Skip to content

Release 0.0.1beta.13 - #104

Merged
Amitgb14 merged 1 commit into
mainfrom
release/0.0.1beta.13
Aug 9, 2026
Merged

Amitgb14 merged 1 commit into
mainfrom
release/0.0.1beta.13

Conversation

@Amitgb14

@Amitgb14 Amitgb14 commented Aug 9, 2026

Copy link
Copy Markdown
Owner

15 commits since 0.0.1beta.12, and one of them is why this should not wait.

--profile prod did not enforce its own promise about publishing. The
profile is asserted against the resolved configuration, but --publish,
--user, --memory, --cpus and --no-hardening arrive as run options and
are applied over that configuration afterwards. So on the released binary:

sandbox-cli run --profile prod --publish 0.0.0.0:8022:22 -- sleep inf

succeeds, publishes the container on every interface, and has the entrypoint
open a matching hole in the default-deny INPUT chain — which is exactly what
prod's own message says cannot happen. Fixed in #103, checked where every caller
converges so fleet and the Studio API get the same answer.

Also in: the gVisor iptables backend (#101), containerd shim-name matching
(#98), --network allowlist finally able to rescue a prod run (#103), the
writability warning's remedy corrected (#99), and the Linux permissions runbook
(#100).

What this PR does

Dates Unreleased as 0.0.1beta.13 — 2026-08-09 and bumps version.Version —
which the Makefile and GoReleaser both inject, so the constant is what a plain
go build/go install reports.

It also adds two entries that were missing. #98 shipped with none at all
despite being user-facing (--runtime runc refused on a host that runs runc),
and #99 changed advice people act on — a chgrp widened to a whole project and
chained with &&, so one file owned by someone else stopped the chmod from
running. Both are in the record now rather than left out of it.

Tagging 0.0.1beta.13 after this merges is what publishes.

Dates the Unreleased section and bumps version.Version, which both the Makefile
and GoReleaser inject but which is what a plain `go build`/`go install` reports.

Two entries were missing and are written now rather than left out of the record:
the containerd shim-name matching (`--runtime runc` refused on hosts that run
runc) shipped with no entry at all, and the writability warning's printed
remedy — which could widen a chgrp to a whole project and then skip the chmod
via `&&` — was a user-facing correction to advice people act on.

The headline of this release is that a flag could widen what `--profile prod`
guarantees: `--publish`, `--user`, `--memory 0`, `--cpus 0` and `--no-hardening`
were applied after the profile was checked, so prod's own promise about
publishing was not enforced. That is present in 0.0.1beta.12.
@vercel

vercel Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
sandbox-cli Ready Ready Preview Aug 9, 2026 9:24pm

@Amitgb14
Amitgb14 merged commit 2865bd7 into main Aug 9, 2026
10 checks passed

This branch was successfully deployed

1 active deployment
Preview — 59a062aa Deployed Aug 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant