github nats-io/nats-server v2.14.8
Release v2.14.8

latest release: v2.15.1
4 hours ago

Changelog

Refer to the 2.14 Upgrade Guide for backwards compatibility notes with 2.12.x. Please note that the 2.13.x version was skipped.

Go Version

Dependencies

  • github.com/klauspost/compress v1.20.1 (#8737)
  • github.com/nats-io/nats.go v1.53.1 (#8737)

Changed

Gateways

  • Support for sending and handling the legacy $GR. reply prefix, used by servers prior to v2.1.2, has been removed (#8615)

Improved

JetStream

  • Stalled source and mirror flow control is now reported in stream info and warning logs, making missing $JS.FC.> imports or exports easier to diagnose (#8633)
  • Stream and consumer placement now prefers peers that have caught up with the metalayer, reducing delays in API responses (#8643)
  • Improved the performance of deleting entries from and encoding AVL sequence sets (#8646)
  • Fast batch publish now reports backward sequence gaps as well as forward gaps (#8699)
  • Stream pending message calculations avoid unnecessary filestore cache access and handle deleted sequence ranges more efficiently (#8680, #8681)
  • Stream restore waits for the preferred node to become leader, avoiding an incorrect create response during clustered restore (#8690)
  • Memory backed streams avoid copying message headers and bodies twice when storing messages (#8652, contributed by @randomizedcoder)

Monitoring

  • Leafz now reports whether a leafnode connection uses WebSockets (#8683)

MQTT

  • Partial packets are no longer copied in full on every read, reducing allocations and buffer copying (#8692)

Fixed

General

  • Concurrent account JWT updates no longer invalidate stream imports and interrupt message delivery (#8610)
  • Configuration reloads no longer incorrectly disconnect operator mode clients that send an nkey (#8609)
  • Connz requests selecting a connection by cid now correctly apply account, user and MQTT client ID filters (#8613)
  • Pipelined client operations are no longer processed after a connection is rejected for exceeding the account's max_connections limit (#8614)
  • Queue subscription deny permissions are now checked against the mapped delivery subject (#8616)
  • Outstanding reply permissions are now preserved when inherited account permissions are refreshed without changing the response policy (#8620, contributed by @0xasritha)
  • Subscription deny filters are now rebuilt atomically when inherited account permissions are refreshed, preventing a window in which denied messages could be delivered (#8622, contributed by @0xasritha)
  • Unquoted configuration values beginning with a number and a size or exponent suffix, such as 0K1abc, are now correctly parsed as strings (#8263, contributed by @koriyoshi2041)
  • Account JWT updates now reject invalid subject mappings instead of reporting success, and failed replacements no longer remove existing mappings (#8627, contributed by @vulragrag-star)
  • Cached subscription results are now cleared when an already connected client sends another CONNECT, preventing stale results from being reused after an account change (#8641, reported by @Tan-JunWei)
  • Fixed several data races affecting service imports and exports during configuration reloads and account updates (#8675)
  • Per-account routes no longer double count inbound account message and byte statistics (#8677)
  • TLS certificate pin validation now checks the correct pins after a configuration reload (#8679)
  • Fast batch ping no longer starts a new batch incorrectly (#8714)
  • Auth callout rejections are now reported as authentication errors instead of account connection limit errors (#8688, contributed by @aniketatgithub)
  • Scoped ProxyRequired settings are now respected in JWTs and auth callouts (#8694)
  • Subscription interest notifications are no longer missed when a subscription is added or removed concurrently (#8703)
  • Fixed issues with auth callout auth_users bypass
  • Fixed a PDH counter buffer overflow on Windows

JetStream

  • Stream scale-down requests are now rejected when the target replica count has no configured account tier (#8608)
  • Stale per-message TTL entries are now removed when their messages have already been deleted, avoiding repeated expiry scans and excess CPU and memory usage (#8595, contributed by @digitalstraw)
  • The maximum deliveries exceeded advisory is now sent correctly when a consumer's max_deliver is lowered below a message's existing delivery count (#8605, contributed by @zeke-lin)
  • The consumer created time is now preserved after recovery (#8621)
  • Filestore compaction now respects the configured sync settings when replacing a message block (#8629)
  • Fixed a race during filestore compaction that could cause consumers to skip messages or lose redelivery tracking (#8623, contributed by @as-clearview)
  • Concurrent updates to R1 consumers no longer lose API responses (#8628)
  • Stream and consumer create and delete requests received during metalayer catchup now receive responses once catchup completes (#8643)
  • R1 consumer create requests no longer lose their responses when the consumer is deleted immediately afterwards (#8643)
  • Fixed a data race when handling consumer leader stepdown requests (#8647)
  • Fixed a memory leak affecting pull requests and direct gets after a configuration reload when the system account is explicitly configured in the accounts block (#8650, contributed by @1995parham)
  • Fixed a panic when shutting down a clustered JetStream server immediately after startup (#8707, contributed by @clwluvw)
  • Idempotent stream create requests with sources no longer time out after leader changes (#8703)
  • Recovered ephemeral consumers with inactive_threshold set are now cleaned up properly after a server restart (#8732)

Leafnodes

  • Publish permissions are now checked against the transformed subject sent over the leafnode connection, avoiding the need to also allow the original stream import subject (#8530, contributed by @fbarth-ifr)
  • Fixed incorrect pending byte accounting after a partial compressed write that could stall a leafnode connection and prevent it from reconnecting (#8636)
  • Closed leafnode connections are now correctly removed from the account's leafnode list, reducing retained memory and garbage collection pressure (#8637)
  • TLS state is now available to auth callouts when leafnodes connect over WebSockets (#8686, contributed by @jurry-duty)
  • Leafnode clients are now shed alongside regular clients during lame duck shutdown, avoiding a thundering herd (#8695)
  • Remote proxies now support TLS with https:// proxy URLs and an optional proxy tls block (#8701)
  • Remote proxies no longer incorrectly warn that nats:// URLs are unsupported or lose the hub's initial INFO message (#8701)
  • Remote proxy options are now rejected when no proxy URL is specified (#8701)
  • Leafnode interest and request/reply across account imports (#8730, contributed by @edjeffreys)

Gateways

  • The legacy $GR. reply prefix is now reserved on client ingress, preventing clients from publishing to gateway reply subjects using that prefix (#8615)

MQTT

  • Config load no longer breaks QoS1/QoS2 delivery when max_ack_pending is unset (#8671)
  • MQTT packet lengths are validated earlier against max_payload (#8692)

Complete Changes

v2.14.7...v2.14.8

Don't miss a new nats-server release

NewReleases is sending notifications on new releases.