Upgrade hotcell to 0.4.1 - #3108
Conversation
A killed worker left its tool's scratch files at the top of the cell's `/tmp`, outside the slot tree that is removed when a request ends, so the scratch volume filled over time. A worker now points `TMPDIR` at the request's home, and the supervisor empties the scratch at boot. That boot sweep is why the dev cell in `saas/Procfile.dev` now gets a `TMPDIR` of its own: unset, it would sweep the developer's `/tmp`. The release's ImageMagick changes do not reach this cell, which loads only the vips, ffprobe, mutool and ffmpeg operations and installs no ImageMagick, so the `MAGICK_*_LIMIT` variables stay unset. ref: https://github.com/basecamp/hotcell/blob/v0.4.0/CHANGELOG.md
A crash's diagnosis — `libgomp: Thread creation failed` — survived only in the exception's message, so a failure that was discarded rather than retried lost it. hotcell 0.4.0 carries the captured stream on the `perform.hot_cell` event; write it as a field on the existing log line. ref: basecamp/hotcell#60
🤖 Upgrade Plan: hotcell v0.3.1..v0.4.0Upgrade Plan: hotcell v0.3.1..v0.4.0 for fizzy
Summary
Answers to the two questions asked up front:
Also: the Execution order
Commits Requiring Mitigation4eda0bc7: Empty the scratch at supervisor boot (#52)Impact: definite impact
Mitigation:
41288269: Read the ImageMagick operations' input through its descriptor (#54)Impact: likely impact
Mitigation: 460a8e1b: Carry a failure's stderr on the perform.hot_cell event (#60)Impact: unlikely impact (pattern search found no unsafe payload serialization), but the CHANGELOG "Upgrading" section asks client apps to log the field, and fizzy has the subscriber to do it.
Mitigation:
ce25447d: Point a worker's TMPDIR at the request's homeImpact: unlikely impact
Mitigation: Override audit (3a-bis)Override surface examined: Residual delta:
Advisories: the only identifier in the range is Analyzed — No App Impact
No Impact (Skipped)9 commits assessed as "no impact" during recon, not analyzed against the app: Transitive Dependency UpgradesBoth moved only in the cell's lockfile (
No security advisories in either range. Execution recordExecuted 2026-09-08 on branch
|
🤖 Transitive Upgrade Plan: image_processing 2.0.3..2.1.0Upgrade Plan: image_processing v2.0.3..v2.1.0 for fizzy
ScopeThis gem moves only in the cell's lockfile, pulled by The cell loads Summary
Commits Requiring MitigationNone. Analyzed — No App ImpactNone reached this stage; both commits were assessed "no impact" at recon. No Impact (Skipped)
The whole diff is Override auditOverride surface for image_processing in the cell: Why the range exists at all: Residual delta: none. No patch is broken, redundant, or inert. AdvisoriesNo Plan
|
🤖 Transitive Upgrade Plan: mini_magick 5.3.3..5.4.0Upgrade Plan: mini_magick v5.3.3..v5.4.0 for fizzy
Summary
The whole release is one additive feature: Why the cell movedThe bump is a hard floor, not a drift: Fizzy exposureNone at runtime. Verified:
If magick operations are ever enabled in the cellNot required now; recorded so the next person does not rediscover it:
Commits Requiring MitigationNone. Analyzed — No App ImpactNone above "no impact". No Impact (Skipped)
Assessments: |
The 0.4.0 dev cell needed a `TMPDIR` of its own, made by hand, or its boot sweep emptied the developer's `/tmp`. hotcell 0.4.1 adds `hotcell --development`, which keeps the scratch in a directory of the cell's own under the system temporary directory and never sweeps the directory it was given. Use it in `saas/Procfile.dev` instead. ref: basecamp/hotcell#61
🤖 Upgrade Plan: hotcell v0.4.0..v0.4.1Upgrade Plan: hotcell v0.4.0..v0.4.1 for fizzy
Summary
The pins ( Decision: replace the
|
| Commit | Summary |
|---|---|
e123993d |
version bump to 0.5.0.dev |
46bd334d |
Release v0.4.1 (version constants and CHANGELOG heading only) |
A `~>` pin let a patch release move the app's client and the cell's server independently, and one version apart is a `protocol` failure on every request. Pin both Gemfiles to `0.4.1`.
* Upgrade hotcell to 0.4.0 A killed worker left its tool's scratch files at the top of the cell's `/tmp`, outside the slot tree that is removed when a request ends, so the scratch volume filled over time. A worker now points `TMPDIR` at the request's home, and the supervisor empties the scratch at boot. That boot sweep is why the dev cell in `saas/Procfile.dev` now gets a `TMPDIR` of its own: unset, it would sweep the developer's `/tmp`. The release's ImageMagick changes do not reach this cell, which loads only the vips, ffprobe, mutool and ffmpeg operations and installs no ImageMagick, so the `MAGICK_*_LIMIT` variables stay unset. ref: https://github.com/basecamp/hotcell/blob/v0.4.0/CHANGELOG.md * Log what a failed cell tool wrote to stderr A crash's diagnosis — `libgomp: Thread creation failed` — survived only in the exception's message, so a failure that was discarded rather than retried lost it. hotcell 0.4.0 carries the captured stream on the `perform.hot_cell` event; write it as a field on the existing log line. ref: basecamp/hotcell#60 * Upgrade hotcell to 0.4.1 and boot the dev cell with --development The 0.4.0 dev cell needed a `TMPDIR` of its own, made by hand, or its boot sweep emptied the developer's `/tmp`. hotcell 0.4.1 adds `hotcell --development`, which keeps the scratch in a directory of the cell's own under the system temporary directory and never sweeps the directory it was given. Use it in `saas/Procfile.dev` instead. ref: basecamp/hotcell#61 * Pin the hotcell gems to exact versions A `~>` pin let a patch release move the app's client and the cell's server independently, and one version apart is a `protocol` failure on every request. Pin both Gemfiles to `0.4.1`.
Upgrade hotcell from 0.3.1 to 0.4.1 (changelog). 19 commits analyzed (16 in v0.3.1..v0.4.0, 3 in v0.4.0..v0.4.1), 5 needing attention, 2 transitive gems in the cell's lockfile analyzed with no impact.
Basecamp card: https://app.basecamp.com/2914079/buckets/1666/card_tables/cards/10281760225
Changes
Gemfile.saasandsaas/hotcell/Gemfilepinned to exactly0.4.1; cell image rebuilt andsaas/config/deploy.ymlpinned to2f4ddc90eae3. The cell's lockfile movesmini_magickto 5.4.0 andimage_processingto 2.1.0 to meet the newactivestorage-hotcell-serverfloors.saas/lib/yabeda/hot_cell.rbwrites the newstderrpayload field on the existingHotCelllog line (hotcell#60). It stays out of the Yabeda labels. Closes the stderr-logging item on Fizzy card 5270 and this Basecamp card.saas/Procfile.devboots the dev cell withhotcell --development(hotcell#61, new in 0.4.1). The 0.4.0 supervisor empties the scratch at boot (hotcell#52), which for a plain-process cell with noTMPDIRof its own meant the developer's/tmp; the first cut of this PR worked around that with a hand-madeTMPDIR, and 0.4.1 replaces the workaround with the flag. With it the cell keeps its scratch in a directory of its own under the system temporary directory and never sweeps the directory it was given. Without the flag 0.4.1 behaves exactly like 0.4.0, so the production accessory (dedicated scratch mounted at/tmp, no flag) is unchanged.ImageMagick resource limits: not needed
hotcell#59 forwards
MAGICK_*_LIMITto themagickchild, which only matters in a cell that runs an ImageMagick operation. Fizzy's cell does not:saas/hotcell/operations/active_storage.rbrequires the vips, ffprobe, mutool and ffmpeg operation files one at a time and never the gem entry point that loads the magick ones,saas/hotcell/Dockerfileinstalls no ImageMagick package, andmagickloadstays blocked in libvips. That is unchanged across the range. A dev cell booted on 0.4.0 registers exactlyactive_storage.analyzers.image.vips,active_storage.analyzers.media.ffprobe,active_storage.previewers.pdf.mutool,active_storage.previewers.video.ffmpeg,active_storage.transformers.image.vipsplus the two example operations.After merge
The cell image
2f4ddc90eae3is built locally only. Thepre-buildkamal hook publishes it on the next deploy, andpre-deployreboots the accessory, so a normalbin/kamal deployships both.Upgrade plan
Full analysis is in the 🤖 comments below and at
37signals-hq/upgrade-analysis/fizzy-20260908-hotcell_v0.3.1..v0.4.0.mdandfizzy-20260908-hotcell_v0.4.0..v0.4.1.md.