Fluxheim 1.7.7 #126
Closed
eldryoth
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Fluxheim 1.7.7 Release Notes
Fluxheim 1.7.7 adds the first opt-in
wasm-proxy-abicompatibility previewboundary. This release does not claim that existing arbitrary proxy-wasm
plugins run unchanged. It establishes the safe shape for that work: explicit
ABI and host-call namespace validation, feature-gated config acceptance, and
deterministic unsupported-call rejection.
Added
wasm-proxy-abifeature propagation through the root, config, server,and
fluxheim-wasmcrates.host_call_namespace = "proxy-wasm-preview"support for[[wasm.plugins]]entries when paired withabi = "proxy-wasm-preview".combinations.
calls deterministically instead of silently binding to Fluxheim's native
policy namespace.
host-call namespace before Wasm instantiation, with a stable import-specific
error.
proxy-wasm
env.proxy_log(i32, i32, i32) -> i32import and prove that theunsupported call fails closed with
503before the upstream is reached.Security
proxy-wasm-previewhost calls remain disabled unless the binary is compiledwith
wasm-proxy-abiand config explicitly setsallow_preview_abi = true.so future compile-cache reuse cannot cross from
fluxheim-policy-v1toproxy-wasm-preview.access-decision, and independentlyprevent native request-header, route, and cache host functions from being
linked into the preview namespace.
[server.host_routing].strict = truefor native HTTP/1 Host andHTTP/2 authority routing. Missing or invalid identity returns
400; anunknown host returns
421instead of reaching the default tenant.spawn_blocking; honor boundedqueue_limitwaiters and replace per-requestwatchdog threads with one process-wide shared epoch ticker.
saturated plugin or attachment from reserving broader process capacity, and
cap active/queued Wasm budgets at
256.rustls/AWS-LC FIPS validation when a rolling distribution's default compiler
is outside the supported range; explicit compiler selections remain
authoritative.
max_in_flight = 64by default and a256process-wide ceiling shared byall routes. Saturation fails closed with
503.authenticated operators through a global invalid-attempt lockout.
header counts, and fallible allocations. Decoded local AES cache keys now
remain in
sanitization::SecretBytes<32>through key construction.cargo-denyandcargo-auditinstalls, and pin every container builder/runtime base image toa reviewed digest.
construction and verify persisted object identity before serving, preventing
cross-policy allocator corruption from becoming cache disclosure.
bridge.
lifetime-exclusive lock file so separate Fluxheim processes cannot allocate
the same root concurrently. Standalone CLI inspection retains a bounded
filesystem-backend index rebuild because that backend has no shared allocator.
socket path that exceeds the platform address limit before spawning PHP-FPM.
431,414, or400responses for bounded request-headparser failures instead of closing the HTTP/1 connection without a response.
256-slot request-driven blocking-work budget across Wasm,external auth, traffic mirrors, disk-cache operations, and ACME challenge
reads. Explicitly cap Tokio's blocking pool at
384, leaving128slotsoutside request admission for operational work.
preventing a losing process from modifying first-start metadata.
per-replica local/RWO volume by default, and require verified cross-node
flockbehavior plus orchestration-level single-writer enforcement beforeusing shared RWX storage in high-assurance deployments.
224non-critical and256totalceilings, reserve
32critical slots, and return503rather than contactingorigin when disk-cache lookup admission is saturated and no stale memory
object is available.
allocation, admit aggregate descriptor sizes before reading/parsing, decode
bounded borrowed country strings, require trusted ownership and non-writable
modes for MMDB files and all parents, and reject files changed during loading.
allowlist. Client-authentication, compliance, listener trust/limits, stream,
UDP, ACME, cache-purger, tracing, and other startup-owned changes now require
process replacement instead of being accepted as snapshot reloads.
identity/domain changes and managed PHP-FPM pool/process changes require
process replacement, while ordinary routing and request-time PHP policy stay
snapshot-safe. Exhaustive vhost, route, and PHP-FPM schema audits prevent new
nested fields from silently bypassing review.
to have trusted ownership and non-writable group/other modes. Verify path and
descriptor identity and reject config files modified during bounded reads.
dual-FIPS-backend feature combinations.
encoded bytes, transfer emitted codec buffers into response bytes without
copying, and permanently discard a codec after an output or allocation
failure.
Accept-Encodingfields,honor explicit coding rejection over wildcard acceptance, and suppress
compression for qualified
Cache-Control: private="..."responses.no-follow
statatmetadata inspection, and remove environment-derivedfilesystem writes from storage-lease subprocess coverage.
Changed
base64-ngto 1.3.7,bytesto 1.12.1,regexto 1.13.0,sanitizationto 1.2.4, and test-onlywatto 1.253.0.1.97.0.
lines in the database and health-check smoke defaults.
dependency patch so the checked-in fuzz targets build against their current
owning crates again. The fuzz validation gate now compiles every target.
with one fallibly-created process-wide persistence worker. Maintain ordered
eviction state so selecting the oldest object no longer scans the complete
object map.
fluxheim-base-images.txtto generated release evidence beside SPDX andCycloneDX output so reviewed image digests are recorded for each build input.
smoke roots, using a compact root for Unix-socket tests, so the suite exercises
the same full-ancestor trust policy enforced in production.
Operator Notes
wasmconfigs usingfluxheim-policy-v1continue unchanged.--features wasm-proxy-abi, setallow_preview_abi = true, and declare both:calls fail closed through the plugin fail mode.
Checksums And Signatures
f1c2497bca3fcfd9112d08ad65b3bc2aafb2e4215dbc0fd24140f2a81b52b46d63f09f70c3056c09fc1ec82cfcbd3860a0083f81 fluxheim-1.7.7.tar.gz40b33aea8811b6091c0fbe3e8e8368bc09843b59758a3c1bd6de2fc2defccbac fluxheim-1.7.7.zipa03d30135990810b66cef61d3b401fe65063e5c8ed7d19304c15c9ec690eb35d fluxheim-1.7.7-full-x86_64-linux.tar.gz9775db4a60895845c436abb9104f9ed53d1d7e987eeaf68b0ba67d2ff2543959 fluxheim-1.7.7-cache-x86_64-linux.tar.gz99e3e18b4c893cb3adf68ccb5757ffe2425de70a7638f52ed22d3c7e61db747f fluxheim-1.7.7-proxy-x86_64-linux.tar.gz9e85a4223cdb22d883937563394f27aa3d862bb23ddde5f2ae5ce45cb5de1c86 fluxheim-1.7.7-php-x86_64-linux.tar.gzcdd5d3f732565744fccdce772f9124db06273db70bd9a20729ba6eed9468d083 fluxheim-1.7.7-load-balancer-x86_64-linux.tar.gz2f167341116e3a08196c9d6bb47014439c8fbcacb36d90af32d15d292475bcc7 fluxheim-1.7.7-config-tester-x86_64-linux.tar.gz871d3f155d71366fd2e3fefbc124ecee4e5af4d065e1fd13f96c616e694e2b89 fluxheim-1.7.7-full-aarch64-linux.tar.gzc6d0144fc24a09c3a95ab4985d37e759d1928ac6940852636661d081c96909c3 fluxheim-1.7.7-cache-aarch64-linux.tar.gze0a88c9d7a0350f0752a8cd2226aa322e8e4937564acb4fe1aa0412f5ee87dac fluxheim-1.7.7-proxy-aarch64-linux.tar.gz7ba6a498023d620ee2325165d64df6b33fab78d50935fc049378df69cd6c3bec fluxheim-1.7.7-php-aarch64-linux.tar.gz860c4bcc84008a1c3d0032afbe5f126c5582a5ae57e55ab635f6e7b397beb954 fluxheim-1.7.7-load-balancer-aarch64-linux.tar.gz94ee9b0f7308f41b42a542c20f9f58a177588c8a2c7e958ff61e9c3548e2c316 fluxheim-1.7.7-config-tester-aarch64-linux.tar.gz3a20a9712b836ce34b4e944b997a3f4cd40896ed087587644cda3d1124e5f0ef fluxheim-1.7.7-dev-aarch64-macos.tar.gz3e4cc3ee37193046c303a2d73607ce7dbb1883a777cec1cd92f2068905e75658 fluxheim.spdx.json81924680a6a3fef7149092ca8a4784f320a0ec2915133a9ace2dd8c4a77c0df2 fluxheim.cyclonedx.jsoned33bac10f18841319f6a58c9e3be70cf762d304bd3d2361b3d9dd54f308d680x86_649bd52b28fd3006209db091e68119b0f591e211a1dca7471dadc4343d478bb1a2aarch64e9ecd72d77fba07de0107afb32aaf5234e15d85929619332a9ae8b211da7f10cmacosghcr.io/valkyoth/fluxheim@sha256:14c6bc7f77b988685818b6e63135d6187c244a33208888c24bf6fd557f7cb682ghcr.io/valkyoth/fluxheim@sha256:27dcb205b3d5ffd188ecd907708ca4c16f416c6429e22e529a741831043b65daghcr.io/valkyoth/fluxheim@sha256:353e3903b2f456079035827417a3cb8500679d6440a6fa012003073d81d25ab7ghcr.io/valkyoth/fluxheim@sha256:f85092f1ebe7904c96c77a95d8755feddf5c228fb9ba1bf4f4ad4c969a16aeb0ghcr.io/valkyoth/fluxheim@sha256:282d1002f856101cfef8d8b9bd2326a5a47ea3b3ecc0d46b1cf8a3805ceceaa2ghcr.io/valkyoth/fluxheim@sha256:8961896aa1f0039c3b300ad0a5b3481abea669f482c0a3105222dfaed44e6d32ghcr.io/valkyoth/fluxheim@sha256:35bfbf10aa16eae80f419e14bb0424cbf4803b57db4421773dc50831322d4d12ghcr.io/valkyoth/fluxheim@sha256:6bba1414f498f6c93a009a443c12e231a0fc3d52cb80f176bfbcbe36c2946ff5ghcr.io/valkyoth/fluxheim@sha256:348aceaa93b612df860f27fb6fe88c687a5bc03f78c973a71ef84485854b26ebghcr.io/valkyoth/fluxheim@sha256:0037f2e7a46c66326ae1e5e28f458c394e19ea76f2a2f3958f6cbd01c1446b47ghcr.io/valkyoth/fluxheim@sha256:6fadde927f83af80bd420a8b756c43d5c7a61a85d20a2363797fd08a74e288bdghcr.io/valkyoth/fluxheim@sha256:79ab7bc774e868686f0aa4796b4793482cb4719a0cf8d2dc9ba87da85c42cb4eghcr.io/valkyoth/fluxheim@sha256:c9055e3cfb2311ac19f14218815c06fa304a8a27e6ebcd50341ea6e8300bb9d9ghcr.io/valkyoth/fluxheim@sha256:16010cafdb92248012f032efd1a075c7f4d724f9411cd50c2c097abadfa6d348ghcr.io/valkyoth/fluxheim@sha256:05e0fc5e2700255809dc48567b65b60e759ef74cbc47ad24b4c32c5546cfb142ghcr.io/valkyoth/fluxheim@sha256:a411ecc767a518022252c53c2c47da7020624082bfd999d8ca188c1692e65235ghcr.io/valkyoth/fluxheim@sha256:1e73487f6d4d4d784174f2403c44783968e9bf8097a8b19b17a5da26e7f204beghcr.io/valkyoth/fluxheim@sha256:217613ed61d96a42828604b02b8990c56fed9e06ac4479b7b2cba42f113e206dghcr.io/valkyoth/fluxheim@sha256:754c1a520325a437de7124b714c42072701e5b8cf8ecc2f921ed5d14c8a280d0ghcr.io/valkyoth/fluxheim@sha256:44549f5abb9aec58cffdceab411c758db94cc495c2c0a398cce6707b9036ccf8Good "git" signature for 1921261+eldryoth@users.noreply.github.com with ED25519 key SHA256:EoLRQ5k4J5pYz3UMFmkrV798gYFNkToGS2xEPvebqB4This discussion was created from the release Fluxheim 1.7.7.
All reactions