Skip to content

v0.4.0

Pre-release
Pre-release

Choose a tag to compare

@flavorjones flavorjones released this 08 Sep 14:45
· 40 commits to master since this release
919491d

v0.4.0 / 2026-09-08

Upgrading

Some actions that application developers should consider taking when upgrading from an earlier version:

  • Log stderr from the perform.hot_cell event in the client Rails application. This improves observability and provides forensic evidence about cell crashes.
  • Set MAGICK_MEMORY_LIMIT, MAGICK_MAP_LIMIT and MAGICK_DISK_LIMIT in a cell image that installs ImageMagick. See docs/IMAGEMAGICK.md.

HotCell::Client

Added

  • The perform.hot_cell event carries stderr, the failure's captured stream, beside signal. A subscriber can log the diagnosis of a crash — libgomp: Thread creation failed — on the same line as its cause. Before, that text survived only in the exception's message, so a failure that was discarded rather than retried lost it. The field is already bounded by Failure.sanitize; it is text a tool wrote while processing a hostile file, so write it to a log field and interpolate it nowhere else.

HotCell::Core

Fixed

  • json 3.0.0 support.

HotCell::Server

Added

  • The supervisor empties the scratch at boot: every top-level entry of Dir.tmpdir and of the workspace's parent that the cell's uid owns, so rebooting the accessory clears a scratch a killed tool filled.
  • The cell refuses to boot when HOTCELL_DIR is inside the scratch, when the scratch is missing or reached through a symlink the cell's uid owns, or when HOTCELL_WORKSPACE, TMPDIR or HOTCELL_DIR is not an absolute, normalized path.

Fixed

  • A worker sets TMPDIR to the request's home, and an exec'd tool inherits it. Before, nothing set it, so a library's scratch went to /tmp — outside the slot tree that is removed when a request ends — and a killed worker orphaned every file there until the scratch filled.

ActiveStorage::HotCell::Server

Fixed

  • Every operation sets MAGICK_TMPDIR to the request's TMPDIR, so ImageMagick's pixel cache — from the magick the magick operations run and from the magickload libvips delegates to — is removed with the request, however it ends.
  • MagickOperation forwards the worker's MAGICK_*_LIMIT, TMPDIR and MAGICK_TMPDIR to the magick it spawns, read per request. MiniMagick.restricted_env had dropped them along with the rest of the environment, so an image's MAGICK_DISK_LIMIT bounded ImageMagick inside libvips and not the magick behind analyzers.image.magick and transformers.image.magick, which ran under ImageMagick's defaults — the host's RAM and an unbounded disk — and the request's TMPDIR above never reached it.

Improved

  • The two ImageMagick operations read their input through its descriptor instead of staging a copy of it, so the operation's file_size no longer bounds how large an input they can read. This needs mini_magick 5.4.0 and image_processing 2.1.0, which the gemspec now requires. (#7)