diff --git a/CHANGELOG.md b/CHANGELOG.md index 95be382..09f4620 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,13 +13,14 @@ Sandwich Hime follows semantic versioning after v1. Compiler and nested runtime - Read-only stale-output checking and structured diagnostics. - Independent Apache-2.0 `sando` component/runtime ABI. - Loopback-only last-good development supervisor with SSE reload and diagnostic overlay. -- Synthetic EQL-shaped proof fixture and production pilot plan. +- Compiler-owned deterministic golden fixture and standalone release gates. - Multi-license, security, governance, trademark, AI contribution, and release policies. ### Removed - Unpublished `.go.hime` syntax and 2025 generated API. - Injected helper directories, nested demo modules, Go plugins, and manually repaired generated output. +- Repository-bundled application examples and deployment-specific evidence. - Placeholder novelty commands that did not perform project work. Private prototype history is intentionally outside the sanitized public repository. The public changelog begins with the pre-1.0 source preview. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index d1eefb0..5a717e4 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -2,7 +2,11 @@ # Contributing -The canonical public project and only contribution venue is the Gamertan Gitea repository. Repository maintainers may temporarily disable issue or patch intake during the pre-1.0 preview; do not route around a closed intake channel by sending unsolicited private patches. +The canonical public project and only contribution venue is the +[founder-controlled Gitea repository](https://gitea.speelman.ca/gamertan/sandwich-hime). +Repository maintainers may temporarily disable issue or patch intake during the +pre-1.0 preview; do not route around a closed intake channel by sending +unsolicited private patches. Public pre-1.0 contributions use Developer Certificate of Origin 1.1 sign-off. The proposed `CLA.md` is an inactive draft, is not a condition of contribution, and creates no contributor or project obligations. If a contribution agreement is ever activated after legal review, the project will announce its prospective terms rather than silently applying the draft. @@ -13,10 +17,10 @@ go test ./... go test -race ./... go vet ./... (cd sando && go test -race ./... && go vet ./...) -go run ./cmd/himesan check ./examples/eql-shaped +./scripts/check-licenses.sh ``` -Changes require focused tests, stable diagnostics, formatted generated goldens when applicable, documentation for public behavior, and a signed-off commit (`git commit -s`). The sign-off certifies the [DCO](DCO.txt); it is not a copyright assignment or acceptance of the inactive CLA. Do not commit an EQL database, production data, secrets, build candidates, or developer cache files. +Changes require focused tests, stable diagnostics, formatted generated goldens when applicable, documentation for public behavior, and a signed-off commit (`git commit -s`). The sign-off certifies the [DCO](DCO.txt); it is not a copyright assignment or acceptance of the inactive CLA. Do not commit production data, private application fixtures, secrets, build candidates, or developer cache files. The project requires no copyright assignment. Ownership remains determined by applicable law and any employer or other agreement. Contributors submit each file under the license identified for that repository area, and the DCO records their certification that they have the right to do so. Material AI assistance must follow [AI_CONTRIBUTIONS.md](AI_CONTRIBUTIONS.md). Review considers provenance, safety, maintenance cost, compatibility, and fit—not just whether code passes tests. diff --git a/LICENSES.md b/LICENSES.md index ba31f8d..1d470d4 100644 --- a/LICENSES.md +++ b/LICENSES.md @@ -7,10 +7,9 @@ Sandwich Hime deliberately separates the development tool from application runti | Path or material | License | | --- | --- | -| Project-authored files in the repository root, `cmd/**`, `internal/**`, `docs/**`, `scripts/**`, and `site/**`, except the legal texts listed below | AGPL-3.0-only | +| Project-authored files in the repository root, `cmd/**`, `internal/**`, `docs/**`, and `scripts/**`, except the legal texts listed below | AGPL-3.0-only | | Nested `sando/**` runtime module, except its verbatim license text | Apache-2.0 | -| Copyable `examples/**`, except their generated-file treatment described below | 0BSD | -| `LICENSE`, `sando/LICENSE`, example `LICENSE` files, and `DCO.txt` | Their own stated copying terms and notices | +| `LICENSE`, `sando/LICENSE`, and `DCO.txt` | Their own stated copying terms and notices | | User-authored `.sando` templates | Chosen by their author, subject to rights in their inputs | | Generated application `.sando.go` files | Chosen by the template/application author, subject to rights in their inputs and dependencies | @@ -18,13 +17,19 @@ Sandwich Hime claims no copyright in a user's template merely because the compil The AGPL compiler is a separately installed development process. The Apache runtime must never import an AGPL package. Importing the Apache runtime or using generated output does not, by itself, incorporate the compiler into an application. Redistribution of the runtime remains subject to Apache-2.0 and any other applicable third-party obligations. -`COPYRIGHT` identifies Cole Speelman's original project work without claiming contributor-owned work. The nested runtime carries its own `sando/COPYRIGHT`, and the example identifies its original author in `examples/eql-shaped/LICENSE`. The project requires no copyright assignment; ownership of contributions remains determined by applicable law and existing agreements. +The `.sando` source and committed `.sando.go` output under +`internal/compiler/testdata/golden/**` are non-copyable compiler test fixtures +covered by the AGPL `internal/**` map above. The generated fixture intentionally +has no inline SPDX header because that absence is one of the generator's tested +application-output properties. + +`COPYRIGHT` identifies Cole Speelman's original project work without claiming contributor-owned work. The nested runtime carries its own `sando/COPYRIGHT`. The project requires no copyright assignment; ownership of contributions remains determined by applicable law and existing agreements. A compiler contribution that adds text intended to be copied into generated output must record the `Himesan-Output-Permission: v1.0` grant required by [CONTRIBUTING.md](CONTRIBUTING.md). Without that grant, the contribution must be designed so its contributor-owned text is not emitted. DCO sign-off alone does not grant the additional output permission. Official flags, mascots, and badges are not covered merely because they use a project mark. Each published asset must identify its copyright holder and reuse license. -SPDX identifiers state the applicable license for comment-capable source and documentation. Directory-level maps cover generated files and formats such as JSON that cannot safely carry comments. Full license texts are at `LICENSE` and `sando/LICENSE`; examples carry their own `LICENSE` and `LICENSES.md`. License texts and the verbatim `DCO.txt` retain their own notices and are not relicensed as project documentation. +SPDX identifiers state the applicable license for comment-capable source and documentation. Directory-level maps cover generated files and formats such as JSON that cannot safely carry comments. Full license texts are at `LICENSE` and `sando/LICENSE`. Copyable examples are maintained in separate repositories and must declare their own licenses; official copyable examples are intended to use 0BSD. License texts and the verbatim `DCO.txt` retain their own notices and are not relicensed as project documentation. The snapshot exporter's `PUBLIC-SNAPSHOT.json` and `PUBLIC-SNAPSHOT.sha256` are generated factual provenance records and intentionally carry no inline SPDX comment. They do not change the license of any listed file. diff --git a/PUBLIC-SNAPSHOT.json b/PUBLIC-SNAPSHOT.json index d3a8945..0832bab 100644 --- a/PUBLIC-SNAPSHOT.json +++ b/PUBLIC-SNAPSHOT.json @@ -1 +1 @@ -{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":98,"allowlist_sha256":"91213f72ddef67aaed7764f08f89fd13281bb79855f3680e1ec0d05cda0e133d","manifest_sha256":"e2eec9fed86828dff900a09f39a05021c48f295bf87a1a9b2896d673886c9a69"} +{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":77,"allowlist_sha256":"db978285858ba5a1fefeb732d716338d8c652c5fc583f465d08f80b9ec74f0a9","manifest_sha256":"6bc38ff6e8ee243f840dbd768769f5be718f5fd01ba26855038fa15c5e518cc9"} diff --git a/PUBLIC-SNAPSHOT.sha256 b/PUBLIC-SNAPSHOT.sha256 index 0b2360b..ee7fb0c 100644 --- a/PUBLIC-SNAPSHOT.sha256 +++ b/PUBLIC-SNAPSHOT.sha256 @@ -2,53 +2,35 @@ 658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore 98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md -cf2e75a6e087570064dc3d8d8ed313676c4e8df1d422bf483d33d81751174bdc ./CHANGELOG.md +7f4414fed21e9578b8d1a0d109ba807cb79d28a9290d58df49cc75145d9d1068 ./CHANGELOG.md b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md -af0a256657e192641b3d7cee24ece36a76287baf225f2a045da16327214ac7ec ./CONTRIBUTING.md +2d98826969cd492cc4dd10c595be21a608def5aacbec40ea5e25f1c3a617d8e6 ./CONTRIBUTING.md 86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT f7ac75b443f4ca16b503241344b41aeff9503b0c30bedc2b119551d83cb0fa90 ./DCO.txt 73cb1b092a40c56e522c5a0ebddf2b44f347cdb57bf6994cdb305d0e5697b55e ./GENERATED_CODE.md 048f96acecd3af84d6abc4f8c38108dff2171445417e5132318a1d18de4279fe ./GOVERNANCE.md 0d96a4ff68ad6d4b6f1f30f713b18d5184912ba8dd389f86aa7710db079abcb0 ./LICENSE -1b398f6e2679a4c1d6c5a03468f66b86be34e82ed40e3a029935c74742502e7a ./LICENSES.md +6587e439cb3c39dce9aaa5b51facdbd78c0e86c24e9e3fb9537b944435a74410 ./LICENSES.md b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md 6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md -88150b7ae8759b62829f3a0ba2b03b1c44abc2f688349d5b3ad39ebf654a29d4 ./README.md -6007b80cd80f8f238a1e77de6417aa0c69c159dce6f5a5bd085ef87b8865f5c9 ./RELEASE.md -f5fe4d5bf5f8b72ad974060faf458ad26bb4b2c05c2bd9539533247b7462f76b ./ROADMAP.md +531b3c183892c71974e25f790e8570ba72519f9299aab4031d23b62952a7682c ./README.md +00ac24b5bc5cd2b62f6176f85d4be29087c59c17f4f670edacf408d56ccc7f23 ./RELEASE.md +370c948b267527fdc2309c808b99089da33ac81346043dd54692ebb0843f6c0a ./ROADMAP.md 2c86f5b983dfeb97a02d46850fa42e18cab1ed23201822aa3c344b9d2e1b0c3f ./SECURITY.md 53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md 842beff8afa72d120fcad0ac73afb2049d580ff3000975f3b1786c4ade6a14d4 ./TRADEMARKS.md 136a6d82db842547b342f8b0c9ffdc7c04f7c9b473b4ef6dca9dbc940cb24b54 ./cmd/himesan/main.go 3011a435aaeb572d34e2d2b582865fd63268c92a9ae3f0ae1a56d1a59d83cd43 ./cmd/himesan/main_test.go 1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md -318ffcf2463036cd533b1c694f1f4840ef4b0c7c15bc049ec714bbcf4850ba15 ./docs/BENCHMARKS.md +9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md 5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md 35f5b4b7d195a7b5c071d4665505afef189c7b386d4e3079e9ce8a96ace07f3a ./docs/COMPATIBILITY.md e4021b554ebc479954321586012add57a5fbfb58a1f7fce001d5638880912fc6 ./docs/DEVELOPMENT_SERVER.md 51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md f1a8e78c5aa521324ad2fcb386512158d0c0f9956e97f9a1bc8f97aa5d5e9844 ./docs/THREAT_MODEL.md -7e2406acc98391ec126b13d512c00b930bbc2c19f4d5b0fe52286ae41bfbc92d ./examples/eql-shaped/LICENSE -eaf381627e6020d7b87b3058ee9c2882bcca5280a8bd409547ecc955a33346db ./examples/eql-shaped/LICENSES.md -78c58c00b93f8029cee67d8facdc81a30cc69feb7683952d1e72b54086485eb0 ./examples/eql-shaped/README.md -2decbbebb78da922d39d0b74ad8358601526c1d36494c857d66d69116403b7ca ./examples/eql-shaped/cmd/example/main.go -385bf9bd6a301723d123c2a52667d320889c47495f018fe0e7daa520c9fa89b0 ./examples/eql-shaped/go.mod -6b53c55daf538b25fba2a60be9887fce086b8635a38120ab3f5bf6e9fcb67867 ./examples/eql-shaped/himesan.json -2c0063ed8724520f146d6717bb7d828ce69be17b41cbfb8f4866664ba09a58a8 ./examples/eql-shaped/views/badge.sando -6befc3b1bd216bb41c7da96e0e2f1c851f5531d2c6ac800f3d06b11de01c2878 ./examples/eql-shaped/views/badge.sando.go -c5b402971618747c906c84508d5af9fd00aa33391b9b59f093b001a3cb0b2164 ./examples/eql-shaped/views/browse_results.sando -065a88f19de5ba15fb7f9d2104e2a74fe2830f95b16c432e27e40f8aba000df9 ./examples/eql-shaped/views/browse_results.sando.go -696c391538cdc50c5ab1abea23b561fa354e56eaf73b7ad6aabe130389715a8c ./examples/eql-shaped/views/home.sando -cdfe566844319accf7a9eaae4b5b43ea32b7a0cb3d4fec2dad086d98fb3e9d0b ./examples/eql-shaped/views/home.sando.go -c9a8102588cb94f946a36414291d12cb681e605acc93c2b5dc8d74fd33ae5603 ./examples/eql-shaped/views/layout.sando -fea981d626bd696068b2384707a217527ad5e24e909d2358cc95444145c424fd ./examples/eql-shaped/views/layout.sando.go -120fd733237ef1f15ce60b6ea27c21ce509f6ddc1a9727a9375bf2bb22b3629b ./examples/eql-shaped/views/model.go -a8e647d7a9cff4804f97e2175c760cf04be6580a85a5eb946b733b46111b2e06 ./examples/eql-shaped/views/render_test.go -8d59b45799d0ed2e9e6997f286315f2cb794ea660940978ec39efa3b9a3b94ab ./examples/eql-shaped/views/security_probe.sando -9d5144c39442e29aded227828099cb4b1a32a69112559f8682b43fa04cfaae65 ./examples/eql-shaped/views/security_probe.sando.go f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod 07d161772e9c6eec0dcc12179286e5c686dcabdc4e56a7cb8d112f640b072563 ./internal/compiler/backend.go -0cb82706496f80e2a852917c047fb1f29138144c96323a23ba2565055aadcf03 ./internal/compiler/compiler_test.go +28123757d27298dd81cf13ebd9242b24556734a35e36c2ac731f2a8475d70d28 ./internal/compiler/compiler_test.go d99ba263bf501ca81ed38ba88216c063d2fc22f4b45a3f28d5105957f449c4de ./internal/compiler/context.go b2a96ef1ad572ad9cd0e9247328ca261de6f9f3689da41e3f3e111d405a6dee6 ./internal/compiler/diagnostic.go 42ccf512381e130bf593b065dccd7697560fb00240818efde6321c9095f6b4a6 ./internal/compiler/discover.go @@ -59,6 +41,8 @@ eefb05a35bd07660a293c8af97949cd6f69a22709728f3fe2cc9132b863b7d5a ./internal/com d7d8181455d5f37ef9bcc6bdbf86e0630f20e8a5b3b81688d12742687b434c99 ./internal/compiler/parse.go 80cf170514a3b955d24440cb086d34e19f3a305510e3c5db95cb897be91f922a ./internal/compiler/replace_unix.go 0fff1c67447bf5353ed1df6e7dfc4b14581b67adc1bf02f7a4a7c1f2680c392f ./internal/compiler/replace_windows.go +f4ba01010ed5f5ba1e979702d82e95312bc0a4b13cc205c098926839be4ecb73 ./internal/compiler/testdata/golden/basic.sando +b190a6a8aed288378ea13d12ec06bac68890c473c03c60016f7fa7534f142008 ./internal/compiler/testdata/golden/basic.sando.go eafbe9f7d8abb8fa792ec9e01f56655f9ec9d67279ffaac66d6035f9b2bfc404 ./internal/devserver/config.go 99807040a870dd38ad1e04ae179243316778f94a41feb5d2c3076d463f52f9fe ./internal/devserver/config_test.go eddac51aecaac99bd11cfcf98f8a47cec5d51672efedad75d6f2a862c5d57fc1 ./internal/devserver/events.go @@ -85,14 +69,9 @@ ff76daee5b642ad84af31701833246d68b54d09580192312d750a7a2e893a692 ./sando/go.mod 80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go 85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go -2d92e1578d8907ab434f1924f698b586f47d6c9bc6fab989639a5332fd235163 ./scripts/README.md -032832440431a532771054bcbfb6c46944ead61bfdb38ca11a049aae14459bc3 ./scripts/check-licenses.sh -e35895423494018d5e380c447a8fb9bd5410af82a4a12f9fbaae391c286dd32a ./scripts/check-site.sh -d53d93df7e355ec45e6540703c6098c3fb49a610cb35600c5d525afa0f0d48cb ./scripts/release-check.sh -be79b6bd1d18ce53a1b4cf301f7c4fa41342728d0a6333a766171cfc586a65d5 ./scripts/verify-public-install.sh -b52ff6d1e0db9c4a72a587fc063d8022c51a439158679029c8df613b51905e51 ./scripts/verify.ps1 -5163a360b212de5abadeaa48db415e6f605e8b2a7f2fd2dc9ab7c1da19cec079 ./scripts/verify.sh -7750a055be12b18c826d033f266a615bc1acdbddcfe5193f70521f7270a3e333 ./site/README.md -1b28cf572543d61f89e7636f74b94fe96916c0dc80847831a9f42b57bebb83cb ./site/assets/site.css -ecb00ac7fac0e161a3e4629c17209ddfaf0fbb8c78fd2615c2a7372808ae7cf7 ./site/index.html -63cf8fc6f059c6a1164a70e9fd35564ff107282e01030d997f4e3e1e3dc0fdda ./site/sando/index.html +2655a3f62772f7b3ef694aea2d03bd99e157d2449c232c7439c258ec36367fb1 ./scripts/README.md +0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh +502da1760bc87f260d474d81fe8f015a6e198f8d1ebf96db6b3f460ce4ef3b02 ./scripts/release-check.sh +6be2fc6b8c3e0a7dd85437fa4089e75b772baa7556675081e6956a1b9f207fb4 ./scripts/verify-public-install.sh +24ed3c9a1d37e46a856cbbd68e5c58ae04c6c9852902b99ed675e1f428339a9f ./scripts/verify.ps1 +f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh diff --git a/README.md b/README.md index c36a682..8f670f7 100644 --- a/README.md +++ b/README.md @@ -36,22 +36,18 @@ request object, or production server. ## Status -This repository is an unsupported public pre-1.0 source preview, not a supported v1 release. EQL Wiki remains the proof-of-production proving ground, and v1 is gated on security testing, cross-platform determinism, and a 14-day production soak with no renderer, security, or accessibility regression. - -[sandwichhime.com](https://sandwichhime.com/) is the running self-hosted proof: -its pages begin as `.sando`, compile into ordinary Go, and ship in an ordinary -Go service whose production binary links only the `sando` runtime—not this -compiler. +This repository is an unsupported public pre-1.0 source preview, not a +supported v1 release. V1 is gated only by repository-owned compiler, runtime, +security, compatibility, and release checks. Application-specific deployments, +examples, and case studies live in their own repositories and are not imported +as release evidence here. For repository development: ```sh go install ./cmd/himesan -himesan generate ./examples/eql-shaped -himesan check ./examples/eql-shaped -go test ./... -(cd sando && go test ./...) -(cd examples/eql-shaped && himesan dev --config himesan.json) +./scripts/verify.sh +./scripts/check-licenses.sh ``` The portable path is `generate`, `check`, and the project's normal Go tools. @@ -123,5 +119,7 @@ participation does not confer ownership of the identity or project. The fuller origin, Japanese craft inspirations, family dedication, human-art commitment, and stewardship boundary live on the -[project site](https://sandwichhime.com/docs/project/). Performance claims will -follow published measurements, never precede them. +[project site](https://sandwichhime.com/docs/project/). Tutorials and copyable +applications are maintained separately from this compiler repository. +Performance claims will follow repository-owned measurements, never precede +them. diff --git a/RELEASE.md b/RELEASE.md index c3beab8..ec9d867 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -6,11 +6,23 @@ Sandwich Hime uses separate root and runtime version lines. Compiler tags are `v The public pre-1.0 source snapshot is not a supported release and does not imply that the v1 gates below have passed. -No v1.0.0 release occurs until every gate in this repository is evidenced, including cross-platform deterministic generation, temporary-module compilation, fuzz/adversarial suites, race/vet/vulnerability/license checks on the latest two supported Go lines, development-supervisor failure tests, an EQL differential pilot, and a completed 14-day production soak without Hime render failures or security/accessibility regression. +No v1.0.0 release occurs until every gate in this repository is evidenced, +including cross-platform deterministic generation, temporary-module +compilation, fuzz/adversarial suites, race/vet/vulnerability/license checks on +the latest two supported Go lines, development-supervisor failure tests, and +reproducible repository-owned benchmark and security results. A deployment, +example, or case study in another repository is neither imported nor required +as release evidence. Release candidates require a clean canonical checkout, reviewed changelog, compatible vanity-import metadata, reproducible binaries, signed annotated tags, checksums, SBOMs, vulnerability results, and verification on Linux, macOS, and Windows. The runtime is tagged and published independently before the compiler that references its ABI. -Gitea is the only canonical public forge. Public source is exported into a separate, sanitized Gitea repository with fresh history; private development history and the private-to-public commit mapping are not published. Release binaries and provenance are built from the reviewed public commit. Publishing documentation, binaries, runtime tag, EQL mark, and case study is one coordinated v1 launch step. +Gitea is the only canonical public forge. Public source is exported into a +separate, sanitized Gitea repository with fresh history; private development +history and the private-to-public commit mapping are not published. Release +binaries and provenance are built from the reviewed public commit. Compiler +documentation, binaries, checksums, SBOMs, and the independently versioned +runtime tag form the coordinated v1 release. Example applications and product +sites keep their own history, deployment, and evidence. The hosting configuration must answer exact package discovery requests, not only module-root pages. In particular, @@ -22,3 +34,8 @@ fresh direct-fetch and public-proxy caches. This post-publication check is separate from the pre-tag, read-only `scripts/release-check.sh`. Release notes report hardware, commit, datasets, commands, `ns/op`, allocations, response latency, and methodology for performance claims. “Fastest” or equivalent language is prohibited without durable, reproducible evidence. + +Production applications compile and deploy their committed `.sando.go` files +with the Apache-2.0 `sando` runtime. They do not need the AGPL compiler or the +local development supervisor. Release checks verify that boundary without +executing or inspecting an unrelated application repository. diff --git a/ROADMAP.md b/ROADMAP.md index ed8261e..faf78e5 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -6,7 +6,7 @@ Unchecked items are release blockers, not aspirational marketing. ## Compiler and runtime -- [ ] Deterministic golden output repeated across Linux, macOS, and Windows. +- [ ] Compiler-owned deterministic golden output repeated across Linux, macOS, and Windows. - [ ] Temporary consumer modules compile using committed Go and only the Apache runtime. - [ ] Parser, delimiter, context, path, and source-map fuzz targets survive the release campaign. - [ ] Adversarial escaping and filesystem cases are evidenced. @@ -20,19 +20,18 @@ Unchecked items are release blockers, not aspirational marketing. - [ ] CSP hash injection, fragment/API/download exclusion, and cache disabling pass. - [ ] Replaced and interrupted child processes leave no descendants on supported systems. -## EQL Wiki proof +## Repository-owned release evidence -- [ ] Separate `codex/himesan-pilot` worktree created after compiler gates. -- [ ] Shared layout/home, browse fragment, and item page reach differential parity. -- [ ] Accessibility, CSP, links/forms, malicious values, status, caching, and fragments pass. -- [ ] Blue/green renderer flag and slot-switch rollback verified. -- [ ] Fourteen continuous production days complete with zero Hime renderer failure or security/accessibility regression. -- [ ] Honest before/after case study and reproducible benchmark report approved. +- [ ] Contextual escaping is differentially tested against Go's documented `html/template` safety baseline. +- [ ] Repository-owned synthetic benchmark cases and methodology are reproducible from a clean checkout. +- [ ] Generated output is reviewed for stable provenance, source mappings, and absence of compiler-license headers. +- [ ] Production application boundaries are documented: committed generated Go plus the Apache runtime, with no compiler or development supervisor in the deployed binary. +- [ ] Unsupported or unmeasured performance and production claims are absent from release materials. ## Public launch - [ ] Ownership notices, output permission, DCO contribution process, and pre-registration trademark terms receive final human review. - [ ] Name clearance, security mailbox, two-person credential recovery, and signing keys complete. -- [ ] Gamertan vanity metadata and documentation verified from a clean machine. +- [ ] `gamertan.com` vanity-import metadata and documented installs verified from a clean machine. - [ ] Sanitized fresh-history public Gitea snapshot contains no private paths, identifiers, history, or unsupported release claims. -- [ ] Canonical public Gitea source preview and Gamertan documentation launch together with no secondary forge mirror. +- [ ] Canonical public Gitea source and project documentation launch with no secondary forge mirror. diff --git a/docs/BENCHMARKS.md b/docs/BENCHMARKS.md index 9c35475..f8db2b8 100644 --- a/docs/BENCHMARKS.md +++ b/docs/BENCHMARKS.md @@ -4,6 +4,12 @@ Benchmarks compare equivalent typed views and output against Go's `html/template` baseline. Reports include hardware, operating system, Go version, repository commit, dataset identity, exact commands, warmup/run counts, `ns/op`, bytes and allocations per operation, end-to-end response latency where relevant, output size, and statistical method. -The v1 gate is no material regression for the selected EQL pages under the published method. Only reproduced improvements become marketing claims. Microbenchmarks do not justify claims about request throughput, database-heavy pages, or whole-application latency. +The v1 gate is no material regression against equivalent repository-owned +synthetic cases under the published method. Only reproduced improvements become +marketing claims. Microbenchmarks do not justify claims about request +throughput, database-heavy pages, or whole-application latency. -Benchmark fixtures must contain synthetic or approved public data. The EQL production database is never copied into this repository or a public artifact. +Benchmark fixtures must be self-contained, synthetic, reviewable, and committed +to this repository. Application-specific datasets and deployment measurements +belong with their applications and are neither copied here nor treated as core +release gates. diff --git a/examples/eql-shaped/LICENSE b/examples/eql-shaped/LICENSE deleted file mode 100644 index 586736e..0000000 --- a/examples/eql-shaped/LICENSE +++ /dev/null @@ -1,14 +0,0 @@ -Zero-Clause BSD - -Copyright (c) 2025-2026 Cole Speelman - -Permission to use, copy, modify, and/or distribute this software for any -purpose with or without fee is hereby granted. - -THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH -REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY -AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, -INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM -LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR -OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR -PERFORMANCE OF THIS SOFTWARE. diff --git a/examples/eql-shaped/LICENSES.md b/examples/eql-shaped/LICENSES.md deleted file mode 100644 index 6afb5c5..0000000 --- a/examples/eql-shaped/LICENSES.md +++ /dev/null @@ -1,15 +0,0 @@ - - - -# Example license map - -The original files in this synthetic, copyable example are licensed under the -0BSD terms in `LICENSE`, including `.sando` templates, handwritten Go, -`himesan.json`, and committed `.sando.go` output. - -The generated files intentionally have no inline SPDX header because Hime-san -replaces the whole file. This module-level license map covers them. Generator -scaffolding copied into those files also has the additional permission in the -root repository's `OUTPUT_EXCEPTION.md`; that permission is not required to -keep this example under 0BSD when the example author already owns the relevant -input code. diff --git a/examples/eql-shaped/README.md b/examples/eql-shaped/README.md deleted file mode 100644 index f49e8a9..0000000 --- a/examples/eql-shaped/README.md +++ /dev/null @@ -1,15 +0,0 @@ - - -# Synthetic EQL-shaped fixture - -This copyable 0BSD example exercises a shared document layout, typed page data, -component composition, loops, text escaping, attribute escaping, and URL -policy without containing EQL Wiki code, data, routes, or its database. - -From the repository root: - -```sh -go run ./cmd/himesan generate ./examples/eql-shaped -go run ./cmd/himesan check ./examples/eql-shaped -(cd examples/eql-shaped && go test ./... && go run ./cmd/example) -``` diff --git a/examples/eql-shaped/cmd/example/main.go b/examples/eql-shaped/cmd/example/main.go deleted file mode 100644 index ddfd624..0000000 --- a/examples/eql-shaped/cmd/example/main.go +++ /dev/null @@ -1,83 +0,0 @@ -// SPDX-License-Identifier: 0BSD - -package main - -import ( - "bytes" - "context" - "errors" - "fmt" - "net/http" - "os" - "time" - - "example.com/eql-shaped/views" - "gamertan.com/sandwich-hime/sando" -) - -func main() { - address := os.Getenv("HIMESAN_LISTEN_ADDR") - if address != "" { - serve(address) - return - } - - output, err := renderPage(context.Background()) - if err != nil { - fmt.Fprintln(os.Stderr, err) - os.Exit(1) - } - _, _ = output.WriteTo(os.Stdout) -} - -func serve(address string) { - mux := http.NewServeMux() - mux.HandleFunc("GET /healthz", func(response http.ResponseWriter, _ *http.Request) { - response.Header().Set("Content-Type", "text/plain; charset=utf-8") - response.WriteHeader(http.StatusOK) - _, _ = response.Write([]byte("ok\n")) - }) - mux.HandleFunc("GET /", func(response http.ResponseWriter, request *http.Request) { - output, err := renderPage(request.Context()) - if err != nil { - http.Error(response, "render failed", http.StatusInternalServerError) - return - } - response.Header().Set("Content-Type", "text/html; charset=utf-8") - response.Header().Set("Content-Security-Policy", "default-src 'none'; style-src 'self'") - response.WriteHeader(http.StatusOK) - _, _ = output.WriteTo(response) - }) - - server := &http.Server{Addr: address, Handler: mux, ReadHeaderTimeout: 5 * time.Second} - if err := server.ListenAndServe(); !errors.Is(err, http.ErrServerClosed) { - fmt.Fprintln(os.Stderr, err) - os.Exit(1) - } -} - -func renderPage(ctx context.Context) (*bytes.Buffer, error) { - body := views.Home(views.HomeView{ - Heading: "EQL-shaped records", - Intro: "Typed markup without making the template compiler your web framework.", - Browse: views.BrowseView{ - Query: "pioneer & archivist", - Records: []views.RecordView{ - {URL: "/items/1?from=home&kind=book", Title: "A guide", Kind: "book", Featured: true}, - {URL: "/items/2", Title: "Community memory", Kind: "archive"}, - }, - }, - }) - - page := views.Layout(views.LayoutView{ - SiteName: "EQL Wiki Fixture", - Title: "Home", - Body: body, - }) - - var output bytes.Buffer - if err := sando.Render(ctx, &output, page); err != nil { - return nil, err - } - return &output, nil -} diff --git a/examples/eql-shaped/go.mod b/examples/eql-shaped/go.mod deleted file mode 100644 index 64e9965..0000000 --- a/examples/eql-shaped/go.mod +++ /dev/null @@ -1,9 +0,0 @@ -// SPDX-License-Identifier: 0BSD - -module example.com/eql-shaped - -go 1.25 - -require gamertan.com/sandwich-hime/sando v0.0.0 - -replace gamertan.com/sandwich-hime/sando => ../../sando diff --git a/examples/eql-shaped/himesan.json b/examples/eql-shaped/himesan.json deleted file mode 100644 index 174bc58..0000000 --- a/examples/eql-shaped/himesan.json +++ /dev/null @@ -1,9 +0,0 @@ -{ - "version": 1, - "sourceRoots": ["views"], - "goPackage": "./cmd/example", - "listenAddressEnv": "HIMESAN_LISTEN_ADDR", - "healthPath": "/healthz", - "proxyAddress": "127.0.0.1:7331", - "additionalWatchRoots": [] -} diff --git a/examples/eql-shaped/views/badge.sando b/examples/eql-shaped/views/badge.sando deleted file mode 100644 index 5328e05..0000000 --- a/examples/eql-shaped/views/badge.sando +++ /dev/null @@ -1,7 +0,0 @@ - - - diff --git a/examples/eql-shaped/views/browse_results.sando b/examples/eql-shaped/views/browse_results.sando deleted file mode 100644 index 42febd8..0000000 --- a/examples/eql-shaped/views/browse_results.sando +++ /dev/null @@ -1,17 +0,0 @@ - - -
- -
diff --git a/examples/eql-shaped/views/browse_results.sando.go b/examples/eql-shaped/views/browse_results.sando.go deleted file mode 100644 index 99f8a15..0000000 --- a/examples/eql-shaped/views/browse_results.sando.go +++ /dev/null @@ -1,85 +0,0 @@ -// Code generated by himesan; DO NOT EDIT. -// himesan:compiler 0.1.0-dev -// himesan:runtime-abi sando.v1 -// himesan:source-sha256 c5b402971618747c906c84508d5af9fd00aa33391b9b59f093b001a3cb0b2164 - -package views - -import ( - __himesan_context "context" - __himesan_sando "gamertan.com/sandwich-hime/sando" - __himesan_io "io" -) - -var _ = __himesan_sando.ABI - -func BrowseResults(view BrowseView) __himesan_sando.Component { - return __himesan_sando.ComponentFunc(func(__himesan_render_context __himesan_context.Context, __himesan_writer __himesan_io.Writer) error { - _ = __himesan_render_context -//line views/browse_results.sando:5:3 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "\n"); __himesan_error != nil { - return __himesan_error - } -//line views/browse_results.sando:6:37 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "\n
\n \n
\n"); __himesan_error != nil { - return __himesan_error - } - return nil - }) -} diff --git a/examples/eql-shaped/views/home.sando b/examples/eql-shaped/views/home.sando deleted file mode 100644 index ef2f8c9..0000000 --- a/examples/eql-shaped/views/home.sando +++ /dev/null @@ -1,11 +0,0 @@ - - -
-

-

- -
diff --git a/examples/eql-shaped/views/home.sando.go b/examples/eql-shaped/views/home.sando.go deleted file mode 100644 index 086bb06..0000000 --- a/examples/eql-shaped/views/home.sando.go +++ /dev/null @@ -1,53 +0,0 @@ -// Code generated by himesan; DO NOT EDIT. -// himesan:compiler 0.1.0-dev -// himesan:runtime-abi sando.v1 -// himesan:source-sha256 696c391538cdc50c5ab1abea23b561fa354e56eaf73b7ad6aabe130389715a8c - -package views - -import ( - __himesan_context "context" - __himesan_sando "gamertan.com/sandwich-hime/sando" - __himesan_io "io" -) - -var _ = __himesan_sando.ABI - -func Home(view HomeView) __himesan_sando.Component { - return __himesan_sando.ComponentFunc(func(__himesan_render_context __himesan_context.Context, __himesan_writer __himesan_io.Writer) error { - _ = __himesan_render_context -//line views/home.sando:5:3 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "\n"); __himesan_error != nil { - return __himesan_error - } -//line views/home.sando:6:37 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "\n
\n

"); __himesan_error != nil { - return __himesan_error - } -//line views/home.sando:8:29 - if __himesan_error := __himesan_sando.WriteText(__himesan_writer, (view.Heading)); __himesan_error != nil { - return __himesan_error - } -//line views/home.sando:8:44 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "

\n

"); __himesan_error != nil { - return __himesan_error - } -//line views/home.sando:9:10 - if __himesan_error := __himesan_sando.WriteText(__himesan_writer, (view.Intro)); __himesan_error != nil { - return __himesan_error - } -//line views/home.sando:9:23 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "

\n "); __himesan_error != nil { - return __himesan_error - } -//line views/home.sando:10:7 - if __himesan_error := __himesan_sando.Render(__himesan_render_context, __himesan_writer, (BrowseResults(view.Browse))); __himesan_error != nil { - return __himesan_error - } -//line views/home.sando:10:36 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "\n
\n"); __himesan_error != nil { - return __himesan_error - } - return nil - }) -} diff --git a/examples/eql-shaped/views/layout.sando b/examples/eql-shaped/views/layout.sando deleted file mode 100644 index ccdb53b..0000000 --- a/examples/eql-shaped/views/layout.sando +++ /dev/null @@ -1,20 +0,0 @@ - - - - - - - - <?= view.Title ?> · <?= view.SiteName ?> - - - Skip to content -
-
- - - diff --git a/examples/eql-shaped/views/layout.sando.go b/examples/eql-shaped/views/layout.sando.go deleted file mode 100644 index 45d5a12..0000000 --- a/examples/eql-shaped/views/layout.sando.go +++ /dev/null @@ -1,61 +0,0 @@ -// Code generated by himesan; DO NOT EDIT. -// himesan:compiler 0.1.0-dev -// himesan:runtime-abi sando.v1 -// himesan:source-sha256 c9a8102588cb94f946a36414291d12cb681e605acc93c2b5dc8d74fd33ae5603 - -package views - -import ( - __himesan_context "context" - __himesan_sando "gamertan.com/sandwich-hime/sando" - __himesan_io "io" -) - -var _ = __himesan_sando.ABI - -func Layout(view LayoutView) __himesan_sando.Component { - return __himesan_sando.ComponentFunc(func(__himesan_render_context __himesan_context.Context, __himesan_writer __himesan_io.Writer) error { - _ = __himesan_render_context -//line views/layout.sando:5:3 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "\n"); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:6:37 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "\n\n\n\n \n \n "); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:12:14 - if __himesan_error := __himesan_sando.WriteRCDATA(__himesan_writer, (view.Title)); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:12:27 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, " · "); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:12:35 - if __himesan_error := __himesan_sando.WriteRCDATA(__himesan_writer, (view.SiteName)); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:12:51 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "\n\n\n Skip to content\n
"); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:16:27 - if __himesan_error := __himesan_sando.WriteText(__himesan_writer, (view.SiteName)); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:16:43 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "
\n
"); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:17:23 - if __himesan_error := __himesan_sando.Render(__himesan_render_context, __himesan_writer, (view.Body)); __himesan_error != nil { - return __himesan_error - } -//line views/layout.sando:17:35 - if __himesan_error := __himesan_sando.WriteString(__himesan_writer, "
\n \n\n\n"); __himesan_error != nil { - return __himesan_error - } - return nil - }) -} diff --git a/examples/eql-shaped/views/model.go b/examples/eql-shaped/views/model.go deleted file mode 100644 index d61e1bd..0000000 --- a/examples/eql-shaped/views/model.go +++ /dev/null @@ -1,29 +0,0 @@ -// SPDX-License-Identifier: 0BSD - -package views - -import "gamertan.com/sandwich-hime/sando" - -type LayoutView struct { - SiteName string - Title string - Body sando.Component -} - -type HomeView struct { - Heading string - Intro string - Browse BrowseView -} - -type BrowseView struct { - Query string - Records []RecordView -} - -type RecordView struct { - URL string - Title string - Kind string - Featured bool -} diff --git a/examples/eql-shaped/views/render_test.go b/examples/eql-shaped/views/render_test.go deleted file mode 100644 index ee16c9f..0000000 --- a/examples/eql-shaped/views/render_test.go +++ /dev/null @@ -1,131 +0,0 @@ -// SPDX-License-Identifier: 0BSD - -package views - -import ( - "bytes" - "context" - "errors" - "html/template" - "io" - "strings" - "testing" - - "gamertan.com/sandwich-hime/sando" -) - -func TestBrowseResultsEscapesUntrustedValues(t *testing.T) { - t.Parallel() - - component := BrowseResults(BrowseView{ - Query: `">`, - Records: []RecordView{{ - URL: `/item?q=" onclick="alert(1)`, - Title: ``, - Kind: `" aria-label="injected`, - }}, - }) - - var output bytes.Buffer - if err := sando.Render(context.Background(), &output, component); err != nil { - t.Fatal(err) - } - got := output.String() - if strings.Contains(got, "