Skip to content

Antalya 26.6: Bump to 26.6.8 - #2481

Open
zvonand wants to merge 396 commits into
antalya-26.6from
bump/antalya-26.6/26.6.8
Open

zvonand wants to merge 396 commits into
antalya-26.6from
bump/antalya-26.6/26.6.8

Conversation

@zvonand

@zvonand zvonand commented Oct 5, 2026

Copy link
Copy Markdown
Member

Changelog category (leave one):

  • Not for changelog (changelog entry is not required)

CI/CD Options

Exclude tests:

  • Fast test
  • Integration Tests
  • Stateless tests
  • Stateful tests
  • Unit tests
  • Performance tests
  • Aarch64 tests
  • All with ASAN
  • All with TSAN
  • All with MSAN
  • All with UBSAN
  • All with Coverage
  • All Regression
  • Disable CI Cache

Regression jobs to run:

  • Fast suites (mostly <1h)
  • Aggregate Functions (2h)
  • Alter (1.5h)
  • Benchmark (30m)
  • CAS (content-addressed storage; Antalya only)
  • ClickHouse Keeper (1h)
  • Iceberg (2h)
  • LDAP (1h)
  • OAuth (5m)
  • Parquet (1.5h)
  • RBAC (1.5h)
  • SSL Server (1h)
  • S3 (2h)
  • S3 Export (2h)
  • Swarms (30m)
  • Tiered Storage (2h)

robot-clickhouse and others added 30 commits September 5, 2026 02:09
…6994

Backport ClickHouse#116994 to 26.6: Do not recurse per empty block in the hadoop-snappy reader
…7034

Backport ClickHouse#117034 to 26.6: Keep `Distributed` spool files after transient split errors
…access check

On master this integration test was already rewritten as the functional
`04510_select_access_rights_rewrite.lib`, which ClickHouse#117979 updated, so the
backport had nothing to change there. On 26.6 the integration test still
exists and expected the column-level message
`SELECT for at least one column` for `SELECT count() FROM table1` without
any grant. With the analyzer checking table access while resolving the
identifier, the error is now `SELECT ON default.table1`, exactly as the
master test expects. Pin `enable_analyzer=1` for these assertions so the
result does not depend on the analyzer mode of the CI job.

Same fix as c7d1f4b in the 26.7 backport (ClickHouse#118179).

CI: https://s3.amazonaws.com/clickhouse-test-reports/json.html?PR=118169&sha=2bc6581ff7d9eb1d276ec947c28162e4108455c4&name_0=BackportPR&name_1=Integration%20tests%20%28amd_asan_ubsan%2C%20db%20disk%2C%20old%20analyzer%2C%203%2F6%29
PR: ClickHouse#118169
…7979

Backport ClickHouse#117979 to 26.6: Check table access when the analyzer resolves a table identifier
…ix the test signature

The 26.6 branch still has the `rows_offset` parameter of
`deserializeBinaryBulkWithMultipleStreams` (removed on master), so the
backported `gtest_string_serialization.cpp` did not compile (five arguments
where six are expected). Port the same branch-only adaptation as the 26.7
twin (ClickHouse#118201):

- `deserializeBinaryBulkWithSizeStream`: accumulate the sizes of the rows
  skipped by `rows_offset` in 128 bits and reject a sum above
  `MAX_TOTAL_STRING_SIZE` with `INCORRECT_DATA`, as the skipped prefix comes
  from the same untrusted sizes stream and an unchecked `size_t` sum could wrap
  and make `ignore` skip a wrong number of bytes.
- `expectSizesStreamRejected` takes `rows_offset`, holds the result as a
  `ColumnPtr` (the branch signature takes `ColumnPtr &`), and a new test
  `WithSizeStreamHugeSkippedSizeIsRejected` covers the skipped-prefix path.

CI: https://s3.amazonaws.com/clickhouse-test-reports/json.html?PR=118200&sha=5bb0496be03bc66420b1316da678c4c25350ec6d&name_0=BackportPR&name_1=Build%20%28amd_debug%29
PR: ClickHouse#118200
…8810

Backport ClickHouse#108810 to 26.6: Fix segfault in StreamingStorageRegistry
…5702

Backport ClickHouse#115702 to 26.6: Fix integer overflow in String deserialization
… Keeper without MULTI_READ on ATTACH/restore
…8194

Backport ClickHouse#118194 to 26.6: Require the whole `ALTER TABLE` grant to imply `ALTER VIEW`
…gs for quotas/roles/row policies/settings profiles
…4975

Backport ClickHouse#114975 to 26.6: Use offset in performSinglepartUpload for Azure
…8441

Backport ClickHouse#108441 to 26.6: Stop refreshable MV gracefully on Keeper without MULTI_READ on ATTACH/restore
…6992

Backport ClickHouse#116992 to 26.6: Do not read the compressed-buffer slack as LZ4 literal data
…8789

Backport ClickHouse#108789 to 26.6: Lower severity for recomputing logs for quotas/roles/row policies/settings profiles
…CATE` of a database over `ON CLUSTER`
…7960

Backport ClickHouse#117960 to 26.6: Require the DROP privilege for CREATE ... OR REPLACE of an access entity
…8155

Backport ClickHouse#118155 to 26.6: Require `DROP DATABASE` for `TRUNCATE` of a database over `ON CLUSTER`
Keep a PostgreSQL session alive after an extended-query execution exception if no output was sent. The next `Sync` can then emit `ReadyForQuery` safely.

CI: https://s3.amazonaws.com/clickhouse-test-reports/json.html?PR=118067&sha=e04319e5518b4e2070c5b3a3f053850267fa9aa1&name_0=BackportPR

PR: ClickHouse#118067
pufit and others added 21 commits September 14, 2026 18:25
…ckport/26.6/119357

Revert "Backport ClickHouse#119357 to 26.6: Fix an ALTER on a SQL SECURITY DEFINER view deleting its auto-created definer user"
…9853

Backport ClickHouse#119853 to 26.6: Fix a server crash on a `NATS` table whose credentials the broker rejects
test_database_delta::test_snapshot_version is chronically flaky: the
get_table_versions() helper runs a read-only DESCRIBE HISTORY via
execute_spark_query() without retry_on_timeout, so a single 600s attempt
is consumed entirely by a transient Unity Catalog HTTP-client hang (the
UC Java client has no per-request timeout, see the jstack root cause
recorded in the retry mechanism added earlier). The test then fails with
'timed out after 600s'.

DESCRIBE HISTORY is read-only and idempotent, so retry_on_timeout is
safe: it uses the shorter 300s per-attempt budget and a fresh-JVM retry,
and two attempts (600s) still fit the 900s pytest timeout. The
non-idempotent INSERT calls are deliberately left un-retried.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 5e22d65)
…9641-manual

Backport ClickHouse#109641 to 26.6: Fix flaky test_database_delta::test_snapshot_version (Spark DESCRIBE HISTORY timeout)
…9849

Backport ClickHouse#119849 to 26.6: Check the schema of every block a client sends for an external table
…4357

Backport ClickHouse#114357 to 26.6: Validate S3 and Azure URLs before client creation and schema inference
…ifest bounds for `int` and `date` columns
…7563

Backport ClickHouse#117563 to 26.6: Enforce single use of TOTP codes (RFC 6238)
…7571

Backport ClickHouse#117571 to 26.6: Fix the byte width of Iceberg manifest bounds for `int` and `date` columns
…8933

Backport ClickHouse#118933 to 26.6: Split the ASan integration test jobs into eight batches
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…8796

Backport ClickHouse#118796 to 26.6: Iceberg manifest list partition summaries
…8474

Backport ClickHouse#108474 to 26.6: Fix SQL injection in MySQL wire protocol replacement queries
…9078

Backport ClickHouse#109078 to 26.6: Fix qualified matcher resolve with non-compound column clash
Release v26.6.8.7-stable

# Conflicts:
#	.github/workflows/master.yml
#	.github/workflows/pull_request.yml
#	ci/defs/job_configs.py
#	ci/jobs/functional_tests.py
#	cmake/autogenerated_versions.txt
#	src/Access/AccessControl.h
#	src/Common/FailPoint.cpp
#	src/Databases/DataLake/DatabaseDataLake.cpp
#	src/Databases/DataLake/GlueCatalog.cpp
#	src/Databases/DataLake/RestCatalog.cpp
#	src/Disks/DiskObjectStorage/ObjectStorages/Local/LocalObjectStorage.cpp
#	src/Disks/DiskObjectStorage/ObjectStorages/S3/S3ObjectStorage.cpp
#	src/Interpreters/IcebergMetadataLog.h
#	src/Parsers/ASTSetQuery.cpp
#	src/Server/TCPHandler.cpp
#	src/Storages/MergeTree/MergeTreeData.cpp
#	src/Storages/MergeTree/MergeTreeSettings.cpp
#	src/Storages/MergeTree/MergeTreeSettings.h
#	src/Storages/ObjectStorage/DataLakes/DataLakeConfiguration.h
#	src/Storages/ObjectStorage/DataLakes/Iceberg/IcebergMetadata.cpp
#	src/Storages/ObjectStorage/DataLakes/Iceberg/IcebergMetadata.h
#	src/Storages/ObjectStorage/DataLakes/Iceberg/IcebergPath.cpp
#	src/Storages/ObjectStorage/DataLakes/Iceberg/IcebergWrites.cpp
#	src/Storages/ObjectStorage/DataLakes/Iceberg/IcebergWrites.h
#	src/Storages/ObjectStorage/DataLakes/Iceberg/ManifestFileIterator.cpp
#	src/Storages/ObjectStorage/DataLakes/Iceberg/PersistentTableComponents.h
#	src/Storages/ObjectStorage/DataLakes/Iceberg/Snapshot.h
#	src/Storages/ObjectStorage/DataLakes/Iceberg/StatelessMetadataFileGetter.cpp
#	src/Storages/ObjectStorage/StorageObjectStorage.cpp
#	src/Storages/ObjectStorage/StorageObjectStorage.h
#	src/Storages/ObjectStorage/StorageObjectStorageCluster.cpp
#	src/Storages/ObjectStorage/StorageObjectStorageCluster.h
#	src/Storages/ObjectStorage/StorageObjectStorageSource.cpp
#	src/Storages/StorageFileCluster.cpp
#	src/Storages/StorageFileCluster.h
#	src/Storages/System/StorageSystemIcebergFiles.cpp
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Workflow [PR], commit [ac6a27c]

@zvonand

zvonand commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

@blau-ai

@blau-ai

This comment was marked as outdated.

`05077_iceberg_equality_delete_nullability_mismatch`: absolute data and
metadata paths inside the table `location` are mapped under the table root
by the path resolver, so they are no longer checked against `user_files`
as raw paths. The check requires that the remainder after `location` does
not climb out of it, so a crafted path cannot escape the table root.

`test_cluster_insert`, `test_writes_parallel_replicas_no_catalog`:
`StorageObjectStorageCluster::write` always writes on the initiator, as
introduced upstream by the backport of
ClickHouse#119214 instead of throwing
`NOT_IMPLEMENTED` when a cluster is set.

CI report: #2481 (comment)
PR: #2481

Signed-off-by: Andrey Zvonov <32552679+zvonand@users.noreply.github.com>
…uded

The `Keeper Stress Tests (PR)` job requires `CH_ARM_BIN_GH` from
`Build (arm_binary)` and is not affected by CI exclude tags, but the build
was skipped by the `arm` exclude tag, so the job failed with
`ClickHouse binary not found`.

CI report: https://altinity-build-artifacts.s3.amazonaws.com/json.html?PR=2481&sha=fa0d83b3f1ce172b87b3c57ac17ffb3a755a65c7&name_0=PR&name_1=Keeper%20Stress%20Tests%20%28PR%29
PR: #2481

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.