Skip to content

Upgrade components and bump ESF to 0.6.1 - #35

Merged
mitkox merged 2 commits into
masterfrom
esf/component-upgrades-20261006
Oct 6, 2026
Merged

mitkox merged 2 commits into
masterfrom
esf/component-upgrades-20261006

Conversation

@mitkox

@mitkox mitkox commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

ESF now pins Unreal 0.3.1, OpenCode V2 2.0.24 and the opt-in Pi Durable runner 1.0.4, with updated Cube Go SDK, Temporal UI 2.55.0, Python 3.14.8, Go/npm/Python dependency graphs and GitHub Actions. ESF version metadata is synchronized to 0.6.1 across builds, inventories, Python, Helm and image defaults. Embedded frontend and Pi assets were rebuilt, and Unreal's renamed release archive is verified by the installer.

CubeAPI 0.7.2 ignores the SDK's camelCase create-time internet-denial field. The adapter now adds the deployed API's snake_case denial field only for that release; wire-level regressions cover the compatibility boundary. The network probe now asserts direct public HTTPS denial independently of sandbox DNS/proxy failure.

Validation ran inside local Cube microVMs: full Go vet/race/build, 17 Pi regressions, 40 frontend tests/build, intake/brief-lab/eval and release-boundary tests, inventories/SBOM, installer digest rejection, three clean npm audits and a clean secret scan. Conformance, OpenCode, Unreal and Pi factory acceptance produced independently verified patches and confirmed cleanup. Final 0.6.1 metadata, focused race regressions and binary version checks passed. govulncheck found no vulnerable calls; the uncalled stable gRPC advisory is recorded in the upgrade report.

The local Cubelet route-aware configuration was backed up and activated. All three callback/isolation/internet-denial scenarios passed with a temporary, narrowly scoped firewall rule. Automatic approval review rejected persistence pending exact user firewall authorization; this remains a local infrastructure follow-up. The source PR does not change host firewall rules automatically.

See release/qualification/component-upgrade-2026-10-06.md for exact versions, artifacts, run IDs and qualification limits. OpenCode remains the default, Pi remains opt-in, mise's release-age protection remains enabled, and existing production qualification gates remain pending. The dirty primary checkout and unrelated local edits were preserved. This source update does not publish release archives or attest production readiness.

Final activated 0.6.1 acceptance after routing:

Harness Run Result
OpenCode run-eb463756890b8fb49951f945 verified patch, cleanup passed
Unreal run-2327e4a977fd9b85b5c224fe verified patch, cleanup passed
Pi run-5524114d8e642753fcdd0dfd verified patch, cleanup passed

Pi first failed safely when the gateway stream ended without finish_reason (run-b0ad997396bb450638007b4b); cleanup passed and a fresh run succeeded. Both receipts are retained. The callback firewall validation rule was removed after testing; persistent callback readiness still requires the pending exact firewall authorization. Cubelet route-aware routing remains enabled.

@mitkox
mitkox marked this pull request as ready for review October 6, 2026 20:08
@mitkox
mitkox merged commit 72d5fed into master Oct 6, 2026
3 checks passed
@mitkox
mitkox deleted the esf/component-upgrades-20261006 branch October 6, 2026 20:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant