2026
- 2026-09-101.24.25 — Allow realistic broker startup time
MojoSec now gives short-lived firewall broker startup and readiness checks a bounded five-second correlation window, eliminating a narrow false-positive edge on busy nodes.
- 2026-09-101.24.24 — Preserve short-lived broker receipts
MojoSec now keeps valid automated firewall work local-only when journald omits process metadata for the fast-exiting root broker.
- 2026-09-101.24.23 — Prevent duplicate same-commit deployments
GitHub deliveries for the same commit now reuse one deployment attempt, preventing repeated JobEngine restarts during post-deploy work. Explicit operator retries remain available.
- 2026-09-091.24.9 — Unambiguous JobEngine audit lineage
django-mojo 1.24.9 makes JobEngine invoke application runners through the already-selected absolute Python executable. This removes the /usr/bin/env PATH-search exec chain that could make legitimate scheduled firewall work look ambiguous to MojoSec and flood the central security stream. No migration…
- 2026-09-091.24.8 — Production Audit lineage without MojoSec event floods
django-mojo 1.24.8 restores MojoSec's ability to prove scheduled firewall work from the Audit records AL2023 actually writes, so routine reconciliations no longer flood the central security stream. Missing, malformed, conflicting, stale, capacity-limited, or unrelated privileged activity still fails…
- 2026-09-091.24.7 — Firewall authority independent of MojoSec
django-mojo 1.24.7 makes firewall reconciliation a separately enrolled host capability instead of a side effect of MojoSec. MojoSec can remain off: only an enrolled, ready application runner advertises firewall authority, and explicit fleet membership prevents an unavailable node from being mistaken…
- 2026-09-091.24.6 — Packaged portal-mojo Admin with coordinated source sessions
django-mojo 1.24.6 replaces the experimental handwritten Admin v2 with the packaged portal-mojo application while preserving the existing Admin. The new Portal automatically uses same-origin APIs, is linked from the legacy sidebar, and coordinates short-lived source sessions across tabs and logout r…
- 2026-09-091.24.5 — Version-aware MojoSec lifecycle during framework deploys
django-mojo 1.24.5 prevents long-lived MojoSec sensors from silently continuing to run old framework code after an upgrade. Deployments now refresh an already-active stale sensor, prove its process generation and loaded version, repeat the operation for rollback and recovery, and preserve the rule t…
- 2026-09-091.24.4 — Firewall broker recovery and MojoSec flood controls
django-mojo 1.24.4 fixes a firewall broker memory ceiling that could make every reconciliation call fail before returning a response, then repeat across thousands of desired objects. Broker-wide failures now stop immediately and enter normal job backoff. The release also adds best-effort MojoSec cat…
- 2026-09-091.24.3 — phonehub: a failed carrier lookup is negative-cached instead of crashing
A provider error on a never-cached phone number no longer raises IntegrityError and no longer re-bills the provider on every retry. The error is cached briefly with exponential backoff and exposed as `lookup_unavailable`; `is_valid` is never written by the error path, so a Twilio outage cannot mint…
- 2026-09-091.24.22 — Ignore non-exec firewall Audit records
MojoSec now excludes explicit non-exec NETFILTER syscall compounds that reuse a firewall child PID from the process-generation proof graph, while managed and unknown exec evidence stays conservative.
- 2026-09-091.24.21 — Correct AL2023 failed-exec boundaries
MojoSec now recognizes AL2023’s trusted PROCTITLE boundary when proving that a failed firewall exec did not create a competing process generation. Missing, incomplete, or conflicting Audit outcomes still remain central.
- 2026-09-091.24.20 — Reliable short-lived firewall proof
MojoSec now handles short-lived AL2023 firewall processes without misclassifying legitimate cron-owned work. Exact receipt, command, parent, and pinned JobEngine checks remain required.
- 2026-09-091.24.19 — Correct AL2023 firewall proof paths
MojoSec now matches the firewall command paths used by the broker to the fixed executables AL2023 records in Audit, so proven cron-owned reconciliations stay local. Exact argv, digest, PID, receipt, and JobEngine checks remain required.
- 2026-09-091.24.18 — Quiet cron-owned firewall readiness
The root firewall broker now proves read-only readiness checks so MojoSec keeps exact cron-owned probes local. Failed or unproven calls still remain central; there are no migrations, configuration changes, or API changes.
- 2026-09-091.24.17 — Reliable firewall proof under reconcile bursts
MojoSec now keeps legitimate cron-owned firewall reconciliations locally classified even when a full reconcile produces a large burst of process and receipt evidence. It also follows the newest audit-health observation after deployment sequence resets. No migrations, configuration changes, or consum…
- 2026-09-091.24.16 — Unambiguous cron Jobman startup
Cron now invokes the installed Jobman module through a stable bash → Jobman → engine process chain. MojoSec can prove scheduled firewall work after deployments without treating the legitimate wrapper re-exec sequence as unexplained privileged activity. No migrations or configuration changes are requ…
- 2026-09-091.24.15 — Reliable cron-owned job restarts
API deploys now verify the real Jobman cron path, retire old job processes safely, and let cron start fresh replacements with provable lineage.
- 2026-09-091.24.14 — Canonical firewall broker lineage
Firewall broker launches now produce one canonical Audit exec generation so MojoSec can prove expected reconciliation work without weakening its fail-open checks.
- 2026-09-091.24.13 — Resilient MojoSec identity helper
MojoSec keeps its least-privilege process-identity resolver available when an individual client request times out, disconnects, or fails.