4.40

spider-rs/spider4.40Jul 20, 2026by chrislusf

AI Summary

This release prioritizes security hardening for S3 and Filer, particularly around OIDC authentication and TUS session authorization. It also includes critical bug fixes for Erasure Coding rebalancing and volume server operations, alongside new administrative shell commands.

Key Highlights

  • S3 security enhancements including OIDC trust policy enforcement and improved CopyObject error handling.
  • Filer hardening for TUS upload endpoints and backup data integrity.
  • Erasure Coding fixes to prevent rebalancing against outdated topology and cleanup of sidecars.
  • New Shell commands for cluster status and volume tier operations.
  • Volume server fixes for overflowing needle IDs and Rust build compatibility.

New Features

  • ec.check.replication shell command
  • cluster.ps shell command
  • volume.tier.upload keeping replicas

Full Release Notes

## What's Changed

## S3

* s3: enforce role trust policy on direct OIDC bearer authentication by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10302
* s3: accept raw semicolons in query strings by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10305
* s3: return NoSuchKey/NoSuchBucket for a missing CopyObject source by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10332
* s3: invalid tagging on CopyObject returns InvalidTag, not InvalidCopySource by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10362
* Fix PutObjectAcl writing back to the wrong object for nested keys by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10333
* Fix object tagging writing back to the wrong object for nested keys by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10338
* fix: report short S3 ReaderAt reads by @7y-9 in https://github.com/seaweedfs/seaweedfs/pull/10345

## Filer

* fix(filer.backup): prevent silent backup data loss on transient not-found by @kisow in https://github.com/seaweedfs/seaweedfs/pull/10295
* filer: scope TUS HEAD/PATCH/DELETE against the session target path by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10309
* filer: harden TUS session authorization against cross-prefix access by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10315
* filer: allow clearing a bucket read-only flag stuck after quota removal by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10310
* route log buffer flush copies through the shared slab pool by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10336
* generate vtproto marshalers for filer_pb and use them on the metadata log path by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10337
* cassandra: do not mask KvGet backend errors as not-found by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10361

## Erasure Coding

* ec.encode: don't rebalance against a topology that predates the new shards by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10303
* ec: remove .ecsum sidecars on destroy / shard delete; align Go and Rust cleanup by @franchb in https://github.com/seaweedfs/seaweedfs/pull/10307
* shell: default batch size for ec.encode and ec.decode by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10308
* Introduce weed shell command `ec.check.replication`. by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10328

## Shell

* shell: volume.tier.upload keeps volume replicas by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10314
* shell: volume.check.disk -resurrectMissingNeedles for never-vacuumed replicas by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10316
* shell: show who holds the cluster lock by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10353
* shell: cluster.ps lists s3 servers by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10359

## Master

* master: statistics used size covers all collections in https://github.com/seaweedfs/seaweedfs/pull/10319
* master: assign re-picks once after its growth concludes instead of shedding by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10348

## Volume Server

* fix(volume): reject overflowing needle ID deltas by @7y-9 in https://github.com/seaweedfs/seaweedfs/pull/10342
* batch delete: align the shard test and Rust server with @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10349
* volume server: fill in ModifiedAtSecond on the /status https://github.com/seaweedfs/seaweedfs/pull/10351
* rust volume: verify the .dat ends at the last indexed needle by @chrislusf in https://github.com/seaweedfs/seaweedfs/pull/10320
* fix Rust build with protoc versions lacking native proto3 https://github.com/seaweedfs/seaweedfs/pull/10343

## Mount

* mount: surface ENOSPC instead of endless waiting in https://github.com/seaweedfs/seaweedfs/pull/10341

## New Contributors
* @franchb made their first contribution in https://github.com/seaweedfs/seaweedfs/pull/10307

**Full Changelog**: https://github.com/seaweedfs/seaweedfs/compare/4.39...4.40