Repository navigation
chore: bump the bundled RustFS to 1.0.1 [ENG-1745] - #30
Merged
Merged
Conversation
1.0.0-alpha.79 accepts a bucket lifecycle configuration and returns it from GetBucketLifecycleConfiguration, but never expires the objects it matches. 1.0.1 enforces it, and includes the fix for CVE-2026-73288. Verified on the generated docker-compose.full.yml: with a past-dated expiry rule on expire/, objects under the prefix 404 within 5 seconds, including ones written after the rule, and an object outside it stays. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1.0.0-alpha.79 answered every request with access-control-allow-origin: * without any configuration. 1.0.1 sends no CORS headers unless RUSTFS_CORS_ALLOWED_ORIGINS or a bucket CORS rule is set, so trace.playwright.dev and the dashboard's stdout and attachment previews fail their cross-origin fetches. "*" restores what alpha.79 sent and matches packages/on-premise in the currents repo. Verified on the generated docker-compose.full.yml: a preflight and a GET on a presigned URL both return access-control-allow-origin: *. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
twk3
marked this pull request as ready for review
October 9, 2026 19:46
Contributor
Author
|
Baz full review |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the bundled RustFS from
1.0.0-alpha.79to1.0.1and keeps the CORS headers the dashboard and trace.playwright.dev depend on (ENG-1745).1.0.0-alpha.79accepts a bucket lifecycle configuration and returns it fromGetBucketLifecycleConfiguration, but never expires the objects it matches. ENG-1738 and ENG-1739 both add lifecycle rules, so they would ship as no-ops on the bundled storage.1.0.1enforces them and includes the fix for CVE-2026-73288 (lifecycle and scanner sweeps could expire objects under COMPLIANCE retention).Changes
DC_RUSTFS_IMAGEdefaults torustfs/rustfs:1.0.1intemplates/compose.rustfs.yml,.env.exampleanddocs/configuration.md.docker-compose.full.ymlis regenerated withgenerate-compose.sh full; the only diff is the image line and the CORS setting below.rustfsservice setsRUSTFS_CORS_ALLOWED_ORIGINS: "*". alpha.79 sentaccess-control-allow-origin: *on every response without configuration;1.0.1sends no CORS headers unless this or a bucket CORS rule is set. Without it the dashboard's stdout and attachment previews and trace.playwright.dev fail their cross-origin fetches.*is what alpha.79 sent, and whatpackages/on-premisein the currents repo already sets.[Unreleased], including a note for anyone running1.0.1from their own compose file.Testing
On the generated
docker-compose.full.ymlwith the2026-07-26-006images, ports moved off the defaults:rustfsis healthy (the image still shipscurlfor the healthcheck) andrustfs-initcreates the bucket.expire/makes objects under the prefix 404 within 5 seconds, including objects written after the rule; an object outside the prefix stays. The same test on alpha.79 left the object in place.FILE_STORAGE_INTERNAL_ENDPOINTlogupload successful, and no service logs a warning or error.RUSTFS_CORS_ALLOWED_ORIGINSremoved from therustfsservice, Chrome blocks the dashboard's stdout fetch (Access to fetch ... has been blocked by CORS policy) and the Console tab stays empty. Restoring it fixes both.Related
Checklist
(fix|feat|chore): title [CSR-xxx]🤖 Generated with Claude Code