Fluxheim 1.8.2 #149
eldryoth
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Fluxheim 1.8.2 Release Notes
Fluxheim 1.8.2 completes unsigned Windows portable parity on native x86_64
MSVC while preserving the same seven public profiles used by Linux and Apple
Silicon macOS. Windows ARM64 is deferred until sustainable native build and
test infrastructure is available.
Windows Portable Release
.zippreviews forfull,wasm,cache,proxy,load-balancer,php, andconfig-testerwith the native MSVCtoolchain and deny Windows-target compiler warnings.
verified upstream TLS, memory and persistent storage-bin cache,
load-balancer, integrity-authenticated snapshot create/list/rollback and
doctor verification, admin, metrics, ACME storage, crash-restart recovery,
CTRL_BREAK shutdown, and packaged-Wasm tests.
certificate-storage assumptions with reviewed Windows-native behavior while
retaining fail-closed owner, ACL, reparse-point, and exclusive-writer checks.
phpprofile on the shared FastCGI request path withexternal TCP pools. Managed PHP-FPM supervision remains Unix-only and is
rejected during Windows configuration validation and runtime construction;
a native Windows TCP FastCGI responder regression proves the supported path.
cache-encryption, peer-fill, and discovery credentials; new private files and
directories receive protected DACLs before secret bytes are written.
reparse traversal disabled, and reject untrusted writable cache, state,
logging, configuration, ACME, and PHP-spool ancestors.
cache reads across concurrent growth, make snapshot/ACME/cache directory
flushes real, and use delete-on-close request-body spool files.
windows-permissionsdependency checksum and isolate first-party unsafeWindows path traversal in the narrowly scoped
fluxheim-windows-securitycrate.and create cache object and encryption-state temporary files relative to a
validated parent before writing bytes.
the vendor configuration ends in a
Matchblock, and reject non-SSH, mixed,or duplicate tag signature formats before allowed-signers verification.
trusted Linux release host, install the required native toolchain, transition
to a dedicated non-administrator SSH account, and verify Administrator SSH
is no longer accepted. Fresh-host provisioning handles empty OpenSSH groups,
refreshes newly installed prerequisite paths without exposing mutable Rust
tools machine-wide, and validates the global policy around the stock
administrator
Matchblock.process so it remains reliable under public-key-only OpenSSH sessions without
granting access to the machine-wide Windows private-key store.
replacement on Windows.
through delete-capable handles, and surface any rollback failure explicitly.
first-party source boundary as well as the pinned ACL dependency checksum.
self-contained managed
PHP-FPM runtimes with one smoke-verified application extension contract,
including MySQLi and its required MySQLnd module. The PHP image smoke rejects
extension load warnings and executes a real request through each image.
php-suse-microwithphp-suse-bci. The dedicated SUSE BCI PHP baseprovides an official PHP repository and matching PHP-FPM stack, while the
pinned SL Micro base does not. Other SUSE Micro profiles remain supported,
and Windows PHP continues to use external TCP FastCGI as documented.
wnaf 0.14.0dependency with0.14.1.phpprofile against a checksum-pinned official PHP NTS FastCGI process and
verifies real PHP output, request-body forwarding, and CGI TLS context over
public HTTP and certificate-validated HTTPS.
sending
SCRIPT_FILENAME,DOCUMENT_ROOT, orPATH_TRANSLATEDto anexternal Windows FastCGI process. This fixes real
php-cgi.exerequests thatpreviously returned
No input file specified.Let's Encrypt staging HTTP-01 issuance, activates the installed certificate,
and verifies its hostname and fingerprint from an off-host client.
certificate-validated HTTPS through the Windows
proxy,load-balancer,cache, andfullZIPs. It proves two-origin selection and failover, memorycache reuse, and persistent storage-bin recovery with the origin offline.
compatible workspace dependencies, and move
sanitization,base64-ng,Brotli, Zstandard, MaxMindDB, AWS-LC, Rustls, Wasmtime, and the QEMU setup
action to their current reviewed releases.
machine-wide executable search path, clean obsolete machine environment
entries, and make the release runner fail closed when invoked with an
administrator token.
recursively read-only tree with a verified file inventory. Official evidence
requires a builder provisioned within 24 hours, a fresh per-run Cargo home,
allowlisted build environment, and protected Cargo working directory.
expired self-healing rollback.
clients so confirmation and successful health reports cannot overwrite the
preserved retryable recovery state.
apply their protected ACL atomically, preventing junction replacement between
validation and creation.
weakening replacement, ownership, or ACL protections; remove unused Rustup
proxy links before sealing future toolchain inventories and correctly record
the native compiler host without colliding with PowerShell's reserved
$Hostvariable.the protected Administrator profile. Provisioning rejects any pre-existing
object instead of attempting to repair its ACL. Official evidence remains
limited to fresh, single-tenant disposable hosts.
default release binary in two clean target directories, build each of the
seven profile archives once, and aggregate native test evidence and checksums
through the repository-owned Linux helper.
identifiers, proving byte-identical default binaries across clean target
directories on the native release host.
O_NOFOLLOWfrom each target ABI instead of using an x86 Linuxliteral, restoring symlink rejection on Linux ARM for configuration, ACME,
Wasm, GeoIP, observability CA, upstream TLS, and static-file inputs.
Windows runtime and seven-ZIP matrix, and the Apple Silicon seven-profile
archive validation before release preparation.
Exact-Tag Publication Gate
from a dedicated native x86_64 Windows builder. Evidence records the
Windows edition and build, and every executable in all seven ZIP profiles
must launch and report the expected version. Planning-only output and the
normal x86_64 CI result are not substitutes for exact-tag release evidence.
directories, collect the seven checked ZIP profiles, and destroy the
disposable builder.
The Unix/OpenSSL FIPS support shim remains excluded as an independent Windows
workspace package while staying covered by the dedicated Linux OpenSSL-FIPS
profiles.
These archives remain unsigned previews. Authenticode and installer work stays
deferred until company-backed publisher credentials are available.
Checksums And Signatures
6ed82b5a9ebd5b8f1bb4bc03f986edd9a33ae855bf88d1d6bd27c0a8b46975230d9483f43bbd0e1289466e72fd9b6e7ee6a9353c fluxheim-1.8.2.tar.gze354839d1a7e9a8a3ca6146baffecc47de06c6aef0e21ba15be2e574d04d11d5 fluxheim-1.8.2.zip1a323dcd5632e25acf2e4463e549f20cdd3d568f445f9d923b1be312ec7f9839 fluxheim-1.8.2-full-x86_64-linux.tar.gz6bfe473e9c12189d4309b662cad64c71d53d49a524cc94adb4980401026a6faf fluxheim-1.8.2-wasm-x86_64-linux.tar.gzae41cafaf1abec4de14e7bec771ece3ced6b3f9f0eebd3bc23c4e5637f953f37 fluxheim-1.8.2-cache-x86_64-linux.tar.gz6d93adbe9d11d9b8dede5acbfb4b5fcd0cb721b58ee6c67a0d748675d471e4b8 fluxheim-1.8.2-proxy-x86_64-linux.tar.gzf0b32023407aaaa745b9c3693731010cedec09c1ef824ba3fed09cf490a86b15 fluxheim-1.8.2-php-x86_64-linux.tar.gz1cd3f30267edb630818434562c566fc8ebb22f2758fb59750299a9f7ef560006 fluxheim-1.8.2-load-balancer-x86_64-linux.tar.gz1c322cc1c959867a6aaf67e6aba82990729bc8b84f2b32c2ce971bf7814de605 fluxheim-1.8.2-config-tester-x86_64-linux.tar.gz814d51ba95337c9014ce3dd641debee20acdccc677befa9877aeaf674b13fc44 fluxheim-1.8.2-full-aarch64-linux.tar.gz6c57cc3842f8947c8d357dd5a7cdfe411b75ee32565811a96832c7a21b50dc8a fluxheim-1.8.2-wasm-aarch64-linux.tar.gzcf316d7012e3db6ceac767695fe7e9bbcdfaf19f8b75a723b368af01f1574481 fluxheim-1.8.2-cache-aarch64-linux.tar.gz1d6e48714e556736f5830738aabb06a8f91bde381430f6994d7eceeba69314e8 fluxheim-1.8.2-proxy-aarch64-linux.tar.gz3400194285112c1a5125d01d80d4452379bf54a626dbe145cd16b2499b42adb1 fluxheim-1.8.2-php-aarch64-linux.tar.gz4335c96925205bdac844a5df02f2c2c19116e253d566f4b9272481e3004781e3 fluxheim-1.8.2-load-balancer-aarch64-linux.tar.gzc603de7f1fb94e418443d48ec9172f59792fbd75e30f7cb545e6ef3c3002aa5f fluxheim-1.8.2-config-tester-aarch64-linux.tar.gza725ebcccac259af6640da57ce12e7a3944c5bd0d9e7869d4001196a0c394031 fluxheim-1.8.2-full-aarch64-macos.tar.gz0cbbe1c936882b6596d97b67599618397b8a541f963651cd4d94eff4ed09f691 fluxheim-1.8.2-wasm-aarch64-macos.tar.gzcb279afe1dd941e497a33797223a583976d28229b2b18ff25eb6837a269b88b0 fluxheim-1.8.2-cache-aarch64-macos.tar.gz88927c0aae2c1f58584b005c9b3bb176474c6645485cf3b09ba0b0253243c506 fluxheim-1.8.2-proxy-aarch64-macos.tar.gzb5bc276d808001cec28afe638808d6c10f704b680aae3f038460fb678c0ed771 fluxheim-1.8.2-php-aarch64-macos.tar.gz60605fcdee80fa3186eecb281ad69add70891bac3cf575eade87434e48b6b4cf fluxheim-1.8.2-load-balancer-aarch64-macos.tar.gz00546a590966b8817e3171de418e963165b645402c3a637276cc2e8f814d4e53 fluxheim-1.8.2-config-tester-aarch64-macos.tar.gza72b84720083406f318bf3fc87555eb62fd76dbd1506dbf2cd368e7364726b44 fluxheim-1.8.2-full-x86_64-windows.zip1ef42f792f5016c93e71fd2768671475738b486cee8d69b0d2514226fda2de4e fluxheim-1.8.2-wasm-x86_64-windows.zipc804c5f5cb4c5aa5a9b3112e1028eeb53cb4bdc65ddddb251cf6f4e38f9d4ef4 fluxheim-1.8.2-cache-x86_64-windows.zipddc55d88f10e0c634eec24c6dd69964a58928033bbd3048ecd927101c6d3a6d2 fluxheim-1.8.2-proxy-x86_64-windows.zip671be0bf8c779ba8d39b57b361bfc23c6ad7af6c26b584aa4e92ef46dca87423 fluxheim-1.8.2-php-x86_64-windows.zip2e433deaf66f0746d23f81bf29972c9ac007e8d192a96bfc0b3da340dff2793d fluxheim-1.8.2-load-balancer-x86_64-windows.zipe687d44f1b2c8da0db6f66cb6da682ea05a8ac6f92fb48756c47c69efc3bf066 fluxheim-1.8.2-config-tester-x86_64-windows.zip5a28b86096642a7484c5b7d6c78bdcaa9e610403bca2be941dea3943eeaf6a6a fluxheim.spdx.json1b946b3b4990aaf8861937d1d91d50cd5ddbe551217d424b90d721c06d32d7ff fluxheim.cyclonedx.jsoncfebc71b181042efbe376232c85e8dd1a25a38d65183ddee1b1d6ae21f84d1edLinux x86_6479ce8547d597319dfd4f51a17650df072c76060af86295359aa909b21d35ac07Linux aarch64822ff4c5bbf23d0164a57296da6457dba3ca47f4eef638bd5b0069fcbda1ba00macOS (Apple Silicon / aarch64)e2bc8612c9570f24730e5b4a91307faf9d0cc0ab5f3edeff0c3038d25a1ddbeaWindows x86_64ghcr.io/valkyoth/fluxheim:v1.8.2-wolfi@sha256:ce770d02f7eedf7c7f61e447c904e9bc1d0a07080eac9d3a538255f65440e11cghcr.io/valkyoth/fluxheim:v1.8.2-alpine@sha256:8625df6702ecadb957f25ae842c6f633913e7780374732ce6b72b57e76774185ghcr.io/valkyoth/fluxheim:v1.8.2-suse-micro@sha256:17db66e5861f5a02dde625f7868cd707cef6bcd6d224640d16d46e8dcfd0e2c8ghcr.io/valkyoth/fluxheim:v1.8.2-debian@sha256:25735646642138517095d3426eaa3e5581d8ea338b03b053796c83c06215a073ghcr.io/valkyoth/fluxheim:v1.8.2-wasm-wolfi@sha256:6c5537c5d2703a98735d5fd90d5d907db40af56443ebe59bf14b522185265959ghcr.io/valkyoth/fluxheim:v1.8.2-wasm-alpine@sha256:0e1ea822359d0d9fb1d310d69517df748bb9ae47f4d098ed382a52877b780201ghcr.io/valkyoth/fluxheim:v1.8.2-wasm-suse-micro@sha256:5d8945b3597ebc788e8b58c806b3094225d7fabc43c04710de8f5e50a6f836d9ghcr.io/valkyoth/fluxheim:v1.8.2-wasm-debian@sha256:1dcf7fed64839c17d0e5c20bc2ea0b8d09e1998cf1a5feb5947e9ea63b55c1abghcr.io/valkyoth/fluxheim:v1.8.2-cache-wolfi@sha256:26ee7950e4d26c795087399fc129a55de1cb5ee71f35a37d35a0303db0f90ee6ghcr.io/valkyoth/fluxheim:v1.8.2-cache-alpine@sha256:99ec49ccc0ad0f6abd562811c7101f07d5f801519b1f69e3d6c13626e782b36fghcr.io/valkyoth/fluxheim:v1.8.2-cache-suse-micro@sha256:541e0db1fb5369c91736bd26e07b4d84fb4c7e654ec05a0c507cfbbcdc4e830cghcr.io/valkyoth/fluxheim:v1.8.2-cache-debian@sha256:9a4708a935c2576f5b75774e79abebe39344ee4c3497ec5894db550fdeff87abghcr.io/valkyoth/fluxheim:v1.8.2-proxy-wolfi@sha256:3e032785fa31181411d8d9633099bb871f51899c6659fb83f3ca777b9a3cc4fdghcr.io/valkyoth/fluxheim:v1.8.2-proxy-alpine@sha256:39d454bd885273bc46bf5de5f4cc4654b39bdf154b41e458377089e4ef5157ceghcr.io/valkyoth/fluxheim:v1.8.2-proxy-suse-micro@sha256:45db1dc898bd27e7452f675b851c65ca977665dce338fe61cd48cb9b4113de2aghcr.io/valkyoth/fluxheim:v1.8.2-proxy-debian@sha256:6674a15a7f804999b2a6b8065901fea6338433fe191e7d8295c75dc0a9be51b6ghcr.io/valkyoth/fluxheim:v1.8.2-php-wolfi@sha256:39a4f620a3556955760082a11fe109ccbac6334011c95e974ad1c712944f377bghcr.io/valkyoth/fluxheim:v1.8.2-php-alpine@sha256:7337a6deb42ab0faff96d8ecd236ce7d107e05cf6f8e918d83fecdb44087662cghcr.io/valkyoth/fluxheim:v1.8.2-php-suse-bci@sha256:c5200ff713f3cfd2cce60dd37674d006a8dee691df4b5d3cf8f2bd95646c5eebghcr.io/valkyoth/fluxheim:v1.8.2-php-debian@sha256:49f9fade1fd124c3350020ebd30c67a60f854f188a533c5ec57a6df05702c475ghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer-wolfi@sha256:ca10d554bf035c5ef9e798ed3378e7abab2e80ef2a3d406738ddbfadb43a288fghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer-alpine@sha256:8fbbdf01030a9d32be05ff74165b6066f96da416d776cc9b2206f4770d317fc2ghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer-suse-micro@sha256:3c07e72da36de9d7a3acb5faf02ed7446d4a50f9ff725263abd56b92c325767aghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer-debian@sha256:d00257ad70fbb364b78335063c168f1ef6043b95136e2cf99dbb117b737ed21aGood "git" signature for 1921261+eldryoth@users.noreply.github.com with ED25519 key SHA256:EoLRQ5k4J5pYz3UMFmkrV798gYFNkToGS2xEPvebqB4This discussion was created from the release Fluxheim 1.8.2.
All reactions