Repository navigation
v0.2.0
Pre-release
Pre-release
v0.2.0 / 2026-08-25
HotCell::Client and HotCell::Server
Security
- The file-size verdict is now earned from the failed write rather than read off a signal. Workers share a uid, so one worker could signal another and have the supervisor write a permanent
fsizeormemoryjudgment against the victim's unrelated input, which Active Storage would then cache forever. Every signal but the supervisor's own deadline kill is nowcrashedand transient. (#25) - Each request now gets a
$HOMEname no earlier request held, under a slot directory whose mode is reasserted first. A tool that reached code execution couldchmod 0500its own configuration directory, defeating both the worker's delete and the supervisor's rename, and hand the next request the tree that had refused to go. (#22) - A failed scratch removal is retried with the modes put back, and logs
slot.unsweptwhen it still fails. Achmod 0500on a directory a conversion wrote left one tree per request on the tmpfs, readable by every later request on the slot, andsweepreported nothing. (#22)
Fixed
Cell#describereads the description inside a rescue. A response with a correctly framed shape but the wrong types raised out ofdescribe_cells, which the README recommends calling fromafter_initializewhere nothing rescues it — so a cell answering badly could stop a Rails application from booting. An unreadable description is now logged and ignored, which is what an unreachable cell already returned. (#29)HotCell.registerraisesConfigurationErrorunlesstimeoutandcontrol_timeoutare positive and finite. Aniltimeout built no deadline at all, so a cell that accepted a connection and never answered held the caller for good. (#34)- The installer writes
hotcell/operations/.keeprather than shipping it as a template.hotcell-client.gemspecselectsDir["lib/**/*"], which does not match a dotfile, so the published v0.1.0 installer wrote a scaffold whose generatedDockerfilecould not build. (#26)