Version 3.9.0 Release Notes
Compatible with OpenSearch and OpenSearch Dashboards version 3.9.0
Features
- Add DELETE task API for removing stored completed task results (#21727)
- Add deployment drain and finish APIs for zero-downtime node deployments (#21448)
- Add adaptive per-action concurrency limiting module with Vegas, Gradient2, and AIMD algorithms (#22312)
- Add virtual thread-per-task executor support to ThreadPool (#22485)
- Add extensible payload decoder framework for pull-based ingestion (#22364)
- Add plugin SPI for dynamic field-type inference and dynamic-template types (#22607)
- Add pluggable PrimaryOperationPolicy to EngineConfig for cross-cluster replication (#22886)
- Add object-store fencing token for remote store primary term validation (#22774)
- Auto-restore remote store primaries on node loss when no valid copy survives (#22904)
- Add FieldDomain metadata producer API for enhanced can_match shard pruning (#22483)
- Add intra-segment search support for histogram, auto_date_histogram, and range aggregations (#22531)
- Add MPP-style distributed join and aggregation execution for the analytics engine (#21844)
Enhancements
- Add
cluster.blocks.read.auto_releasesetting to prevent unconditional auto-release of user-set index read blocks (#22610) - Add cluster-level remote-store flush settings for uncommitted segments (#22935)
- Restore size-based periodic flush on remote-store shards (#22865)
- Apply
index.periodic_flush_intervalchanges to running shards dynamically (#22991) - Use ordinals instead of byte values for bucket keys in multi-term aggregations (#21033)
- Optimize bucket counting and tracking in LongKeyedBucketOrds with O(1) lookups (#22450)
- Speed up reading history operations from Lucene via sequential stored-fields reader (#22603)
- Use
prefixQueryto speed upwildcardQueryandregexpQueryfor wildcard field type (#22510) - Preserve
constant_scorethrough filtered aliases to maintain Lucene no-scoring fast path (#22776) - Promote lowest-version replica on document-replication failover to prevent stuck replicas during rolling upgrades (#22783)
- Avoid cancellation checks on every
advance()call for posting enums to reduce CPU overhead (#22856) - Avoid quadratic identifier scan when removing snapshots (#22968)
- Stream translog parts instead of buffering the whole file for upload (#23015)
- Change tiered cache default partition count to 16 for improved hit rates on high-core instances (#23032)
- Bound Arrow native memory pools when
node.native_memory.limitis unknown (#22762) - Lower default
arrow.flight.channel.outbound_buffer_thresholdfrom 64 MB to 512 KB (#22697) - Deprecate
RestHighLevelClientin favor ofopensearch-javaclient (#23008) - Remove Jackson 2.x dependencies from OpenSearch core (#22704)
- Remove legacy client benchmark and noop API plugin modules (#21839)
- Preserve routing in
Translog.Deletefor CDC-based replication (#22584) - Exempt server-injected preferences from strict weighted routing check and scope them per index (#22571)
- Reject out-of-range WLM node threshold updates at validation time (#22649)
- Return HTTP 400 for
too_many_clausesandtoo_many_nested_clauseserrors (#21725) - Refactor
forPatternif-else chains to switch onFormatNamesenum for O(1) dispatch (#22568) - Drain active streams before closing Flight channel to prevent spurious leak errors (#22642)
- Skip stream connections to nodes without a stream address in mixed-version clusters (#22810)
- Remove duplicate native memory limit setting from
NodeDuressSettings(#22620)
Bug Fixes
- Fix
ApproximateScoreQuery.equalsfor query cache correctness (#22737) - Fix NPE on collapse with
search_aftersort using_scoreor_doc(#23029) - Fix NPE when creating a match-all composable index template without an inline template (#22421)
- Fix NPE in routing table checksum when a shard has no primary (#22723)
- Fix
ClassCastExceptionin mixed rollup and raw indexavgaggregation reduce (#22658) - Fix parent-bucket scoping in
StreamStringTermsAggregatorfor nested terms aggregations (#21447) - Fix cache entries removed before promotion being retained indefinitely (#22662)
- Fix stale fielddata retention by invalidating exact key on reader close (#22491)
- Use point-in-time key snapshot for fielddata cache cleanup to prevent missed entries (#22499)
- Invalidate exact bitset filter cache keys on reader close (#22498)
- Make
ICachekeys()iteration safe under concurrent mutation (#22542) - Fix stranded snapshot markers on publish failure with bounded retry (#22518)
- Fix OpenSearch process not exiting when startup fails due to
StartupException(#22259) - Bound completion suggester
max_determinized_statesto prevent heap exhaustion (CVE-2026-63136) (#22924) - Fix silent hang when REST response body cannot be serialized (#22840)
- Fix
opensearch-heap-prof resetcrashing on non-numericlg_prof_sampleargument (#22970) - Re-register persistent task throttling keys to prevent cluster state restore failure (#22656)
- Fix node crash on partially-consumed native stream teardown (#22754)
- Fix virtual-thread scheduler deadlock from Flight client stream failure logging (#22743)
- Fix constant ~5s stall in coordinator reduce teardown on limited queries (#22609)
- Fix 500 on PPL query over alias spanning mapping-less index (#22665)
- Fix
use slice()instead ofclone()for multipart uploads inRemoteDirectoryto preventAlreadyClosedException(#22705) - Gate internal ignore settings on remote data attributes in snapshot restore (#22570)
- Allow read access to Kubernetes pod cgroup paths (#22846)
- Fix HTTP connection leaks in plugin install command (#22507)
- Fix ambiguous
Nodetype reference inbuild.gradle(#22514) - Revert default SSE type to
bucket_defaultto fix S3-compatible storage uploads (#23041)
Maintenance
- Bump Apache HttpCore5 to 5.4.3 and Apache HttpClient5 to 5.6.4 to fix TLS latency regression (#22731)
- Update AWS SDK to 2.54.2 to fix S3 upload failures (#22816)
- Upgrade Lucene to 10.5.1 (#22898)
- Update bundled JDK to 25.0.4.1+1 (#22808)
- Update Gradle to 9.7.1 (#22719)
- Update log4j to 2.25.5 (CVE-2026-49844) (#22923)
- Bump Jackson to 2.22.2 (#22847)
- Update OpenTelemetry to 1.66.0 and OpenTelemetry Semconv to 1.44.0 (#23033)
- Update Project Reactor to 3.8.7 and Reactor Netty to 1.3.7 (#22848)
- Update SnakeYaml to 2.7 and SnakeYaml Engine to 3.1.1 (#23006)
- Bump Apache RAT dependency from 0.15 to 0.18 (#22770)
- Bump com.squareup.okio:okio from 3.16.4 to 3.17.0 (#21617)
- Bump com.sun.xml.bind:jaxb-impl from 4.0.7 to 4.0.8 (#21614)
- Bump org.apache.commons:commons-configuration2 from 2.15.0 to 2.15.1 (#21947)
- Bump org.carrot2:morfologik-stemming from 2.1.9 to 2.2.0 (#22156)
- Bump org.jsoup:jsoup from 1.22.2 to 1.23.1 (#22641)
- Bump org.jspecify:jspecify from 1.0.0 to 1.0.1 (#22640)
- Bump org.jline:jline from 4.0.14 to 4.4.2 (#23001)
- Bump com.google.jimfs:jimfs from 1.3.1 to 1.3.2 (#22866)
- Bump com.github.spotbugs:spotbugs-annotations from 4.10.1 to 4.10.4 (#22158, #23000)
- Bump com.diffplug.spotless to 8.10.1 (#22874)
- Remove obsolete OS packaging tests (#22879)
- Replace deprecated
AccessControllerin core libraries and plugins (#22503, #22988)