Skip to content

v0.6.3

Choose a tag to compare

@beastyrabbit beastyrabbit released this 29 Sep 11:41
· 2 commits to main since this release
a034108

Note

馃 Claude Opus 5.5 responding on behalf of beastyrabbit

Moddrop 0.6.3 makes backend handovers safer. When a canvas backend gives up leadership, it now always frees the room for the next one, even if a shutdown step fails.

Reliable leadership handover

The canvas backend holds a PostgreSQL advisory lock while it owns live rooms. Before this release, a shutdown handler that failed synchronously skipped the step that releases that lock and its database connection. A successor could then not admit sessions until the connection died. Every handler failure is now collected and reported together. The lock and connection are released in all cases.

A regression test covers this path against a disposable PostgreSQL database. It fails on 0.6.2.

Hardened frontend image

The frontend container's entrypoint is now owned by root. The unprivileged runtime user can execute it but can no longer modify it.

Code analysis and delivery

SonarQube now analyses main and non-draft pull requests from this repository, replacing the previous OpenGrep workflow. Convex's generated code is excluded from analysis. The backend guide now describes the current delivery path: the release tag publishes both images, Flux image automation rolls them out to the Homelab, and a bad release is fixed forward with a new tag.

Upgrade and verification

No schema migration or configuration change is required. Both 0.6.3 images roll out together; the backend keeps its stop, flush and start handover.

Verification covered lint, formatting, types, 86 frontend tests, 40 backend tests with disposable PostgreSQL and WebSocket scenarios, seven browser flows, both builds, the compiled runtime configuration check, and a container smoke test. SonarQube's quality gate passes with no blocker issues or vulnerabilities on main. An independent release review and the repository's Codex code and security reviews found no issues.

One existing lifecycle test assertion about disposal timing fails intermittently on 0.6.2 as well. This release doesn't change it.

Changes: #8, #9, #7