| tag name | v0.3.2 (136a2ea1a61f85d6fa792e992e4fd222d3e7fccf) |
| tag date | 2025-12-09 08:12:52 +0900 |
| tagged by | Ophestra <cat@gensokyo.uk> |
| tagged object | commit ccc0d98bd7... |
hakurei 0.3.2
Security:
This release introduces support for PipeWire `SecurityContext`. It is highly
recommended to upgrade to this release as soon as possible.
Legacy flatpak-like PulseAudio behaviour is now disabled by default and produces
an error message. To make PulseAudio available in the container, use the `hst`
filesystem type `"daemon"` and point it to `pipewire-pulse` within the container.
An example of this can be found in the
[NixOS module](https://git.gensokyo.uk/security/hakurei/src/tag/v0.3.2/nixos.nix#L199-L207).
Fixes:
- Package `ldd` cancels `ldd` process on decoding error.
Enhancements:
- Package `ldd` checks for absolute pathname.
- Output of the `cmd/hakurei` sub-command `show` is reordered to improve
readability.
- Container init now supports spawning daemon processes.
- PipeWire `SecurityContext` is now supported and can be enabled via the
`hst.EPipeWire` enablement bit.
- Container daemons are exposed via the `hst` filesystem types.
Internal:
- Move multiple packages to internal. Wrappers are maintained until `v0.4.0`.
- Implement PipeWire protocol native at `internal/pipewire`.
- Package `ldd` now decodes from an `io.Reader` stream.
- Package `container` now comes with a testable example.
- Releases are now built using clang.
- Error handling for `libwayland-client` is significantly improved.
- Container ops are now able to access `wait4` loop state.
-----BEGIN SSH SIGNATURE-----
U1NIU0lHAAAAAQAAADMAAAALc3NoLWVkMjU1MTkAAAAg/+8EpV0uLIR+MAtm7kYw4ssYDi
TAEe6cY2wdrwBLU38AAAADZ2l0AAAAAAAAAAZzaGE1MTIAAABTAAAAC3NzaC1lZDI1NTE5
AAAAQHZxVqAlBXWqmJ19PbpjKph6D5m70IRSez3ThGXY5vJXH2C/bHvAfZILfSVs0Mlyue
Oj3ccWt4IjHwqAPeuKvAo=
-----END SSH SIGNATURE-----
