From c22afea076518fcfcb4ea063173f6f7504e183a7 Mon Sep 17 00:00:00 2001 From: w-release-notes-v059-corrections Date: Wed, 16 Sep 2026 05:54:28 -0700 Subject: [PATCH] docs(release): correct two v0.5.9 release-note sentences The docker alias sentence named only the MCP-server trigger. The predicate at crates/maxplayer-core/src/seller_exec.rs:1137-1145 adds --add-host only when the job carries no netns AND either an env value or an MCP server entry references PROXY_HOST_ALIAS, so an environment reference alone is sufficient and the alias is never added under namespace containment. The evidence sentence claimed every bundle under evidence/ carries a README. Three of the six do: the 20260914T* bundles of this feature. Scoped the claim to them. --- RELEASE_NOTES.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/RELEASE_NOTES.md b/RELEASE_NOTES.md index 0ec1a4f8a..091262ff2 100644 --- a/RELEASE_NOTES.md +++ b/RELEASE_NOTES.md @@ -72,8 +72,9 @@ one that fits it. **A seat that declares neither key is unchanged.** credential proxy (#647) swaps the real credential into the `Authorization` header at egress, for the vendor's host only, for the life of the job, and the job reaches a vendor-hosted MCP server through `mcp-http-bridge`, now installed in the sandbox image. The docker alias pinhole opens only - when an MCP server entry names it, and the launch capture redactor knows every real credential - value a launch holds. + for a job outside namespace containment, and only when that job's environment or one of its MCP + server entries references the alias; the launch capture redactor knows every real credential value + a launch holds. - **Holder** (`[[sandbox.held_tools]]`). The daemon runs one persistent holder container per declared tool — `tool-holderd` from the new `maxplayer-tool-kit` crate, plus the vendor's own CLI. The holder enrols once and resumes its login across restarts. Each job gets its own Unix socket per @@ -109,8 +110,8 @@ difference is the reason to read this paragraph: does not claim one. The live tests are `#[ignore]`d and configured by environment — `seller_exec::mcp_tool_tests::live_*` -and `held_tool::live_tests::live_*` — and each bundle under `evidence/` carries a README stating -what it proves and its limits. +and `held_tool::live_tests::live_*` — and each of this feature's three bundles under `evidence/` +(the `20260914T…` directories) carries a README stating what it proves and its limits. Two limits ship with the feature. The Holder route needs Docker Engine 26 or newer for the volume subpath mount, and a seat too old for it fails its boot line rather than every awarded job. The