Skip to content

open-compute 0.2.4

Latest

Choose a tag to compare

@github-actions github-actions released this 05 Oct 23:09
· 46 commits to main since this release
Immutable release. Only release title and notes can be modified.
73efa56

open-compute 0.2.4 adds ordinary Python Worker deployment with immutable prepared applications and adopts Cloudflare's cf CLI for application tooling. It also fixes service installation under Debian's common umask and qualifies requests/httpx through the real daemon. This release is intended for operators who need Python applications or were blocked by the systemd setup failure; Dynamic Python remains outside the qualified production surface.

What's new

  • Ordinary Python entrypoints, multi-module imports, package data and supported Pyodide dependencies can be built, uploaded and deployed. Deployment-time preparation produces an encrypted, immutable application snapshot; restart and rollback reuse verified stored content without installing dependencies or rebuilding applications.
  • Python uses the unmodified Workers runtime SDK 1.9.2 and the existing resource authority. The qualified paths cover bindings, Services/RPC, Queues, Durable Objects, Workflows, Cache, Assets, Images, search extensions and observability, with explicit resource isolation and failure/recovery checks.
  • Django and FastAPI HTTP and streaming, and Flask HTTP and templates, are qualified on ordinary deployments. requests 2.33.1 and httpx 0.28.1, including synchronous and asynchronous httpx, are exercised for Unicode data, errors, streams, deadlines, connection refusal, quotas, cancellation cleanup, restart and rollback.
  • Application configuration, authentication, upload, deployment and resource management use cf 1.0.0-beta.12 and Cloudflare Vite plugin 2.0.0-beta.sha-52b0dc0e9. Python builds temporarily call the user's installed PyWrangler; it is neither bundled nor automatically installed, and the bridge does not check its version.

Workerd

The third_party/workerd gitlink advances from a266c0305e4c002b61ff48bc49deab3dfe24b731 to fdcb8c97f0b9f75f610b66e418d5175b9188ddad. The formal runtime pin changes from v1.20260930.0-open-compute-r3.e3bdb07f5 (source e3bdb07f52affc6a618f02ed2b731a581b0b2f69) to v1.20260930.0-open-compute-r4.e98a3e843 (binary source e98a3e8433979356047a202d3e0d1b0e2e2c4b8c, upstream base d99bc6b777e35d72d71c2f1fe2fd1db53284528a). The workflow-only gitlink tip is not the binary source. workerd --version remains workerd 2026-09-30; the date output is unchanged even though the source and verified archive/binary identities change. Pyodide remains 314.0.6_2026-08-17_6.

Every commit in the submodule range is listed below:

Commit Change and operator impact
0177c203fac4 Enable host-only Python preparation and native binding policies, allowing deployment initialization without exposing host authority to tenant Python.
a692581ebc92 Pass only the batch to Python WorkerEntrypoint queue handlers, matching the official SDK callback shape.
c92952f47bba Keep Python entrypoint regression coverage on supported SDK exports; no additional tenant API is introduced.
e98a3e843397 Relax scheduled class-handler arguments to the supported SDK shape. This is the R4 binary source.
fdcb8c97f0b9 Fix the nested release-artifact publication path. R4 publication reused the four existing successful native build artifacts and did not rebuild workerd.

Native source qualification explicitly fetches the immutable formal revision when a shallow gitlink checkout lacks it. Runtime preparation continues to verify the formal lock, release checksums, version, metadata and process flags. Production startup stays offline. Automatic workerd CI builds are disabled; manual publication remains available.

SDK

  • Package: @open-compute/sdk@0.2.4, paired with ocd 0.2.4.
  • Install: bun add @open-compute/sdk@0.2.4.
  • npm version: @open-compute/sdk 0.2.4.
  • Official management SDK pin: cloudflare@7.2.0; OpenAPI source: cloudflare/api-schemas@780de88d0324b007c907a1782259b1a0e5e87c7d.
  • The generated management SDK and configuration guidance follow the selected cf surface. Python's workers-runtime-sdk 1.9.2 is a separate application runtime package, not a substitute for this management SDK.
  • Only matching stable ocd and management SDK versions are qualified together.

Fixed

  • AI Search opens existing instance storage and validates its configuration in one SQLite snapshot. Concurrent metadata updates no longer cause a stale inspection to fail contract validation and mark an otherwise healthy instance unavailable. Identity, model and configuration corruption remain rejected.
  • Service setup creates missing nested service directories with explicit 0700 permissions, independent of inherited umask, and writes unit definitions with 0600 permissions. Errors preserve useful sanitized diagnostics. This fixes #135, including Debian 13 installations using umask 002; unsafe existing directories and symlinks remain rejected.
  • Sudo setup accepts private scope temporary directories owned by the verified service user, matching the installer, while crash-recovery staging contents retain strict caller ownership checks.
  • Python and JavaScript consume the same native binding objects and persistent resource authority. Assets header conversion and Workflow interruption use existing upstream primitives instead of a private Python runtime protocol.
  • Runtime-source snapshots, prepared application identity, encrypted artifacts and generation fencing are validated before execution; failures cannot silently rebuild or repair persisted content.
  • HTTP client qualification records genuine timeout causes and checks native subrequest admission. Captured multipart fixtures retain their original protocol bytes across Git checkout.
  • English and Chinese Python guides now distinguish Cloudflare GA, ordinary deployments and unqualified Dynamic Python. Historical W1/W2 records are identified as historical rather than current support evidence (#129).

Before you upgrade

  • Breaking pre-1.0 deployment identity: 0.2.4 changes the system Worker manifest bound into immutable deployment descriptors. An instance with retained pre-0.2.4 Worker versions cannot be upgraded in place. Upgrade preflight returns MIGRATION_FAILED before replacing the binary or changing the database; the old service, deployed Workers and KV data remain usable. Use a separate fresh 0.2.4 installation, explicitly transfer application data and redeploy before switching traffic. Do not delete or reset the old instance to bypass this guard.
  • Back up instance data directories, SQLite authorities, configuration and encrypted object storage before upgrading. Plan a service restart; do not run two daemon owners against the same scope or data directory.
  • This release appends the platform migration V14__python_prepared_artifacts.sql. Previously published migration filenames, ordering and bytes remain unchanged. Startup rejects unsupported or corrupt state instead of repairing it silently; do not downgrade a migrated data directory to an older binary.
  • cf is the application CLI. Migrate existing Wrangler project configuration with the official migration command and follow the current cf guide. Python builds additionally require user-installed PyWrangler, its explicit build interpreter input and a project-local Wrangler development dependency; the exception applies only to Python building.
  • General outbound retains the documented host-routable IP capability, including private and loopback destinations. Apply any required destination filtering with the host firewall, network namespace, container or VM.
  • Setup does not automatically change permissions on existing insecure service directories. An installation left with group-writable directories by an older failed setup must have its ownership and permissions reviewed before retrying.

Install or upgrade

For a receipt-managed installation without retained pre-0.2.4 Worker versions, after taking a backup:

ocd upgrade 0.2.4

For a new user-owned installation, download and review the version-pinned installer:

curl -fsSL -o install.sh https://raw.githubusercontent.com/elliothux/open-compute/v0.2.4/scripts/install.sh
less install.sh
OPEN_COMPUTE_RELEASE_TAG=v0.2.4 sh install.sh
ocd setup --yes

Check ocd --version, ocd config check, ocd instances, ocd doctor and ocd capabilities --json before admitting traffic.

Downloads

Host Asset
macOS on Apple silicon ocd-v0.2.4-darwin-arm64
Linux on ARM64 ocd-v0.2.4-linux-arm64
Linux on x86-64 ocd-v0.2.4-linux-x64

The release also contains release.json and SHA256SUMS. Each executable embeds the verified workerd and Caddy inputs. Windows and Intel macOS remain source-build-only targets.

Security

There are no published security advisories specific to 0.2.4. Python uses the same declared bindings, resource permissions, authenticated platform listeners, immutable deployment authority and secret handling as JavaScript. General outbound is controlled by host networking policy; Unix and abstract Unix sockets remain denied. Production startup does not download runtimes, execute package managers or expose preparation credentials to tenants.

Known limitations

  • Raw Dynamic Python child initialization still exceeds the unchanged 1,000 ms startup CPU limit on the formal pin. New children, repeated cached keys, an ordinarily warmed process and fresh daemon restart all fail closed. Successful Dynamic Python support remains #126.
  • Flask context-dependent streaming is affected by cloudflare/workers-py#287. The SDK remains unmodified; this path is excluded while ordinary Flask HTTP and templates remain qualified.
  • The selected requests/urllib3 transport reports actual timeout as ConnectionError with a timeout cause, rather than requests.Timeout. Async httpx task cancellation does not guarantee immediate abort of the underlying Fetch.
  • Python PostgreSQL/MySQL drivers, TLS, higher-level AI/API clients and HTTP MCP remain unqualified follow-ups under #128. Native socket source support is not evidence that all Python drivers work.
  • Public cross-Script Durable Object and Workflow bindings are rejected. Python/JavaScript tests use separately owned namespaces and definitions.
  • open-compute remains a single-machine self-hosted platform, without managed multi-region placement or per-Worker/per-instance destination filtering. AI Search public queries remain text-only.
  • macOS document parsing has no enforceable hard memory ceiling. Code signing and macOS notarization are not included. Product purge can still reject ambiguous hardlinked OCR entries while retaining data.

Verification

Local acceptance requires one complete workspace Gate with zero ignored cases and at least 90% Rust line coverage against formally pinned R4. The HTTP/Dynamic real-process case passed complete initial, restart and rollback checks with exact native inventory and zero ignored. Version preparation validates the generated SDK, source identity, published migration bytes, locked inputs, release contracts and Git LFS objects.

Publication additionally requires successful main static CI, fresh tag coverage and one complete macOS workspace Gate, controlled Linux egress, three native packaged-executable checks, the npm SDK package, and all five real install/upgrade jobs on Ubuntu 24.04 and Debian 13 x64/ARM64 plus macOS ARM64. These jobs qualify fresh installation and the declared fail-closed rejection of a 0.2.3 instance with retained Worker versions, including unchanged binary, receipt, process, identity and working old Worker/KV data. The GitHub Release becomes public only after all required jobs succeed and all five uploaded assets are downloaded and verified byte-for-byte against their manifest/checksums. These are publication prerequisites; local source checks alone do not prove a completed cross-platform release.

Full changelog

Thanks

Thanks to @Raphael-Penning for reporting the Debian 13 systemd setup failure in #135, fixed in this release.

Thanks also to @tossp for #130 and #131. Both reports were addressed in 0.2.3 and marked completed after that version's tag was created.