Ben McClelland
d6d6cc856e
Merge pull request #2225 from versity/ben/path-traversal
...
fix: copy-source parsing mismatch that could bypass path validation
2026-07-03 14:06:56 -07:00
Ben McClelland
67aaa80d99
fix: copy-source parsing mismatch that could bypass path validation
...
The copy-source header was being interpreted differently by request
validation and the backend parser. An encoded ?versionId= separator
could be decoded at one layer but treated as part of the object path
at another, which opened a path traversal risk on filesystem-backed
copy operations.
Align backend copy-source parsing with validation by decoding the
header before splitting the versionId suffix, so both layers derive
the same bucket, object, and versionId values. This closes the
traversal path and adds regression coverage for encoded
copy-source inputs.
Reported by 5ud0 / Tarmo Technologies.
2026-07-03 13:49:59 -07:00
Ben McClelland
7416c53ba6
Merge pull request #2224 from versity/ben/service-example
...
fix: update example config with recent options
2026-07-02 21:31:25 -07:00
Ben McClelland
dbc9bb1b08
fix: update example config with recent options
2026-07-02 20:47:38 -07:00
Ben McClelland
66cc82047e
Merge pull request #2218 from versity/ben/default-etag
...
feat: add configurable default ETag for files without metadata
2026-07-02 20:36:30 -07:00
Ben McClelland
9db2c9c702
feat: add configurable default ETag for files without metadata
...
When versitygw serves files that were placed on the filesystem outside
of the gateway, those files have no stored etag attribute and are
served with an empty ETag. This causes problems for S3 clients that
rely on ETags being non empty.
The new --default-etag flag (VGW_DEFAULT_ETAG) lets operators specify
a fallback ETag value returned for any object that lacks a stored etag
attribute, making pre-existing filesystem data behave more predictably
under S3 workloads without requiring a metadata migration.
2026-07-02 18:09:27 -07:00
Ben McClelland
6b2380853f
Merge pull request #2217 from edespino/fix/azure-multipart-etag-quoting
...
azure: return quoted, consistent multipart part ETags
2026-07-02 17:39:37 -07:00
Ben McClelland
4b83214895
Merge pull request #2212 from versity/test/go_executable_install_script
...
test: add go executable, install base dependencies script
2026-07-02 14:37:44 -07:00
Ed Espino
45674fc2d6
Merge remote-tracking branch 'origin/main' into fix/azure-multipart-etag-quoting
2026-06-30 13:53:16 -07:00
Ed Espino
40cbe85612
test(azure): widen multipart test parts above min size; tighten isQuotedEtag
2026-06-30 13:28:12 -07:00
Luke McCrone
d41ea78799
test: go executable, base install script
2026-06-30 17:15:57 -03:00
Ed Espino
12f22838e2
make azure multipart part etags quoted and consistent
...
quote part etags across all azure multipart surfaces (uploadpart,
listparts, uploadpartcopy) via a shared quoteETag helper, matching the
s3 contract and the posix backend's GenerateEtag convention. populate
the previously-empty UploadPartCopy CopyPartResult with the quoted etag
and last-modified. normalize the client-supplied etag in
CompleteMultipartUpload with backend.TrimEtag so both quoted and raw
etags are accepted. add an azure-full-flow integration test asserting
part etags are quoted and consistent across uploadpart, listparts and
completemultipartupload.
2026-06-30 11:51:38 -07:00
Ed Espino
05cfa0fffa
fix azure etag quote bytes
2026-06-30 10:42:27 -07:00
Ed Espino
efa7e7739a
fix azure multipart etag quoting
2026-06-30 10:36:38 -07:00
Ben McClelland
3e848c8177
Merge pull request #2215 from versity/ben/package-section
...
fix: add section for goreleaser deb/rpm
2026-06-29 16:52:19 -07:00
Ben McClelland
e40462e024
Merge pull request #2214 from versity/dependabot/go_modules/dev-dependencies-996a7a47bb
...
chore(deps): bump the dev-dependencies group with 14 updates
2026-06-29 15:34:54 -07:00
Ben McClelland
a37b655ab7
fix: add section for goreleaser deb/rpm
...
Fixes #2213
2026-06-29 15:33:51 -07:00
dependabot[bot]
03f02a9393
chore(deps): bump the dev-dependencies group with 14 updates
...
Bumps the dev-dependencies group with 14 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/DataDog/datadog-go/v5](https://github.com/DataDog/datadog-go ) | `5.8.3` | `5.9.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.32.25` | `1.32.26` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.19.24` | `1.19.25` |
| [github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager](https://github.com/aws/aws-sdk-go-v2 ) | `0.2.11` | `0.2.12` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2 ) | `1.104.0` | `1.104.1` |
| [github.com/aws/smithy-go](https://github.com/aws/smithy-go ) | `1.27.2` | `1.27.3` |
| [github.com/valyala/fasthttp](https://github.com/valyala/fasthttp ) | `1.71.0` | `1.72.0` |
| [github.com/andybalholm/brotli](https://github.com/andybalholm/brotli ) | `1.2.1` | `1.2.2` |
| [github.com/aws/aws-sdk-go-v2/service/internal/s3shared](https://github.com/aws/aws-sdk-go-v2 ) | `1.19.29` | `1.19.30` |
| [github.com/aws/aws-sdk-go-v2/service/signin](https://github.com/aws/aws-sdk-go-v2 ) | `1.2.0` | `1.2.1` |
| [github.com/aws/aws-sdk-go-v2/service/sso](https://github.com/aws/aws-sdk-go-v2 ) | `1.31.3` | `1.31.4` |
| [github.com/aws/aws-sdk-go-v2/service/ssooidc](https://github.com/aws/aws-sdk-go-v2 ) | `1.36.6` | `1.36.7` |
| [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) | `1.43.3` | `1.43.4` |
| [github.com/gofiber/utils/v2](https://github.com/gofiber/utils ) | `2.1.0` | `2.1.1` |
Updates `github.com/DataDog/datadog-go/v5` from 5.8.3 to 5.9.0
- [Release notes](https://github.com/DataDog/datadog-go/releases )
- [Changelog](https://github.com/DataDog/datadog-go/blob/master/CHANGELOG.md )
- [Commits](https://github.com/DataDog/datadog-go/compare/v5.8.3...v5.9.0 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.25 to 1.32.26
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.25...config/v1.32.26 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.24 to 1.19.25
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.19.24...credentials/v1.19.25 )
Updates `github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager` from 0.2.11 to 0.2.12
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/feature/s3/transfermanager/v0.2.11...feature/s3/transfermanager/v0.2.12 )
Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.104.0 to 1.104.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.104.0...service/s3/v1.104.1 )
Updates `github.com/aws/smithy-go` from 1.27.2 to 1.27.3
- [Release notes](https://github.com/aws/smithy-go/releases )
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md )
- [Commits](https://github.com/aws/smithy-go/compare/v1.27.2...v1.27.3 )
Updates `github.com/valyala/fasthttp` from 1.71.0 to 1.72.0
- [Release notes](https://github.com/valyala/fasthttp/releases )
- [Commits](https://github.com/valyala/fasthttp/compare/v1.71.0...v1.72.0 )
Updates `github.com/andybalholm/brotli` from 1.2.1 to 1.2.2
- [Commits](https://github.com/andybalholm/brotli/compare/v1.2.1...v1.2.2 )
Updates `github.com/aws/aws-sdk-go-v2/service/internal/s3shared` from 1.19.29 to 1.19.30
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/internal/s3shared/v1.19.29...service/internal/s3shared/v1.19.30 )
Updates `github.com/aws/aws-sdk-go-v2/service/signin` from 1.2.0 to 1.2.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/v1.2.1/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.2.0...v1.2.1 )
Updates `github.com/aws/aws-sdk-go-v2/service/sso` from 1.31.3 to 1.31.4
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.31.3...config/v1.31.4 )
Updates `github.com/aws/aws-sdk-go-v2/service/ssooidc` from 1.36.6 to 1.36.7
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.36.6...service/ram/v1.36.7 )
Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.43.3 to 1.43.4
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/amp/v1.43.3...service/amp/v1.43.4 )
Updates `github.com/gofiber/utils/v2` from 2.1.0 to 2.1.1
- [Release notes](https://github.com/gofiber/utils/releases )
- [Commits](https://github.com/gofiber/utils/compare/v2.1.0...v2.1.1 )
---
updated-dependencies:
- dependency-name: github.com/DataDog/datadog-go/v5
dependency-version: 5.9.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.32.26
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-version: 1.19.25
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager
dependency-version: 0.2.12
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
dependency-version: 1.104.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/smithy-go
dependency-version: 1.27.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/valyala/fasthttp
dependency-version: 1.72.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: github.com/andybalholm/brotli
dependency-version: 1.2.2
dependency-type: indirect
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/internal/s3shared
dependency-version: 1.19.30
dependency-type: indirect
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/signin
dependency-version: 1.2.1
dependency-type: indirect
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sso
dependency-version: 1.31.4
dependency-type: indirect
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ssooidc
dependency-version: 1.36.7
dependency-type: indirect
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-version: 1.43.4
dependency-type: indirect
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/gofiber/utils/v2
dependency-version: 2.1.1
dependency-type: indirect
update-type: version-update:semver-patch
dependency-group: dev-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-29 21:16:06 +00:00
Ben McClelland
0aa0f0d4fc
Merge pull request #2208 from versity/test/readme_and_quick_comparison
...
test: README updates, speed up some file integrity checks
v1.6.0
2026-06-24 10:41:30 -07:00
Ben McClelland
ac5170c584
Merge pull request #2211 from versity/ben/enospc
...
fix: prevent connection errors in space/quotas error paths
2026-06-24 10:41:03 -07:00
Ben McClelland
3bdda9a95a
Merge pull request #2210 from versity/ben/middleware
...
feat: add options extensions to embed config
2026-06-24 10:40:46 -07:00
Ben McClelland
9610ef8a4e
fix: prevent connection errors in space/quotas error paths
...
When uploads hit ENOSPC or EDQUOT, the server was returning the
correct S3 error but could close the connection while unread
request bytes were still in flight, which caused TCP resets and
surfaced as broken pipe/connection reset errors in SDKs instead
of a clean Insufficient Storage response. This change drains the
remaining upload body before returning the error so the response
can be delivered and the connection can close gracefully,
preserving correct client-visible behavior under disk-full and
quota-exceeded conditions.
Fixes #2209
2026-06-24 09:18:25 -07:00
Ben McClelland
6f1dfe84e5
feat: add options extensions to embed config
...
Expose S3 option injection in embed gateway config so
integrators can attach request middleware and other
server behaviors without needing to re-implement
RunVersityGW().
2026-06-24 08:54:38 -07:00
Luke McCrone
dba147380e
test: README updates, speed up some file integrity checks
2026-06-23 20:37:14 -03:00
Ben McClelland
bf8b18839f
Merge pull request #2203 from versity/dependabot/github_actions/actions/checkout-7
...
chore(deps): bump actions/checkout from 6 to 7
2026-06-23 11:25:57 -07:00
dependabot[bot]
04bb314817
chore(deps): bump actions/checkout from 6 to 7
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-22 21:05:04 +00:00
Ben McClelland
fd38689567
Merge pull request #2192 from Mart-Kuc/MK-topologySpreadConstraints
...
feat: Add 'topologySpreadConstraints'
2026-06-18 13:13:35 -07:00
Ben McClelland
93bf3d381c
Merge pull request #2090 from versity/ben/windows-test
...
test: add windows build/test for functional tests
2026-06-18 13:08:04 -07:00
Ben McClelland
27f04ad5ea
feat: add windows functional test coverage and fix some windows behavior
...
This change adds Windows functional test execution in CI and updates
backend handling so windows filesystem error/path semantics map correctly
to expected S3 outcomes.
The only meta supported on windows right now is sidecar, so the tests
in windows mode also skip sidecar skips.
Future work is to address the skips and/or more clearly document
the unsupported/incompatible behavior on windows.
The windows support will still remain best effort, but these tests
should at least flag when future changes introduce incompatible
behavior on windows.
2026-06-18 11:34:05 -07:00
Mart-Kuc
4599daafb1
feat: Add 'topologySpreadConstraints'
2026-06-18 09:02:40 +02:00
Ben McClelland
7bde76e982
Merge pull request #2195 from versity/sis/object-lock-default-retention-too-large
...
fix: validate object lock default retention upper limits
2026-06-17 15:35:03 -07:00
Ben McClelland
3311c7f3c1
Merge pull request #2194 from versity/sis/asterisk-read-preconditions
...
fix: support asterisk read preconditions
2026-06-17 15:32:44 -07:00
Ben McClelland
1327b52acd
Merge pull request #2189 from versity/test/list_object_versions
...
test: ListObjectVersions query tests
2026-06-17 15:10:44 -07:00
Luke McCrone
2fa0a2df89
test: ListObjectVersions query tests
2026-06-17 16:42:17 -03:00
Ben McClelland
f0dc14b1fa
Merge pull request #2176 from catdog2/chart-strategy
...
feat(helm): Make it possible to specify deployment strategy
2026-06-17 09:08:15 -07:00
Ben McClelland
3c8d7f9a9c
Merge pull request #2197 from versity/dependabot/go_modules/dev-dependencies-41ce95eee7
...
chore(deps): bump the dev-dependencies group across 1 directory with 12 updates
2026-06-17 08:14:26 -07:00
dependabot[bot]
0d03381d98
chore(deps): bump the dev-dependencies group across 1 directory with 12 updates
...
Bumps the dev-dependencies group with 7 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [github.com/Azure/azure-sdk-for-go/sdk/azidentity](https://github.com/Azure/azure-sdk-for-go ) | `1.13.1` | `1.14.0` |
| [github.com/Azure/azure-sdk-for-go/sdk/storage/azblob](https://github.com/Azure/azure-sdk-for-go ) | `1.7.0` | `1.8.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.32.24` | `1.32.25` |
| [github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager](https://github.com/aws/aws-sdk-go-v2 ) | `0.2.9` | `0.2.11` |
| [github.com/aws/smithy-go](https://github.com/aws/smithy-go ) | `1.27.1` | `1.27.2` |
| [github.com/rabbitmq/amqp091-go](https://github.com/rabbitmq/amqp091-go ) | `1.11.0` | `1.12.0` |
| [github.com/gofiber/schema](https://github.com/gofiber/schema ) | `1.7.1` | `1.8.0` |
Updates `github.com/Azure/azure-sdk-for-go/sdk/azidentity` from 1.13.1 to 1.14.0
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases )
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azidentity/v1.13.1...sdk/azcore/v1.14.0 )
Updates `github.com/Azure/azure-sdk-for-go/sdk/storage/azblob` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases )
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azcore/v1.7.0...sdk/azcore/v1.8.0 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.24 to 1.32.25
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.24...config/v1.32.25 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.23 to 1.19.24
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.19.23...credentials/v1.19.24 )
Updates `github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager` from 0.2.9 to 0.2.11
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/feature/s3/transfermanager/v0.2.9...feature/s3/transfermanager/v0.2.11 )
Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.103.3 to 1.104.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.103.3...service/s3/v1.104.0 )
Updates `github.com/aws/smithy-go` from 1.27.1 to 1.27.2
- [Release notes](https://github.com/aws/smithy-go/releases )
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md )
- [Commits](https://github.com/aws/smithy-go/compare/v1.27.1...v1.27.2 )
Updates `github.com/rabbitmq/amqp091-go` from 1.11.0 to 1.12.0
- [Release notes](https://github.com/rabbitmq/amqp091-go/releases )
- [Changelog](https://github.com/rabbitmq/amqp091-go/blob/main/CHANGELOG.md )
- [Commits](https://github.com/rabbitmq/amqp091-go/compare/v1.11.0...v1.12.0 )
Updates `github.com/aws/aws-sdk-go-v2/service/signin` from 1.1.5 to 1.2.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/v1.2.0/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.1.5...v1.2.0 )
Updates `github.com/gofiber/schema` from 1.7.1 to 1.8.0
- [Release notes](https://github.com/gofiber/schema/releases )
- [Commits](https://github.com/gofiber/schema/compare/v1.7.1...v1.8.0 )
Updates `github.com/gofiber/utils/v2` from 2.0.6 to 2.1.0
- [Release notes](https://github.com/gofiber/utils/releases )
- [Commits](https://github.com/gofiber/utils/compare/v2.0.6...v2.1.0 )
Updates `golang.org/x/net` from 0.55.0 to 0.56.0
- [Commits](https://github.com/golang/net/compare/v0.55.0...v0.56.0 )
---
updated-dependencies:
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azidentity
dependency-version: 1.14.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/storage/azblob
dependency-version: 1.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.32.25
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-version: 1.19.24
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager
dependency-version: 0.2.11
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
dependency-version: 1.104.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: github.com/aws/smithy-go
dependency-version: 1.27.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dev-dependencies
- dependency-name: github.com/rabbitmq/amqp091-go
dependency-version: 1.12.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/signin
dependency-version: 1.2.0
dependency-type: indirect
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: github.com/gofiber/schema
dependency-version: 1.8.0
dependency-type: indirect
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: github.com/gofiber/utils/v2
dependency-version: 2.1.0
dependency-type: indirect
update-type: version-update:semver-minor
dependency-group: dev-dependencies
- dependency-name: golang.org/x/net
dependency-version: 0.56.0
dependency-type: indirect
update-type: version-update:semver-minor
dependency-group: dev-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-17 04:09:18 +00:00
Ben McClelland
dd6e7de6c6
Merge pull request #2184 from versity/sis/empty-content-md5
...
fix: reject empty Content-MD5 on PUT operations
2026-06-16 21:06:16 -07:00
Ben McClelland
ee2364e70c
Merge pull request #2182 from versity/sis/fiber-migration-v3
...
feat: migrate Fiber to v3.3.0
2026-06-16 21:00:09 -07:00
niksis02
67af0afa81
fix: validate object lock default retention upper limits
...
Fixes #2187
Enforce maximum default retention periods when parsing PutObjectLockConfiguration requests. Reject Days values greater than 36500 and Years values greater than 100 with InvalidArgument errors.
2026-06-16 22:48:51 +04:00
niksis02
6df901ba42
fix: support asterisk read preconditions
...
Fixes #2185
Add asterisk handling for `If-Match` and `If-None-Match` read preconditions across `GetObject`, `HeadObject`, `CopyObject`, and `UploadPartCopy`.
`If-Match`: `*` now matches any `ETag`, while `If-None-Match`: `*` returns `304 Not Modified`.
2026-06-16 21:36:45 +04:00
niksis02
12fb5a6594
fix: reject empty Content-MD5 on PUT operations
...
Fixes #2179
Treat a present but empty `Content-MD5` header as an invalid digest instead of handling it as if the header were absent. This makes PUT operations return `InvalidDigest` for empty `Content-MD5` values while preserving existing behavior for missing headers.
2026-06-15 18:53:42 +04:00
Peter Dahlberg
27e90ce86e
feat(helm): Make it possible to specify deployment strategy
2026-06-15 14:20:55 +02:00
niksis02
4d391cabc8
feat: migrate Fiber to v3.3.0
...
Fixes #2180
Fixes #2181
Migrate the gateway from Fiber v2 to Fiber v3.3.0 and update the affected server, middleware, handler, controller, and test code for the new APIs.
Replace the deprecated Fiber filesystem middleware used by the WebUI with the Fiber v3 static middleware, serving the embedded WebUI assets from an fs.Sub filesystem.
Fix the request header limit handling regression by adding a temporary handler for Fiber v3/fasthttp small-buffer errors so oversized request headers return the expected regulated S3 error response.
Fix the debuglogger panic by reworking the boxed key/value formatter used for debug request and response dumps. The formatter now handles long header keys and values without producing invalid wrap widths, negative padding, or out-of-range string slices.
2026-06-15 14:48:31 +04:00
Ben McClelland
fa789478d2
Merge pull request #2163 from versity/test/jailing
...
test: jailing (all code)
2026-06-10 20:24:13 -07:00
Luke McCrone
3a35e37b5c
test: jailing, logging, executable cleanups
2026-06-10 12:46:27 -03:00
Ben McClelland
619fdb8dce
Merge pull request #2171 from versity/sis/static-website-hosting
...
Static website hosting
2026-06-10 08:10:18 -07:00
Ben McClelland
df6ee64ad6
Merge pull request #2175 from SebTardif/fix/nil-panic-ownership-controls
...
fix: prevent index-out-of-range panic in s3proxy GetBucketOwnershipControls
2026-06-10 08:07:25 -07:00
niksis02
f08f76fea4
feat: support x-amz-website-redirect-location
...
Integrate x-amz-website-redirect-location across object metadata flows so uploads, copies, multipart creation, HEAD, and GET preserve and return redirect locations, and website hosting applies object-level redirects from the stored value.
2026-06-10 12:41:55 +04:00
niksis02
1625c5963e
feat: improve static website hosting support
...
Enhances the static website hosting implementation with more complete S3-compatible behavior across request handling, backend storage, validation, CORS, and errors.
Adds dedicated website endpoint handling for GET, HEAD, and OPTIONS requests, including index document resolution, error document serving, redirect-all support, pre-fetch and post-error routing rules, query string preservation in redirects, public access checks before object reads, and method-not-allowed responses.
Improves error handling for website responses by returning S3-compatible HTML error bodies with request IDs, host IDs, x-amz-error-code, x-amz-error-message, and specialized error fields. This also fixes website-related validation errors to return more accurate S3-style error codes and messages, including invalid redirect protocols, invalid HTTP redirect/error codes, conflicting routing rule replacements, routing rule limits, and oversized website configuration requests.
Adds website CORS support for GET, HEAD, and OPTIONS preflight requests, including bucket CORS lookup through website host bucket resolution, allowed origin/method/header validation, exposed header handling, ETag exposure, Vary headers, max-age handling, and CORS access-denied responses.
Adds debug logging around website configuration parsing, validation failures, CORS checks, backend lookup failures, and internal website error paths to make failures easier to diagnose.
Adds compressed website configuration storage so larger configs fit backend metadata limits, including gzip storage for POSIX extended attributes and base64-encoded compressed metadata for Azure. Also adds Azure PutBucketWebsite, GetBucketWebsite, and DeleteBucketWebsite support.
Adds and expands test coverage for website config validation, S3-compatible HTML error bodies, website routing behavior, public access enforcement, HEAD behavior, CORS handling, PutBucketWebsite limits, and end-to-end website hosting through a Docker-based dnsmasq test setup and CI workflow.
2026-06-10 12:41:55 +04:00