Apache Pulsar 5.0.0
2026-10-05
Milestone release notes
The 5.0.0 release also includes the changes from these milestone releases:
Approved PIPs
- [improve][pip] PIP-441: Add Broker-Level Metrics for Skipped Non-Recoverable Data (#24716)
- [improve][pip] PIP-494: Scalable Topics Client Specification — authoritative reference and change process (#26447)
- [improve][pip] PIP-496: Pulsar Functions and IO support for the V5 client and scalable topics (#26698)
Library updates
- [improve][broker] Upgrade bookkeeper to 4.18.1 (#26574)
- [fix][sec] Upgrade Async HTTP Client to 3.0.14 and Netty Reactive Streams to 2.0.20 (#26764)
- [fix][sec] Upgrade at.yawk.lz4:lz4-java to 1.11.4 (#26758)
- [fix][sec] Upgrade zstd-jni to 1.5.7-20 (#26766)
- [fix][build] Upgrade Conscrypt to 2.6.3 (#26660)
- [fix][build] Upgrade LightProto to 0.8.2 (#26623)
- [improve][zk] Upgrade ZooKeeper to 3.9.6 (#26750)
- [improve][build] Upgrade Bouncy Castle libraries (#26753)
- [improve][build] Upgrade Caffeine to 3.3.0 (#26755)
- [improve][build] Upgrade Gradle to 9.8.0 and update plugins (#26752)
- [improve][build] Upgrade gRPC to 1.84.0 (#26762)
- [improve][build] Upgrade Guava to 33.7.1-jre (#26760)
- [improve][build] Upgrade Jackson to 2.21.7 (#26754)
- [improve][build] Upgrade OpenTelemetry libraries to 1.66.0 level (#26756)
- [improve][build] Upgrade Protobuf to 4.36.2 (#26757)
- [improve][build] Upgrade SnakeYAML to 2.7 (#26761)
- [improve][misc] Upgrade Jetty to 12.1.13 (#26738)
Broker
- [fix][broker] Align entry filter policy checks for non-persistent topics (#26774)
- [fix][broker] Align partitioned topic truncate checks with non-partitioned topics (#26776)
- [fix][broker] Apply managedLedgerContinueCachingAddedEntriesAfterLastActiveCursorLeavesMillis to managed ledgers (#26785)
- [fix][broker] Apply subscription policies to namespace and topic subscription operations (#26767)
- [fix][broker] Apply the role logging anonymizer to topic authorization denial logs (#26642)
- [fix][broker] Avoid misleading ownership lock expiry logs during shutdown (#26633)
- [fix][broker] Bound classic Key_Shared dispatcher replay queue look-ahead (#26677)
- [fix][broker] Bound the local partition metadata retry when starting a geo-replicator (#26681)
- [fix][broker] Check the original principal of proxied HTTP requests with its own authentication data (#26748)
- [fix][broker] Check topic permissions for binary GetSchema and GetOrCreateSchema (#26643)
- [fix][broker] Check topic permissions for partitions and subscriptions added to a transaction (#26644)
- [fix][broker] Decode topic name in the scalable topic migrate endpoint (#26711)
- [fix][broker] Derive scalable topic identity from the raw local name (#26668)
- [fix][broker] Do not enable replicated subscriptions on scalable topic segments (#26679)
- [fix][broker] Do not start classic geo-replicators on scalable-topic segment topics (#26691)
- [fix][broker] Fix lookup permit leak when namespace policy reads fail (#26606)
- [fix][broker] Keep accepting Avro named type references written as objects (#26586)
- [fix][broker] Log only non-default settings at broker startup (#26612)
- [fix][broker] Preserve compaction state on ledger close failure (#26665)
- [fix][broker] Preserve replicated subscription activity on activation (#26780)
- [fix][broker] Preserve topic initialization failures (#26775)
- [fix][broker] Prevent slow Key_Shared sockets from stalling other consumers (#26635)
- [fix][broker] Propagate bundle split failures to the completion future (#26735)
- [fix][broker] Read the producer name of GetOrCreateSchema before authorization completes (#26770)
- [fix][broker] Release the compaction buffers and permits on flush failures (#26576)
- [fix][broker] Spurious ERROR log for 307 redirect in getReplicatedSubscriptionStatus (#26706)
- [fix][admin] Restore Pulsar 4.x compatible serialVersionUID for PackageMetadata (#26784)
- [fix][ml] Close abandoned write ledger handle to prevent leak (#26585)
- [fix][ml] Fail in-flight adds when a managed ledger is terminated (#26678)
- [fix][ml] Fail queued adds when a managed ledger is terminated during a ledger rollover (#26680)
- [fix][ml] Fix active cursor position tracking after untracking (#26629)
- [fix][ml] Fix backlog estimation during ledger rollover with pending writes (#26647)
- [fix][ml] Propagate cursor ledger deletion failures (#26734)
- [fix][ml] Reset the lazily-cached position when reusing a recycled EntryImpl (#26707)
- [fix][ml][broker] Keep source ledger data on every shadow managed ledger trim, delete and offload path (#26746)
- [fix][meta] Close resources when ZKMetadataStore construction fails (#26673)
- [fix][meta] Track explicitly acquired underreplicated ledger locks (#26670)
- [improve][broker] Add configuration to enable shadow topics (#26739)
- [improve][broker] Add metrics for message position find by timestamp (#26751)
- [improve][broker] Allow disabling scalable topics when upgrading to 5.x (#26740)
- [improve][broker] Allow dynamically updating topic load timeout (#26781)
- [improve][broker] Avoid read locks in Key_Shared consumer selection (#26591)
- [improve][broker] Avoid redundant read-completion executor handoffs for Exclusive/Failover (#26619)
- [improve][broker] Avoid the topic-wide deduplication lock (#26763)
- [improve][broker] Change the default number of namespace bundles to 32 and make the system namespace bundle count configurable (#26610)
- [improve][broker] Disable subscription-thread dispatch by default (#26578)
- [improve][broker] Make AvgShedder the default load shedding and placement strategy (#26609)
- [improve][broker] Optimize consumer selection for shared subscriptions (#26593)
- [improve][broker] PIP-379: Remove the classic Shared and Key_Shared dispatcher implementations (#26687)
- [improve][broker] Raise the default dispatcherMaxReadBatchSize from 100 to 500 (#26744)
- [improve][broker] Reduce cache retention after reads and apply retention settings at startup (#26627)
- [improve][broker] Resume Shared dispatch when consumer channels become writable (#26630)
- [improve][broker] Skip unused replicated subscription timestamp updates (#26655)
- [improve][broker] Speed up auto-split Key_Shared consumer selection (#26654)
- [improve][broker] Store deferred acknowledgment completion state in arrays (#26592)
- [improve][broker] trace topic loading latency and timeout states (#26666)
- [improve][broker] Use separate IO threads for BookKeeper Client (#25812)
- [improve][admin] Redesign scalable topic stats and add per-segment stats (#26639)
- [fix][txn] Improve transaction admin checks (#26773)
- [fix][txn] Prevent queued snapshot writes from stalling (#26565)
- [fix][txn] Stop the pending ack replay loop from spinning forever (#26369)
- [improve][ml] Allow inline read completion and preserve replication order (#26620)
- [improve][ml] Batch managed-ledger adds across the thread boundary to the ledger executor (#26717)
- [improve][ml] Complete a read at the last confirmed entry instead of extending it on the ledger executor (#26743)
- [improve][ml] Defer cached message metadata parsing until first read (#26628)
- [improve][ml] Open ledgers through the BookKeeper builder API (#26598)
- [improve][ml] Pin ledger callbacks to the managed ledger thread with withOrderingKey (#26599)
- [improve][ml] Reduce tiered storage reads of the search by timestamp in offloaded ledgers (#26778)
- [improve][ml] Use adaptive allocation for managed ledger cache copies (#26603)
- [improve][offload] Resume offloaded reads from offsets learned in the same data block (#26782)
- [improve][txn] Move TransactionCoordinatorClient to public API (#26646)
- [feat][broker] PIP-441:Add broker-level metrics for non-recoverable data skips (#24726)
- [feat][ml] Configure and track named Pulsar allocators independently (#26597)
- [feat][ml] Support Bookkeeper Batch Read API (#25280)
- [fix][broker] Preserve standalone bookie identities across upgrades (#26790)
Client
- [fix][client] Apply V5 connection backoff initial and max intervals (#26799)
- [fix][client] Complete a v5 send in place while its client is closing (#26686)
- [fix][client] Complete table view refresh after applying messages (#26566)
- [fix][client] Don't close a shared DNS resolver group's address resolver when a client closes (#26723)
- [fix][client] Drop a send receipt for a removed producer, not the connection (#26618)
- [fix][client] Enable TableView compacted reads for short topic names (#26626)
- [fix][client] Fix buffer ownership on the send failure paths (#26455)
- [fix][client] Flush acknowledgment groups at the combined size limit (#26594)
- [fix][client] Keep a gone segment's producer until the layout drops it (#26617)
- [fix][client] Prevent duplicate cleanup and leaks on producer send failures (#26641)
- [fix][client] Release connections opened after close (#26733)
- [fix][client] Stop DAG watch reconnects on a closing client and quiet perf-tool Ctrl-C shutdown (#26613)
- [improve][client] Coalesce message listener drain scheduling (#26531)
- [improve][client] Log V5 segment-gone send retries at DEBUG (#26615)
- [improve][client] Pull v5 blocking receives straight from the receive buffer (#26614)
- [improve][client] Reduce V5 queue receive completion stages (#26596)
- [improve][client] Skip redundant per-segment cumulative acks in the v5 stream consumer (#26616)
- [feat][client] PIP-445: Add Builder Methods to Create Message-based TableView (#24809)
Pulsar IO and Pulsar Functions
- [fix][fn] Apply the worker connectors list checks to the deprecated functions connectors endpoint (#26745)
- [fix][fn] Check packages permission for function, source and sink package URLs (#26771)
- [fix][fn] Check produce permission on the input topic when triggering functions (#26777)
- [fix][fn] Remove deprecated github.com/golang/protobuf dependency from pulsar-function-go (#26587)
- [fix][fn] Validate package name components and storage paths consistently (#26768)
- [feat][fn] PIP-496: Support the V5 client and topic:// topics in Pulsar Functions and IO (#26697)
Others
- [fix][ws] Check dead letter topic permission for WebSocket consumers (#26772)
- [fix][cli] Avoid inheriting broker initial heap settings in tools (#26736)
- [fix][cli] Correct admin command documentation generation (#26649)
- [improve][cli] Pick the v4 or V5 client from the topic domain in pulsar-perf and pulsar-client (#26693)
- [improve][misc] Disable Netty leak detection by default in bin/pulsar, pulsar-perf and the CLI tools (#26783)
- [improve][misc] Reduce executor queue allocation with growable arrays (#26588)
- [improve][misc] Trim executor queues using a shared capacity budget (#26589)
- [improve][misc] Use compact object headers on JDK 25 and 26 (#26719)
- [improve][misc] Use Netty's adaptive allocator for Pulsar's default allocator (#26720)
- [fix][Client] permit leak in chunked message discard path (#26661)
- [feat][misc] Support AdaptiveByteBufAllocator with configurable allocator type and metrics (#26595)
- [doc][spec] PIP-494: Scalable Topics client specification (#26805)
- [fix] Fix cursor deadlock when skipping non-recoverable entries during mark-delete persistence (#26570)
- [improve] Preload mimalloc in the Alpine-based Pulsar image (#26791)
Tests & CI
- [fix][build] Restore test JAR publications in Gradle (#26622)
- [fix][ci] Ensure disk headroom for replication tests (#26559)
- [fix][ci] Skip pull request title check outside apache/pulsar (#26645)
- [fix][ci] Update GraalVM setup action to ASF-approved version (#26571)
- [fix][test] Allow for CLI startup in function integration tests (#26564)
- [fix][test] Avoid blocking common-pool workers in ledger shutdown test (#26560)
- [fix][test] Avoid unsafe cleanup between shared-cluster tests (#26611)
- [fix][test] Await both DLQ producers in multi-consumer test (#26561)
- [fix][test] Cover scheduler shutdown membership-lock deadlock (#26557)
- [fix][test] Disable Pulsar message parsing for raw ledger test entries (#26604)
- [fix][test] Fix flaky LatencyTracerTest.testTraceFuture (#26741)
- [fix][test] Fix flaky ManagedLedgerBkTest.verifyConcurrentUsage (#26637)
- [fix][test] Fix flaky NonDurableCursorTest.subscribeToEarliestPositionWithDeferredDeletion (#26747)
- [fix][test] Fix flaky OneWayReplicatorDeduplicationTest.testDeduplication (#26737)
- [fix][test] Fix flaky RawReaderTest.testPauseAndResumeWithUnloading (#26690)
- [fix][test] Fix flaky V5CumulativeAckTest.testRetryingAnAckThatFailedWhileDisconnectedAdvancesTheCursor (#26789)
- [fix][test] Fix flaky V5ProducerBackpressureTest.retriesAcrossASegmentSplitKeepTheAccountingBalanced (#26792)
- [fix][test] Fix scalable topic stats access in v5 tests (#26650)
- [fix][test] Isolate mutable broker fixtures between test methods (#26563)
- [fix][test] Isolate token CLI test output from background logging (#26657)
- [fix][test] Make TopicOwnerTest bundle assignments deterministic (#26624)
- [fix][test] Preserve class loading in broker interceptor fixtures (#26567)
- [fix][test] Restore NETTY_LEAK_DETECTION for Gradle and CI tests (#26605)
- [fix][test] Wait for the ack to be persisted before rewinding in V5StreamConsumerAckWatermarkTest (#26684)
- [improve][build] Add validated API/SPI publication subset (#26579)
- [improve][build] Bump the version to 5.0.0-SNAPSHOT (#26580)
- [improve][build] Require Java 21 for servers while preserving Java 17 client compatibility (#26769)
- [improve][build] Resolve the integration-test commit id lazily to keep the configuration cache reusable (#26638)
- [improve][ci] Check ASF action allowlist in preconditions (#26572)
- [improve][ci] Configure SSH access action default and update Upterm (#26575)
- [improve][ci] Enable the "Update branch" button on pull requests via .asf.yaml (#26573)
- [improve][ci] Pin latest Develocity and Common Custom User Data plugin versions (#26608)
- [improve][ci] Support smaller runners and restricted fork environments (#26558)
- [improve][test] Add disk-limit options and A/B comparison charts to the Pulsar Performance Testing Framework (#26800)
- [improve][test] Add host and per-container CPU and perf counter sampling, default bookie cache sizes and bottleneck analysis guidance to the performance tests (#26749)
- [improve][test] Add IoT telemetry performance scenario (#26653)
- [improve][test] Add YAML scenarios to profiling harness (#26600)
- [improve][test] Improve performance experiments, analysis tooling and agent guidance (#26715)
- [improve][test] Record Netty's allocator events and other JFR settings per profiled component, and profile on Alpine (#26787)
- [improve][test] Reduce overlapping TestNG fixtures (#26562)
- [improve][test] Separate IoT warmup from performance measurements (#26667)
- [improve][test] Strengthen auto-split selector concurrency test (#26779)
- [improve][test] Support isolated v4 perf clients (#26601)
- [feat][test] Add a Docker-based performance testing framework with profiling, metrics and AI agent support (#26714)
For the complete list, check the full changelog.