NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #3098 most downloaded on NuGet
The TigerBeetle client for C# and .NET
Last release 3 months ago
06 Jul 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
127 years old
300 releases · first in 1900
Note: Before performing this upgrade, please make sure to check that no replicas are lagging and state syncing.
Released: 2025-02-17
Note: Before performing this upgrade, please make sure to check that no replicas are lagging and state syncing.
You can ensure this by temporarily pausing load to the TigerBeetle cluster and waiting for all
replicas to catch up. If some replicas in your cluster were indeed lagging, you should see
on_repair_sync_timeout: request sync; lagging behind cluster in the logs, followed by
sync: ops=, which indicates the end of state sync. If you don't see the former in the logs, then
you are already safe to upgrade!
This is to work around an issue in the upgrade between 0.16.25 → 0.16.26, wherein a state syncing replica goes into a crash loop when it upgrades to 0.16.26. If one of your replicas has already hit this crash loop, please reach out to us on the Community Slack so we can help you safely revive it.
Test misdirected writes in the VOPR.
Fix a recovery correctness bug caused by a misdirected write in the WAL (discovered by the VOPR in #2677).
Refactor the tb_client packet interface, hiding private members in an opaque field. Add assertions to enforce expectations for each packet field.
Fix a Node.js client crash when it was closed with outstanding requests.
Flush loopback queue before queueing another prepare_ok.
Fuzzer weights are now configurable.
The REPL now uses StaticAllocator on init and deinit.
tigerbeetle inspect constants now prints a napkin math estimate for the memory usage.
Update docs with new talks, an updated illustration, and a new Slack invite link.
Don't expose VSR module to dependents in build.zig.
One column per quarter.
Remove the deprecated version of the start_view message.
Released: 2025-02-10
Note: Before performing this upgrade, please make sure to check that no replicas are lagging and state syncing.
You can ensure this by temporarily pausing load to the TigerBeetle cluster and waiting for all
replicas to catch up. If some replicas in your cluster were indeed lagging, you should see
on_repair_sync_timeout: request sync; lagging behind cluster in the logs, followed by
sync: ops=, which indicates the end of state sync. If you don't see the former in the logs, then
you are already safe to upgrade!
This is to work around an issue in the upgrade between 0.16.25 → 0.16.26, wherein a state syncing replica goes into a crash loop when it upgrades to 0.16.26. If one of your replicas has already hit this crash loop, please reach out to us on the Community Slack so we can help you safely revive it.
Remove redundant calls to IO.init() and IO.deinit() during the format and start commands.
These redundant calls could lead to an assertion error in the Zig standard library when a failure
occurs after the second IO.init().
Enhance the docs search bar with arrow-key navigation over search results, and folder collapse using the enter key.
Add talks from SystemsDistributed '23, P99 CONF '23, Money2020 '24, and SYCL '24.
Improve CPU utilization of the CFO by spawning fuzzers more frequently.
Motivated by the measurement that the cumulative CPU was (on average) 40-45% idle.
Assert zeroed padding for WAL prepares in the VOPR.
Remove the deprecated version of the start_view message.
As part of #2600, we rolled out a new on-disk format for the CheckpointState. To avoid bumping the VSR version, we made it so that replicas temporarily send two versions of the start_view message, with both the old and new CheckpointState formats.
Add fair scheduler to the CFO to avoid starvation of short running fuzzers.
Earlier, long running LSM fuzzers ended up spending more than their fair share of time on the CPU, with only 1-10% of CFO time being spent on short running VOPR fuzzers.
Note: Before performing this upgrade, please make sure to check that no replicas are lagging and state syncing.
Released: 2025-02-03
Note: Before performing this upgrade, please make sure to check that no replicas are lagging and state syncing.
You can ensure this by temporarily pausing load to the TigerBeetle cluster and waiting for all
replicas to catch up. If some replicas in your cluster were indeed lagging, you should see
on_repair_sync_timeout: request sync; lagging behind cluster in the logs, followed by
sync: ops=, which indicates the end of state sync. If you don't see the former in the logs, then
you are already safe to upgrade!
This is to work around an issue in the upgrade between 0.16.25 → 0.16.26, wherein a state syncing replica goes into a crash loop when it upgrades to 0.16.26. If one of your replicas has already hit this crash loop, please reach out to us on the Community Slack so we can help you safely revive it.
Consider blocks and prepares with nonzero padding to be corrupt. Previously blocks asserted zero padding, which can fail due to bitrot.
Also fix a similar bug in the superblock copy index handling. The copy index is not covered by a checksum, so we must treat it carefully to avoid propagating bad data if it is corrupt.
VOPR now injects single-bit errors into storage rather than whole-sector errors.
The current checkpoint process immediately frees all blocks released in the previous checkpoint. This can lead to cluster unavailability by prematurely freeing and overwriting released blocks.
To fix this, delay freeing blocks until the checkpoint is durable on a commit-quorum, ensuring data integrity and preventing single-replica failures (in a 3 node cluster) from impacting availability.
When state syncing, replicas would send prepare_oks only up to a point, to ensure they don't falsely contribute to the durability of a non-durable checkpoint they've synced to.
However, the logic to send these prepare_oks after state sync has finished was missing, which could lead to a situation where a primary was unavailable to advance. Add in the ability to send these prepare_oks after syncing.
Recently, tb_client was reworked to use OS native signals instead of a socket for delivering cross thread events.
Fix some incorrect asserts, and add a fuzz test.
#2694, #2695, #2686, #2688, #2685, #2676, #2684
A few fixes and an "Edit this page" button for our new docs!
Allocate the reply buffer in the Go client once the reply has been received. This can save up to 1MB of memory.
Refactor parts of our CFO, the process responsible for running fuzzers and the VOPR and sending the results to devhub, to better handle OOM in subprocesses and reduce false fuzz failures.
Avoid considering just-repaired journal headers as faulty during WAL recovery.
Released: 2025-01-27
Avoid considering just-repaired journal headers as faulty during WAL recovery.
Reduce the minimum exponential backoff delay from 100ms (which is too pessimistic) to 10ms, a value more appropriate for fast networks.
Introduce a new CheckpointState format on disk, which ensures that blocks released during
a checkpoint are freed only when the next checkpoint is durable, solving a known
liveness issue.
The previous format is still supported and will be removed in a future release to ensure the
proper upgrade path.
Demote a clock skew warning to a debug message when the ping time is legitimately behind the window. On the other hand, assert that the monotonic clock is within the window.
Workaround to prevent the initialization value for the AOF message from being embedded as a
binary resource, saving constants.message_size_max bytes in the executable size!
Fix a VOPR false positive where it erroneously infers that a replica has lost a prepare that it has acknowledged.
New statically generated docs website, featuring many UX improvements while removing tons of dependencies! Check it out at https://docs.tigerbeetle.com/
Make the CFO utilize all cores all the time for running tests, pushing updates every 5 minutes.
Nothing published for this version
Released: 2025-01-20
Released: 2025-01-20
Nothing published for this version
Fix multiple VOPR false positives
Released: 2025-01-13
Happy 2025!
Fix multiple VOPR false positives
Disable costly cache map verification: trust, verify, but mind big-O!
Improve state sync performance by getting rid of awaiting_checkpoint state.
Improve VOPR coverage when running out of IOPs.
#2593, #2623, #2625, #2626, #2627, #2628
Improve WAL repair performance.
Improve replication performance.
Add simple metrics to the state machine.
Greatly improve performance of append-only file (AOF). Note that this changes format of AOF on disk.
Add tigerbeetle inspect constants command to visualize important compile-time parameters.
Use asynchronous disk IO on Windows (as a reminder, at the moment TigerBeetle server is considered to production-ready only on Linux).
Add experimental alternative replication topologies (star and closed loop).
Move RingBufferType into stdx, TigerBeetle's extended standard library.
Run go vet on CI.
Fix tracing compatibility with perfetto.
Make it easier to investigate Vortex runs.
Correctly calculate the number of results in the Go client. Previously, the answer was correct despite the logic being wrong!
Improve replication reliability for tiny messages.
Released: 2024-12-27
Improve replication reliability for tiny messages.
Add info-level logging for basic progress events.
Add logging and runtime configuration parameters for state sync.
Fix fuzz_lsm_scan checkpoint schedule.
Coalesce LSM tables in memory before writing them to disk. This significantly improves workloads with small batch sizes, that would otherwise churn in
Released: 2024-12-22
Coalesce LSM tables in memory before writing them to disk. This significantly improves workloads with small batch sizes, that would otherwise churn in the top level of the LSM while incurring heavy write amplification.
TigerBeetle recently gained the ability to do runtime debug logging with --log-debug. Extend
that to other subcommands - not just start.
Additionally, the Python client now has logs integrated with Python's native logging module,
which means no more printing to stderr!
Fix broken links to TigerBeetle blog posts, thanks @PThorpe92!
Our repair can create a feedback loop. Repair requests prepares and headers, but, upon receiving back, we re-trigger repair, which could lead to dupli
Released: 2024-12-19
Our repair can create a feedback loop. Repair requests prepares and headers, but, upon receiving back, we re-trigger repair, which could lead to duplicate repair work.
To avoid that, make sure that we are not sending more than two repair messages per replica per our repair timeout.
Trace AOF write duration
Timeouts with exponential backoff should reset to their original delay when the timeout is stopped.
Assert against ABA problem during commit.
Add retry for flock. flocks are cleaned up by the kernel when the file descriptor is closed,
but since that file descriptor is used by io_uring, it actually outlives the process itself.
Fix mlock flag value.
Don't crash if a round of view changes happened while repairing the pipeline.
This release includes a correctness fix for the preview API get_account_balances, get_account_transfers, query_accounts, and query_transfers. If your
Released: 2024-12-09
This release includes a correctness fix for the preview API get_account_balances,
get_account_transfers, query_accounts, and query_transfers. If your application uses these
features it might be affected.
Fix correctness bug which affected the preview get_account_balances, get_account_transfers,
query_accounts, and query_transfers queries. Specifically, if several filters are used (that
is, several fields in QueryFilter or AccountFilter are set), then some objects might be
missing from the result set.
The underlying data is safely stored in the database, so re-running these queries using the new version of TigerBeetle will give correct results.
Fix panic in the node client which occurred on eviction.
Fix incorrect ABI used on aarch64 for the client library. To prevent such issues from cropping up in the future, add aarch64 testing to CI.
Add extra assertions to verify object cache consistency.
Implement network fault injection in Vörtex, our non-deterministic whole system simulator.
Log level can now be specified at runtime.
Log messages now include UTC timestamp (formatted as per RFC 3339).
Relax compiler requirements for building TigerBeetle. While we only support building using one
specific version of Zig, the one downloaded via ./zig/download.sh, you can try using other
versions.
Document how to handle errors during release. TigerBeetle's release process is complicated, as we
need to release, in lockstep, both the tigerbeetle binary and all the related client libraries.
The release process is intentionally designed to be "highly-available", such that a failure of any
aspect of a release can be safely detected, isolated, and repaired. But, so far, this wasn't
clearly spelled out in the documentation!
The highlight of today's release is the new official Python client, implemented in #2527, and #2487. Please kick the tires!
Released: 2024-12-02
The highlight of today's release is the new official Python client, implemented in #2527, and #2487. Please kick the tires!
Require that all replicas in a cluster have the latest TigerBeetle binary as a precondition for an upgrade.
Fix several bugs when handling misdirected writes. That is, situations when the disk reports a write as successful, despite the write ending up in the wrong place on the disk!
Make sure that TigerBeetle memory is not swappable, otherwise a storage fault can occur in a currently swapped-out page, circumventing TigerBeetle guarantees.
REPL correctly emits errors when several objects are used as an argument of an operation that
only works for a single object, like get_account_transfers.
Add randomized integration tests for the Java client.
Ignore OOM failures during fuzzing. Fuzzers normally don't use that much memory, but, depending on random parameters selected by swarm testing, there are big outliers. If all concurrent fuzzers hit a seed that requires a lot of memory, a fuzzing machine runs out of physical RAM. Handle such errors and don't treat them as fuzzing failures.
Track the number of untriaged issues on DevHub.
Nothing published for this version
Call DetachCurrentThread when the Java client is closed. The underlying Zig TigerBeetle client runs in a separate thread internally, and a handler to
Released: 2024-11-25
Call DetachCurrentThread when the Java client is closed. The underlying Zig TigerBeetle client
runs in a separate thread internally, and a handler to this thread was being leaked.
This is not noticeable in normal operation, but could impact long running processes that create and close clients frequently.
Document that it's not possible to currently look up or query more than a full batch of accounts atomically without using the history flag and querying balances.
Add the ability to check timestamp order - and verify they are monotonically increasing - for accounts and transfers inside Vortex.
Recently the VOPR has gotten too good, and it's very tempting to switch to an empirical mode of coding: write some code and let the VOPR figure out whether it is correct or not.
This is suboptimal - silence of the VOPR doesn't guarantee total absence of bugs and safety comes in layers and cross checks. Just formal or informal reasoning is not enough, we need both.
Document this in TigerStyle.
Previously, the Zig part of languages clients logged directly to stderr using Zig's std.log, but
since directly outputting to stderr is considered rude for a library, logging was disabled.
This PR adds in scaffolding for sending these logs to the client language to be handled there, tying in with native log libraries (e.g., Log4j). No languages use it yet, however.
Additionally, log warn and err directly to stderr, if there's no handler.
Fix a broken assert when a recently-state-synced replica that has not completed journal repair receives an old commit message.
Released: 2024-11-18
Fix a broken assert when a recently-state-synced replica that has not completed journal repair
receives an old commit message.
Retry EAGAIN on (disk) reads. This is essential for running TigerBeetle on XFS, since XFS
returns EAGAIN unexpectedly.
Fix a message bus crash when a client reconnects to a replica without the replica receiving a disconnect for the first connection.
Save 256KiB of RAM by not having a prefetch cache for historical balances. (Historical balances are never prefetched, so this cache was unused.)
Update hardware requirements in the documentation to include the recommended network bandwidth, advice for very large data files, and farther emphasis on the importance of ECC RAM.
Don't panic the client when the client's session is
evicted.
Instead, report an error any time a new batch is submitted to the evicted client.
(How the error is reported depends on the client language – e.g. Java throws an exception, whereas
Node.js rejects the Promise).
Note that if running clients are evicted, that typically indicates that there are too many clients running – check out the suggested system architecture.
Add REPL interactivity. Also change the REPL from dynamic to static allocation. Thanks @wpaulino!
Expose the VSR timestamp to the client. (This is an experimental feature which will be removed soon – don't use this!)
Fix an attempt to access uninitialized fields of tb_packet_t when tb_client_deinit aborts pending requests. Also add Java unit tests to reproduce the
Released: 2024-11-11
Fix an attempt to access uninitialized fields of tb_packet_t when tb_client_deinit aborts
pending requests. Also add Java unit tests to reproduce the problem and validate the fix.
Fix a liveness issue where the cluster gets stuck despite sufficient durability, caused by buggy
logic for cycling through faulty blocks during repair. Now, we divide the request buffer between
the read_global_queue and faulty_blocks, ensuring that we always request blocks from both.
Update DevHub styling.
Vortex can now not only crash replicas (by killing and restarting the process) but also stop and resume them.
Fix the Dotnet walkthrough example that misused length instead of the final index when slicing
an array. Thanks @tenatus for reporting it!
Fix a CI failure caused by concurrent processes trying to create the fs_supports_direct_io
probe file in the same path.
Replace curl shell invocation with Zig's http client. 😎
Properly handle "host unreachable" (EHOSTUNREACH) on Linux, instead of returning unexpected
error.
#2443, #2451, #2459, #2460, #2465
Various code refactorings to improve naming conventions, readability, and organization.
Make Grid.reserve() abort rather than returning null. When Grid.reserve() aborts, that indicates that the data file size limit would be exceeded by th
Released: 2024-10-28
Make Grid.reserve() abort rather than returning null.
When Grid.reserve() aborts, that indicates that the data file size limit would be exceeded by
the reservation. We were already panicking in this case by unwrapping the result, but now it has
a useful error message.
Improve availability and performance by sending start_view message earlier in the new-primary
recovery – as soon as the journal headers are repaired.
Refactor compaction to clarify the scheduling logic, schedule more aggressively, and make it easier to run multiple compactions concurrently. This also improved the benchmark performance.
Support multiversion (non-automatic) upgrades when the replica is started with --development
or --experimental.
Allow a release's Git tag and config.process.release to differ. This simplifies the release
process for hotfixes, when the Git tag is bumped but the config.process.release is unchanged.
Improve performance & availability during view change by ensuring a replica only repairs the portion of the WAL that is *required* to become primary,
Released: 2024-10-21
Improve performance & availability during view change by ensuring a replica only repairs the portion of the WAL that is required to become primary, instead of repairing it in its entirety.
Add a unit test for Zig's stdlib sort.
Stable sort is critical for compaction correctness. Zig stdlib does have a sort fuzz test, but it doesn't cover the presorted subarray case, and doesn't check arrays much larger than the sort algorithm's on-stack cache.
Fix a bug in the MessageBus wherein connections weren't being terminated during client teardown.
Fix a bug in the benchmark wherein the usage of --account-count-hot was broken when used in
conjunction with the uniform distribution.
Revamp the core_missing_prepares liveness-mode check to correctly check for the prepares that a
replica should repair (after #2414).
TigerBeetle clients internally batch operations for improved performance. Fix a bug where an unclosed link chain could be batched before another linke
Released: 2024-10-15
TigerBeetle clients internally batch operations for improved performance. Fix a bug where an unclosed link chain could be batched before another linked chain, causing them to be treated as one long linked chain. Additionally, prevent non-batchable requests from sharing packets entirely.
AMOUNT_MAX is used as a sentinel value for things like balancing transfers to specify moving
as much as possible. Correct and fix its value in the Java client. Thanks @tKe!
Improve the benchmark by adding Zipfian distributed random numbers, to better simulate realistic conditions and as a precursor to approximating YCSB.
Previously, TigerBeetle's clients disallowed empty batches locally, before the request was even sent to the cluster. However, this is actually a valid protocol message - even if it's not used by the current state machine - so allow empty batches to be sent from clients.
Revamp client documentation so that each snippet is self-contained, and standardize it across all languages.
Give the DevHub a fresh coat of paint, and fix passing seeds being blue in dark mode.
#2408, #2400, #2391, #2399, #2402, #2385
Improve VOPR logging and fix a few failing seeds.
Significantly reduced P100 latency by incrementally spreading the mutable table's sort during compaction. This leverages the optimization of sort algo
Released: 2024-10-07
Significantly reduced P100 latency by incrementally spreading the mutable table's sort during compaction. This leverages the optimization of sort algorithms for processing sequences of already sorted sub-arrays.
Improve the workload generator to support concurrent tests with different ledgers.
Fix VOPR seeds. For more awesome details about the backstory and solutions to these issues, please refer to the PR.
Update the REPL to support representing the maximum integer value as -0,
serving as the AMOUNT_MAX sentinel.
Additionally, other negative values such as -1 can be used to represent maxInt - 1.
Also, include support for hexadecimal numbers for more convenient inputting of GUID/UUID
literals (e.g. 0xa1a2a3a4_b1b2_c1c2_d1d2_e1e2e3e4e5e6).
Allow the timestamp field to be set, enabling the REPL to be used for imported events.
Use zig fetch as a replacement for downloading files, removing dependence on external tools.
Port of Rust's dbg! macro to Zig,
and the corresponding CI validation to prevent code using it from being merged into main! 😎
Verify the release versions included in the multiversion binary pack at build time (not only
during runtime) and improve the tigerbeetle version --verbose command's multiversion output.
Fix a multiversioning issue where the binary size exceeded the read buffer, failing to parse the executable header.
Consistently use transient_error instead of transient_failure and cleanup the StateMachine
code.
Add missing links to the operations query_accounts and query_transfers in the documentation
and include the declaration for QueryFilter and QueryFilterFlags in the tb_client.h header.
Clearer error message when the replica crashes due to a data file being too large, instructing the operator to increase the memory allocated for the manifest log.
This release introduces "transient errors": error codes for create_transfers which depend on the state of the database (e.g. exceeds_credits). Going f
Released: 2024-09-30
This release introduces "transient errors": error codes for create_transfers which depend on the
state of the database (e.g. exceeds_credits). Going forward, a transfer that fails with a
transient error will not succeed if retried.
See the API tracking issue and the documentation for more details.
Reduce chance of recovering_head status by recovering from torn writes in the WAL.
This improves the availability of the cluster, as recovering_head replicas cannot participate in
consensus until after they repair.
Ensure idempotence for create_transfers' "transient errors" with new result code
id_already_failed. In particular, this guards against surprising behavior when the client is
running in a stateless API service.
Improve cluster availability by more aggressive recovery for crashes that happen while a replica is checkpointing.
Released: 2024-09-23
Improve cluster availability by more aggressive recovery for crashes that happen while a replica is checkpointing.
Add a more efficient recipe for balance-conditional transfers. A balance-conditional transfer is a transfer that succeeds only if the source account has more than a threshold amount of funds in it.
Add a new recipe for enforcing debits_must_not_exceed_credits on some subset of transfers (this
is a special case of a balance-conditional transfer, with the threshold value being equal to
transferred amount).
Add triaged issue label to prevent newly opened issues from slipping through the cracks.
Add CI check for dead code.
Cleanup the source tree by removing top-level tools directory.
Make sure that process-spawning API used for build-time "scripting" consistently reports errors when the subprocess fails or hangs.
Tighten up the VSR assertions so the transition to .recovering_head can only be called from the .recovering status.
Released: 2024-09-16
Tighten up the VSR assertions so the transition to .recovering_head can only be called from the
.recovering status.
Make the primary abdicate if it is unable to process requests due to a broken clock.
Smoke integration test using the real multiversion binary.
Workload generator based on the Java client to be used in integration tests (i.e. Antithesis).
#2298, #2307, #2304, #2309, #2321
Remove Tracy integration and dependencies.
Add JSON traces for events with multiple running instances, such as IO, lookups, and scans.
Add the ability to filter by user_data_{128,64,32} and code in get_account_transfers
and get_account_balances.
Mute the log on stderr when building client libraries.
Reduce the log's severity of some entries logged as .err to .warn for less noise when
running with log_level = .err.
Document and explain how time works in TigerBeetle ⏱️.
Refactor Forest.compact and remove some dead code.
Rewrite commit_dispatch, a chain of asynchronous stages calling each other, as a state machine
implementation that resembles linear control flow that is much easier to read.
Fix the Node.js example that was using an incorrect enum flag. Thanks for the heads up @jorispz!
Update outdated scripts in HACKING.md.
Use git timestamps to build Docker images. This is a requirement for being deterministic in CI.
Devhub link to pending code reviews.
Improve view change efficiency; new heuristic for lagging replicas to forfeit view change.
Released: 2024-09-09
Improve view change efficiency; new heuristic for lagging replicas to forfeit view change.
A lagging replicas first gives a more up-to-date replica a chance to become primary by forfeiting view change. If the more up-to-date replica cannot step up as primary, the lagging replica attempts to step up as primary.
Complete rollout of the new state sync protocol.
Remove in-code remnants of the old state sync protocol. Replicas now panic if they receive messages belonging to the old protocol.
Improve log warnings for client eviction due to its version being too low/high.
Fix VOPR false positive wherein checkpoint was being updated twice in the upgrade path.
Fix typos found using codespell.
Document example for debiting multiple accounts and crediting a single account wherein the total amount to transfer to the credit account is known, but the balances of the individual debit accounts are not known.
Document the behavior of user_data_128/user_data_64/user_data_32 in the presence of pending
transfers.
Inline Dockerfile in the release code, removing tools/docker/Dockerfile.
Add support for tracing IO & CPU events. This allows for coarse-grained performance analysis, for example collectively profiling IO and CPU performance (as opposed to IO or CPU in isolation).
Remove explicit header sector locks, using a common locking path for prepare and header sectors.
Change CliArgs -> CLIArgs in accordance with TigerStyle.
Vendor llvm-objcopy in the dependencies
repository in accordance with our "no dependencies" policy. This ensures users don't have to
manually install LLVM.
Assign correct date to the release binary date; it was earlier set to the epoch ("Jan 1 1970").
Introduce fatal errors for crashing the replica process in the face of uncorrectable errors (for example, insufficient memory/storage).
Add formatting check in the CI for the Go client.
Reduce dimensionality of configuration modes.
Removes the development configuration which was used to run the replica with asserts enabled, enabling asserts for the production configuration instead. Additionally, removes the -Dconfig CLI option, making production configuration the default.
…value in such cases. Note that this is a breaking change.
Released: 2024-09-02
This release is 0.16.0 as it includes a new breaking API change around zero amount transfers, as well as the behavior around posting a full pending transfer amount or balancing as much as possible. These are all gated by the client's release version.
If you're running a client older than 0.16.0, you'll see the old behavior where zero amount transfers are disallowed, but on newer clients these are supported and will create a transfer with an amount of 0.
Additionally, the sentinel value to representing posting the full amount of a pending transfer, or
doing a balancing transfer for as much as possible has changed. It's no longer 0, but instead
AMOUNT_MAX.
See the tracking issue for more details.
Change how replicas that haven't finished syncing send a prepare_ok message,
preventing them from falsely contributing to the durability of a checkpoint, which could
potentially cause liveness issues in the event of storage faults.
The new state sync protocol regressed the behavior where the replica would try to repair the WAL before switching to state sync, and this puts the old behavior back in.
WAL repair is used when the lagging replica's log still intersects with the cluster's current log, while state sync is used when the logs no longer intersect.
Try to repair (but not commit) prepares, even if we don't have all the headers between checkpoint and head.
This makes things consistent between the normal and repair paths, and improves concurrency while repairing.
Reject prepares on the primary if its view isn't durable, much like solo clusters.
This solves a failing VOPR seed wherein a primary accepting prepares before making its log_view durable exposes a break in its hash chain.
A few sysctls and security frameworks (e.g., seccomp) might block io_uring. Print out a more
helpful error message, rather than a generic "permission denied" or "system outdated".
Add the new imported flag to allow user-defined timestamps when creating
Accounts and Transfers from historical events.
Allow Transfers with amount=0 and change behavior for balancing and post-pending
transfers, introducing the constant AMOUNT_MAX to replace the use of the zero sentinel when
representing the maximum/original value in such cases. Note that this is a
breaking change.
Also, explicitly define optional indexes, which previously were determined simply by not indexing zeroed values.
Introduce a new flag, Account.flags.closed, which causes an account to reject any further
transfers, except for voiding two-phase transfers that are still pending.
The account flag can be set during creation or through a closing transfer. In the latter case, closed account can be re-opened by voiding or expiring the closing transfer.
Deprecates the old state sync protocol, no longer supporting both protocols simultaneously. As planned for this release, it only ignores old messages, allowing replicas to upgrade normally. In the next release, replicas would panic if they receive an old message.
Move multiversion build logic into build.zig from release.zig. This makes it much easier to
build multiversion binaries as part of a regular zig build, without having to invoke CI or
release process specific code that's normally part of release.zig.
It also makes it possible to build multiversion binaries on platforms that aren't x86_64 Linux.
Refactor the Multiversion API, bringing it in line with pre-existing code patterns.
Previously, TigerBeetle release numbers were based on a finicky conversion of GitHub's internal action run number to a version number.
This was error prone, and difficult to reason about before hand (what would the given version number for a release be?). Instead, make it so this very changelog is the source of truth for the version number which is explicitly set.
Change init function signatures to allow for in-place initialization. This addresses the silent
stack growth caused by intermediate copy/move allocations during the initialization of large
objects.
Specifically, the Forest struct can grow indefinitely depending on the number of
Grooves/IndexTrees needed to support the StateMachine's custom logic, causing TigerBeetle to
crash during startup due to stack-overflow.
Don't cancel in-progress GitHub actions on the main branch. In particular, this ensures that the devhub records the benchmark measurements for every merge to main, even if those merges occur in quick succession.
Make the experimental feature aof (append-only file) a runtime flag instead of a build-time
setting. This simplifies operations, allowing the use of the same standard release binary in
environments that require aof.
Renames the LSM constant lsm_batch_multiple to lsm_compaction_ops, providing clearer meaning
on how it relates to the pace at which LSM tree compaction is triggered.
Add support for indexing flags, namely the new imported flag.
Add new state sync protocol, fixing a couple of liveness issues. State sync is now performed as part of the view change.
Released: 2024-08-19
Add new state sync protocol, fixing a couple of liveness issues. State sync is now performed as part of the view change.
Major state sync performance improvements.
Ensure u128 (and related type) consistency across client implementations.
Fix multiversioning builds for aarch64 macOS.
Automatically include oldest supported releases in release notes.
Refactor build.zig to break up the biggest function in the codebase.
Minor improvements to zig install scripts.
Highlight of this release is fully rolled-out support for multiversion binaries. This means that, from now on, the upgrade procedure is going to be as
Released: 2024-08-12
Highlight of this release is fully rolled-out support for multiversion binaries. This means that,
from now on, the upgrade procedure is going to be as simple as dropping the new version of
tigerbeetle binary onto the servers. TigerBeetle will take care of restarting the cluster at the
new version when it is appropriate. See https://docs.tigerbeetle.com/operating/upgrading for
reference documentation.
Note that the upgrade procedure from 0.15.3 and 0.15.4 is a bit more involved.
0.15.3, you'll need to stop and restart tigerbeetle binary manually.0.15.4, the binary will stop automatically by hitting an assert. You
should restart it after that.Test client eviction in the VOPR.
Add integration tests for upgrades.
Add more hardening parameters to the suggested systemd unit definition.
Make the root directory smaller by getting rid of scripts and .gitattributes entries.
Root directory is the first thing you see when opening the repository, this space shouldn't be
wasted!
Complete the integration of multiversion binaries with the release infrastructure. From now on, the upgrade procedure is as simple as replacing the binary on disk with a new version. TigerBeetle will take care of safely and seamlessly restarting the cluster when appropriate itself.
Prepare to rollout the new state sync protocol. Stay tuned for the next release!
Simplify iteration over an LSM tree during scans.
Fix addresses logging in the client regressed by #2164.
Modernize scripts to generate client bindings to follow modern idioms for build.zig.
Fix typo in the currency exchange example.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →