Skip to content

chore: Bump the orleans group with 2 updates - #1654

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/nuget/benchmarks/comparison/orleans/orleans-0ecd5ebf0f
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/nuget/benchmarks/comparison/orleans/orleans-0ecd5ebf0f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Updated Microsoft.Orleans.Sdk from 10.3.1 to 10.4.0.

Release notes

Sourced from Microsoft.Orleans.Sdk's releases.

10.4.0

This release strengthens cluster membership consistency, extends cooperative cancellation across framework APIs, and gives streaming applications more control over subscription start positions and dequeue sizes. This release also fixes SQLite persistence under contention, modernizes request-latency metrics, improves serialization and source-generation efficiency, and expands the preview journaling and Durable Jobs capabilities.

Compatibility and upgrade notes

[!IMPORTANT]
Review the SQLite query updates and metric schema changes when upgrading.

  • Refresh existing SQLite persistence queries (#​11354). SQLite writes now use a single implicit transaction, preserving atomicity and durable clears when pooled connections encounter writer contention. Reapply the 10.4.0 SQLite main script and SQLite persistence script to existing databases to install the corrected queries. Both scripts are idempotent and preserve grain state.
  • Update request-latency dashboards and exporter configuration (#​11251). Application request latency is now a standard Histogram<double> named orleans-app-requests-latency, measured in fractional milliseconds. It replaces the separate orleans-app-requests-latency-bucket, -count, and -sum instruments and their duration attribute. Configure histogram boundaries through an OpenTelemetry View and update dashboards, alerts, and recording rules for the exporter representation. Use matching boundaries across instances whose distributions are aggregated.
  • Use canonical grain-type metric dimensions (#​11253). orleans-grains now uses grain_type, containing the canonical GrainId.Type identity, in place of type, which contained the CLR implementation name. Activation lifecycle metrics also gain this dimension. Update queries and label filters accordingly.
  • Review explicitly numbered RPC parameters (#​11179). RPC parameter [Id] attributes now control serialized argument IDs, and automatic IDs count serialized parameters. Place CancellationToken last. Existing contracts with parameter [Id] attributes or non-last cancellation tokens can change argument wire IDs relative to 10.3.1; coordinate their client/silo contract upgrade or introduce versioned contracts. Method-level [Id] attributes and ordinary unannotated, token-last contracts retain their existing identities and argument numbering.
  • Review preview journaling API changes (#​11211, #​11276, #​11319). Journaling and Durable Jobs packages continue as 10.4.0-alpha.1. Custom integrations should adopt the updated durable-state/state-machine contracts and streamed catalog enumeration APIs. Named-provider migration is an opt-in capability for moving Durable Jobs between storage backends; existing default-provider convenience registrations remain available.

Highlights

Runtime, clustering, and reminders

  • Consistent membership across providers. Core membership and the Azure Storage, Cosmos DB, DynamoDB, Consul, Redis, Cassandra, Firestore, ADO.NET, and ZooKeeper implementations strengthen atomic updates, canonical snapshots, and heartbeat handling. ZooKeeper preserves consistent snapshot reads under contention, and Firestore preserves atomic membership reads (#​11307, #​11309, #​11317, #​11342, #​11387).
  • Cancellation-aware framework contracts. Trailing cancellation tokens flow through runtime, reminder, streaming, transaction, management, and other framework operations. Legacy overloads and stable wire aliases preserve existing implementations and established framework call identities (#​10937).
  • More efficient manifest retrieval. Content-addressed retrieval is enabled by default, allowing silos to reuse immutable manifests by canonical SHA-256 hash and repair missing metadata from peers. ClusterManifestOptions.EnableContentAddressedRetrieval selects the retrieval mode (#​11239).
  • Stronger lifecycle handling. Shutdown drains admitted connection-establishment and client-observer work; reminder startup and topology reconciliation are better ordered; directory recovery deactivates duplicate activations; and idle migrated activations are collected (#​11263, #​11264, #​11118, #​11030, #​11365).

Streaming

  • Choose where subscriptions begin. StreamSubscriptionStartPosition.Latest and EarliestAvailable provide per-subscription control, with a provider default through StreamPullingAgentOptions.InitialSubscriptionStartPosition. EarliestAvailable starts at the oldest retained message for the stream in the local queue cache. An explicit sequence token takes precedence, and Latest remains the default. Enable the new controls after pulling-agent silos have been upgraded (#​10936).
  • Better recovery and handoffs. Typed cache-cursor results, provider-encoded offsets, and a reusable checkpoint state machine improve provider recovery. SQS and Azure Queue handoffs release messages, recovery preserves prefetched batches and pooled-buffer ownership, and pulling agents drain detached work during shutdown (#​9714, #​11153, #​11154, #​11062, #​11144, #​11268).
  • Tune memory-stream dequeue sizes. Per-provider MemoryStreamCacheOptions.MaxAddCount controls the maximum number of queue records requested per dequeue, allowing applications to balance response size and queue-call overhead. The default remains 100 (#​11238).

Persistence and transactions

  • SQLite persistence returns scalar versions and recovers cleanly from writer contention. Relational providers also receive normalized integer reads, corrected PostgreSQL persistence scripts, and Oracle defunct-silo cleanup support (#​11322, #​11354, #​11283, #​11247, #​11246).
  • Transaction participant locks honor transaction timeouts, aborted queued lock operations are removed, and recovery cleanup tasks are awaited (#​10457, #​10455, #​11188).
  • DynamoDB providers honor configured endpoint credentials, bind token and profile options, and redact tokens in logs. Provider configuration validation and invariant text handling are strengthened across storage and clustering integrations (#​11292, #​11290, #​11288).

Preview journaling and Durable Jobs

  • S3 Express One Zone journal storage. Microsoft.Orleans.Journaling.S3 adds append-based write-ahead logs, conditional metadata/checkpoint publication, catalog discovery, and provider metrics. A conditional-rewrite mode supports S3-compatible development environments (#​10161).
  • Composable, named journal providers. Grains can compose durable state through the updated APIs, while named providers bind storage, catalogs, and state-manager factories together. Catalog enumeration streams results, and recovery serializes retries while preserving persistence failures (#​11279, #​11275, #​11211, #​11326).
  • Controlled Durable Jobs provider migration. Select an active provider for new shards and draining providers for existing jobs, inspect storage before retirement, and retain saved job handles across the cutover. Shard discovery uses start-time ordering, and shutdown drains scheduling and releases running shards. Queue wake-ups and flush signals are coalesced (#​11277, #​11258, #​11301, #​11103, #​11206).

Serialization, code generation, and deployment

  • Improved NativeAOT building blocks. Generated C# codecs and copiers use ref-returning UnsafeAccessor methods for private, readonly, and backing fields on supported targets. Grain activation constructors are preserved, non-generic grain references gain native construction, and serialization constructors can initialize existing objects under NativeAOT. Default serializer activation uses a shared construction path with consistent exception propagation (#​11372, #​11383, #​11371, #​11373, #​11390).
  • Opt-in serializer Hot Reload. Set <OrleansHotReload>true</OrleansHotReload> to generate stable member/dependency identities and lazily initialize dependencies added to existing serializers and copiers. Supported updates add strongly typed serialized members to classes and records; restart to refresh manifests when adding new polymorphic or collection-element types (#​10932).
  • Correct compound-aliased array resolution. Polymorphic arrays and arrays nested in closed generic types deserialize correctly, with the existing writer bytes preserved (#​11392).
  • Less repeated work and copying. The generator caches library types per compilation, serialization-attribute analysis skips generated code, contiguous JSON payloads are read directly, and buffered tail reads avoid repeated page traversal. Metadata discovery also supports single-file deployment (#​11363, #​11384, #​11270, #​11209, #​11054).

Observability and developer tooling

  • Request latency uses native histogram aggregation, while canonical, cached grain-type dimensions make activation populations and lifecycle events easier to correlate (#​11251, #​11253).
    ... (truncated)

Commits viewable in compare view.

Updated Microsoft.Orleans.Server from 10.3.1 to 10.4.0.

Release notes

Sourced from Microsoft.Orleans.Server's releases.

10.4.0

This release strengthens cluster membership consistency, extends cooperative cancellation across framework APIs, and gives streaming applications more control over subscription start positions and dequeue sizes. This release also fixes SQLite persistence under contention, modernizes request-latency metrics, improves serialization and source-generation efficiency, and expands the preview journaling and Durable Jobs capabilities.

Compatibility and upgrade notes

[!IMPORTANT]
Review the SQLite query updates and metric schema changes when upgrading.

  • Refresh existing SQLite persistence queries (#​11354). SQLite writes now use a single implicit transaction, preserving atomicity and durable clears when pooled connections encounter writer contention. Reapply the 10.4.0 SQLite main script and SQLite persistence script to existing databases to install the corrected queries. Both scripts are idempotent and preserve grain state.
  • Update request-latency dashboards and exporter configuration (#​11251). Application request latency is now a standard Histogram<double> named orleans-app-requests-latency, measured in fractional milliseconds. It replaces the separate orleans-app-requests-latency-bucket, -count, and -sum instruments and their duration attribute. Configure histogram boundaries through an OpenTelemetry View and update dashboards, alerts, and recording rules for the exporter representation. Use matching boundaries across instances whose distributions are aggregated.
  • Use canonical grain-type metric dimensions (#​11253). orleans-grains now uses grain_type, containing the canonical GrainId.Type identity, in place of type, which contained the CLR implementation name. Activation lifecycle metrics also gain this dimension. Update queries and label filters accordingly.
  • Review explicitly numbered RPC parameters (#​11179). RPC parameter [Id] attributes now control serialized argument IDs, and automatic IDs count serialized parameters. Place CancellationToken last. Existing contracts with parameter [Id] attributes or non-last cancellation tokens can change argument wire IDs relative to 10.3.1; coordinate their client/silo contract upgrade or introduce versioned contracts. Method-level [Id] attributes and ordinary unannotated, token-last contracts retain their existing identities and argument numbering.
  • Review preview journaling API changes (#​11211, #​11276, #​11319). Journaling and Durable Jobs packages continue as 10.4.0-alpha.1. Custom integrations should adopt the updated durable-state/state-machine contracts and streamed catalog enumeration APIs. Named-provider migration is an opt-in capability for moving Durable Jobs between storage backends; existing default-provider convenience registrations remain available.

Highlights

Runtime, clustering, and reminders

  • Consistent membership across providers. Core membership and the Azure Storage, Cosmos DB, DynamoDB, Consul, Redis, Cassandra, Firestore, ADO.NET, and ZooKeeper implementations strengthen atomic updates, canonical snapshots, and heartbeat handling. ZooKeeper preserves consistent snapshot reads under contention, and Firestore preserves atomic membership reads (#​11307, #​11309, #​11317, #​11342, #​11387).
  • Cancellation-aware framework contracts. Trailing cancellation tokens flow through runtime, reminder, streaming, transaction, management, and other framework operations. Legacy overloads and stable wire aliases preserve existing implementations and established framework call identities (#​10937).
  • More efficient manifest retrieval. Content-addressed retrieval is enabled by default, allowing silos to reuse immutable manifests by canonical SHA-256 hash and repair missing metadata from peers. ClusterManifestOptions.EnableContentAddressedRetrieval selects the retrieval mode (#​11239).
  • Stronger lifecycle handling. Shutdown drains admitted connection-establishment and client-observer work; reminder startup and topology reconciliation are better ordered; directory recovery deactivates duplicate activations; and idle migrated activations are collected (#​11263, #​11264, #​11118, #​11030, #​11365).

Streaming

  • Choose where subscriptions begin. StreamSubscriptionStartPosition.Latest and EarliestAvailable provide per-subscription control, with a provider default through StreamPullingAgentOptions.InitialSubscriptionStartPosition. EarliestAvailable starts at the oldest retained message for the stream in the local queue cache. An explicit sequence token takes precedence, and Latest remains the default. Enable the new controls after pulling-agent silos have been upgraded (#​10936).
  • Better recovery and handoffs. Typed cache-cursor results, provider-encoded offsets, and a reusable checkpoint state machine improve provider recovery. SQS and Azure Queue handoffs release messages, recovery preserves prefetched batches and pooled-buffer ownership, and pulling agents drain detached work during shutdown (#​9714, #​11153, #​11154, #​11062, #​11144, #​11268).
  • Tune memory-stream dequeue sizes. Per-provider MemoryStreamCacheOptions.MaxAddCount controls the maximum number of queue records requested per dequeue, allowing applications to balance response size and queue-call overhead. The default remains 100 (#​11238).

Persistence and transactions

  • SQLite persistence returns scalar versions and recovers cleanly from writer contention. Relational providers also receive normalized integer reads, corrected PostgreSQL persistence scripts, and Oracle defunct-silo cleanup support (#​11322, #​11354, #​11283, #​11247, #​11246).
  • Transaction participant locks honor transaction timeouts, aborted queued lock operations are removed, and recovery cleanup tasks are awaited (#​10457, #​10455, #​11188).
  • DynamoDB providers honor configured endpoint credentials, bind token and profile options, and redact tokens in logs. Provider configuration validation and invariant text handling are strengthened across storage and clustering integrations (#​11292, #​11290, #​11288).

Preview journaling and Durable Jobs

  • S3 Express One Zone journal storage. Microsoft.Orleans.Journaling.S3 adds append-based write-ahead logs, conditional metadata/checkpoint publication, catalog discovery, and provider metrics. A conditional-rewrite mode supports S3-compatible development environments (#​10161).
  • Composable, named journal providers. Grains can compose durable state through the updated APIs, while named providers bind storage, catalogs, and state-manager factories together. Catalog enumeration streams results, and recovery serializes retries while preserving persistence failures (#​11279, #​11275, #​11211, #​11326).
  • Controlled Durable Jobs provider migration. Select an active provider for new shards and draining providers for existing jobs, inspect storage before retirement, and retain saved job handles across the cutover. Shard discovery uses start-time ordering, and shutdown drains scheduling and releases running shards. Queue wake-ups and flush signals are coalesced (#​11277, #​11258, #​11301, #​11103, #​11206).

Serialization, code generation, and deployment

  • Improved NativeAOT building blocks. Generated C# codecs and copiers use ref-returning UnsafeAccessor methods for private, readonly, and backing fields on supported targets. Grain activation constructors are preserved, non-generic grain references gain native construction, and serialization constructors can initialize existing objects under NativeAOT. Default serializer activation uses a shared construction path with consistent exception propagation (#​11372, #​11383, #​11371, #​11373, #​11390).
  • Opt-in serializer Hot Reload. Set <OrleansHotReload>true</OrleansHotReload> to generate stable member/dependency identities and lazily initialize dependencies added to existing serializers and copiers. Supported updates add strongly typed serialized members to classes and records; restart to refresh manifests when adding new polymorphic or collection-element types (#​10932).
  • Correct compound-aliased array resolution. Polymorphic arrays and arrays nested in closed generic types deserialize correctly, with the existing writer bytes preserved (#​11392).
  • Less repeated work and copying. The generator caches library types per compilation, serialization-attribute analysis skips generated code, contiguous JSON payloads are read directly, and buffered tail reads avoid repeated page traversal. Metadata discovery also supports single-file deployment (#​11363, #​11384, #​11270, #​11209, #​11054).

Observability and developer tooling

  • Request latency uses native histogram aggregation, while canonical, cached grain-type dimensions make activation populations and lifecycle events easier to correlate (#​11251, #​11253).
    ... (truncated)

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Microsoft.Orleans.Sdk from 10.3.1 to 10.4.0
Bumps Microsoft.Orleans.Server from 10.3.1 to 10.4.0

---
updated-dependencies:
- dependency-name: Microsoft.Orleans.Sdk
  dependency-version: 10.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: orleans
- dependency-name: Microsoft.Orleans.Server
  dependency-version: 10.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: orleans
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants