policy: maintain Linux as the release target
Publishes the exact allowlisted snapshot from the private Beta 2 development line. Historical platform evidence remains truthful; native Windows and macOS are no longer release gates or support promises. Material AI assistance was reviewed by the maintainer. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
This commit was merged in pull request #1.
This commit is contained in:
@@ -6,6 +6,23 @@ Sandwich Hime follows semantic versioning after final v1. Compiler and nested
|
||||
runtime releases are versioned independently and listed together when they form
|
||||
one coordinated release.
|
||||
|
||||
## Unreleased
|
||||
|
||||
### Changed
|
||||
|
||||
- Linux/amd64 is the maintained execution, verification, artifact, and release
|
||||
target. WSL remains a Linux development environment; native Windows, macOS,
|
||||
and other targets are best-effort portability surfaces rather than release
|
||||
gates or compatibility promises.
|
||||
- Release preflight now builds the supported Linux/amd64 candidate only and
|
||||
requires Linux platform evidence for RC/final publication.
|
||||
|
||||
### Removed
|
||||
|
||||
- The native Windows PowerShell verifier and private multi-OS release-gate
|
||||
workflow. Historical platform evidence and best-effort portability code are
|
||||
retained without creating a support obligation.
|
||||
|
||||
## v1.0.0-beta.2 — 2026-08-12
|
||||
|
||||
Compiler-only release; the unchanged Apache runtime remains
|
||||
|
||||
@@ -1 +1 @@
|
||||
{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":90,"allowlist_sha256":"393ee598dc7e12cdbb603887bf06599e46b40d7c19e4ff693a818cc32afb01ec","manifest_sha256":"38a02b05cec70c82076df0f40de8b98edfc9280f54c12fa0cbe84949da253fdf"}
|
||||
{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":89,"allowlist_sha256":"2947ef034f9bfe9bd20c00e67d0033f0ff5e62e55fc2db0952696485d9eeec40","manifest_sha256":"5005a799e84f5cbb66cc9d0ced03c5897924de1b9c28adf8aaf06b2ddb4affff"}
|
||||
|
||||
+11
-12
@@ -2,7 +2,7 @@
|
||||
658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes
|
||||
d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore
|
||||
98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md
|
||||
0828545d3aa440e1ec5dce4b934de6800413f55a925988b60923c5ee9b700a4e ./CHANGELOG.md
|
||||
5bc3db089eb243640adc2e4bae62d94754aff420d1eb64057036032dfd9a626b ./CHANGELOG.md
|
||||
b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md
|
||||
797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md
|
||||
86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT
|
||||
@@ -13,10 +13,10 @@ a4570d054f072d33b8f17b0c8b162a6ee0ca37d7df2b1aee7e4b728ab350a892 ./GOVERNANCE.m
|
||||
47d857e49f89596bac9b09fc8ca57a668a33d01e2b51508acfc92ed321cdc27f ./LICENSES.md
|
||||
b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md
|
||||
6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md
|
||||
c3ac873ae2e6248e1d86dd542a11557b24b8dba80e4785f3bc1018152020235c ./README.md
|
||||
2751674c180f15a42c1d2b40cf149be4138aa6cf247d7be176f1f0c468103c24 ./RELEASE.md
|
||||
209decb6769646eb2f58e312fbcd9c497c26234f3d3115bae3f20493b8178584 ./ROADMAP.md
|
||||
0fef473ac46b71215d1eb7922da4594210ffbbb8bb2dedd5e531fb3bd09396e1 ./SECURITY.md
|
||||
fbc4a7c118ac983a1ea49dc3a9d714f5130ace21a8af59ab9fcabd6519cb6b97 ./README.md
|
||||
fafa1494fa1a5a5cf3b3d371155f0448d46f1f13cd394555e06396b336bc102a ./RELEASE.md
|
||||
c0e65a8bffcba71cd42d6122be25fd4993c04c8cba8c5e69108c9f5dbaca9243 ./ROADMAP.md
|
||||
17e10aaab589d40b479e374523982117d2c7ffac95306493cfa4e3171108a1a8 ./SECURITY.md
|
||||
53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md
|
||||
3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md
|
||||
8cd8db68e1300f9b78cc7235855853cbc7aeb499a921419e23a22e4d22826fcb ./cmd/himesan/main.go
|
||||
@@ -24,13 +24,13 @@ c3ac873ae2e6248e1d86dd542a11557b24b8dba80e4785f3bc1018152020235c ./README.md
|
||||
1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md
|
||||
9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md
|
||||
5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md
|
||||
2b815d3b815b8d338560183c6f0af46f761c2465309783c93870b8ac8d022d03 ./docs/COMPATIBILITY.md
|
||||
a88ae86f046779db2ee4e0e7458510d782c459ab898efb8b58decaec53f72743 ./docs/COMPATIBILITY.md
|
||||
5f4ac209a16ab110baeaa64a40c19d9239c903e17550c3f05e1e1473ddcc33a3 ./docs/DEVELOPMENT_SERVER.md
|
||||
51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md
|
||||
a62cc7174f3c92d8ef77e4bd9607fbf5d4b80bc514ff05bd433c02a9b0578f18 ./docs/LANGUAGE_SERVER.md
|
||||
091d40da988d61e0f2f13fa022363a2113aea626a45785ddd348eca2817be56c ./docs/SECURITY_EVIDENCE.md
|
||||
d969c7b5486ee93e54232fd69d9db06f3b4dc1bba63001596ec48545073c2680 ./docs/THREAT_MODEL.md
|
||||
738258ba8f7e5ffea67d3f00eb70839590171971a9946a55b013ca95baf7aafb ./docs/V1_RELEASE_PLAN.md
|
||||
f2622e0eba601470624e862caf717060c7b73037f13f0b7bd6e9792a49463480 ./docs/SECURITY_EVIDENCE.md
|
||||
f2423c325ebe5371af43db6b09b11ea5a4ea3d3d3c14098f9d0ccd89110ea03d ./docs/THREAT_MODEL.md
|
||||
bb2fde5ffd9736ef2a46b2931484bcec7b872353c7c20821a8fa7a32946fa97d ./docs/V1_RELEASE_PLAN.md
|
||||
f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod
|
||||
ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go
|
||||
d891b9b075617050471b2ca34de73d926aaebde4ec638a5039b0d5001d3172f4 ./internal/compiler/analysis.go
|
||||
@@ -82,9 +82,8 @@ ff76daee5b642ad84af31701833246d68b54d09580192312d750a7a2e893a692 ./sando/go.mod
|
||||
80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go
|
||||
85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go
|
||||
b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go
|
||||
c4a161faba46ce5b508c0788078256a520277a573a3ace0e85ae0c26b16d298b ./scripts/README.md
|
||||
36265470310f8463895761bb53a2137583d395d4b19b0190d038eecce1f4ce25 ./scripts/README.md
|
||||
0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh
|
||||
1b003062799b99bfe271b47438397a8cce5875c60c982a0117eb11c3babcadf0 ./scripts/release-check.sh
|
||||
03d58bea32691d6d503983ddcf979fb88091eed4cb322e74a9eeb4ee434bacec ./scripts/release-check.sh
|
||||
78a64c7fb3a039b15a1d08b4c0b873952852287a07f670247b081e59dbb09a30 ./scripts/verify-public-install.sh
|
||||
24ed3c9a1d37e46a856cbbd68e5c58ae04c6c9852902b99ed675e1f428339a9f ./scripts/verify.ps1
|
||||
f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh
|
||||
|
||||
@@ -48,13 +48,17 @@ semantic-version prerelease: source syntax, generated output, the runtime API,
|
||||
and CLI behavior may change before final v1, and this beta is not recommended
|
||||
for production deployment.
|
||||
|
||||
The exact Beta 1 source passed maintainer-run native Windows and executed Linux
|
||||
matrices with Go 1.25.12 and Go 1.26.5. Native macOS validation is still
|
||||
pending, so macOS support is provisional in this beta. Mac learners and Go
|
||||
developers are warmly invited to try it and share their macOS version,
|
||||
architecture, Go version, command, and smallest useful reproduction. Community
|
||||
reports broaden the evidence; maintainers remain responsible for security
|
||||
review, triage, fixes, and release decisions.
|
||||
Linux/amd64 is the maintained execution and release target. Required release
|
||||
evidence runs on Linux with the supported Go lines. WSL is a useful Linux
|
||||
development environment, but it does not turn native Windows into a supported
|
||||
target. Native Windows, macOS, and other operating systems may happen to build
|
||||
or work and portability reports are welcome; they are not release gates or a
|
||||
maintained compatibility promise.
|
||||
|
||||
The evidence ledger retains the exact Beta 1 Windows and Linux observations as
|
||||
historical facts. Those past results do not expand the current support policy.
|
||||
Maintainers remain responsible for security review, triage, fixes, and release
|
||||
decisions on the supported Linux target.
|
||||
|
||||
Inside an application module, add the small runtime first:
|
||||
|
||||
|
||||
+19
-16
@@ -21,11 +21,11 @@ while it is the current prerelease, but it is not recommended or supported as a
|
||||
production-stable dependency. Syntax, generated output, runtime APIs, CLI
|
||||
behavior, and diagnostics may change in a later prerelease.
|
||||
|
||||
Beta 1 may publish with native macOS validation pending when Windows and Linux
|
||||
have passed the exact-candidate matrix and macOS is clearly marked provisional.
|
||||
Community Mac results are valuable compatibility input; they do not transfer
|
||||
security review, triage, remediation, or release responsibility away from the
|
||||
maintainers.
|
||||
Current and future beta release gates run on Linux/amd64. WSL may be used as a
|
||||
Linux development environment, but native Windows, macOS, and other targets
|
||||
are not release blockers or maintained compatibility promises. Portability
|
||||
reports remain useful input; they do not transfer security review, triage,
|
||||
remediation, or release responsibility away from the maintainers.
|
||||
|
||||
Beta tags are signed, annotated, and immutable. Beta 1 is a source/module
|
||||
release installed through the Go toolchain; it does not promise downloadable
|
||||
@@ -37,9 +37,9 @@ final v1.
|
||||
|
||||
An RC means the intended v1 source, runtime, CLI, diagnostics, schemas, and
|
||||
generated contract are frozen except for release-blocking fixes. An RC requires
|
||||
maintainer-run native Linux, macOS, and Windows evidence, complete release
|
||||
artifacts and provenance, signed tags, clean direct/proxy installs, and every RC
|
||||
gate in this repository. Findings produce a new RC rather than a moved tag.
|
||||
maintainer-run Linux/amd64 evidence, complete release artifacts and provenance,
|
||||
signed tags, clean direct/proxy installs, and every RC gate in this repository.
|
||||
Findings produce a new RC rather than a moved tag.
|
||||
|
||||
### Final v1
|
||||
|
||||
@@ -49,7 +49,11 @@ published assurance gap, and the documented RC observation period. A
|
||||
deployment, example, classroom project, or case study in another repository is
|
||||
neither imported nor required as release evidence.
|
||||
|
||||
## Beta 1 publication gates
|
||||
## Beta 1 publication gates (historical)
|
||||
|
||||
The first beta used a broader one-time platform campaign. The completed items
|
||||
below are retained as publication history; they do not define future platform
|
||||
support.
|
||||
|
||||
Before `sando/v1.0.0-beta.1` and `v1.0.0-beta.1` are created:
|
||||
|
||||
@@ -99,8 +103,7 @@ In addition to every Beta 1 compiler/security/determinism gate:
|
||||
nested-module boundaries, completion scope, and component definitions;
|
||||
2. prove the language-server package does not write, execute project code,
|
||||
invoke Go, fetch, access the network, or start the development supervisor;
|
||||
3. run the exact candidate on supported Go lines under executed Linux and
|
||||
native Windows, with native macOS status stated explicitly;
|
||||
3. run the exact candidate on supported Go lines under executed Linux/amd64;
|
||||
4. build an exact version-stamped candidate and assert the additive
|
||||
`features: ["lsp-stdio"]` JSON identity;
|
||||
5. publish a signed annotated compiler tag only after the reviewed sanitized
|
||||
@@ -111,16 +114,16 @@ In addition to every Beta 1 compiler/security/determinism gate:
|
||||
## RC and final gates
|
||||
|
||||
No release candidate or v1.0.0 release occurs until every applicable gate in
|
||||
this repository is evidenced, including cross-platform deterministic
|
||||
generation, temporary-module compilation, fuzz/adversarial suites,
|
||||
this repository is evidenced, including deterministic generation on supported
|
||||
Linux and Go lanes, temporary-module compilation, fuzz/adversarial suites,
|
||||
race/vet/vulnerability/license checks on the latest two supported Go lines,
|
||||
development-supervisor failure tests, and reproducible repository-owned
|
||||
benchmark and security results.
|
||||
|
||||
Release candidates require a clean canonical checkout, reviewed changelog,
|
||||
compatible vanity-import metadata, reproducible binaries, signed annotated
|
||||
tags, checksums, SBOMs, vulnerability results, and verification on Linux,
|
||||
macOS, and Windows.
|
||||
compatible vanity-import metadata, reproducible Linux/amd64 binaries, signed
|
||||
annotated tags, checksums, SBOMs, vulnerability results, and verification on
|
||||
Linux/amd64.
|
||||
|
||||
## Public source and artifacts
|
||||
|
||||
|
||||
+9
-11
@@ -7,31 +7,29 @@ necessarily blockers for an earlier prerelease. The ordered initiative,
|
||||
repository topology, release-candidate sequence, and definition of confidence
|
||||
are maintained in [docs/V1_RELEASE_PLAN.md](docs/V1_RELEASE_PLAN.md).
|
||||
|
||||
## Beta 1: public learning and evaluation
|
||||
## Beta 1: public learning and evaluation (historical)
|
||||
|
||||
Beta 1 deliberately ships before the final-v1 compatibility and artifact gates.
|
||||
Its scope is classroom use, learning, prototypes, and compatibility feedback;
|
||||
it is not a production-stability promise.
|
||||
|
||||
- [x] Define beta versus RC/final support and compatibility policy.
|
||||
- [x] Establish a public pre-beta Linux/Windows matrix on Go 1.25 and Go 1.26.
|
||||
- [x] Document macOS as provisional and invite useful community reports while
|
||||
retaining maintainer responsibility for security and releases.
|
||||
- [x] Rerun all required Windows/Linux checks and deterministic generation on
|
||||
the exact Beta 1 candidate.
|
||||
- [x] Establish a one-time public pre-beta Linux/Windows evidence matrix on Go
|
||||
1.25 and Go 1.26.
|
||||
- [x] Record the untested macOS boundary without presenting it as evidence.
|
||||
- [x] Rerun the historical Windows/Linux campaign and deterministic generation
|
||||
on the exact Beta 1 candidate.
|
||||
- [x] Publish immutable `sando/v1.0.0-beta.1`, then
|
||||
`v1.0.0-beta.1`, from the reviewed public commit.
|
||||
- [x] Verify clean runtime-first direct and public-proxy installs after
|
||||
publication.
|
||||
- [ ] Complete native macOS maintainer validation. This is an RC/final gate,
|
||||
not a Beta 1 gate.
|
||||
|
||||
## Compiler and runtime for RC/final
|
||||
|
||||
- [ ] Freeze and machine-check the compiler, CLI, diagnostic, schema, generated,
|
||||
and runtime compatibility contracts.
|
||||
- [ ] Repeat compiler-owned deterministic golden output across Linux, macOS,
|
||||
and Windows on the exact candidate.
|
||||
- [ ] Repeat compiler-owned deterministic golden output across the supported
|
||||
Linux and Go lanes on the exact candidate.
|
||||
- [ ] Compile temporary consumer modules using committed Go and only the Apache
|
||||
runtime.
|
||||
- [ ] Run the parser, delimiter, context, path, and source-map release fuzz
|
||||
@@ -75,5 +73,5 @@ it is not a production-stability promise.
|
||||
machines.
|
||||
- [ ] Confirm the sanitized public Gitea source contains no private paths,
|
||||
identifiers, history, or unsupported claims.
|
||||
- [ ] Publish and observe a signed RC on every supported native platform.
|
||||
- [ ] Publish and observe a signed RC on the supported Linux/amd64 target.
|
||||
- [ ] Publish `sando/v1.0.0`, then `v1.0.0`, without moving either tag.
|
||||
|
||||
+3
-2
@@ -9,7 +9,8 @@ Security reports are welcome and receive best-effort maintainer assessment and
|
||||
fixes while this pair is current. This is not production support,
|
||||
an SLA, a fitness guarantee, or a promise that a fix will preserve beta APIs.
|
||||
|
||||
The community is invited to help find compatibility gaps, especially on macOS.
|
||||
The community is invited to help find portability gaps outside the maintained
|
||||
Linux target, but those reports do not create a support or release commitment.
|
||||
That invitation does not outsource security assurance. Maintainers retain
|
||||
responsibility for vulnerability review, triage, remediation decisions,
|
||||
advisories, and release decisions.
|
||||
@@ -35,7 +36,7 @@ public issue.
|
||||
If that new mailbox rejects or bounces a message, retain the report and open a
|
||||
canonical Gitea issue containing only the fact that the private security contact
|
||||
failed. Do not include technical details or sensitive data. The maintainer will
|
||||
publish a corrected private route. Ordinary usage, classroom, and macOS
|
||||
publish a corrected private route. Ordinary usage, classroom, and portability
|
||||
compatibility reports that do not reveal a vulnerability may use a public issue.
|
||||
|
||||
Helpful reports include:
|
||||
|
||||
+22
-15
@@ -32,9 +32,17 @@ payloads before final v1, or hand-edited generated files.
|
||||
|
||||
## Go and platform support
|
||||
|
||||
The current beta targets Go 1.25 and Go 1.26. Support is based on point-in-time,
|
||||
maintainer-run release matrices, not an implication of continuous CI coverage.
|
||||
A Go support change is announced in release notes before it takes effect.
|
||||
The current beta targets Go 1.25 and Go 1.26 on Linux/amd64. Required release
|
||||
evidence runs in Linux CI and on Linux deployment hosts. WSL is treated as a
|
||||
Linux development environment. Native Windows, macOS, and other targets are
|
||||
not maintained release targets or release blockers; a successful build there
|
||||
is useful portability evidence, not a compatibility promise. A Go or platform
|
||||
support change is announced in release notes before it takes effect.
|
||||
|
||||
### Historical Beta 1 observations
|
||||
|
||||
The following table is retained because the tests genuinely ran. It records a
|
||||
point-in-time Beta 1 campaign and does not define the current support matrix.
|
||||
|
||||
The current public evidence is the exact Beta 1 source at commit
|
||||
`b7a84054d755e42285e50298e41e47f06a8325a5` (tree
|
||||
@@ -45,26 +53,25 @@ The current public evidence is the exact Beta 1 source at commit
|
||||
| Windows 11/amd64 on NTFS | 1.25.12, 1.26.5 | Native tests, race, vet, builds, generation, process cleanup, watcher boundaries, and temporary consumer compilation passed; privileged symlink and POSIX-only permission cases were not exercised |
|
||||
| Linux/amd64 on WSL2 with an ext4 checkout | 1.25.12, 1.26.5 | Tests, race, vet, builds, generation, focused filesystem/development cases, and license checks passed |
|
||||
| Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | The earlier pre-beta baseline passed tests, race, vet, builds, deterministic generation, and license checks; this was not rerun on the exact Beta 1 commit |
|
||||
| macOS | — | Native maintainer validation pending; provisional for Beta 1 |
|
||||
| macOS | — | Not executed during the Beta 1 campaign |
|
||||
|
||||
The golden generated file had SHA-256
|
||||
`63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`
|
||||
on every tested Windows and Linux lane.
|
||||
on every tested Windows and Linux lane in that historical campaign.
|
||||
|
||||
The signed Beta tags and fresh direct/public-proxy installation were verified
|
||||
after publication. For Beta 1, add the nested runtime to an application module
|
||||
before installing the parent compiler at the same version; this avoids a Go
|
||||
module-cache path-selection ambiguity observed in the reverse order.
|
||||
|
||||
## macOS feedback
|
||||
## Portability feedback
|
||||
|
||||
Mac learners, teachers, and Go developers are warmly invited to try the beta.
|
||||
A useful compatibility report includes the macOS version, Intel or Apple
|
||||
Silicon architecture, `go version`, the exact command, and a minimal
|
||||
reproduction or diagnostic output. Ordinary compatibility reports belong on
|
||||
the canonical Gitea project. Suspected vulnerabilities must use the private
|
||||
route in [SECURITY.md](../SECURITY.md).
|
||||
Developers may try the beta on an unsupported target and report useful gaps. A
|
||||
good report includes the operating system and architecture, `go version`, the
|
||||
exact command, and a minimal reproduction or diagnostic output. Ordinary
|
||||
portability reports belong on the canonical Gitea project. Suspected
|
||||
vulnerabilities must use the private route in [SECURITY.md](../SECURITY.md).
|
||||
|
||||
Community reports can reveal gaps and help prioritize maintainer testing. They
|
||||
do not constitute an independent audit or shift responsibility for security
|
||||
review, triage, fixes, and release decisions to the community.
|
||||
Community reports can reveal gaps and help prioritize future work. They do not
|
||||
constitute an independent audit, create a support promise, or shift
|
||||
responsibility for security review, triage, fixes, and release decisions.
|
||||
|
||||
+20
-17
@@ -23,8 +23,10 @@ The named Windows and WSL2 platform runs used the exact public commit and tree
|
||||
above. The isolated server-container matrix preceded the final candidate and
|
||||
is retained only as supplementary Linux evidence. Hostnames, network addresses,
|
||||
account names, private paths, private repository identities, and private commit
|
||||
mappings are intentionally absent from this public ledger. Native macOS
|
||||
execution remains pending and is provisional for the beta.
|
||||
mappings are intentionally absent from this public ledger. These platform
|
||||
observations are historical evidence, not the current support matrix.
|
||||
Linux/amd64 is now the maintained release target; WSL is a Linux development
|
||||
environment, while native Windows and macOS are not release blockers.
|
||||
|
||||
## Beta 2 compiler publication addendum
|
||||
|
||||
@@ -48,7 +50,8 @@ focused process-tree/watcher/consumer tests, candidate-stamped version checks,
|
||||
and deterministic generation on Go 1.25.12 and Go 1.26.5. Clean isolated
|
||||
`GOPROXY=direct` and public-proxy-only installs produced
|
||||
`features:["lsp-stdio"]`; the public-proxy path also verified the retained
|
||||
runtime through `sum.golang.org`. Native macOS execution remains provisional.
|
||||
runtime through `sum.golang.org`. The Windows result is retained as historical
|
||||
portability evidence and does not create an ongoing support promise.
|
||||
|
||||
The Beta 2 language server is additive development tooling. Its tested
|
||||
security boundary includes protocol-only stdout; bounded header and message
|
||||
@@ -83,7 +86,7 @@ baseline commit.
|
||||
| URL scheme handling | ordinary/trusted URL test matrix | Pass for enumerated cases |
|
||||
| Filesystem boundaries | symlink, nested-module, VCS, ownership, stale-output tests | Pass for tested cases; see open findings |
|
||||
| Development proxy browser boundary | Host, Origin, Fetch Metadata, CSP, fragment and response tests | Pass for tested cases |
|
||||
| Platform behavior | Exact-candidate native Windows and executed Linux matrices; macOS cross-compilation | Windows/Linux pass for tested lanes; native macOS pending |
|
||||
| Platform behavior | Historical exact-candidate native Windows and executed Linux matrices | Windows/Linux passed for the tested lanes; current releases require Linux/amd64 evidence |
|
||||
|
||||
Coverage measures statements executed by tests. It is not branch completeness
|
||||
and is not evidence that the executed behavior is secure.
|
||||
@@ -92,7 +95,7 @@ and is not evidence that the executed behavior is secure.
|
||||
and reachable through its analysis. A clean result cannot detect unknown flaws,
|
||||
design errors, or vulnerabilities outside its model.
|
||||
|
||||
## Beta 1 native compatibility matrix
|
||||
## Historical Beta 1 compatibility matrix
|
||||
|
||||
These are maintainer-run, point-in-time results, not continuous CI and not an
|
||||
independent audit.
|
||||
@@ -102,7 +105,7 @@ independent audit.
|
||||
| Windows 11/amd64, NTFS | 1.25.12, 1.26.5 | Native PowerShell verifier with race; root/runtime tests, vet, trimpath build, freshness, two generation passes, process-tree cleanup, watcher boundaries, and temporary consumer compilation | Pass. Symlink-output rejection skipped because the test account lacked symlink privilege; the read-only-directory case is POSIX-only |
|
||||
| Ubuntu 20.04/amd64 under WSL2, native ext4 checkout | 1.25.12, 1.26.5 | Race-enabled verifier; root/runtime tests, vet, build, two generation passes, ten focused filesystem cases, five focused development-process/watcher cases, and license check | Pass. This is Linux execution under WSL2, not bare-metal or Linux/arm64 evidence |
|
||||
| Linux/amd64 server containers | 1.25.12, 1.26.5 | Earlier pre-beta root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass on the earlier baseline only. Container resources were capped at 1 CPU and 2 GiB; this is supplementary evidence, not an exact Beta 1 lane or Linux/arm64 evidence |
|
||||
| macOS | — | Cross-compilation only | Native maintainer execution pending; provisional for Beta 1 |
|
||||
| macOS | — | Cross-compilation only | No native Beta 1 evidence; not a maintained release target |
|
||||
|
||||
The generated golden `basic.sando.go` was 1,399 bytes and had SHA-256
|
||||
`63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`
|
||||
@@ -110,12 +113,12 @@ on every tested Windows and Linux lane. Repeated generation also preserved its
|
||||
timestamp. This demonstrates cross-host agreement for one compiler-owned
|
||||
fixture, not equivalence for every possible template.
|
||||
|
||||
Mac learners and Go developers are warmly invited to report ordinary
|
||||
compatibility results with macOS version, architecture, `go version`, exact
|
||||
command, and a minimal reproduction. Suspected vulnerabilities use the private
|
||||
route in [SECURITY.md](../SECURITY.md). Community reports help find gaps;
|
||||
maintainers remain responsible for reproducing security-relevant behavior,
|
||||
triage, remediation, and release decisions.
|
||||
Portability reports for unsupported targets may include the operating system,
|
||||
architecture, `go version`, exact command, and a minimal reproduction.
|
||||
Suspected vulnerabilities use the private route in
|
||||
[SECURITY.md](../SECURITY.md). Such reports help find gaps but do not create a
|
||||
support promise; maintainers remain responsible for security triage and fixes
|
||||
on the supported Linux target.
|
||||
|
||||
## Security-relevant design evidence
|
||||
|
||||
@@ -203,8 +206,9 @@ known-vulnerability scans, candidate-version provenance checks, native Windows
|
||||
and executed Linux matrices, and Windows/macOS cross-compilation on 2026-08-12.
|
||||
Signed annotated runtime and compiler tags were then published from that commit
|
||||
in that order. Fresh runtime-first installation passed through both direct Git
|
||||
resolution and the public Go proxy after normal proxy propagation. Native
|
||||
macOS and the other gaps below remain separate release decisions.
|
||||
resolution and the public Go proxy after normal proxy propagation. Future
|
||||
release decisions use the current Linux-only support policy rather than
|
||||
requiring this historical multi-platform campaign.
|
||||
|
||||
## Open assurance gaps
|
||||
|
||||
@@ -214,9 +218,8 @@ macOS and the other gaps below remain separate release decisions.
|
||||
- the signed annotated Beta tags and their common peeled commit were verified;
|
||||
prebuilt-artifact signing, checksums, SBOM, reproducible provenance, and key
|
||||
recovery remain incomplete;
|
||||
- native macOS, Linux/arm64, and Windows/arm64 execution remain outstanding;
|
||||
- Windows symlink rejection was not natively exercised because the test account
|
||||
lacked symlink privilege;
|
||||
- Linux/arm64 and non-Linux portability are outside the current maintained
|
||||
release target;
|
||||
- browser-parser differential and semantic property testing need expansion;
|
||||
- compiler input size, CPU, and memory have no built-in hard budget;
|
||||
- filesystem checks do not defend against a hostile local actor racing path
|
||||
|
||||
@@ -177,7 +177,7 @@ Sandwich Hime does not:
|
||||
## Open release work
|
||||
|
||||
- broaden semantic and browser-parser differential testing;
|
||||
- execute the native Windows/macOS security and process-lifecycle matrix;
|
||||
- execute the Linux/amd64 security and process-lifecycle release matrix;
|
||||
- complete signed release provenance, checksums, and SBOM evidence;
|
||||
- test the confidential reporting and signing-key recovery procedures; and
|
||||
- close or explicitly accept every finding listed in the evidence ledger before
|
||||
|
||||
+17
-19
@@ -28,17 +28,18 @@ private history or an indiscriminate Git mirror.
|
||||
|
||||
Beta 1 is deliberately earlier than a release candidate. It creates a real,
|
||||
repeatable install for learners and evaluators without claiming that the final
|
||||
v1 compatibility, native-platform, artifact, signing, or soak gates are
|
||||
complete.
|
||||
v1 compatibility, Linux release, artifact, signing, or soak gates are complete.
|
||||
|
||||
### Demonstrated for Beta 1
|
||||
|
||||
Public commit `b7a84054d755e42285e50298e41e47f06a8325a5` (tree
|
||||
`be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run Go
|
||||
1.25.12 and Go 1.26.5 matrices on native Windows/amd64, Linux/amd64 under WSL2,
|
||||
with the earlier pre-beta server-container run retained only as supplementary
|
||||
Linux evidence. The same generated golden SHA-256 was observed across the exact
|
||||
Beta Windows and Linux lanes.
|
||||
1.25.12 and Go 1.26.5 matrices on native Windows/amd64 and Linux/amd64 under
|
||||
WSL2, with the earlier pre-beta server-container run retained only as
|
||||
supplementary Linux evidence. The same generated golden SHA-256 was observed
|
||||
across the exact Beta Windows and Linux lanes. This is historical evidence,
|
||||
not the current support definition; Linux/amd64 is now the maintained release
|
||||
target.
|
||||
|
||||
Other demonstrated controls include:
|
||||
|
||||
@@ -52,7 +53,7 @@ Other demonstrated controls include:
|
||||
|
||||
### Not demonstrated yet
|
||||
|
||||
- native maintainer-run macOS execution; macOS is provisional for Beta 1;
|
||||
- final Linux/amd64 release-candidate evidence on the exact candidate;
|
||||
- stable final-v1 API, CLI, schema, diagnostic, and generated snapshots;
|
||||
- systematic browser-parser and `html/template` differential testing;
|
||||
- a long semantic fuzz campaign beyond bounded no-panic smoke;
|
||||
@@ -60,7 +61,7 @@ Other demonstrated controls include:
|
||||
- complete real-browser development-supervisor evidence;
|
||||
- deterministic prebuilt archives, checksums, SBOMs, signed binaries, and
|
||||
tested signing/recovery procedures; or
|
||||
- native macOS installation of the published Beta 1 tags.
|
||||
- independently reproduced Linux release artifacts, checksums, and SBOMs.
|
||||
|
||||
## Beta 1 publication lane
|
||||
|
||||
@@ -68,9 +69,8 @@ Beta 1 is supported for learning, classroom projects, evaluation, prototypes,
|
||||
and compatibility feedback. It is not recommended as a production-stable
|
||||
dependency, and its interfaces may change.
|
||||
|
||||
- [x] Define beta support, security, compatibility, and macOS-provisional
|
||||
language.
|
||||
- [x] Establish the named public pre-beta Linux/Windows baseline.
|
||||
- [x] Define beta support, security, and compatibility language.
|
||||
- [x] Establish the historical public pre-beta Linux/Windows evidence baseline.
|
||||
- [x] Rerun the supported Go matrix and deterministic generation on the exact
|
||||
Beta 1 candidate.
|
||||
- [x] Run the candidate-version freshness, bounded fuzz, vulnerability, and
|
||||
@@ -79,12 +79,10 @@ dependency, and its interfaces may change.
|
||||
`v1.0.0-beta.1`, from the same reviewed public commit.
|
||||
- [x] Verify clean runtime-first direct and public-proxy installs and record the
|
||||
result.
|
||||
- [ ] Add native macOS maintainer evidence before RC; community reports inform
|
||||
that work but do not replace maintainer responsibility.
|
||||
|
||||
## Milestone 1: contract freeze
|
||||
|
||||
Required before security/platform release-candidate work is declared complete:
|
||||
Required before security/Linux release-candidate work is declared complete:
|
||||
|
||||
- [ ] Decide and specify whether generic component function signatures are v1.
|
||||
- [ ] Inventory and freeze every exported `sando` symbol, trusted type,
|
||||
@@ -97,11 +95,11 @@ Required before security/platform release-candidate work is declared complete:
|
||||
output compatibility snapshots.
|
||||
- [ ] Define the v1 deprecation and security-support policy.
|
||||
|
||||
## Milestone 2: security and native-platform evidence
|
||||
## Milestone 2: security and Linux release evidence
|
||||
|
||||
- [ ] Run the minimum supported Go line and the latest two stable Go lines on
|
||||
native Linux, macOS, and Windows hosts.
|
||||
- [ ] Prove identical generated bytes across those hosts and exercise native
|
||||
Linux/amd64 runners and a Linux deployment-class host.
|
||||
- [ ] Prove identical generated bytes across those Linux lanes and exercise
|
||||
path, replacement, permission, race, process-tree, and watcher behavior.
|
||||
- [ ] Build a systematic differential corpus against Go's documented
|
||||
`html/template` safety baseline for overlapping supported contexts.
|
||||
@@ -147,7 +145,7 @@ Required before security/platform release-candidate work is declared complete:
|
||||
2. Publish signed `sando/v1.0.0-rc.1`, then signed `v1.0.0-rc.1` from the same
|
||||
reviewed public Gitea commit.
|
||||
3. Verify documented installs through fresh `GOPROXY=direct` and
|
||||
`proxy.golang.org` caches on supported Go versions and native platforms.
|
||||
`proxy.golang.org` caches on supported Go versions under Linux/amd64.
|
||||
4. Run the complete evidence suite again from the exact public commit.
|
||||
5. Operate the official Sandwich Hime website on the RC runtime for a 14-day
|
||||
observation period with no unresolved Hime render, security, accessibility,
|
||||
@@ -172,6 +170,6 @@ marketing. New features do not outrank a small stable contract.
|
||||
## Definition of confidence
|
||||
|
||||
“Ready for v1” means a reviewer can trace each promise to a stable public
|
||||
contract, executable evidence from supported native environments, and a signed
|
||||
contract, executable evidence from supported Linux environments, and a signed
|
||||
artifact built from the exact canonical source. It does not mean perfect,
|
||||
invulnerable, or finished forever.
|
||||
|
||||
+7
-3
@@ -2,10 +2,11 @@
|
||||
|
||||
# Repository verification tools
|
||||
|
||||
These scripts are intentionally understandable shell and PowerShell rather than a release framework with hidden defaults.
|
||||
These scripts are intentionally understandable shell rather than a release
|
||||
framework with hidden defaults. The maintained verification and release path
|
||||
is Linux.
|
||||
|
||||
- `verify.sh` runs root and nested-module tests and vet, builds `himesan`, checks the compiler-owned golden output, and proves two generation passes leave the same bytes and unchanged modification times. Set `HIMESAN_RACE=1` for race tests.
|
||||
- `verify.ps1` provides the equivalent native Windows lane; pass `-Race` to include the race detector.
|
||||
- `check-licenses.sh` enforces the AGPL compiler / Apache runtime boundary and prevents generated application Go from inheriting an AGPL identifier.
|
||||
- `release-check.sh --version vX.Y.Z` is a clean-checkout technical preflight, including exact candidate-version and generated-provenance checks. Beta publication follows the narrower prerelease gates in `RELEASE.md`; release candidates and final v1 additionally use `--public` with a human-reviewed `HIMESAN_RELEASE_EVIDENCE_DIR`. The script never tags, pushes, publishes, or deploys.
|
||||
- `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes, adds the nested runtime before installing the parent compiler, and exercises fresh direct-fetch and public-proxy caches without interactive Git credentials.
|
||||
@@ -16,6 +17,9 @@ The release preflight invokes `govulncheck` from the official Go vulnerability p
|
||||
|
||||
## Preview automation status
|
||||
|
||||
Forge workflows are intentionally excluded from the sanitized pre-1.0 public snapshot until the project has confirmed its own Gitea runner availability and reviewed locally hosted or otherwise pinned dependencies. Local `verify.sh`, `verify.ps1`, license, and release-preflight results are the preview gates.
|
||||
Forge workflows are intentionally excluded from the sanitized pre-1.0 public
|
||||
snapshot. The private development repository uses pinned Linux runners; the
|
||||
public source remains independently verifiable with `verify.sh`, the license
|
||||
check, and the Linux release preflight.
|
||||
|
||||
If Gitea automation is later added to the public repository, pin every external action to a reviewed immutable commit, document its provenance, grant minimum permissions, and keep a local verification path. A secondary forge may host a sanitized, read-only discovery snapshot, but hosted workflows stay disabled there and it does not become a release or contribution authority.
|
||||
|
||||
@@ -253,23 +253,14 @@ go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./...
|
||||
go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./...
|
||||
)
|
||||
|
||||
printf '\n==> cross-compiling release binary smoke set\n'
|
||||
printf '\n==> building supported Linux release binary\n'
|
||||
for target in \
|
||||
linux/amd64 \
|
||||
linux/arm64 \
|
||||
darwin/amd64 \
|
||||
darwin/arm64 \
|
||||
windows/amd64 \
|
||||
windows/arm64; do
|
||||
linux/amd64; do
|
||||
target_os=${target%/*}
|
||||
target_arch=${target#*/}
|
||||
extension=''
|
||||
if [[ "$target_os" == windows ]]; then
|
||||
extension='.exe'
|
||||
fi
|
||||
CGO_ENABLED=0 GOOS="$target_os" GOARCH="$target_arch" \
|
||||
go build -trimpath -ldflags "$compiler_linker_flags" \
|
||||
-o "$artifact_dir/himesan-$target_os-$target_arch$extension" ./cmd/himesan
|
||||
-o "$artifact_dir/himesan-$target_os-$target_arch" ./cmd/himesan
|
||||
done
|
||||
|
||||
for required in \
|
||||
@@ -289,7 +280,7 @@ if (( public_release == 1 )); then
|
||||
fi
|
||||
for evidence in \
|
||||
legal-review.md \
|
||||
cross-platform.md \
|
||||
linux-platform.md \
|
||||
security.md \
|
||||
development-supervisor.md \
|
||||
benchmark-methodology.md \
|
||||
|
||||
@@ -1,133 +0,0 @@
|
||||
# SPDX-License-Identifier: AGPL-3.0-only
|
||||
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[switch]$Race
|
||||
)
|
||||
|
||||
$ErrorActionPreference = "Stop"
|
||||
$RepoRoot = (Resolve-Path (Join-Path $PSScriptRoot "..")).Path
|
||||
Set-Location $RepoRoot
|
||||
|
||||
function Invoke-Checked {
|
||||
param(
|
||||
[Parameter(Mandatory = $true)]
|
||||
[string]$Label,
|
||||
[Parameter(Mandatory = $true)]
|
||||
[scriptblock]$Command
|
||||
)
|
||||
|
||||
Write-Host "`n==> $Label"
|
||||
& $Command
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "$Label failed with exit code $LASTEXITCODE"
|
||||
}
|
||||
}
|
||||
|
||||
function Invoke-ModuleChecks {
|
||||
param(
|
||||
[Parameter(Mandatory = $true)]
|
||||
[string]$Directory,
|
||||
[Parameter(Mandatory = $true)]
|
||||
[string]$Label
|
||||
)
|
||||
|
||||
Push-Location $Directory
|
||||
try {
|
||||
Invoke-Checked "$Label`: go test" { go test ./... }
|
||||
Invoke-Checked "$Label`: go vet" { go vet ./... }
|
||||
}
|
||||
finally {
|
||||
Pop-Location
|
||||
}
|
||||
}
|
||||
|
||||
function Get-SandoSources {
|
||||
if (-not (Test-Path "internal/compiler/testdata/golden" -PathType Container)) {
|
||||
return @()
|
||||
}
|
||||
|
||||
return @(Get-ChildItem "internal/compiler/testdata/golden" -File -Filter "*.sando" |
|
||||
Sort-Object FullName)
|
||||
}
|
||||
|
||||
function Get-GeneratedManifest {
|
||||
$lines = foreach ($source in (Get-SandoSources)) {
|
||||
$output = "$($source.FullName).go"
|
||||
if (-not (Test-Path $output -PathType Leaf)) {
|
||||
"missing $output"
|
||||
continue
|
||||
}
|
||||
$hash = (Get-FileHash -Algorithm SHA256 $output).Hash.ToLowerInvariant()
|
||||
$modified = (Get-Item -LiteralPath $output).LastWriteTimeUtc.Ticks
|
||||
"$hash $modified $output"
|
||||
}
|
||||
return ($lines -join "`n")
|
||||
}
|
||||
|
||||
$TempRoot = Join-Path ([System.IO.Path]::GetTempPath()) ("himesan-verify-" + [guid]::NewGuid())
|
||||
New-Item -ItemType Directory -Path $TempRoot | Out-Null
|
||||
|
||||
try {
|
||||
Invoke-ModuleChecks "." "compiler module"
|
||||
Invoke-Checked "compiler module: go build" {
|
||||
go build -trimpath -o (Join-Path $TempRoot "himesan.exe") ./cmd/himesan
|
||||
}
|
||||
|
||||
if (-not (Test-Path "sando/go.mod" -PathType Leaf)) {
|
||||
throw "nested Apache runtime module sando/go.mod is missing"
|
||||
}
|
||||
Invoke-ModuleChecks "sando" "sando runtime module"
|
||||
|
||||
$Sources = @(Get-SandoSources)
|
||||
if ($Sources.Count -eq 0) {
|
||||
throw "compiler-owned golden .sando fixture is missing"
|
||||
}
|
||||
else {
|
||||
$SourcePaths = @($Sources | ForEach-Object { $_.FullName })
|
||||
$CheckArgs = @("run", "./cmd/himesan", "check") + $SourcePaths
|
||||
$GenerateArgs = @("run", "./cmd/himesan", "generate") + $SourcePaths
|
||||
Invoke-Checked "golden generation: read-only freshness check" {
|
||||
& go $CheckArgs
|
||||
}
|
||||
$Before = Get-GeneratedManifest
|
||||
|
||||
Invoke-Checked "golden generation: first deterministic pass" {
|
||||
& go $GenerateArgs
|
||||
}
|
||||
$First = Get-GeneratedManifest
|
||||
if ($Before -cne $First) {
|
||||
throw "generation changed committed output after check declared it fresh"
|
||||
}
|
||||
|
||||
Invoke-Checked "golden generation: second deterministic pass" {
|
||||
& go $GenerateArgs
|
||||
}
|
||||
$Second = Get-GeneratedManifest
|
||||
if ($First -cne $Second) {
|
||||
throw "repeated generation changed output bytes or an unchanged timestamp"
|
||||
}
|
||||
|
||||
Invoke-Checked "golden generation: final freshness check" {
|
||||
& go $CheckArgs
|
||||
}
|
||||
}
|
||||
|
||||
if ($Race) {
|
||||
Invoke-Checked "compiler module: race tests" { go test -race ./... }
|
||||
Push-Location "sando"
|
||||
try {
|
||||
Invoke-Checked "sando runtime module: race tests" { go test -race ./... }
|
||||
}
|
||||
finally {
|
||||
Pop-Location
|
||||
}
|
||||
}
|
||||
|
||||
Write-Host "`n==> verification complete"
|
||||
}
|
||||
finally {
|
||||
if (Test-Path $TempRoot -PathType Container) {
|
||||
Remove-Item -LiteralPath $TempRoot -Recurse -Force
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user