This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+10 more
Affected surfaces
Summary
AI summaryUpdates What's Changed Seaweed Volume, Rust, and Go across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Require JWT authorization on TUS upload endpoints. Require JWT authorization on TUS upload endpoints. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Measure quota usage by logical size. Measure quota usage by logical size. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Surface OIDC groups and roles into STS session request context for ABAC. Surface OIDC groups and roles into STS session request context for ABAC. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Implement async, buffered writes in VolumeEcShardsCopy for Seaweed Volume (Rust). Implement async, buffered writes in VolumeEcShardsCopy for Seaweed Volume (Rust). Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Feature | Low |
Rank volumes by physical disk usage. Rank volumes by physical disk usage. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Feature | Low |
Keep listing when empty directories fill the listing window. Keep listing when empty directories fill the listing window. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Feature | Low |
Share replica selection between shell and workers in topology/balancer. Share replica selection between shell and workers in topology/balancer. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Dependency | Low |
Upgrade google.golang.org/api from 0.278.0 to 0.287.0. Upgrade google.golang.org/api from 0.278.0 to 0.287.0. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Dependency | Low |
Upgrade github.com/aws/aws-sdk-go-v2/credentials from 1.19.24 to 1.19.26. Upgrade github.com/aws/aws-sdk-go-v2/credentials from 1.19.24 to 1.19.26. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Dependency | Low |
Upgrade github.com/Azure/azure-sdk-for-go/sdk/storage/azblob from 1.7.0 to 1.8.0 in Go dependencies. Upgrade github.com/Azure/azure-sdk-for-go/sdk/storage/azblob from 1.7.0 to 1.8.0 in Go dependencies. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Dependency | Low |
Upgrade github.com/go-redsync/redsync/v4 from 4.16.0 to 4.17.0 in Go dependencies. Upgrade github.com/go-redsync/redsync/v4 from 4.16.0 to 4.17.0 in Go dependencies. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Performance | Low |
Cut metadata‑subscription allocation churn. Cut metadata‑subscription allocation churn. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Performance | Low |
Share one log‑buffer window snapshot across all subscriber reads. Share one log‑buffer window snapshot across all subscriber reads. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Performance | Low |
Optimize encodePath memory allocations in S3. Optimize encodePath memory allocations in S3. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Performance | Low |
Reduce memory allocation while building strings in refract. Reduce memory allocation while building strings in refract. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Performance | Low |
Cap the shared‑snapshot race test's heap in log_buffer. Cap the shared‑snapshot race test's heap in log_buffer. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Bugfix | Medium |
Fail over routed object writes when the owner filer is unreachable. Fail over routed object writes when the owner filer is unreachable. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Re‑assign to a live volume when a write cannot land. Re‑assign to a live volume when a write cannot land. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Parallelize under‑replicated volume copies. Parallelize under‑replicated volume copies. Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
Verify SigV4 against each plausible reverse‑proxy host. Verify SigV4 against each plausible reverse‑proxy host. Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Low |
Fix orphan purge against the Rust volume server. Fix orphan purge against the Rust volume server. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Bugfix | Low |
Clear remote flag when tiering a volume back to local. Clear remote flag when tiering a volume back to local. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Bugfix | Low |
Reload a remote‑tiered volume without re‑entering the data lock. Reload a remote‑tiered volume without re‑entering the data lock. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Bugfix | Low |
Keep the internal .system folder out of the per‑bucket store path. Keep the internal .system folder out of the per‑bucket store path. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Bugfix | Low |
Keep empty‑folder cleanup out of the multipart .uploads staging tree. Keep empty‑folder cleanup out of the multipart .uploads staging tree. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Bugfix | Low |
Tear down the emptied .versions directory on last‑version delete. Tear down the emptied .versions directory on last‑version delete. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Bugfix | Low |
Stop holding the shell admin lock across whole scheduler batches. Stop holding the shell admin lock across whole scheduler batches. Source: granite4.1:30b@2026-07-16-audit Confidence: high |
— |
| Bugfix | Low |
Support HTTP Basic Auth for filer behind an Nginx reverse proxy. Support HTTP Basic Auth for filer behind an Nginx reverse proxy. Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Low |
Keep tier‑uploaded volume reporting to master after volume.tier.upload. Keep tier‑uploaded volume reporting to master after volume.tier.upload. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Low |
Fail cleanly when a chunk read returns short or empty data in Java Client. Fail cleanly when a chunk read returns short or empty data in Java Client. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
Full changelog
What's Changed
Seaweed Volume (Rust)
- async, buffered writes in VolumeEcShardsCopy (#10237)
- fix orphan purge against the rust volume server (#10289)
Volume (Go)
- keep tier-uploaded volume reporting to master after volume.tier.upload (#10259)
- clear remote flag when tiering a volume back to local (#10262)
- reload a remote-tiered volume without re-entering the data lock (#10266)
- parallelize under-replicated volume copies (#10275)
- rank by physical disk usage (#10271)
Filer
- keep the internal .system folder out of the per-bucket store path (#10248)
- require JWT authorization on TUS upload endpoints (#10249)
- cut metadata-subscription allocation churn (#10260)
- share one log-buffer window snapshot across all subscriber reads (#10267)
S3
- optimize encodePath memory allocations (#10252)
- fail over routed object writes when the owner filer is unreachable (#10251)
- keep empty-folder cleanup out of the multipart .uploads staging tree (#10273)
- tear down the emptied .versions directory on last-version delete (#10278)
- keep listing when empty directories fill the listing window (#10280)
- measure quota usage by logical size (#10274)
- verify SigV4 against each plausible reverse-proxy host (#10284)
Mount
- re-assign to a live volume when a write can't land (#10239)
IAM
- surface OIDC groups and roles into the STS session request context for resource-policy ABAC (#10263)
Java Client
- HTTP Basic Auth for filer behind an Nginx reverse proxy (#10258)
- fail cleanly when a chunk read returns short or empty data (#10269)
Shell & Admin
- print markVolumeWritable/markVolumeReadonly based on the writable flag (#10283)
- stop holding the shell admin lock across whole scheduler batches (#10290)
Topology & Balancer
- share replica selection between shell and workers (#10276)
Other
- reduce mem alloc while building str in refract (#10261)
- cap the shared-snapshot race test's heap in log_buffer (#10281)
- dropped test error in weed/worker/tasks/balance (#10291)
- merge filer service annotations to avoid duplicate keys in Helm (#10293)
Dependencies
- google.golang.org/api 0.278.0 → 0.287.0 (#10246)
- github.com/Azure/azure-sdk-for-go/sdk/storage/azblob 1.7.0 → 1.8.0 (#10245)
- github.com/aws/aws-sdk-go-v2/credentials 1.19.24 → 1.19.26 (#10243)
- github.com/go-redsync/redsync/v4 4.16.0 → 4.17.0 (#10244)
- github.com/ydb-platform/ydb-go-sdk-auth-environ 0.5.1 → 0.5.2 (#10240)
- docker/setup-qemu-action 4.1.0 → 4.2.0 (#10242)
- docker/login-action 4.2.0 → 4.4.0 (#10241)
- golang.org/x/crypto 0.45.0 → 0.52.0 in /test/sftp (#10264)
- golang.org/x/crypto 0.51.0 → 0.52.0 in /test/kafka/kafka-client-loadtest (#10265)
New Contributors
- @dongle-code made their first contribution in https://github.com/seaweedfs/seaweedfs/pull/10252
- @chriswydra made their first contribution in https://github.com/seaweedfs/seaweedfs/pull/10263
Full Changelog: https://github.com/seaweedfs/seaweedfs/compare/4.38...4.39
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About seaweedfs
SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables, designed to handle billions of files with O(1) disk access and effortless horizontal scaling.
Related context
Related tools
Earlier breaking changes
- v4.24 Version 4.23 is unsafe with multiple disks when using erasure coding (EC).
Beta — feedback welcome: [email protected]