Skip to content

fix(runtime): update libkrunfw to Linux 6.12.111 - #1740

Merged
toksdotdev merged 3 commits into
mainfrom
toks/update-libkrunfw-6-12-111
Oct 2, 2026
Merged

toksdotdev merged 3 commits into
mainfrom
toks/update-libkrunfw-6-12-111

Conversation

@toksdotdev

@toksdotdev toksdotdev commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

bump libkrunfw for Linux 6.12.111 and stale kernel bundle protection (superradcompany/libkrunfw#30, superradcompany/libkrunfw#31). add the matching CI checksum.

tested: six kernel builds, bundle regression checks, and macOS runtime smoke checks. cold boot to use the new kernel; full snapshots retain their original kernel.

RetriggerConfidence Score: 5/5

No blocking issue was established, so the PR appears safe to merge.

Reviews (2) 路 Last reviewed commit: "fix(runtime): include stale kernel bundl..."

Pin the merged firmware security update from superradcompany/libkrunfw#30. The firmware source change updates the guest kernel from 6.12.109 to 6.12.111.
@toksdotdev
toksdotdev requested a review from appcypher as a code owner October 2, 2026 10:18
Advance libkrunfw to the merged follow-up that rebuilds stale macOS bundles and rejects stale Windows bundles before linking.
@toksdotdev
toksdotdev merged commit 38bc152 into main Oct 2, 2026
117 checks passed
@toksdotdev
toksdotdev deleted the toks/update-libkrunfw-6-12-111 branch October 2, 2026 11:54
@github-actions github-actions Bot added the release:fix Category for generated release notes label Oct 2, 2026
@appcypher appcypher mentioned this pull request Oct 3, 2026
7 of 8 tasks
appcypher added a commit that referenced this pull request Oct 5, 2026
## TL;DR
Prepare microsandbox 0.7.7 from 0.7.6, including the merged command-tree
controls and the other fixes on main.

## Description
- Align the Rust workspace, four shared TypeScript packages, Node
platform packages, Go version constant, Ruby gem and extension, and
TypeScript examples at 0.7.7; Python inherits the workspace version.
- Regenerate Cargo.lock and the active npm workspace lockfiles without
changing third-party dependency versions.
- Advance MCP and skills to their signed 0.7.7 companion commits.
Skills: superradcompany/skills#43. MCP:
superradcompany/microsandbox-mcp#44.
- The Node lockfile contains updated root and local workspace metadata;
npm removes the five old native package entries because 0.7.7 is
unpublished. CI already prunes these dependencies and supplies locally
built native packages for smoke tests; release.yml refreshes registry
tarballs and integrity hashes after publication.
- Preserve the Ruby standalone registry lockfile, legacy nested
shared-types lockfile, and example lockfiles according to the release
workflow. Ruby's registry graph is refreshed after publication.

## Changelog since 0.7.6
- Add command-tree depth limits and commands-only/brief output, with
`-L`, `-C`, and `-b` short forms (#1759).
- Add storage usage reporting, cache cleanup, and CLI improvements
(#1637).
- Add outbound proxy configuration and optional guest clock
synchronization (#1508, #1707).
- Fix snapshot archive imports, restored resource reporting, and removal
of sandboxes that never started (#1712, #1744, #1741, #1724).
- Fix secret handling and SDK adapters, report rejected control
operations more clearly, and reject symlinked bind-mount roots earlier
(#1756, #1757, #1734).
- Reduce paused sandbox host CPU, improve published-port routing and TCP
response draining, apply exec limits before switching users, and correct
SFTP ownership (#1755, #1754, #1726, #1746, #1713).
- Update firmware to Linux 6.12.111, parallelize Ruby builds, fix the
NAT64 API schema, and refresh dependencies and documentation (#1740,
#1728, #1729, #1718, #1719, #1723, #1725, #1752).

## Test Plan
- [x] Verify all 22 microsandbox Rust packages report 0.7.7, SDK/package
references align, Cargo.lock changes only 25 workspace versions, and npm
lockfile changes are limited to release metadata/native entries.
- [x] `cargo fmt --all -- --check`, `git diff --check`, `python3
scripts/ci/test_bump_version.py`, and `cargo check --workspace --locked
--offline`.
- [x] `cargo clippy --workspace --locked --offline -- -D warnings` and
`cargo run -p microsandbox-types --features ts --bin
microsandbox-types-generate --locked --offline -- --check`.
- [x] `cargo test --workspace --locked --offline -- --test-threads=1`
(4,321 passed, 182 ignored).
- [x] Shared packages: `npm run build`, `npm run typecheck`, and `npm
test`; Node SDK: CI optional-dependency pruning/install, `npm run
build:ts`, `npm run typecheck`, and `npm run test:unit` (335 passed, 1
skipped).
- [x] Python: `maturin develop --locked --offline` and `python -m pytest
-q` (279 passed, 3 skipped); Go: `go test -count=1 .`; MCP: `npm test`
against the candidate SDK (21 passed).
- [x] `cargo publish -p microsandbox-types-macros --dry-run
--allow-dirty --no-verify` and Ruby gem/Cargo exact-pin alignment
checks.
- [ ] Live VM and cross-platform release smoke tests (CI/required
fixtures); Ruby native build (local Ruby is 2.6, below the supported ABI
range).

Rust validation used an isolated MSB_HOME and existing local runtime
artifacts through MSB_EMBED_ARTIFACTS_DIR. The initial parallel SDK test
run hit runtime-probe timeouts, so the complete workspace suite was
rerun serially. Native registry publication and post-publication
lockfile refreshes remain part of the release workflow.


<!-- greptile_comment -->

<!-- greptile_summary -->

<h2><a
href="https://app.greptile.com/api/retrigger?id=74016313"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source
media="(prefers-color-scheme: light)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img
alt="Retrigger"
src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"
align="right"></picture></a>Confidence Score: 5/5</h2>

<!-- greptile-risk -->

The version bump appears safe to merge based on the checked release
paths.

What we checked:
- Node checks without native packages: The checks remove the optional
native packages from both Node files before running `npm ci`. The
release regenerates the full lockfile after publication.

<!-- greptile_confidence_score:5 -->

<sub>Reviews (1) 路 Last reviewed commit: ["chore(release): bump
microsandbox to
0.7..."](https://github.com/superradcompany/microsandbox/commit/0ec75f743c1f8d1c2d9daa26f1d87703e76f1c78)</sub>

<!-- /greptile_comment -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release:fix Category for generated release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant