Release version 2.2.0
Some checks failed
tests / lint (push) Has been cancelled
tests / pytest (push) Has been cancelled
tests / tor-network-e2e (push) Has been cancelled

This commit is contained in:
Kevin Veen-Birkenbach
2026-07-21 19:09:25 +02:00
parent 05e9129f4e
commit 69779919e5
2 changed files with 15 additions and 1 deletions

View File

@@ -1,5 +1,19 @@
# Changelog
## [2.2.0] - 2026-07-21
- Optional remote LUKS unlock via a Tor onion service in the initramfs.
Encrypted image setups can bake *tor* into the initramfs (mkinitcpio hooks
ordered *netconf tor dropbear encryptssh*), generate the v3 onion keys
offline in the image chroot, and print the stable *.onion* address. Unlock
with *torsocks ssh root@<onion-address>*. Useful behind NAT/CGNAT or a
dynamic IP, where the direct *ssh root@<ip>* unlock cannot reach the host.
- End-to-end tests: a rootless one (*LIM_E2E_TOR=1*) that round-trips a
passphrase through a real Tor onion service, and a full virtualized one
(*LIM_E2E_QEMU=1*) that builds a LUKS image, boots it in QEMU, and unlocks
the root over Tor. The offline onion keygen runs in CI; *make test-tor* /
*make test-qemu* / *make test-all* run the opt-in stages.
## [2.1.0] - 2026-07-14
Initial PyPI release 🥳