dir` on the command line and then issuing a configuration reload (#6609)
- Correctly remove messages from an interest-based stream when using `AckAll` consumers (#6587)
- Preserve the first sequence when rebuilding state due to invalid checksums with no remaining messages (#6647)
- When recovering from disk, ignore temporary files that can be created during stream compression so that the same blocks do not get loaded more than once (#6684)
- Do not incorrectly reset group WALs when a new leader sends matching term information after a snapshot (#6691)
- Corrected a regression in the memory store when purging, aligning it with the filestore behaviour (#6714)
- When issuing a peer remove on a stream, the new peer set is now proposed through the NRG layer, potentially avoiding a drift in peers (#6720)
- When issuing a peer remove on a consumer, the new peer set is now proposed through the NRG layer, potentially avoiding a drift in peers (#6727)
- A race condition that could result in observer nodes becoming incorrectly elected as a group leader has been fixed when using leafnodes with shared system accounts (#6730)
- Ensure that duplicate Raft groups are not created for the same asset during a restart (#6732)
- Allow the use of the extended consumer create API when combining service imports/exports and limited API permissions (#6759)
- Streams with the `FirstSeq` configured are no longer incorrectly purged after a restart if the stream first sequence still matches the configured first sequence (#6753)
- Correctly write tombstones when purging and compacting, fixing a bug that could result in some deleted messages returning if the stream index had to be rebuilt (#6685)
- The memory store no longer leaks memory tracking deleted sequences after a full stream purge (#6769)
- Correctly handle acks for subjects that include a `@` character (#6777)
- Avoid losing stream sequence numbers of the server is interrupted by generating a new last message block before removing the final remaining block, particularly noticeable with WQ or interest retention policies (#6778)
- Use the correct floor when using `AckAll` in R1 consumers (#6790)
- Preserve consumer state when a stream needs to be reset due to a failed catchup (#6796)
- Correctly enforce the 32MB maximum publish size limit into JetStream, avoiding filestore corruption from overflowing the maximum record length (#6798)
- Push consumers are no longer incorrectly marked as inactive after a delivery failure if there is continued interest (#6807)
- Internal clients for JetStream are no longer closed unexpectedly after updating an expired account claim (#6817)
- Fixed a panic that could potentially occur when starting clustered consumers when the metalayer is shutting down (#6823)
- Fixed a bug in subject tree intersection that could miss some subjects when looking for first matching messages matching `FilterSubjects` (#6828, #6827)

Gateways

- Fixed a bug that could result in a lost queue subscriptions on gateway connections after a restart or a remote unsubscribe (#6607)

### Complete Changes
 
https://github.com/nats-io/nats-server/compare/v2.10.27...v2.10.28