PGSTY SILO Blog
-
Bucket Configuration Replication: Source Times, Deletions, and Deterministic Convergence
#77 is a reproduced site-replication correctness defect. A receiver replaces source time with arrival time and may then reject a genuinely newer deletion. Some configuration types stop exporting their timestamp after deletion, preventing heal from …
#77 is a reproduced site-replication correctness defect. A receiver replaces source time with arrival time and may then reject a genuinely newer deletion. Some configuration types stop exporting their timestamp after deletion, preventing heal from …
-
Replication Reliability: Delete Completion, MRF Visibility, and Resync Cancellation
This page records the analysis, design choices, review, and implementation of #153, #152, and #137. They belong to the same replication reliability series, but affect operation classification, recovery visibility, and task lifecycle respectively. One …
This page records the analysis, design choices, review, and implementation of #153, #152, and #137. They belong to the same replication reliability series, but affect operation classification, recovery visibility, and task lifecycle respectively. One …
-
An Unsigned Header Is Not Part of the Request
This record describes the unsigned-header coverage repair committed to SILO as 123325430 and merged through PR #173, tracked as SN-2026-011. It was reported by Oren Yomtov against a released build and reproduced locally on both signature paths. …
This record describes the unsigned-header coverage repair committed to SILO as 123325430 and merged through PR #173, tracked as SN-2026-011. It was reported by Oren Yomtov against a released build and reproduced locally on both signature paths. …
-
mcli 20260903 Released
Published: 2026-09-03 · Version: RELEASE.2026-09-03T07-13-05Z · Source: a2ef95c0 Twenty-eight days after mcli 20260806, this release carries everything the client accumulated since. The toolchain moves to Go 1.27.1 and the shared dependency stack is …
Published: 2026-09-03 · Version: RELEASE.2026-09-03T07-13-05Z · Source: a2ef95c0 Twenty-eight days after mcli 20260806, this release carries everything the client accumulated since. The toolchain moves to Go 1.27.1 and the shared dependency stack is …
-
Silo 20260903 Released
Version date: 2026-09-03 · Published: 2026-09-04 · Version: RELEASE.2026-09-03T13-18-01Z · Previous release: RELEASE.2026-08-06T00-00-00Z SILO 20260903 is the security and correctness release following the first fully rebranded Silo release. Its main …
Version date: 2026-09-03 · Published: 2026-09-04 · Version: RELEASE.2026-09-03T13-18-01Z · Previous release: RELEASE.2026-08-06T00-00-00Z SILO 20260903 is the security and correctness release following the first fully rebranded Silo release. Its main …
-
SILO Server 20260903 Pre-release Review
This is the durable pre-release engineering record behind SILO 20260903. It explains why an earlier “all issues are solved” assessment was not accepted at face value, what the independent review found, how the fixes were narrowed, and which gates …
This is the durable pre-release engineering record behind SILO 20260903. It explains why an earlier “all issues are solved” assessment was not accepted at face value, what the independent review found, how the fixes were narrowed, and which gates …
-
SILO 20260903 Security Notes: SN-2026-006 through 010
Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …
Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …
-
Explicit Version Deletes Now Require DeleteObjectVersion
Release status: this change is implemented in pgsty/silo#104, tracking issue #58. Publishing this note does not by itself mean that a server release, package, image, or deployment contains the change. SILO now maps object-delete authorization to the …
Release status: this change is implemented in pgsty/silo#104, tracking issue #58. Publishing this note does not by itself mean that a server release, package, image, or deployment contains the change. SILO now maps object-delete authorization to the …
-
No I/O Before Auth, No Privilege From Headers
This record describes the CORS hot-path and replication-request trust repair merged into SILO as PR #101 (938603458 through 04b097fd9). Status on 2026-09-03: PR #101 merged into main on 2026-09-01 with four follow-up commits: per-entry Snowball trust …
This record describes the CORS hot-path and replication-request trust repair merged into SILO as PR #101 (938603458 through 04b097fd9). Status on 2026-09-03: PR #101 merged into main on 2026-09-01 with four follow-up commits: per-entry Snowball trust …
-
Should SILO Fix ListMultipartUploads? Design Review of Issue #79
This is the problem, design, and decision record for SILO issue #79. Status on 2026-08-30: confirmed compatibility defect; design proposal only. No server implementation, release artifact, deployment, or production verification is claimed by this …
This is the problem, design, and decision record for SILO issue #79. Status on 2026-08-30: confirmed compatibility defect; design proposal only. No server implementation, release artifact, deployment, or production verification is claimed by this …
-
silo-pkg 3.13.0 Released
Release date: 2026-08-30 · Version: v3.13.0 · Commit: 215f116 · Repository: pgsty/silo-pkg Version 3.13.0 is a breaking release with one theme: the module stops claiming upstream’s import path and takes its own. It also retires the pgsty/silo-go …
Release date: 2026-08-30 · Version: v3.13.0 · Commit: 215f116 · Repository: pgsty/silo-pkg Version 3.13.0 is a breaking release with one theme: the module stops claiming upstream’s import path and takes its own. It also retires the pgsty/silo-go …
-
Read-Only Checksum Audit and Reliable CLI Output
This is the design and implementation record for MCLI’s read-only checksum verification workflow and pgsty/mc#5, the non-TTY output defect found during release review. Status: shipped in the final mcli 20260903 release. The command merged to main …
This is the design and implementation record for MCLI’s read-only checksum verification workflow and pgsty/mc#5, the non-TTY output defect found during release review. Status: shipped in the final mcli 20260903 release. The command merged to main …
-
Two SSE-C Keys, One CopyObject Response
This record explains the CopyObject SSE-C checksum response repair committed in SILO as e73436c99. Status on 2026-08-28: implementation, encryption and key-rotation tests, complete server suites, race tests, static checks, build, and independent …
This record explains the CopyObject SSE-C checksum response repair committed in SILO as e73436c99. Status on 2026-08-28: implementation, encryption and key-rotation tests, complete server suites, race tests, static checks, build, and independent …
-
Config Environment Files Are Not Shell Scripts
This record defines the startup contract for MINIO_CONFIG_ENV_FILE and explains the compatibility repair committed in SILO as 2aea7fe9c. Status on 2026-08-28: implementation, focused tests, the complete cmd and internal suites, tagged tests, race …
This record defines the startup contract for MINIO_CONFIG_ENV_FILE and explains the compatibility repair committed in SILO as 2aea7fe9c. Status on 2026-08-28: implementation, focused tests, the complete cmd and internal suites, tagged tests, race …
-
BadDigest, InvalidRequest, and the CompleteMultipartUpload Checksum Contract
This is the design, investigation, and verification record for SILO #48, with the decision boundary for the related SILO #50. Status: pgsty/silo#74 merged as 590aeaa7d, and pgsty/silo.pgsty.com#6 merged as 9805dd7; full local verification, remote CI, …
This is the design, investigation, and verification record for SILO #48, with the decision boundary for the related SILO #50. Status: pgsty/silo#74 merged as 590aeaa7d, and pgsty/silo.pgsty.com#6 merged as 9805dd7; full local verification, remote CI, …
-
A ListObjects Shortcut Must Not Turn a Missing Bucket into an Empty One
This document records the problem analysis, design discussion, and repair decision for SILO #32 and PR #37. Status on 2026-08-26: PR #37 was updated to the DCO-signed head e9c5340be, formally approved, and merged as 49c8aeac4; #32 closed …
This document records the problem analysis, design discussion, and repair decision for SILO #32 and PR #37. Status on 2026-08-26: PR #37 was updated to the DCO-signed head e9c5340be, formally approved, and merged as 49c8aeac4; #32 closed …
-
One Endpoint, Two Privileges: Separating User and Group Status
This document records the discussion, repair, and final authorization design for upstream issue minio/minio#21478 and SILO PR #73. Status on 2026-08-26: SILO PR #73 was merged as 2e2377d1c, preserving the signed-off repair commit 58735ee38. All eight …
This document records the discussion, repair, and final authorization design for upstream issue minio/minio#21478 and SILO PR #73. Status on 2026-08-26: SILO PR #73 was merged as 2e2377d1c, preserving the signed-off repair commit 58735ee38. All eight …
-
Conditional DELETE: Why the Condition Must Be Evaluated Once
This document records the analysis, design discussion, and repair decision for SILO PR #12. Status on 2026-08-26: PR #12 remains open at head 5b71a75e, 118 commits behind the latest main. Its commit has no DCO sign-off and GitHub reports no check …
This document records the analysis, design discussion, and repair decision for SILO PR #12. Status on 2026-08-26: PR #12 remains open at head 5b71a75e, 118 commits behind the latest main. Its commit has no DCO sign-off and GitHub reports no check …
-
Silo Console 2.2.0 Release Notes
Note Released on 2026-08-26. v2.2.0 points to final commit 7dc4258a6. The exact tagged tree passed the full CI matrix, vulnerability checks, and release pipeline. The public release contains six standalone binaries, nine Linux packages, and a …
Note Released on 2026-08-26. v2.2.0 points to final commit 7dc4258a6. The exact tagged tree passed the full CI matrix, vulnerability checks, and release pipeline. The public release contains six standalone binaries, nine Linux packages, and a …
-
Why CompleteMultipartUpload Must Return ChecksumType: Review of PR #57
This is the design, review, and decision record for SILO #47 and PR #57. Status on 2026-08-26: PR #57 was approved and merged as a96116b1; #47 closed automatically. All nine checks on the tested PR head passed, followed by green Go CI and VulnCheck …
This is the design, review, and decision record for SILO #47 and PR #57. Status on 2026-08-26: PR #57 was approved and merged as a96116b1; #47 closed automatically. All nine checks on the tested PR head passed, followed by green Go CI and VulnCheck …