Repository navigation
Expand file tree
/
Copy path00-RELEASENOTES
More file actions
280 lines (226 loc) · 17.8 KB
/
Copy path00-RELEASENOTES
File metadata and controls
280 lines (226 loc) · 17.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
Redis Open Source 8.10 release notes
====================================
--------------------------------------------------------------------------------
Upgrade urgency levels:
LOW: No need to upgrade unless there are new features you want to use.
MODERATE: Program an upgrade of the server, but it's not urgent.
HIGH: There is a critical bug that may affect a subset of users. Upgrade!
CRITICAL: There is a critical bug affecting MOST USERS. Upgrade ASAP.
SECURITY: There are security fixes in the release.
--------------------------------------------------------------------------------
The release notes contain PRs from multiple repositories:
#n - Redis (https://github.com/redis/redis)
#Qn = Query Engine (https://github.com/RediSearch/RediSearch)
#Jn = JSON (https://github.com/RedisJSON/RedisJSON)
#Tn = Time Series (https://github.com/RedisTimeSeries/RedisTimeSeries)
#Pn = Probabilistic (https://github.com/RedisBloom/RedisBloom)
================================================================================
Redis 8.10.2 Released Thu 17 Sep 2026 18:00:00 IST
================================================================================
Update urgency: `SECURITY`: There are security fixes in the release.
### Security fixes
- #15673 Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed
- #15722 The cluster bus protocol has no authentication of its own unless `tls-cluster` is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new `cluster-bus-port-protected-mode` option (default `no`) makes refusing to run in that state an explicit choice: set it to `yes` and the node starts only when `tls-cluster` authenticates the bus
- TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload
- RedisSearch: KNN queries on indexes with very long vector field names could cause the server to crash
- Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash
================================================================================
Redis 8.10.1 Released Mon 17 Aug 2026 10:00:00 IST
================================================================================
Update urgency: `SECURITY`: There are security fixes in the release.
### Security fixes
- (CVE-2026-62356) Miscalculated buffer size in `CMSketch` RDB loading may lead to heap OOB write
- Out-of-bounds access in TopK heap cleanup path (MOD-15410)
- Use-after-free in the TLS pending-data list when a command closes another pending connection
- A malicious RDB payload with an out-of-range `SLOT_INFO` slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
- Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
- Vector Sets: use-after-free when `VREM` mutates the HNSW graph while background `VSIM` threads are still running
- Vector Sets: a negative `hnsw_search()` return was treated as a huge unsigned count, reading past the end of the result arrays
- TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
- #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key
==================================================================
Redis 8.10 GA Released Wed 29 Jul 2026 21:00:00 IST
==================================================================
This is the General Availability release of Redis 8.10 in Redis Open Source.
### Major changes compared to 8.8
- Compact hashes - a new hash encoding that reduces memory usage by storing hash field names just once for keys that share a schema
- New command: `HIMPORT` - high-throughput compact hash bulk insertion
- TLS peer certificate-based server-to-server authentication
- New commands: `LMOVEM`, `BLMOVEM` - move multiple elements between lists
- New command: `SUNIONCARD` - get the cardinality of the union of multiple sets
- New command: `SDIFFCARD` - get the cardinality of the difference between sets
- New command: `BACKUP` - node-side implementation for backup and restore based on multi-part AOF (MP-AOF)
- `XREAD`, `XREADGROUP` - new `MAXCOUNT` and `MAXSIZE` arguments to cap the cumulative reply entries and size
- New command: `FT.ALIASLIST` - get all aliases for the index
- Stemmer support for Malay and Tagalog languages
- JSONPath extensions
- New commands: `TS.NRANGE`, `TS.NREVRANGE` - Query a range across multiple time series; group results by timestamp
- New command: `TS.READ` - optionally blocking read
- New command: `TS.QUERYLABELS` - Get a list of labels and label-values
- New command: `TS.MRANGE`, `TS.MREVRANGE` - new `EXCLUDEEMPTY` argument to exclude series with no reported samples
- Performance improvements
### Binary distributions
- Alpine and Debian Docker images - https://hub.docker.com/_/redis
- Install using snap - see https://github.com/redis/redis-snap
- Install using brew - see https://github.com/redis/homebrew-redis
- Install using RPM - see https://github.com/redis/redis-rpm
- Install using Debian APT - see https://github.com/redis/redis-debian
### Operating systems we test Redis 8.10 on
- Ubuntu 22.04 (Jammy Jellyfish), 24.04 (Noble Numbat), 26.04 (Resolute Raccoon)
- Rocky Linux 8.10, 9.7, 10.1
- AlmaLinux 8.10, 9.7, 10.1
- Debian 12.13 (Bookworm), Debian 13.4 (Trixie)
- Alpine 3.23
- macOS 14.8.4 (Sonoma), 15.7.4 (Sequoia), 26.3 (Tahoe) - for both Intel and ARM
### Bug fixes (compared to 8.10-RC2)
- #15513 Prevented a division-by-zero error when active defragmentation thresholds are configured with equal or reversed value
- #15453 Clients blocked on `BLPOP`, `BLMOVE`, or `BLMOVEM` could remain blocked after `SORT` with `STORE` replaced the target key with a list
- #15499 Memory usage reported for compressed replication clients could be lower than the actual memory consumed
- #15518 notify modules when node's own ip/port changes
- #15539 Loading an AOF file with an RDB preamble could fail when active defragmentation was enabled
- #Q10528 Crash in the numeric range tree when background garbage collection encounters an empty leaf during active indexing on a numeric field. (MOD-16877)
- #Q10605 FT.CREATE and FT.ALTER now reject an empty string as a field name, preventing a crash loop in the fork-GC on indexes with an empty TAG field. (MOD-17034)
- #Q10488 FT.INFO reports a negative num_records after garbage collection on indexes that include an INDEXMISSING field. (MOD-16940)
- #Q10568 Cluster FT.AGGREGATE fails with SEARCH_FIELD_DUP when a GROUPBY contains multiple REDUCE COLLECT calls over the same field differing only in option-keyword casing. (MOD-16365)
- #Q10605 FT.CREATE and FT.ALTER now return an error when a field name is an empty string; previously such schemas were accepted silently. (MOD-17034)
- #Q10522 coord_total_query_warnings_timeout double-counts timeout warnings for FT.SEARCH queries that use a hybrid (vector + filter) execution path. (MOD-15973)
==================================================================
Redis 8.10-RC2 (v8.9.241) Released Mon 20 Jul 2026 21:00:00 IST
==================================================================
This is the second Release Candidate of Redis 8.10 in Redis Open Source.
Release Candidates are feature-complete pre-releases. Pre-releases are not suitable for production use.
### Bug fixes (compared to 8.10-RC1)
- A user can manipulate data read by a connection by injecting \r\n sequences into a Redis error reply
- A typo in release.h that could cause build failures
==================================================================
Redis 8.10-RC1 (v8.9.240) Released Mon 20 Jul 2026 18:00:00 IST
==================================================================
This is the first Release Candidate of Redis 8.10 in Redis Open Source.
Release Candidates are feature-complete pre-releases. Pre-releases are not suitable for production use.
### Headlines:
Redis 8.10 introduces new features and performance improvements.
### Operating systems we test Redis 8.10 on
- Ubuntu 22.04 (Jammy Jellyfish), 24.04 (Noble Numbat), 26.04 (Resolute Raccoon)
- Rocky Linux 8.10, 9.7, 10.1
- AlmaLinux 8.10, 9.7, 10.1
- Debian 12.13 (Bookworm), Debian 13.4 (Trixie)
- Alpine 3.23
- macOS 14.8.4 (Sonoma), 15.7.4 (Sequoia), 26.3 (Tahoe) - for both Intel and ARM
### New Features (compared to 8.8)
- #15364 Compact hashes - a new hash encoding that reduces memory usage by storing hash field names just once for keys that share a schema
- #15366 Replication stream compression to reduce bandwidth consumption between primaries and replicas
- #15364 New command: `HIMPORT` - high-throughput compact hash bulk insertion
- #15405 New commands: `LMOVEM`, `BLMOVEM` - move multiple elements between lists
- #14893 New command: `SUNIONCARD` - get the cardinality of the union of multiple sets
- #15278 New command: `SDIFFCARD` - get the cardinality of the difference between sets
- #15441 New command: `BACKUP` - node-side implementation for backup and restore based on multi-part AOF (MP-AOF)
- #15282 `XREAD`, `XREADGROUP` - new `MAXCOUNT` and `MAXSIZE` arguments to cap the cumulative reply entries and size
- #15337 New `SCRIPT_RUNNER` command flag: flag commands that execute scripts or functions
- #15347 `SLOWLOG GET` - new reply argument: total argument count
- #Q9626 New command: `FT.ALIASLIST` - get all aliases for the index (RED-197340)
- #Q9052 New Languages Search: Stemmer support for Malay and Tagalog languages (RED-132425)
- #Q9291 `FT.AGGREGATE` now supports whole-document fetching using `COLLECT`, in-group SORTBY/LIMIT, and deduplication control within a single query. (RED-177887)
- #Q8169, #Q8236, #Q9234, #Q9443 — `FT.SEARCH`, `FT.AGGREGATE`, `FT.HYBRID`: enforce query `TIMEOUT` more strictly; long-running queries require vertical scaling (multi-threaded execution). (RED-132340)
- use `FAIL` when correctness requires rejecting timed-out queries. With `search-workers` > 0` (the default), the timeout is enforced preemptively
- use `RETURN` when best-effort partial results are acceptable and strictness not enforced at post-processing time.
- use `RETURN_STRICT` when best-effort partial results are acceptable and strictness enforced on post-processing.
- New parameter `search-global-timeout` acting as cap value to timeout setting on query time TIMEOUT param
- #J1602, #J1603, #J1604, #J1607, #J1618 JSONPath extensions (MOD-16274, MOD-16275):
- Projection expressions at the top level of a JSONPath query
- `==` and `!=` can now compare any literal, including array and object literals
- Filter negation operator: `!`
- `size`/`sizeof` and `empty` operators on string, array, object, and nodelist
- `in` and `nin` operators: membership test on an array and nodelist
- Operators on numbers: binary `-`, `+`, `*`, `/`, `%`, and unary `-` and `+`
- Operator on object: `~`
- `length()` function on array, object, and string
- Functions on number: `abs()`, `ceiling()`, `floor()`
- Functions on string: `match()`, `search()`
- Strings concatenation with `concat()`
- Functions on array: `first()`, `last()`, `index()`, `append()`
- Aggregation functions on array: `min()`, `max()`, `avg()`, `sum()`, `stddev()`
- Function on object: `keys()`
- Function on nodelist: `count()`
- Function on nodelist with exactly one node: `value()`
- Relations functions on array and nodelist: `subsetof()`, `anyof()`, `noneof()`
- #T2052 New commands: `TS.NRANGE`, `TS.NREVRANGE` - Query a range across multiple time series; group results by timestamp (RED-149232)
- #T2054 New command: `TS.READ` - optionally blocking read (RED-132421)
- #T2090 New command: `TS.QUERYLABELS` - Get a list of labels and label-values (RED-132355)
- #T2072 New command: `TS.MRANGE`, `TS.MREVRANGE` - new `EXCLUDEEMPTY` argument to exclude series with no reported samples (RED-132536)
### Bug fixes (compared to 8.8.0)
- #15478 `SORT`, `GEORADIUS`, `GEORADIUSBYMEMBER`, `XREAD`, `XREADGROUP` - ACL permission bypass
- #15329, #15467 - I/O thread busy looping for replica clients
- #15466 Duplicate KeyMeta restoration in `RESTORE`-based AOF rewrites
- #15462 `MEMORY USAGE` over-reports memory consumption
- #15447 Full sync under heavy write load
- #15412 Unit mismatch disables the FAST expire cycle stale trigger
- #15392 Crash on `VRANDMEMBER` with `LLONG_MIN` count
- #15409 `CONFIG SET` - crash on of TLS options in non-TLS builds
- #15371 ACL key-name leak in BCAST client-side caching invalidations
- #15433 Signed overflow in `BITFIELD` offset parsing
- #15446 The select-based event loop backend enqueues registered file descriptors that `select()` did not mark ready
- #15309 `mem_clients_normal` drift when a replica drops its cached master after a failed partial resync
- #15357 Crash on missing module numeric config
- #15377 In-progress atomic slot migration tasks keep running on `RM_ResetDataset` and `RM_RdbLoad`
- #15391, #15356, #15436 NULL dereference
- #15390 Overflow on memory unit conversions
- #15291 `SET` does not enforce mutually exclusive `NX`/`XX` and `IF*` options
- #15322 `CONFIG SET` does not reject duplicate arguments when using both primary name and alias
- #15407 `LSET` out-of-range 64-bit index truncation
- #15308 Improve RDB load robustness (streams)
- #15263 Tighter cluster bus parsing for `PING`, `PONG`, and `MEET` packets
- #15247 Partial crash log on LoongArch architecture
- #15270 `VADD ... CAS SETATTR` - wrong attributes count
- #Q10375 `FT.CURSOR READ`: crash after the underlying index was dropped (MOD-16703)
- #Q10408 `FT.SEARCH` with `LIMIT` returns too many results in cluster mode over RESP3 (MOD-16767)
- #Q10420 `FT.INFO` could report incorrect values for multi-value TAG fields after document updates (MOD-16745)
- #Q10488 `FT.INFO` reports a negative `num_records` after garbage collection on indexes with an `INDEXMISSING` field (MOD-16940)
- #Q10392 Vector search: crash (SIGSEGV) in FP32/L2 distance computation on x86 without AVX support, affecting certain vector dimensions (MOD-16730)
- #Q9963 Range query returns incomplete results when the lower bound is an excluded empty string (MOD-15897)
- #Q10066 `FT.AGGREGATE .. WITHCOUNT` coordinator leaks resources on timeout (MOD-16210)
- #Q10247 Local `FT.HYBRID` ignores `ON_TIMEOUT RETURN_STRICT` and continues execution past the deadline (MOD-16492)
- #Q10255 Blocked search clients trigger unnecessary query dumps, adding CPU and log overhead (MOD-16518)
- #Q10151 `FT.HYBRID` supports `EXPLAINSCORE`, exposing the fusion method (`RRF` or `LINEAR`) (MOD-10044)
- #J1542, #J1543 Wrong results when evaluating paths with recursive descent (MOD-6722, MOD-14664)
- #J1554 Any literal that starts with true/false/null is interpreted as true/false/null (MOD-7266)
- #J1600 Improve RDB load robustness
- #T2067 `TS.INFO` - inaccurate memory usage calculation (MOD-6409)
- #T2036, #T2053, #T2056, #2074 Aggregation fixes (MOD-8187, MOD-16224, MOD-15565)
- #T2004, #T2051 Improve RDB load robustness
- #T2104 Issues after cluster topology changes
- #T2122 Error on the first cross-shard command (TLS)
- #T2109 `TS.INCRBY` with `TIMESTAMP *` replication timestamp drift
- #P1014 `CF.LOADCHUNK` partial replication (MOD-16050)
- #P1026, #P1027 Improve RDB load robustness
### Performance and resource utilization improvements (compared to 8.8.0)
- #15376 Optimize `lpSeek()` by validating entries only when necessary
- #15345 Optimize wide `HSET`/`HMSET` on a fresh hash with a single batched listpack append
- #15330 Avoid recomputing allocator fragmentation twice per cron tick (RED-200844)
- #15259 Trim excess SDS allocation in inline command parsing
- #15256 rax memory reduction: leaf-inlining for fixed-length-key trees - improves `XREADGROUP` performance
- #15397 Improve `RESTORE REPLACE` performance for new keys
- #14704 Optimizes an internal memory accounting
- #Q10246 Write operations block on a read lock held throughout vector range query result collection (MOD-16437)
- #Q10392 Vector search: Reduce HNSW index memory usage with one-byte per-node locks (MOD-16696).
- #J1617, #JIJSON9 JSON - memory object footprint improvements (MOD-16608)
### Modules API
- #15350 `RedisModuleEvent_ClusterTopologyChange` - cluster topology change
- #15327 `REDISMODULE_SUBEVENT_FORK_CHILD_*` - allow multi-threaded modules can quiesce background work before `fork()`
- #15373 `REDISMODULE_SUBEVENT_CLUSTER_SLOT_MIGRATION_MIGRATE_MODULE_PROPAGATE_END` - inject commands after ASM replication stream
- #15242 `RedisModule_AddPostNotificationJobForKey` - binds deferred work to a specific key from a keyspace-notification handler
### Configuration parameters
- #15364 Compact hashes:
- `hash-rdb-load-min-template-entries` - minimum field count to convert a plain hash to a template during load
- `hash-rdb-load-max-template-entries` - maximum field count for load-time conversion
- `hash-rdb-load-template-disassembly-threshold` - minimum number of keys a converted template must end up with to be kept
### Metrics
- #15364 Compact hashes:
- `INFO STATS` - `hash_templates` - number of distinct compact hash templates
- `INFO STATS` - `hash_template_keys` - total number of keys backed by a compact hash template
- `INFO MEMORY` - `used_memory_hash_templates` - total memory used by all compact hash templates
- `MEMORY STATS` - `hash.templates` - total memory used by all compact hash templates
- `MEMORY USAGE <key>` reports the key’s own + plus its share of a compact hash template cost
### CLI tools
- #15352 Adds `--latency-percentiles <p1,p2,...>` to `--latency` / `--latency-history`: reporting user-chosen percentiles
- #15262 `redis-cli --cluster rebalance` - CROSSSLOT error on when using `-user` without `-a`
- #15338 `redis-cli --cluster reshard` and `rebalance` now move slots with server-side atomic slot migration