Skip to content

Releases: fwdslsh/fhold

fhold 0.1.2610050714-alpha.6

Pre-release

Choose a tag to compare

Admin's System view now presents four compact, collapsed sections in order:
Installation details, Recent logs, Import / export, and Ephemeral container
support. Import/export explicitly transfers reviewed content into a fresh
installation; ephemeral support restores the same instance's runtime state,
including native history and account configuration. Existing CLI commands and
archive formats are unchanged.

Admin and CLI can configure directory or Blob checkpoints for managed instances,
inspect checkpoint status, initialize an explicitly confirmed fresh namespace,
and restore while application writers are stopped. Configuration changes remain
pending until confirmed activation. Recovery is opt-in, credentials remain
private, and no cloud administration, sidecar, startup installer or new service
is added. See configuration and safe transitions.

Recovery now fills missing ephemeral files and registered SQLite databases when
the exact accepted receipt survives on a persistent mount, without replacing
newer surviving state. Unreceipted partial state still fails closed. Reading an
atomically published recovery status no longer falsely fails when its previous
inode is replaced; strict snapshot capture checks are unchanged.

Includes selection and lifecycle regressions, a concurrent status publication
test, and real Electron/Docker setup, import/export and cold-recovery checks.
The native-worker retry fixture now flushes its output before exiting and allows
the existing bounded process-group cleanup; no runtime retry delay is changed.
Fresh CLI/Admin installs use the matching public Docker Hub images. Existing
homes, names, ports, credentials and policies are preserved during upgrade.
Claude/Codex remote workers remain experimental; ARM64 Admin startup remains
unqualified. Previously reviewed scoped dependency exceptions remain disclosed.

Full Changelog: 0.1.2610050129-alpha.5...0.1.2610050714-alpha.6

fhold 0.1.2610050129-alpha.5

Pre-release

Choose a tag to compare

Runtime recovery now supports explicit directory exclusions, required independent
mounts and opt-in network-mount discovery through the versioned
FH_RECOVERY_INCLUDE_FILE. Ordinary local volumes keep their coverage.
Registered SQLite and WAL/SHM paths must remain local and cannot be excluded.
Missing required mounts and changed ownership policies block startup rather than
restoring historical files over independently persistent content.
See the policy and stopped-writer transition.

The image adds private read-only fhold-recovery inspect and confirmed offline
restore --confirm-stopped without starting application writers. Legacy catalogs
remain readable; catalog 3 requires a supporting image. Existing namespace policy
changes require a reviewed transition to a fresh namespace. Portable backup stays
the fresh-install content-transfer path, with no new runtime authority or archive
conversion.

Admin settings save without immediately restarting containers. A persistent
pending-restart notice survives closing/reopening and instance switching.
Users can confirm activation now or restart later; failed activation leaves
changes pending. Explicit start/stop/restart and native setup interruptions also
require confirmation. CLI status reports pending activation, and successful
activation clears it through the same shared control plane.

Includes mount-policy regressions, real directory/Blob-emulator cold replacement,
read-only external-content preservation, offline restore and native AKM harness
checks. GitHub release gates now exercise directory recovery on native amd64 and
arm64 runners. Actual SMB/NFS/FUSE hosting, real account renewal/reconnect and
measured RPO/RTO still require deployment-specific qualification.

Fresh CLI/Admin installs default to the matching public Docker Hub images.
Publishing does not restart or upgrade existing instances. Claude/Codex remote
workers remain experimental; native ARM64 Admin startup remains unqualified.
Previously reviewed scoped dependency exceptions remain disclosed.

Full Changelog: 0.1.2610041911-alpha.4...0.1.2610050129-alpha.5

fhold 0.1.2610041911-alpha.4

Pre-release

Choose a tag to compare

OpenCode, Codex and Claude now load operator-owned native policies from the
instance's config/ directory. Edit the files and restart; no image rebuild,
new service or cloud-specific configuration is needed. Updates preserve edits,
and the files are mounted read-only inside the Assistant. See
the file map and examples.

Built-in AKM/fhold hooks use native managed registration, with no personal hook
approval required. Custom-hook behavior changes: the managed-only defaults
suppress user, project and ordinary plugin hooks. Add reviewed custom hooks to
the native managed settings if needed; plugin skills and MCP servers remain
available. Managed policy is deployment configuration, not part of portable
knowledge backups; preserve and reprovision it separately.

Upgrade the CLI/Admin and Assistant image together. Activation checks image
compatibility, preventing an older image pin from silently losing its hooks.
Existing image pins remain explicit choices. See alpha.3 upgrade instructions.

New named instances live under ~/fhold/instances/<name>, leaving room beside
instances/ for backups, docs and other local files. One global CLI --name/-n
accepts a directory name under that root or an absolute path, with precedence
argument → optional FH_HOME → current directory. The selector works before or
after commands. A DNS-safe name is also the initial container/hostname identity;
there is no separate instance selector or install-name option. Existing saved
identities are preserved when selecting a home by name or absolute path.
Admin suggests the folder as a new instance is named; its unnamed default is
~/fhold/instances/default, and custom folder choices remain supported.
Existing homes, project names, ports, credentials and data are not relocated or
changed automatically. Alpha.3 binaries still require FH_HOME; the new global
selector is available in alpha.4.

Admin and CLI now link directly to the matching public Claude Desktop extension.
Installation, management and release documentation have been aligned with the
public GitHub/Docker Hub distribution and native configuration paths.

Linux x64/ARM64 CLI, Admin AppImages and the optional unsigned MCPB are built
on GitHub with checksums and an asset manifest. Fresh installs select the
matching pinned public images. Claude/Codex remote workers remain experimental;
ARM64 Admin startup remains unqualified. The previously approved, scoped
dependency exceptions
remain in effect; this is not a clean-audit claim. Publishing does not update
existing running instances.

Full Changelog: 0.1.2610040821-alpha.3...0.1.2610041911-alpha.4

fhold 0.1.2610040821-alpha.3

Pre-release

Choose a tag to compare

@github-actions github-actions released this 04 Oct 09:07
f42ce81

First public GitHub/Docker Hub release: standalone Linux x64/ARM64 CLI, optional
Admin AppImages, Claude Desktop extension, checksums and asset manifest. CLI and
Admin fresh installs use the pinned public fwdslsh/fhold-assistant image;
optional Guardian/Portal use their matching public images. Images support amd64
and arm64 and are signed through GitHub Actions. No Docker Hub login is needed.

Includes the dependency refresh, native fhold plugins and shared image-baked
skills for OpenCode, Claude Code and Codex. Optional conditional HTTP keep-alive
uses the existing scheduler and can run with user scheduling disabled. Native
completion/cancellation handling prevents stale activity from keeping instances
awake; append-only history does not count as live work. Older AKM catalogs no
longer prevent startup. See keep-alive configuration.

Assistant now runs as fhold at /home/fhold; its OpenCode HTTP username is
user. Custom deployments must update old mount paths, absolute plugin/backup
paths and clients before upgrading. Managed host data directories are preserved.
Existing local-build homes retain their namespace; they do not silently switch
to public images. Native plugin customizations and consent are preserved.

Claude/Codex remote workers remain experimental. ARM64 Admin is cross-built,
not native-startup-qualified. The owner approved narrow, expiring exceptions for
three npm-bundled denial-of-service advisories and the existing unsigned MCPB
build-tool advisory; see scope and expiry.
Raw reports remain visible; no upstream package internals were patched.

What's Changed

  • Release alpha.3: native plugins, conditional keep-alive and public Linux distribution by @itlackey in #2

New Contributors

Full Changelog: https://github.com/fwdslsh/fhold/commits/0.1.2610040821-alpha.3