Skip to content

unMotion 0.4.2

Choose a tag to compare

@rtho782 rtho782 released this 03 Oct 23:53

unMotion 0.4.2

General availability release with restricted host pairing, safer process signalling and native pre-start recovery fencing.

Upgrade both peers together

0.4.2 requires protocol 7 on both hosts. Transfers and recovery coordination with 0.4.1 or earlier are not supported.

Before updating, finish or explicitly remove prepared/partial Warm Moves using the old version, pause scheduled replication, wait for migration/recovery/cleanup jobs to finish, and shut down recovery-managed source VMs and recovered activations. Keep verified backups. Upgrade both peers in the same maintenance window, then test their pairing and native-fence readiness before resuming operations.

Existing settings, host IDs, pairings and durable recovery authority are preserved. Unproven legacy receive ownership is retained and blocked rather than silently adopted or deleted. Do not clear fencing records or remove key restrictions to bypass an upgrade error.

What's included

  • Plugin-managed SSH keys now use a restricted forced-command endpoint. Authenticated operations are bound to the paired host, selected VM and admitted storage; arbitrary shell commands, forwarding, unrestricted file transfers and unsafe XML/archive targets are refused.
  • Cancellation and service cleanup verify process lifetime, executable and arguments before signalling. Dynamic HTML quotes are escaped, and numeric resource/progress input is bounded before shell arithmetic.
  • Native libvirt hooks reject unauthorized recovery-managed starts before QEMU starts, preserving Unraid's existing hooks. Recovery arming requires actual hook-callback proof. An unresolved source start blocks destination recovery authority.
  • Recovery → Start source VM requests a one-off authorized start without enabling autostart. Start recovered VM obtains fresh authority for an existing destination activation.
  • Same-job retries preserve verified completed ZFS receives after later host-state failures. Managed-start autostart parsing handles large libvirt output correctly.

This remains coordinated manual recovery with a reachable source—not automatic failover or live migration. Replication still requires dedicated ZFS storage and eligible Guest Agent evidence for recovery. Pair only trusted hosts: permitted VM/storage operations remain privileged.

Verification and downloads

The full Linux verification suite and disposable two-host lab tests cover cold/Warm Move, sparse raw/ZFS/zvol storage, ISO, UEFI/TPM, cloning, resumable receives, replication/recovery, mixed-version rejection and native fencing, including libvirt reconnect. See the test record, upgrade guidance and Unraid user guide.

Install through Community Apps or the stable plugin feed. Both update feeds graduate to 0.4.2-stable; the application reports 0.4.2. The PLG downloads the attached TXZ and checks its SHA-256. Keep the installed descriptor filename unmotion.plg. SHA256SUMS covers both release artifacts.

Author: Richard Skinner. GPL-3.0-only.