Fluxheim 1.7.8 #127
Closed
eldryoth
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Fluxheim 1.7.8 Release Notes
Fluxheim 1.7.8 starts the optional WASI Preview 1 capability boundary for
non-request-body policy plugins. This is a narrow access-decision preview, not
general-purpose WASI application hosting.
Added
wasm-wasifeature through the root, config, server, andfluxheim-wasmcrates.wasi-previewABI and host-call namespace pair.[wasm.plugins.wasi]with independentclocksandrandomnessgrants,both disabled by default.
wasm.max_total_preview_concurrent_executions, defaulting to and cappedat
32, for both WASI and proxy-ABI preview access hooks.the normal Fluxheim sandbox.
normal route handling while an ungranted import fails closed before origin
dispatch.
standalone Wasm smoke.
client address for HTTP/1 and HTTP/2 policy evaluation.
provider-specific string ASN field.
ASN policy on static, direct-proxy, and load-balanced request paths.
Security
rebinding checks, closing access to embedded loopback, private, link-local,
metadata, carrier-grade NAT, benchmark, and other reserved IPv4 addresses.
shared idle deadline from their latest successful transfer. Partial writes
can no longer be cancelled and silently discarded when reverse traffic wins
the dispatcher race.
copy buffers on drop through
sanitization.StreamUpstreamSelector, preserving the config limits at the public runtimeconstruction boundary.
private locking, explicit parent/generation history, create-new publication,
temporary/orphan cleanup, retryable rollback, persisted self-healing state,
redacted invalid-ID diagnostics, and typed clock errors.
Config and metadata are verified before rollback parsing; legacy stores are
reported as unverified rather than silently authenticated.
generation witnesses so pruning cannot reuse audit generations and freshness
scans remain bounded without rereading complete snapshot configurations.
fully verified all-legacy store with no generation counter bootstraps from
its highest generation, persists authenticated state first, migrates its
manifests, and publishes the next snapshot at
max + 1. Missing state stillfails closed for V2 and mixed stores.
OpenSSL-FIPS, or AWS-LC-FIPS provider, returning provider failures to the
administrative caller instead of aborting the data plane.
keys outside the snapshot store, and authenticate intentional pruning
boundaries.
show,diff,verify,doctor, andprotected
pruneoperations. Snapshot TOML remains plaintext and needsencrypted storage or backups when confidentiality is required.
only TLS 1.3 suites disables TLS 1.2, and a policy with only TLS 1.2 suites
disables TLS 1.3, preventing inherited acceptor defaults from negotiating an
unconfigured suite. Move to OpenSSL's Mozilla v5 acceptor baseline so the
legacy v4 template cannot suppress configured TLS 1.3 listeners.
bounded, atomically replaced in-memory SNI certificate table. Remote
handshakes perform lookup only and cannot trigger file parsing or loader
logging.
64 KiB, and client-auth CA bundles to 8 MiB and 4096 certificates in both
downstream TLS providers.
sanitization::SecretVecuntil provider parsing completes. Read key filesdirectly into protected storage so partial I/O and concurrent-growth errors
also wipe initialized key bytes.
constant-time-oriented decoder and report only the redacted decode-error
class, never an offending secret-adjacent byte or input index.
builds no longer include AWS-LC; AWS-LC remains explicitly selected by the
rustls FIPS profile.
base64-ngout of default and OpenSSL-onlyfluxheim-tlsdependencygraphs; it is now activated only by the Rustls key-parsing boundary.
wasi_snapshot_preview1import before instantiation.Clock imports require
clocks = true;random_getrequiresrandomness = true.polling, and process-exit imports unavailable in this preview, regardless of
capabilities granted for clocks or randomness.
random_getcall at 4096 bytes so guest-selected host workcannot request the full memory budget in one operation.
wasi-previewtoaccess-decision, require explicit preview-ABIallowance, require pinned module digests for that security phase, and retain
fail-closed composition.
authorized modules cannot share an identity.
admission and 32-slot blocking-work pools, preventing preview saturation
from consuming native
fluxheim-policy-v1capacity.FastCGI response collection, discarding timed-out pooled connections.
opened file and every ancestor for trusted ownership and modes, and execute
through the retained descriptor to close path-replacement races.
complete group on shutdown, failed status checks, and watchdog restarts.
retaining a descriptor for retry replay. Give every reader an independent
logical offset backed by bounded positional reads so overlapping readers
cannot corrupt each other's request body stream.
sanitization::SecretVec, clear consumed spool buffers immediately, andclear full buffer capacity on cancellation, error, or drop.
probe growth with a separate stack byte, preventing a one-byte in-place
append from triggering large
Veccapacity growth before rejection.GeoContextconstruction, canonicalize accepted two-letterASCII countries to uppercase, and reject ASN zero before policy consumers can
observe malformed security state.
PATHhandling with a fixed allowlistedsearch path after clearing the child environment.
-after checked epochand year-9999 bounds, preventing attacker-influenced file metadata from
reaching panic-prone timestamp formatters in release builds.
SafeRelativePathcomponent insertion with a validatingsingle-normal-component API so the public type preserves its traversal-safety
invariant for current and future static-serving callers.
execution-timeout, and compile-timeout limits, with matching config rejection
and checked
Instantdeadline arithmetic.constructing a semaphore, and create compilation workers through the fallible
named thread builder instead of the panicking convenience API.
callback so late callback results fail as timeouts. Keep blocking callbacks
prohibited until a killable subprocess runner exists.
guest integer, and property-test all current guest-ID decoders over arbitrary
i32inputs. Keep panic-prone or third-party native callbacks behind thefuture subprocess-isolation boundary.
Validation
Operator Notes
wasm-wasi; the feature remains absent from default images andincompatible with
privacy-mode.[wasm].allow_preview_abi = true, then declare bothabi = "wasi-preview"andhost_call_namespace = "wasi-preview".or execution errors and security-decision hooks fail closed.
stdio, arguments, or process-control access.
untrusted multi-tenant plugins colocated with secret-dependent computation.
config mounts, including explicit
podman unshare chown, an opt-in:Ualternative, and an in-container verification command.
upgrade automatically on their next locked snapshot creation only when every
retained legacy manifest verifies. See
docs/config-snapshots.mdfor thefail-closed mixed-store and external anti-rollback requirements.
docs/geoip.mdfor dataset attribution,trusted installation, pinned checksums, schema details, and the opt-in live
database proof. The large network download remains outside normal CI gates.
Checksums And Signatures
b5a05744b994302cad28612fd542b3957478f794c3194178c40ed80c1343dd58d228c88355ce42b2e220771aa3e7e5ab3e5497a4 fluxheim-1.7.8.tar.gz37021b43b385cdf4f8c8641da80f8938da42b09f0ea4cd1b2c525d6ca4acb2b6 fluxheim-1.7.8.zip3d521d8495ca375c5b294bc3ab1674113fb42cfc9077bd075c11af450c640ebd fluxheim-1.7.8-full-x86_64-linux.tar.gz946a782e943eff2f104795f76625874997ab70ea458cf3fcc0a997ff57563635 fluxheim-1.7.8-cache-x86_64-linux.tar.gz7e44296595f982aa160ef281510fa8496819a97696d4376583d229ea8d7afe03 fluxheim-1.7.8-proxy-x86_64-linux.tar.gz1d2e528611e33901fb05b22f451fbd7347ed26f8eafe942e41283ae136e69006 fluxheim-1.7.8-php-x86_64-linux.tar.gz82f91c9a5fc9e3d36825bfaaf309431e88675fb7a794b3400c26843634efa06d fluxheim-1.7.8-load-balancer-x86_64-linux.tar.gzc2a62959de4cb0de5b4c6a702e669ff1229a9f01fd4ee31ec3dd842f9e9eefe9 fluxheim-1.7.8-config-tester-x86_64-linux.tar.gzd5257311ba44dfc7b6b3f05121156d223e6dd74d8f2fb9bdb60d2d4fffeff55b fluxheim-1.7.8-full-aarch64-linux.tar.gz478238adfb07a7155a3cfd7d7a3fa16b618a5e166d47a4b6e8a7097e178d3627 fluxheim-1.7.8-cache-aarch64-linux.tar.gz281bafeb3275cab9c9b785582c80ba8d4198e6a560ad310fd3e2d4497437e18b fluxheim-1.7.8-proxy-aarch64-linux.tar.gz2a90707a5c626d17dbf108500955a859be10788f8cdfae0f6981b511ded32b23 fluxheim-1.7.8-php-aarch64-linux.tar.gzd75e8c962cebf94bae16cecfb5f79e92f06bef48f8c7f94d1444193f1867301c fluxheim-1.7.8-load-balancer-aarch64-linux.tar.gzb274e6cf61c67b9fa16bab7e00b13d3b44f9076deb21866e783e073bf37e46f9 fluxheim-1.7.8-config-tester-aarch64-linux.tar.gz2d4674caff67a3b2038ea6cc3550252ac57a1a7b31bb3564755d7c654da7a092 fluxheim-1.7.8-dev-aarch64-macos.tar.gz4f4b406af1c8d2cea51dfb380131c36bbb71b2616fc719aa51af3c7178a40179 fluxheim.spdx.jsone6a666da528b7919c305287ce102f3acd43beb6ee4e9311eb448cd22b316bc61 fluxheim.cyclonedx.json177bd4c7d6858e52b69e0dfba08d15e7bc88efb342e700b15aa02542de6deb55x86_64b33ae8ebb600b229652eb35e78edd9f3aaa7c0602ded5f0fdea6db141fc1596caarch64f12ff88fb13f18251722babbfc7d8a336eb6980d033a3ff085903c52f518922fmacosghcr.io/valkyoth/fluxheim@sha256:65b0ec4b2a173abc0cea6739c00048ecbc2d8440778b4e395c5afe624c4e04e6ghcr.io/valkyoth/fluxheim@sha256:6462fa8bf2c5474c94a77a2464c181fc606888f4c5bf9c79fc25d7aac0024c9fghcr.io/valkyoth/fluxheim@sha256:91ffb1f4ea1348c8af7715e3c28cd3e39767dbe048f3b40ed87bc99b926d6f1fghcr.io/valkyoth/fluxheim@sha256:9584cba3b59d8930fa324b60bf71d2ec3d6d6ececfcc9eb03a47b6ea02447d43ghcr.io/valkyoth/fluxheim@sha256:1d3c28a0375f12cf5c31bb6a461573c23ab931b77806372787564fcc9c4d70d5ghcr.io/valkyoth/fluxheim@sha256:01dfa51ae2faf669f02ac8aac615431cf3b42aa699713fdc04a74eccc80bf9d9ghcr.io/valkyoth/fluxheim@sha256:133992977765501b643674e80e12a154723c309c090b856cd41a0654226ba360ghcr.io/valkyoth/fluxheim@sha256:7e9fb73f6d6c8bc77aac11ea613f672c6a51131ffbb77574d79e3fb7cf3304e7ghcr.io/valkyoth/fluxheim@sha256:dce3f37b1b5054ee4bc885f7e97ec15f92db25bec9b9adc6c08833f1aad6e481ghcr.io/valkyoth/fluxheim@sha256:3286412105f05db0da33a8ae3b40a08785f65e0e4a51189118c4a51122bbcb42ghcr.io/valkyoth/fluxheim@sha256:0f21d68713e8125e856f6606c44005a64feb66fc779b3c4c0fec3dc6963f85ecghcr.io/valkyoth/fluxheim@sha256:546f1c0f62184dde3cb9ce21a283acfd71b7dbe6356637e6a4716af5e61f91b6ghcr.io/valkyoth/fluxheim@sha256:8fcf582d0ae1ac20771b7723700d03f2db64130d110bb39404975427a85e616fghcr.io/valkyoth/fluxheim@sha256:3a864626ac2c8de0c67cf2c3f65893fd89baa8167a1b7bc651fbac31d66bbb67ghcr.io/valkyoth/fluxheim@sha256:51539343bf419842d88e494efc6dd5ebba41e65d4f6ed06dfd71b6aedd5359d7ghcr.io/valkyoth/fluxheim@sha256:0e1ce1e37f295e7c392f245a2b5b217ff5b504efe83841df00577f1b2aa05fe7ghcr.io/valkyoth/fluxheim@sha256:07803a0d072eb0a1c7117f78dc0e19cf078b7edf7c78f64f9171da4884f23785ghcr.io/valkyoth/fluxheim@sha256:5efed1e1d711b6e199031e386b8503b2150606c0835d80fb87a3a32800d4f968ghcr.io/valkyoth/fluxheim@sha256:9015d89b4620f7cc9709a62ffb2ea9f0eb487b378cd87cfd3a0118704c1f2491ghcr.io/valkyoth/fluxheim@sha256:43737bc3084861045f957571e26ab1b1c55db40d217f27f4393f602bff7f961dGood "git" signature for 1921261+eldryoth@users.noreply.github.com with ED25519 key SHA256:EoLRQ5k4J5pYz3UMFmkrV798gYFNkToGS2xEPvebqB4This discussion was created from the release Fluxheim 1.7.8.
All reactions