Added
-
- Added local fallback collection and
mirrord diagnose sip-reportfor
protected macOS binaries that still require Rosetta.
- Added local fallback collection and
- Added the
explain_config_optiontool tomirrord mcp, which describes a
mirrord.jsonormirrord-up.yamloption (docs, type, allowed values,
default and required plan) from the installed version's schema. - TLS stealing can present a client certificate matching the identity of the
original mTLS client: the agent when passing through unmatched traffic
(agentAsClient.identitiesin the TLS steal configuration), and the local
delivery when sending stolen and mirrored traffic to the local application
(feature.network.incoming.tls_delivery.client_identities). - Vendored the mirrord docs and skills into the
mirrord mcpbinary from
pinned commits, whichmirrord://inforeports and every release PR bumps. feature.db_branchesaccepts"*"or entry ids from the target's
MirrordSplitConfig.mirrord-schema.jsonandmirrord-up-schema.jsonrecord the mirrord plan
(oss,teamorenterprise) each feature option and target kind needs, as
x-mirrord-plan.
Fixed
- An invalid
feature.network.incoming.http_filter(a regex, method or jq
expression that doesn't compile, ormethod_filter/header_filter_jq
combined with another filter) is reported when the config is verified,
instead of crashing the layer when it starts. - Bun users now resolve cluster hostnames, without needing
BUN_FEATURE_FLAG_DISABLE_DNS_CACHE_LIBINFO. - Corrected CI command help:
mirrord ci startandmirrord ci containeruse
automatic ordinary credentials without a CI API key when a supporting Free
operator advertises keyless CI; other operator-backed CI sessions require a
CI API key. No-operator sessions and localmirrord ci stopdo not require
one. - Fixed
unlinkatrelative to an opened remote directory to keep using that
directory after it is renamed or its original path is replaced, preventing
deletion in a replacement directory. - Fixed some calls in mirrord that waited for I/O while they kept an internal
lock:closeon a socket or a remote file,closediron a remote directory,
connectto a local listener, anddup2ordup3onto a remote file. Other
threads could stall while one of these calls waited, if they made socket or
file calls or started a process. Also fixed a remote directory that could
stay open afterclosedirwhen another thread calledforkat the same
time. - Fixed the interactive progress spinner on Windows erasing the output of the
program started bymirrord exec. - On Windows, programs that mirrord runs by name (
docker,podman,
redis-server,git, ...) are now also found when they are installed as
.cmd/.batshims, the same waycmd.exeand PowerShell resolve them
throughPATHEXT. - Starting a queue-splitting session shows why the target's pods aren't ready
yet, andmirrord queues statuslists each pod's reason. - The
validate_configtool ofmirrord mcpchecks eachmirrord-up.yaml
service the waymirrord upassembles it, so it reports services that
mirrord upwould refuse to run, such as a targetless service insplit
mode or areplaceservice with a pod target. - The configuration reference describes what MySQL and MariaDB
copy.dump_args
can leave out of a branch. - Warnings about a database branch, such as a server version mismatch, show in
the session that creates the branch, not only in sessions that reuse it.