Table of Contents

Release 2026-08-29

This page is part of the documentation for Orleans.Lattice 9.9.0 (release line 9.9), built 2026-10-04. It is also published as markdown, with every table and list, at 2026-08-29.md, and llms.txt lists every page.

Part of the changelog.

A coordinated lockstep release advances the whole published package family to 9.4.0: every Orleans.Lattice and Orleans.Lattice.* package on the v9 line moves to 9.4.0 together. The headline is the first release of the multi-tenancy family - Orleans.Lattice.Tenancy, Orleans.Lattice.Api.TenantAdmin, and Orleans.Lattice.Api.TenantAdmin.Grpc all debut here - which partitions the keyspace into isolated tenants with their own durable registry, quotas and rate limiting, and a fail-closed operator control plane reachable in-process, over gRPC, or from an AI agent over MCP. It spans a multi-cluster deployment rather than stopping at one cluster: quotas admit against either a cluster-converged or a per-cluster enforcement scope, usage folds across clusters, and optional per-tenant region residency governs where a tenant's data may live and replicate; a cluster that does not reference the new packages is byte-for-byte unchanged. Riding along on the existing packages: a public LatticeKeyRange.PrefixUpperBound helper and resilient streaming scans for materialised views; throughput work on the catalog and enumeration paths (registry-scoped tree-id enumeration, batched catalog paging) plus allocation trims on the CRDT merge and multi-key batch hot paths; a batch of CRDT convergence, buffer-ownership, and contract fixes across the RGA sequence, OR-map, bounded-register, and multi-value register primitives, including a vector-clock aliasing fix on the co-located [Immutable] grain-call path, with both the buffer-ownership contract and that grain-boundary copy elision now held closed by reflection-driven contract guards so a future primitive cannot join the family without picking them up; correctness fixes on the read and administration paths, where tools documented read-only silently provisioned the tree they were asked to read, durable-history retention modes were configured but never enforced, and a view drop was non-idempotent; and a set of security fixes, headed by closing an unauthorized tree-metadata and existence disclosure on the core facade grain (several read verbs reached the registry with no access-gate call at all), alongside MCP region discovery, the Explorer's per-circuit selection state, the Entra Graph directory search, the replication batch-apply merge algebra and framing decoder, and the tree-admin view-creation and cross-tree merge authorization seams. A second wave the same day advances three of those packages one patch digit to 9.4.1 - Orleans.Lattice, Orleans.Lattice.Api.TreeAdmin, and Orleans.Lattice.Dashboards - while every other published package stays at 9.4.0. It carries an allocation trim on the materialised-view maintenance hashing path; four tree-lifecycle and leaf-activation fixes, two of which unwedge a tree that could previously be left permanently un-activatable after a replay-budget overrun or permanently unwritable after an interrupted purge, alongside a resize-undo that now compensates while the resize is still running and an actionable typed exception in place of an opaque argument fault when a leaf takes a CRDT write before its shard root has bound it; and access-gate hardening that closes an unauthorized read of tree state and a value disclosure across six in-cluster core facade verbs, with the tree-admin status projections re-scoped so a lifecycle-only grant can no longer be denied after the mutation it authorized has already landed. A third wave the same day advances Orleans.Lattice alone one further patch digit to 9.4.2, completing the interrupted-purge repair that shipped in 9.4.1: a tree left with a routable-but-unbound leaf now heals itself on its next typed CRDT write, so a deployment already stranded no longer needs an operator to run a delete/recover cycle over live production data to get writable again, the damage no longer spreads across the key range through splits, and recovery's own re-assert no longer infers a whole shard's health from its leftmost leaf. Every other published package stays where the earlier waves left it. The not-yet-published Orleans.Lattice.Api.Mcp.RepoContext, Orleans.Lattice.Api.Mcp.RepoContext.Replication, and Orleans.Lattice.Storage.File packages remain unreleased and stay at 8.0.0.

Releases