docs: publish the v1 beta evidence

Publish the exact-candidate Windows and Linux results, signed-tag and clean-install status, provisional macOS boundary, and reliable runtime-first Beta 1 installation order. The post-publication verifier now cleans read-only module caches safely.

This commit is an exact sanitized export from the private development record. Material drafting and review were assisted by OpenAI Codex; Cole Speelman reviewed the changes and accepts human responsibility.

Signed-off-by: Cole Speelman <crspeelman@gmail.com>
This commit is contained in:
2026-08-12 15:09:32 -04:00
parent b7a84054d7
commit 532724baf7
12 changed files with 136 additions and 126 deletions
+14 -9
View File
@@ -27,24 +27,29 @@ not a production-stability promise.
- Public beta support policy for evaluation and classroom use, including a - Public beta support policy for evaluation and classroom use, including a
provisional macOS lane and a community compatibility-reporting path. provisional macOS lane and a community compatibility-reporting path.
### Pre-beta verification baseline ### Release verification
Maintainer-run Linux and native Windows matrices passed on public commit The exact public Beta 1 commit
`113c95c21e57227b4675c9fda015ada59cc9e9a6` (tree `b7a84054d755e42285e50298e41e47f06a8325a5` (tree
`a2aeb4dac22853cb3894e3e487b94bbeff5051e5`) with Go 1.25.12 and Go `be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run
1.26.5. The tested golden output had the same SHA-256 on each tested host: executed Linux and native Windows matrices with Go 1.25.12 and Go 1.26.5. The
tested golden output had the same SHA-256 on each tested host:
`63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`. `63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`.
That commit is a pre-beta baseline, not evidence for the later Beta 1 commit. The complete release preflight passed, including race tests, bounded parser
The required matrix must be rerun from the exact candidate before its tags are fuzz smoke, known-vulnerability analysis of both zero-third-party-dependency
published. Native macOS execution remains pending and is explicitly provisional modules, candidate-version provenance, and six cross-builds. The signed runtime
for this beta. and compiler tags were published in that order. Fresh direct and public-proxy
runtime-first installs passed after normal proxy propagation. Native macOS
execution remains pending and is explicitly provisional for this beta.
### Known limitations ### Known limitations
- Source syntax, generated format, CLI details, and runtime API may change - Source syntax, generated format, CLI details, and runtime API may change
before final v1. before final v1.
- Native macOS behavior has not yet been maintainer-validated. - Native macOS behavior has not yet been maintainer-validated.
- In a shared fresh Go module cache, add the nested `sando` runtime before
installing the parent compiler module at the same Beta 1 version.
- Prebuilt binary artifacts, checksums, SBOMs, reproducible archives, - Prebuilt binary artifacts, checksums, SBOMs, reproducible archives,
key-recovery rehearsal, systematic browser differential, long fuzz, key-recovery rehearsal, systematic browser differential, long fuzz,
benchmark, and final compatibility gates remain work toward the release benchmark, and final compatibility gates remain work toward the release
+1 -1
View File
@@ -1 +1 @@
{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":80,"allowlist_sha256":"e40a56b3431efdd99b3a78c38c387722de347216640383fc849569a817edf5c6","manifest_sha256":"93870a8c1e91602754de257c30249892821356ea9bf8d89e1b4502b62d769b06"} {"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":80,"allowlist_sha256":"e40a56b3431efdd99b3a78c38c387722de347216640383fc849569a817edf5c6","manifest_sha256":"1ba4d6b66c26796b5bbce118680726f9a964824f72142aea568642e25d0f33b3"}
+10 -10
View File
@@ -2,7 +2,7 @@
658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes 658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes
d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore
98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md 98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md
8bc6c7586a58bdc648c7d3df2db33fa6db6381a111da9d8fc2d5817b5e0517ad ./CHANGELOG.md b1faa7df0336b9ba68b28136fb72e9ba44185c35ba8cbec01d01c00599ea5c46 ./CHANGELOG.md
b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md
797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md 797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md
86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT 86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT
@@ -13,10 +13,10 @@ a4570d054f072d33b8f17b0c8b162a6ee0ca37d7df2b1aee7e4b728ab350a892 ./GOVERNANCE.m
47d857e49f89596bac9b09fc8ca57a668a33d01e2b51508acfc92ed321cdc27f ./LICENSES.md 47d857e49f89596bac9b09fc8ca57a668a33d01e2b51508acfc92ed321cdc27f ./LICENSES.md
b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md
6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md 6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md
dda0ffee17bc1586ac16cc9707999cde2909a116c98cd43aeab85e0d3da7b636 ./README.md e17347ac53a05bad439308f8f9a6bc10f7438d06ce75d09a7f94aadc1d96a726 ./README.md
9895823f9f7ba88ddf048c53c23ed32298b151ab049a9c4470366389d9498ff4 ./RELEASE.md 9b78254033063ec97f1c9f66aaef9503e477e1f5c3dd602bb78fd78f9e64b90b ./RELEASE.md
6d1e49dd72ba9592a3fd0562fcca1857803a3dd86dc097b36043e20f5d5cd591 ./ROADMAP.md 209decb6769646eb2f58e312fbcd9c497c26234f3d3115bae3f20493b8178584 ./ROADMAP.md
50a24995b39a957e47e0e181f8771a87141302b4d308fa8d8bfdc2e70121c2b9 ./SECURITY.md ea26e6bcdf97746627f21ba64bed16bdb7630f808215e19558ff7c7550422491 ./SECURITY.md
53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md 53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md
3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md 3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md
136a6d82db842547b342f8b0c9ffdc7c04f7c9b473b4ef6dca9dbc940cb24b54 ./cmd/himesan/main.go 136a6d82db842547b342f8b0c9ffdc7c04f7c9b473b4ef6dca9dbc940cb24b54 ./cmd/himesan/main.go
@@ -24,12 +24,12 @@ dda0ffee17bc1586ac16cc9707999cde2909a116c98cd43aeab85e0d3da7b636 ./README.md
1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md 1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md
9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md 9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md
5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md 5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md
4f7b04b3f74a2e90fc69019cad78a1287f4806ae84e7207cfdf000971702395d ./docs/COMPATIBILITY.md 796618a874a53176f7459192c3f5e0aa0c28c2027d4874d2ffa87e285d6692d0 ./docs/COMPATIBILITY.md
5f4ac209a16ab110baeaa64a40c19d9239c903e17550c3f05e1e1473ddcc33a3 ./docs/DEVELOPMENT_SERVER.md 5f4ac209a16ab110baeaa64a40c19d9239c903e17550c3f05e1e1473ddcc33a3 ./docs/DEVELOPMENT_SERVER.md
51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md 51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md
9bd43853d91b841c4879dac94dda5aafefa25bcdf4a02763445e2506fc618b03 ./docs/SECURITY_EVIDENCE.md 965a6ae57a8162c3af81f4987771e88617247f903088d210720ea2afab152cc9 ./docs/SECURITY_EVIDENCE.md
d969c7b5486ee93e54232fd69d9db06f3b4dc1bba63001596ec48545073c2680 ./docs/THREAT_MODEL.md d969c7b5486ee93e54232fd69d9db06f3b4dc1bba63001596ec48545073c2680 ./docs/THREAT_MODEL.md
82107c57043af40b9e3ec03f4ed9efddcf3bcdda1765b99ec413f835be4a46e3 ./docs/V1_RELEASE_PLAN.md 738258ba8f7e5ffea67d3f00eb70839590171971a9946a55b013ca95baf7aafb ./docs/V1_RELEASE_PLAN.md
f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod
ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go
6ef6a0f15a5aca1c8708cbf24218372e1fca9c6fead1a5a75d261faa69651af7 ./internal/compiler/backend.go 6ef6a0f15a5aca1c8708cbf24218372e1fca9c6fead1a5a75d261faa69651af7 ./internal/compiler/backend.go
@@ -72,9 +72,9 @@ ff76daee5b642ad84af31701833246d68b54d09580192312d750a7a2e893a692 ./sando/go.mod
80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go 80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go
85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go 85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go
b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go
504897b29686e0ea7adff8beb8ec91612df3ee169397309c3b6b69eb0393491b ./scripts/README.md c4a161faba46ce5b508c0788078256a520277a573a3ace0e85ae0c26b16d298b ./scripts/README.md
0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh 0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh
6c73ad46beb642836ae4d462f40e7ecc8d86a3cc194e71a5d0859dac73af0410 ./scripts/release-check.sh 6c73ad46beb642836ae4d462f40e7ecc8d86a3cc194e71a5d0859dac73af0410 ./scripts/release-check.sh
9cd43005a7d0f3659b11c5c14e4e0b9e7f675b695da185f4ee97c54edebf0dc6 ./scripts/verify-public-install.sh 78a64c7fb3a039b15a1d08b4c0b873952852287a07f670247b081e59dbb09a30 ./scripts/verify-public-install.sh
24ed3c9a1d37e46a856cbbd68e5c58ae04c6c9852902b99ed675e1f428339a9f ./scripts/verify.ps1 24ed3c9a1d37e46a856cbbd68e5c58ae04c6c9852902b99ed675e1f428339a9f ./scripts/verify.ps1
f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh
+17 -13
View File
@@ -48,26 +48,29 @@ semantic-version prerelease: source syntax, generated output, the runtime API,
and CLI behavior may change before final v1, and this beta is not recommended and CLI behavior may change before final v1, and this beta is not recommended
for production deployment. for production deployment.
Maintainer-run testing has established a pre-beta baseline on native Windows The exact Beta 1 source passed maintainer-run native Windows and executed Linux
and on Linux with Go 1.25 and Go 1.26. That matrix must pass again on the exact matrices with Go 1.25.12 and Go 1.26.5. Native macOS validation is still
Beta 1 commit before its tags are published. Native macOS validation is still
pending, so macOS support is provisional in this beta. Mac learners and Go pending, so macOS support is provisional in this beta. Mac learners and Go
developers are warmly invited to try it and share their macOS version, developers are warmly invited to try it and share their macOS version,
architecture, Go version, command, and smallest useful reproduction. Community architecture, Go version, command, and smallest useful reproduction. Community
reports broaden the evidence; maintainers remain responsible for security reports broaden the evidence; maintainers remain responsible for security
review, triage, fixes, and release decisions. review, triage, fixes, and release decisions.
Install the beta compiler: Inside an application module, add the small runtime first:
```sh
go get gamertan.com/sandwich-hime/sando@v1.0.0-beta.1
```
Then install the beta compiler:
```sh ```sh
go install gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-beta.1 go install gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-beta.1
``` ```
Add the small runtime to an application module: Keep that runtime-first order for Beta 1. It avoids a Go module-cache ambiguity
between the parent compiler module and its nested runtime when both use the
```sh same prerelease version.
go get gamertan.com/sandwich-hime/sando@v1.0.0-beta.1
```
For a reproducible one-off or classroom invocation that does not depend on the For a reproducible one-off or classroom invocation that does not depend on the
learner's `PATH`: learner's `PATH`:
@@ -76,10 +79,11 @@ learner's `PATH`:
go run gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-beta.1 --help go run gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-beta.1 --help
``` ```
The runtime is released first as `sando/v1.0.0-beta.1`; the compiler follows as The runtime was released first as `sando/v1.0.0-beta.1`; the compiler followed
`v1.0.0-beta.1`. If a newly announced version is not immediately available as `v1.0.0-beta.1`. Both signed tags, direct fetching, the public Go proxy, and
through a module proxy, retry after the proxy has discovered the immutable tag the checksum database have been verified. A newly announced future version may
or use the canonical Gitea release instructions. still need a short propagation interval before every proxy sees its immutable
tag.
For repository development: For repository development:
+12 -10
View File
@@ -68,14 +68,15 @@ Before `sando/v1.0.0-beta.1` and `v1.0.0-beta.1` are created:
generated fixtures are current under that exact binary. generated fixtures are current under that exact binary.
7. Create signed annotated tags and publish the runtime tag first, then the 7. Create signed annotated tags and publish the runtime tag first, then the
compiler tag, from the same reviewed commit. compiler tag, from the same reviewed commit.
8. Verify both documented installs from fresh `GOPROXY=direct` and public-proxy 8. Verify both documented runtime-first installs from fresh `GOPROXY=direct`
caches. Record propagation delays as delays, not test passes. and public-proxy caches. Record propagation delays as delays, not test
passes.
The passing public commit Beta 1 was published from public commit
`113c95c21e57227b4675c9fda015ada59cc9e9a6` (tree `b7a84054d755e42285e50298e41e47f06a8325a5` (tree
`a2aeb4dac22853cb3894e3e487b94bbeff5051e5`) is only the pre-beta `be9e118e38dfebed19f60403ededdadabe07d2aa`) after its exact-candidate
platform baseline. Any documentation, versioning, or code change produces a new matrix passed. Future prereleases require their own candidate evidence; this
candidate and requires the candidate matrix to run again before tagging. result cannot be relabeled for another commit.
## RC and final gates ## RC and final gates
@@ -110,9 +111,10 @@ metadata exist, run:
scripts/verify-public-install.sh --version vX.Y.Z scripts/verify-public-install.sh --version vX.Y.Z
``` ```
That check exercises the documented `go install` and `go get` commands from That check adds the nested runtime before installing the parent compiler, then
fresh direct-fetch and public-proxy caches. It is separate from the pre-tag, exercises both commands from fresh direct-fetch and public-proxy caches. The
read-only `scripts/release-check.sh`. order avoids the Go module-cache ambiguity documented for Beta 1. It is
separate from the pre-tag, read-only `scripts/release-check.sh`.
Release notes report hardware, commit, datasets, commands, `ns/op`, Release notes report hardware, commit, datasets, commands, `ns/op`,
allocations, response latency, and methodology for any performance claim. allocations, response latency, and methodology for any performance claim.
+4 -3
View File
@@ -17,11 +17,12 @@ it is not a production-stability promise.
- [x] Establish a public pre-beta Linux/Windows matrix on Go 1.25 and Go 1.26. - [x] Establish a public pre-beta Linux/Windows matrix on Go 1.25 and Go 1.26.
- [x] Document macOS as provisional and invite useful community reports while - [x] Document macOS as provisional and invite useful community reports while
retaining maintainer responsibility for security and releases. retaining maintainer responsibility for security and releases.
- [ ] Rerun all required Windows/Linux checks and deterministic generation on - [x] Rerun all required Windows/Linux checks and deterministic generation on
the exact Beta 1 candidate. the exact Beta 1 candidate.
- [ ] Publish immutable `sando/v1.0.0-beta.1`, then - [x] Publish immutable `sando/v1.0.0-beta.1`, then
`v1.0.0-beta.1`, from the reviewed public commit. `v1.0.0-beta.1`, from the reviewed public commit.
- [ ] Verify clean direct and public-proxy installs after publication. - [x] Verify clean runtime-first direct and public-proxy installs after
publication.
- [ ] Complete native macOS maintainer validation. This is an RC/final gate, - [ ] Complete native macOS maintainer validation. This is an RC/final gate,
not a Beta 1 gate. not a Beta 1 gate.
+2 -2
View File
@@ -17,7 +17,7 @@ advisories, and release decisions.
| Version | Security status | | Version | Security status |
| --- | --- | | --- | --- |
| `v1.0.0-beta.1` and `sando/v1.0.0-beta.1` | Current evaluation/classroom prerelease once published; best-effort security assessment and fixes; interfaces may change | | `v1.0.0-beta.1` and `sando/v1.0.0-beta.1` | Current published evaluation/classroom prerelease; best-effort security assessment and fixes; interfaces may change |
| Public `main` | Development source; reports welcome, but no compatibility or production-support promise | | Public `main` | Development source; reports welcome, but no compatibility or production-support promise |
| Older prereleases | Superseded when a newer prerelease or final version is published; reports are still triaged to determine affected versions | | Older prereleases | Superseded when a newer prerelease or final version is published; reports are still triaged to determine affected versions |
@@ -133,7 +133,7 @@ an independent security audit, certification, or formal verification. Coverage
percentages, passing scanners, and a clean vulnerability database result are percentages, passing scanners, and a clean vulnerability database result are
evidence of specific checks—not proof that no vulnerability exists. evidence of specific checks—not proof that no vulnerability exists.
Beta 1 publication requires signed annotated source tags, but may precede the Beta 1 uses signed annotated source tags, but precedes the
complete prebuilt-artifact and key-recovery system. Signed binaries, checksums, complete prebuilt-artifact and key-recovery system. Signed binaries, checksums,
an SBOM, reproducible archives, and complete source/build provenance are an SBOM, reproducible archives, and complete source/build provenance are
release-candidate and final-v1 gates. Their absence from a source-only beta must release-candidate and final-v1 gates. Their absence from a source-only beta must
+8 -8
View File
@@ -36,25 +36,25 @@ Beta 1 targets Go 1.25 and Go 1.26. Support is based on point-in-time,
maintainer-run release matrices, not an implication of continuous CI coverage. maintainer-run release matrices, not an implication of continuous CI coverage.
A Go support change is announced in release notes before it takes effect. A Go support change is announced in release notes before it takes effect.
The current public evidence is a **pre-beta baseline** on commit The current public evidence is the exact Beta 1 source at commit
`113c95c21e57227b4675c9fda015ada59cc9e9a6` (tree `b7a84054d755e42285e50298e41e47f06a8325a5` (tree
`a2aeb4dac22853cb3894e3e487b94bbeff5051e5`): `be9e118e38dfebed19f60403ededdadabe07d2aa`):
| Platform | Go lanes | Maintainer-run result | | Platform | Go lanes | Maintainer-run result |
| --- | --- | --- | | --- | --- | --- |
| Windows 11/amd64 on NTFS | 1.25.12, 1.26.5 | Native tests, race, vet, builds, generation, process cleanup, watcher boundaries, and temporary consumer compilation passed; privileged symlink and POSIX-only permission cases were not exercised | | Windows 11/amd64 on NTFS | 1.25.12, 1.26.5 | Native tests, race, vet, builds, generation, process cleanup, watcher boundaries, and temporary consumer compilation passed; privileged symlink and POSIX-only permission cases were not exercised |
| Linux/amd64 on WSL2 with an ext4 checkout | 1.25.12, 1.26.5 | Tests, race, vet, builds, generation, focused filesystem/development cases, and license checks passed | | Linux/amd64 on WSL2 with an ext4 checkout | 1.25.12, 1.26.5 | Tests, race, vet, builds, generation, focused filesystem/development cases, and license checks passed |
| Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | Tests, race, vet, builds, deterministic generation, and license checks passed | | Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | The earlier pre-beta baseline passed tests, race, vet, builds, deterministic generation, and license checks; this was not rerun on the exact Beta 1 commit |
| macOS | — | Native maintainer validation pending; provisional for Beta 1 | | macOS | — | Native maintainer validation pending; provisional for Beta 1 |
The golden generated file had SHA-256 The golden generated file had SHA-256
`63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f` `63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`
on every tested Windows and Linux lane. on every tested Windows and Linux lane.
Because the Beta 1 candidate contains changes after that public baseline, the The signed Beta tags and fresh direct/public-proxy installation were verified
complete Windows/Linux matrix must be rerun on the exact candidate before the after publication. For Beta 1, add the nested runtime to an application module
tags are published. The baseline does not become beta evidence merely because before installing the parent compiler at the same version; this avoids a Go
its code is nearby in history. module-cache path-selection ambiguity observed in the reverse order.
## macOS feedback ## macOS feedback
+31 -31
View File
@@ -11,23 +11,20 @@ verification, or guarantee that no vulnerability exists.
| Field | Value | | Field | Value |
| --- | --- | | --- | --- |
| Assessment date | 2026-08-12 | | Assessment date | 2026-08-12 |
| Evidence sets | Clean security self-assessment plus an exact-commit pre-beta platform baseline; neither is evidence for the later Beta 1 candidate | | Evidence sets | Clean security self-assessment plus exact-commit Beta 1 platform, release, signing, and installation checks |
| Public commit | `113c95c21e57227b4675c9fda015ada59cc9e9a6` | | Public commit | `b7a84054d755e42285e50298e41e47f06a8325a5` |
| Public tree | `a2aeb4dac22853cb3894e3e487b94bbeff5051e5` | | Public tree | `be9e118e38dfebed19f60403ededdadabe07d2aa` |
| Maintainer-run environments | Windows 11/amd64 on NTFS; Ubuntu 20.04/amd64 under WSL2 on ext4; Linux/amd64 server containers | | Maintainer-run environments | Windows 11/amd64 on NTFS; Ubuntu 20.04/amd64 under WSL2 on ext4; supplementary pre-beta Linux/amd64 server containers |
| Supported Go lanes exercised | Go 1.25.12 and Go 1.26.5 | | Supported Go lanes exercised | Go 1.25.12 and Go 1.26.5 |
| Declared minimum Go | Go 1.25 | | Declared minimum Go | Go 1.25 |
| Assessor | Project maintainer with AI-assisted code review; human responsibility retained | | Assessor | Project maintainer with AI-assisted code review; human responsibility retained |
The named platform runs used the exact public commit and tree above. Hostnames, The named Windows and WSL2 platform runs used the exact public commit and tree
network addresses, account names, private paths, private repository identities, above. The isolated server-container matrix preceded the final candidate and
and private commit mappings are intentionally absent from this public ledger. is retained only as supplementary Linux evidence. Hostnames, network addresses,
account names, private paths, private repository identities, and private commit
Beta 1 necessarily changes the tree through versioning, provenance, mappings are intentionally absent from this public ledger. Native macOS
documentation, or source fixes. Therefore this baseline cannot be relabeled as execution remains pending and is provisional for the beta.
Beta 1 evidence. The required Windows/Linux campaign must pass again on the
exact Beta 1 candidate before either tag is published. Native macOS execution
remains pending and is provisional for the beta.
## Observed security self-assessment evidence ## Observed security self-assessment evidence
@@ -52,7 +49,7 @@ baseline commit.
| URL scheme handling | ordinary/trusted URL test matrix | Pass for enumerated cases | | URL scheme handling | ordinary/trusted URL test matrix | Pass for enumerated cases |
| Filesystem boundaries | symlink, nested-module, VCS, ownership, stale-output tests | Pass for tested cases; see open findings | | Filesystem boundaries | symlink, nested-module, VCS, ownership, stale-output tests | Pass for tested cases; see open findings |
| Development proxy browser boundary | Host, Origin, Fetch Metadata, CSP, fragment and response tests | Pass for tested cases | | Development proxy browser boundary | Host, Origin, Fetch Metadata, CSP, fragment and response tests | Pass for tested cases |
| Platform behavior | Native Windows and executed Linux matrices; macOS cross-compilation | Windows/Linux pass for tested lanes; native macOS pending | | Platform behavior | Exact-candidate native Windows and executed Linux matrices; macOS cross-compilation | Windows/Linux pass for tested lanes; native macOS pending |
Coverage measures statements executed by tests. It is not branch completeness Coverage measures statements executed by tests. It is not branch completeness
and is not evidence that the executed behavior is secure. and is not evidence that the executed behavior is secure.
@@ -61,7 +58,7 @@ and is not evidence that the executed behavior is secure.
and reachable through its analysis. A clean result cannot detect unknown flaws, and reachable through its analysis. A clean result cannot detect unknown flaws,
design errors, or vulnerabilities outside its model. design errors, or vulnerabilities outside its model.
## Pre-beta native compatibility matrix ## Beta 1 native compatibility matrix
These are maintainer-run, point-in-time results, not continuous CI and not an These are maintainer-run, point-in-time results, not continuous CI and not an
independent audit. independent audit.
@@ -70,7 +67,7 @@ independent audit.
| --- | --- | --- | --- | | --- | --- | --- | --- |
| Windows 11/amd64, NTFS | 1.25.12, 1.26.5 | Native PowerShell verifier with race; root/runtime tests, vet, trimpath build, freshness, two generation passes, process-tree cleanup, watcher boundaries, and temporary consumer compilation | Pass. Symlink-output rejection skipped because the test account lacked symlink privilege; the read-only-directory case is POSIX-only | | Windows 11/amd64, NTFS | 1.25.12, 1.26.5 | Native PowerShell verifier with race; root/runtime tests, vet, trimpath build, freshness, two generation passes, process-tree cleanup, watcher boundaries, and temporary consumer compilation | Pass. Symlink-output rejection skipped because the test account lacked symlink privilege; the read-only-directory case is POSIX-only |
| Ubuntu 20.04/amd64 under WSL2, native ext4 checkout | 1.25.12, 1.26.5 | Race-enabled verifier; root/runtime tests, vet, build, two generation passes, ten focused filesystem cases, five focused development-process/watcher cases, and license check | Pass. This is Linux execution under WSL2, not bare-metal or Linux/arm64 evidence | | Ubuntu 20.04/amd64 under WSL2, native ext4 checkout | 1.25.12, 1.26.5 | Race-enabled verifier; root/runtime tests, vet, build, two generation passes, ten focused filesystem cases, five focused development-process/watcher cases, and license check | Pass. This is Linux execution under WSL2, not bare-metal or Linux/arm64 evidence |
| Linux/amd64 server containers | 1.25.12, 1.26.5 | Root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass. Container resources were capped at 1 CPU and 2 GiB; this is not Linux/arm64 evidence | | Linux/amd64 server containers | 1.25.12, 1.26.5 | Earlier pre-beta root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass on the earlier baseline only. Container resources were capped at 1 CPU and 2 GiB; this is supplementary evidence, not an exact Beta 1 lane or Linux/arm64 evidence |
| macOS | — | Cross-compilation only | Native maintainer execution pending; provisional for Beta 1 | | macOS | — | Cross-compilation only | Native maintainer execution pending; provisional for Beta 1 |
The generated golden `basic.sando.go` was 1,399 bytes and had SHA-256 The generated golden `basic.sando.go` was 1,399 bytes and had SHA-256
@@ -144,6 +141,9 @@ go test ./internal/compiler -run '^$' \
-fuzz '^FuzzCompileNeverPanics$' -fuzztime=20s -fuzz '^FuzzCompileNeverPanics$' -fuzztime=20s
go test ./internal/compiler -run '^$' \ go test ./internal/compiler -run '^$' \
-fuzz '^FuzzGoDelimiterNeverPanics$' -fuzztime=20s -fuzz '^FuzzGoDelimiterNeverPanics$' -fuzztime=20s
./scripts/release-check.sh --version v1.0.0-beta.1
./scripts/verify-public-install.sh --version v1.0.0-beta.1
``` ```
The fuzz targets currently assert process robustness and result bounds. They do The fuzz targets currently assert process robustness and result bounds. They do
@@ -152,7 +152,7 @@ not yet prove semantic HTML safety.
## Assessment findings and remediation status ## Assessment findings and remediation status
The 2026-08-12 assessment identified six concrete gaps. Their status in the The 2026-08-12 assessment identified six concrete gaps. Their status in the
named public pre-beta baseline is recorded here: named public Beta 1 source is recorded here:
| Finding | Current remediation | Executable evidence | | Finding | Current remediation | Executable evidence |
| --- | --- | --- | | --- | --- | --- |
@@ -163,23 +163,23 @@ named public pre-beta baseline is recorded here:
| Trusted-value warnings were described more broadly than their analysis supports | Policy and threat-model copy now call them best-effort lexical audit hints rather than type or taint analysis | Documentation assertion and review | | Trusted-value warnings were described more broadly than their analysis supports | Policy and threat-model copy now call them best-effort lexical audit hints rather than type or taint analysis | Documentation assertion and review |
| Public copy implied a completed systematic `html/template` differential campaign | Policy and public security copy now describe fixed adversarial cases and list systematic differential work as open | Documentation assertion and review | | Public copy implied a completed systematic `html/template` differential campaign | Policy and public security copy now describe fixed adversarial cases and list systematic differential work as open | Documentation assertion and review |
The clean remediated assessment source passed the race-enabled repository The exact public Beta 1 source passed the race-enabled repository verifier,
verifier, sanitized-snapshot tests, both bounded fuzz-smoke targets, sanitized-snapshot tests, both bounded fuzz-smoke targets, compiler/runtime
compiler/runtime known-vulnerability scans, and Windows/macOS cross-compilation known-vulnerability scans, candidate-version provenance checks, native Windows
on 2026-08-12. Separately, the exact public pre-beta commit passed the native and executed Linux matrices, and Windows/macOS cross-compilation on 2026-08-12.
Windows and executed Linux matrices recorded above. These results still do not Signed annotated runtime and compiler tags were then published from that commit
become Beta 1 evidence: both sets of required checks must run on the exact in that order. Fresh runtime-first installation passed through both direct Git
candidate after all candidate changes. Native macOS and the other gaps below resolution and the public Go proxy after normal proxy propagation. Native
remain separate release decisions. macOS and the other gaps below remain separate release decisions.
## Open assurance gaps ## Open assurance gaps
- the exact Beta 1 candidate Windows/Linux matrix and post-tag install checks - delivery to `security@sandwichhime.com` is owner-confirmed through a
must still run; controlled domain catch-all; encrypted reporting, documented backup, and
- confidential mailbox delivery and response/recovery procedure must be tested; recovery rehearsal remain incomplete;
- SSH tag-signing rehearsal passed, but the candidate tags still require - the signed annotated Beta tags and their common peeled commit were verified;
post-publication verification; prebuilt-artifact signing, checksums, SBOM, prebuilt-artifact signing, checksums, SBOM, reproducible provenance, and key
reproducible provenance, and key recovery remain incomplete; recovery remain incomplete;
- native macOS, Linux/arm64, and Windows/arm64 execution remain outstanding; - native macOS, Linux/arm64, and Windows/arm64 execution remain outstanding;
- Windows symlink rejection was not natively exercised because the test account - Windows symlink rejection was not natively exercised because the test account
lacked symlink privilege; lacked symlink privilege;
+12 -15
View File
@@ -31,17 +31,14 @@ repeatable install for learners and evaluators without claiming that the final
v1 compatibility, native-platform, artifact, signing, or soak gates are v1 compatibility, native-platform, artifact, signing, or soak gates are
complete. complete.
### Demonstrated in the pre-beta public baseline ### Demonstrated for Beta 1
Public commit `113c95c21e57227b4675c9fda015ada59cc9e9a6` (tree Public commit `b7a84054d755e42285e50298e41e47f06a8325a5` (tree
`a2aeb4dac22853cb3894e3e487b94bbeff5051e5`) passed maintainer-run Go `be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run Go
1.25.12 and Go 1.26.5 matrices on native Windows/amd64, Linux/amd64 under WSL2, 1.25.12 and Go 1.26.5 matrices on native Windows/amd64, Linux/amd64 under WSL2,
and isolated Linux/amd64 server containers. The same generated golden SHA-256 with the earlier pre-beta server-container run retained only as supplementary
was observed across those lanes. Linux evidence. The same generated golden SHA-256 was observed across the exact
Beta Windows and Linux lanes.
That result is a pre-beta baseline only. The exact Beta 1 candidate must rerun
the required Windows/Linux matrix after all version, documentation, and source
changes and before tags are created.
Other demonstrated controls include: Other demonstrated controls include:
@@ -63,8 +60,7 @@ Other demonstrated controls include:
- complete real-browser development-supervisor evidence; - complete real-browser development-supervisor evidence;
- deterministic prebuilt archives, checksums, SBOMs, signed binaries, and - deterministic prebuilt archives, checksums, SBOMs, signed binaries, and
tested signing/recovery procedures; or tested signing/recovery procedures; or
- clean direct and public-proxy installation of the not-yet-published Beta 1 - native macOS installation of the published Beta 1 tags.
tags.
## Beta 1 publication lane ## Beta 1 publication lane
@@ -75,13 +71,14 @@ dependency, and its interfaces may change.
- [x] Define beta support, security, compatibility, and macOS-provisional - [x] Define beta support, security, compatibility, and macOS-provisional
language. language.
- [x] Establish the named public pre-beta Linux/Windows baseline. - [x] Establish the named public pre-beta Linux/Windows baseline.
- [ ] Rerun the supported Go matrix and deterministic generation on the exact - [x] Rerun the supported Go matrix and deterministic generation on the exact
Beta 1 candidate. Beta 1 candidate.
- [ ] Run the candidate-version freshness, bounded fuzz, vulnerability, and - [x] Run the candidate-version freshness, bounded fuzz, vulnerability, and
license gates. license gates.
- [ ] Publish immutable `sando/v1.0.0-beta.1`, then - [x] Publish immutable `sando/v1.0.0-beta.1`, then
`v1.0.0-beta.1`, from the same reviewed public commit. `v1.0.0-beta.1`, from the same reviewed public commit.
- [ ] Verify clean direct and public-proxy installs and record the result. - [x] Verify clean runtime-first direct and public-proxy installs and record the
result.
- [ ] Add native macOS maintainer evidence before RC; community reports inform - [ ] Add native macOS maintainer evidence before RC; community reports inform
that work but do not replace maintainer responsibility. that work but do not replace maintainer responsibility.
+1 -1
View File
@@ -8,7 +8,7 @@ These scripts are intentionally understandable shell and PowerShell rather than
- `verify.ps1` provides the equivalent native Windows lane; pass `-Race` to include the race detector. - `verify.ps1` provides the equivalent native Windows lane; pass `-Race` to include the race detector.
- `check-licenses.sh` enforces the AGPL compiler / Apache runtime boundary and prevents generated application Go from inheriting an AGPL identifier. - `check-licenses.sh` enforces the AGPL compiler / Apache runtime boundary and prevents generated application Go from inheriting an AGPL identifier.
- `release-check.sh --version vX.Y.Z` is a clean-checkout technical preflight, including exact candidate-version and generated-provenance checks. Beta publication follows the narrower prerelease gates in `RELEASE.md`; release candidates and final v1 additionally use `--public` with a human-reviewed `HIMESAN_RELEASE_EVIDENCE_DIR`. The script never tags, pushes, publishes, or deploys. - `release-check.sh --version vX.Y.Z` is a clean-checkout technical preflight, including exact candidate-version and generated-provenance checks. Beta publication follows the narrower prerelease gates in `RELEASE.md`; release candidates and final v1 additionally use `--public` with a human-reviewed `HIMESAN_RELEASE_EVIDENCE_DIR`. The script never tags, pushes, publishes, or deploys.
- `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes and runs the documented compiler install and runtime get from fresh direct-fetch and public-proxy caches without interactive Git credentials. - `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes, adds the nested runtime before installing the parent compiler, and exercises fresh direct-fetch and public-proxy caches without interactive Git credentials.
The canonical Linux CI and release preflight also run bounded fuzz sessions for the parser/context compiler and Go-aware delimiter scanner. Seed-corpus execution remains part of ordinary `go test`; the bounded sessions are extra evidence, not a substitute for longer scheduled fuzzing before v1. The canonical Linux CI and release preflight also run bounded fuzz sessions for the parser/context compiler and Go-aware delimiter scanner. Seed-corpus execution remains part of ordinary `go test`; the bounded sessions are extra evidence, not a substitute for longer scheduled fuzzing before v1.
+24 -23
View File
@@ -103,6 +103,7 @@ fi
scratch_dir=$(mktemp -d "${TMPDIR:-/tmp}/himesan-public-install.XXXXXXXX") scratch_dir=$(mktemp -d "${TMPDIR:-/tmp}/himesan-public-install.XXXXXXXX")
cleanup() { cleanup() {
if [[ -n "${scratch_dir:-}" && -d "$scratch_dir" ]]; then if [[ -n "${scratch_dir:-}" && -d "$scratch_dir" ]]; then
chmod -R u+w -- "$scratch_dir" 2>/dev/null || true
rm -rf -- "$scratch_dir" rm -rf -- "$scratch_dir"
fi fi
} }
@@ -116,7 +117,29 @@ run_install_pair() {
local installed_binary installed_version go_executable_suffix local installed_binary installed_version go_executable_suffix
mkdir -p "$mode_dir/gopath" "$mode_dir/modcache" "$mode_dir/buildcache" "$mode_dir/consumer" mkdir -p "$mode_dir/gopath" "$mode_dir/modcache" "$mode_dir/buildcache" "$mode_dir/consumer"
printf '\n==> %s clean-cache install\n' "$mode" printf '\n==> %s clean-cache runtime then compiler install\n' "$mode"
(
cd "$mode_dir/consumer"
go mod init example.invalid/himesan-public-install >/dev/null
env \
GIT_TERMINAL_PROMPT=0 \
GIT_CONFIG_NOSYSTEM=1 \
GIT_CONFIG_GLOBAL=/dev/null \
GIT_ASKPASS="$false_command" \
SSH_ASKPASS="$false_command" \
GOPATH="$mode_dir/gopath" \
GOMODCACHE="$mode_dir/modcache" \
GOCACHE="$mode_dir/buildcache" \
GOPROXY="$proxy" \
GOPRIVATE= \
GONOPROXY=none \
GONOSUMDB="$no_sum_db" \
GOSUMDB=sum.golang.org \
GOINSECURE= \
GOAUTH=off \
go get "gamertan.com/sandwich-hime/sando@$version"
)
env \ env \
GIT_TERMINAL_PROMPT=0 \ GIT_TERMINAL_PROMPT=0 \
GIT_CONFIG_NOSYSTEM=1 \ GIT_CONFIG_NOSYSTEM=1 \
@@ -154,28 +177,6 @@ EOF
printf 'error: generated provenance did not record installed compiler version %s\n' "$version" >&2 printf 'error: generated provenance did not record installed compiler version %s\n' "$version" >&2
exit 1 exit 1
fi fi
(
cd "$mode_dir/consumer"
go mod init example.invalid/himesan-public-install >/dev/null
env \
GIT_TERMINAL_PROMPT=0 \
GIT_CONFIG_NOSYSTEM=1 \
GIT_CONFIG_GLOBAL=/dev/null \
GIT_ASKPASS="$false_command" \
SSH_ASKPASS="$false_command" \
GOPATH="$mode_dir/gopath" \
GOMODCACHE="$mode_dir/modcache" \
GOCACHE="$mode_dir/buildcache" \
GOPROXY="$proxy" \
GOPRIVATE= \
GONOPROXY=none \
GONOSUMDB="$no_sum_db" \
GOSUMDB=sum.golang.org \
GOINSECURE= \
GOAUTH=off \
go get "gamertan.com/sandwich-hime/sando@$version"
)
} }
run_install_pair direct direct gamertan.com/sandwich-hime run_install_pair direct direct gamertan.com/sandwich-hime