Skip to content

Releases: ewanc26/metalbear

v0.44.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 04:36

This is the first signed release. An earlier tag and release of this number, and a 0.44.1, were withdrawn: the release workflow had a mistake of mine that stopped it publishing, and the repaired one is what built this.

Changed

  • Wolfram is pinned to v0.28.0 (was v0.26.0). (#82)

  • Releases are signed, and the updater refuses an unsigned one or one signed by any other key. The private key is only the RELEASE_SIGNING_KEY secret; the public half is in pdsadmin/release-signers and built into metalbear-update.sh. The release workflow now fails rather than publish unsigned, and checks its own signature first. Releases up to v0.43.0 are unsigned, so installing one needs ALLOW_UNSIGNED=1. (#55)

Added

  • Every database now records a schema version, and MetalBear refuses to open one written by a newer build instead of migrating it blindly. Existing databases are stamped as version 1 on first start. It only protects a rollback to a build that has this check, so it starts helping with the release after this one. (#79)

Container image

docker pull ghcr.io/ewanc26/metalbear:0.44.0
Tag Digest Platforms
0.44.0-alpine sha256:a59f2466e43bada183217497af26bb8f7b41a1c783d76b95973d746b2a0b8971 linux/amd64,linux/arm64,linux/arm/v7
0.44.0 sha256:f74997238437d6ab5e4023c3a58a1e266def090a3da984406ba2cd506915236d linux/amd64,linux/arm64
0.44.0-dev sha256:00e0098ce3ac34fec4a28c4e11a2346f37f70b3c019ec3e28a348334172be5d6 linux/amd64,linux/arm64

There is no image for the Raspberry Pi 1B or Zero (ARMv6): build from
source with the minimal profile, see docs/pi1-hardware-validation.md.
The Alpine image's linux/arm/v7 covers 32-bit ARMv7 boards only.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each archive
holds the binary, the lexicon corpus records are validated against,
an example configuration, and a note on the runtime libraries it
expects. SHA256SUMS covers every archive and is what
pdsadmin/metalbear-update.sh checks. There is no Intel macOS build.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

What's Changed

  • test(build): build module-specific tests only when their module is on by @ewanc26 in #78
  • feat(storage): record a schema version in every database and refuse newer ones by @ewanc26 in #79
  • ci(flow): fail on live repository metadata drift by @ewanc26 in #80
  • feat(update): refuse an unsigned release or one signed by another key by @ewanc26 in #81
  • build(wolfram): pin Wolfram v0.28.0 by @ewanc26 in #82
  • docs(changelog): one Changed heading under Unreleased by @ewanc26 in #83
  • chore(version): bump to 0.44.0 by @ewanc26 in #84
  • fix(ci): repair release.yml, whose signing edit duplicated 336 lines by @ewanc26 in #85
  • docs(changelog): say v0.44.0 was tagged but not published by @ewanc26 in #86
  • chore(version): bump to 0.44.1 by @ewanc26 in #87
  • refactor(main): remove five helpers nothing calls by @ewanc26 in #88
  • fix(release): make the tree say 0.44.0 again, with 0.44.1 withdrawn by @ewanc26 in #90

Full Changelog: v0.43.0...v0.44.0

v0.43.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 14:35

Added

  • I can update a prebuilt install from these releases with pdsadmin/metalbear-update.sh: it checks the SHA-256 (and a signature, once I have a signing key), snapshots the databases, installs, and rolls back if the health check fails. It does nothing unless asked. See docs/updating.md. (#57)
  • Releases now carry a SHA256SUMS file, which is what the updater reads. (#57)

Changed

  • The admin app's icons were Expo's placeholder. They are the bear now, drawn from docs/logo.svg by tools/gen_icons.py in the house green, and the web favicon uses the same green. (#65)
  • Container images are tagged with the exact version, the minor and, for the newest stable release only, latest. A published version tag is never moved, and each release's notes list the image digests and lead with its CHANGELOG section. The README says how to upgrade a container. (#63)
  • Wolfram is pinned to v0.26.0. (#49)
  • OAuth scopes are stricter: an rpc: method or a repo: collection has to be a real NSID now, checked by Wolfram's validator, so rpc:foo.bar no longer parses. AT-URIs given to the admin takedown routes are parsed by Wolfram too. (#59)
  • A release tag is refused unless it matches the version in CMakeLists.txt, sits on main and passed CI. Releases are cut with tools/release.sh. (#52)

Fixed

  • The minimal build profile, the one meant for a Raspberry Pi 1B or Zero, did not compile. It does now, and CI builds it, runs the Pi checklist's tests against it and checks that the 64-bit atomics compile for ARMv6Z without libatomic. None of that has run on a Pi yet. (#66)
  • The README said there were four DNS providers in one place and three in another. There are four. (#50)

Container image

docker pull ghcr.io/ewanc26/metalbear:0.43.0
Tag Digest Platforms
0.43.0-alpine sha256:43c01e9cd21e316adfc9f7724f8e0fedbb00e3407a60bce848b6eb53f7e98dfc linux/amd64,linux/arm64,linux/arm/v7
0.43.0 sha256:e08a5f351f45393e9b492f4821e08d1ad07b5e2502581627bd63cc1316503edb linux/amd64,linux/arm64
0.43.0-dev sha256:9c74c5133f42580a512544b2d934a10c7a13a5e1e174bbba7d08856b045d85e9 linux/amd64,linux/arm64

There is no image for the Raspberry Pi 1B or Zero (ARMv6): build from
source with the minimal profile, see docs/pi1-hardware-validation.md.
The Alpine image's linux/arm/v7 covers 32-bit ARMv7 boards only.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each archive
holds the binary, the lexicon corpus records are validated against,
an example configuration, and a note on the runtime libraries it
expects. SHA256SUMS covers every archive and is what
pdsadmin/metalbear-update.sh checks. There is no Intel macOS build.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

What's Changed

  • chore: bump Wolfram to v0.26.0 by @ewanc26 in #49
  • docs(dns): four providers, not three by @ewanc26 in #50
  • ci: enforce the PR flow with flow-check, drift-check and a single gate by @ewanc26 in #51
  • ci(release): gate releases on verify, and add tools/release.sh by @ewanc26 in #52
  • ci(flow): merge with rebase only, and reject merge commits in a PR by @ewanc26 in #53
  • feat(update): opt-in updater with checksum, backup and automatic rollback by @ewanc26 in #57
  • ci(flow): adopt Wolfram's reusable flow checks and canonical flow block by @ewanc26 in #58
  • refactor(syntax): use Wolfram's NSID and AT-URI validators by @ewanc26 in #59
  • docs(changelog): start CHANGELOG.md, and have release.sh roll it into each version by @ewanc26 in #60
  • feat(release): container tags, digests in the notes, and a pull-and-run check by @ewanc26 in #63
  • fix(build): make the minimal profile (Pi 1B/Zero) compile, and check it and ARMv6Z atomics in CI by @ewanc26 in #66
  • docs(readme): house style order, and admin app icons drawn from the bear by @ewanc26 in #67
  • docs(spaces): note where AT Protocol Spaces would land, ahead of the gate by @ewanc26 in #68
  • fix(release): fall back to the REST API when a tag push is refused by @ewanc26 in #69
  • chore(version): bump to 0.43.0 by @ewanc26 in #70
  • ci(flow): sync the flow block and adopt Wolfram's issue forms by @ewanc26 in #74
  • ci(release): release by dispatch from main, tagging with GITHUB_TOKEN by @ewanc26 in #75
  • fix(release): read the repo slug from the remote, not from GraphQL by @ewanc26 in #76
  • fix(ci): let verify push the tag on a dispatch release by @ewanc26 in #77

Full Changelog: v0.42.3...v0.43.0

v0.42.3

Choose a tag to compare

@github-actions github-actions released this 04 Oct 22:20
3f10723

Container image

docker pull ghcr.io/ewanc26/metalbear:0.42.3

Built for linux/amd64 and linux/arm64.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.

There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

What's Changed

  • test: update expectations for Wolfram v0.25.0, and fix a mock race by @ewanc26 in #48

Full Changelog: v0.42.2...v0.42.3

v0.42.2

Choose a tag to compare

@github-actions github-actions released this 23 Sep 19:49
v0.42.2
5e2ca78

Container image

docker pull ghcr.io/ewanc26/metalbear:0.42.2

Built for linux/amd64 and linux/arm64.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.

There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

What's Changed

  • docs(pi1): add hardware validation checklist by @ewanc26 in #45
  • docs: tailor contributor and agent guidance by @ewanc26 in #46

Full Changelog: v0.42.1...v0.42.2

v0.42.1

Choose a tag to compare

@ewanc26 ewanc26 released this 28 Aug 09:20
v0.42.1
18fe584

Container image

docker pull ghcr.io/ewanc26/metalbear:0.42.1

Built for linux/amd64 and linux/arm64.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.

There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

Full Changelog: v0.42.0...v0.42.1

v0.42.0

Choose a tag to compare

@ewanc26 ewanc26 released this 28 Aug 08:37
v0.42.0
534f428

Container image

docker pull ghcr.io/ewanc26/metalbear:0.42.0

Built for linux/amd64 and linux/arm64.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.

There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

Full Changelog: v0.41.0...v0.42.0

v0.41.0

Choose a tag to compare

@ewanc26 ewanc26 released this 26 Aug 10:26
9a98a29

Container image

docker pull ghcr.io/ewanc26/metalbear:0.41.0

Built for linux/amd64 and linux/arm64.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.

There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

Full Changelog: v0.40.0...v0.41.0

v0.40.0

Choose a tag to compare

@ewanc26 ewanc26 released this 24 Aug 17:16
v0.40.0
a3ea2f9

Container image

docker pull ghcr.io/ewanc26/metalbear:0.40.0

Built for linux/amd64 and linux/arm64.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.

There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

What's Changed

  • feat(blob-store): keep file-backed payloads on disk by @ewanc26 in #31
  • fix(video): align limits and project metadata with current code by @ewanc26 in #35
  • feat(video): add durable multipart uploads by @ewanc26 in #37
  • perf(account): bound resident account contexts by @ewanc26 in #38

Full Changelog: v0.39.1...v0.40.0

v0.39.1

Choose a tag to compare

@github-actions github-actions released this 13 Aug 00:51
v0.39.1
7730e16

Container image

docker pull ghcr.io/ewanc26/metalbear:0.39.1

Built for linux/amd64 and linux/arm64.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.

There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

Full Changelog: v0.39.0...v0.39.1

v0.39.0

Choose a tag to compare

@github-actions github-actions released this 12 Aug 17:48
v0.39.0
ee580bd

Container image

docker pull ghcr.io/ewanc26/metalbear:0.39.0

Built for linux/amd64 and linux/arm64.

Binaries

Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.

There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.

MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.

Full Changelog: v0.38.2...v0.39.0