# AIStor Client RELEASE.2026-09-06T02-44-40Z

Released: 2026-09-08

This release brings `main` up to date with a large batch of client features that
the stable AIStor server already supports: per-table Iceberg maintenance, a new
memory-bandwidth performance test, an ILM expiry tracker, and progress and
watch mode for decommission status. It also fixes a cluster of data
races, shutdown panics and goroutine leaks in `cp`, `mv`, `mirror`, `watch` and
`support`, and clears the last two dependency CVE findings on `main`. Operators
scripting `mc admin cordon --node` or `mc support telemetry` should read
Breaking Changes before upgrading.

---

## Downloads

### Binary Downloads

| Platform | Architecture | Download                                                            |
| -------- | ------------ | ------------------------------------------------------------------- |
| Linux    | amd64        | [mc](https://dl.min.io/aistor/mc/release/linux-amd64/mc)            |
| Linux    | arm64        | [mc](https://dl.min.io/aistor/mc/release/linux-arm64/mc)            |
| macOS    | arm64        | [mc](https://dl.min.io/aistor/mc/release/darwin-arm64/mc)           |
| macOS    | amd64        | [mc](https://dl.min.io/aistor/mc/release/darwin-amd64/mc)           |
| Windows  | amd64        | [mc.exe](https://dl.min.io/aistor/mc/release/windows-amd64/mc.exe)  |

### FIPS Binaries

| Platform | Architecture | Download                                                            |
| -------- | ------------ | ------------------------------------------------------------------- |
| Linux    | amd64        | [mc.fips](https://dl.min.io/aistor/mc/release/linux-amd64/mc.fips)  |

### Package Downloads

| Format | Architecture | Download                                                                                                                        |
| ------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------- |
| DEB    | amd64        | [acli_20260906024440.0.0_amd64.deb](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli_20260906024440.0.0_amd64.deb)   |
| DEB    | arm64        | [acli_20260906024440.0.0_arm64.deb](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli_20260906024440.0.0_arm64.deb)   |
| RPM    | amd64        | [acli-20260906024440.0.0-1.x86_64.rpm](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli-20260906024440.0.0-1.x86_64.rpm)   |
| RPM    | arm64        | [acli-20260906024440.0.0-1.aarch64.rpm](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli-20260906024440.0.0-1.aarch64.rpm) |
| APK    | amd64        | [acli_20260906024440.0.0_x86_64.apk](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli_20260906024440.0.0_x86_64.apk)  |
| APK    | arm64        | [acli_20260906024440.0.0_aarch64.apk](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli_20260906024440.0.0_aarch64.apk) |

The installed command remains `mcli`. Legacy `mcli.*` package filenames are
symlinked onto the new `acli-*` packages, so existing download URLs and upgrade
paths keep working — see Improvements.

<details>
<summary>All published assets, including checksums and signatures</summary>

#### darwin-amd64

- [mc](https://dl.min.io/aistor/mc/release/darwin-amd64/archive/mc)
- [mc.RELEASE.2026-09-06T02-44-40Z](https://dl.min.io/aistor/mc/release/darwin-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z)
- [mc.RELEASE.2026-09-06T02-44-40Z.sha256sum](https://dl.min.io/aistor/mc/release/darwin-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.sha256sum)
- [mc.sha256sum](https://dl.min.io/aistor/mc/release/darwin-amd64/archive/mc.sha256sum)
- [mc.RELEASE.2026-09-06T02-44-40Z.asc](https://dl.min.io/aistor/mc/release/darwin-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.asc)
- [mc.RELEASE.2026-09-06T02-44-40Z.minisig](https://dl.min.io/aistor/mc/release/darwin-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.minisig)
- [mc.asc](https://dl.min.io/aistor/mc/release/darwin-amd64/archive/mc.asc)
- [mc.minisig](https://dl.min.io/aistor/mc/release/darwin-amd64/archive/mc.minisig)

#### darwin-arm64

- [mc](https://dl.min.io/aistor/mc/release/darwin-arm64/archive/mc)
- [mc.RELEASE.2026-09-06T02-44-40Z](https://dl.min.io/aistor/mc/release/darwin-arm64/archive/mc.RELEASE.2026-09-06T02-44-40Z)
- [mc.RELEASE.2026-09-06T02-44-40Z.sha256sum](https://dl.min.io/aistor/mc/release/darwin-arm64/archive/mc.RELEASE.2026-09-06T02-44-40Z.sha256sum)
- [mc.sha256sum](https://dl.min.io/aistor/mc/release/darwin-arm64/archive/mc.sha256sum)
- [mc.RELEASE.2026-09-06T02-44-40Z.asc](https://dl.min.io/aistor/mc/release/darwin-arm64/archive/mc.RELEASE.2026-09-06T02-44-40Z.asc)
- [mc.RELEASE.2026-09-06T02-44-40Z.minisig](https://dl.min.io/aistor/mc/release/darwin-arm64/archive/mc.RELEASE.2026-09-06T02-44-40Z.minisig)
- [mc.asc](https://dl.min.io/aistor/mc/release/darwin-arm64/archive/mc.asc)
- [mc.minisig](https://dl.min.io/aistor/mc/release/darwin-arm64/archive/mc.minisig)

#### linux-amd64

- [mc](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc)
- [mc.RELEASE.2026-09-06T02-44-40Z](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z)
- [acli-20260906024440.0.0-1.x86_64.rpm.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli-20260906024440.0.0-1.x86_64.rpm.sha256sum)
- [acli_20260906024440.0.0_amd64.deb.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli_20260906024440.0.0_amd64.deb.sha256sum)
- [acli_20260906024440.0.0_x86_64.apk.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli_20260906024440.0.0_x86_64.apk.sha256sum)
- [mc.RELEASE.2026-09-06T02-44-40Z.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.sha256sum)
- [mc.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.sha256sum)
- [mcli-20260906024440.0.0-1.x86_64.rpm.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli-20260906024440.0.0-1.x86_64.rpm.sha256sum)
- [mcli_20260906024440.0.0_amd64.deb.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli_20260906024440.0.0_amd64.deb.sha256sum)
- [mcli_20260906024440.0.0_x86_64.apk.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli_20260906024440.0.0_x86_64.apk.sha256sum)
- [mc.RELEASE.2026-09-06T02-44-40Z.asc](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.asc)
- [mc.RELEASE.2026-09-06T02-44-40Z.minisig](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.minisig)
- [mc.asc](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.asc)
- [mc.minisig](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.minisig)
- [acli-20260906024440.0.0-1.x86_64.rpm](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli-20260906024440.0.0-1.x86_64.rpm)
- [acli.apk](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli.apk)
- [acli.deb](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli.deb)
- [acli.rpm](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli.rpm)
- [acli_20260906024440.0.0_amd64.deb](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli_20260906024440.0.0_amd64.deb)
- [acli_20260906024440.0.0_x86_64.apk](https://dl.min.io/aistor/mc/release/linux-amd64/archive/acli_20260906024440.0.0_x86_64.apk)
- [mcli-20260906024440.0.0-1.x86_64.rpm](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli-20260906024440.0.0-1.x86_64.rpm)
- [mcli.apk](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli.apk)
- [mcli.deb](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli.deb)
- [mcli.rpm](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli.rpm)
- [mcli_20260906024440.0.0_amd64.deb](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli_20260906024440.0.0_amd64.deb)
- [mcli_20260906024440.0.0_x86_64.apk](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mcli_20260906024440.0.0_x86_64.apk)

#### linux-amd64 (FIPS)

- [mc.RELEASE.2026-09-06T02-44-40Z.fips](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.fips)
- [mc.fips](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.fips)
- [mc.RELEASE.2026-09-06T02-44-40Z.fips.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.fips.sha256sum)
- [mc.fips.sha256sum](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.fips.sha256sum)
- [mc.RELEASE.2026-09-06T02-44-40Z.fips.asc](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.fips.asc)
- [mc.RELEASE.2026-09-06T02-44-40Z.fips.minisig](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.RELEASE.2026-09-06T02-44-40Z.fips.minisig)
- [mc.fips.asc](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.fips.asc)
- [mc.fips.minisig](https://dl.min.io/aistor/mc/release/linux-amd64/archive/mc.fips.minisig)

#### linux-arm64

- [mc](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mc)
- [mc.RELEASE.2026-09-06T02-44-40Z](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mc.RELEASE.2026-09-06T02-44-40Z)
- [acli-20260906024440.0.0-1.aarch64.rpm.sha256sum](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli-20260906024440.0.0-1.aarch64.rpm.sha256sum)
- [acli_20260906024440.0.0_aarch64.apk.sha256sum](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli_20260906024440.0.0_aarch64.apk.sha256sum)
- [acli_20260906024440.0.0_arm64.deb.sha256sum](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli_20260906024440.0.0_arm64.deb.sha256sum)
- [mc.RELEASE.2026-09-06T02-44-40Z.sha256sum](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mc.RELEASE.2026-09-06T02-44-40Z.sha256sum)
- [mc.sha256sum](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mc.sha256sum)
- [mcli-20260906024440.0.0-1.aarch64.rpm.sha256sum](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli-20260906024440.0.0-1.aarch64.rpm.sha256sum)
- [mcli_20260906024440.0.0_aarch64.apk.sha256sum](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli_20260906024440.0.0_aarch64.apk.sha256sum)
- [mcli_20260906024440.0.0_arm64.deb.sha256sum](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli_20260906024440.0.0_arm64.deb.sha256sum)
- [mc.RELEASE.2026-09-06T02-44-40Z.asc](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mc.RELEASE.2026-09-06T02-44-40Z.asc)
- [mc.RELEASE.2026-09-06T02-44-40Z.minisig](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mc.RELEASE.2026-09-06T02-44-40Z.minisig)
- [mc.asc](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mc.asc)
- [mc.minisig](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mc.minisig)
- [acli-20260906024440.0.0-1.aarch64.rpm](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli-20260906024440.0.0-1.aarch64.rpm)
- [acli.apk](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli.apk)
- [acli.deb](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli.deb)
- [acli.rpm](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli.rpm)
- [acli_20260906024440.0.0_aarch64.apk](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli_20260906024440.0.0_aarch64.apk)
- [acli_20260906024440.0.0_arm64.deb](https://dl.min.io/aistor/mc/release/linux-arm64/archive/acli_20260906024440.0.0_arm64.deb)
- [mcli-20260906024440.0.0-1.aarch64.rpm](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli-20260906024440.0.0-1.aarch64.rpm)
- [mcli.apk](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli.apk)
- [mcli.deb](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli.deb)
- [mcli.rpm](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli.rpm)
- [mcli_20260906024440.0.0_aarch64.apk](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli_20260906024440.0.0_aarch64.apk)
- [mcli_20260906024440.0.0_arm64.deb](https://dl.min.io/aistor/mc/release/linux-arm64/archive/mcli_20260906024440.0.0_arm64.deb)

#### windows-amd64

- [mc.exe](https://dl.min.io/aistor/mc/release/windows-amd64/archive/mc.exe)
- [mc.exe.RELEASE.2026-09-06T02-44-40Z](https://dl.min.io/aistor/mc/release/windows-amd64/archive/mc.exe.RELEASE.2026-09-06T02-44-40Z)
- [mc.exe.RELEASE.2026-09-06T02-44-40Z.sha256sum](https://dl.min.io/aistor/mc/release/windows-amd64/archive/mc.exe.RELEASE.2026-09-06T02-44-40Z.sha256sum)
- [mc.exe.sha256sum](https://dl.min.io/aistor/mc/release/windows-amd64/archive/mc.exe.sha256sum)
- [mc.exe.RELEASE.2026-09-06T02-44-40Z.asc](https://dl.min.io/aistor/mc/release/windows-amd64/archive/mc.exe.RELEASE.2026-09-06T02-44-40Z.asc)
- [mc.exe.RELEASE.2026-09-06T02-44-40Z.minisig](https://dl.min.io/aistor/mc/release/windows-amd64/archive/mc.exe.RELEASE.2026-09-06T02-44-40Z.minisig)
- [mc.exe.asc](https://dl.min.io/aistor/mc/release/windows-amd64/archive/mc.exe.asc)
- [mc.exe.minisig](https://dl.min.io/aistor/mc/release/windows-amd64/archive/mc.exe.minisig)

</details>

### Container Images

```bash
# Standard
docker pull quay.io/minio/aistor/mc:RELEASE.2026-09-06T02-44-40Z
podman pull quay.io/minio/aistor/mc:RELEASE.2026-09-06T02-44-40Z

# FIPS
docker pull quay.io/minio/aistor/mc:RELEASE.2026-09-06T02-44-40Z.fips
podman pull quay.io/minio/aistor/mc:RELEASE.2026-09-06T02-44-40Z.fips
```

### Homebrew (macOS/Linux)

```bash
brew install minio/stable/mc
```

---

## Breaking Changes

- **`--node` is removed from `mc admin cordon` and `mc admin uncordon`.** The
  flag was accepted but never read — the target node has always come from the
  alias argument. Scripts still passing `--node` will now fail with an unknown
  flag error rather than silently ignoring it. `mc admin cordon` keeps
  `--no-drain`, whose help text now states plainly that it terminates in-flight
  requests instead of draining first (#521).

- **`mc support telemetry` now samples 1 in 100 calls by default** instead of
  every call. Pass `--sample 100%` to restore the previous behavior. The
  reduction cuts telemetry overhead on busy clusters; raise the rate when
  capturing a short diagnostic window (#586).

---

## Security Updates

- **`github.com/apache/thrift` upgraded to v0.24.0**, resolving
  [CVE-2026-48586](https://nvd.nist.gov/vuln/detail/CVE-2026-48586) and
  [CVE-2026-55969](https://nvd.nist.gov/vuln/detail/CVE-2026-55969) (#613).

- **`golang.org/x/crypto` upgraded to v0.56.0**, resolving two denial-of-service
  advisories against `x/crypto/ssh`:
  [CVE-2026-78662](https://nvd.nist.gov/vuln/detail/CVE-2026-78662)
  (GO-2026-6354) and
  [CVE-2026-56855](https://nvd.nist.gov/vuln/detail/CVE-2026-56855)
  (GO-2026-6355) (4283c2d1).

Both modules are transitive dependencies on non-reachable code paths —
`govulncheck` reported zero unignored vulnerabilities before and after each
bump. These upgrades clear SCA scanner findings rather than close an
exploitable path in mc, so the upgrade is not urgent, but it removes both
findings from compliance reports.

---

## New Features

### Iceberg table maintenance

- **Per-table maintenance overrides.** Maintenance was previously configurable
  only per warehouse, with every table inheriting it. Four new commands let a
  single table opt out of or customize one maintenance type without touching the
  rest of the warehouse (#576):

  ```text
  mc table maintenance info   ALIAS/WAREHOUSE/NAMESPACE/TABLE
  mc table maintenance set    ALIAS/WAREHOUSE/NAMESPACE/TABLE --type <type> ...
  mc table maintenance update ALIAS/WAREHOUSE/NAMESPACE/TABLE --type <type> ...
  mc table maintenance remove ALIAS/WAREHOUSE/NAMESPACE/TABLE --type <type>
  ```

  `info` reports the effective configuration per maintenance type along with its
  `Source`, so it is clear whether a setting is the table's own override or the
  inherited warehouse default. `remove` deletes the override and restores full
  inheritance, which is distinct from `update --status disabled` — that keeps the
  override in place but inactive.

- **`--interval` flag for both maintenance levels.** `mc table maintenance
  set/update` and `mc table warehouse maintenance set/update` now accept
  `--interval <minutes>` to control how often a maintenance type runs. Setting
  it below the tables subsystem's poll cadence prints a warning naming the
  server setting (`MINIO_TABLES_MAINTENANCE_POLL_INTERVAL`) that also needs
  lowering (#576).

- **Iceberg compaction is now available from the CLI.** The
  `icebergCompaction` maintenance type is no longer gated as unsupported, and a
  new `--target-file-size-mb` flag sets the compaction target (#539):

  ```bash
  mc table warehouse maintenance set ALIAS/WAREHOUSE --type icebergCompaction --target-file-size-mb 128
  ```

### Performance analysis

- **`mc support perf mem` measures memory bandwidth per node.** Memory
  bandwidth caps large-object throughput on many-core storage nodes and is
  invisible to ordinary utilization counters, since DMA from a drive or NIC
  never touches a core. The new opt-in test reports what each node's memory
  subsystem actually delivered under saturating load next to what its populated
  DIMMs allow, flagging any node below 65% efficiency or running DIMMs below
  their rated speed. `--threads`, `--buffersize` and `--duration` tune the load
  (#614):

  ```text
  Server     Bandwidth  Theoretical  Efficiency  Memory
  node1:9000 392 GiB/s  460 GiB/s    85.2%       12 ch, 4800 MT/s, 2 NUMA ⚠
  node2:9000 120 GiB/s  460 GiB/s    26.1% ⚠     12 ch, 4800 MT/s, 2 NUMA
  ```

- **`mc support perf object` flags outlier nodes and projects throughput.**
  Nodes whose PUT or GET results deviate from the cluster are marked with a
  warning glyph in the final table, and projected per-second throughput is shown
  alongside measured figures, making a single underperforming node obvious
  without cross-reading raw numbers (#552).

### Observability

- **`mc ilm expiry status` tracks object expiration in real time.** A new
  interactive command summarizes pending expiry tasks, the expiration queue, and
  queue health, so operators can tell whether ILM expiration is keeping up.
  `--nodes` narrows to matching servers, `--recent-count` sets how many
  queued objects to display, `--interval` and `-n` control polling, and `--in`
  replays a previously saved JSON capture (#501).

- **Watch mode and progress metrics for decommissioning.** `mc admin
  decommission status` now reports data transferred, average speed, elapsed time
  and estimated time remaining with an inline progress bar. `--watch`/`-w` and
  `--watch-interval` poll continuously (#429).

- **Upload realtime metrics straight to a SUBNET issue.** `mc admin cluster
  stats --upload=<issue>` saves the capture locally and attaches it to the named
  SUBNET issue in one step; `--upload=0` writes only the local file (#549).

- **`--sync-before-expiry` controls ILM expiry during replication.** `mc
  replicate add` and `mc replicate update` accept
  `--sync-before-expiry enable|disable` to decide whether object expiration
  waits for replication to finish. The default holds expiry until replication
  completes, so unreplicated objects are not expired out from under a target.
  `mc replicate status --json` reports `DisableSyncBeforeExpiry` when the hold
  is off. This replaces `--edge-sync-before-expiry`, which is now deprecated but
  still accepted (#532).

- **`mc license info` shows product, node count and license serial.** The
  three fields are read from the license JWT, and local license verification is
  now scoped to AIStor (#517).

- **`mc ls --incomplete` shows the upload ID.** Incomplete multipart uploads
  now display their `UploadID` inline, and `--json` output adds a
  `multipartDir` field pointing at the upload's location under
  `.minio.sys/multipart`, which turns tracking down a repeatedly-retried upload
  consuming space from guesswork into a lookup (#493).

---

## Performance Improvements

- **Same-alias `--checksum` copies are now server-side.** `mc cp`, `mc mv` and
  `mc mirror` with `--checksum` between two paths on the same alias use
  `CopyObject` (under 64 MiB) or multipart `UploadPartCopy` (64 MiB and above)
  instead of streaming the object down and back up, eliminating the round trip
  entirely (#565).

  Note: for objects 64 MiB and larger this needs a server that returns part
  checksums on `UploadPartCopy`. AIStor `RELEASE.2026-07-24` and later does.
  Against community MinIO or an AIStor release older than that, such a copy now
  fails where it previously fell back to a client-side transfer — add
  `--disable-multipart` to copy the object in a single request, which needs no
  part checksums. Copies under 64 MiB work everywhere. A failed copy leaves an
  incomplete multipart upload behind; clear it with `mc rm --incomplete`.

- **Lower telemetry overhead by default.** `mc support telemetry` samples 1 in
  100 calls rather than all of them, substantially reducing the cost of leaving
  telemetry enabled on a busy cluster (#586).

---

## Bug Fixes

### Concurrency and resource leaks

- **Fixed data races, shutdown panics and leaks across `cp`, `mv`, `mirror`,
  `watch` and `support`** (#588). Each defect below was reproduced by a
  regression test that fails against the previous code:

  - Pressing Ctrl-C during `mc watch` or `mc mirror --watch` on a local path
    could panic with "send on closed channel" as shutdown closed the event
    channels while a forwarding goroutine was mid-send.
  - Interrupting `mc mv` could panic, because the removal manager closed while
    in-flight additions were still arriving, and iterated its map without
    holding the mutex.
  - `mc support diag` could hang indefinitely: a non-EOF decode error left the
    progress bar waiting forever, and the progress goroutine shared state with
    the bar without synchronization.
  - `mc support perf object` reported torn interim numbers, having sent a
    pointer to a loop variable that the loop then overwrote.
  - Every multi-object `cp` or `mv` raced on its object counter and, on
    interrupt, on its error flag.
  - Filesystem listers and the mirror delta pipeline blocked forever when a
    consumer stopped early, leaking goroutines that accumulated for the life of
    a long-running `mirror --watch` process.
  - Seven output files were created and never closed, discarding write errors;
    `mc support telemetry record` also printed its success hint without
    finalizing the file.

### Transfers

- **`mirror --preserve` keeps sub-second source modification times.**
  Previously the target modtime was truncated to the second, so every subsequent
  `mirror --preserve` re-copied objects that had not changed. Objects above the
  multipart threshold lost the preserved modtime entirely, because the
  `X-Minio-Source-Mtime` header was dropped before `CompleteMultipartUpload`;
  bumping minio-go to v7.3.1 restores it. This covers mirrors from a local
  source. A separate, pre-existing server-side gap means S3-to-S3
  `mirror --preserve` still does not propagate the source modtime; that is
  tracked independently (#616, #620).

- **Progress bars always reach 100%.** `mc cp` progress froze at an arbitrary
  percentage — 30%, 50%, 90% depending on transfer speed — because the final
  frame was requested after the completion flag had already been set, and the
  draw was skipped. Every copy now ends on a correctly rendered 100% frame, and
  progress values are clamped to the total on re-read (#564).

### Admin and diagnostics

- **`mc support telemetry --incoming` now works, and `--user-agent` was
  added.** The `--incoming` filter silently had no effect because the code read
  a flag name that does not exist. The new `--user-agent` flag filters HTTP call
  types by a User-Agent substring (#623).

- **`mc support telemetry` sends the configured HTTP header filter.** Header
  filtering configured on the client is now applied by the server (#587).

- **`mc admin prometheus metrics --api-version v3` accepts the paths the server
  actually serves.** The client-side allowlist had drifted badly: SMART, power,
  XFS, ECC and heal collectors were unreachable by their specific paths, ten
  top-level subsystems were missing, `api/` and `logs/` were unhandled, and
  `cluster/iam` was listed where the server serves `/iam`. Two new network debug
  collectors are added. Paths that previously worked are unchanged (#547).

- **`mc admin heal` distinguishes a scheduled healing pass from an idle drive.**
  When two drives in the same erasure set are replaced, the second was labelled
  `QUEUED`, implying nothing was happening for that set. It now reads
  `HEALING (another pass is scheduled)`, and `QUEUED` is reserved for drives
  whose erasure set has no active healing (#530).

- **Disabled access keys are visible in list output.** `mc idp
  openid/ldap/admin accesskey list` appends `, status: disabled` to disabled
  keys, and `mc admin user svcacct ls` adds a `Status` column when any account
  in the listing is disabled. `mc admin user svcacct info` now reports
  `Status: disabled` instead of `off`, matching `mc idp accesskey info`.
  Previously the only way to spot a disabled key was to run `info` on each one
  (#534).

- **Incomplete metadata exports are no longer saved silently.** `mc admin
  cluster iam export` and `mc admin cluster bucket export` validate the
  downloaded archive before renaming it into place. A truncated export now
  produces a warning advising a check of the server logs, instead of a success
  message over a corrupt zip file (#505).

### Output correctness

- **`mc retention info` no longer misreports locked buckets.** A bucket created
  with `--with-lock` but without a default retention rule was reported as
  "Object locking is not enabled." It now reads "Object locking is enabled. No
  default retention configured." JSON output was already correct and is
  unchanged (#518).

- **Table borders are consistent across commands.** Several commands rendered
  tables without the standard border; all now use the same style (#522).

- **`mc table warehouse maintenance set` colorizes its success message**
  consistently with the rest of the CLI (#594).

- **`mc ilm rule edit` success message reworded** for clarity (#545).

---

## Improvements

- **Linux packages are published as `acli-*`.** The rebranded package name
  mirrors `aistor` on the server side and follows the existing `mcli`
  convention. The installed command is unchanged — `mcli` remains at
  `/usr/local/bin/mcli`, no new binary is built, and `provides`/`replaces`/
  `conflicts` metadata means upgrades from an `mcli` package take over cleanly.
  Legacy `mcli.rpm`, `mcli.deb` and `mcli.apk` filenames are symlinked onto the
  new packages, so existing download URLs keep working (#599).

- **`madmin-go/v4` pinned to v4.10.2**, matching the version the stable AIStor
  server serves, so client support for features already implemented server-side
  can be shipped on this branch (8845b6b1).

- **Updated health-analyzer** used by `mc support diag` to its latest release
  (#490).

---

### Deprecations

- **`--edge-sync-before-expiry` on `mc replicate add`/`update` is deprecated**
  in favor of `--sync-before-expiry`, which takes an explicit
  `enable`/`disable` value. The old flag still works (#532).

---

## Security & Compliance

### Software Bill of Materials (SBOM)

This release includes SBOM documentation in multiple formats:

- `sbom-RELEASE.2026-09-06T02-44-40Z.spdx.json` — standard SBOM format
- `sbom-RELEASE.2026-09-06T02-44-40Z.cyclonedx.json` — security scanner compatible
- `go-modules-RELEASE.2026-09-06T02-44-40Z.txt` — human-readable dependency list

All three are attached to this release as downloadable assets.

SBOM files document all direct and transitive dependencies for security
auditing and compliance requirements.

---

## Upgrade Instructions

1. Download the binary or package for your platform from the Downloads section
   above.
2. Replace your existing binary, or install the package over the previous one.
3. Verify the version: `mc --version`

Existing alias configurations are preserved.

### New Command Options

| Command | New option |
| ------- | ---------- |
| `mc table maintenance info\|set\|update\|remove` | entire command group (#576) |
| `mc table maintenance set\|update` | `--interval` (#576) |
| `mc table warehouse maintenance set\|update` | `--interval` (#576), `--target-file-size-mb` (#539) |
| `mc support perf mem` | new subcommand, with `--threads`, `--buffersize`, `--duration` (#614) |
| `mc ilm expiry status` | new subcommand, with `--nodes`, `-n`, `--interval`, `--recent-count`, `--in` (#501) |
| `mc admin decommission status` | `--watch`/`-w`, `--watch-interval` (#429) |
| `mc admin cluster stats` | `--upload=<subnet-issue>` (#549) |
| `mc replicate add\|update` | `--sync-before-expiry` (#532) |
| `mc support telemetry` | `--user-agent` (#623) |

### Removed Command Options

| Command | Removed option |
| ------- | -------------- |
| `mc admin cordon` | `--node` (#521) |
| `mc admin uncordon` | `--node` (#521) |

### Support

For enterprise support:

- SUBNET Support: https://subnet.min.io
- Documentation: https://docs.min.io/enterprise/aistor-object-store/reference/cli/

