Releases: genmeta/pishoo
Release list
v0.8.0-beta.6
pishoo v0.8.0-beta.6
Changed
- Use
dhttpas the default pishoo worker group on non-macOS systems while retaining_wwwon macOS; DEB and RPM installation hooks create thedhttpgroup when needed. - Publish
pishoo-commonfrom the same0.8.0-beta.6source version as pishoo. Linux packages render it as0.8.0~beta.6-1, and pishoo accepts common-package versions from the last published0.5.1-1through the current version.
Fixed
- Restore the identity profile
db/access.dbas the default access-policy source for identity services without an explicitaccess_rulesdirective. - Fall back to an empty policy only when the implicit database is genuinely absent; keep explicit, unreadable, corrupt, and invalid databases as service-preparation failures.
Components
pishoov0.8.0-beta.6gatewayv0.8.0-beta.5 (unchanged)pishoo-commonv0.8.0-beta.6 (0.8.0~beta.6-1in DEB/RPM repositories)
Release surfaces
- Preview DEB, RPM, and Homebrew packages
- GitHub prerelease and packaged release assets
Authentication and provenance
- Tag:
v0.8.0-beta.6 - Annotated tag object:
99d4e47bcf9f149b70fa1bd6db01d156d4560a37 - Target commit:
bcd7613cf79d328a40d335cafdc8d23c3b1cebc5 - Workflow run: https://github.com/genmeta/pishoo/actions/runs/29630555927
- Workflow attempt:
1 - Published by: GitHub Actions
Releaseworkflow
v0.8.0-beta.5
pishoo v0.8.0-beta.5
Added
- Build inherited per-account DHTTP home trees into a static reload service pipeline.
Changed
- Use role-aware typed domains, sealed inherited trees, and typed compound STUN server values.
- Enforce exhaustive immutable reload snapshots and transport contracts before worker activation.
Fixed
- Preserve typed identity and registry contracts in cascaded and inherited configuration queries.
- Redirect slash-directory proxy requests before fallback routing.
- Compile IP-family parse failures cleanly with the release packaging nightly toolchain.
Dependencies
- Use
dhttpv0.6.0-beta.4,dynsv0.7.0-beta.2,h3xv0.6.0-beta.4,dquicv0.7.0-beta.4, anddshellv0.6.0-beta.3.
Components
gatewayv0.8.0-beta.5pishoov0.8.0-beta.5pishoo-commonv0.5.1-1 (unchanged)
Authentication and provenance
- Tag:
v0.8.0-beta.5 - Annotated tag object:
47e4b4d1141ff81774fd6ee84f49f8aaa1f7ff89 - Target commit:
4bafb7412b9c6e126e15598f053bfcb3f6015bb5 - Workflow run: https://github.com/genmeta/pishoo/actions/runs/29488246924
- Workflow attempt:
1 - Published by: GitHub Actions
Releaseworkflow
v0.8.0-beta.4
pishoo v0.8.0-beta.4
Changes
- pishoo keeps identity access-rule databases as live policy sources instead of loading only static in-memory snapshots.
- Gateway and pishoo access checks evaluate rules through the shared
dhttpaccess policy evaluator trait. - pishoo enables the
dhttpaccess ORM facade feature for access-rule database evaluation. - Release workflows upload package assets from publish reports instead of broad local artifact globs.
Release surfaces
- Product/package release:
pishoo v0.8.0-beta.4preview channel. - Rust workspace packages:
gateway v0.8.0-beta.4,pishoo v0.8.0-beta.4. - Package manager surfaces: DEB/RPM and Homebrew preview.
- Sidecar package:
pishoo-common v0.5.1-1remains unchanged.
Dependencies
dhttp v0.5.0-beta.3,dhttp-home v0.4.0-beta.1,dhttp-identity v0.3.0-beta.1,dyns v0.6.0-beta.3,h3x v0.6.0-beta.3,dshell v0.6.0-beta.2.- Release tooling:
genmeta-xtask-release v0.2.0-beta.8.
Verification
cargo +nightly fmt -- --checkcargo testwith temporary local patches for same-wave upstreamscargo clippy --all-targets --all-features -- -D warningswith temporary local patches for same-wave upstreams
Registry gate
- Final readiness requires same-wave upstream versions visible on crates.io and
Cargo.lockregenerated without path-resolved upstream sources.
Authentication and provenance
- Tag:
v0.8.0-beta.4 - Annotated tag object:
b17be9bfdc70d538f6e262f6400e62916a9db97f - Target commit:
4ac01d3607c23882bca9b4dff9f2330b27f74920 - Workflow run: https://github.com/genmeta/pishoo/actions/runs/29007667298
- Workflow attempt:
1 - Published by: GitHub Actions
Releaseworkflow
v0.8.0-beta.3
pishoo v0.8.0-beta.3
Changes
- Refresh release tooling so preview DEB/RPM metadata keeps the
pishoo-commonsidecar package required by previewpishoopackages. - Publish a beta.3 package metadata correction for the pishoo Linux package repositories.
Published packages
gatewayv0.8.0-beta.3pishoov0.8.0-beta.3pishoo-commonv0.5.1-1
Authentication and provenance
- Tag:
v0.8.0-beta.3 - Annotated tag object:
bb533177f920c03904c8d7bc1112b0b6b493f5ff - Target commit:
77a16111d6401fa8a01883ee0df1fab41abeeca5 - Workflow run: https://github.com/genmeta/pishoo/actions/runs/28789293911
- Workflow attempt:
1 - Published by: GitHub Actions
Releaseworkflow
v0.8.0-beta.2
pishoo v0.8.0-beta.2
Changes
- Load identity access rules from the identity profile access-rule database.
- Refresh Linux packaging Zig/cargo-zigbuild tooling for DEB/RPM builds.
- Update DHTTP stack dependency contracts for the beta.2 line.
Published packages
gatewayv0.8.0-beta.2pishoov0.8.0-beta.2pishoo-commonv0.5.1-1
Authentication and provenance
- Tag:
v0.8.0-beta.2 - Annotated tag object:
b00f89d88eeea978d3d4f2651f50b991acf1a2f0 - Target commit:
1e1f35f9956b1995fe5802b58ff27ef0f891851e - Workflow run: https://github.com/genmeta/pishoo/actions/runs/28785500819
- Workflow attempt:
1 - Published by: GitHub Actions
Releaseworkflow
v0.8.0-beta.1
pishoo v0.8.0-beta.1
Changes
- Prepare gateway and pishoo for the DHTTP beta dependency line.
- Update pishoo package publishing to stable/preview-aware release destinations for DEB, RPM, and Homebrew.
- Pin the shared release tooling through the reproducible
genmeta-xtask-releaserelease tag.
Fixes
- Use the existing macOS
_wwwgroup for default worker discovery instead of creating apishoogroup during Homebrew installation. - Check macOS worker group membership through platform membership APIs instead of bounded supplementary group lists.
- Initialize worker process group state through the platform
initgroupspath.
Components
gatewayv0.8.0-beta.1pishoov0.8.0-beta.1pishoo-commonv0.5.1-1
Release surfaces
- DEB preview packages
- RPM preview packages
- Homebrew preview formula
Authentication and provenance
- Tag:
v0.8.0-beta.1 - Annotated tag object:
89f88679f4955938176190cc41488feacffccc0b - Target commit:
a5189a00ff3128e1cc441e1034d76181cb614d75 - Workflow run: https://github.com/genmeta/pishoo/actions/runs/28675115336
- Workflow attempt:
1 - Published by: GitHub Actions
Releaseworkflow
v0.7.0
pishoo v0.7.0
This release updates pishoo and gateway for global dhttp home services, default group-based worker discovery, and the current DHTTP endpoint stack.
Added:
- pishoo can load global services from the global dhttp home.
- pishoo can discover default workers from the pishoo system group when explicit workers or groups are not configured.
- Gateway config parsing resolves pishoo paths relative to the configuration file.
- Release packaging now reads the pishoo package contract from xtask/release.toml, including target-local build environment overrides.
Changed:
- Root-owned registered listeners now apply DHTTP endpoint defaults when constructing pishoo endpoints.
- pishoo configuration now distinguishes standalone config-file mode from global dhttp-home mode.
- Product package generation now uses the manifest-first package contract for DEB, RPM, Homebrew, and S3/R2 package metadata.
- Homebrew package metadata uses the canonical dhttp download layout and emits versioned formula assets.
Fixed:
- Worker dhttp homes and identity services are loaded through the dhttp home API instead of hard-coded home-directory paths.
- Default pishoo group discovery is limited to global dhttp-home mode.
- pishoo package installation creates or explains the pishoo group best-effort, and startup warns instead of failing when the default group is absent.
- AArch64 GNU package builds filter the unsupported Zig/Rust linker mitigation flag.
Dependencies:
- Release dependencies now target h3x 0.5.0, dhttp 0.4.0, dshell 0.5.0, dyns 0.5.0, and rankey 0.2.1.
Component versions:
- gateway 0.7.0
- pishoo 0.7.0
- pishoo-common 0.5.1-1
Authentication and provenance
- Tag:
v0.7.0 - Annotated tag object:
e351dec7f17f78c08722c7edbf05ab728fb832c7 - Target commit:
8e17d953e4a72a5843e46c1c6717a32a5ddd4fac - Product release workflow run: https://github.com/genmeta/pishoo/actions/runs/28227117985
- Homebrew tap PR: genmeta/homebrew-stable#3
- Published by: GitHub Actions
Releaseworkflow
v0.6.0
-
Route gateway and pishoo DHTTP integration through the
dhttpendpoint facade, including endpoint-backed listeners, DHTTP DNS publication loops, and final crates.io release-wave dependencies. -
Move pishoo SSH service handling to WebTransport DShell sessions over h3x IPC, replacing the legacy stream-oriented session path.
-
Add the span-aware gateway configuration parser, nginx-style
proxy_passURI rewriting, typed listen-scope validation, and safer static-file path handling. -
Rework pishoo worker supervision around per-server runtimes, UID-keyed worker lifecycle, guarded listener/resource transitions, receiver-chosen FD transfer, and typed cleanup/failure paths.
-
Add manifest-first private release packaging for pishoo DEB, RPM, and Homebrew artifacts, including the
pishoo-commonrelease contract and S3/R2 publish idempotence. -
pishoo DEB packages
-
pishoo RPM packages
-
pishoo Homebrew packages
-
gateway0.6.0 -
pishoo0.6.0 -
pishoo-common0.5.0-1 -
h3x0.4.0 -
dhttp0.2.0 -
dyns0.4.0 -
dshell0.4.0
Authentication and provenance
- Tag:
v0.6.0 - Annotated tag object:
739b04af3b07b298ba91ab87281ef9909894b454 - Target commit:
d10e6ea610da549cbd5dec0b8c5ec79bee59f3fc - Workflow run: https://github.com/genmeta/pishoo/actions/runs/27669923414
- Workflow attempt:
1 - Published by: GitHub Actions
Releaseworkflow
gateway v0.5.0
[0.5.0] - 2026-04-20
Added
- dhttp-home identity model: pishoo now adopts
dhttp-homeas the
foundational identity abstraction. Each OS user owns a dhttp home
that contains any number of identity homes, each holding one
identity's TLS certificate/key, server configuration, and related
assets. The gateway resolves services per identity home rather than
consuming a single monolithic config. - Privilege-separated multi-process supervisor: motivated directly by
dhttp-home, pishoo splits into a privileged root process and per-user
worker processes. The root owns listeners, the PID file, and a
server_name -> owner workerregistry; each worker runs as its owning
OS user and serves the identity homes that live in that user's dhttp
home. This is what makes it correct to host many users' identities on
one gateway without running business logic as root. - Standalone STUN server mode: new
stun_server { bind / outer_addr / change_addr / change_port }directives for running RFC 5780 STUN
endpoints inside aserverblock. - Access control plane: new
access_rules sqlite://...directive
backed by a SQLite ACL database, plus an HTTP configuration API for
rule management. - Per-identity access logs: non-blocking writer producing structured
access logs scoped to each identity. - Response compression:
gzip,gzip_comp_level,gzip_min_length,
gzip_vary, andgzip_typesdirectives. - Header directives:
proxy_set_headerandadd_headerwith variable
interpolation ($host,$scheme,$http_*,$arg_*,$remote_addr). - Upstream TLS: configurable TLS to proxied upstreams.
- SIGHUP-driven selective reload: listeners are reused where possible
when only per-worker configuration changes. - xtask distribution tooling:
cargo xtaskreplaces the shell /
Makefile pipeline with parallel builds, shared cargo cache,
dpkg-buildpackage+ debhelper based.debgeneration, Homebrew
formula generation, and cross-compilation foramd64,arm64,
armhf,i686, and macOS Apple Silicon / Intel. - README rewritten to document the new supervisor architecture and boot
flow.
Changed
- Switched to the h3x / dquic 0.2 line; forward and reverse data paths
migrate to h3xTowerService,h3x::quic::Listen, and
Arc<Connection>propagation for reduced per-request allocation. - TLS certificate/key resolution is delegated to dhttp-home
Identity
instead of ad-hoc file loading. - Forward proxy client certificate fields now refer to per-identity
keychain paths. - DNS publishing now publishes empty records when no endpoints are
available, clearing stale entries instead of leaving them. - STUN configuration: the
STUN_SERVERenvironment variable is removed;
the built-in default server is nownat.genmeta.net:20004(was
stun.genmeta.net:20002) and can be overridden via config. - Missing files on reverse-proxied paths return HTTP 404 instead of 500.
- IPC between supervisor and workers uses a multiplexed channel
transport. - Upgrade
nix0.30 → 0.31.
Removed
- SSH3 password / basic authentication:
ssh_login basicis no
longer accepted; onlyssh_login ssl(client-certificate
authentication) is supported. STUN_SERVERenvironment variable (use config instead).- Legacy
Makefile/homebrew.sh/pishoo/pkgpackaging artifacts
(superseded byxtask).
Fixed
sshd: prevent lingeringpishoo-ssh-sessionprocesses after client
disconnect; register the conversation before returning 200 OK.- Pishoo: use SOCK_CLOEXEC fallback on macOS; close leaked seqpacket
sockets; tolerate worker spawn failures without crashing the root. - DNS: spawn interface teardown in the background to prevent the
reconcile loop from blocking on slow closes.
Dependencies
- Pin all git dependencies to specific revisions (
rev = "...") of the
respective repositories' default branches to avoid accidental drift. - h3x is the only git dependency over
https://; all others use
ssh://.
v0.4.0
pishoo & gateway 0.4.0
- 结合acces对客户端进行认证
- 支持ssl免密登录,将用户名加入path,同时保持对旧客户端的兼容性
- 整理日志和错误汇报
- 修复信号处理
- 结合gm-quic 0.3的QuicListener进行并行DNS汇报
Full Changelog: v0.2.5...v0.4.0