---
title: "Release 2026-08-29 - Changelog"
url: "https://nsta1.github.io/Orleans.Lattice/changelog/2026-08-29.html"
source: "https://github.com/NSTA1/Orleans.Lattice/blob/release/9.9/CHANGELOG.md?plain=1#L1447-L1450"
documents: "Orleans.Lattice 9.9.0 (release line 9.9)"
built: "2026-10-04"
all-pages: "https://nsta1.github.io/Orleans.Lattice/llms.txt"
---
# Release 2026-08-29

Part of the [changelog](../CHANGELOG.md).

A coordinated lockstep release advances the whole published package family to `9.4.0`: every `Orleans.Lattice` and `Orleans.Lattice.*` package on the v9 line moves to `9.4.0` together. The headline is the **first release of the multi-tenancy family** - `Orleans.Lattice.Tenancy`, `Orleans.Lattice.Api.TenantAdmin`, and `Orleans.Lattice.Api.TenantAdmin.Grpc` all debut here - which partitions the keyspace into isolated tenants with their own durable registry, quotas and rate limiting, and a fail-closed operator control plane reachable in-process, over gRPC, or from an AI agent over MCP. It spans a multi-cluster deployment rather than stopping at one cluster: quotas admit against either a cluster-converged or a per-cluster enforcement scope, usage folds across clusters, and optional per-tenant region residency governs where a tenant's data may live and replicate; a cluster that does not reference the new packages is byte-for-byte unchanged. Riding along on the existing packages: a public `LatticeKeyRange.PrefixUpperBound` helper and resilient streaming scans for materialised views; throughput work on the catalog and enumeration paths (registry-scoped tree-id enumeration, batched catalog paging) plus allocation trims on the CRDT merge and multi-key batch hot paths; a batch of CRDT convergence, buffer-ownership, and contract fixes across the RGA sequence, OR-map, bounded-register, and multi-value register primitives, including a vector-clock aliasing fix on the co-located `[Immutable]` grain-call path, with both the buffer-ownership contract and that grain-boundary copy elision now held closed by reflection-driven contract guards so a future primitive cannot join the family without picking them up; correctness fixes on the read and administration paths, where tools documented read-only silently provisioned the tree they were asked to read, durable-history retention modes were configured but never enforced, and a view drop was non-idempotent; and a set of security fixes, headed by closing an unauthorized tree-metadata and existence disclosure on the core facade grain (several read verbs reached the registry with no access-gate call at all), alongside MCP region discovery, the Explorer's per-circuit selection state, the Entra Graph directory search, the replication batch-apply merge algebra and framing decoder, and the tree-admin view-creation and cross-tree merge authorization seams. A second wave the same day advances three of those packages one patch digit to `9.4.1` - `Orleans.Lattice`, `Orleans.Lattice.Api.TreeAdmin`, and `Orleans.Lattice.Dashboards` - while every other published package stays at `9.4.0`. It carries an allocation trim on the materialised-view maintenance hashing path; four tree-lifecycle and leaf-activation fixes, two of which unwedge a tree that could previously be left permanently un-activatable after a replay-budget overrun or permanently unwritable after an interrupted purge, alongside a resize-undo that now compensates while the resize is still running and an actionable typed exception in place of an opaque argument fault when a leaf takes a CRDT write before its shard root has bound it; and access-gate hardening that closes an unauthorized read of tree state and a value disclosure across six in-cluster core facade verbs, with the tree-admin status projections re-scoped so a lifecycle-only grant can no longer be denied after the mutation it authorized has already landed. A third wave the same day advances `Orleans.Lattice` alone one further patch digit to `9.4.2`, completing the interrupted-purge repair that shipped in `9.4.1`: a tree left with a routable-but-unbound leaf now heals itself on its next typed CRDT write, so a deployment already stranded no longer needs an operator to run a delete/recover cycle over live production data to get writable again, the damage no longer spreads across the key range through splits, and recovery's own re-assert no longer infers a whole shard's health from its leftmost leaf. Every other published package stays where the earlier waves left it. The not-yet-published `Orleans.Lattice.Api.Mcp.RepoContext`, `Orleans.Lattice.Api.Mcp.RepoContext.Replication`, and `Orleans.Lattice.Storage.File` packages remain unreleased and stay at `8.0.0`.

## Releases

- [Added to Changed](../changelog/2026-08-29-1.md)
- [Fixed](../changelog/2026-08-29-2.md)
- [Security](../changelog/2026-08-29-3.md)

Newer release: [Release 2026-08-31](../changelog/2026-08-31.md). Older release: [Release 2026-08-29: Added to Changed](../changelog/2026-08-29-1.md). Contents: [Changelog](../CHANGELOG.md).
