Merged PRs
dolt
- 11665: go: sqle/resolve: Have SearchPath() parse the search path in a way which is more compliant with postgres.
Correctly handle quoted identifiers and ToLower any unquoted ones. - 11659: build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /integration-tests/go-sql-server-driver
Bumps google.golang.org/grpc from 1.82.1 to 1.83.1.Release notes
Sourced from google.golang.org/grpc's releases.
Release 1.83.1
Security
- xds/rbac: Fix a bug where nested
PrincipalorPermissionrules with:schemeorgrpc-prefixed header matchers were not rejected, which could cause DENY rules to fail open. (#9258)- Special Thanks:
@nvxbug
- Special Thanks:
- xds/rbac: Fix a bug where the
hostheader matcher was not being replaced with:authorityin nestedPrincipalorPermissionrules. (#9258)- Special Thanks:
@nvxbug
- Special Thanks:
- xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as
X-Role, matched no header, which could cause DENY rules to fail open. (#9332)- Special Thanks:
@alimony
- Special Thanks:
- xds/rbac: Fix a bug where a
:schemeorgrpc-prefixed header matcher was accepted when its name was not lowercase. (#9332)- Special Thanks:
@alimony
- Special Thanks:
- xds/rbac: Fix a bug where a
Hostheader matcher was not replaced with:authority. (#9332)- Special Thanks:
@alimony
- Special Thanks:
Performance
- transport: Restrict memory overhead of buffering small data frames. (#9331)
Release 1.83.0
Security
- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable
GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT. - xds/rbac: Support
MetadataandRequestedServerNamepermissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in
NotRule/NotIdpermissions. - xds/rbac: Support the deprecated
source_ipprincipal identifier by treating it as equivalent todirect_remote_ip. - xds: Fix panic when parsing route header matchers configured with empty
exact_match,prefix_match, orsuffix_matchstrings. (#9223)
New Features
- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the
force-xdstarget URI query parameter. (#9133) - xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. (#9145)
- authz: Add
OnPolicyUpdatecallback toFileWatcherOptionsto notify when an authz policy is loaded or updated. (#9142)- Special Thanks:
@hnefatl
- Special Thanks:
- xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
- This feature can be enabled by setting environment variable
GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true. (#9119)
- This feature can be enabled by setting environment variable
- xds: Add support for xDS-based HTTP CONNECT proxies.
- This feature can be enabled by setting environment variable
GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true. (#9151)
- This feature can be enabled by setting environment variable
- xds: Add support for
contains_matchin route header matchers. (#9223)
Bug Fixes
- credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. (#9197)
- grpc: Fix compilation on Plan 9 targets (
GOOS=plan9), broken since v1.81.0. (#9255)- Special Thanks:
@Yusufihsangorgel
- Special Thanks:
Release 1.82.2
Security
- server: Reject requests missing both
:authorityandHostheaders with HTTP 400 and statusInternal. (grpc/grpc-go#9365)
... (truncated)
Commits
1550d9eChange version to 1.83.1 (#9336)ebba6f3Cherry-pick #9258 and #9332 into v1.83.x (#9335)8cfeca0Cherry-pick #9331 to v1.83.x (#9333)dec6951Change version to 1.83.1-dev (#9229)4c226daChange version to 1.83.0 (#9228)c198988Cherrypick 9223 into v1.83.x (#9279)8ce3ebfCherrypick PR 9255 into v1.83.x (#9263)e393849Cherry-pick recent changes from master (#9240)2a112a8authz: add onPolicyUpdate callback to authz file watcher (#9142)1a80fcavet: adds a check to disallow usage of regex.Compile in xDS code (#9216)- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dolthub/dolt/network/alerts). - xds/rbac: Fix a bug where nested
- 11654: build(deps): bump mysql2 from 3.9.8 to 3.22.0 in /integration-tests/mysql-client-tests/node
Bumps mysql2 from 3.9.8 to 3.22.0.Release notes
Sourced from mysql2's releases.
v3.22.0
3.22.0 (2026-04-10)
Features
- disable mysql_clear_password plugin by default (#4236) (884bec5), closes #1617
- implement COM_RESET_CONNECTION with pool integration (#4148) (49a64cc)
Performance Improvements
v3.21.1
3.21.1 (2026-04-09)
Bug Fixes
- limit client flags to server capabilities (#4227) (e1930b8)
- use Number.isSafeInteger for supportBigNumbers boundary check (#4225) (295264b)
v3.21.0
3.21.0 (2026-04-09)
Features
- add support for query attributes (#4223) (d732f78)
- types: export ExecuteValues and QueryValues from entry point (9fafd6f)
v3.20.0
3.20.0 (2026-03-15)
Features
Bug Fixes
- explicitly specify in auth plugins (#4175) (#4187) (5ac5563)
- prevent double release from corrupting the connection pool (#4186) (7e57db6)
- restore
PoolConnectionas subclass ofConnection(#4183) (97855a6)
v3.19.1
3.19.1 (2026-03-09)
... (truncated)
Changelog
Sourced from mysql2's changelog.
3.22.0 (2026-04-10)
Features
- disable mysql_clear_password plugin by default (#4236) (884bec5), closes #1617
- implement COM_RESET_CONNECTION with pool integration (#4148) (49a64cc)
Performance Improvements
3.21.1 (2026-04-09)
Bug Fixes
- limit client flags to server capabilities (#4227) (e1930b8)
- use Number.isSafeInteger for supportBigNumbers boundary check (#4225) (295264b)
3.21.0 (2026-04-09)
Features
- add support for query attributes (#4223) (d732f78)
- types: export ExecuteValues and QueryValues from entry point (9fafd6f)
3.20.0 (2026-03-15)
Features
Bug Fixes
- explicitly specify in auth plugins (#4175) (#4187) (5ac5563)
- prevent double release from corrupting the connection pool (#4186) (7e57db6)
- restore
PoolConnectionas subclass ofConnection(#4183) (97855a6)
3.19.1 (2026-03-09)
Bug Fixes
... (truncated)
Commits
71bcbffchore(master): release 3.22.0 (#4237)ab131deperf: defer Error object creation to error handlers in promise wrappers (#4257)bb0100bbuild(deps-dev): bump the website-dev-dependencies group across 1 directory w...5f63557build(deps-dev): bump the dev-dependencies group across 1 directory with 4 up...0b750e0build(deps): bump the docusaurus group in /website with 2 updates (#4249)9566475ci(dependabot): group dependency updates to reduce PR noise (#4248)e4f3b42build(deps): bump the react group in /website with 2 updates (#4247)53f9c9eci(dependabot): group react and react-dom updates together (#4246)49a64ccfeat: implement COM_RESET_CONNECTION with pool integration (#4148)884bec5feat: disable mysql_clear_password plugin by default (#4236)- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dolthub/dolt/network/alerts). - 11652: go: sqle: Improve autotracker update robustness during dolt_reset --hard.
Get rid of the unnecessary background work, and update the tracker state synchronously as part of the reset itself. - 11651: store/val: return error on malformed adaptive value
Fix panic when reading corrupted or truncated off-page storage chunks to return a SQL error.- Malformed addresses that aren't exactly 20 bytes now return
ErrInvalidAddressLen. - Add
varintPrefixLento assert buffer length before reading varints, preventing out-of-bounds slice panics on truncated multi-byte headers. - Add
ErrNullAdaptiveValue,ErrInlineAdaptiveValue,ErrTruncatedVarint, andErrInvalidAddressLenfor callers and tests.
Fix #11641
- Malformed addresses that aren't exactly 20 bytes now return
- 11646: cmd/dolt: improve connection error reporting and stale server info cleanup
CLI commands cleanup stale.dolt/sql-server.infofiles left by crashed servers and recover locally, while connection failures provide troubleshooting steps. - 11634: build(deps): bump org.mariadb:r2dbc-mariadb from 1.2.2 to 1.4.1 in /integration-tests/mysql-client-tests/java
Bumps org.mariadb:r2dbc-mariadb from 1.2.2 to 1.4.1.Release notes
Sourced from org.mariadb:r2dbc-mariadb's releases.
MariaDB Connector/R2DBC 1.4.1
1.4.1 (Jun 2026)
Notable Changes:
- R2DBC-116 Add GraalVM native-image configuration and CI coverage
- Update dependencies (Project Reactor 2025.0.6, Netty 4.2.15.Final)
Bugs Fixed:
- R2DBC-115 Clear-text authentication plugins (PAM, mysql_clear_password) must require a secure connection (report by fg0x0)
- R2DBC-117 Cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if MitM (report by tonghuaroot)
- R2DBC-119 Fail closed when a
classpath:SSL certificate is missing - R2DBC-120 Stored-procedure CALL detection wrongly matched any query containing "call" (thanks to yunhobb)
- R2DBC-121
caching_sha2_password/sha256_passwordlogin fails with passwords of 20 characters or more (report by 4UjwXc) - R2DBC-124 Ensure a non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- R2DBC-122 Fix SQL parser to correctly handle '--' in expressions
- R2DBC-123 Pin Locale.ROOT on locale-sensitive wire-format codec sites (thanks to jmestwa-coder)
MariaDB Connector/R2DBC 1.4.0
1.4.0 (Feb 2026)
Notable Changes:
- R2DBC-109 Add fallbackToSystemTrustStore and fallbackToSystemKeyStore options
- R2DBC-110 Support java.time.Instant parameters
- R2DBC-114 Implement Wrapped interface to expose EventLoop scheduler for r2dbc-pool optimization
Bugs Fixed:
- R2DBC-108 Handle authentication plugin multi-exchange prefix (0x01) introduced in MDEV-37554
- R2DBC-111 Potential hang when upstream subscription is cancelled before demand
- R2DBC-112 Failed authentication when using
caching_sha2_passwordwith passwords longer than 18 characters - R2DBC-113 Add support for RSA public key content in cachingRsaPublicKey and rsaPublicKey options
MariaDB Connector/R2DBC 1.3.1
1.3.1 (Jun 2026)
Maintenance release for the 1.3 line, back-porting the corrections, CI and security fixes made after 1.3.0.
java.time.Instantparameter support is intentionally not included.Notable Changes:
- R2DBC-108 Handle authentication plugin multi-exchange prefix (0x01) introduced in MDEV-37554
- R2DBC-109 Add
fallbackToSystemTrustStoreandfallbackToSystemKeyStoreoptions - R2DBC-113 Support inline RSA public key for
sha256_passwordandcaching_sha2_password - R2DBC-114 Implement
Wrappedinterface to expose the EventLoop scheduler for r2dbc-pool - R2DBC-116 Add GraalVM native-image configuration and CI testing
Bugs Fixed:
- R2DBC-111 Potential hang when upstream subscription is cancelled before demand
- R2DBC-112 Failed authentication using
caching_sha2_passwordwith passwords longer than 18 characters
... (truncated)
Changelog
Sourced from org.mariadb:r2dbc-mariadb's changelog.
1.4.1 (Jun 2026)
Notable Changes:
- R2DBC-116 Add GraalVM native-image configuration and CI coverage
- Update dependencies (Project Reactor 2025.0.6, Netty 4.2.15.Final)
Bugs Fixed:
- R2DBC-115 Clear-text authentication plugins (PAM, mysql_clear_password) must require a secure connection (report by fg0x0)
- R2DBC-117 Cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if MitM (report by tonghuaroot)
- R2DBC-119 Fail closed when a
classpath:SSL certificate is missing - R2DBC-120 Stored-procedure CALL detection wrongly matched any query containing "call" (thanks to yunhobb)
- R2DBC-121
caching_sha2_password/sha256_passwordlogin fails with passwords of 20 characters or more (report by 4UjwXc) - R2DBC-124 Ensure a non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- R2DBC-122 Fix SQL parser to correctly handle '--' in expressions
- R2DBC-123 Pin Locale.ROOT on locale-sensitive wire-format codec sites (thanks to jmestwa-coder)
1.4.0 (Feb 2026)
Notable Changes:
- R2DBC-109 Add fallbackToSystemTrustStore and fallbackToSystemKeyStore options
- R2DBC-110 Support java.time.Instant parameters
- R2DBC-114 Implement Wrapped interface to expose EventLoop scheduler for r2dbc-pool optimization
Bugs Fixed:
- R2DBC-108 Handle authentication plugin multi-exchange prefix (0x01) introduced in MDEV-37554
- R2DBC-111 Potential hang when upstream subscription is cancelled before demand
- R2DBC-112 Failed authentication when using
caching_sha2_passwordwith passwords longer than 18 characters - R2DBC-113 Add support for RSA public key content in cachingRsaPublicKey and rsaPublicKey options
1.3.0 (Oct 2024)
Notable Changes:
- R2DBC-106 Implement parsec authentication. see https://mariadb.com/kb/en/authentication-plugin-parsec/
Commits
a82d265bump 1.4.144602cb[misc] fix flaky PrepareResultSetTest.cacheReuse under load68d9f81[misc] test correction about pamOtherPwd sanitization4656951[misc] bump dependenciescd9b6f9[misc] code style correction76181aa[R2DBC-121] caching_sha2_password/sha256_password login fails with passwords ...ccf4326[R2DBC-120] Stored-procedure CALL detection wrongly matched any query contain...84dc70cMerge PR #92 (yunhobb): fix incorrect stored procedure CALL detection in crea...11d92c0[misc] mask pamOtherPwd in MariadbConnectionConfiguration.toString()1ec789e[misc] reject malformed auth-switch seed and column-definition packets cleanly- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dolthub/dolt/network/alerts). - 11633: build(deps): bump org.mariadb.jdbc:mariadb-java-client from 3.5.3 to 3.5.9 in /integration-tests/mysql-client-tests/java
Bumps org.mariadb.jdbc:mariadb-java-client from 3.5.3 to 3.5.9.Release notes
Sourced from org.mariadb.jdbc:mariadb-java-client's releases.
MariaDB Connector/Java 3.5.9
3.5.9 (Jun 2026)
Key Enhancements
- CONJ-1223 - cache TLS trust/key managers across connections to reduce SSL connection cost
- CONJ-1314 - add SPI for interactive dialog (PAM) authentication callback
- CONJ-1311 - add dedicated option
useIpForKillQueryfor query cancellation - CONJ-1310 - Add full native image support and CI coverage
Issues Resolved
- CONJ-1320 - PAM (dialog) authentication must require a secure connection (report by fg0x0)
- CONJ-1319 - Use constant-time comparison when validating the server certificate fingerprint (report by jmestwa-coder)
- CONJ-1318 - enforce
allowLocalInfile=falseon the server's local-infile request, so a malicious server cannot read a client file despite the option being disabled - CONJ-1322 - match local infile filename case-sensitively (thanks to jmestwa-coder)
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
- CONJ-1315 - cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if MitM (report by tonghuaroot)
- CONJ-1317 - ensure non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- CONJ-1304 - CallableStatement parameter metadata read from mysql.proc, with MySQL info_schema fallback
- CONJ-1299 - keep VALUES literals after the last placeholder when rewriting batches
- CONJ-1313 - race condition in HaMode#getAvailableHostInOrder can cause NPE
- CONJ-1311 - Connection.cancelCurrentQuery fails with SslMode.VERIFY_FULL when client socket IP is set
- CONJ-1264 - handle LocalDateTime as a zoneless wall-clock value
- CONJ-1316 - pin Locale.ROOT on locale-sensitive call sites and date/time/Duration text formatting (fixes locale-dependent parsing/formatting, e.g. under tr_TR) (thanks to jmestwa-coder)
- CONJ-1324 - fix SQL parser to correctly handle '--' in expressions and reset lastChar after block comments
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
MariaDB Connector/Java 3.5.8
3.5.8 (Apr 2026)
Issues Resolved
- CONJ-1305 - XAResource.isSameRM() incorrectly returns true when rewriteBatchedStatements differs between connections
- CONJ-1303 - Statement.cancel() fails to kill running query during result streaming
Other
- CONJ-1298 - Performance improvement: avoid decoding extended format
MariaDB Connector/Java 3.5.7
3.5.7 (Dec 2025)
Key Enhancements
... (truncated)
Changelog
Sourced from org.mariadb.jdbc:mariadb-java-client's changelog.
3.5.9 (Jun 2026)
Key Enhancements
- CONJ-1223 - cache TLS trust/key managers across connections to reduce SSL connection cost
- CONJ-1314 - add SPI for interactive dialog (PAM) authentication callback
- CONJ-1311 - add dedicated option
useIpForKillQueryfor query cancellation - CONJ-1310 - Add full native image support and CI coverage
Issues Resolved
- CONJ-1320 - PAM (dialog) authentication must require a secure connection (report by fg0x0)
- CONJ-1319 - Use constant-time comparison when validating the server certificate fingerprint (report by jmestwa-coder)
- CONJ-1318 - enforce
allowLocalInfile=falseon the server's local-infile request, so a malicious server cannot read a client file despite the option being disabled - CONJ-1322 - match local infile filename case-sensitively (thanks to jmestwa-coder)
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
- CONJ-1315 - cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if MitM (report by tonghuaroot)
- CONJ-1317 - ensure non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- CONJ-1304 - CallableStatement parameter metadata read from mysql.proc, with MySQL info_schema fallback
- CONJ-1299 - keep VALUES literals after the last placeholder when rewriting batches
- CONJ-1313 - race condition in HaMode#getAvailableHostInOrder can cause NPE
- CONJ-1311 - Connection.cancelCurrentQuery fails with SslMode.VERIFY_FULL when client socket IP is set
- CONJ-1264 - handle LocalDateTime as a zoneless wall-clock value
- CONJ-1316 - pin Locale.ROOT on locale-sensitive call sites and date/time/Duration text formatting (fixes locale-dependent parsing/formatting, e.g. under tr_TR) (thanks to jmestwa-coder)
- CONJ-1324 - fix SQL parser to correctly handle '--' in expressions and reset lastChar after block comments
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
- CONJ-1318 - allowLocalInfile=false does not block LOAD DATA LOCAL INFILE against a malicious server (thanks to tharavel)
3.4.3 (Jun 2026)
Bugs Fixed
- CONJ-1315 - cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if Mitm (report by tonghuaroot)
- CONJ-1316 - pin Locale.ROOT on locale-sensitive call sites and date/time/Duration text formatting (fixes locale-dependent parsing/formatting, e.g. under tr_TR) (thanks to jmestwa-coder)
- CONJ-1259 - DatabaseMetaData read-only detection: handle MariaDB 12.0
@@read_onlyreturningON/OFFinstead of1/0 - CONJ-1317 - ensure non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- CONJ-1320 - PAM (dialog) authentication now requires a secure connection (TLS or unix socket), like mysql_clear_password (report by fg0x0)
- CONJ-1319 - use constant-time comparison when validating the server certificate fingerprint (thanks to jmestwa-coder)
- CONJ-1322 - match local infile filename case-sensitively (thanks to jmestwa-coder)
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
- CONJ-1318 - allowLocalInfile=false does not block LOAD DATA LOCAL INFILE against a malicious server (thanks to tharavel)
3.3.5 (Jun 2026)
... (truncated)
Commits
df4ebe2[misc] enhance TcpProxy and TcpProxySocket for improved thread safety and con...687c840[misc] update environment variable for Maxscale version4466ad6[misc] test stability improvement : update proxy close method in PooledConnec...1e29819[misc] update README versionda297f1Merge branch 'develop'83d3da9[misc] Update CHANGELOGe39e8b9match local infile filename case-sensitivelyd90b987[misc] Implement secure authentication checks and add regression tests for cr...f4a727c[CONJ-1320] PAM (dialog) authentication must require a secure connectiona87c711[misc] update CHANGELOG- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dolthub/dolt/network/alerts). - 11630: argparser: fix panic on empty-string value for list options
Passing an empty string as the value of a list-valued option (e.g.dolt log --not "",dolt diff --include-cols "") no longer panics.
Close #11347 - 11623: build(deps): bump mariadb from 3.4.5 to 3.5.3 in /integration-tests/mysql-client-tests/node
Bumps mariadb from 3.4.5 to 3.5.3.Release notes
Sourced from mariadb's releases.
MariaDB Connector/Node.js 3.5.3
3.5.3 (Jun1 2026)
Notable changes
- Minimum supported Node.js version is now 20 (was 18; Node 18 went EOL in April 2025)
- CONJS-346: Add
RowsWithMeta<T>andWithMeta<T>helper types for typingquery()/execute()result shapes —RowsWithMeta<T>for the default rows-array-with-metashape,WithMeta<T>for themetaAsArray: truetuple form (types-only, no runtime change)
Issues Fixed
- CONJS-354: Reject a server-initiated LOAD DATA LOCAL INFILE request when
permitLocalInfileis disabled (report by tharavel) - CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
- CONJS-351: Use constant-time comparison when validating the server certificate fingerprint token, preventing a timing side-channel that could leak the token to a man-in-the-middle
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-344: Restore dual ESM/CJS support after the 3.5 ESM migration (#346):
- TypeScript types now compile under
moduleResolution: "Node16" / "NodeNext" / "Bundler"— fixes TS2846 / TS2834 reported in 3.5.1 and 3.5.2 - Ship paired
.d.ctsdeclarations for therequirecondition - Ship a real CJS bundle in
dist/sorequire('mariadb')works on Node 20+ without--experimental-require-moduleorExperimentalWarning - Restore the default ESM export, so
import mariadb from 'mariadb'works again (matches 3.4.x behavior)
- TypeScript types now compile under
MariaDB Connector/Node.js 3.5.2
3.5.2 (Mar 2026)
Issues Fixed
- CONJS-342 Resolved TypeScript compilation errors introduced in mariadb-connector-nodejs v3.5.1
- CONJS-343 Fixed an issue where batch operations would hang when provided with empty array parameter values
MariaDB Connector/Node.js 3.5.1
3.5.1 (Feb 2026)
Notable changes
- CONJS-338 Add asyncDispose support for Connection, PoolConnection and Pool #250
- CONJS-339 Add default type parameter to Prepare interface and fix executeStream generic #334
- CONJS-339 Add wildcard for values params on Prepare
Issues Fixed
- CONJS-331 Plugin authentication change correction
- CONJS-335 Deno compatibility: send COM_QUIT synchronously to prevent socket cleanup race condition
- CONJS-336 Connection attribute _server_host send host, but IP resulting of name resolution
- CONJS-340 Fix pool connection event to emit wrapped connections and prevent user errors from breaking pool #342
- CONJS-341 Support charset + collation combination in connection options #337
MariaDB Connector/Node.js 3.5.0 RC
3.5.0-rc.0 (Oct 2025)
Notable changes
- CONJS-326 migrate from commonJS to ESM
- CONJS-325 deno compatibility
... (truncated)
Changelog
Sourced from mariadb's changelog.
3.5.3 (Jun1 2026)
Notable changes
- Minimum supported Node.js version is now 20 (was 18; Node 18 went EOL in April 2025)
- CONJS-346: Add
RowsWithMeta<T>andWithMeta<T>helper types for typingquery()/execute()result shapes —RowsWithMeta<T>for the default rows-array-with-metashape,WithMeta<T>for themetaAsArray: truetuple form (types-only, no runtime change)
Issues Fixed
- CONJS-354: Reject a server-initiated LOAD DATA LOCAL INFILE request when
permitLocalInfileis disabled (report by tharavel) - CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
- CONJS-351: Use constant-time comparison when validating the server certificate fingerprint token, preventing a timing side-channel that could leak the token to a man-in-the-middle
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-344: Restore dual ESM/CJS support after the 3.5 ESM migration (#346):
- TypeScript types now compile under
moduleResolution: "Node16" / "NodeNext" / "Bundler"— fixes TS2846 / TS2834 reported in 3.5.1 and 3.5.2 - Ship paired
.d.ctsdeclarations for therequirecondition - Ship a real CJS bundle in
dist/sorequire('mariadb')works on Node 20+ without--experimental-require-moduleorExperimentalWarning - Restore the default ESM export, so
import mariadb from 'mariadb'works again (matches 3.4.x behavior)
- TypeScript types now compile under
3.4.6 (Jun 2026)
Issues Fixed
- CONJS-331: Corrected parsec authentication plugin handling
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-349: Fixed cleartext password disclosure to a man-in-the-middle when relying on certificate fingerprint validation (self-signed trust mode)
- CONJS-351: Use constant-time comparison when validating the server certificate fingerprint token, preventing a timing side-channel that could leak the token to a man-in-the-middle
- CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
- CONJS-354: Reject a server-initiated LOAD DATA LOCAL INFILE request when
permitLocalInfileis disabled (report by tharavel) - Refuse sending the password in clear (
mysql_clear_password) over an unencrypted connection
3.3.3 (Jun 2026)
Issues Fixed
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-349: Fixed cleartext password disclosure to a man-in-the-middle when relying on certificate fingerprint validation (self-signed trust mode)
- CONJS-351: Use constant-time comparison when validating the server certificate fingerprint token, preventing a timing side-channel that could leak the token to a man-in-the-middle
- CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
- CONJS-354: Reject a server-initiated LOAD DATA LOCAL INFILE request when
permitLocalInfileis disabled (report by tharavel) - Refuse sending the password in clear (
mysql_clear_password) over an unencrypted connection
3.2.4 (Jun 2026)
Issues Fixed
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
... (truncated)
Commits
14e0f16[misc] Update CHANGELOG.md to include recent security fixes for PAM authentic...cd00457Merge branch 'develop'f34b785[misc] test stability: poll debug log until flushed instead of fixed wait2df7c26[CONJS-354] Reject server-initiated LOAD DATA LOCAL INFILE when permitLocalIn...7d6e44a[misc] Cap the length of server-sent numeric strings before BigInt parsing, p...53b3042[CONJS-353] PAM (dialog) authentication now requires a secure connection (TLS...41eec7f[CONJS-351] Implement constant-time comparison in validateFingerPrint to prev...aa50c50Update CHANGELOG.md for version 3.4.6, 3.3.3 and 3.2.4, adding fixed issues a...6c10db5[misc] test stability correction5d5293a[misc] Refuse mysql_clear_password over an insecure connection- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dolthub/dolt/network/alerts). - 11614: go: sqle/dtablefunctions: defer dolt_query_diff execution to
RowIterand enforce subquery auth
Fix permission checking and planning fordolt_query_diff. With this change, permissions on tables, views, and databases referenced are verified during planning. Table rows are only fetched when the query is executed, fixing edge cases withEXPLAIN. - 11611: Resolve predicates before partial index backfill
Resolve partial-index predicates against the actual table schema before evaluating them while backfilling an index over existing rows. This prevents planner-relative field ordinals from being evaluated against stored table rows.
Part of dolthub/doltgresql#3100 - 11610: go/libraries/doltcore/env, sqle: handle duplicate database directories
Log warning to skip duplicate database folders when scanning for databases to prevent overwriting an existing database. - 11607: dbfactory: git remotes with more flexible cache dir name
Enable DumboDB to use git* remotes, but under a different cache directory, that doesn't include.dolt - 11606: tracking field so that adaptive encoded keys work with garbage collection, push, etc
New field in prolly.fbs to account for address values in keys. Doltgres permits this; Dolt does not (always requires prefixes for long keys). This gap would cause any key values stored out of band in Doltgres to be garbage collected inappropriately, as well as fail to be pushed. - 11604: go: sqle/expranalysis: Have ResolveExpression take a schema-qualified TableName.
Allows for fixing some partial-index creation failures in doltgres. - 11598: feat: add orcarouter provider to dolt assist
Thedolt assistcommand is Dolt's chat assistant for running dolt commands and queries in plain language. This PR adds a named OrcaRouter provider via--provider orcarouter, mirroring the existing OpenAI wiring: it readsORCAROUTER_API_KEY, targetshttps://api.orcarouter.ai/v1/chat/completions, and defaults to theorcarouter/automodel. OrcaRouter is an OpenAI-compatible AI gateway built for both models and agents — like OpenRouter it exposes a provider/model namespace across many models, but also combines adaptive routing, automatic failover, zero-markup inference, observability, guardrails, and agent-tool governance behind the same endpoint, so Dolt users can use that stack without treating it as an anonymous base URL. It also runs gateway-level, zero-trust security for AI agents on the same endpoint — screening every prompt/response and governing every tool call on a default-deny basis, with no application code changes. OpenAI stays the default; no behavior change. I also fixed a pre-existing bug ingetJsonPromptthat emitted a leading comma (invalid JSON) on the first request.
Verification:go build+go vetpass,gofmtclean, live-tested--provider orcarouteragainst OrcaRouter (200).go test ./cmd/dolt/commands/passes; the only failure is pre-existingTestSignAndVerifyCommit(needsgpg, not installed here).
Discord: discord.gg/YEubt8enRA · X: https://x.com/OrcaRouter
I'm an engineer on the OrcaRouter team. - 11597: Fix duplicate key errors with expression indexes
Sizes reconstructed rows from mapped SQL ordinals so system-hidden expression-index columns cannot leave out-of-range gaps after schema changes. Covers keyed and keyless tables across duplicate errors, ignored inserts, and duplicate-key updates.
Supports doltgresql #3082. - 11596: Fix macOS-only bats CI failures
Fixes the long-standing macOS-only bats CI failures (verified: 38 → 0 failures across two full nightly-workflow runs).- Skip docker-entrypoint.bats/tzdata.bats for MacOS (no docker available on PATH in MacOS runners)
- Fix BSD awk/grep incompatibilities in sql-diff.bash and GNU-only
sed -iin sql-pull.bats - Disable the detached
dolt send-metricsprocess during bats runs (raced with test teardown cleanup) - Default
DOLT_PAGER=cat(less races with expect scripts typing ahead, dropping keystrokes)
- 11594: Added extended vector index support
This adds support for extended vector index support for Doltgres. Builds on top of: - 11593: go: clone: Make clone use the same semantics on srcDB as fetch. Open without caching and close when finished with it.
- 11592: Say that a failed conjoin was deferred, not that something went fatal
Reword the conjoin failure log line to say that compaction was deferred and will be retried, and add adeferredfield so log consumers can classify it without parsing prose.
Fixes #11591
Close #11624
Blocked by #11624 - 11585: Fix auto-increment tracker init race
NewSequenceTrackerFromRootsinitializes sequence state in a background goroutine but ran it on the caller's request-scoped context, so it could be canceled as soon as the triggering query (e.g.CREATE DATABASE) returned, poisoning the tracker for later callers. Detach that goroutine's context from the caller's cancellation, and add a deterministic regression test. - 11582: go: Add cleanup of the created directory on some database creation failure paths.
- 11580: Fix FK lookup during table rename
UpdateForeignKey was looking up the existing foreign key using the new table name passed in the constraint, but go-mysql-server calls it during a rename before the table has actually been renamed. This lookup only matters (and only broke) for schema-qualified engines like Doltgres, since plain Dolt's foreign key lookups ignore table name when schema is empty. Fixed by looking up using the table's current name, and added a regression test that reproduces the mid-rename state directly against WritableDoltTable.UpdateForeignKey.
Related to: dolthub/doltgresql#3114 - 11577: Fix a race in SequenceTracker.InitWithRoots
Concurrentdolt_resetordolt_checkoutcalls from different sessions against the same database could race insideSequenceTracker.InitWithRoots, with two overlapping calls both ending up closing the same completion channel and crashing the whole server process. This PR serializesInitWithRootswith a mutex and has each asyncinitclose a captured channel reference instead of the mutable field. Also adds a unit test that reproduces the panic against the old code and passes clean under -race against the fix. - 11576: dumbo: expose session operations
- 11571: user contribution: s3 remote support
Original PR: #11433
Fixes: #509
Documentation Change: dolthub/docs-2#174 - 11569: build(deps): upgrade Hibernate to 6.6.55
Summary
- replace the vulnerable Hibernate 5.6 dependency with Hibernate ORM 6.6.55.Final
- migrate the smoke-test entity annotations from
javax.persistencetojakarta.persistence - remove the obsolete
hibernate-entitymanagerdependency and target Java 11, as required by Hibernate 6 - resolve Dependabot alert #122 / CVE-2026-0603
Validation
mvn -B -ntp clean compilemvn -B -ntp dependency:tree -Dincludes=org.hibernate:hibernate-core,org.hibernate.orm:hibernate-core
[no-release-notes]
- 11449: pin the aborted-rebase state behind ErrRebaseDataConflictsCantBeResolved
Related to #10951 — extends the existingdolt_rebasedata-conflict enginetest to assert the abort that the error message promises actually happened: original branch restored, thedolt_rebase_<branch>working branch and thedolt_rebaseplan table both gone, anddolt_conflictsempty. - 11438: fix: populate dolt_statistics created_at
SetsStatistic.Createdon newly generated table-scan and index statistics sodolt_statistics.created_atreports the collection time instead of Go’s zero value, while cached statistics keep their existing timestamps.
Fix #10168
Close #11647 - 11433: Add s3:// remote scheme for generic S3-compatible object stores (#509)
Motivation
#509 asks for S3-compatible storage support. The historical blocker was the manifest:aws://pairs S3 with a DynamoDB table for the atomic check-and-set, which generic S3-compatible stores cannot provide. That blocker is gone: AWS S3 supports conditional writes (If-None-Match: *for create since Aug 2024,If-Match: <ETag>CAS since Nov 2024), and Cloudflare R2 and current MinIO AIStor document both headers onPutObject.Design
A news3://bucket/pathscheme backed by an endpoint-configurableS3Blobstore:- The manifest ETag is an opaque version token.
CheckAndPutissues a direct single-part conditionalPutObject(If-None-Match: *on create,If-Matchon replace). HTTP 412, AWS's conditional409 ConditionalRequestConflict, andIf-Matchagainst a missing key all map to the unwrappedblobstore.CheckAndPutError, so the existing NBS manifest reread/retry path handles races unchanged. 429/5xx are left to the caller's retry with the original condition preserved. CheckAndPutnever uses multipart (multipart ETags are not content-stable across providers, and conditional headers onCompleteMultipartUploadare not universally supported). OrdinaryPutuses the SDK upload manager, which switches to multipart automatically for large table files.- The factory wires
nbs.NewNoConjoinBSStore, soConcatenateis never invoked — no server-side compose operation is required, following the Git-remote backend precedent. - Credentials come from the standard AWS SDK chain. New optional remote params:
s3-endpoint,s3-region,s3-path-style(theAWS_ENDPOINT_URL_S3env var is honored when params are omitted).
The first commit fixes a pre-existing gap this work surfaced:noConjoinBlobstorePersister.Openlacked the archive-format (.darc) fallback thatblobstorePersister.Openhas, so pushing archive table files into a no-conjoin blobstore store failed atopenChunkSources.
Verification
- Integration tests (env-gated on
TEST_S3_BUCKET/TEST_S3_ENDPOINT/TEST_S3_PATH_STYLE, following the GCS/OCI convention) cover put/get/exists/ranged reads, conditional create/update/stale-version/missing-key semantics, an 8-writer concurrentCheckAndPutrace asserting exactly one winner, multipartPut, and unsupportedConcatenate. All pass against live Cloudflare R2. - End-to-end against R2:
remote add→push→clone→ data verified → secondpush→pullround-trip verified. - Caveat stated plainly: the concurrent-race test is a smoke test, not a proof of provider-side CAS linearization. R2 documents the conditional headers but not an explicit exactly-one-winner guarantee, and R2 rate-limits ~1 write/sec per key (relevant to the hot manifest). A more rigorous conformance harness (synchronized independent clients, disabled SDK retries, raw timing/status capture, repetition) is planned; providers lacking conditional writes should eventually get a fast capability-probe error.
Open questions
- Is this design shape acceptable, and is the work planned under the current #509 assignment far enough along that this PR conflicts? Happy to adapt or hand off.
- Naming/config bikeshed:
s3://scheme ands3-endpoint/s3-region/s3-path-styleparam names. - Whether a startup capability probe (fail-fast on providers without conditional-write support) should land in this PR or a follow-up.
Known cosmetic issue: a second push to an existing branch prints[new branch]instead of a fast-forward line; investigating.
- The manifest ETag is an opaque version token.
- 11022: build(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /.github/actions/ses-email-action
Bumps fast-xml-builder from 1.1.5 to 1.2.0.Changelog
Sourced from fast-xml-builder's changelog.
1.2.0 (2026-05-08)
- Add support for
sanitizeNameoption - Support xml-naming for validating and sanitizing tag and attribute names
1.1.9 (2026-05-06)
- fix: format output for preserve order when indent by is set to empty string
1.1.8 (2026-05-05)
- fix: skip text property for PI tags
- improve typings
1.1.7 (2026--05-04)
- fix security issues when attribute value contains quotes
1.1.6 (2026--05-04)
- fix security issues related to comment
- skip comment with null value
1.1.5 (2026-04-17)
- fix security issues related to comment and cdata
1.1.4 (2026-03-16)
- support maxNestedTags option
1.1.3 (2026-03-13)
- declare Matcher & Expression as unknown so user is not forced to install path-expression-matcher
1.1.2 (2026-03-11)
- fix typings
1.1.1 (2026-03-11)
- upgrade path-expression-matcher to 1.1.3
1.1.0 (2026-03-10)
- Integrate path-expression-matcher
Commits
a9a905bfor release42680e8support name sanitization8b00185release info8a08f17allow indentation to be empty string7fc5decupdate docsc241b6aimprove documentation15d5668update for release9877485fix: skip text property for PI tags311a221fix #5 typing import issuese8fc5b1update for releast- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) You can trigger a rebase of this PR by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dolthub/dolt/network/alerts). - Add support for
- 11018: build(deps): bump github.com/apache/thrift from 0.13.1-0.20201008052519-daf620915714 to 0.23.0 in /go
Bumps github.com/apache/thrift from 0.13.1-0.20201008052519-daf620915714 to 0.23.0.Release notes
Sourced from github.com/apache/thrift's releases.
Version 0.23.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Version 0.22.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Version 0.21.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Version 0.20.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Version 0.19.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Version 0.18.1
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Version 0.18.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Version 0.17.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Version 0.16.0
For release 0.16.0 head over to the official release download source:
... (truncated)
Changelog
Sourced from github.com/apache/thrift's changelog.
0.23.0
Build Process
- THRIFT-5877 - Add cpp cross tests
- THRIFT-5866 - Dockerfile to support Ubuntu 24.04 LTS (Noble Numbat)
- THRIFT-5909 - add Ruby in GitHub workflow
- THRIFT-5649 - add go in GitHub workflow / action
C glib
- THRIFT-5931 - thrift_ssl_socket_get_ssl_error() can underflow its remaining-buffer counter and write past the stack buffer
- THRIFT-5871 - Improve MAX_MESSAGE_SIZE check and friends
C++
- THRIFT-5911 - Inconsistent UUID compilation for aliased types
- THRIFT-5912 - Assertion failed:
delta > 0, file ThreadManagerTests.h, line 162 - THRIFT-5880 - C++ TSocket on an IPv6-only system fails if you use a hostname of 127.0.0.1
- THRIFT-3268 - warning: token pasting of ',' and
__VA_ARGS__is a GNU extension - THRIFT-5887 - build/cmake/ should be prepended (not appended) to CMAKE_MODULE_PATH
- THRIFT-5878 - Add UUID support for THeaderProtocol and TProtocolTap
- THRIFT-5898 - Unable to build Thrift as a shared library on Windows
Contributed
- THRIFT-5920 - Remove threadsafe warnings in thrift-maven-plugin
Delphi
- THRIFT-5939 - Replace GUID generation with stable UUID algorithm
- THRIFT-5876 - Add Delphi WinHTTP client TLS1.3 support
Go
- THRIFT-5896 - Race condition in TServerSocket.Addr() method
Java
- THRIFT-5925 - UUID implementation in JAVA is not according to the Thrift Specification
- THRIFT-5869 - Close the transport after TServerEventHandler deleteContext
- THRIFT-5863 - Make TServerTransport able to customize the max message size
- THRIFT-5774 - Add remote client's IP address to ServerContext in TServerEventHandler
- THRIFT-4280 - Add async nonblocking ssl support in java client
- THRIFT-5879 - java and kotlin cross tests fail in the GitHub action
netstd
- THRIFT-5902 - Add net10 support
... (truncated)
Commits
- See full diff in compare view
> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
go-mysql-server
-
3748: sql.ValueRows: Correctly handle NULLs in comparisons.
This fixes a correctness issue running a query against a Dolt MySQL server:
The test currently passes prior to this PR. This is because the test harness needs to be updated to more accurately reflect running against a Dolt MySQL server, but this currently causes other tests to fail. Instead, this change was tested locally to with the new test harness, and I confirmed that this PR fixes some of the failing tests and does not introduce any new failures. -
3747: sql.ValueRows: Correctly handle filter expressions that aren't bools
This fixes a correctness issue running the following queries from
TestQueriesagainst a Dolt MySQL server:SELECT i,v from stringandtable WHERE i SELECT i,v from stringandtable WHERE v SELECT i FROM mytable WHERE NULL > 10; SELECT i FROM mytable WHERE NULL IN (10); SELECT i FROM mytable WHERE NULL IN (NULL, NULL); SELECT i FROM mytable WHERE NOT NULL NOT IN (NULL); SELECT i FROM mytable WHERE NOT (NULL) <> 10; SELECT i FROM mytable WHERE NOT NULL <> NULL;There are no test changes because the test harness needs to be updated for every query test at once, once every test passes. I ran the new test harness locally and confirmed that this PR fixes some of the failing tests and does not introduce any new failures.
-
3746: Support conditional duplicate updates
Adds support for conditionally applying duplicate-key updates, as required by PostgreSQL’sON CONFLICT DO UPDATE ... WHERE.
When an insert conflicts with an existing row, the optional condition is evaluated against the existing and proposed rows. A false condition skips that row; a true condition applies the update. The change also supports returning the updated row and lets PostgreSQL count a duplicate update as one affected row without changing MySQL’s default behavior.
Tests cover conditional updates,RETURNING, affected-row counts, and a batch of 100,000 filtered conflicts.
Supports dolthub/doltgresql#3235.
Depends on: dolthub/vitess#483 -
3745: Plumb DROP TABLE ... CASCADE through to plan.DropTable
Adds a Cascade flag to plan.DropTable (populated from the vitess AST) so that integrator pre-execution hooks can implement dialect-specific cascade semantics; the engine itself does not act on it.
Companion PRs:- dolthub/vitess: dolthub/vitess#482
- dolthub/doltgresql: dolthub/doltgresql#3155
-
3744: sql/mysql_db: Make OverwriteUsersAndGrantsData leave ephemeral users in place.
Ephemeral users are part of in-memory process-local state, and any functionally equivalent users are not included in the persisted payload coming in for OverwriteUsersAndGrantsData. This allows Dolt CLI access to retain access through dolt_local_user even when cluster replication replicates users and grants to a replica. -
3742: Avoid redundant window output sort
Window execution currently performs a second stable sort after evaluating results solely to restore input order, even though each result already carries its original row ordinal.
Place results directly at their original ordinals and compact empty positions for grouped windows. This changes output restoration from O(n log n) to O(n) while preserving row order and grouped output cardinality.
A temporary 1,000-row ROW_NUMBER benchmark matching the reported query shape improved from approximately 1.03 ms/op to 0.76 ms/op on an Apple M1 Max, about 25%. Allocations changed from 10,041 to 10,038 per operation.
Fixes #11626 -
3741: Don't re-evaluate set-returning expressions in the final projection
When a select alias is materialized in an inner projection (e.g. so an ORDER BY can reference it), the final projection re-evaluated the alias expression. For expressions that return a RowIter (set-returning functions), the inner projection has already expanded the rows, so re-evaluation multiplied them again and clobbered the sort order. The final projection now references the expanded column instead.
There's an engine test with a synthetic function, but most testing lives in Doltgres. Companion PR:
dolthub/doltgresql#3151 -
3740: Convert
LOAD_FILEfilename to text type
Fixes #11564
Casting filename to string was causing a panic when it was not a string type. UsingTypeAwareConversionfirst is much safer and prevents the panic. -
3739: Fix HAVING aggregate alias resolution
Resolve HAVING aggregate inputs using their full table qualifiers so joins with duplicate column names do not bind the wrong source.
Fixes #11627 -
3738: Don't set the max1Row query flag for plans containing RowIter exprs
Set-returning functions multiply output rows, so a strict index lookup no longer guarantees at most one result row when the plan contains one.
See dolthub/doltgresql#3151 -
3737: Preserve LEFT JOIN semantics for lateral joins with no join filters
A LEFT JOIN LATERAL with a trivially true condition (e.g. ON true) had its filter simplified away, and the memo exec builder then rebuilt every filterless lateral join as a lateral cross join incorrectly. -
3735: handle parenthesized select with trailing order by and limit
Enable planning engine to evaluate parenthesized query expressions inCREATE TABLE ... AS (SELECT ....)with optional modifiers.- Apply trailing
ORDER BYandLIMITclauses inbuildSelectStmt. - Add shared
buildLimitAndOffsethelper.
Fix #11620
Blocked by dolthub/vitess#481
- Apply trailing
-
3733: Evaluate sort key expressions once per row instead of once per comparison
Sort comparators previously re-evaluated ORDER BY expressions on every comparison. For non-deterministic expressions (e.g. ORDER BY RAND()), this biased the result heavily toward rows late in the scan: with ORDER BY RAND() LIMIT 1 each comparison was a fresh coin flip, so the last row won ~50% of the time instead of 1/N. It was also wasteful for expensive sort keys, evaluating them O(n log n) times instead of O(n).
Sort keys are now evaluated at most once per row and cached, in the full sort, Top-N heap, and top-1 paths. The top-1 path also now surfaces sort expression evaluation errors instead of swallowing them. -
3732: Validate DISTINCT windows after function resolution
Add an optional validation hook for engine-specific DISTINCT window-function behavior after the exact function overload has been resolved. This lets consumers enforce their compatibility policy without changing native MySQL behavior. -
3731: Reject unsafe partial index join scans
Prevent partial indexes from being used as complete sorted inputs for merge and range-heap joins unless the source filters include the index predicate.
Adds optimizer coverage for predicate-absent rejection and predicate-present eligibility in both join paths.
Part of dolthub/doltgresql#3100 -
3730: Return an error for a bind variable in an AS OF clause
An unresolved bind variable in an AS OF clause caused the query planner to evaluate a nil expression, triggering a panic instead of returning a SQL error. This change detects that case and returns ErrInvalidAsOfExpression, preventing callers from hanging during transaction cleanup.
Now, the bigger question if this PR should be accepted or not, si that this can silently return the current db state when "AS OF" cannot be resolved. Not sure if semantically this is acceptable or not.
Other paths, notably SHOW TABLES and CALL, allow an unresolved AS OF placeholder during the initial prepare pass and bind it on execution. This change intentionally leaves those paths unchanged. -
3728: Expose DISTINCT aggregate retention
Expose whether a DISTINCT aggregate argument was retained separately from its evaluated value. This lets aggregates distinguish a retained SQL NULL from a duplicate that should be skipped while preserving existing Eval behavior.
Part of dolthub/doltgresql#3099 -
3727: Support extended types in COUNT DISTINCT
Hash single-expression extended values using their canonical serialized representation inCOUNT(DISTINCT ...). This allows PostgreSQL UUID values to participate in distinct aggregates without changing ordinary or multi-expression aggregate behavior.
Part of dolthub/doltgresql#3099 -
3726: Handle empty set results in table function wrappers
Handle strict set-returning functions used inFROMwithout fabricating a NULL row, while preserving ordinary scalar NULL behavior and multi-column SRF row shapes.
Restrict PostgreSQL scalar alias-as-column behavior to one-column function results. Regular functions with multiple named OUT parameters retain those output names instead of being misclassified as scalar. MySQL-compatible callers remain unchanged because the alias behavior is opt-in.
Added focused wrapper and planbuilder coverage for empty strict SRFs, scalar NULLs, multi-column rows, scalar aliases, native table functions, and record-returning regular functions. Verified withgo test ./sql/expression/tablefunction -count=1andgo test ./sql/planbuilder -count=1. -
3725: Support PostgreSQL scalar function aliases in FROM
Add an opt-in plan-builder override for PostgreSQL scalar-function alias semantics inFROMclauses. The default remains disabled so MySQL-compatible callers retain existing behavior.
Native table functions continue to preserve their named output columns. Added planbuilder coverage for PostgreSQL mode, default MySQL mode, and native table functions.
Verified withgo test ./sql/planbuilder -count=1. -
3724: Added extended vector support
This adds support for extended vector operations, to primarily be used by integrators -
3719: fix panic on date type in
Round()
fixes the panic here: #11495
converts that issue into just a datetime conversion problem -
3718: Fix functional index display in
SHOW INDEXandinformation_schema.statistics
SHOW INDEXandinformation_schema.statisticswere exposing the internal !hidden!... system-column name inColumn_nameand leavingExpressionNULLfor functional index key parts, instead of matching MySQL's Column_name=NULL / Expression= convention. Chasing this down also surfaced a bug inCoalesce.IsNullable()that only checked its first argument, causing wrongNULLreporting for expressions likeCOALESCE(b, a)where a isNOT NULL. -
3717: bug fix: outer scope visibility in multiple levels of nested derived tables
Fixes a bug where a derived table nested inside another derived table (both within a correlated subquery expression) failed to inherit outer-scope visibility past the first nesting level, causing correlated references two-plus levels deep to resolve to the wrong field index or silently return wrong results. OuterScopeVisibility now propagates transitively through nested derived tables instead of only being granted to the outermost one. -
3716: fix panic for
UNION,INTERSECTandEXCEPTwith unequal schema lengths
fixes: #11491 -
3714: fix panic on invalid
Nargument toNTILE
Depends on: dolthub/vitess#480
Fixes #11467 -
3710: fix panic in TRIM functions
Added a conversion forTimeSpantype toLongTextand updated errors to not panic.
fixes: #11455 -
3705: Actually resolve column
DEFAULTexpression when building scalar expressions
fixes #11453
Also removesDefaultColumnplaceholder expression type and add more guards for updating withdefaultvalues.
Doltgres updated in dolthub/doltgresql#3205 -
3704: transaction-scoped session var support
MySQL has no concept of these, but Postgres does. -
3699: Correctly parse and compare JSON docs with numbers that are too large to fit in a float64 without losing precision.
Previously we would parse all numbers in serialized JSON as 64-bit floats, and all comparisons between numbers in JSON would be coerced to 64-bit floats.
This was causing problems for inputs that can't be represented precisely as a float, but can be represented precisely as an int64 or uint64.
This PR enhances the logic for both parsing and comparing JSON documents to correctly handle float64, int64, and uint64 without any loss of precision.
vitess
- 483: Add conditional duplicate update metadata
Add insert AST metadata for a duplicate-update predicate and single-row affected-count semantics. This lets PostgreSQL dialect translation carryON CONFLICT DO UPDATE ... WHEREbehavior through the shared parser boundary.
Adds formatting and AST-walk coverage for the predicate.
Supports dolthub/doltgresql#3235. - 482: Add Cascade field to DDL for DROP statements
Adds a Cascade field to the DDL AST node for DROP statements, which the MySQL grammar never sets (MySQL parses but ignores CASCADE) but integrators with real CASCADE semantics can set when constructing statements.
Companion PRs:- dolthub/go-mysql-server: dolthub/go-mysql-server#3745
- dolthub/doltgresql: dolthub/doltgresql#3155
- 481: support parenthesized select in create table as select (CTAS)
AllowCREATE TABLE ... ASstatements to accept queries enclosed in parentheses. Data tools can emit this syntax, such asdbt(data transformation tool).sql.y: Extractparen_selectrule to parse(SELECT ...).sql.y: Addparen_selectas a production for thecreate_query_expressionrule.ast.go: Implement missing methods and fields on theParenSelectstruct to storeORDER BY,LIMIT,WITHandFOR UPDATE(locking).ast.go: Add sharednewLockhelper.
Fix #11620
Block dolthub/go-mysql-server#3735
- 480: parse
Nas integer only for window functions - 479: README,SECURITY: Slightly update some security messaging.
Clarify that recoverable panics are not currently covered as security issues. - 478: go: sqlparser: Fix some panics on inputs with strange quotes, like SELECT''A.
In a context where sqlparser.Parse is called into without a recover(), this could cause a process crash and thus be an availability concern.
Thanks to Daniel Birtwhistle for the report. - 477: Adding
Columnsfield toTableFuncExpr
Allows aliasing columns from a table function.
Needed primarily for Doltgres, which supports more expressive table functions than MySQL. - 475: go/netutil: Fix tests to be determinsitic even with Go > 1.24, GODEBUG=randseednop.
Closed Issues
- 11468: Dolt panics when
FIRST_VALUEreceives the star placeholder - 11469: Legal
BIT(2)RANGE following frame panics - 11641:
AdaptiveValuedecode paths panic inhash.Newon a malformed out-of-band address instead of returning an error - 11639: Cluster standby:
dolt sqlfails withAccess denied for user '__dolt_local_user__'after users/grants replication - 10856: Error when LateBindQueryist fails to connect to the running sql-server noted in sql-server.info is confusing
- 10168:
dolt_statistics.created_atis always0001-01-01 00:00:00 - 11626: Window-function CTE query is 2.2x slower than MySQL
- 11627: Second reference to a CTE fails with table not found for its alias
- 11564: Dolt panics when LOAD_FILE receives a numeric argument below a window
- 11591: Conjoin failure logs git's fatal auth text on a push that succeeded
- 11620: Dolt - ctas statement raises Syntax Error if 'as' subquery is wrapped in parens
- 10701:
DOLT_QUERY_DIFF: Scope privilege checks to tables referenced in queries - 11453:
DEFAULT(column)reaches an unresolved placeholder during SELECT analysis - 10143: Reused database name should be an error or warning
- 11455:
TRIMpanics on a nativeTIMEvalue - 509: Ensure ability to use AWS S3 compatible data stores
- 11495: Dolt panics on
ROUNDon a date-valued window result - 11467: Dolt panics on a non-numeric NTILE bucket expression
- 11491: Dolt panics on recursive CTE column-arity error.