Fluxheim 1.6.37
·
207 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Fluxheim 1.6.37 Release Notes
Fluxheim 1.6.37 is the final pre-Wasm crate-boundary cleanup release after the
Pingora-free runtime cutover and the 1.6.36 structural cleanup.
This release should keep runtime behavior stable while moving obvious remaining
root helpers into focused workspace crates. New substantial code should default
to an existing domain crate, or to a focused new crate when the dependency graph
is clean.
Highlights
- Start the final pre-Wasm crate-boundary cleanup pass.
- Update the pinned Rust toolchain, workspace
rust-versionfields, and
container builder images to Rust 1.96.1. - Harden OpenSSL stream-upstream TLS connectors with a TLS 1.2 minimum and an
explicit modern TLS 1.2/TLS 1.3 cipher allowlist. - Store serialized ACME account credentials in
sanitization::SecretVecwhile
writing them to disk so account private-key JSON is cleared from heap memory
on drop. - Prepare ACME, observability, header-policy, TLS helper, native proxy, and CLI
boundaries for smaller crate-owned APIs. - Remove private root compatibility shims for common errors, filesystem trust
checks, and OTLP HTTP agents; affected call sites now use
fluxheim-common,fluxheim-config, andfluxheim-observabilitydirectly. - Remove the single-use root path-safety shim; admin validation now calls the
fluxheim-commonpath-safety helper directly. - Remove the root test-support shim; root tests now import shared helpers from
fluxheim-commondirectly. - Remove the root cache-header shim; static response planning now calls
fluxheim-cacheheader helpers directly. - Remove root reload, snapshot, and load-balancer re-export shims from active
code; admin and CLI paths now usefluxheim-config,fluxheim-snapshot, and
fluxheim-load-balancerdirectly. - Remove root GeoIP, OTLP trace-exporter, and trace-context re-export shims;
callers should usefluxheim-geoipandfluxheim-observabilitydirectly. - Remove unused root
config_*compatibility modules; remaining callers use
the owningfluxheim-configmodules directly. - Remove root cache API compatibility shims; admin, CLI, metrics, runtime, and
native proxy code now usefluxheim-cacheDTOs and helpers directly. - Move the remaining root header DTOs into
fluxheim-headersand remove the
inline rootheadersmodule. - Split access-log helper functions out of
fluxheim-observability/src/lib.rs
into a focused crate module while preserving the public exports. - Split metrics label and bounded numeric helpers out of
fluxheim-observability/src/lib.rsinto a focused crate module while
preserving the public exports. - Split trace-context parsing and generation helpers out of
fluxheim-observability/src/lib.rsinto a focused crate module while
preserving the public exports. - Split OTLP HTTP agent and OTLP metrics payload helpers out of
fluxheim-observability/src/lib.rsinto focused crate modules while
preserving the public exports. - Split trusted client-IP restoration and Forwarded header helpers out of
fluxheim-headers/src/lib.rsinto a focused crate module while preserving
the public exports and privacy-mode gating. - Split background supervision and shutdown primitives out of
fluxheim-runtime/src/lib.rsinto focused runtime modules while preserving
the public exports. - Move
fluxheim-webcrate tests out ofsrc/lib.rsso the production static
response and directory-listing implementation stays below the line-limit
target. - Split stream upstream selection and stream tests out of
fluxheim-stream/src/lib.rs, leaving the stream crate root below the
line-limit target while preserving public exports. - Split snapshot runtime validation state from snapshot-store persistence and
turnfluxheim-snapshot/src/lib.rsinto a small crate re-export surface. - Split snapshot symlink-safe filesystem helpers and atomic write logic out of
fluxheim-snapshot/src/store.rsinto a focusedstore_fsmodule. - Split snapshot metadata, message, and ID validation helpers out of
fluxheim-snapshot/src/store.rsinto a focused metadata module. - Move snapshot store regression tests into focused functional and path-safety
test modules, bringingfluxheim-snapshot/src/store.rsbelow the line-limit
target. - Move
fluxheim-cacherequest/key/range tests out ofsrc/request.rs,
leaving the production cache request helpers below the line-limit target. - Move
fluxheim-cacheobject/envelope/index tests out ofsrc/object.rs,
leaving the production disk object helpers below the line-limit target. - Move
fluxheim-cachestorage-bin tests out ofsrc/storage_bin.rsas the
first step toward splitting manifest/layout, allocator, and index helpers. - Split the storage-bin free-range allocator into a focused
storage_bin_allocmodule while re-exporting the existing public API. - Split storage-bin layout, manifest, and object-location validation into a
focused manifest module while keeping thestorage_binpublic exports stable. - Split storage-bin symlink-safe filesystem helpers into a focused private
module, bringingfluxheim-cache/src/storage_bin.rsbelow the line-limit
target. - Split cache admin math, warm summaries, object-lookup summaries, and tests
out offluxheim-cache/src/api.rs, leaving cache API DTOs below the
line-limit target. - Split cache header Cache-Control and Pragma directive parsing into a focused
private module as the first step toward request/response header policy
modules. - Split cache request-side header policy, cookie/query bypass matching, and
range/slice request selection into a focused private module while preserving
the existingfluxheim-cache::headersexports. - Split cache Vary header policy and request-hash material helpers into a
focused private module while preserving the existingheadersexports. - Split cache response header policy, freshness helpers, content-type checks,
and range response admission into a focused private module while preserving
the existingheadersexports. - Split cache stale-if-error and stale-while-revalidate policy helpers into a
focused private module while preserving the existingheadersexports. - Split load-balancer selected-upstream and queue/persistence outcome DTOs out
offluxheim-load-balancer/src/api.rs, leaving the load-balancer API DTO
module below the line-limit target. - Split load-balancer FNV hashing, random selection seeds, and per-process route
secrets into a focused private selection-hash module. - Split the nginx-compatible Ketama continuum builder and backend-key iterator
into a focused private load-balancer selection module. - Split the Maglev table builder, candidate iterator, and modular-arithmetic
helper into a focused private load-balancer selection module. - Split load-balancer candidate filtering, passive-health ejection floor, and
slow-start permit checks into a focused private selection module. - Split power-of-two choice selection and weighted random candidate selection
into a focused private load-balancer selection module. - Split consistent-hash, nginx-compatible Ketama selection, and bounded-load
consistent selection into a focused private load-balancer selection module. - Split FNV hash selection and shared weighted-index expansion into focused
private load-balancer selection modules, bringingselection.rsbelow the
line-limit target. - Move
fluxheim-cacheheader policy tests out ofsrc/headers.rs, leaving
the cache header facade below the line-limit target. - Move load-balancer policy override tests out of
src/policy.rsas a
preparatory split for the remaining policy key/snapshot/mutation modules. - Split load-balancer config-derived backend policy maps and aliases into a
focused private policy-config module. - Split load-balancer backend runtime stats assembly into a focused private
policy-stats module. - Split load-balancer runtime override and snapshot state into a focused
private policy-runtime module, bringingpolicy.rsbelow the line-limit
target. - Split load-balancer persistence request-key helpers and managed-cookie
HMAC/token handling into focused private modules, bringingpersistence.rs
below the line-limit target. - Split the pure load-balancer backend model, backend identity, and backend-set
helpers out of the runtime module as a focused private module. - Split load-balancer backend health/discovery state and backend runtime tests
into focused child modules, bringingbackend.rsbelow the line-limit target. - Split load-balancer HTTP discovery, DNS discovery, and discovery tests into
focused modules, bringingdiscovery.rsbelow the line-limit target. - Split load-balancer HTTP/gRPC health-check construction and response
validation into a focused health submodule, bringing the production
health.rsdispatcher below the line-limit target. - Split load-balancer health-check regression tests by transport/protocol
family, removing the temporary oversized health test exception. - Split the load-balancer crate-root regression suite into focused test modules,
reducingfluxheim-load-balancer/src/lib.rsto orchestration/facade code. - Split the load-balancer background-service wrapper into a focused service
module while preserving the publicUpstreamLoadBalancerServiceexport. - Split the load-balancer inner strategy dispatcher and backend member adapter
helpers into a focused private module, further reducing the crate root to the
public facade and orchestration glue. - Split load-balancer runtime-state snapshot/load/save glue into a focused
private module while preserving the public runtime-state methods. - Split load-balancer runtime backend mutation and persistence-clear methods
into a focused private module, leaving the crate root closer to construction,
selection, and stats orchestration. - Split load-balancer queue wait/timeout handling into a focused private module,
leaving the crate root below 800 lines. - Split load-balancer runtime stats assembly into a focused private stats
facade module. - Split load-balancer public construction and background-service factory methods
into a focused private construction module, bringing the crate root below the
line-limit target. - Split PHP-FPM FastCGI request parameter translation into a focused private
module while preserving the existing crate exports. - Split PHP-FPM script-name, path-translation, deny-prefix, and static-file
script mapping helpers into a focused private module. - Split PHP-FPM response parsing, static-offload target validation, cache-policy
checks, and response-header strip policy into a focused private module. - Split managed PHP-FPM config rendering, instance-name generation, sanitized
PATH fallback, and restart backoff helpers into a focused private module. - Split managed PHP-FPM spawn safety, private config-file creation, managed
directory validation, and socket readiness waits into a focused private
module. - Split managed PHP-FPM process lifecycle, child cleanup, restart watchdog, and
process start handling into a focused private module below the line-limit
target. - Split the remaining PHP-FPM crate regression suite into focused I/O/policy,
parameter/script, and response/config test modules, reducing the crate root to
a small facade below the line-limit target. - Split native route static-web PHP resolution tests into a focused module,
bringing the route static-web test module below the line-limit target. - Split PHP-FPM keepalive pool management and one-shot FastCGI execution into a
focused private module while preserving the public crate exports. - Split PHP-FPM endpoint selection, timeout classification, retry policy, and
retry deadline helpers into a focused private module. - Split PHP-FPM request-body replay, zeroized memory body ownership, spool-file
allocation, cleanup, and spool-directory validation into a focused private
module. - Split PHP-FPM streamed FastCGI response collection and bounded chunk
accounting into a focused private module. - Split native runtime launch-plan TSV report rendering into a focused module,
bringing the launch-plan assembly file below the line-limit target. - Split native HTTP/2 response validation and bounded response-data writes into
a focused private module, bringing the downstream H2 stack below the
line-limit target. - Split native HTTP/2 response, trailer, flow-control hold, and HTTP/1 adapter
regression tests into a focused response test module. - Split native upstream TLS proxy regression tests into base TLS, Rustls H2
ALPN, and mTLS modules, removing the oversized TLS test exception. - Split native upstream HTTP/1 client regression tests into base response,
h2c-upgrade, forwarded-header/timeout, and PROXY protocol modules, removing
the oversized client-test exception. - Split native HTTP/1 runtime proxy tests into plain/PROXY, Rustls TLS, and
OpenSSL TLS modules, removing the oversized runtime-proxy test exception. - Split native downstream HTTP/1 tests into base listener/framing, request-view,
body/limit/timeout, and TLS-listener modules, removing the oversized
downstream HTTP/1 test exception. - Split server-plan tests into base policy, native-runtime cutover, manifest,
and listener-inventory modules, removing the oversized server test exception. - Split native static-web path resolution, directory listing, response planning,
and rooted body-opening helpers into focused child modules, removing the
oversized static-web exception. - Split native HTTP/1 proxy runtime TLS listener planning and runtime error
formatting into focused child modules, removing the oversized runtime proxy
exception. - Split route redirect config and redirect-template validation into a focused
config module, bringingconfig_route.rsto the line-limit target. - Split TLS policy enums/defaults, client-auth config, and static certificate
path validation into focused TLS config modules, removing the oversized TLS
config exception. - Keep the root
fluxheimcrate focused on binary, CLI, admin, and runtime
orchestration glue. - Continue enforcing modularity, release metadata, Pingora dependency,
native-runtime, RPM, container, and smoke gates as blocking release evidence.
Compatibility Notes
- This release should not change runtime configuration semantics.
- Crate moves should preserve public behavior and move tests with the owned
logic where practical.
Verification
scripts/validate-release-metadata.shscripts/validate-modularity-policy.sh checkscripts/validate-pingora-dependency-policy.sh checkscripts/validate-pingora-boundary-policy.sh checkscripts/validate-native-runtime-cutover.shscripts/stable_release_gate.sh check
Checksums And Signatures
- Commit:
c9fe6939d95b22464ffed4ebb08a925fd0115675 - Local gate: GitHub CI green before tag; local release metadata checks passed
- CodeQL/code scanning: no open release-blocking alerts before tag
- Source archive checksums:
e20a2d10e097fa8fd67f033642bf3607b26301958e1b2bb862161dee822e92be fluxheim-1.6.37.tar.gzf5420d9d2672f0ba52736714011955c4675252e7f43d3e65bfdc4ed1fb446601 fluxheim-1.6.37.zip
- Binary checksums:
- x86_64:
d900216417fa22a78a1a1fc4d78bec76454043bcb22e4954543c2adf44481998 fluxheim-1.6.37-full-x86_64-linux.tar.gzf261304c25c69eb7f7495c2f9477f7927b36f7bceb43481460ac7156c2227c95 fluxheim-1.6.37-cache-x86_64-linux.tar.gz11a7925ca7e09aa17af1a014d9d3d67e3480dbbf7526302c93953f3550aa3577 fluxheim-1.6.37-proxy-x86_64-linux.tar.gze1c42c9bcfd66e3a8b002a8ee5a1fd52fcb6a577c895b3b17e63d1096be5e1d1 fluxheim-1.6.37-php-x86_64-linux.tar.gz85158f67414bea1cafcf116e7bf9e00e9633cb1686704e2b86f110beef436795 fluxheim-1.6.37-load-balancer-x86_64-linux.tar.gz914c364cb1273bf716c1b79dc1a9f71b7e704d59510fe4b6b7644b515b588946 fluxheim-1.6.37-config-tester-x86_64-linux.tar.gz
- aarch64:
49714b192c1a0a29542ceb0705d5ebc87452de7ea3251a993cad38e811fb03af fluxheim-1.6.37-full-aarch64-linux.tar.gzeac582a5a7db130d0baf3fa31a6c8e4720d4e9040c533a669868db643a4e0843 fluxheim-1.6.37-cache-aarch64-linux.tar.gzf2b33633331490f55a1ec8a4af2a6faa28465efd2a2a530c386ece1a65ca00cb fluxheim-1.6.37-proxy-aarch64-linux.tar.gz4aa5eed99e8f1e49ed702a4454730600f856aec7c7c83b94c3cacafa86b04292 fluxheim-1.6.37-php-aarch64-linux.tar.gzcc842f73f0b8a78cff915b00f163a3eaf5d68a864f8fdd63e62e8abc8f869899 fluxheim-1.6.37-load-balancer-aarch64-linux.tar.gz2c189b413591de29c3eba073a43d666f0ad122ed3093f720edaeaa601958aee5 fluxheim-1.6.37-config-tester-aarch64-linux.tar.gz
- macos:
62448e98586a7c6de08e80d6d12b7d373713f8d7ce9215064e6396371a840bbb fluxheim-1.6.37-dev-aarch64-macos.tar.gz
- x86_64:
- SBOM checksums:
27a892ffe1c11f47c881c85da4f37dccafa28a6f31b3d293842a1c60856b92ce fluxheim.spdx.json3f90badecf62de1beafe73333baa3d70238f1356f6db221c672ed08a90a5f29e fluxheim.cyclonedx.json
- Reproducible build:
6f4e3a58215126a27bb1949cee03636f12243fb6c44577dcf1b9cfdb197d90bex86_6416204b232521a71674e6a0e570256ffe9bb874ac12958b32bc7ddf3812e67b6daarch645bf4151235b0e128a54d935eeaf74fb62d9b6e4c1fa89c02ef529576dc7898bamacos
- Full Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim@sha256:1ae47062e52053077db973af085b742f3e5aa9771c4c1a591a434827f0f66b7f - Alpine:
ghcr.io/valkyoth/fluxheim@sha256:37547d23647370245ec103ba37448da97d13284211557e9f71df00c38c8d4438 - SUSE Micro:
ghcr.io/valkyoth/fluxheim@sha256:03e1cca6c4ec513a6f336fb73e7dce1da9af118656b11ce279f0818a1070e3a2 - Debian:
ghcr.io/valkyoth/fluxheim@sha256:157f9c3a9dafb62f96920a461196069e1e32eb210d7bae45ffd747ac0d136dee
- Wolfi:
- Cache Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim@sha256:5d2693d70bc1ad515a8e870a388de5cc9aed53162c3ab2afdc9c5104ca65beba - Alpine:
ghcr.io/valkyoth/fluxheim@sha256:3ba8e02c42a8e98612c2a9533dbe4a55318c2eb5254ec527c93b98a186ce1d7a - SUSE Micro:
ghcr.io/valkyoth/fluxheim@sha256:7356904f548db736675277960d8d5fa22223354453bad135391cff1f7ec8feec - Debian:
ghcr.io/valkyoth/fluxheim@sha256:cde81c08b1a598d9cf9097f479915b966badc44687c2048cc0d14ae516288e05
- Wolfi:
- Proxy Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim@sha256:9596af2f5539d80a6abc88596713e06a2a50e9899c5cf39726e4b8815483b7cc - Alpine:
ghcr.io/valkyoth/fluxheim@sha256:da6ed1542bfc0d8002952b56118ce6c9eccbb1890ce3c8d97ac50dd036c7017b - SUSE Micro:
ghcr.io/valkyoth/fluxheim@sha256:469c72e0c98720e78931838520480e1b450bc03488daa3545eda132cc14f68dc - Debian:
ghcr.io/valkyoth/fluxheim@sha256:546662344528018e2cb6bd32064f844cad791aa592ff606d5986e12f6ab559ca
- Wolfi:
- PHP Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim@sha256:51de60381ec1fe72711129bc29b4749f2c42328e797d76f1b7cf19e8eb64214c - Alpine:
ghcr.io/valkyoth/fluxheim@sha256:21e08aa20cf62b38343f793341aa08cef91127668645145259d4672a6d859bad - SUSE Micro:
ghcr.io/valkyoth/fluxheim@sha256:0690636a2211d645797e17f8a58f680defba97a714a2dd4b74ede174f5cb9530 - Debian:
ghcr.io/valkyoth/fluxheim@sha256:ae78e9b25d8b7d365fa7c3d377711db5c04237ca11941f4ed277d49ccdea9060
- Wolfi:
- Load Balancer Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim@sha256:d1c826e565e5137c36873cc4e5d958ee46972739d945138764df7599f5913c61 - Alpine:
ghcr.io/valkyoth/fluxheim@sha256:7a10f51ba262a9ef4553883ef7a4b492c82cab65df3193265aa57a2a5b1c5aec - SUSE Micro:
ghcr.io/valkyoth/fluxheim@sha256:a655bdfae7d937b42b5c62048a2612d135074d0b85ffbd420cf78422d5660b9c - Debian:
ghcr.io/valkyoth/fluxheim@sha256:0a4385ada4ae4c108c0fe698d9ee30b900f4fd73fc1bee996022451fe4492654
- Wolfi:
- Tag signature:
Good "git" signature for 1921261+eldryoth@users.noreply.github.com with ED25519 key SHA256:EoLRQ5k4J5pYz3UMFmkrV798gYFNkToGS2xEPvebqB4