Skip to content

chore(main): release 0.7.2 - #1551

Open
opennhp-release-please[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main
Open

chore(main): release 0.7.2#1551
opennhp-release-please[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main

Conversation

@opennhp-release-please

@opennhp-release-please opennhp-release-please Bot commented May 16, 2026

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

0.7.2 (2026-08-10)

⚠ BREAKING CHANGES

  • server,agent: a server with this change rejects any agent that does not populate AgentKnockMsg.HeaderType. The agent half is included here; build and deploy agents from this change together with the server.
  • agent: bind resources to clusters by name, drop ambiguous host fields
  • core,server: stateless overload cookies for cluster verification
  • relay: lift multi-instance restriction, pick by load balance scheme
  • core: move recv-address stickiness from peer to ConnectionData
  • relay: remove legacy POST /relay; tighten routing contract

Features

  • ac: fan-out AOL/KPL to all server endpoints in a cluster (77f1fa5)
  • ac: support multiple endpoints per nhp-server identity (066bdf1)
  • agent registration with OTP/REG/RAK, SQLite keystore, SES SMTP (7fc976e)
  • agent-register: complete NHP agent registration flow via relay (397812f)
  • agent: add interactive CLI registration command (OTP → REG two-step flow) (c5ec008)
  • agent: bind resources to clusters by name, drop ambiguous host fields (a947e1c)
  • agent: match register CLI cipher-scheme labels to the reg page (58fb601)
  • agent: multi-instance server clusters with sticky/non-sticky modes (187d1b3)
  • agent: show both derived public keys in register CLI regardless of scheme (cd168aa)
  • AWS demo deployment (infra, nginx+LE, js-agent, nhp-relay) (0582e89)
  • core,server: stateless overload cookies for cluster verification (d46bda1)
  • core: move recv-address stickiness from peer to ConnectionData (9e40d88)
  • demo: add demo.nhp TLS proxy to AC nginx (cc0647c)
  • demo: add demo.nhp TLS proxy to AC nginx (738a996)
  • demo: add second independent nhp-server+nhp-ac cluster (cluster 2) (8cc75f7)
  • deploy: support dual cipher schemes (Curve25519 + SM2) in demo (fd34319)
  • interactive agent registration CLI + dual-cipher (Curve25519 + SM2) demo support (6acdb5d)
  • js-agent: add CBOR token support for loading NHP-Agent parameters (1fb9793)
  • js-agent: add CBOR token support for loading NHP-Agent parameters (cc36a68)
  • js-agent: add EN/zh-cn language switcher to demo page (5a7f89d)
  • js-agent: add EN/zh-cn language switcher to demo page (ca4604e)
  • js-agent: email as primary ID + CBOR token + 24h key expiry hint (155cd1a)
  • js-agent: expose NHPAgent.version + bump VERSION to 0.7.3 (e9ba4a4)
  • js-agent: expose NHPAgent.version sourced from nhp/version/VERSION (0616094)
  • js-agent: improve demo page DX for SDK integrators (0e3c561)
  • js-agent: improve demo page DX for SDK integrators (2f718af)
  • js-agent: scope perf metric to network round trip; demo form polish (1f5408d)
  • js-agent: scope perf metric to network round trip; demo form polish (8b4c869)
  • js-agent: success overlay, IP footer, and code panel polish (bd38ed7)
  • js-agent: success overlay, IP footer, and code panel polish (b55f14c)
  • js-agent: vendor browser SDK into endpoints/js-agent (6709d00)
  • plugin: improve OTP verification email (code-in-subject, headers, injection-safe) (4cc3f0b)
  • plugin: include OTP code in email subject and add opennhp.org link (c881e2b)
  • reg: add NHP-OTP / NHP-REG protocol workflow diagram to reg page (afee0f9)
  • reg: add page header "NHP-Agent Key Registration Workflow Demo" (ed5c0aa)
  • registration: add WebAuthn/FIDO2 hardware key support (e114d55)
  • reg: redesign registration page — 2-step flow, colorful protocol diagram, message spec (2565d52)
  • reg: replace message spec with tabbed API examples panel (112ea9f)
  • reg: replace message spec with tabbed API examples panel (3e6345b)
  • relay: lift multi-instance restriction, pick by load balance scheme (66c1730)
  • relay: support multiple nhp-server clusters via pubkey-derived id (eef8b56)
  • relay: support multiple nhp-server clusters via pubkey-derived id (d083653)
  • server-plugin: polish basic auth-plugin demo page (2b7a3f9)
  • server-plugin: polish basic auth-plugin demo page (599eb8c)
  • server: add AllowPrivateRelaySource flag for local-demo NAT (fe50276)
  • server: add ForceOverload debug flag to exercise the cookie path (43d1b6a)
  • server: per-source-IP rate limit for RKN-under-overload cookie ECDH (2a3ef64)

Bug Fixes

  • ac,core: post-review cleanup — lock config.Servers, skip empty SrcIP, comment fixes (3e56ffc)
  • ac: fail-close on initial etcd peer-table load (16b7180)
  • add OTP generation cooldown and reorder identity check before OTP (f3d583b)
  • add per-userId and distinct-device OTP rate limits to prevent cooldown bypass (f4ea94a)
  • address code review feedback for CBOR token modal (c245470)
  • address code review findings for agent registration (310bcab)
  • address review — enforce OTP-key binding, wire WebAuthn verification, mask SMTP secret (b5dd9d3)
  • address review — WebAuthn fail-closed, verifier hardening, handshake key binding (0520613)
  • agent,ac,relay: make config-reload paths preserve cluster bindings and fail-close (f545851)
  • agent,ac,server: close nil-deref, sticky-pin wedge, and attestation bypass (e9be6c7)
  • agent,ac: repair SDK knock crash and AC endpoint-key collision (c6f9c76)
  • agent: clear stale cookie on cluster swap; non-blocking SDK signals (568cb53)
  • agent: guard SDK request sends against post-Stop channel close (af93143)
  • agent: preserve extension response errors (71a36b4)
  • agent: preserve extension response errors (bdaad29)
  • agent: prevent double-close and post-stop send panics in lifecycle (8e983f1)
  • agent: propagate specific cluster-lookup errors to SDK callers (c318abd)
  • agent: re-arm knock-stop Once per Start; guard ExitKnockRequest send (bf3e5ef)
  • agent: scope missing-config tolerance to register; make run fail loudly (ae05338)
  • agent: send email in NHP-OTP UserData from register CLI (d3eaf6b)
  • bootstrap-tls: add verbose SAN diagnostic logging (972258c)
  • bootstrap-tls: force certbot to use correct lineage when expanding SANs (e351be3)
  • bootstrap-tls: include all existing SANs when expanding cert with --expand (4010c70)
  • bounds-check cborSkipValue and recover panics in message handlers (94a5ff6)
  • bump go-toml to v2.4.1 in plugin modules to match endpoints (38459d9)
  • bump go-toml to v2.4.1 in plugin modules to match endpoints (a3c3e8f)
  • ci: allow fork contributors to trigger claude-pr-review (133d527)
  • ci: fix claude-pr-review for fork PRs with gh token scrub bypass (0705438)
  • ci: hard-fail external-plugin step instead of silent no-op (30b30fa)
  • ci: move CLAUDE_CODE_SUBPROCESS_ENV_SCRUB override to job level (71a67a2)
  • core,server: post-second-review correctness + comment hardening (751529b)
  • core: copy cookie key out of StatelessCookieParams under the lock (a4f7322)
  • core: key cookies on real client addr, not relay addr (c828f75)
  • core: remove cgo dependency from errors (a7aa3e6)
  • core: remove cgo dependency from errors (6558da6)
  • correct SAN extraction in bootstrap-tls.sh (635774f)
  • default require_email_match to true in demo plugin (4d083af)
  • demo: address code review feedback for demo.nhp TLS (c2f23ac)
  • demo: address follow-up PR review issues for demo.nhp TLS (3a779a4)
  • demo: address follow-up PR review issues in demo.nhp renewal workflow (6be6d4d)
  • demo: address follow-up review issues in TLS automation (ae4b87f)
  • demo: address PR review issues for demo.nhp TLS proxy (d3cc4b5)
  • demo: address PR review issues for demo.nhp TLS proxy (b599278)
  • demo: address PR review issues for optional demo.nhp TLS deployment (5747bee)
  • demo: address review follow-ups for demo.nhp TLS (c8f6dbc)
  • demo: convert install-demo-nhp-cert.sh to LF line endings (14d1013)
  • demo: correct step ordering, full cert chain, and add -target comment (f85ddd8)
  • demo: create logs (plural) dir before starting nhp daemons (742530e)
  • demo: delete legacy certbot lineage instead of expanding it (7673c29)
  • demo: force fresh connection + no-store on acdemo vhosts (1516585)
  • demo: grant nhp-acd CAP_NET_RAW and CAP_DAC_OVERRIDE (3230f57)
  • demo: migrate legacy certbot lineage when renaming primary domain (526969e)
  • demo: null-guard scanPorts labels in acdemo changeLanguage (f7a5316)
  • demo: per-stack resource.toml overrides so shared default stays :443 (1c08665)
  • demo: scan cluster-2 server2/ac2 SSH host keys in infra apply (b686494)
  • demo: use relative paths in multicluster knock-test scripts (29f93f2)
  • demo: use sudo test for /etc/letsencrypt path checks (3ab0391)
  • deploy: add envsubst for SMTP placeholders in server2 plugin config (535e43e)
  • deploy: align server2 AC_PRIVATE_IP with server1 pattern (94fde22)
  • deploy: fix SMTP config not rendered on server2 and add missing DB migration (d8c0823)
  • deploy: register SM2 public keys for js-agent in server agent.toml (7950650)
  • deploy: rewrite ac/server.toml template to new [[Servers.Instances]] schema (2f4f680)
  • deploy: rewrite import map path in reg.html for production deployment (b1c71d9)
  • deps: bump vite to ^8.0.16 in docs (Dependabot #108) (b8a898b)
  • deps: bump vite to ^8.0.16 in docs to fix CVE server.fs.deny bypass (5764feb)
  • deps: fix basic-ftp and ws vulnerabilities in docs (e5542bd)
  • endpoints/ac: fail-close expandServerPeers when an entry's Endpoints all fail to parse (488cc87)
  • endpoints/server: keep s.config.CookieSigningKeyBase64 in sync with the running device key on reload (71124c7)
  • gofmt formatting in nhpmsg.go (01b9b38)
  • guard register config overwrite; derive SM2 pubkey instead of rotating (0f6ad4b)
  • infra: drop nhp-acd from root to ec2-user + bounded capabilities (8813ca7)
  • initialize EXPAND_FLAG before use in bootstrap-tls.sh (e9c17d5)
  • js-agent: address code review feedback for CBOR token modal (08598cc)
  • js-agent: always load demo config from server, drop localStorage cache (7f80de1)
  • js-agent: always load demo config from server, drop localStorage… (f1eb543)
  • js-agent: authenticate knock HeaderType (mirror wire type in body) (d10afec)
  • js-agent: map protected-host picker to cluster by explicit index (322fa9d)
  • js-agent: navigate reg Knock button to agent vhost via URL fragment (981c6f5)
  • js-agent: prevent protected server section from wrapping to two lines (fbc4ae1)
  • js-agent: prevent protected server section from wrapping to two lines (ca398f4)
  • js-agent: remove hardcoded relay URL default from reg.html (ca6b540)
  • js-agent: shorten protected server text to prevent wrapping (6a9d475)
  • js-agent: shorten protected server text to prevent wrapping (d282fae)
  • js-agent: sync package-lock.json version with package.json (811f1cf)
  • js-agent: update i18n strings to match shortened text (0daaba2)
  • js-agent: update i18n strings to match shortened text (1000647)
  • js-agent: use Curve25519 fingerprint for relay routing in GMSM mode (7fb23cb)
  • js-agent: use RAK packet in registerPublicKey expiresAt tests (4620032)
  • keystore: add incremental migration for otp_records.pub_key column (f15ec9a)
  • lint: correct British-spelling misspells flagged by golangci-lint 2.7.2 (c2e12d7)
  • lint: satisfy golangci-lint 2.7.2 (gosec G404, misspell) (cd2bb33)
  • lint: use US spelling in comments flagged by misspell (analog, penalized) (33cb8cf)
  • nginx: serve /nhp-js/ bundle from parent dir on reg vhost (6511851)
  • nginx: use try_files instead of alias to serve config.json on reg vhost (4360699)
  • nhp/core: route sendCookie through PrevParserData so the wire counter matches the agent KNK (a4388e9)
  • nil config dereference in relay routing test helper (57ff354)
  • noise: never carry zeroed intermediate chain key between packets (e7886f8)
  • OTP rate-limit info leak and sweep retention=0 regression (d580d9b)
  • pass --expand to certbot when cert already exists (a5fad5f)
  • plugins: align shared deps with endpoints to fix plugin.Open (a4acc5f)
  • plugins: align shared deps with endpoints to fix plugin.Open (5390ffa)
  • prevent DOM-based XSS in js-agent demo pages via innerHTML (6f8e450)
  • re-issue cert when EXTRA_DOMAINS missing from existing SAN (fb1c4d6)
  • relay: bound concurrent forwards per instance to cap pendingRequests (48dd472)
  • relay: bound naked channel sends to avoid handler-goroutine leaks (372216c)
  • relay: scope instance-address dedupe to (pubkey, addr) (1230386)
  • relay: spell "behavior" the American way to satisfy misspell linter (768725a)
  • remove IAM user from ses.tf, use manually-provisioned SMTP creds (cf39b4e)
  • remove WebAuthn and restore OTP/REG flow (5200e1a)
  • remove WebAuthn UI from reg.html (4ce46f4)
  • repoint recv channel + restart routine on ReinitWithKey; flag plugin API break (ba864ec)
  • resolve TTL test flake from Unix-second truncation race (495c838)
  • server,agent: authenticate knock HeaderType (reject on-path header flips) (cfa0871)
  • server,agent: authenticate knock HeaderType to block on-path header flips (306a73f)
  • server: bind stateless cookie to agent static pubkey (8bb8244)
  • server: close races and unbounded growth on hot config + handler paths (bc499d7)
  • server: identity-check map entry on conn teardown to match counter accounting (5c23ba2)
  • server: IPv6-safe relay conn key, prevent counter leak (e89e566)
  • server: make relay stale-replace and teardown counter-safe (db4d376)
  • server: model HRF fresh-insert branch in stale-replace race tests (1ba54e4)
  • server: preserve random cookie key on window-only reload (single-instance) (c0f68fd)
  • server: raise guard-disabling flags to Critical and warn on demo-key hot-reload (4e27e51)
  • server: reclaim per-relay slot on global-cap reject after stale-replace (f5ef3fe)
  • server: surface ForceOverload reload changes instead of silently dropping (4a7eb89)
  • server: warn loudly when CookieSigningKeyBase64 matches the shipped demo value (93553b4)
  • smtp_port TOML validity and relay StickyInstance default (871fc56)
  • terraform: mark demo_nhp_cert output as sensitive (e903f92)
  • terraform: mark demo_nhp_cert output as sensitive (3e4a817)
  • terraform: mark derived-from-sensitive outputs as nonsensitive (73dbc24)
  • terraform: mark derived-from-sensitive outputs as nonsensitive (9501ba2)
  • use --force-renewal instead of --keep-until-expiring with --expand (29911b0)
  • use correct aws_ses_domain_identity attributes for provider v5 (c6c3650)
  • use valid Go version in deploy workflow (85b6fab)

Performance Improvements

  • server: make rknRateLimiter eviction O(1) via random sampling (f17fc19)
  • server: per-relay connection cap is now O(1) under a dedicated lock (e7b74e6)

Reverts

  • relay: drop the multi-instance rejection introduced by f545851 (2b5b41f)

Miscellaneous Chores

Code Refactoring

  • relay: remove legacy POST /relay; tighten routing contract (bda88e1)

This PR was generated with Release Please. See documentation.

@codecov

codecov Bot commented May 16, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Impacted file tree graph

@@           Coverage Diff           @@
##             main    #1551   +/-   ##
=======================================
  Coverage   13.08%   13.08%           
=======================================
  Files          96       96           
  Lines       15005    15005           
=======================================
  Hits         1964     1964           
  Misses      12844    12844           
  Partials      197      197           
Flag Coverage Δ
unittests 13.08% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 4 times, most recently from b595e46 to aabaf68 Compare May 26, 2026 08:15
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 2 times, most recently from 73900ad to 2d488e0 Compare May 27, 2026 14:50
@opennhp-release-please opennhp-release-please Bot changed the title chore(main): release 1.1.0 chore(main): release 2.0.0 Jun 5, 2026
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 4 times, most recently from 8a2f59e to c36e3ec Compare June 11, 2026 01:34
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 6 times, most recently from 5996b42 to 87bd016 Compare June 19, 2026 01:50
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 5 times, most recently from 0ef33ce to 249532e Compare July 1, 2026 14:55
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 2 times, most recently from 1c65116 to 0ca8552 Compare July 7, 2026 17:12
@opennhp-release-please opennhp-release-please Bot changed the title chore(main): release 2.0.0 chore(main): release 0.7.2 Jul 7, 2026
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 3 times, most recently from c6b101b to 255be17 Compare July 10, 2026 07:26
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 3 times, most recently from f6a867d to b44bc19 Compare July 19, 2026 04:53

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 Changes Requested - Found 1 significant issue (plus 1 minor observation)

This is an automated release-please PR that only modifies CHANGELOG.md. No application code changes, so categories 1–2 (security/logic bugs) are N/A. However, the release metadata itself is wrong in a way that would corrupt the project's release history.

1. Version regression / collision — this release proposes 0.7.2, which already exists and is older than the current release (breaking, must fix)

CHANGELOG.md:9 inserts a new section:

## 0.7.2 (2026-07-19)

directly above the existing top entry (CHANGELOG.md:243):

## [1.0.0](.../compare/v0.7.3...v1.0.0) (2026-05-15)

Problems:

  • v0.7.2 already exists as a git tag (created 2026-05-07), as do v0.7.3 and v1.0.0. This PR re-uses the 0.7.2 version number for a brand-new, differently-dated release.
  • The current latest release is 1.0.0. Cutting 0.7.2 now is a semantic-version regression — a lower version number, dated later (2026-07-19 vs 2026-05-15), placed at the top of the changelog above 1.0.0.
  • .release-please-manifest.json is empty/absent in the repo, so release-please has no record that 1.0.0 (or 0.7.3) shipped. It is recomputing the next version from a stale base and landing on an already-used number.

Recommended fix: do not merge as-is. Reconcile release-please state before regenerating this PR — populate .release-please-manifest.json with the current released version (1.0.0) so the next release computes to 1.0.1/1.1.0/2.0.0 (the changelog lists several BREAKING CHANGES, so a major bump is likely warranted). Merging this PR would collide with the existing v0.7.2 tag and leave the changelog non-monotonic.

2. Minor: many duplicate entries

The generated section contains numerous duplicated lines from rebased/cherry-picked commits with identical messages, e.g. "add demo.nhp TLS proxy to AC nginx" (cc0647c, 738a996), "add CBOR token support…" (1fb9793, cc36a68), "support multiple nhp-server clusters via pubkey-derived id" (eef8b56, d083653), "authenticate knock HeaderType" (cfa0871, 306a73f), "mark demo_nhp_cert output as sensitive" (e903f92, 3e4a817), and others. This is cosmetic and pre-exists in the 1.0.0 section too, but it's worth cleaning the commit history / squashing before the next release cut. Not blocking on its own.

Once the manifest/version state is corrected and the PR regenerated with a sane version number, this is good to go.

@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 11 times, most recently from aff1a68 to c2ebae1 Compare July 26, 2026 05:33
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 3 times, most recently from acd3491 to ddabe52 Compare July 31, 2026 22:26
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch 4 times, most recently from 27cb289 to 2e50ef6 Compare August 3, 2026 23:00
@opennhp-release-please
opennhp-release-please Bot force-pushed the release-please--branches--main branch from 2e50ef6 to 682f715 Compare August 10, 2026 22:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants