Skip to content

Rackpad v1.8.3-beta.1

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 09 Sep 01:06
· 2 commits to main since this release
7853908

Published on 2026-09-09 at 01:06:47 UTC from commit 78539083582aca909e425708c6092faf2a3318e5 through PR #155. Main remains unchanged. All six issues remain open.

Executed publication validation

The PR pipeline and tag publication workflow passed. This includes 344 server tests, 92 client tests, 51 configuration/publication/installer tests, 30 Proxmox fixture scenarios, 42 Chromium tests, 12 Storage browser cases, four Net-SNMP security combinations, all shell/workflow checks, and 40 deterministic screenshots with zero changed pixels. Browser versions: Chromium 149.0.7827.55 and Firefox 151.0 through Playwright 1.61.1 on Ubuntu 24.04.

The tag's full raw CodeQL report contains exactly the two reviewed SNMP findings at lines 83/90. Both were accepted under the unchanged hash/tree/expiry policy; raw bytes and all retained metadata remain unchanged. Raw SHA-256: 119c542db36476dd833f0b615a1b168c58a1282e36a761559ccf8e2ef41bd5f6.

Both actual published architectures passed startup, authentication/denial, SPA/CSP, exact HTTP asset/font bytes, logical/native recovery, preserved stack identities and repeated schema-51 startup using disposable data. All 316 built asset hashes match across architectures. Node is v22.23.2, the image OS is Debian 13.6, and Nodemailer is 9.1.1. Verification used Docker Engine 29.5.2 on aarch64; amd64 ran through Docker emulation. Disposable containers and volumes were removed.

Platform Published digest
Index sha256:25e3edb1a879020d0fa0cf15a1e7c619e7473de425a9a46b33e4df1e4d7b9351
linux/amd64 sha256:817bbd6eae374b67787b7b60a193d67e76f9abd9d04c7dc9eece01ec1db8ea5c
linux/arm64 sha256:f657db192ee8014193b6ee44cbcc60cd9675dbd1488c0997af843170c095b464

Trivy 0.74.0 scans of both published images, including image configuration, found zero fixable high/critical vulnerabilities, zero high/critical secrets and zero high/critical configuration findings. Each architecture retains 54 unfixed upstream OS advisories (51 high, 3 critical), documented individually in the scan evidence. No suppression was used for these scans. The published source archive and 27 checked source/deployment assets match the tagged commit.

Download the published runtime and asset evidence, scan evidence, source archive evidence, CodeQL evidence and SHA-256 checksums.

Community acceptance is pending and soak has not started. Use the exact-candidate acceptance record. Stable/main requires all acceptance criteria and then seven consecutive days of soak. Automated results do not establish Cisco IOS-XE, Firefox LAN HTTP or real PVE 9 guest acceptance.

This candidate includes the maintenance, stabilization, stacked-switch, routing,
patch-panel, Storage and SNMPv3 changes documented in the retained
beta.0 notes. Stable 1.8.3 requires community acceptance,
seven consecutive days of soak, and final release checks. Docker remains the
supported general deployment; native Proxmox LXC remains experimental.

Repairs since beta.0

  • CodeQL security severity must be a decimal string from 0 through 10. Arrays,
    booleans, null, empty strings, numbers and out-of-range values fail validation
    before suppression or exception handling. Security-tagged rules require a
    score; ordinary unscored quality rules remain supported.
  • Nodemailer moves from 9.0.3 to 9.1.1, the compatible 9.x repair for the
    address-parser denial of service
    and legacy content-resolution guard bypass.
    SMTP settings and credential storage are unchanged.

The beta.0 tag remains at fb7fbcec511e2b95060055103a669cdbc894be3a, the merge
of PR #154. Its publication was canceled before build or release steps after
independent review confirmed the severity-validation defect. No beta.0 GitHub
release or versioned GHCR image was published. The tag must never be moved.

Reviewed CodeQL exceptions

Only js/insufficient-password-hash at server/lib/snmp-v3.ts lines 83 and 90
is eligible, with one primary location confined to its identified line. Owner:
@Kobii-git. Acceptance expires at 2026-11-30 00:00:00 UTC; the exact
boundary rejects the exception.

  • File SHA-256: 4029cff16fe59c2120322cf3340bc543564bd44f12835b57f20f27c2e35b3e63
  • Git server tree: 29b7962b93a62fa05da1e4147afef36a68166827

RFC 3414 requires MD5/SHA password
expansion and localization for interoperable SNMPv3 USM wire keys. These operations
are not application login password storage. Existing credential encryption and
configured MD5/SHA/AES128 interoperability remain intact.

The shared policy requires unchanged tracked server content, no additional server
files, valid Git/source evidence and an unambiguous analyzed source identity.
Native reports without an absolute source-root mapping require embedded complete
source matching the approved hash. Missing evidence disables acceptance. Dates
and hashes are never renewed automatically.

Raw SARIF is schema-validated and retained unchanged alongside an explicit review
summary. Only accepted results are omitted from a separate upload report; all
other findings, fingerprints, severities and analysis identities remain intact.
Failed processing uploads raw analysis and blocks publication. Upload failure
also blocks publication. No new broad suppression or alert dismissal is used.

Upgrade and recovery

Schema remains 51. Published migrations 49 and 50 and stack migration
51 are unchanged; security conversion remains at the schema-50 boundary.
No new public API, environment variable or credential format is introduced.

Before upgrade, retain the previous application plus its pre-upgrade database,
configuration and original encryption key. Preserve RACKPAD_SECRET_KEY exactly.
See the security upgrade guidance for trusted proxy
settings, OIDC role recovery and trap-source reconfiguration. Missing-key legacy
conversion fails atomically; traps remain opt-in.

Rollback restores that entire previous application/database/configuration/key
pair. Older binaries must never open schema-51 data. A current logical backup
cannot replace the pre-upgrade snapshot for downgrade. Test recovery only with
disposable data and reject invalid ownership or newer-schema backups atomically.

Exact-candidate acceptance

Use the full guest and feature checklist
against beta.1's immutable commit and published digests, not beta.0 or a
floating branch/tag. Record version, source commit, both architecture digests,
source-asset hashes, platform/browser versions, UTC timestamps and results.

Issue Required community evidence
#152 Cisco IOS-XE SHA/AES in the reporter's Docker-network scenario: credential testing, monitoring, IF-MIB discovery, idle/engine-time recovery and rejection of wrong credentials.
#153 Firefox over ordinary LAN HTTP with fresh/upgraded Storage data: navigation, section creation/editing, saving and reload; record UUID availability and console errors.
#138 Disposable Debian 13 and Ubuntu 24.04 on PVE 9: install, schema 45/48/49/50 upgrades, reboot, custom ports, discovery modes, exact keys, recovery, injected failures and paired rollback.
#139 Rear/mixed-face continuations, selection, tracing, waypoints and exports. Brush-panel redesign remains outside this fix.
#148 Independent front/rear edits on a custom 24-column descendant: 48 bindings, zero unmapped ports, 24 pass-through pairs, tracing and persistence.
#146 Member metadata/order/MACs, nullable assignments, inherited types, derived height, unmount/undo/redo, loose-room moves, earlier history, genuine conflicts and preserved identities.

Include normal email alert delivery in beta.1 acceptance because Nodemailer is a
runtime dependency change. Automated Net-SNMP and browser checks do not substitute
for community Cisco, Firefox LAN HTTP or Proxmox guest evidence.

After all acceptance criteria pass, record seven consecutive days of soak.
Runtime, security, schema, dependency or OS-package changes require affected
acceptance to repeat and soak to restart. Documentation/version-label changes
alone do not. No community acceptance or soak is claimed by earlier CI results.
All six issues stay open, including after publication. External Community Scripts
listing remains separate from Rackpad's readiness for main.