From b37b4bfe3cae050ac2c28bcbd7f15ef2478ec75e Mon Sep 17 00:00:00 2001 From: DJ Mountney Date: Fri, 9 Oct 2026 10:54:57 -0700 Subject: [PATCH 1/2] chore: bump the bundled RustFS to 1.0.1 [ENG-1745] 1.0.0-alpha.79 accepts a bucket lifecycle configuration and returns it from GetBucketLifecycleConfiguration, but never expires the objects it matches. 1.0.1 enforces it, and includes the fix for CVE-2026-73288. Verified on the generated docker-compose.full.yml: with a past-dated expiry rule on expire/, objects under the prefix 404 within 5 seconds, including ones written after the rule, and an object outside it stays. Co-Authored-By: Claude Opus 5.5 --- docs/configuration.md | 2 +- on-prem/.env.example | 2 +- on-prem/CHANGELOG.md | 10 ++++++++++ on-prem/docker-compose.full.yml | 2 +- on-prem/templates/compose.rustfs.yml | 2 +- 5 files changed, 14 insertions(+), 4 deletions(-) diff --git a/docs/configuration.md b/docs/configuration.md index 29fa820..2b87fa8 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -97,7 +97,7 @@ These variables configure Docker Compose behavior only (not passed to containers | `DC_MONGODB_IMAGE` | string | `mongo:8.2.3` | MongoDB image | | `DC_REDIS_IMAGE` | string | `redis/redis-stack-server:7.4.0-v8` | Redis image | | `DC_CLICKHOUSE_IMAGE` | string | `clickhouse/clickhouse-server:25.8` | ClickHouse image | -| `DC_RUSTFS_IMAGE` | string | `rustfs/rustfs:1.0.0-alpha.79` | RustFS image | +| `DC_RUSTFS_IMAGE` | string | `rustfs/rustfs:1.0.1` | RustFS image | | `DC_AWS_CLI_IMAGE` | string | `amazon/aws-cli:latest` | AWS CLI image (for bucket init) | #### Port Configuration diff --git a/on-prem/.env.example b/on-prem/.env.example index 6c8dcc8..88b9178 100644 --- a/on-prem/.env.example +++ b/on-prem/.env.example @@ -165,7 +165,7 @@ INVITE_EXPIRATION_DAYS= # DC_MONGODB_IMAGE=mongo:8.2.3 # DC_REDIS_IMAGE=redis/redis-stack-server:7.4.0-v8 # DC_CLICKHOUSE_IMAGE=clickhouse/clickhouse-server:25.8 -# DC_RUSTFS_IMAGE=rustfs/rustfs:1.0.0-alpha.79 +# DC_RUSTFS_IMAGE=rustfs/rustfs:1.0.1 # DC_AWS_CLI_IMAGE=amazon/aws-cli:latest # Port Configuration diff --git a/on-prem/CHANGELOG.md b/on-prem/CHANGELOG.md index 0177bc2..b97821a 100644 --- a/on-prem/CHANGELOG.md +++ b/on-prem/CHANGELOG.md @@ -6,6 +6,16 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). ## [Unreleased] +### Compose File Changes +- The bundled RustFS image is `rustfs/rustfs:1.0.1` (requires `./scripts/generate-compose.sh` if using custom templates) + +### Changed Environment Variables +- `DC_RUSTFS_IMAGE` defaults to `rustfs/rustfs:1.0.1`. If your `.env` sets it, update the value to pick up the fixes below. + +### Fixed +- The bundled RustFS enforces bucket lifecycle rules. `1.0.0-alpha.79` accepted a lifecycle configuration and returned it from `GetBucketLifecycleConfiguration`, but never expired the matching objects. +- The bundled RustFS includes the fix for CVE-2026-73288, where lifecycle and scanner sweeps could expire objects under COMPLIANCE retention when lock metadata was missing or unreadable. + ## [2026-07-26-006] - 2026-10-07 Image-only update: no compose file or environment variable changes. Update `DC_CURRENTS_IMAGE_TAG`, then `docker compose pull && docker compose up -d`. diff --git a/on-prem/docker-compose.full.yml b/on-prem/docker-compose.full.yml index 5571c9e..d1cb6c4 100644 --- a/on-prem/docker-compose.full.yml +++ b/on-prem/docker-compose.full.yml @@ -270,7 +270,7 @@ services: - ${DC_REDIS_VOLUME:-./data/redis}:/data rustfs: hostname: rustfs - image: ${DC_RUSTFS_IMAGE:-rustfs/rustfs:1.0.0-alpha.79} + image: ${DC_RUSTFS_IMAGE:-rustfs/rustfs:1.0.1} ports: - ${DC_RUSTFS_S3_PORT:-9000}:9000 # S3 API port - ${DC_RUSTFS_CONSOLE_PORT:-9001}:9001 # Web console port diff --git a/on-prem/templates/compose.rustfs.yml b/on-prem/templates/compose.rustfs.yml index b778cc3..58e4195 100644 --- a/on-prem/templates/compose.rustfs.yml +++ b/on-prem/templates/compose.rustfs.yml @@ -4,7 +4,7 @@ services: rustfs: hostname: rustfs - image: ${DC_RUSTFS_IMAGE:-rustfs/rustfs:1.0.0-alpha.79} + image: ${DC_RUSTFS_IMAGE:-rustfs/rustfs:1.0.1} ports: - ${DC_RUSTFS_S3_PORT:-9000}:9000 # S3 API port - ${DC_RUSTFS_CONSOLE_PORT:-9001}:9001 # Web console port From 0fd80eb181dd9b30a6303632855a660dc142d0d7 Mon Sep 17 00:00:00 2001 From: DJ Mountney Date: Fri, 9 Oct 2026 11:02:17 -0700 Subject: [PATCH 2/2] fix: keep CORS headers on the bundled RustFS 1.0.1 [ENG-1745] 1.0.0-alpha.79 answered every request with access-control-allow-origin: * without any configuration. 1.0.1 sends no CORS headers unless RUSTFS_CORS_ALLOWED_ORIGINS or a bucket CORS rule is set, so trace.playwright.dev and the dashboard's stdout and attachment previews fail their cross-origin fetches. "*" restores what alpha.79 sent and matches packages/on-premise in the currents repo. Verified on the generated docker-compose.full.yml: a preflight and a GET on a presigned URL both return access-control-allow-origin: *. Co-Authored-By: Claude Opus 5.5 --- on-prem/CHANGELOG.md | 1 + on-prem/docker-compose.full.yml | 4 ++++ on-prem/templates/compose.rustfs.yml | 4 ++++ 3 files changed, 9 insertions(+) diff --git a/on-prem/CHANGELOG.md b/on-prem/CHANGELOG.md index b97821a..cef5b61 100644 --- a/on-prem/CHANGELOG.md +++ b/on-prem/CHANGELOG.md @@ -8,6 +8,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). ### Compose File Changes - The bundled RustFS image is `rustfs/rustfs:1.0.1` (requires `./scripts/generate-compose.sh` if using custom templates) +- The `rustfs` service sets `RUSTFS_CORS_ALLOWED_ORIGINS: "*"`. `1.0.1` sends no CORS headers without it, which breaks trace.playwright.dev and the dashboard's stdout and attachment previews. If you run `1.0.1` from your own compose file, add it there too. ### Changed Environment Variables - `DC_RUSTFS_IMAGE` defaults to `rustfs/rustfs:1.0.1`. If your `.env` sets it, update the value to pick up the fixes below. diff --git a/on-prem/docker-compose.full.yml b/on-prem/docker-compose.full.yml index d1cb6c4..add57cd 100644 --- a/on-prem/docker-compose.full.yml +++ b/on-prem/docker-compose.full.yml @@ -278,6 +278,10 @@ services: RUSTFS_CONSOLE_ENABLE: "true" RUSTFS_ACCESS_KEY: ${RUSTFS_ACCESS_KEY} RUSTFS_SECRET_KEY: ${RUSTFS_SECRET_KEY} + # The dashboard and https://trace.playwright.dev fetch objects from the + # browser through presigned URLs. RustFS sends no CORS headers unless this + # or a bucket CORS rule is set. + RUSTFS_CORS_ALLOWED_ORIGINS: "*" env_file: - .env networks: diff --git a/on-prem/templates/compose.rustfs.yml b/on-prem/templates/compose.rustfs.yml index 58e4195..0b641bf 100644 --- a/on-prem/templates/compose.rustfs.yml +++ b/on-prem/templates/compose.rustfs.yml @@ -12,6 +12,10 @@ services: RUSTFS_CONSOLE_ENABLE: "true" RUSTFS_ACCESS_KEY: ${RUSTFS_ACCESS_KEY} RUSTFS_SECRET_KEY: ${RUSTFS_SECRET_KEY} + # The dashboard and https://trace.playwright.dev fetch objects from the + # browser through presigned URLs. RustFS sends no CORS headers unless this + # or a bucket CORS rule is set. + RUSTFS_CORS_ALLOWED_ORIGINS: "*" env_file: - .env networks: