Skip to content

Releases: netsec-ethz/debuglet

Debuglet v0.2.0

Choose a tag to compare

@vincent10400094 vincent10400094 released this 27 Sep 11:10
v0.2.0
be5142f

Stable operational release

This release promotes the tested 0.2.0 release candidates and includes the final documentation and CI layout cleanup.

Highlights:

  • dbl CLI, Go SDK, browser login, and managed dispatcher/executor services.
  • Verified TLS control channels and backed-up database upgrades.
  • HTTP API 1.3 and canonical lowercase run IDs.

Known limitations: packages are Linux amd64 only; SCION traffic attribution and complete authenticated dashboard workflows are not yet supported.

See CHANGELOG.md for details.

Debuglet v0.2.0-rc.3

Debuglet v0.2.0-rc.3 Pre-release
Pre-release

Choose a tag to compare

@vincent10400094 vincent10400094 released this 26 Sep 16:55
v0.2.0-rc.3
1bf2bde

Changed

  • Keep the HTTP API at 1.3; the rc.2 changelog incorrectly said 1.2.
  • Use tc clsact when TCX is unavailable. The pure-Go fallback now tags IPv4
    UDP and ICMP with SipHash-2-4 and CAP_NET_RAW; TCP, TLS, and SCION remain
    untagged in this mode.
  • Require lowercase canonical run IDs in the API, CLI, and Go client.
  • Configuration-only deployments now preserve the release recorded on each
    host and reject conflicting version overrides.

Fixed

  • Continue deploying other executors when one host becomes unreachable.
  • Handle invalid SCION path indices and missing metadata without panicking.
  • Reject expired or not-yet-valid executor client certificates at startup.
  • Flush credentials, local state, and managed-service files before atomic
    replacement to prevent empty or truncated files after a crash.
  • Use the selected environment's SSH known_hosts file in maintenance tasks.
  • Release completed runs from the eBPF bandwidth-counter map.
  • Enforce SQLite foreign keys, briefly wait for locks, and write payment intent
    data atomically. Database upgrades report existing invalid rows.

Removed

  • Remove unused verification scripts superseded by dbl, pkg/client, and
    verify_pcap.py.
  • Drop big-endian eBPF artifacts and executor builds; supported Linux targets
    are little-endian.

Known limitations

  • SCION traffic is not attributed to runs.
  • The web dashboard is not fully compatible with authenticated sessions; use
    dbl or pkg/client for complete workflows.
  • Packages are Linux amd64 only. Local state is package-version-specific, and
    interrupted runs are not recovered.

Debuglet v0.2.0-rc.2

Debuglet v0.2.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@vincent10400094 vincent10400094 released this 26 Sep 16:25
v0.2.0-rc.2
5f953e3

Release-note correction: this release serves HTTP API contract 1.3, which adds GitHub browser-login routes. The original changelog prose below incorrectly says that rc.2 keeps contract 1.2; the embedded api/openapi.yaml, GET /version, and client constant correctly report 1.3.

Added

  • Add browser login with GitHub OAuth, including PKCE, short-lived login state,
    and deployment-specific credentials stored outside version control. This adds
    dispatcher database migration 00009; run make deploy-upgrade-db DEPLOY_ENV=<env> before the full deployment. The target builds and installs
    the candidate payload before it applies that payload's migration.
  • debuglet-dispatcher -upgrade-database, debuglet-executor -upgrade-database
    and deploy/ansible/upgrade-database.yml bring a deployed database forward to
    the packaged schema, with a backup taken by the playbook. The upgrade is
    supported for wallet-free TEST state only; local state directories still
    require a new directory per package version.

Changed

  • The HTTP contract stays at version 1.2 while it changes in ways that its
    rules otherwise reserve for a major version. Release candidates may do so
    before the final v0.2.0; from then on the rules bind without exception.
    docs/API.md lists every such change of this
    candidate, including the ones below.
  • Every route answers a body above 32 MiB with 413 payload_too_large.
  • An identical resubmission on PUT /debuglet answers 200 with the runs already
    recorded for the batch instead of admitting it again. PUT /payment/intent
    refuses an empty batch and a repeated order_id.
  • PUT /payment/intent prices a run by its timeout in milliseconds, rounded up,
    instead of whole seconds truncated. Sub-second runs are no longer free, and a
    client that computes prices itself must use the new formula.
  • DELETE /debuglet answers an executor's refusal 400 cancel_refused whatever
    its gRPC code, and an Abort that may not have reached the executor 500
    internal_error ("cancellation not confirmed").
  • dbl service status exits 4 when the role is not ready, where it exited 0.
  • Setting a destination limit below the floors already admitted is refused with
    409 capacity_exhausted.

Fixed

  • A refused resubmission of a batch whose orders already have runs no longer
    refunds its transaction.
  • A datagram read into a buffer shorter than the datagram is charged for the
    whole datagram.

Schema

  • Dispatcher migration 00004 gained DEFAULT clauses after v0.1.0, so that a
    populated database at version 3 can be upgraded. A database already past
    version 4 is unaffected and keeps the columns without defaults.

Known limitations

  • SCION sockets cannot be marked, so their packets are not attributed to the
    run by the eBPF tagger. The executor logs a warning once when it dials SCION.
  • The limitations of v0.2.0-rc.1 still apply, except that a deployed database
    can now be upgraded: the web dashboard is not compatible, only Linux amd64
    packages are published, a local state directory stays with its package version
    and interrupted runs are not recovered.

Debuglet v0.2.0-rc.1

Debuglet v0.2.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@vincent10400094 vincent10400094 released this 25 Sep 20:15
v0.2.0-rc.1
8a8e7e4

This is the first release candidate for Debuglet's hardened local and remote
operation workflow.

It introduces the dbl CLI, Go client SDK, versioned HTTP API, authenticated
sessions, enrolled executor control, verified Linux amd64 packaging, and
isolated development and production deployments. See
CHANGELOG.md
for the complete categorized changes and limitations.

Download all three assets into one directory and verify them before installing:

sha256sum --check SHA256SUMS
sh ./install.sh \
  --archive ./debuglet-v0.2.0-rc.1-linux-amd64.tar.gz \
  --checksums ./SHA256SUMS \
  --version v0.2.0-rc.1 \
  --prefix "$HOME/.local"
"$HOME/.local/bin/dbl" --output json demo

The separately deployed web dashboard still uses the retired mock-login API
and is not compatible with this candidate. Use dbl or pkg/client while its
migration is completed. State-directory upgrades between package versions are
not supported; use a fresh state directory for this candidate.