AIXCL v1.1.65
AIXCL v1.1.65
Release v1.1.65 -- Security and reliability release: a full capability audit of every hardened entrypoint (pgadmin, grafana, ollama, open-webui), a plaintext-password permission fix and a minimal-capability set for pgadmin that also repairs its previously-broken postfix integration, a CI fix for Dependabot PRs, and a fork-PR token bug that had silently disabled automated issue closing since introduction.
What's New in v1.1.65
Fixed
- ✅ Capability-hardened entrypoints failed silently instead of loudly: pgadmin, grafana, ollama, and open-webui entrypoints silenced
2>/dev/null || trueon privileged filesystem operations, masking capability regressions until a clean init; required operations now fail fast naming the missing capability, optional operations emit a visible WARN instead of hiding the failure. Verified against a 3-scenario harness (empty volume, partial volume, capability-withheld) for all four services, then confirmed live against a real clean-init purge: 21/21 healthy, zero restarts, every WARN firing as designed (#1909). - ✅ Grafana ignored SIGTERM on first start: the first-start entrypoint backgrounded its process and stayed PID 1 with no signal trap, so every stop of a freshly-initialised container stalled the full SIGKILL grace period; a trap now forwards TERM/INT (measured 9.0s pre-fix vs 0.25s post-fix) (#1920).
- ✅ pgadmin ran with no capability restrictions at all: re-verified against the currently pinned image (the #1667 exception predates it) via a real harness -- the minimal set is
cap_add: [SETUID, SETGID, NET_BIND_SERVICE](sudo's internal privilege calls and a python3 file capability both need them to execute at all, independent of any actual privilege change). Also fixes postfix, which was already broken under the previous unrestricted configuration (#1921). - ✅ pgadmin-servers.json exposed a plaintext Postgres password world-readable on the host: the file was
chmod 644to work around rootless podman's UID mapping, not an oversight; now usespodman unshare chownto give the file the pgadmin container's actual mapped identity, so it stays600and the container can still read it (#1922). - ✅ Dependabot PRs failed the title-format CI check by design: dependency-bump PRs have no issue reference and use a
commit-message.prefixthat adds a colon, so they could never pass and had to be merged past a red check; the title-format job now exemptsdependabot[bot]specifically, leaving every other author's check unchanged (#1923). - ✅ close-linked-issues.yml silently failed to close any issue since introduction: GitHub Actions forces a read-only token on
pull_request-triggered workflows when the PR head is a fork, which every PR in this repo's two-remote workflow is; switched topull_request_target, which resolves against the base repository's token instead (#1928).
Documentation
Full Changelog: v1.1.64...v1.1.65