Repository navigation
fix(runtime): update libkrunfw to Linux 6.12.111 - #1740
Merged
Merged
Conversation
Pin the merged firmware security update from superradcompany/libkrunfw#30. The firmware source change updates the guest kernel from 6.12.109 to 6.12.111.
Advance libkrunfw to the merged follow-up that rebuilds stale macOS bundles and rejects stale Windows bundles before linking.
7 of 8 tasks
appcypher
added a commit
that referenced
this pull request
Oct 5, 2026
## TL;DR Prepare microsandbox 0.7.7 from 0.7.6, including the merged command-tree controls and the other fixes on main. ## Description - Align the Rust workspace, four shared TypeScript packages, Node platform packages, Go version constant, Ruby gem and extension, and TypeScript examples at 0.7.7; Python inherits the workspace version. - Regenerate Cargo.lock and the active npm workspace lockfiles without changing third-party dependency versions. - Advance MCP and skills to their signed 0.7.7 companion commits. Skills: superradcompany/skills#43. MCP: superradcompany/microsandbox-mcp#44. - The Node lockfile contains updated root and local workspace metadata; npm removes the five old native package entries because 0.7.7 is unpublished. CI already prunes these dependencies and supplies locally built native packages for smoke tests; release.yml refreshes registry tarballs and integrity hashes after publication. - Preserve the Ruby standalone registry lockfile, legacy nested shared-types lockfile, and example lockfiles according to the release workflow. Ruby's registry graph is refreshed after publication. ## Changelog since 0.7.6 - Add command-tree depth limits and commands-only/brief output, with `-L`, `-C`, and `-b` short forms (#1759). - Add storage usage reporting, cache cleanup, and CLI improvements (#1637). - Add outbound proxy configuration and optional guest clock synchronization (#1508, #1707). - Fix snapshot archive imports, restored resource reporting, and removal of sandboxes that never started (#1712, #1744, #1741, #1724). - Fix secret handling and SDK adapters, report rejected control operations more clearly, and reject symlinked bind-mount roots earlier (#1756, #1757, #1734). - Reduce paused sandbox host CPU, improve published-port routing and TCP response draining, apply exec limits before switching users, and correct SFTP ownership (#1755, #1754, #1726, #1746, #1713). - Update firmware to Linux 6.12.111, parallelize Ruby builds, fix the NAT64 API schema, and refresh dependencies and documentation (#1740, #1728, #1729, #1718, #1719, #1723, #1725, #1752). ## Test Plan - [x] Verify all 22 microsandbox Rust packages report 0.7.7, SDK/package references align, Cargo.lock changes only 25 workspace versions, and npm lockfile changes are limited to release metadata/native entries. - [x] `cargo fmt --all -- --check`, `git diff --check`, `python3 scripts/ci/test_bump_version.py`, and `cargo check --workspace --locked --offline`. - [x] `cargo clippy --workspace --locked --offline -- -D warnings` and `cargo run -p microsandbox-types --features ts --bin microsandbox-types-generate --locked --offline -- --check`. - [x] `cargo test --workspace --locked --offline -- --test-threads=1` (4,321 passed, 182 ignored). - [x] Shared packages: `npm run build`, `npm run typecheck`, and `npm test`; Node SDK: CI optional-dependency pruning/install, `npm run build:ts`, `npm run typecheck`, and `npm run test:unit` (335 passed, 1 skipped). - [x] Python: `maturin develop --locked --offline` and `python -m pytest -q` (279 passed, 3 skipped); Go: `go test -count=1 .`; MCP: `npm test` against the candidate SDK (21 passed). - [x] `cargo publish -p microsandbox-types-macros --dry-run --allow-dirty --no-verify` and Ruby gem/Cargo exact-pin alignment checks. - [ ] Live VM and cross-platform release smoke tests (CI/required fixtures); Ruby native build (local Ruby is 2.6, below the supported ABI range). Rust validation used an isolated MSB_HOME and existing local runtime artifacts through MSB_EMBED_ARTIFACTS_DIR. The initial parallel SDK test run hit runtime-probe timeouts, so the complete workspace suite was rerun serially. Native registry publication and post-publication lockfile refreshes remain part of the release workflow. <!-- greptile_comment --> <!-- greptile_summary --> <h2><a href="https://app.greptile.com/api/retrigger?id=74016313"><picture><source media="(prefers-color-scheme: dark)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source media="(prefers-color-scheme: light)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img alt="Retrigger" src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2" align="right"></picture></a>Confidence Score: 5/5</h2> <!-- greptile-risk --> The version bump appears safe to merge based on the checked release paths. What we checked: - Node checks without native packages: The checks remove the optional native packages from both Node files before running `npm ci`. The release regenerates the full lockfile after publication. <!-- greptile_confidence_score:5 --> <sub>Reviews (1) 路 Last reviewed commit: ["chore(release): bump microsandbox to 0.7..."](https://github.com/superradcompany/microsandbox/commit/0ec75f743c1f8d1c2d9daa26f1d87703e76f1c78)</sub> <!-- /greptile_comment -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
bump libkrunfw for Linux 6.12.111 and stale kernel bundle protection (superradcompany/libkrunfw#30, superradcompany/libkrunfw#31). add the matching CI checksum.
tested: six kernel builds, bundle regression checks, and macOS runtime smoke checks. cold boot to use the new kernel; full snapshots retain their original kernel.
No blocking issue was established, so the PR appears safe to merge.
Reviews (2) 路 Last reviewed commit: "fix(runtime): include stale kernel bundl..."