From 59a062aaae5d7a4e6f4c7496b481e9ae3ab202a4 Mon Sep 17 00:00:00 2001 From: Amit Ghadge Date: Sun, 9 Aug 2026 14:23:50 -0700 Subject: [PATCH] Release 0.0.1beta.13 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Dates the Unreleased section and bumps version.Version, which both the Makefile and GoReleaser inject but which is what a plain `go build`/`go install` reports. Two entries were missing and are written now rather than left out of the record: the containerd shim-name matching (`--runtime runc` refused on hosts that run runc) shipped with no entry at all, and the writability warning's printed remedy — which could widen a chgrp to a whole project and then skip the chmod via `&&` — was a user-facing correction to advice people act on. The headline of this release is that a flag could widen what `--profile prod` guarantees: `--publish`, `--user`, `--memory 0`, `--cpus 0` and `--no-hardening` were applied after the profile was checked, so prod's own promise about publishing was not enforced. That is present in 0.0.1beta.12. --- CHANGELOG.md | 28 +++++++++++++++++++++++++++- internal/version/version.go | 2 +- 2 files changed, 28 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4877ccb9..fe495444 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,7 +9,7 @@ changed default, a behavior that used to work differently. Entries land under `Unreleased` and are moved under a version heading when that version is tagged. -## Unreleased +## 0.0.1beta.13 — 2026-08-09 ### Fixed @@ -77,6 +77,32 @@ version is tagged. root)" on a rootless daemon, say — is printed rather than swallowed, so the cause is named rather than guessed at. +- **`--runtime runc` was refused on hosts that run runc.** A containerd-backed + daemon answers the same question in two vocabularies — `docker info` reports + `DefaultRuntime: runc` while keying its runtime map `io.containerd.runc.v2` — + and sandbox-cli compared those as plain strings: + + ``` + runtime "runc" is not registered with the Docker daemon + available runtimes: io.containerd.runc.v2 + ``` + + Runtimes are now matched by runtime rather than by spelling, and whatever the + preflight accepts is the name handed to the engine. This also means a stronger + runtime registered under a shim name is recognised as one, rather than going + unnoticed. Seen on Rocky Linux 10.2; unaffected on daemons that use the plain + names. + +- **The fix printed by the workspace-writability warning could be wrong.** It + emitted one command per finding, so a repository whose working tree and whose + `.git/objects` were both unwritable got two recursive `chmod` lines where the + first already covered the second. Worse, a `chgrp` needed only for `.git` was + widened to the whole project and chained with `&&`, so a single file owned by + someone else stopped the `chmod` from running at all — one recommended command + that fixed nothing while looking complete. Nested paths now collapse to one + command, a `chgrp` stays scoped to the directory that needs it, and the two + stand as separate lines. + ## 0.0.1beta.12 — 2026-08-09 ### Added diff --git a/internal/version/version.go b/internal/version/version.go index 7f261207..d362ca24 100644 --- a/internal/version/version.go +++ b/internal/version/version.go @@ -3,7 +3,7 @@ package version // Version is the sandbox-cli release version. Overridable at build time via // -ldflags "-X github.com/Amitgb14/sandbox-cli/internal/version.Version=x.y.z". -var Version = "0.0.1beta.12" +var Version = "0.0.1beta.13" // BaseImageVersion is the human-readable generation of the base image. It is // only the prefix of the image tag: the full reference (image.Ref) appends a