Skip to content

Commit c7dc6cb

Browse files
committed
Fix fresh Linux LXC state path
1 parent 3b8bad4 commit c7dc6cb

10 files changed

Lines changed: 27 additions & 12 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,17 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
77

88
## [Unreleased]
99

10+
## [0.0.28] - 2026-07-29
11+
12+
### Fixed
13+
14+
- Fresh Linux installs now create and use the same `/var/lib/1helm-lxc/machines`
15+
runtime tree, so a newly created channel can provision, start, and enter its
16+
private LXC computer instead of failing with a missing lifecycle path.
17+
18+
- Includes the durable installer payload and API-quota corrections from the
19+
superseded Linux-only `0.0.27` prerelease.
20+
1021
## [0.0.27] - 2026-07-29
1122

1223
### Fixed
@@ -786,7 +797,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
786797
notarization, stapled tickets, Gatekeeper verification, persistent
787798
Application Support, and isolated Apple container machines.
788799

789-
[Unreleased]: https://github.com/gitcommit90/1Helm/compare/v0.0.27...HEAD
800+
[Unreleased]: https://github.com/gitcommit90/1Helm/compare/v0.0.28...HEAD
801+
[0.0.28]: https://github.com/gitcommit90/1Helm/compare/v0.0.27...v0.0.28
790802
[0.0.27]: https://github.com/gitcommit90/1Helm/compare/v0.0.26...v0.0.27
791803
[0.0.26]: https://github.com/gitcommit90/1Helm/compare/v0.0.23...v0.0.26
792804
[0.0.25]: https://github.com/gitcommit90/1Helm/compare/v0.0.23...v0.0.25

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -307,7 +307,7 @@ A fresh data directory opens first-run setup. The source runtime defaults to
307307
| `PORT` | `8123` | HTTP/WebSocket control-plane port. |
308308
| `CTRL_DATA_DIR` | `./data` | Databases, routing state, uploads, and narrow workspace mirrors. |
309309
| `HELM_CHANNEL_COMPUTER_BACKEND` | `apple` on macOS, `lxc` on Linux, `wsl` on Windows | Host isolation backend; `native` and `mock` are explicit development/test overrides. |
310-
| `HELM_CHANNEL_MACHINE_IMAGE` | `local/1helm-channel-machine:0.0.27` | Versioned channel-machine image contract. |
310+
| `HELM_CHANNEL_MACHINE_IMAGE` | `local/1helm-channel-machine:0.0.28` | Versioned channel-machine image contract. |
311311

312312
### Agent-first JSON CLI
313313

‎package-lock.json‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"name": "1helm",
33
"productName": "1Helm",
4-
"version": "0.0.27",
4+
"version": "0.0.28",
55
"private": true,
66
"type": "module",
77
"license": "AGPL-3.0-only",

‎site/public/install-lxc-runtime.sh‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ APP_SOURCE="${1:-}"
1010
INSTALL_ROOT="/opt/1helm"
1111
RUNTIME_ROOT="$INSTALL_ROOT/runtime/lxc"
1212
LXC_ROOT="/var/lib/1helm-lxc"
13-
LXC_PATH="$LXC_ROOT/containers"
13+
LXC_PATH="$LXC_ROOT/machines"
1414
CACHE_BASE="/var/cache/1helm-lxc"
1515
NETWORK_STATE="$LXC_ROOT/network"
1616
HELPER_PATH="/usr/libexec/1helm-lxc-runtime"
@@ -20,7 +20,7 @@ IDMAP_PATH="/etc/1helm/lxc-idmap"
2020
SUDOERS_PATH="/etc/sudoers.d/1helm-lxc-runtime"
2121
SERVICE_USER="1helm"
2222
IMAGE_BUILD="20260726_07:42"
23-
IMAGE_RELEASE="0.0.27"
23+
IMAGE_RELEASE="0.0.28"
2424

2525
# v0.0.11's updater unit made the exact destination files writable under
2626
# ProtectSystem=strict. Atomic replacement still requires write access to each

‎site/public/install.sh‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ NODE_LINK="$INSTALL_ROOT/node-current"
1010
STATE_ROOT="/var/lib/1helm"
1111
SERVICE_USER="1helm"
1212
NODE_VERSION="22.23.1"
13-
RELEASE_VERSION="0.0.27"
13+
RELEASE_VERSION="0.0.28"
1414
HOST_CONTRACT_PATHS=(
1515
/usr/libexec/1helm-lxc-runtime
1616
/usr/libexec/1helm-lxc-net

‎src/server/channel-computers.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ const APPLE_RUNTIME_VERSION = "1.1.0";
6767
export const APPLE_RUNTIME_PACKAGE = `container-${APPLE_RUNTIME_VERSION}-installer-signed.pkg`;
6868
export const APPLE_RUNTIME_URL = `https://github.com/apple/container/releases/download/${APPLE_RUNTIME_VERSION}/${APPLE_RUNTIME_PACKAGE}`;
6969
export const APPLE_RUNTIME_SHA256 = "0ca1c42a2269c2557efb1d82b1b38ac553e6a3a3da1b1179c439bcee1e7d6714";
70-
export const DEFAULT_CHANNEL_IMAGE = process.env.HELM_CHANNEL_MACHINE_IMAGE || "local/1helm-channel-machine:0.0.27";
70+
export const DEFAULT_CHANNEL_IMAGE = process.env.HELM_CHANNEL_MACHINE_IMAGE || "local/1helm-channel-machine:0.0.28";
7171
const CONTAINER_CANDIDATES = [process.env.HELM_CONTAINER_CLI, "/usr/local/bin/container", "/opt/homebrew/bin/container", "container"].filter(Boolean) as string[];
7272
const LXC_RUNTIME_VERSION = "1helm-lxc-runtime-v1";
7373
const LXC_HELPER_CANDIDATES = [

‎src/server/db.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1009,7 +1009,7 @@ export function migrate(): void {
10091009
const platformBackend = process.platform === "darwin" ? "apple" : process.platform === "win32" ? "wsl" : "lxc";
10101010
const configuredBackend = String(process.env.HELM_CHANNEL_COMPUTER_BACKEND || platformBackend);
10111011
const backend = ["apple", "lxc", "wsl", "native", "mock"].includes(configuredBackend) ? configuredBackend : platformBackend;
1012-
const image = String(process.env.HELM_CHANNEL_MACHINE_IMAGE || "local/1helm-channel-machine:0.0.27");
1012+
const image = String(process.env.HELM_CHANNEL_MACHINE_IMAGE || "local/1helm-channel-machine:0.0.28");
10131013
// Earlier Linux/Windows releases persisted the compatibility `native`
10141014
// seam into every channel row. A production host update must actually
10151015
// move those rows onto the platform isolation backend; changing the unit's

‎test/channel-computers.mjs‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -168,7 +168,7 @@ test("Apple channel-computer contract preserves isolation, files, wakes, archive
168168
test("runtime digest and packaged image recipe stay pinned", async () => {
169169
assert.equal(computers.APPLE_RUNTIME_SHA256, "0ca1c42a2269c2557efb1d82b1b38ac553e6a3a3da1b1179c439bcee1e7d6714");
170170
assert.match(computers.APPLE_RUNTIME_URL, /\/1\.1\.0\/container-1\.1\.0-installer-signed\.pkg$/);
171-
assert.equal(computers.DEFAULT_CHANNEL_IMAGE, "local/1helm-channel-machine:0.0.27");
171+
assert.equal(computers.DEFAULT_CHANNEL_IMAGE, "local/1helm-channel-machine:0.0.28");
172172
const packaging = await readFile(join(root, "scripts", "package-mac-dmg.cjs"), "utf8");
173173
assert.match(packaging, /container\(\?:\$\|\\\/\)/, "release packaging includes container/ image assets");
174174
const image = await readFile(join(root, "container", "Containerfile"), "utf8");

‎test/site.mjs‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -140,7 +140,7 @@ test("installer assets are explicit and syntax-valid", () => {
140140
assert.match(installer, /snapshot_host_contract[\s\S]*rollback_host_contract[\s\S]*TRANSACTION_ACTIVE/, "fresh and repeat installs restore runtime files and unit state after any transactional failure");
141141
assert.match(installer, /rollback_host_contract[\s\S]*1helm\.service\.active[\s\S]*api\/setup\/status[\s\S]*restored_healthy/, "installer rollback verifies the restored service before claiming recovery");
142142
assert.match(installer, /NODE_VERSION="22\.23\.1"/);
143-
assert.match(installer, /RELEASE_VERSION="0\.0\.27"/, "fresh installs use the deliberately published Linux release instead of a rate-limited API lookup");
143+
assert.match(installer, /RELEASE_VERSION="0\.0\.28"/, "fresh installs use the deliberately published Linux release instead of a rate-limited API lookup");
144144
assert.doesNotMatch(installer, /api\.github\.com/, "fresh installs do not depend on unauthenticated GitHub API quota");
145145
assert.match(installer, /need=\([^\n]*flock[^\n]*make[^\n]*c\+\+[^\n]*python3[^\n]*\)/, "the host updater and native dependency toolchain are probed even when download prerequisites already exist");
146146
assert.match(installer, /import ensurepip[\s\S]*python3-venv/, "the Linux host installs Python's venv support required by durable memory instead of accepting a python3 executable alone");
@@ -172,6 +172,9 @@ test("installer assets are explicit and syntax-valid", () => {
172172
const lxcNetwork = readFileSync(`${root}/scripts/1helm-lxc-net`, "utf8");
173173
const lxcConfig = readFileSync(`${root}/deploy/1helm-lxc-unprivileged.conf`, "utf8");
174174
const uninstaller = readFileSync(`${root}/site/public/uninstall-host.sh`, "utf8");
175+
assert.match(lxcInstaller, /LXC_PATH="\$LXC_ROOT\/machines"/, "installation and the runtime use the same LXC state directory");
176+
assert.match(lxcHelper, /LXC_PATH="\$LXC_ROOT\/machines"/, "the runtime reads the installer-created LXC state directory");
177+
assert.doesNotMatch(lxcInstaller, /LXC_ROOT\/containers/, "the obsolete mismatched LXC state directory is not installed");
175178
assert.match(lxcInstaller, /20260726_07:42/);
176179
assert.match(lxcInstaller, /9c23724d6d22b3a5adf5d0f79d7e3779ded16a6d45f928bce93e14c48113d955/);
177180
assert.match(lxcInstaller, /d5351325dc23e344c4974d7ff546e5e0c91b8e47a9caeb26f39cdc60eaad19e8/);

0 commit comments

Comments
 (0)