v0.109.2 #991
v0.109.2
#991
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What
The second refusal, one layer down.
v0.109.1fixed the fossil envelopein the release gates and died on both Linux builders one leg later:
[consent-run] exit=3 want=4— since #889 (0.109.0) a workflow thatdeclares
permits:refuses to START on a host with no sandbox backend(
NIKA-1710), and a GitHub Linux runner has no bubblewrap. The macOSbuilders, where seatbelt exists, passed both gates confined. No asset
shipped under
v0.109.1either; the binaries were fine both times. Thispatch is the same tree plus the second fix and is the version consumers
install.
Fixed
(release.yml). The Diamond CI tests-leg recipe (apt bubblewrap · detach
ubuntu-24.04's AppArmor bwrap profile · keep unprivileged userns open) now
runs on the two Linux builders, so the funnel e2e and the trust battery
run CONFINED there exactly as they do on macOS — never a waiver. A gate
that spends an
execunderpermits:proves the jail as a side effect;a host that cannot jail says so (
NIKA-1710) instead of being wavedthrough.
Install
Tarballs below: macOS arm64 / x64 · Linux x64 / arm64, plus
SHA256SUMS.Verify: three independent proofs
Provenance
Built from tag
v0.109.2byrelease.ymlon GitHub-hosted runners. Provenance is published twice: GitHub's native
build attestation (proof 2) and the SLSA generator's
multiple.intoto.jsonlrelease asset (proof 3). The release itself is a claim on the
machine-verified timeline: https://nika.sh/timeline
What's Changed
Full Changelog: v0.109.1...v0.109.2
This discussion was created from the release v0.109.2.
All reactions