Prepare Sandwich Hime v1.0.0-rc.1 source

This commit is contained in:
2026-08-24 13:21:14 -04:00
parent efd5b997ed
commit e730dd1b56
8 changed files with 128 additions and 93 deletions
+35 -8
View File
@@ -8,20 +8,47 @@ one coordinated release.
## Unreleased
No changes have been accepted after the first v1 release candidate.
## v1.0.0-rc.1 — 2026-08-24
The first release candidate coordinates compiler `v1.0.0-rc.1` and runtime
`sando/v1.0.0-rc.1` at runtime ABI `sando.v1`. The intended v1 language,
generated API, runtime API, CLI, diagnostics, and schemas are frozen except for
release-blocking corrections.
### Added
- Maintained native Linux/amd64 and Apple Silicon macOS/arm64 verification on
pinned Go 1.26.7 and Go 1.27.0 toolchains.
- Reproducible Linux and Darwin archives with checksums, SPDX SBOMs, manifests,
build provenance, and exact public-source identities.
- A Developer ID-signed, notarized, and stapled macOS disk image for the native
arm64 compiler.
- Exact contract snapshots, contextual-escaping differentials, real-browser
compiler and development-supervisor evidence, long fuzz evidence, and
repository-owned benchmark evidence.
- Standard-library-only LSP diagnostics, hover, document symbols, component
completion, and go-to-definition retained from Beta 2 as part of the frozen
v1 command surface.
### Changed
- Linux/amd64 is the maintained execution, verification, artifact, and release
target. WSL remains a Linux development environment; native Windows, macOS,
and other targets are best-effort portability surfaces rather than release
gates or compatibility promises.
- Release preflight now builds the supported Linux/amd64 candidate only and
requires Linux platform evidence for RC/final publication.
- Linux/amd64 and Apple Silicon macOS/arm64 are the maintained execution,
verification, artifact, and release targets. WSL, native Windows, Intel
macOS, Linux/arm64, and other targets remain useful portability surfaces but
are not v1 compatibility promises.
- The module language directive remains Go 1.25 for consumer compatibility;
maintained release builds use the pinned patched Go 1.26 and Go 1.27 lines.
- Release evidence is bound to the exact sanitized public commit and tree.
GitHub remains an untagged discovery snapshot; Gitea remains the source,
contribution, module, tag, and artifact authority.
### Removed
- The native Windows PowerShell verifier and private multi-OS release-gate
workflow. Historical platform evidence and best-effort portability code are
retained without creating a support obligation.
workflow. Historical Windows evidence remains recorded without creating a
current support obligation.
## v1.0.0-beta.2 — 2026-08-12
+1 -1
View File
@@ -1 +1 @@
{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":125,"allowlist_sha256":"b320a95ca85f48941ee956fde1eda46e0d9bc664da21d13c5f65a8f623063ed5","manifest_sha256":"882a7147949ab827f11102095dbe6cbd75811336e677192969c3abb25ffb0001"}
{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":125,"allowlist_sha256":"b320a95ca85f48941ee956fde1eda46e0d9bc664da21d13c5f65a8f623063ed5","manifest_sha256":"6f9f21ff9ff641de9765f0491edd7e9f173d718454fe68f32c6379f5331d9c13"}
+6 -6
View File
@@ -2,7 +2,7 @@
658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes
d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore
98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md
5bc3db089eb243640adc2e4bae62d94754aff420d1eb64057036032dfd9a626b ./CHANGELOG.md
954fb577484d5ca95f3fedb80d967ec6012ed4ed24fb7d999174f1b163697c80 ./CHANGELOG.md
b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md
797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md
86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT
@@ -13,10 +13,10 @@ a4570d054f072d33b8f17b0c8b162a6ee0ca37d7df2b1aee7e4b728ab350a892 ./GOVERNANCE.m
9957e4aea02effb4d4b8012a3cc0e2d6ee1ce8be3761555c2c3e8aee27a5ee08 ./LICENSES.md
b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md
6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md
de0d4945a8246edc8da46fbc54f18349c45b6b08069309d071cb33127aee101d ./README.md
80de7a9ede0fbe2f364456e72b08c5a4b965ea656eaab63f3e1d246abeb9c01e ./README.md
14fbed2a6de1496d7ad3783bac1b79f3f340de72545fe0dcf39de829622d7d32 ./RELEASE.md
c0e65a8bffcba71cd42d6122be25fd4993c04c8cba8c5e69108c9f5dbaca9243 ./ROADMAP.md
813e329cfc692c0a341c47a12e2950b0c2ee403b739ad763a204d678a27765b5 ./SECURITY.md
d4ae7927633d42851581d2bcbc94777aef9853b4880883cc50bfc94ce0c78842 ./ROADMAP.md
b9ee0e394494a66ba6291a8e06a14fd159ba9fb3f46997e1b2de03e1cc2ef77c ./SECURITY.md
d566b8b27777cb33209602df81d654a94072ad875440c089ac41764a349b6c17 ./SPEC.md
3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md
e2ce8cbc43e4575984839b61332207f7c90e2848fa270d4c68dbc5fc394f28e7 ./cmd/himesan-release/main.go
@@ -32,13 +32,13 @@ e6fb36b274bf44143497b2af454e9ee0fabe6122f935cbf97e785a003277e211 ./contracts/hi
1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md
9e4f5a80afbffe51dda3e7f9fa5221e3ef4ca516c4b7f7ca33b61ac97ff213bb ./docs/BENCHMARKS.md
5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md
8627f689faa123507102e3c2114c368f905580ea2b0151c717860de9cfa7a4b0 ./docs/COMPATIBILITY.md
60f0c1257cfce8388a252a105042be57c2978820d37ef81e46c6d3a49474fde3 ./docs/COMPATIBILITY.md
d1b4ef192e02b59a9d8d0eb3b1072392e633116433fa308f6ca9bbe17b75e213 ./docs/DEVELOPMENT_SERVER.md
4d92dc88ef33d4f7d952de039f842e54a3f3bfb4dbe56debf7ddb6e6c4a428f6 ./docs/DIAGNOSTICS.md
a62cc7174f3c92d8ef77e4bd9607fbf5d4b80bc514ff05bd433c02a9b0578f18 ./docs/LANGUAGE_SERVER.md
32253dbe59d9b0da40354b48c2e54feb8c38d441b41efba046125571d3dabb50 ./docs/SECURITY_EVIDENCE.md
e600caf17a87997de330ca787bfc5f16c1b20e07f467f8d1ad450e96e2421910 ./docs/THREAT_MODEL.md
280e5d78f5bead40f10308b750c725d2b2aca00aaf435aa07419bbc290b37fb0 ./docs/V1_RELEASE_PLAN.md
978c6fdb8ed82aa2b118bbfb3d6217adf8edf425370ecdffdfc96ac24a9cbdce ./docs/V1_RELEASE_PLAN.md
f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod
ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go
d891b9b075617050471b2ca34de73d926aaebde4ec638a5039b0d5001d3172f4 ./internal/compiler/analysis.go
+19 -17
View File
@@ -42,11 +42,12 @@ request object, or production server.
## Status
`v1.0.0-beta.2` is the current compiler beta. It is supported for
learning, classroom projects, evaluation, and compatibility feedback. It is a
semantic-version prerelease: source syntax, generated output, the runtime API,
and CLI behavior may change before final v1, and this beta is not recommended
for production deployment.
`v1.0.0-rc.1` is the current release candidate for both the compiler and the
independently tagged runtime. The intended v1 source syntax, generated API,
runtime API, CLI, diagnostics, and schemas are frozen except for
release-blocking corrections. It remains a semantic-version prerelease while
the project completes its public observation period; a finding is fixed in a
new RC rather than by moving either tag.
Linux/amd64 and Apple Silicon macOS/arm64 are the maintained v1 execution and
release targets. Native release evidence runs with pinned Go 1.26.7 and Go
@@ -63,13 +64,13 @@ decisions on both supported native targets.
Inside an application module, add the small runtime first:
```sh
go get gamertan.com/sandwich-hime/sando@v1.0.0-beta.1
go get gamertan.com/sandwich-hime/sando@v1.0.0-rc.1
```
Then install the current beta compiler:
Then install the matching release-candidate compiler:
```sh
go install gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-beta.2
go install gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-rc.1
```
Keep that runtime-first order. It avoids path-selection ambiguity between the
@@ -80,22 +81,23 @@ does not contain `sando`, seed the exact nested module without clearing the
global cache, then retry:
```sh
go mod download gamertan.com/sandwich-hime/sando@v1.0.0-beta.1
go get gamertan.com/sandwich-hime/sando@v1.0.0-beta.1
go mod download gamertan.com/sandwich-hime/sando@v1.0.0-rc.1
go get gamertan.com/sandwich-hime/sando@v1.0.0-rc.1
```
For a reproducible one-off or classroom invocation that does not depend on the
learner's `PATH`:
```sh
go run gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-beta.2 --help
go run gamertan.com/sandwich-hime/cmd/himesan@v1.0.0-rc.1 --help
```
The unchanged runtime remains `sando/v1.0.0-beta.1`; compiler versions are
independent. Beta 2 adds `himesan lsp --stdio` without changing the runtime ABI.
Signed compiler tags, direct fetching, the public Go proxy, and the checksum
database are verified after publication. A newly announced version may still
need a short propagation interval before every proxy sees its immutable tag.
The runtime implementation retains ABI `sando.v1` and zero third-party module
requirements. The coordinated RC tags make the intended v1 pair explicit even
though compiler and runtime versions remain independently addressable. Signed
tags, direct fetching, the public Go proxy, and the checksum database are
verified after publication. A newly announced version may still need a short
propagation interval before every proxy sees its immutable tag.
For repository development:
@@ -113,7 +115,7 @@ and serves it through `http://127.0.0.1:7331` with local-only reload
diagnostics. That is a Cole-shaped convenience, not a production server or a
requirement. Take the paved path—or don't.
Beta 2 also provides a standard, editor-neutral language server. It analyzes
Hime-san also provides a standard, editor-neutral language server. It analyzes
unsaved overlays with the compiler's real parser and context model, but never
generates, runs Go, executes a project, fetches a module, accesses the network,
or starts the dev supervisor. See
+20 -19
View File
@@ -26,41 +26,42 @@ it is not a production-stability promise.
## Compiler and runtime for RC/final
- [ ] Freeze and machine-check the compiler, CLI, diagnostic, schema, generated,
- [x] Freeze and machine-check the compiler, CLI, diagnostic, schema, generated,
and runtime compatibility contracts.
- [ ] Repeat compiler-owned deterministic golden output across the supported
Linux and Go lanes on the exact candidate.
- [ ] Compile temporary consumer modules using committed Go and only the Apache
- [x] Repeat compiler-owned deterministic golden output across the supported
Linux and macOS Go lanes on the exact candidate.
- [x] Compile temporary consumer modules using committed Go and only the Apache
runtime.
- [ ] Run the parser, delimiter, context, path, and source-map release fuzz
- [x] Run the parser, delimiter, context, path, and source-map release fuzz
campaign.
- [ ] Evidence adversarial escaping and filesystem cases.
- [ ] Pass test, race, vet, vulnerability, and license gates on the latest two
- [x] Evidence adversarial escaping and filesystem cases.
- [x] Pass test, race, vet, vulnerability, and license gates on the latest two
supported Go lines.
- [ ] Reproduce signed compiler/runtime release artifacts, checksums, and SBOMs.
- [x] Reproduce compiler/runtime release artifacts, checksums, and SBOMs; sign
and notarize the macOS distribution outside runner authority.
## Development supervisor for RC/final
- [ ] Generation/build/start/health failures keep the previous healthy server
- [x] Generation/build/start/health failures keep the previous healthy server
live.
- [ ] SSE reconnect/reload and mapped overlay diagnostics pass browser-level
- [x] SSE reconnect/reload and mapped overlay diagnostics pass browser-level
tests.
- [ ] CSP hash injection, fragment/API/download exclusion, and cache disabling
- [x] CSP hash injection, fragment/API/download exclusion, and cache disabling
pass.
- [ ] Replaced and interrupted child processes leave no descendants on
- [x] Replaced and interrupted child processes leave no descendants on
supported systems.
## Repository-owned release evidence
- [ ] Differentially test contextual escaping against Go's documented
- [x] Differentially test contextual escaping against Go's documented
`html/template` safety baseline.
- [ ] Reproduce repository-owned synthetic benchmark cases and methodology from
- [x] Reproduce repository-owned synthetic benchmark cases and methodology from
a clean checkout.
- [ ] Review generated output for stable provenance, source mappings, and
- [x] Review generated output for stable provenance, source mappings, and
absence of compiler-license headers.
- [ ] Document the production boundary: committed generated Go plus the Apache
- [x] Document the production boundary: committed generated Go plus the Apache
runtime, with no compiler or development supervisor in the deployed binary.
- [ ] Keep unsupported or unmeasured performance and production claims out of
- [x] Keep unsupported or unmeasured performance and production claims out of
release materials.
## Final public launch
@@ -69,9 +70,9 @@ it is not a production-stability promise.
contribution process, and pre-registration trademark terms.
- [ ] Complete name clearance, security-mailbox recovery, release signing, and
two-person credential recovery.
- [ ] Verify `gamertan.com` vanity metadata and documented installs from clean
- [ ] Verify `gamertan.com` vanity metadata and documented RC installs from clean
machines.
- [ ] Confirm the sanitized public Gitea source contains no private paths,
identifiers, history, or unsupported claims.
- [ ] Publish and observe a signed RC on the supported Linux/amd64 target.
- [ ] Publish and observe signed RC artifacts on Linux/amd64 and Darwin/arm64.
- [ ] Publish `sando/v1.0.0`, then `v1.0.0`, without moving either tag.
+16 -15
View File
@@ -2,12 +2,13 @@
# Security policy
Sandwich Hime compiler `v1.0.0-beta.2` and runtime
`sando/v1.0.0-beta.1` are supported within a deliberately narrow scope:
learning, classroom projects, evaluation, and compatibility testing.
Security reports are welcome and receive best-effort maintainer assessment and
fixes while this pair is current. This is not production support,
an SLA, a fitness guarantee, or a promise that a fix will preserve beta APIs.
Sandwich Hime compiler `v1.0.0-rc.1` and runtime
`sando/v1.0.0-rc.1` are the current release-candidate pair. The intended v1
interfaces are frozen except for release-blocking corrections while the RC
completes its public observation period. Security reports are welcome and
receive best-effort maintainer assessment and fixes while this pair is current.
This is not an SLA, certification, fitness guarantee, or final-v1 support
promise.
The community is invited to help find portability gaps outside the maintained
Linux/amd64 and Darwin/arm64 targets, but those reports do not create a support
@@ -20,11 +21,12 @@ advisories, and release decisions.
| Version | Security status |
| --- | --- |
| `v1.0.0-beta.2` compiler and `sando/v1.0.0-beta.1` runtime | Current evaluation/classroom prerelease pair; best-effort security assessment and fixes; interfaces may change |
| `v1.0.0-rc.1` compiler and `sando/v1.0.0-rc.1` runtime | Current release-candidate pair; intended v1 interfaces frozen except for release-blocking corrections; best-effort security assessment and fixes during the RC observation period |
| `v1.0.0-beta.2` compiler and `sando/v1.0.0-beta.1` runtime | Superseded evaluation/classroom pair after RC publication |
| Public `main` | Development source; reports welcome, but no compatibility or production-support promise |
| Older prereleases | Superseded when a newer prerelease or final version is published; reports are still triaged to determine affected versions |
Beta support lasts until it is superseded or explicitly withdrawn in the
Prerelease support lasts until it is superseded or explicitly withdrawn in the
supported-version table and release notes. Published tags are immutable. A
security fix is issued as a new version, never by silently replacing a tag.
@@ -158,17 +160,16 @@ an independent security audit, certification, or formal verification. Coverage
percentages, passing scanners, and a clean vulnerability database result are
evidence of specific checks—not proof that no vulnerability exists.
The Beta 2 language server is read-only and standard-library-only. Its tests
The language server is read-only and standard-library-only. Its tests
exercise bounded framing, malformed messages, cancellation, UTF-16 positions,
unsaved overlays, workspace re-indexing, and no generated writes. Source review
forbids process execution and network-client imports inside the server. Editor
workspace trust and executable resolution remain editor-client responsibilities.
Beta 1 uses signed annotated source tags, but precedes the
complete prebuilt-artifact and key-recovery system. Signed binaries, checksums,
an SBOM, reproducible archives, and complete source/build provenance are
release-candidate and final-v1 gates. Their absence from a source-only beta must
not be read as evidence of artifact authenticity beyond the verified tag and
canonical source.
Beta 1 uses signed annotated source tags but predates the complete artifact
system. The RC adds signed or checksummed binaries, SPDX SBOMs, reproducible
archives, and source/build provenance. Those controls establish artifact
identity and provenance; they do not constitute an independent security audit
or prove the absence of vulnerabilities.
This policy is practical project guidance, not legal advice.
+9 -10
View File
@@ -2,19 +2,18 @@
# Compatibility policy
## Beta contract
## Current release-candidate contract
Compiler `v1.0.0-beta.2` and runtime `sando/v1.0.0-beta.1` are semantic-version
prereleases. They are supported for learning, classroom projects, evaluation,
and compatibility testing. Before final v1, source syntax, generated output,
the runtime API, CLI behavior, diagnostics, and configuration may change
without compatibility shims. Every public change must still be documented and
generation must remain deterministic.
Compiler `v1.0.0-rc.1` and runtime `sando/v1.0.0-rc.1` are the current
semantic-version prereleases. The intended v1 source syntax, generated API,
runtime API, CLI behavior, diagnostics, and configuration schemas are frozen
except for release-blocking corrections. Every correction receives a new
immutable RC, documentation, and deterministic generation evidence.
The beta is not a production-stability commitment. Maintainers accept and
The RC is not yet the final-v1 support commitment. Maintainers accept and
triage security reports within the boundary described in
[SECURITY.md](../SECURITY.md), but cannot promise that a beta fix preserves its
public API.
[SECURITY.md](../SECURITY.md). A security correction may intentionally fail
closed when retaining behavior would contradict a published safety guarantee.
## Final-v1 contract
+22 -17
View File
@@ -51,18 +51,23 @@ Other demonstrated controls include:
- loopback-only, browser-origin-hardened development proxy behavior; and
- a public threat model, security policy, and dated evidence ledger.
### Not demonstrated yet
### Demonstrated for the first RC candidate
- final Linux/amd64 and Darwin/arm64 release-candidate evidence on the exact
canonical candidate;
- native Linux/amd64 and Darwin/arm64 release-candidate lanes on pinned Go
1.26.7 and Go 1.27.0 toolchains;
- exact-public-candidate execution of the committed real-browser generated
document and development-supervisor gate on both maintained hosts;
document and development-supervisor gates;
- a long semantic fuzz campaign beyond bounded no-panic smoke;
- exact-candidate comparative benchmark results on both maintained targets;
- deterministic prebuilt archives, checksums, SBOMs, signed binaries, and
tested signing/recovery procedures; or
- independently reproduced Linux and macOS release artifacts, checksums, and
SBOMs.
- exact-candidate comparative benchmark results;
- deterministic prebuilt archives, checksums, SPDX SBOMs, and provenance;
- Developer ID signing, notarization, stapling, and Gatekeeper validation for
the Darwin/arm64 distribution; and
- byte-identical generated output and independently reproduced release
archives across the maintained native evidence lanes.
The final immutable tags, clean direct/proxy installation, credential-recovery
drills, and public observation period remain publication or post-publication
gates rather than properties that source code can prove by itself.
## Beta 1 publication lane
@@ -99,16 +104,16 @@ Required before security/native release-candidate work is declared complete:
## Milestone 2: security and native release evidence
- [ ] Run the pinned patched Go 1.26 and Go 1.27 lines on Linux/amd64 and
- [x] Run the pinned patched Go 1.26 and Go 1.27 lines on Linux/amd64 and
native Darwin/arm64 runners, plus a Linux deployment-class host.
- [ ] Prove identical generated bytes across both native platforms and exercise
- [x] Prove identical generated bytes across both native platforms and exercise
path, replacement, permission, race, process-tree, and watcher behavior.
- [x] Build a systematic differential corpus against Go's documented
`html/template` safety baseline for overlapping supported contexts.
- [x] Commit a real-browser gate that generates and builds a representative
typed document, then tests parsed structure and hostile-value inertness in
Chrome rather than relying only on byte equality.
- [ ] Extend semantic fuzzing across delimiters, HTML transitions, imports,
- [x] Extend semantic fuzzing across delimiters, HTML transitions, imports,
paths, source maps, URL normalization, and filesystem operations.
- [ ] Resolve or explicitly accept every open item in
`SECURITY_EVIDENCE.md`; no accepted item may contradict a public guarantee.
@@ -120,23 +125,23 @@ Required before security/native release-candidate work is declared complete:
- [x] Commit a synthetic, repository-owned benchmark corpus comparing
equivalent typed views and output with `html/template`.
- [x] Define “no material regression” before measuring the release candidate.
- [ ] Measure the exact release candidate and publish hardware, OS, Go version,
- [x] Measure the exact release candidate and preserve hardware, OS, Go version,
commands, samples, allocations, and output equivalence with every result.
- [x] Commit a real-browser development-supervisor gate covering SSE
diagnostics, reload, CSP behavior, fragment/API exclusions, caching, and
child cleanup.
- [ ] Execute the committed browser gate on the exact public candidate on both
- [x] Execute the committed browser gate on the exact public candidate on both
maintained hosts and preserve the browser identities and results.
- [ ] Remove any v1 development-supervisor guarantee that cannot be evidenced
reliably instead of substituting prose for a test.
## Milestone 4: release rehearsal
- [ ] Make version validation identical in the CLI, generated headers, scripts,
- [x] Make version validation identical in the CLI, generated headers, scripts,
and release artifacts; reject ambiguous build metadata.
- [ ] Build the candidate compiler at its candidate version and prove its
- [x] Build the candidate compiler at its candidate version and prove its
committed outputs are current under that exact binary.
- [ ] Produce deterministic archives/binaries, checksums, SBOMs, signatures,
- [x] Produce deterministic archives/binaries, checksums, SBOMs, signatures,
and source/build provenance from a clean sanitized canonical checkout.
- [ ] Test release-key backup and two-person recovery for Gitea, domains,
signing material, and publication instructions.