|
1 | 1 | # Table of Contents |
2 | 2 |
|
| 3 | +* [Changelog for 8.0.9](#changelog-for-809-2026-10-02) |
3 | 4 | * [Changelog for 8.0.8](#changelog-for-808-2026-08-20) |
4 | 5 | * [Changelog for 8.0.7](#changelog-for-807-2026-07-31) |
5 | 6 | * [Changelog for 8.0.6](#changelog-for-806-2026-07-15) |
|
67 | 68 | * [Changelog for 1.1.0](#changelog-for-110-2021-01-22) |
68 | 69 | * [Changelog for 1.0.0](#changelog-for-100-2020-12-17) |
69 | 70 |
|
| 71 | +# Changelog for [8.0.9] (2026-10-02) |
| 72 | + |
| 73 | +The following sections list the changes for 8.0.9. |
| 74 | + |
| 75 | +[8.0.9]: https://github.com/owncloud/ocis/compare/v8.0.8...v8.0.9 |
| 76 | + |
| 77 | +## Summary |
| 78 | + |
| 79 | +* Security - Bump grpc-go dependency: [#13020](https://github.com/owncloud/ocis/pull/13020) |
| 80 | +* Security - Bump axios to 1.20.0: [#13056](https://github.com/owncloud/ocis/pull/13056) |
| 81 | +* Bugfix - Keep shares visible in sharedWithMe when a resource cannot be statted: [#12430](https://github.com/owncloud/ocis/pull/12430) |
| 82 | +* Bugfix - Release the quota of upload sessions with unreadable node metadata: [#12739](https://github.com/owncloud/ocis/pull/12739) |
| 83 | +* Bugfix - Remove the unmarshalable request body field from graph log messages: [#12918](https://github.com/owncloud/ocis/pull/12918) |
| 84 | +* Bugfix - Correct introduction version for OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL: [#12949](https://github.com/owncloud/ocis/pull/12949) |
| 85 | +* Bugfix - Return a retryable 503 when the OIDC userinfo call fails transiently: [#13047](https://github.com/owncloud/ocis/pull/13047) |
| 86 | +* Change - Replace GRPC_MAX_CONNECTION_AGE with client keepalive: [#13020](https://github.com/owncloud/ocis/pull/13020) |
| 87 | +* Enhancement - Add TLS support for the frontend stat cache store connection: [#12777](https://github.com/owncloud/ocis/pull/12777) |
| 88 | +* Enhancement - Make the public share expiry janitor configurable: [#13020](https://github.com/owncloud/ocis/pull/13020) |
| 89 | +* Enhancement - The public link resolution flag added to PROPFIND: [#13020](https://github.com/owncloud/ocis/pull/13020) |
| 90 | + |
| 91 | +## Details |
| 92 | + |
| 93 | +* Security - Bump grpc-go dependency: [#13020](https://github.com/owncloud/ocis/pull/13020) |
| 94 | + |
| 95 | + We've updated the google.golang.org/grpc dependency to fix a reported |
| 96 | + denial-of-service vulnerability related to gRPC server handling of requests |
| 97 | + missing authority or Host headers. As no tagged release containing the fix was |
| 98 | + available yet, we pulled in a pre-release snapshot of grpc-go that includes it, |
| 99 | + which also required bumping the minimum Go version to 1.26.8. |
| 100 | + |
| 101 | + https://github.com/owncloud/ocis/pull/13020 |
| 102 | + |
| 103 | +* Security - Bump axios to 1.20.0: [#13056](https://github.com/owncloud/ocis/pull/13056) |
| 104 | + |
| 105 | + We've updated the axios dependency of the idp service to 1.20.0. This fixes |
| 106 | + several denial-of-service, request-smuggling and server-side request forgery |
| 107 | + vulnerabilities flagged by the release filesystem scan. |
| 108 | + |
| 109 | + https://github.com/owncloud/ocis/pull/13056 |
| 110 | + |
| 111 | +* Bugfix - Keep shares visible in sharedWithMe when a resource cannot be statted: [#12430](https://github.com/owncloud/ocis/pull/12430) |
| 112 | + |
| 113 | + The graph `sharedWithMe` handler resolves each received share by fanning out a |
| 114 | + per-resource `Stat` call with a concurrency limit, all sharing the request |
| 115 | + context. When a `Stat` failed for any reason (slow or stuck downstream, deleted |
| 116 | + space, gateway error, deadline exceeded) the worker logged at debug and returned |
| 117 | + without emitting a drive item, so the share was silently omitted from the |
| 118 | + response and the handler still returned `200 OK` with a partial, |
| 119 | + non-deterministic list. A single chronically-slow share could therefore make |
| 120 | + other, recently-accepted shares intermittently invisible, and repeated calls |
| 121 | + returned different subsets of the user's shares. |
| 122 | + |
| 123 | + The handler now: |
| 124 | + |
| 125 | + - bounds each per-share `Stat` with its own timeout derived from the request |
| 126 | + context, so one slow resource can no longer consume the deadline shared by all |
| 127 | + the other shares. The bound is configurable via |
| 128 | + `GRAPH_RECEIVED_SHARES_STAT_TIMEOUT` (default `10s`); - returns a degraded drive |
| 129 | + item built from the data already present in the share record (ids, permissions, |
| 130 | + grantees, timestamps, mountpoint name) when the resource cannot be statted due |
| 131 | + to a transient or indeterminate failure (timeout, slow or unavailable |
| 132 | + downstream), so the share stays visible instead of intermittently disappearing. |
| 133 | + A genuinely missing resource or revoked access (for example after the sharer was |
| 134 | + deleted) still drops the share, as before; - logs the dropped/degraded shares at |
| 135 | + warning level with a per-request count for operator visibility. |
| 136 | + |
| 137 | + https://github.com/owncloud/ocis/pull/12430 |
| 138 | + |
| 139 | +* Bugfix - Release the quota of upload sessions with unreadable node metadata: [#12739](https://github.com/owncloud/ocis/pull/12739) |
| 140 | + |
| 141 | + When an upload's target node lost its metadata, e.g. because an ancestor was |
| 142 | + moved to the trash while the upload was still in flight, the upload could never |
| 143 | + finish processing. It stayed in "Processing" forever, could not be downloaded or |
| 144 | + deleted, and kept consuming the space quota. |
| 145 | + |
| 146 | + Cleaning such a session up with `ocis storage-users uploads sessions --clean` |
| 147 | + did not help either: it removed the uploaded bytes and the session info file |
| 148 | + before failing to revert the node, so it destroyed the only copy of the data |
| 149 | + without releasing any quota. |
| 150 | + |
| 151 | + Cleanup now reverts the node before removing anything irreversible and falls |
| 152 | + back to the session metadata when the node cannot be read, so the quota is |
| 153 | + released and the orphaned node is removed. If the quota cannot be released the |
| 154 | + upload is kept so it can be retried instead of being lost. |
| 155 | + |
| 156 | + A new `--orphaned` filter lists the affected sessions: |
| 157 | + |
| 158 | + ``` |
| 159 | + ocis storage-users uploads sessions --orphaned |
| 160 | + ocis storage-users uploads sessions --orphaned --clean |
| 161 | + ``` |
| 162 | + |
| 163 | + Note that evaluating the filter reads the node metadata of every session, so it |
| 164 | + is only done when the flag is set. |
| 165 | + |
| 166 | + https://github.com/owncloud/ocis/pull/12739 |
| 167 | + |
| 168 | +* Bugfix - Remove the unmarshalable request body field from graph log messages: [#12918](https://github.com/owncloud/ocis/pull/12918) |
| 169 | + |
| 170 | + We've removed the `body` field from the log messages of the graph service's HTTP |
| 171 | + handlers. The field was set from `http.Request.Body`, an `io.ReadCloser`, which |
| 172 | + can never be serialized into a useful log value. |
| 173 | + |
| 174 | + The tracing middleware replaces the request body with a wrapper that carries an |
| 175 | + exported function field, so serializing it failed outright and the log line was |
| 176 | + emitted with `"body": "marshaling error: json: unsupported type: func(int64)"` |
| 177 | + instead of the payload. Without the tracing middleware the field serialized to |
| 178 | + an empty object. In both cases the intended payload was never logged. |
| 179 | + |
| 180 | + https://github.com/owncloud/ocis/pull/12918 |
| 181 | + |
| 182 | +* Bugfix - Correct introduction version for OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL: [#12949](https://github.com/owncloud/ocis/pull/12949) |
| 183 | + |
| 184 | + We changed the documented introduction version of the |
| 185 | + OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL from 8.0.0 to 8.3.0. |
| 186 | + |
| 187 | + https://github.com/owncloud/ocis/pull/12949 |
| 188 | + |
| 189 | +* Bugfix - Return a retryable 503 when the OIDC userinfo call fails transiently: [#13047](https://github.com/owncloud/ocis/pull/13047) |
| 190 | + |
| 191 | + A transient failure of the OIDC userinfo call (a timeout, a network error or a |
| 192 | + 5xx/429 from the IdP) was mapped to HTTP 401. Clients read the 401 as an invalid |
| 193 | + session and logged the user out on a brief IdP slowdown. |
| 194 | + |
| 195 | + The proxy now distinguishes a transient IdP failure from an authentication |
| 196 | + failure and returns a retryable 503 (with Retry-After) for the former, so |
| 197 | + clients retry and keep their session. A genuinely invalid or expired token still |
| 198 | + returns 401. |
| 199 | + |
| 200 | + https://github.com/owncloud/ocis/pull/13047 |
| 201 | + |
| 202 | +* Change - Replace GRPC_MAX_CONNECTION_AGE with client keepalive: [#13020](https://github.com/owncloud/ocis/pull/13020) |
| 203 | + |
| 204 | + The grpc clients now send a keepalive ping while a request is in flight and fail |
| 205 | + the requests on a connection whose peer stops answering, instead of waiting for |
| 206 | + as long as the caller allows. This covers both the reva CS3 clients (gateway, |
| 207 | + storage-users, storage-shares, ...) and the go-micro based clients used for |
| 208 | + inter-service calls between the other oCIS services. Set |
| 209 | + GRPC_CLIENT_KEEPALIVE_TIME and GRPC_CLIENT_KEEPALIVE_TIMEOUT to enable and tune |
| 210 | + this; leave them unset to keep grpc's own default (no pings). |
| 211 | + |
| 212 | + GRPC_MAX_CONNECTION_AGE has been removed. It only closed healthy connections on |
| 213 | + a timer, never ended a request that was already in flight, and silently did |
| 214 | + nothing when its value had no unit suffix. |
| 215 | + |
| 216 | + https://github.com/owncloud/ocis/pull/13020 |
| 217 | + |
| 218 | +* Enhancement - Add TLS support for the frontend stat cache store connection: [#12777](https://github.com/owncloud/ocis/pull/12777) |
| 219 | + |
| 220 | + The frontend service was the only remaining place where a `nats-js-kv` store |
| 221 | + connection could not be secured. Its OCS stat cache forwarded the store type, |
| 222 | + nodes, database, table, TTL and credentials to reva, but not the TLS settings, |
| 223 | + so the connection stayed plaintext with no operator toggle to change it. The |
| 224 | + stat cache now honours `OCIS_CACHE_ENABLE_TLS`, `OCIS_CACHE_TLS_INSECURE` and |
| 225 | + `OCIS_CACHE_TLS_ROOT_CA_CERTIFICATE` like every other cache and store. |
| 226 | + |
| 227 | + https://github.com/owncloud/ocis/pull/12777 |
| 228 | + |
| 229 | +* Enhancement - Make the public share expiry janitor configurable: [#13020](https://github.com/owncloud/ocis/pull/13020) |
| 230 | + |
| 231 | + The sharing service runs a background janitor that permanently deletes expired |
| 232 | + public shares. Whether that cleanup runs at all could previously only be set in |
| 233 | + the sharing service's yaml config, and how often it ran was fixed internally |
| 234 | + with no way to tune it. |
| 235 | + |
| 236 | + Both settings are now exposed as environment variables: |
| 237 | + OCIS_SHARING_ENABLE_EXPIRED_SHARES_CLEANUP toggles the cleanup (default: |
| 238 | + enabled, expired shares stay hidden from listings even when disabled), and the |
| 239 | + new OCIS_SHARING_JANITOR_RUN_INTERVAL sets the interval in seconds between |
| 240 | + janitor runs (default: 3600). |
| 241 | + |
| 242 | + https://github.com/owncloud/ocis/pull/13020 |
| 243 | + |
| 244 | +* Enhancement - The public link resolution flag added to PROPFIND: [#13020](https://github.com/owncloud/ocis/pull/13020) |
| 245 | + |
| 246 | + The public link resolution flag and the context timeout added to PROPFIND |
| 247 | + request The ocdav PROPFIND handler resolves public link shares to populate the |
| 248 | + oc:share-type property. A new toggle for skipping that lookup. The toggle is now |
| 249 | + exposed as OCDAV_DISABLE_PROPFIND_PUBLIC_LINK_RESOLUTION, which can be set to |
| 250 | + reduce load on services for large collections. Also, the bounded context was |
| 251 | + added for least public share request. Since this property is needed only to |
| 252 | + display an icon next to files in the list, indicating that a public link exists, |
| 253 | + it can be omitted if the ListPublicShares request is slow. |
| 254 | + |
| 255 | + https://github.com/owncloud/ocis/pull/13020 |
| 256 | + |
70 | 257 | # Changelog for [8.0.8] (2026-08-20) |
71 | 258 |
|
72 | 259 | The following sections list the changes for 8.0.8. |
|
0 commit comments