Fluxheim 1.8.2 Release Notes
Fluxheim 1.8.2 completes unsigned Windows portable parity on native x86_64
MSVC while preserving the same seven public profiles used by Linux and Apple
Silicon macOS. Windows ARM64 is deferred until sustainable native build and
test infrastructure is available.
Windows Portable Release
- Build and execute unsigned
.zippreviews forfull,wasm,cache,
proxy,load-balancer,php, andconfig-testerwith the native MSVC
toolchain and deny Windows-target compiler warnings. - Run the complete workspace suite plus live static, proxy, downstream and
verified upstream TLS, memory and persistent storage-bin cache,
load-balancer, integrity-authenticated snapshot create/list/rollback and
doctor verification, admin, metrics, ACME storage, crash-restart recovery,
CTRL_BREAK shutdown, and packaged-Wasm tests. - Replace Unix-only filesystem, path, locking, shutdown, and
certificate-storage assumptions with reviewed Windows-native behavior while
retaining fail-closed owner, ACL, reparse-point, and exclusive-writer checks. - Keep the Windows
phpprofile on the shared FastCGI request path with
external TCP pools. Managed PHP-FPM supervision remains Unix-only and is
rejected during Windows configuration validation and runtime construction;
a native Windows TCP FastCGI responder regression proves the supported path. - Enforce confidential Windows ACLs for TLS, ACME, admin, metrics, snapshot,
cache-encryption, peer-fill, and discovery credentials; new private files and
directories receive protected DACLs before secret bytes are written. - Open Windows static response files through retained directory handles with
reparse traversal disabled, and reject untrusted writable cache, state,
logging, configuration, ACME, and PHP-spool ancestors. - Preserve Windows cache purge/refresh semantics with delete-sharing, bound
cache reads across concurrent growth, make snapshot/ACME/cache directory
flushes real, and use delete-on-close request-body spool files. - Pin and record the manual review evidence for the exact
windows-permissionsdependency checksum and isolate first-party unsafe
Windows path traversal in the narrowly scoped
fluxheim-windows-securitycrate. - Evaluate Windows trust policy against retained target and ancestor handles,
and create cache object and encryption-state temporary files relative to a
validated parent before writing bytes. - Make dedicated builder SSH provisioning global and account-scoped even when
the vendor configuration ends in aMatchblock, and reject non-SSH, mixed,
or duplicate tag signature formats before allowed-signers verification. - Bootstrap disposable Windows Server 2025 Desktop Experience builders from a
trusted Linux release host, install the required native toolchain, transition
to a dedicated non-administrator SSH account, and verify Administrator SSH
is no longer accepted. Fresh-host provisioning handles empty OpenSSH groups,
refreshes newly installed prerequisite paths without exposing mutable Rust
tools machine-wide, and validates the global policy around the stock
administratorMatchblock. - Run the verified-upstream-TLS smoke against a second native Fluxheim/Rustls
process so it remains reliable under public-key-only OpenSSH sessions without
granting access to the machine-wide Windows private-key store. - Flush the load-balancer state file and containing directory after atomic
replacement on Windows. - Roll back newly created Windows files after a retained-parent ACL rejection
through delete-capable handles, and surface any rollback failure explicitly. - Bind the Windows filesystem-security audit to the complete reviewed
first-party source boundary as well as the pinned ACL dependency checksum. - Make the focused Wolfi, Alpine, Debian, and SUSE BCI PHP images
self-contained managed
PHP-FPM runtimes with one smoke-verified application extension contract,
including MySQLi and its required MySQLnd module. The PHP image smoke rejects
extension load warnings and executes a real request through each image. - Replace
php-suse-microwithphp-suse-bci. The dedicated SUSE BCI PHP base
provides an official PHP repository and matching PHP-FPM stack, while the
pinned SL Micro base does not. Other SUSE Micro profiles remain supported,
and Windows PHP continues to use external TCP FastCGI as documented. - Replace the yanked transitive
wnaf 0.14.0dependency with0.14.1. - Add an opt-in off-host Windows ingress smoke that runs the packaged
php
profile against a checksum-pinned official PHP NTS FastCGI process and
verifies real PHP output, request-body forwarding, and CGI TLS context over
public HTTP and certificate-validated HTTPS. - Normalize canonical Win32 verbatim roots to ordinary DOS or UNC paths before
sendingSCRIPT_FILENAME,DOCUMENT_ROOT, orPATH_TRANSLATEDto an
external Windows FastCGI process. This fixes realphp-cgi.exerequests that
previously returnedNo input file specified. - Add a separate opt-in Windows ACME lifecycle smoke that performs an isolated
Let's Encrypt staging HTTP-01 issuance, activates the installed certificate,
and verifies its hostname and fingerprint from an off-host client. - Add an opt-in off-host packaged-profile matrix that verifies public HTTP and
certificate-validated HTTPS through the Windowsproxy,load-balancer,
cache, andfullZIPs. It proves two-origin selection and failover, memory
cache reuse, and persistent storage-bin recovery with the origin offline. - Refresh the pinned Rust toolchain and container builders to 1.98.1, update
compatible workspace dependencies, and movesanitization,base64-ng,
Brotli, Zstandard, MaxMindDB, AWS-LC, Rustls, Wasmtime, and the QEMU setup
action to their current reviewed releases. - Keep the dedicated Windows build account's mutable Rust toolchain out of the
machine-wide executable search path, clean obsolete machine environment
entries, and make the release runner fail closed when invoked with an
administrator token. - Move the Windows release compiler into an Administrator-provisioned,
recursively read-only tree with a verified file inventory. Official evidence
requires a builder provisioned within 24 hours, a fresh per-run Cargo home,
allowlisted build environment, and protected Cargo working directory. - Authenticate admin HTTP requests before they can trigger or observe an
expired self-healing rollback. - Return failed expired-validation rollbacks directly to authenticated admin
clients so confirmation and successful health reports cannot overwrite the
preserved retryable recovery state. - Create private Windows directories relative to a retained parent handle and
apply their protected ACL atomically, preventing junction replacement between
validation and creation. - Validate fresh builders against the standard Windows volume-root ACL without
weakening replacement, ownership, or ACL protections; remove unused Rustup
proxy links before sealing future toolchain inventories and correctly record
the native compiler host without colliding with PowerShell's reserved
$Hostvariable. - Stage privileged bootstrap scripts only in a newly created directory inside
the protected Administrator profile. Provisioning rejects any pre-existing
object instead of attempting to repair its ACL. Official evidence remains
limited to fresh, single-tenant disposable hosts. - Align Windows release production with Linux ARM and macOS: reproduce the
default release binary in two clean target directories, build each of the
seven profile archives once, and aggregate native test evidence and checksums
through the repository-owned Linux helper. - Build Windows MSVC executables with deterministic PE timestamps and CodeView
identifiers, proving byte-identical default binaries across clean target
directories on the native release host. - Derive Unix
O_NOFOLLOWfrom each target ABI instead of using an x86 Linux
literal, restoring symlink rejection on Linux ARM for configuration, ACME,
Wasm, GeoIP, observability CA, upstream TLS, and static-file inputs. - Run the complete Linux x86_64 and aarch64 archive matrices, the native
Windows runtime and seven-ZIP matrix, and the Apple Silicon seven-profile
archive validation before release preparation.
Exact-Tag Publication Gate
- Produce exact-tag architecture, checksum, test, and reproducibility evidence
from a dedicated native x86_64 Windows builder. Evidence records the
Windows edition and build, and every executable in all seven ZIP profiles
must launch and report the expected version. Planning-only output and the
normal x86_64 CI result are not substitutes for exact-tag release evidence. - Verify the default release binary is reproducible across two clean target
directories, collect the seven checked ZIP profiles, and destroy the
disposable builder.
The Unix/OpenSSL FIPS support shim remains excluded as an independent Windows
workspace package while staying covered by the dedicated Linux OpenSSL-FIPS
profiles.
These archives remain unsigned previews. Authenticode and installer work stays
deferred until company-backed publisher credentials are available.
Checksums And Signatures
- Commit:
6ed82b5a9ebd5b8f1bb4bc03f986edd9a33ae855 - Local gate: GitHub CI green before tag; local release metadata checks passed
- CodeQL/code scanning: no open release-blocking alerts before tag
- Source archive checksums:
bf88d1d6bd27c0a8b46975230d9483f43bbd0e1289466e72fd9b6e7ee6a9353c fluxheim-1.8.2.tar.gze354839d1a7e9a8a3ca6146baffecc47de06c6aef0e21ba15be2e574d04d11d5 fluxheim-1.8.2.zip
- Binary Checksums (SHA-256):
- Linux (x86_64):
1a323dcd5632e25acf2e4463e549f20cdd3d568f445f9d923b1be312ec7f9839 fluxheim-1.8.2-full-x86_64-linux.tar.gz6bfe473e9c12189d4309b662cad64c71d53d49a524cc94adb4980401026a6faf fluxheim-1.8.2-wasm-x86_64-linux.tar.gzae41cafaf1abec4de14e7bec771ece3ced6b3f9f0eebd3bc23c4e5637f953f37 fluxheim-1.8.2-cache-x86_64-linux.tar.gz6d93adbe9d11d9b8dede5acbfb4b5fcd0cb721b58ee6c67a0d748675d471e4b8 fluxheim-1.8.2-proxy-x86_64-linux.tar.gzf0b32023407aaaa745b9c3693731010cedec09c1ef824ba3fed09cf490a86b15 fluxheim-1.8.2-php-x86_64-linux.tar.gz1cd3f30267edb630818434562c566fc8ebb22f2758fb59750299a9f7ef560006 fluxheim-1.8.2-load-balancer-x86_64-linux.tar.gz1c322cc1c959867a6aaf67e6aba82990729bc8b84f2b32c2ce971bf7814de605 fluxheim-1.8.2-config-tester-x86_64-linux.tar.gz
- Linux (aarch64):
814d51ba95337c9014ce3dd641debee20acdccc677befa9877aeaf674b13fc44 fluxheim-1.8.2-full-aarch64-linux.tar.gz6c57cc3842f8947c8d357dd5a7cdfe411b75ee32565811a96832c7a21b50dc8a fluxheim-1.8.2-wasm-aarch64-linux.tar.gzcf316d7012e3db6ceac767695fe7e9bbcdfaf19f8b75a723b368af01f1574481 fluxheim-1.8.2-cache-aarch64-linux.tar.gz1d6e48714e556736f5830738aabb06a8f91bde381430f6994d7eceeba69314e8 fluxheim-1.8.2-proxy-aarch64-linux.tar.gz3400194285112c1a5125d01d80d4452379bf54a626dbe145cd16b2499b42adb1 fluxheim-1.8.2-php-aarch64-linux.tar.gz4335c96925205bdac844a5df02f2c2c19116e253d566f4b9272481e3004781e3 fluxheim-1.8.2-load-balancer-aarch64-linux.tar.gzc603de7f1fb94e418443d48ec9172f59792fbd75e30f7cb545e6ef3c3002aa5f fluxheim-1.8.2-config-tester-aarch64-linux.tar.gz
- macOS (Apple Silicon / aarch64):
a725ebcccac259af6640da57ce12e7a3944c5bd0d9e7869d4001196a0c394031 fluxheim-1.8.2-full-aarch64-macos.tar.gz0cbbe1c936882b6596d97b67599618397b8a541f963651cd4d94eff4ed09f691 fluxheim-1.8.2-wasm-aarch64-macos.tar.gzcb279afe1dd941e497a33797223a583976d28229b2b18ff25eb6837a269b88b0 fluxheim-1.8.2-cache-aarch64-macos.tar.gz88927c0aae2c1f58584b005c9b3bb176474c6645485cf3b09ba0b0253243c506 fluxheim-1.8.2-proxy-aarch64-macos.tar.gzb5bc276d808001cec28afe638808d6c10f704b680aae3f038460fb678c0ed771 fluxheim-1.8.2-php-aarch64-macos.tar.gz60605fcdee80fa3186eecb281ad69add70891bac3cf575eade87434e48b6b4cf fluxheim-1.8.2-load-balancer-aarch64-macos.tar.gz00546a590966b8817e3171de418e963165b645402c3a637276cc2e8f814d4e53 fluxheim-1.8.2-config-tester-aarch64-macos.tar.gz
- Windows (x86_64):
a72b84720083406f318bf3fc87555eb62fd76dbd1506dbf2cd368e7364726b44 fluxheim-1.8.2-full-x86_64-windows.zip1ef42f792f5016c93e71fd2768671475738b486cee8d69b0d2514226fda2de4e fluxheim-1.8.2-wasm-x86_64-windows.zipc804c5f5cb4c5aa5a9b3112e1028eeb53cb4bdc65ddddb251cf6f4e38f9d4ef4 fluxheim-1.8.2-cache-x86_64-windows.zipddc55d88f10e0c634eec24c6dd69964a58928033bbd3048ecd927101c6d3a6d2 fluxheim-1.8.2-proxy-x86_64-windows.zip671be0bf8c779ba8d39b57b361bfc23c6ad7af6c26b584aa4e92ef46dca87423 fluxheim-1.8.2-php-x86_64-windows.zip2e433deaf66f0746d23f81bf29972c9ac007e8d192a96bfc0b3da340dff2793d fluxheim-1.8.2-load-balancer-x86_64-windows.zipe687d44f1b2c8da0db6f66cb6da682ea05a8ac6f92fb48756c47c69efc3bf066 fluxheim-1.8.2-config-tester-x86_64-windows.zip
- Linux (x86_64):
- SBOM checksums:
5a28b86096642a7484c5b7d6c78bdcaa9e610403bca2be941dea3943eeaf6a6a fluxheim.spdx.json1b946b3b4990aaf8861937d1d91d50cd5ddbe551217d424b90d721c06d32d7ff fluxheim.cyclonedx.json
- Reproducible build:
cfebc71b181042efbe376232c85e8dd1a25a38d65183ddee1b1d6ae21f84d1edLinux x86_6479ce8547d597319dfd4f51a17650df072c76060af86295359aa909b21d35ac07Linux aarch64822ff4c5bbf23d0164a57296da6457dba3ca47f4eef638bd5b0069fcbda1ba00macOS (Apple Silicon / aarch64)e2bc8612c9570f24730e5b4a91307faf9d0cc0ab5f3edeff0c3038d25a1ddbeaWindows x86_64
- Full Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim:v1.8.2-wolfi@sha256:ce770d02f7eedf7c7f61e447c904e9bc1d0a07080eac9d3a538255f65440e11c - Alpine:
ghcr.io/valkyoth/fluxheim:v1.8.2-alpine@sha256:8625df6702ecadb957f25ae842c6f633913e7780374732ce6b72b57e76774185 - SUSE Micro:
ghcr.io/valkyoth/fluxheim:v1.8.2-suse-micro@sha256:17db66e5861f5a02dde625f7868cd707cef6bcd6d224640d16d46e8dcfd0e2c8 - Debian:
ghcr.io/valkyoth/fluxheim:v1.8.2-debian@sha256:25735646642138517095d3426eaa3e5581d8ea338b03b053796c83c06215a073
- Wolfi:
- Wasm Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim:v1.8.2-wasm-wolfi@sha256:6c5537c5d2703a98735d5fd90d5d907db40af56443ebe59bf14b522185265959 - Alpine:
ghcr.io/valkyoth/fluxheim:v1.8.2-wasm-alpine@sha256:0e1ea822359d0d9fb1d310d69517df748bb9ae47f4d098ed382a52877b780201 - SUSE Micro:
ghcr.io/valkyoth/fluxheim:v1.8.2-wasm-suse-micro@sha256:5d8945b3597ebc788e8b58c806b3094225d7fabc43c04710de8f5e50a6f836d9 - Debian:
ghcr.io/valkyoth/fluxheim:v1.8.2-wasm-debian@sha256:1dcf7fed64839c17d0e5c20bc2ea0b8d09e1998cf1a5feb5947e9ea63b55c1ab
- Wolfi:
- Cache Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim:v1.8.2-cache-wolfi@sha256:26ee7950e4d26c795087399fc129a55de1cb5ee71f35a37d35a0303db0f90ee6 - Alpine:
ghcr.io/valkyoth/fluxheim:v1.8.2-cache-alpine@sha256:99ec49ccc0ad0f6abd562811c7101f07d5f801519b1f69e3d6c13626e782b36f - SUSE Micro:
ghcr.io/valkyoth/fluxheim:v1.8.2-cache-suse-micro@sha256:541e0db1fb5369c91736bd26e07b4d84fb4c7e654ec05a0c507cfbbcdc4e830c - Debian:
ghcr.io/valkyoth/fluxheim:v1.8.2-cache-debian@sha256:9a4708a935c2576f5b75774e79abebe39344ee4c3497ec5894db550fdeff87ab
- Wolfi:
- Proxy Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim:v1.8.2-proxy-wolfi@sha256:3e032785fa31181411d8d9633099bb871f51899c6659fb83f3ca777b9a3cc4fd - Alpine:
ghcr.io/valkyoth/fluxheim:v1.8.2-proxy-alpine@sha256:39d454bd885273bc46bf5de5f4cc4654b39bdf154b41e458377089e4ef5157ce - SUSE Micro:
ghcr.io/valkyoth/fluxheim:v1.8.2-proxy-suse-micro@sha256:45db1dc898bd27e7452f675b851c65ca977665dce338fe61cd48cb9b4113de2a - Debian:
ghcr.io/valkyoth/fluxheim:v1.8.2-proxy-debian@sha256:6674a15a7f804999b2a6b8065901fea6338433fe191e7d8295c75dc0a9be51b6
- Wolfi:
- PHP Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim:v1.8.2-php-wolfi@sha256:39a4f620a3556955760082a11fe109ccbac6334011c95e974ad1c712944f377b - Alpine:
ghcr.io/valkyoth/fluxheim:v1.8.2-php-alpine@sha256:7337a6deb42ab0faff96d8ecd236ce7d107e05cf6f8e918d83fecdb44087662c - SUSE BCI:
ghcr.io/valkyoth/fluxheim:v1.8.2-php-suse-bci@sha256:c5200ff713f3cfd2cce60dd37674d006a8dee691df4b5d3cf8f2bd95646c5eeb - Debian:
ghcr.io/valkyoth/fluxheim:v1.8.2-php-debian@sha256:49f9fade1fd124c3350020ebd30c67a60f854f188a533c5ec57a6df05702c475
- Wolfi:
- Load Balancer Build Container digests:
- Wolfi:
ghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer-wolfi@sha256:ca10d554bf035c5ef9e798ed3378e7abab2e80ef2a3d406738ddbfadb43a288f - Alpine:
ghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer-alpine@sha256:8fbbdf01030a9d32be05ff74165b6066f96da416d776cc9b2206f4770d317fc2 - SUSE Micro:
ghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer-suse-micro@sha256:3c07e72da36de9d7a3acb5faf02ed7446d4a50f9ff725263abd56b92c325767a - Debian:
ghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer-debian@sha256:d00257ad70fbb364b78335063c168f1ef6043b95136e2cf99dbb117b737ed21a
- Wolfi:
- Tag signature:
Good "git" signature for 1921261+eldryoth@users.noreply.github.com with ED25519 key SHA256:EoLRQ5k4J5pYz3UMFmkrV798gYFNkToGS2xEPvebqB4