From 532724baf71216b00ab642600d339a16228bab79 Mon Sep 17 00:00:00 2001 From: Cole Speelman Date: Wed, 12 Aug 2026 15:09:32 -0400 Subject: [PATCH] docs: publish the v1 beta evidence Publish the exact-candidate Windows and Linux results, signed-tag and clean-install status, provisional macOS boundary, and reliable runtime-first Beta 1 installation order. The post-publication verifier now cleans read-only module caches safely. This commit is an exact sanitized export from the private development record. Material drafting and review were assisted by OpenAI Codex; Cole Speelman reviewed the changes and accepts human responsibility. Signed-off-by: Cole Speelman --- CHANGELOG.md | 23 +++++++----- PUBLIC-SNAPSHOT.json | 2 +- PUBLIC-SNAPSHOT.sha256 | 20 +++++------ README.md | 30 +++++++++------- RELEASE.md | 22 ++++++------ ROADMAP.md | 7 ++-- SECURITY.md | 4 +-- docs/COMPATIBILITY.md | 16 ++++----- docs/SECURITY_EVIDENCE.md | 62 ++++++++++++++++---------------- docs/V1_RELEASE_PLAN.md | 27 +++++++------- scripts/README.md | 2 +- scripts/verify-public-install.sh | 47 ++++++++++++------------ 12 files changed, 136 insertions(+), 126 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9966744..d3502d8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -27,24 +27,29 @@ not a production-stability promise. - Public beta support policy for evaluation and classroom use, including a provisional macOS lane and a community compatibility-reporting path. -### Pre-beta verification baseline +### Release verification -Maintainer-run Linux and native Windows matrices passed on public commit -`113c95c21e57227b4675c9fda015ada59cc9e9a6` (tree -`a2aeb4dac22853cb3894e3e487b94bbeff5051e5`) with Go 1.25.12 and Go -1.26.5. The tested golden output had the same SHA-256 on each tested host: +The exact public Beta 1 commit +`b7a84054d755e42285e50298e41e47f06a8325a5` (tree +`be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run +executed Linux and native Windows matrices with Go 1.25.12 and Go 1.26.5. The +tested golden output had the same SHA-256 on each tested host: `63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`. -That commit is a pre-beta baseline, not evidence for the later Beta 1 commit. -The required matrix must be rerun from the exact candidate before its tags are -published. Native macOS execution remains pending and is explicitly provisional -for this beta. +The complete release preflight passed, including race tests, bounded parser +fuzz smoke, known-vulnerability analysis of both zero-third-party-dependency +modules, candidate-version provenance, and six cross-builds. The signed runtime +and compiler tags were published in that order. Fresh direct and public-proxy +runtime-first installs passed after normal proxy propagation. Native macOS +execution remains pending and is explicitly provisional for this beta. ### Known limitations - Source syntax, generated format, CLI details, and runtime API may change before final v1. - Native macOS behavior has not yet been maintainer-validated. +- In a shared fresh Go module cache, add the nested `sando` runtime before + installing the parent compiler module at the same Beta 1 version. - Prebuilt binary artifacts, checksums, SBOMs, reproducible archives, key-recovery rehearsal, systematic browser differential, long fuzz, benchmark, and final compatibility gates remain work toward the release diff --git a/PUBLIC-SNAPSHOT.json b/PUBLIC-SNAPSHOT.json index b4830e4..852b001 100644 --- a/PUBLIC-SNAPSHOT.json +++ b/PUBLIC-SNAPSHOT.json @@ -1 +1 @@ -{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":80,"allowlist_sha256":"e40a56b3431efdd99b3a78c38c387722de347216640383fc849569a817edf5c6","manifest_sha256":"93870a8c1e91602754de257c30249892821356ea9bf8d89e1b4502b62d769b06"} +{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":80,"allowlist_sha256":"e40a56b3431efdd99b3a78c38c387722de347216640383fc849569a817edf5c6","manifest_sha256":"1ba4d6b66c26796b5bbce118680726f9a964824f72142aea568642e25d0f33b3"} diff --git a/PUBLIC-SNAPSHOT.sha256 b/PUBLIC-SNAPSHOT.sha256 index 8033803..468b169 100644 --- a/PUBLIC-SNAPSHOT.sha256 +++ b/PUBLIC-SNAPSHOT.sha256 @@ -2,7 +2,7 @@ 658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore 98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md -8bc6c7586a58bdc648c7d3df2db33fa6db6381a111da9d8fc2d5817b5e0517ad ./CHANGELOG.md +b1faa7df0336b9ba68b28136fb72e9ba44185c35ba8cbec01d01c00599ea5c46 ./CHANGELOG.md b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md 797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md 86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT @@ -13,10 +13,10 @@ a4570d054f072d33b8f17b0c8b162a6ee0ca37d7df2b1aee7e4b728ab350a892 ./GOVERNANCE.m 47d857e49f89596bac9b09fc8ca57a668a33d01e2b51508acfc92ed321cdc27f ./LICENSES.md b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md 6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md -dda0ffee17bc1586ac16cc9707999cde2909a116c98cd43aeab85e0d3da7b636 ./README.md -9895823f9f7ba88ddf048c53c23ed32298b151ab049a9c4470366389d9498ff4 ./RELEASE.md -6d1e49dd72ba9592a3fd0562fcca1857803a3dd86dc097b36043e20f5d5cd591 ./ROADMAP.md -50a24995b39a957e47e0e181f8771a87141302b4d308fa8d8bfdc2e70121c2b9 ./SECURITY.md +e17347ac53a05bad439308f8f9a6bc10f7438d06ce75d09a7f94aadc1d96a726 ./README.md +9b78254033063ec97f1c9f66aaef9503e477e1f5c3dd602bb78fd78f9e64b90b ./RELEASE.md +209decb6769646eb2f58e312fbcd9c497c26234f3d3115bae3f20493b8178584 ./ROADMAP.md +ea26e6bcdf97746627f21ba64bed16bdb7630f808215e19558ff7c7550422491 ./SECURITY.md 53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md 3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md 136a6d82db842547b342f8b0c9ffdc7c04f7c9b473b4ef6dca9dbc940cb24b54 ./cmd/himesan/main.go @@ -24,12 +24,12 @@ dda0ffee17bc1586ac16cc9707999cde2909a116c98cd43aeab85e0d3da7b636 ./README.md 1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md 9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md 5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md -4f7b04b3f74a2e90fc69019cad78a1287f4806ae84e7207cfdf000971702395d ./docs/COMPATIBILITY.md +796618a874a53176f7459192c3f5e0aa0c28c2027d4874d2ffa87e285d6692d0 ./docs/COMPATIBILITY.md 5f4ac209a16ab110baeaa64a40c19d9239c903e17550c3f05e1e1473ddcc33a3 ./docs/DEVELOPMENT_SERVER.md 51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md -9bd43853d91b841c4879dac94dda5aafefa25bcdf4a02763445e2506fc618b03 ./docs/SECURITY_EVIDENCE.md +965a6ae57a8162c3af81f4987771e88617247f903088d210720ea2afab152cc9 ./docs/SECURITY_EVIDENCE.md d969c7b5486ee93e54232fd69d9db06f3b4dc1bba63001596ec48545073c2680 ./docs/THREAT_MODEL.md -82107c57043af40b9e3ec03f4ed9efddcf3bcdda1765b99ec413f835be4a46e3 ./docs/V1_RELEASE_PLAN.md +738258ba8f7e5ffea67d3f00eb70839590171971a9946a55b013ca95baf7aafb ./docs/V1_RELEASE_PLAN.md f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go 6ef6a0f15a5aca1c8708cbf24218372e1fca9c6fead1a5a75d261faa69651af7 ./internal/compiler/backend.go @@ -72,9 +72,9 @@ ff76daee5b642ad84af31701833246d68b54d09580192312d750a7a2e893a692 ./sando/go.mod 80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go 85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go -504897b29686e0ea7adff8beb8ec91612df3ee169397309c3b6b69eb0393491b ./scripts/README.md +c4a161faba46ce5b508c0788078256a520277a573a3ace0e85ae0c26b16d298b ./scripts/README.md 0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh 6c73ad46beb642836ae4d462f40e7ecc8d86a3cc194e71a5d0859dac73af0410 ./scripts/release-check.sh -9cd43005a7d0f3659b11c5c14e4e0b9e7f675b695da185f4ee97c54edebf0dc6 ./scripts/verify-public-install.sh +78a64c7fb3a039b15a1d08b4c0b873952852287a07f670247b081e59dbb09a30 ./scripts/verify-public-install.sh 24ed3c9a1d37e46a856cbbd68e5c58ae04c6c9852902b99ed675e1f428339a9f ./scripts/verify.ps1 f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh diff --git a/README.md b/README.md index 6241b18..142271d 100644 --- a/README.md +++ b/README.md @@ -48,26 +48,29 @@ semantic-version prerelease: source syntax, generated output, the runtime API, and CLI behavior may change before final v1, and this beta is not recommended for production deployment. -Maintainer-run testing has established a pre-beta baseline on native Windows -and on Linux with Go 1.25 and Go 1.26. That matrix must pass again on the exact -Beta 1 commit before its tags are published. Native macOS validation is still +The exact Beta 1 source passed maintainer-run native Windows and executed Linux +matrices with Go 1.25.12 and Go 1.26.5. Native macOS validation is still pending, so macOS support is provisional in this beta. Mac learners and Go developers are warmly invited to try it and share their macOS version, architecture, Go version, command, and smallest useful reproduction. Community reports broaden the evidence; maintainers remain responsible for security review, triage, fixes, and release decisions. -Install the beta compiler: +Inside an application module, add the small runtime first: + +```sh +go get gamertan.com/sandwich-hime/sando@v1.0.0-beta.1 +``` + +Then install the beta compiler: ```sh go install gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-beta.1 ``` -Add the small runtime to an application module: - -```sh -go get gamertan.com/sandwich-hime/sando@v1.0.0-beta.1 -``` +Keep that runtime-first order for Beta 1. It avoids a Go module-cache ambiguity +between the parent compiler module and its nested runtime when both use the +same prerelease version. For a reproducible one-off or classroom invocation that does not depend on the learner's `PATH`: @@ -76,10 +79,11 @@ learner's `PATH`: go run gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-beta.1 --help ``` -The runtime is released first as `sando/v1.0.0-beta.1`; the compiler follows as -`v1.0.0-beta.1`. If a newly announced version is not immediately available -through a module proxy, retry after the proxy has discovered the immutable tag -or use the canonical Gitea release instructions. +The runtime was released first as `sando/v1.0.0-beta.1`; the compiler followed +as `v1.0.0-beta.1`. Both signed tags, direct fetching, the public Go proxy, and +the checksum database have been verified. A newly announced future version may +still need a short propagation interval before every proxy sees its immutable +tag. For repository development: diff --git a/RELEASE.md b/RELEASE.md index 4b21742..ac86d54 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -68,14 +68,15 @@ Before `sando/v1.0.0-beta.1` and `v1.0.0-beta.1` are created: generated fixtures are current under that exact binary. 7. Create signed annotated tags and publish the runtime tag first, then the compiler tag, from the same reviewed commit. -8. Verify both documented installs from fresh `GOPROXY=direct` and public-proxy - caches. Record propagation delays as delays, not test passes. +8. Verify both documented runtime-first installs from fresh `GOPROXY=direct` + and public-proxy caches. Record propagation delays as delays, not test + passes. -The passing public commit -`113c95c21e57227b4675c9fda015ada59cc9e9a6` (tree -`a2aeb4dac22853cb3894e3e487b94bbeff5051e5`) is only the pre-beta -platform baseline. Any documentation, versioning, or code change produces a new -candidate and requires the candidate matrix to run again before tagging. +Beta 1 was published from public commit +`b7a84054d755e42285e50298e41e47f06a8325a5` (tree +`be9e118e38dfebed19f60403ededdadabe07d2aa`) after its exact-candidate +matrix passed. Future prereleases require their own candidate evidence; this +result cannot be relabeled for another commit. ## RC and final gates @@ -110,9 +111,10 @@ metadata exist, run: scripts/verify-public-install.sh --version vX.Y.Z ``` -That check exercises the documented `go install` and `go get` commands from -fresh direct-fetch and public-proxy caches. It is separate from the pre-tag, -read-only `scripts/release-check.sh`. +That check adds the nested runtime before installing the parent compiler, then +exercises both commands from fresh direct-fetch and public-proxy caches. The +order avoids the Go module-cache ambiguity documented for Beta 1. It is +separate from the pre-tag, read-only `scripts/release-check.sh`. Release notes report hardware, commit, datasets, commands, `ns/op`, allocations, response latency, and methodology for any performance claim. diff --git a/ROADMAP.md b/ROADMAP.md index fb00664..7f481f1 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -17,11 +17,12 @@ it is not a production-stability promise. - [x] Establish a public pre-beta Linux/Windows matrix on Go 1.25 and Go 1.26. - [x] Document macOS as provisional and invite useful community reports while retaining maintainer responsibility for security and releases. -- [ ] Rerun all required Windows/Linux checks and deterministic generation on +- [x] Rerun all required Windows/Linux checks and deterministic generation on the exact Beta 1 candidate. -- [ ] Publish immutable `sando/v1.0.0-beta.1`, then +- [x] Publish immutable `sando/v1.0.0-beta.1`, then `v1.0.0-beta.1`, from the reviewed public commit. -- [ ] Verify clean direct and public-proxy installs after publication. +- [x] Verify clean runtime-first direct and public-proxy installs after + publication. - [ ] Complete native macOS maintainer validation. This is an RC/final gate, not a Beta 1 gate. diff --git a/SECURITY.md b/SECURITY.md index 939e278..cbe5f24 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -17,7 +17,7 @@ advisories, and release decisions. | Version | Security status | | --- | --- | -| `v1.0.0-beta.1` and `sando/v1.0.0-beta.1` | Current evaluation/classroom prerelease once published; best-effort security assessment and fixes; interfaces may change | +| `v1.0.0-beta.1` and `sando/v1.0.0-beta.1` | Current published evaluation/classroom prerelease; best-effort security assessment and fixes; interfaces may change | | Public `main` | Development source; reports welcome, but no compatibility or production-support promise | | Older prereleases | Superseded when a newer prerelease or final version is published; reports are still triaged to determine affected versions | @@ -133,7 +133,7 @@ an independent security audit, certification, or formal verification. Coverage percentages, passing scanners, and a clean vulnerability database result are evidence of specific checks—not proof that no vulnerability exists. -Beta 1 publication requires signed annotated source tags, but may precede the +Beta 1 uses signed annotated source tags, but precedes the complete prebuilt-artifact and key-recovery system. Signed binaries, checksums, an SBOM, reproducible archives, and complete source/build provenance are release-candidate and final-v1 gates. Their absence from a source-only beta must diff --git a/docs/COMPATIBILITY.md b/docs/COMPATIBILITY.md index 6720131..8d45db2 100644 --- a/docs/COMPATIBILITY.md +++ b/docs/COMPATIBILITY.md @@ -36,25 +36,25 @@ Beta 1 targets Go 1.25 and Go 1.26. Support is based on point-in-time, maintainer-run release matrices, not an implication of continuous CI coverage. A Go support change is announced in release notes before it takes effect. -The current public evidence is a **pre-beta baseline** on commit -`113c95c21e57227b4675c9fda015ada59cc9e9a6` (tree -`a2aeb4dac22853cb3894e3e487b94bbeff5051e5`): +The current public evidence is the exact Beta 1 source at commit +`b7a84054d755e42285e50298e41e47f06a8325a5` (tree +`be9e118e38dfebed19f60403ededdadabe07d2aa`): | Platform | Go lanes | Maintainer-run result | | --- | --- | --- | | Windows 11/amd64 on NTFS | 1.25.12, 1.26.5 | Native tests, race, vet, builds, generation, process cleanup, watcher boundaries, and temporary consumer compilation passed; privileged symlink and POSIX-only permission cases were not exercised | | Linux/amd64 on WSL2 with an ext4 checkout | 1.25.12, 1.26.5 | Tests, race, vet, builds, generation, focused filesystem/development cases, and license checks passed | -| Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | Tests, race, vet, builds, deterministic generation, and license checks passed | +| Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | The earlier pre-beta baseline passed tests, race, vet, builds, deterministic generation, and license checks; this was not rerun on the exact Beta 1 commit | | macOS | — | Native maintainer validation pending; provisional for Beta 1 | The golden generated file had SHA-256 `63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f` on every tested Windows and Linux lane. -Because the Beta 1 candidate contains changes after that public baseline, the -complete Windows/Linux matrix must be rerun on the exact candidate before the -tags are published. The baseline does not become beta evidence merely because -its code is nearby in history. +The signed Beta tags and fresh direct/public-proxy installation were verified +after publication. For Beta 1, add the nested runtime to an application module +before installing the parent compiler at the same version; this avoids a Go +module-cache path-selection ambiguity observed in the reverse order. ## macOS feedback diff --git a/docs/SECURITY_EVIDENCE.md b/docs/SECURITY_EVIDENCE.md index fda9a51..f1239d2 100644 --- a/docs/SECURITY_EVIDENCE.md +++ b/docs/SECURITY_EVIDENCE.md @@ -11,23 +11,20 @@ verification, or guarantee that no vulnerability exists. | Field | Value | | --- | --- | | Assessment date | 2026-08-12 | -| Evidence sets | Clean security self-assessment plus an exact-commit pre-beta platform baseline; neither is evidence for the later Beta 1 candidate | -| Public commit | `113c95c21e57227b4675c9fda015ada59cc9e9a6` | -| Public tree | `a2aeb4dac22853cb3894e3e487b94bbeff5051e5` | -| Maintainer-run environments | Windows 11/amd64 on NTFS; Ubuntu 20.04/amd64 under WSL2 on ext4; Linux/amd64 server containers | +| Evidence sets | Clean security self-assessment plus exact-commit Beta 1 platform, release, signing, and installation checks | +| Public commit | `b7a84054d755e42285e50298e41e47f06a8325a5` | +| Public tree | `be9e118e38dfebed19f60403ededdadabe07d2aa` | +| Maintainer-run environments | Windows 11/amd64 on NTFS; Ubuntu 20.04/amd64 under WSL2 on ext4; supplementary pre-beta Linux/amd64 server containers | | Supported Go lanes exercised | Go 1.25.12 and Go 1.26.5 | | Declared minimum Go | Go 1.25 | | Assessor | Project maintainer with AI-assisted code review; human responsibility retained | -The named platform runs used the exact public commit and tree above. Hostnames, -network addresses, account names, private paths, private repository identities, -and private commit mappings are intentionally absent from this public ledger. - -Beta 1 necessarily changes the tree through versioning, provenance, -documentation, or source fixes. Therefore this baseline cannot be relabeled as -Beta 1 evidence. The required Windows/Linux campaign must pass again on the -exact Beta 1 candidate before either tag is published. Native macOS execution -remains pending and is provisional for the beta. +The named Windows and WSL2 platform runs used the exact public commit and tree +above. The isolated server-container matrix preceded the final candidate and +is retained only as supplementary Linux evidence. Hostnames, network addresses, +account names, private paths, private repository identities, and private commit +mappings are intentionally absent from this public ledger. Native macOS +execution remains pending and is provisional for the beta. ## Observed security self-assessment evidence @@ -52,7 +49,7 @@ baseline commit. | URL scheme handling | ordinary/trusted URL test matrix | Pass for enumerated cases | | Filesystem boundaries | symlink, nested-module, VCS, ownership, stale-output tests | Pass for tested cases; see open findings | | Development proxy browser boundary | Host, Origin, Fetch Metadata, CSP, fragment and response tests | Pass for tested cases | -| Platform behavior | Native Windows and executed Linux matrices; macOS cross-compilation | Windows/Linux pass for tested lanes; native macOS pending | +| Platform behavior | Exact-candidate native Windows and executed Linux matrices; macOS cross-compilation | Windows/Linux pass for tested lanes; native macOS pending | Coverage measures statements executed by tests. It is not branch completeness and is not evidence that the executed behavior is secure. @@ -61,7 +58,7 @@ and is not evidence that the executed behavior is secure. and reachable through its analysis. A clean result cannot detect unknown flaws, design errors, or vulnerabilities outside its model. -## Pre-beta native compatibility matrix +## Beta 1 native compatibility matrix These are maintainer-run, point-in-time results, not continuous CI and not an independent audit. @@ -70,7 +67,7 @@ independent audit. | --- | --- | --- | --- | | Windows 11/amd64, NTFS | 1.25.12, 1.26.5 | Native PowerShell verifier with race; root/runtime tests, vet, trimpath build, freshness, two generation passes, process-tree cleanup, watcher boundaries, and temporary consumer compilation | Pass. Symlink-output rejection skipped because the test account lacked symlink privilege; the read-only-directory case is POSIX-only | | Ubuntu 20.04/amd64 under WSL2, native ext4 checkout | 1.25.12, 1.26.5 | Race-enabled verifier; root/runtime tests, vet, build, two generation passes, ten focused filesystem cases, five focused development-process/watcher cases, and license check | Pass. This is Linux execution under WSL2, not bare-metal or Linux/arm64 evidence | -| Linux/amd64 server containers | 1.25.12, 1.26.5 | Root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass. Container resources were capped at 1 CPU and 2 GiB; this is not Linux/arm64 evidence | +| Linux/amd64 server containers | 1.25.12, 1.26.5 | Earlier pre-beta root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass on the earlier baseline only. Container resources were capped at 1 CPU and 2 GiB; this is supplementary evidence, not an exact Beta 1 lane or Linux/arm64 evidence | | macOS | — | Cross-compilation only | Native maintainer execution pending; provisional for Beta 1 | The generated golden `basic.sando.go` was 1,399 bytes and had SHA-256 @@ -144,6 +141,9 @@ go test ./internal/compiler -run '^$' \ -fuzz '^FuzzCompileNeverPanics$' -fuzztime=20s go test ./internal/compiler -run '^$' \ -fuzz '^FuzzGoDelimiterNeverPanics$' -fuzztime=20s + +./scripts/release-check.sh --version v1.0.0-beta.1 +./scripts/verify-public-install.sh --version v1.0.0-beta.1 ``` The fuzz targets currently assert process robustness and result bounds. They do @@ -152,7 +152,7 @@ not yet prove semantic HTML safety. ## Assessment findings and remediation status The 2026-08-12 assessment identified six concrete gaps. Their status in the -named public pre-beta baseline is recorded here: +named public Beta 1 source is recorded here: | Finding | Current remediation | Executable evidence | | --- | --- | --- | @@ -163,23 +163,23 @@ named public pre-beta baseline is recorded here: | Trusted-value warnings were described more broadly than their analysis supports | Policy and threat-model copy now call them best-effort lexical audit hints rather than type or taint analysis | Documentation assertion and review | | Public copy implied a completed systematic `html/template` differential campaign | Policy and public security copy now describe fixed adversarial cases and list systematic differential work as open | Documentation assertion and review | -The clean remediated assessment source passed the race-enabled repository -verifier, sanitized-snapshot tests, both bounded fuzz-smoke targets, -compiler/runtime known-vulnerability scans, and Windows/macOS cross-compilation -on 2026-08-12. Separately, the exact public pre-beta commit passed the native -Windows and executed Linux matrices recorded above. These results still do not -become Beta 1 evidence: both sets of required checks must run on the exact -candidate after all candidate changes. Native macOS and the other gaps below -remain separate release decisions. +The exact public Beta 1 source passed the race-enabled repository verifier, +sanitized-snapshot tests, both bounded fuzz-smoke targets, compiler/runtime +known-vulnerability scans, candidate-version provenance checks, native Windows +and executed Linux matrices, and Windows/macOS cross-compilation on 2026-08-12. +Signed annotated runtime and compiler tags were then published from that commit +in that order. Fresh runtime-first installation passed through both direct Git +resolution and the public Go proxy after normal proxy propagation. Native +macOS and the other gaps below remain separate release decisions. ## Open assurance gaps -- the exact Beta 1 candidate Windows/Linux matrix and post-tag install checks - must still run; -- confidential mailbox delivery and response/recovery procedure must be tested; -- SSH tag-signing rehearsal passed, but the candidate tags still require - post-publication verification; prebuilt-artifact signing, checksums, SBOM, - reproducible provenance, and key recovery remain incomplete; +- delivery to `security@sandwichhime.com` is owner-confirmed through a + controlled domain catch-all; encrypted reporting, documented backup, and + recovery rehearsal remain incomplete; +- the signed annotated Beta tags and their common peeled commit were verified; + prebuilt-artifact signing, checksums, SBOM, reproducible provenance, and key + recovery remain incomplete; - native macOS, Linux/arm64, and Windows/arm64 execution remain outstanding; - Windows symlink rejection was not natively exercised because the test account lacked symlink privilege; diff --git a/docs/V1_RELEASE_PLAN.md b/docs/V1_RELEASE_PLAN.md index b10311f..8cd5d76 100644 --- a/docs/V1_RELEASE_PLAN.md +++ b/docs/V1_RELEASE_PLAN.md @@ -31,17 +31,14 @@ repeatable install for learners and evaluators without claiming that the final v1 compatibility, native-platform, artifact, signing, or soak gates are complete. -### Demonstrated in the pre-beta public baseline +### Demonstrated for Beta 1 -Public commit `113c95c21e57227b4675c9fda015ada59cc9e9a6` (tree -`a2aeb4dac22853cb3894e3e487b94bbeff5051e5`) passed maintainer-run Go +Public commit `b7a84054d755e42285e50298e41e47f06a8325a5` (tree +`be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run Go 1.25.12 and Go 1.26.5 matrices on native Windows/amd64, Linux/amd64 under WSL2, -and isolated Linux/amd64 server containers. The same generated golden SHA-256 -was observed across those lanes. - -That result is a pre-beta baseline only. The exact Beta 1 candidate must rerun -the required Windows/Linux matrix after all version, documentation, and source -changes and before tags are created. +with the earlier pre-beta server-container run retained only as supplementary +Linux evidence. The same generated golden SHA-256 was observed across the exact +Beta Windows and Linux lanes. Other demonstrated controls include: @@ -63,8 +60,7 @@ Other demonstrated controls include: - complete real-browser development-supervisor evidence; - deterministic prebuilt archives, checksums, SBOMs, signed binaries, and tested signing/recovery procedures; or -- clean direct and public-proxy installation of the not-yet-published Beta 1 - tags. +- native macOS installation of the published Beta 1 tags. ## Beta 1 publication lane @@ -75,13 +71,14 @@ dependency, and its interfaces may change. - [x] Define beta support, security, compatibility, and macOS-provisional language. - [x] Establish the named public pre-beta Linux/Windows baseline. -- [ ] Rerun the supported Go matrix and deterministic generation on the exact +- [x] Rerun the supported Go matrix and deterministic generation on the exact Beta 1 candidate. -- [ ] Run the candidate-version freshness, bounded fuzz, vulnerability, and +- [x] Run the candidate-version freshness, bounded fuzz, vulnerability, and license gates. -- [ ] Publish immutable `sando/v1.0.0-beta.1`, then +- [x] Publish immutable `sando/v1.0.0-beta.1`, then `v1.0.0-beta.1`, from the same reviewed public commit. -- [ ] Verify clean direct and public-proxy installs and record the result. +- [x] Verify clean runtime-first direct and public-proxy installs and record the + result. - [ ] Add native macOS maintainer evidence before RC; community reports inform that work but do not replace maintainer responsibility. diff --git a/scripts/README.md b/scripts/README.md index 442bda2..cc2f6e2 100644 --- a/scripts/README.md +++ b/scripts/README.md @@ -8,7 +8,7 @@ These scripts are intentionally understandable shell and PowerShell rather than - `verify.ps1` provides the equivalent native Windows lane; pass `-Race` to include the race detector. - `check-licenses.sh` enforces the AGPL compiler / Apache runtime boundary and prevents generated application Go from inheriting an AGPL identifier. - `release-check.sh --version vX.Y.Z` is a clean-checkout technical preflight, including exact candidate-version and generated-provenance checks. Beta publication follows the narrower prerelease gates in `RELEASE.md`; release candidates and final v1 additionally use `--public` with a human-reviewed `HIMESAN_RELEASE_EVIDENCE_DIR`. The script never tags, pushes, publishes, or deploys. -- `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes and runs the documented compiler install and runtime get from fresh direct-fetch and public-proxy caches without interactive Git credentials. +- `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes, adds the nested runtime before installing the parent compiler, and exercises fresh direct-fetch and public-proxy caches without interactive Git credentials. The canonical Linux CI and release preflight also run bounded fuzz sessions for the parser/context compiler and Go-aware delimiter scanner. Seed-corpus execution remains part of ordinary `go test`; the bounded sessions are extra evidence, not a substitute for longer scheduled fuzzing before v1. diff --git a/scripts/verify-public-install.sh b/scripts/verify-public-install.sh index 2e91fed..71e8450 100755 --- a/scripts/verify-public-install.sh +++ b/scripts/verify-public-install.sh @@ -103,6 +103,7 @@ fi scratch_dir=$(mktemp -d "${TMPDIR:-/tmp}/himesan-public-install.XXXXXXXX") cleanup() { if [[ -n "${scratch_dir:-}" && -d "$scratch_dir" ]]; then + chmod -R u+w -- "$scratch_dir" 2>/dev/null || true rm -rf -- "$scratch_dir" fi } @@ -116,7 +117,29 @@ run_install_pair() { local installed_binary installed_version go_executable_suffix mkdir -p "$mode_dir/gopath" "$mode_dir/modcache" "$mode_dir/buildcache" "$mode_dir/consumer" - printf '\n==> %s clean-cache install\n' "$mode" + printf '\n==> %s clean-cache runtime then compiler install\n' "$mode" + ( + cd "$mode_dir/consumer" + go mod init example.invalid/himesan-public-install >/dev/null + env \ + GIT_TERMINAL_PROMPT=0 \ + GIT_CONFIG_NOSYSTEM=1 \ + GIT_CONFIG_GLOBAL=/dev/null \ + GIT_ASKPASS="$false_command" \ + SSH_ASKPASS="$false_command" \ + GOPATH="$mode_dir/gopath" \ + GOMODCACHE="$mode_dir/modcache" \ + GOCACHE="$mode_dir/buildcache" \ + GOPROXY="$proxy" \ + GOPRIVATE= \ + GONOPROXY=none \ + GONOSUMDB="$no_sum_db" \ + GOSUMDB=sum.golang.org \ + GOINSECURE= \ + GOAUTH=off \ + go get "gamertan.com/sandwich-hime/sando@$version" + ) + env \ GIT_TERMINAL_PROMPT=0 \ GIT_CONFIG_NOSYSTEM=1 \ @@ -154,28 +177,6 @@ EOF printf 'error: generated provenance did not record installed compiler version %s\n' "$version" >&2 exit 1 fi - - ( - cd "$mode_dir/consumer" - go mod init example.invalid/himesan-public-install >/dev/null - env \ - GIT_TERMINAL_PROMPT=0 \ - GIT_CONFIG_NOSYSTEM=1 \ - GIT_CONFIG_GLOBAL=/dev/null \ - GIT_ASKPASS="$false_command" \ - SSH_ASKPASS="$false_command" \ - GOPATH="$mode_dir/gopath" \ - GOMODCACHE="$mode_dir/modcache" \ - GOCACHE="$mode_dir/buildcache" \ - GOPROXY="$proxy" \ - GOPRIVATE= \ - GONOPROXY=none \ - GONOSUMDB="$no_sum_db" \ - GOSUMDB=sum.golang.org \ - GOINSECURE= \ - GOAUTH=off \ - go get "gamertan.com/sandwich-hime/sando@$version" - ) } run_install_pair direct direct gamertan.com/sandwich-hime