Skip to content

SecondBox v0.17.0

Choose a tag to compare

@melonamin melonamin released this 25 Sep 21:26
· 7 commits to main since this release
81515d2

SecondBox v0.17.0

Deployment boundary

This release ships a new signed Firecracker bundle containing the guest file-error fix. Its runtime and toolchain component-manifest digests change. The guided updater refuses that change because existing Sandboxes remain pinned to immutable Profile revisions. Existing deployments must retire their Sandboxes, install this release with a fresh database and separate Runner storage root, then recreate resources. Do not overwrite an existing bundle or reconstruct Workspaces. Keep the previous deployment, database, storage, assets, and credentials together for rollback. See the deployment procedure.

The public API remains v1, Runner protocol generation remains 5, and the v0.15.0 database migration baseline is unchanged. The RSA trust anchor from v0.12.0 is retained; verify it independently against the fingerprint below before installing the new bundle. Update the control plane, every Runner, image fetchers, signed asset catalog, and standard resources together.

Firecracker bundle and trust anchor

The signed secondbox-0.17.0 bundle uses the retained 6.12.94 kernel and RSA trust anchor. It is built from source commit 5e3cf943e30b89db6e024278c8d795b0c35c33a5, which contains the guest change in #168. The canonical public-key DER SHA-256 remains:

59c127f459b8c93ca422f2f6c5bd43ff1e17d50309a262b7aff1b07bf59a5ced

The independently verified bundle identities (SHA-256) are:

Manifest Digest
manifest.json 5c121ea4b4eadffe8e167a0ec2581387cf774ba3a67c937afca039acdd6245f3
Runtime component abdfe1ff2e9a1752418868664dd23ddb1fd28f46fdbe3d89feb39ffb18e47b78
Toolchain component 6999b7927eb8e06f1b2a794e3619d19ad2267a035f2b96f7815c307cca6859ee

Component pins use the sha256: prefix. The release artifact manifest binds these identities to the packaged microvm-artifacts image. Operators must install the new bundle and apply the new signed asset catalog and standard Profile revisions as one coordinated step. Runners reject Assignments pinned to mismatched component digests.

Attributed connection policy

The latest standard agent-compartment Profile revision grants 128 simultaneous open TCP connections per attributed generation and permits a Subject controller to select a value up to 4096. Operators must explicitly apply the updated standard bundle; deploying code alone does not raise an operator-owned grant. Custom Profiles need their own explicit default and ceiling. A complete Subject policy PUT can include attributedExecution.maximumConnections, and policy reads project the default, effective value, and ceiling for the next Assignment.

The numeric limit resolves from the current Profile head on each new Assignment, including an existing Sandbox pinned to an older revision. An old two-connection pin inherits 128 after the standard revision is applied; a saved Subject selection is capped by the current ceiling. Active Assignments keep their admitted limit. Pinned gateway, other execution authority, and lifecycle policy do not change. At capacity, the forwarder closes newly accepted TCP sockets before contacting the gateway; existing streams stay open. See attributed connection policy and downstream adoption.

Workspace file errors

File mutations that encounter a full Workspace now return HTTP 507 workspace_full instead of a generic failure. This includes guest ENOSPC and quota exhaustion. Clients can delete files and retry. The Firecracker guest must come from this release's new signed bundle for the guest-side classification to work.

Distribution

The default release tier qualifies Firecracker, local gVisor, and the Btrfs-image installer guest and publishes Linux amd64 container images. CLI and deployment binaries ship for Linux and macOS on amd64 and arm64. The public API remains v1; the Runner protocol window is [5,5].

Install the TypeScript SDK with npm install @secondstack-ai/secondbox@0.17.0. The Go module is github.com/SecondStack-AI/SecondBox@v0.17.0.

Install

Guided Linux amd64 install:

curl -fsSL https://github.com/SecondStack-AI/SecondBox/releases/download/v0.17.0/install.sh | sh

SDKs: npm install @secondstack-ai/secondbox@0.17.0 and go get github.com/SecondStack-AI/SecondBox@v0.17.0