What vitessio/vitess shipped
Written by FoxPlug from public releases; not affiliated with Vitess. An automatic summary of the public release, pull request and commit data of github.com/vitessio/vitess. Vitess did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- EmergencyReparentShard no longer counts divergent tablets as semi-sync ackers, fixing promotion candidate validation. Pull request #21188
- SHOW VARIABLES and SHOW GLOBAL VARIABLES in shard-targeted sessions now return correct VTGate-owned system variable values. Pull request #21185
- VTTablet now resets
foreign_key_checksandunique_checksto global values instead of opposite values after SET SESSION DEFAULT. Pull request #21167 - VTTablet table ACL checks now cover reads embedded in CREATE TABLE AS SELECT, EXPLAIN ANALYZE, SHOW WHERE, and SET statements. Pull request #21139
- VTTablet discards pooled connections after CALL statements to prevent stored procedure session state leaks. Pull request #21062
- smartconnpool rechecks capacity after CAS to prevent connection leaks when capacity is lowered concurrently. Pull request #21190
- VTAdmin now sends non-empty :authority header so gRPC calls work behind proxies that validate HTTP/2 headers. Pull request #21191
- VDiff fixes PK column ordering and index mapping in getSourcePKCols to correctly handle source table primary keys. Pull request #20603
- VTTablet and VTGate now reject server-side CRL configuration when TLS certificate and key flags are not set. Pull request #21153
- sqlparser fixes panic when WITH clause is immediately followed by a parenthesized query. Pull request #21125
Why it matters
This week includes fixes for reparenting safety, system variable handling correctness, security in stored procedures, and table ACL enforcement. Connection pooling and gRPC proxy compatibility improvements address reliability issues. These changes strengthen operational correctness and security across core Vitess components.
Changelog entry
- EmergencyReparentShard: stop counting divergent tablets as semi-sync ackers Pull request #21188
- vtgate: fix SHOW VARIABLES in shard-targeted sessions and SHOW GLOBAL VARIABLES Pull request #21185
- vttablet: reset
foreign_key_checksandunique_checkssettings to the global value Pull request #21167 - VTTablet: check the reads embedded in CREATE TABLE AS SELECT, EXPLAIN ANALYZE, SHOW WHERE and SET under table ACL Pull request #21139
- VTTablet: Discard the pooled connection after CALL so procedure session state cannot leak Pull request #21062
- smartconnpool: re-check capacity after getNew's CAS Pull request #21190
- vtadmin: send a non-empty :authority so gRPC works behind a proxy Pull request #21191
- fix(vdiff): map source PK columns to their SELECT positions in getSourcePKCols Pull request #20603
- vttls: Refuse a server-side CRL when the server is not configured for TLS Pull request #21153
- sqlparser: fix panic on WITH followed by parenthesized query Pull request #21125
Vitess ships fixes for reparenting validation, system variables in sessions, stored procedure state isolation, table ACL coverage, connection pooling safety, and gRPC proxy compatibility.
This week's Vitess releases address critical operational and security improvements: EmergencyReparentShard now correctly validates promotion candidates, session variables return accurate values, stored procedures can no longer leak state, table ACLs cover more statement types, and connection pooling handles concurrent capacity changes safely. VTAdmin also now works reliably behind proxies.
Week of September 14, 2026
What shipped
- VTTablet now fails closed under strict table ACL when a statement's table set cannot be determined, fixing a security gap where DO, CALL, REPAIR, OPTIMIZE and LOAD DATA statements bypassed ACL checks. Pull request #21053
- VTTablet table ACL now derives permissions the same way MySQL resolves CTE names, fixing a security issue where common table expressions could be used to bypass access controls. Pull request #21091
- VTTls now enforces certificate revocation lists in all SSL modes and on resumed TLS sessions, preventing revoked certificates from reconnecting. Pull request #21054
- VTTablet fixed a data race in transaction timeout handling that was causing all
e2e_racetest failures. Pull request #21024 - VTAdmin fixed a crash in the tablet info dialog and resolved multiple type errors from dependency API changes in react-query, react-router and headlessui. Pull request #21131
- CI replaced MinIO server with MicroCeph RGW for S3 backup tests after MinIO archived its community releases. Pull request #21086
- CI bumped Apache ZooKeeper to 3.9.6 since 3.9.5 is no longer available on the distribution site. Pull request #21099
- Removed a write-only timestamp field from LRUCache entries that had not been read since 2021. Pull request #21080
- VTAdmin declared children and JSX types that React 19 removed from its type definitions. Pull request #21130
- VTAdmin fixed project configuration errors that prevented TypeScript type checking from running. Pull request #21129
Why it matters
This week addresses three security vulnerabilities in table ACL enforcement and TLS certificate validation, plus a data race causing test failures. Infrastructure updates keep CI working as upstream projects archive old releases, and frontend improvements prepare VTAdmin for current tooling versions.
Changelog entry
- VTTablet: fail closed under strict table ACL when a statement's table set cannot be determined Pull request #21053
- VTTablet: derive table ACL permissions the way MySQL resolves CTE names Pull request #21091
- VTTls: Enforce CRLs in every SSL mode and on resumed TLS sessions Pull request #21054
- VTTablet: fix data race in transaction timeout publishing Pull request #21024
- VTAdmin: fix tablet info dialog crash and type errors from dependency API changes Pull request #21131
- CI: Replace MinIO server with MicroCeph RGW for S3 backup tests Pull request #21086
- CI: bump Apache ZooKeeper to 3.9.6 Pull request #21099
- Cache: remove unused timestamp field from LRUCache entries Pull request #21080
Shipped: table ACL and TLS security fixes, resolved e2e_race test failures, updated CI infrastructure for current ZooKeeper and S3 services.
This week's releases include important security fixes: VTTablet now properly enforces table ACL for all statement types, CTE name resolution matches MySQL behavior, and TLS certificate revocation checks work across all SSL modes and resumed sessions. We also fixed a data race in transaction timeouts and updated CI infrastructure as upstream projects archive releases.