Apache Pulsar 4.0.14
2026-10-05
Library updates
- [improve][broker][branch-4.2] Upgrade bookkeeper to 4.17.4 (#26219)
- [fix][sec] Bump google.golang.org/grpc from 1.79.3 to 1.82.1 in /pulsar-function-go/examples (#26231)
- [fix][sec] Bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /pulsar-function-go (#26446)
- [fix][sec] Bump google.golang.org/grpc from 1.83.1 to 1.83.2 in /pulsar-function-go (#26541)
- [fix][sec] Bump log4j2 from 2.26.0 to 2.26.1 (#26329)
- [fix][sec] Upgrade at.yawk.lz4:lz4-java to 1.11.4 (#26758)
- [fix][sec] Upgrade grpc in pulsar-function-go to 1.82.1 to fix GHSA-hrxh-6v49-42gf (#26235)
- [fix][sec] Upgrade Jackson to 2.18.10 (#26339)
- [fix][sec] Upgrade lz4-java to 1.11.1 to address CVE-2026-59949 (#26250)
- [fix][sec][branch-4.2] Upgrade BouncyCastle to 1.85 and BouncyCastle FIPS to 2.0.2 to address CVEs (#26370)
- [fix][sec][branch-4.2] Upgrade Netty to 4.1.137 to address several CVEs and bugs (#26301)
- [fix][sec][branch-4.2] Upgrade Spring to 7.0.8 (#26270)
- [fix][sec][branch-4.x] Upgrade async-http-client to 2.16.1 (#26436)
- [fix][sec][branch-4.x] Upgrade lz4-java to 1.11.2 (#26439)
- [fix][sec][branch-4.x] Upgrade Netty to 4.1.138 to address several CVEs and bugs (#26515)
- [fix][sec][branch-4.x] Upgrade Thrift to 0.24.0 (#26438)
- [fix][sec][branch-4.x] Upgrade vertx to 4.5.32 (#26437)
- [fix][build] Upgrade Conscrypt to 2.6.3 (#26660)
- [improve][zk] Upgrade ZooKeeper to 3.9.6 (#26750)
- [improve][build] Upgrade Apache Commons libraries (#26348)
- [improve][build] Upgrade Bouncy Castle libraries (#26753)
- [improve][build] Upgrade Oxia Java client to 0.9.5 (#26538)
- [improve][misc] Upgrade Conscrypt to 2.6.1 to add aarch64 native support (#26314)
- [improve][misc] Upgrade Conscrypt to 2.6.2 to restore the native library glibc baseline (#26315)
- [improve][misc] Upgrade Jetty to 12.1.12 (#26302)
- [improve][misc] Upgrade Jetty to 12.1.13 (#26738)
- [improve][misc] Upgrade log4j to 2.26.0 and slf4j to 2.0.18 (#25973)
- [improve][misc][branch-4.x] Upgrade Jackson to 2.18.11 (#26759)
Broker
- [fix][broker] Add missing bundle Prometheus metrics for extensible load manager (#26192)
- [fix][broker] Align entry filter policy checks for non-persistent topics (#26774)
- [fix][broker] Align partitioned topic truncate checks with non-partitioned topics (#26776)
- [fix][broker] Apply subscription policies to namespace and topic subscription operations (#26767)
- [fix][broker] Avoid load shedding and metadata writes from a former leader (#26253)
- [fix][broker] Avoid misleading ownership lock expiry logs during shutdown (#26633)
- [fix][broker] Bound classic Key_Shared dispatcher replay queue look-ahead (#26677)
- [fix][broker] Bound the topic deletion retries triggered by a replication cluster removal (#26432)
- [fix][broker] Cancel queued transaction snapshot recovery on topic close (#26335)
- [fix][broker] Check the original principal of proxied HTTP requests with its own authentication data (#26748)
- [fix][broker] Check topic permissions for binary GetSchema and GetOrCreateSchema (#26643)
- [fix][broker] Check topic permissions for partitions and subscriptions added to a transaction (#26644)
- [fix][broker] Debit un-acked messages only when the consumer is actually removed (#26422)
- [fix][broker] Do not log an error when the tenant does not exist (#26361)
- [fix][broker] Don't serve topic policies from a cache whose init future has not completed (#26513)
- [fix][broker] Fix assignment and ownership cleanup races in the extensible load manager (#26520)
- [fix][broker] Fix AvgShedder assignment cache keying with stable bundle names (#26246)
- [fix][broker] Fix delayed-delivery bucket merge failures when delayedDeliveryMaxNumBuckets is 1-3 (#26242)
- [fix][broker] Fix dispatcherPauseOnAckStatePersistentEnabled and schemaValidationEnforced returning wrong values when applied=true (#26472)
- [fix][broker] Fix early completion and false timeouts in SplitManager and UnloadManager (#26363)
- [fix][broker] Fix lookup permit leak when namespace policy reads fail (#26606)
- [fix][broker] Fix multi-role authorization regressions and optimize nested checks (#26551)
- [fix][broker] Fix NPE in ManagedLedgerInterceptorImpl when AppendIndexMetadataInterceptor isn't configured (#26497)
- [fix][broker] Fix ownership-generation races in OwnershipCache removeOwnership and lock-expiry cleanup (#26197)
- [fix][broker] Fix persistent throughput degradation caused by permit loss during frequent reconnects on Shared subscriptions (#26289)
- [fix][broker] Log exception in PulsarMetadataEventSynchronizer failure path (#26203)
- [fix][broker] Preserve compaction state on ledger close failure (#26665)
- [fix][broker] Preserve replicated subscription activity on activation (#26780)
- [fix][broker] Preserve topic initialization failures (#26775)
- [fix][broker] Prevent automatic TTL expiry from skipping reader messages (#26505)
- [fix][broker] Prevent Key_Shared out-of-order replay starvation at the end of topic (#26268)
- [fix][broker] Prevent NPE when the last ACK races with sticky hash reassignment (#26471)
- [fix][broker] Propagate bundle split failures to the completion future (#26735)
- [fix][broker] Release the compaction buffers and permits on flush failures (#26576)
- [fix][broker] Resolve replicator remote cluster by prefix so cluster names containing a dot work (#26451)
- [fix][broker] Send ActiveConsumerChange for non-persistent Failover subscriptions (#26482)
- [fix][broker] Spurious ERROR log for 307 redirect in getReplicatedSubscriptionStatus (#26706)
- [fix][broker] Stop reporting a deliberate ownership release as an expired resource lock (#26533)
- [fix][admin] Allow defaultNumPartitions for non-partitioned autoTopicCreation override (#25163)
- [fix][admin] Avoid creating subscriptions when peeking messages if auto-creation is disabled (#26279)
- [fix][admin] Reject empty cluster migration URL: fix inverted ClusterUrl.isEmpty() (#26473)
- [fix][ml] Close abandoned write ledger handle to prevent leak (#26585)
- [fix][ml] Fail in-flight adds when a managed ledger is terminated (#26678)
- [fix][ml] Fail queued adds when a managed ledger is terminated during a ledger rollover (#26680)
- [fix][ml] Fix batch ACK index loss when recovering cursor from MetadataStore (#26474)
- [fix][ml] Preserve cursor properties when recovering from an unreadable cursor ledger (#26512)
- [fix][ml] Preserve ledger properties when closing ledger (#26227)
- [fix][ml] Preserve ledger properties when recovering the last ledger on open (#26509)
- [fix][ml] Propagate cursor ledger deletion failures (#26734)
- [fix][ml] Reset the lazily-cached position when reusing a recycled EntryImpl (#26707)
- [fix][ml] Skip contiguous deleted ranges during reads (#26299)
- [fix][ml] Tolerate concurrent creation of the managed ledger z-node (#26247)
- [fix][ml][broker] Keep source ledger data on every shadow managed ledger trim, delete and offload path (#26746)
- [fix][offload] Cache and reuse entry offsets discovered while skipping in BlobStoreBackedReadHandleImpl (#26424)
- [fix][offload] Normalize offloader cache directory path (#26372)
- [fix][meta] Close resources when ZKMetadataStore construction fails (#26673)
- [fix][meta] Track explicitly acquired underreplicated ledger locks (#26670)
- [fix][meta][branch-4.0] Tolerate concurrent creation of the underreplication LAYOUT node (#26248)
- [improve][broker] Add configuration to enable shadow topics (#26739)
- [improve][broker] Add pulsar_subscription_storage_backlog_age_seconds metric (#26313)
- [improve][broker] Allow dynamically updating topic load timeout (#26781)
- [improve][broker] Avoid iterator allocation in BrokerInterceptors hot paths and restore configured ordering (#26462)
- [improve][broker] Change partition metadata not-found log to warn (#26381)
- [improve][broker] Conflate concurrent readMoreEntries calls (#26539)
- [improve][broker] Copy small entries into a flat buffer when prepending broker entry metadata (#26464)
- [improve][broker] Disable subscription-thread dispatch by default (#26578)
- [improve][broker] Expose interface for the replicator in ManagedLedger instead of cast the class (#26298)
- [improve][broker] Make exposing topic level metric dynamic (#21006)
- [improve][broker] Skip unused replicated subscription timestamp updates (#26655)
- [improve][broker] Support OpenID multi-role authorization and improve proxy authentication defaults (#26549)
- [fix][txn] Do not fail topic deletion when the aborted txn snapshot cannot be cleared (#26431)
- [fix][txn] Fix X-Pulsar-txn-uncommitted header semantics and add X-Pulsar-txn-consumable for peek messages (#26073)
- [fix][txn] Improve transaction admin checks (#26773)
- [fix][txn] Prevent queued snapshot writes from stalling (#26565)
- [fix][txn] Stop the pending ack replay loop from spinning forever (#26369)
- [Fix][broker]Get a fenced error when loading a topic that does not allowed the cluster to access (#26276)
Client
- [fix][client] Apply no-memory-limit producer queue defaults at producer creation (#26342)
- [fix][client] Avoid exception in ConsumerImpl hasMessageAvailable before first receive (#25857)
- [fix][client] Complete table view refresh after applying messages (#26566)
- [fix][client] Defer op cmd release to the write event loop on send timeout (#26456)
- [fix][client] Divide the across-partitions budget only when it was set explicitly (#26384)
- [fix][client] Drop a send receipt for a removed producer, not the connection (#26618)
- [fix][client] Enable TableView compacted reads for short topic names (#26626)
- [fix][client] Fix buffer ownership on the send failure paths (#26455)
- [fix][client] Flush acknowledgment groups at the combined size limit (#26594)
- [fix][client] Keep transactional and non-transactional messages in separate batches (#26547)
- [fix][client] Prevent duplicate cleanup and leaks on producer send failures (#26641)
- [fix][client] Release connections opened after close (#26733)
- [fix][client] Release the command header when send serialization fails (#26492)
- [fix][client] Release the reserved memory only once when failing a send in a terminal state (#26476)
- [fix][client] Restore OAuth2 HTTP client after deserialization (#26325)
- [fix][client] Stop tracking ack timeouts on non-persistent topics (#26548)
- [improve][client] Avoid eager broker metadata allocation for outgoing messages (#26521)
- [improve][client] Avoid unused send-stat snapshots for default callbacks (#26519)
- [improve][client] Coalesce message listener drain scheduling (#26531)
- [fix][client] Remove the dead letter candidate entry using the entry-level message id
Pulsar IO and Pulsar Functions
- [fix][fn] Allow retainKeyOrdering on Go functions (#26421)
- [fix][fn] Apply the worker connectors list checks to the deprecated functions connectors endpoint (#26745)
- [fix][fn] Bound function package downloads from BookKeeper and stop SchedulerManager.close() from hanging on a stuck scheduling round (#26556)
- [fix][fn] Check packages permission for function, source and sink package URLs (#26771)
- [fix][fn] Check produce permission on the input topic when triggering functions (#26777)
- [fix][fn] Honour negativeAckRedeliveryDelayMs in the Go function runtime (#26415)
- [fix][fn] Honour negativeAckRedeliveryDelayMs in the Python function runtime (#26413)
- [fix][fn] Honour retainOrdering and retainKeyOrdering in the Go function runtime (#26414)
- [fix][fn] Remove deprecated github.com/golang/protobuf dependency from pulsar-function-go (#26587)
- [fix][fn] Return descriptive errors for unknown JSON properties (#26441)
- [fix][fn] Validate package name components and storage paths consistently (#26768)
- [improve][fn] Standardize log4j2 Root logger configuration to use system property (#26121)
Others
- [fix][ws] Check dead letter topic permission for WebSocket consumers (#26772)
- [fix][cli] Apply PULSAR_MEM and PULSAR_GC in bin/pulsar-perf (#26465)
- [fix][cli] Avoid inheriting broker initial heap settings in tools (#26736)
- [fix][cli] Correct admin command documentation generation (#26649)
- [fix][cli] pulsar-perf: register subcommand classes with picocli instead of instances (#26467)
- [fix][cli] Set --enable-native-access=ALL-UNNAMED for the CLI tools on Java 24+ (#26365)
- [fix][cli][branch-4.0] Don't pass unset pulsar-perf pending-message options to the producer (#26371)
- [fix][misc] Remove unnecessary " " suffix from log lines when there are no context attributes (#26285)
- [improve][cli] Default the pulsar-perf client memory limit to half of the JVM max direct memory (#26491)
- [improve][cli] pulsar-perf: cut latency histogram memory ~100x, fix range units and static stats state (#26466)
- [fix][Client] permit leak in chunked message discard path (#26661)
- [fix][common] Handle synchronous failures from future suppliers (#25939)
- [fix] Fix cursor deadlock when skipping non-recoverable entries during mark-delete persistence (#26570)
- [fix] Fix ManagedLedgerImpl's pendingAddEntries leak. (#25240)
Tests & CI
- [improve][ci][branch-4.0] Upgrade GitHub Actions built-in action versions
- [fix][test] Allow for CLI startup in function integration tests (#26564)
- [fix][test] Avoid blocking common-pool workers in ledger shutdown test (#26560)
- [fix][test] Await both DLQ producers in multi-consumer test (#26561)
- [fix][test] Cover scheduler shutdown membership-lock deadlock (#26557)
- [fix][test] Fix flaky AdminApiTest caused by leaked brokerShutdownTimeoutMs (#26249)
- [fix][test] Fix flaky IsolatedBookieEnsemblePlacementPolicyTest by awaiting the initial rack config load (#26429)
- [fix][test] Fix flaky NonDurableCursorTest.subscribeToEarliestPositionWithDeferredDeletion (#26747)
- [fix][test] Fix flaky OneWayReplicatorDeduplicationTest.testDeduplication (#26737)
- [fix][test] Fix flaky RawReaderTest.testPauseAndResumeWithUnloading (#26690)
- [fix][test] Fix OneWayReplicatorSchemaValidationEnforcedTest racing the replicator's remote topic creation (#26382)
- [fix][test] Isolate mutable broker fixtures between test methods (#26563)
- [fix][test] Join assignment tailer before asserting its last message ID (#26536)
- [fix][test] Make consistent hashing consumer selection test deterministic (#26534)
- [fix][test] Preserve class loading in broker interceptor fixtures (#26567)
- [improve][ci] Configure SSH access action default and update Upterm (#26575)
- [improve][ci] Run the Python function instance tests in CI (#26399)
- [fix][build][branch-4.0] Fix Java 8 compile error in backported TableViewImplTest
- [fix][ci][branch-4.0] Use an ASF-approved docker/setup-qemu-action version
- [fix][test] Fix import order in authorization test
- [fix][test][branch-4.0] Correct transaction replay marker fixture and release assertion
- [fix][test][branch-4.0] Use branch-4.0 role claim in nested authorization checks
- [fix][test][branch-4.0] Use initialized namespace in dynamic metrics configuration test
- [fix][test][branch-4.0] Use initialized namespace in extensible load manager metrics test
- [fix][test][branch-4.2] Create the CLI test producer only once CmdProduce asks for it
- [fix][test][branch-4.x] Explicitly disable memory limit when testing pending-message defaults
For the complete list, check the full changelog.