From c11552b87a2dff9d3be0b241cdba1710df131aa1 Mon Sep 17 00:00:00 2001 From: Cole Speelman Date: Sun, 16 Aug 2026 17:50:00 -0400 Subject: [PATCH] policy: maintain Linux as the release target Publishes the exact allowlisted snapshot from the private Beta 2 development line. Historical platform evidence remains truthful; native Windows and macOS are no longer release gates or support promises. Material AI assistance was reviewed by the maintainer. Signed-off-by: Cole Speelman --- CHANGELOG.md | 17 +++++ PUBLIC-SNAPSHOT.json | 2 +- PUBLIC-SNAPSHOT.sha256 | 23 ++++--- README.md | 18 ++++-- RELEASE.md | 35 +++++----- ROADMAP.md | 20 +++--- SECURITY.md | 5 +- docs/COMPATIBILITY.md | 37 ++++++----- docs/SECURITY_EVIDENCE.md | 37 ++++++----- docs/THREAT_MODEL.md | 2 +- docs/V1_RELEASE_PLAN.md | 36 +++++------ scripts/README.md | 10 ++- scripts/release-check.sh | 17 ++--- scripts/verify.ps1 | 133 -------------------------------------- 14 files changed, 142 insertions(+), 250 deletions(-) delete mode 100644 scripts/verify.ps1 diff --git a/CHANGELOG.md b/CHANGELOG.md index efb9d42..2986a1b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,23 @@ Sandwich Hime follows semantic versioning after final v1. Compiler and nested runtime releases are versioned independently and listed together when they form one coordinated release. +## Unreleased + +### Changed + +- Linux/amd64 is the maintained execution, verification, artifact, and release + target. WSL remains a Linux development environment; native Windows, macOS, + and other targets are best-effort portability surfaces rather than release + gates or compatibility promises. +- Release preflight now builds the supported Linux/amd64 candidate only and + requires Linux platform evidence for RC/final publication. + +### Removed + +- The native Windows PowerShell verifier and private multi-OS release-gate + workflow. Historical platform evidence and best-effort portability code are + retained without creating a support obligation. + ## v1.0.0-beta.2 — 2026-08-12 Compiler-only release; the unchanged Apache runtime remains diff --git a/PUBLIC-SNAPSHOT.json b/PUBLIC-SNAPSHOT.json index 96bafa4..f5fc685 100644 --- a/PUBLIC-SNAPSHOT.json +++ b/PUBLIC-SNAPSHOT.json @@ -1 +1 @@ -{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":90,"allowlist_sha256":"393ee598dc7e12cdbb603887bf06599e46b40d7c19e4ff693a818cc32afb01ec","manifest_sha256":"38a02b05cec70c82076df0f40de8b98edfc9280f54c12fa0cbe84949da253fdf"} +{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":89,"allowlist_sha256":"2947ef034f9bfe9bd20c00e67d0033f0ff5e62e55fc2db0952696485d9eeec40","manifest_sha256":"5005a799e84f5cbb66cc9d0ced03c5897924de1b9c28adf8aaf06b2ddb4affff"} diff --git a/PUBLIC-SNAPSHOT.sha256 b/PUBLIC-SNAPSHOT.sha256 index 2a95e2a..182d42a 100644 --- a/PUBLIC-SNAPSHOT.sha256 +++ b/PUBLIC-SNAPSHOT.sha256 @@ -2,7 +2,7 @@ 658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore 98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md -0828545d3aa440e1ec5dce4b934de6800413f55a925988b60923c5ee9b700a4e ./CHANGELOG.md +5bc3db089eb243640adc2e4bae62d94754aff420d1eb64057036032dfd9a626b ./CHANGELOG.md b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md 797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md 86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT @@ -13,10 +13,10 @@ a4570d054f072d33b8f17b0c8b162a6ee0ca37d7df2b1aee7e4b728ab350a892 ./GOVERNANCE.m 47d857e49f89596bac9b09fc8ca57a668a33d01e2b51508acfc92ed321cdc27f ./LICENSES.md b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md 6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md -c3ac873ae2e6248e1d86dd542a11557b24b8dba80e4785f3bc1018152020235c ./README.md -2751674c180f15a42c1d2b40cf149be4138aa6cf247d7be176f1f0c468103c24 ./RELEASE.md -209decb6769646eb2f58e312fbcd9c497c26234f3d3115bae3f20493b8178584 ./ROADMAP.md -0fef473ac46b71215d1eb7922da4594210ffbbb8bb2dedd5e531fb3bd09396e1 ./SECURITY.md +fbc4a7c118ac983a1ea49dc3a9d714f5130ace21a8af59ab9fcabd6519cb6b97 ./README.md +fafa1494fa1a5a5cf3b3d371155f0448d46f1f13cd394555e06396b336bc102a ./RELEASE.md +c0e65a8bffcba71cd42d6122be25fd4993c04c8cba8c5e69108c9f5dbaca9243 ./ROADMAP.md +17e10aaab589d40b479e374523982117d2c7ffac95306493cfa4e3171108a1a8 ./SECURITY.md 53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md 3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md 8cd8db68e1300f9b78cc7235855853cbc7aeb499a921419e23a22e4d22826fcb ./cmd/himesan/main.go @@ -24,13 +24,13 @@ c3ac873ae2e6248e1d86dd542a11557b24b8dba80e4785f3bc1018152020235c ./README.md 1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md 9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md 5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md -2b815d3b815b8d338560183c6f0af46f761c2465309783c93870b8ac8d022d03 ./docs/COMPATIBILITY.md +a88ae86f046779db2ee4e0e7458510d782c459ab898efb8b58decaec53f72743 ./docs/COMPATIBILITY.md 5f4ac209a16ab110baeaa64a40c19d9239c903e17550c3f05e1e1473ddcc33a3 ./docs/DEVELOPMENT_SERVER.md 51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md a62cc7174f3c92d8ef77e4bd9607fbf5d4b80bc514ff05bd433c02a9b0578f18 ./docs/LANGUAGE_SERVER.md -091d40da988d61e0f2f13fa022363a2113aea626a45785ddd348eca2817be56c ./docs/SECURITY_EVIDENCE.md -d969c7b5486ee93e54232fd69d9db06f3b4dc1bba63001596ec48545073c2680 ./docs/THREAT_MODEL.md -738258ba8f7e5ffea67d3f00eb70839590171971a9946a55b013ca95baf7aafb ./docs/V1_RELEASE_PLAN.md +f2622e0eba601470624e862caf717060c7b73037f13f0b7bd6e9792a49463480 ./docs/SECURITY_EVIDENCE.md +f2423c325ebe5371af43db6b09b11ea5a4ea3d3d3c14098f9d0ccd89110ea03d ./docs/THREAT_MODEL.md +bb2fde5ffd9736ef2a46b2931484bcec7b872353c7c20821a8fa7a32946fa97d ./docs/V1_RELEASE_PLAN.md f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go d891b9b075617050471b2ca34de73d926aaebde4ec638a5039b0d5001d3172f4 ./internal/compiler/analysis.go @@ -82,9 +82,8 @@ ff76daee5b642ad84af31701833246d68b54d09580192312d750a7a2e893a692 ./sando/go.mod 80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go 85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go -c4a161faba46ce5b508c0788078256a520277a573a3ace0e85ae0c26b16d298b ./scripts/README.md +36265470310f8463895761bb53a2137583d395d4b19b0190d038eecce1f4ce25 ./scripts/README.md 0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh -1b003062799b99bfe271b47438397a8cce5875c60c982a0117eb11c3babcadf0 ./scripts/release-check.sh +03d58bea32691d6d503983ddcf979fb88091eed4cb322e74a9eeb4ee434bacec ./scripts/release-check.sh 78a64c7fb3a039b15a1d08b4c0b873952852287a07f670247b081e59dbb09a30 ./scripts/verify-public-install.sh -24ed3c9a1d37e46a856cbbd68e5c58ae04c6c9852902b99ed675e1f428339a9f ./scripts/verify.ps1 f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh diff --git a/README.md b/README.md index e0d1e8c..ba37022 100644 --- a/README.md +++ b/README.md @@ -48,13 +48,17 @@ semantic-version prerelease: source syntax, generated output, the runtime API, and CLI behavior may change before final v1, and this beta is not recommended for production deployment. -The exact Beta 1 source passed maintainer-run native Windows and executed Linux -matrices with Go 1.25.12 and Go 1.26.5. Native macOS validation is still -pending, so macOS support is provisional in this beta. Mac learners and Go -developers are warmly invited to try it and share their macOS version, -architecture, Go version, command, and smallest useful reproduction. Community -reports broaden the evidence; maintainers remain responsible for security -review, triage, fixes, and release decisions. +Linux/amd64 is the maintained execution and release target. Required release +evidence runs on Linux with the supported Go lines. WSL is a useful Linux +development environment, but it does not turn native Windows into a supported +target. Native Windows, macOS, and other operating systems may happen to build +or work and portability reports are welcome; they are not release gates or a +maintained compatibility promise. + +The evidence ledger retains the exact Beta 1 Windows and Linux observations as +historical facts. Those past results do not expand the current support policy. +Maintainers remain responsible for security review, triage, fixes, and release +decisions on the supported Linux target. Inside an application module, add the small runtime first: diff --git a/RELEASE.md b/RELEASE.md index 9278302..28e2bba 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -21,11 +21,11 @@ while it is the current prerelease, but it is not recommended or supported as a production-stable dependency. Syntax, generated output, runtime APIs, CLI behavior, and diagnostics may change in a later prerelease. -Beta 1 may publish with native macOS validation pending when Windows and Linux -have passed the exact-candidate matrix and macOS is clearly marked provisional. -Community Mac results are valuable compatibility input; they do not transfer -security review, triage, remediation, or release responsibility away from the -maintainers. +Current and future beta release gates run on Linux/amd64. WSL may be used as a +Linux development environment, but native Windows, macOS, and other targets +are not release blockers or maintained compatibility promises. Portability +reports remain useful input; they do not transfer security review, triage, +remediation, or release responsibility away from the maintainers. Beta tags are signed, annotated, and immutable. Beta 1 is a source/module release installed through the Go toolchain; it does not promise downloadable @@ -37,9 +37,9 @@ final v1. An RC means the intended v1 source, runtime, CLI, diagnostics, schemas, and generated contract are frozen except for release-blocking fixes. An RC requires -maintainer-run native Linux, macOS, and Windows evidence, complete release -artifacts and provenance, signed tags, clean direct/proxy installs, and every RC -gate in this repository. Findings produce a new RC rather than a moved tag. +maintainer-run Linux/amd64 evidence, complete release artifacts and provenance, +signed tags, clean direct/proxy installs, and every RC gate in this repository. +Findings produce a new RC rather than a moved tag. ### Final v1 @@ -49,7 +49,11 @@ published assurance gap, and the documented RC observation period. A deployment, example, classroom project, or case study in another repository is neither imported nor required as release evidence. -## Beta 1 publication gates +## Beta 1 publication gates (historical) + +The first beta used a broader one-time platform campaign. The completed items +below are retained as publication history; they do not define future platform +support. Before `sando/v1.0.0-beta.1` and `v1.0.0-beta.1` are created: @@ -99,8 +103,7 @@ In addition to every Beta 1 compiler/security/determinism gate: nested-module boundaries, completion scope, and component definitions; 2. prove the language-server package does not write, execute project code, invoke Go, fetch, access the network, or start the development supervisor; -3. run the exact candidate on supported Go lines under executed Linux and - native Windows, with native macOS status stated explicitly; +3. run the exact candidate on supported Go lines under executed Linux/amd64; 4. build an exact version-stamped candidate and assert the additive `features: ["lsp-stdio"]` JSON identity; 5. publish a signed annotated compiler tag only after the reviewed sanitized @@ -111,16 +114,16 @@ In addition to every Beta 1 compiler/security/determinism gate: ## RC and final gates No release candidate or v1.0.0 release occurs until every applicable gate in -this repository is evidenced, including cross-platform deterministic -generation, temporary-module compilation, fuzz/adversarial suites, +this repository is evidenced, including deterministic generation on supported +Linux and Go lanes, temporary-module compilation, fuzz/adversarial suites, race/vet/vulnerability/license checks on the latest two supported Go lines, development-supervisor failure tests, and reproducible repository-owned benchmark and security results. Release candidates require a clean canonical checkout, reviewed changelog, -compatible vanity-import metadata, reproducible binaries, signed annotated -tags, checksums, SBOMs, vulnerability results, and verification on Linux, -macOS, and Windows. +compatible vanity-import metadata, reproducible Linux/amd64 binaries, signed +annotated tags, checksums, SBOMs, vulnerability results, and verification on +Linux/amd64. ## Public source and artifacts diff --git a/ROADMAP.md b/ROADMAP.md index 7f481f1..7c2d767 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -7,31 +7,29 @@ necessarily blockers for an earlier prerelease. The ordered initiative, repository topology, release-candidate sequence, and definition of confidence are maintained in [docs/V1_RELEASE_PLAN.md](docs/V1_RELEASE_PLAN.md). -## Beta 1: public learning and evaluation +## Beta 1: public learning and evaluation (historical) Beta 1 deliberately ships before the final-v1 compatibility and artifact gates. Its scope is classroom use, learning, prototypes, and compatibility feedback; it is not a production-stability promise. - [x] Define beta versus RC/final support and compatibility policy. -- [x] Establish a public pre-beta Linux/Windows matrix on Go 1.25 and Go 1.26. -- [x] Document macOS as provisional and invite useful community reports while - retaining maintainer responsibility for security and releases. -- [x] Rerun all required Windows/Linux checks and deterministic generation on - the exact Beta 1 candidate. +- [x] Establish a one-time public pre-beta Linux/Windows evidence matrix on Go + 1.25 and Go 1.26. +- [x] Record the untested macOS boundary without presenting it as evidence. +- [x] Rerun the historical Windows/Linux campaign and deterministic generation + on the exact Beta 1 candidate. - [x] Publish immutable `sando/v1.0.0-beta.1`, then `v1.0.0-beta.1`, from the reviewed public commit. - [x] Verify clean runtime-first direct and public-proxy installs after publication. -- [ ] Complete native macOS maintainer validation. This is an RC/final gate, - not a Beta 1 gate. ## Compiler and runtime for RC/final - [ ] Freeze and machine-check the compiler, CLI, diagnostic, schema, generated, and runtime compatibility contracts. -- [ ] Repeat compiler-owned deterministic golden output across Linux, macOS, - and Windows on the exact candidate. +- [ ] Repeat compiler-owned deterministic golden output across the supported + Linux and Go lanes on the exact candidate. - [ ] Compile temporary consumer modules using committed Go and only the Apache runtime. - [ ] Run the parser, delimiter, context, path, and source-map release fuzz @@ -75,5 +73,5 @@ it is not a production-stability promise. machines. - [ ] Confirm the sanitized public Gitea source contains no private paths, identifiers, history, or unsupported claims. -- [ ] Publish and observe a signed RC on every supported native platform. +- [ ] Publish and observe a signed RC on the supported Linux/amd64 target. - [ ] Publish `sando/v1.0.0`, then `v1.0.0`, without moving either tag. diff --git a/SECURITY.md b/SECURITY.md index 80049cf..1a12db4 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -9,7 +9,8 @@ Security reports are welcome and receive best-effort maintainer assessment and fixes while this pair is current. This is not production support, an SLA, a fitness guarantee, or a promise that a fix will preserve beta APIs. -The community is invited to help find compatibility gaps, especially on macOS. +The community is invited to help find portability gaps outside the maintained +Linux target, but those reports do not create a support or release commitment. That invitation does not outsource security assurance. Maintainers retain responsibility for vulnerability review, triage, remediation decisions, advisories, and release decisions. @@ -35,7 +36,7 @@ public issue. If that new mailbox rejects or bounces a message, retain the report and open a canonical Gitea issue containing only the fact that the private security contact failed. Do not include technical details or sensitive data. The maintainer will -publish a corrected private route. Ordinary usage, classroom, and macOS +publish a corrected private route. Ordinary usage, classroom, and portability compatibility reports that do not reveal a vulnerability may use a public issue. Helpful reports include: diff --git a/docs/COMPATIBILITY.md b/docs/COMPATIBILITY.md index 361a6fe..fe69e5b 100644 --- a/docs/COMPATIBILITY.md +++ b/docs/COMPATIBILITY.md @@ -32,9 +32,17 @@ payloads before final v1, or hand-edited generated files. ## Go and platform support -The current beta targets Go 1.25 and Go 1.26. Support is based on point-in-time, -maintainer-run release matrices, not an implication of continuous CI coverage. -A Go support change is announced in release notes before it takes effect. +The current beta targets Go 1.25 and Go 1.26 on Linux/amd64. Required release +evidence runs in Linux CI and on Linux deployment hosts. WSL is treated as a +Linux development environment. Native Windows, macOS, and other targets are +not maintained release targets or release blockers; a successful build there +is useful portability evidence, not a compatibility promise. A Go or platform +support change is announced in release notes before it takes effect. + +### Historical Beta 1 observations + +The following table is retained because the tests genuinely ran. It records a +point-in-time Beta 1 campaign and does not define the current support matrix. The current public evidence is the exact Beta 1 source at commit `b7a84054d755e42285e50298e41e47f06a8325a5` (tree @@ -45,26 +53,25 @@ The current public evidence is the exact Beta 1 source at commit | Windows 11/amd64 on NTFS | 1.25.12, 1.26.5 | Native tests, race, vet, builds, generation, process cleanup, watcher boundaries, and temporary consumer compilation passed; privileged symlink and POSIX-only permission cases were not exercised | | Linux/amd64 on WSL2 with an ext4 checkout | 1.25.12, 1.26.5 | Tests, race, vet, builds, generation, focused filesystem/development cases, and license checks passed | | Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | The earlier pre-beta baseline passed tests, race, vet, builds, deterministic generation, and license checks; this was not rerun on the exact Beta 1 commit | -| macOS | — | Native maintainer validation pending; provisional for Beta 1 | +| macOS | — | Not executed during the Beta 1 campaign | The golden generated file had SHA-256 `63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f` -on every tested Windows and Linux lane. +on every tested Windows and Linux lane in that historical campaign. The signed Beta tags and fresh direct/public-proxy installation were verified after publication. For Beta 1, add the nested runtime to an application module before installing the parent compiler at the same version; this avoids a Go module-cache path-selection ambiguity observed in the reverse order. -## macOS feedback +## Portability feedback -Mac learners, teachers, and Go developers are warmly invited to try the beta. -A useful compatibility report includes the macOS version, Intel or Apple -Silicon architecture, `go version`, the exact command, and a minimal -reproduction or diagnostic output. Ordinary compatibility reports belong on -the canonical Gitea project. Suspected vulnerabilities must use the private -route in [SECURITY.md](../SECURITY.md). +Developers may try the beta on an unsupported target and report useful gaps. A +good report includes the operating system and architecture, `go version`, the +exact command, and a minimal reproduction or diagnostic output. Ordinary +portability reports belong on the canonical Gitea project. Suspected +vulnerabilities must use the private route in [SECURITY.md](../SECURITY.md). -Community reports can reveal gaps and help prioritize maintainer testing. They -do not constitute an independent audit or shift responsibility for security -review, triage, fixes, and release decisions to the community. +Community reports can reveal gaps and help prioritize future work. They do not +constitute an independent audit, create a support promise, or shift +responsibility for security review, triage, fixes, and release decisions. diff --git a/docs/SECURITY_EVIDENCE.md b/docs/SECURITY_EVIDENCE.md index 956b9fa..ef2af33 100644 --- a/docs/SECURITY_EVIDENCE.md +++ b/docs/SECURITY_EVIDENCE.md @@ -23,8 +23,10 @@ The named Windows and WSL2 platform runs used the exact public commit and tree above. The isolated server-container matrix preceded the final candidate and is retained only as supplementary Linux evidence. Hostnames, network addresses, account names, private paths, private repository identities, and private commit -mappings are intentionally absent from this public ledger. Native macOS -execution remains pending and is provisional for the beta. +mappings are intentionally absent from this public ledger. These platform +observations are historical evidence, not the current support matrix. +Linux/amd64 is now the maintained release target; WSL is a Linux development +environment, while native Windows and macOS are not release blockers. ## Beta 2 compiler publication addendum @@ -48,7 +50,8 @@ focused process-tree/watcher/consumer tests, candidate-stamped version checks, and deterministic generation on Go 1.25.12 and Go 1.26.5. Clean isolated `GOPROXY=direct` and public-proxy-only installs produced `features:["lsp-stdio"]`; the public-proxy path also verified the retained -runtime through `sum.golang.org`. Native macOS execution remains provisional. +runtime through `sum.golang.org`. The Windows result is retained as historical +portability evidence and does not create an ongoing support promise. The Beta 2 language server is additive development tooling. Its tested security boundary includes protocol-only stdout; bounded header and message @@ -83,7 +86,7 @@ baseline commit. | URL scheme handling | ordinary/trusted URL test matrix | Pass for enumerated cases | | Filesystem boundaries | symlink, nested-module, VCS, ownership, stale-output tests | Pass for tested cases; see open findings | | Development proxy browser boundary | Host, Origin, Fetch Metadata, CSP, fragment and response tests | Pass for tested cases | -| Platform behavior | Exact-candidate native Windows and executed Linux matrices; macOS cross-compilation | Windows/Linux pass for tested lanes; native macOS pending | +| Platform behavior | Historical exact-candidate native Windows and executed Linux matrices | Windows/Linux passed for the tested lanes; current releases require Linux/amd64 evidence | Coverage measures statements executed by tests. It is not branch completeness and is not evidence that the executed behavior is secure. @@ -92,7 +95,7 @@ and is not evidence that the executed behavior is secure. and reachable through its analysis. A clean result cannot detect unknown flaws, design errors, or vulnerabilities outside its model. -## Beta 1 native compatibility matrix +## Historical Beta 1 compatibility matrix These are maintainer-run, point-in-time results, not continuous CI and not an independent audit. @@ -102,7 +105,7 @@ independent audit. | Windows 11/amd64, NTFS | 1.25.12, 1.26.5 | Native PowerShell verifier with race; root/runtime tests, vet, trimpath build, freshness, two generation passes, process-tree cleanup, watcher boundaries, and temporary consumer compilation | Pass. Symlink-output rejection skipped because the test account lacked symlink privilege; the read-only-directory case is POSIX-only | | Ubuntu 20.04/amd64 under WSL2, native ext4 checkout | 1.25.12, 1.26.5 | Race-enabled verifier; root/runtime tests, vet, build, two generation passes, ten focused filesystem cases, five focused development-process/watcher cases, and license check | Pass. This is Linux execution under WSL2, not bare-metal or Linux/arm64 evidence | | Linux/amd64 server containers | 1.25.12, 1.26.5 | Earlier pre-beta root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass on the earlier baseline only. Container resources were capped at 1 CPU and 2 GiB; this is supplementary evidence, not an exact Beta 1 lane or Linux/arm64 evidence | -| macOS | — | Cross-compilation only | Native maintainer execution pending; provisional for Beta 1 | +| macOS | — | Cross-compilation only | No native Beta 1 evidence; not a maintained release target | The generated golden `basic.sando.go` was 1,399 bytes and had SHA-256 `63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f` @@ -110,12 +113,12 @@ on every tested Windows and Linux lane. Repeated generation also preserved its timestamp. This demonstrates cross-host agreement for one compiler-owned fixture, not equivalence for every possible template. -Mac learners and Go developers are warmly invited to report ordinary -compatibility results with macOS version, architecture, `go version`, exact -command, and a minimal reproduction. Suspected vulnerabilities use the private -route in [SECURITY.md](../SECURITY.md). Community reports help find gaps; -maintainers remain responsible for reproducing security-relevant behavior, -triage, remediation, and release decisions. +Portability reports for unsupported targets may include the operating system, +architecture, `go version`, exact command, and a minimal reproduction. +Suspected vulnerabilities use the private route in +[SECURITY.md](../SECURITY.md). Such reports help find gaps but do not create a +support promise; maintainers remain responsible for security triage and fixes +on the supported Linux target. ## Security-relevant design evidence @@ -203,8 +206,9 @@ known-vulnerability scans, candidate-version provenance checks, native Windows and executed Linux matrices, and Windows/macOS cross-compilation on 2026-08-12. Signed annotated runtime and compiler tags were then published from that commit in that order. Fresh runtime-first installation passed through both direct Git -resolution and the public Go proxy after normal proxy propagation. Native -macOS and the other gaps below remain separate release decisions. +resolution and the public Go proxy after normal proxy propagation. Future +release decisions use the current Linux-only support policy rather than +requiring this historical multi-platform campaign. ## Open assurance gaps @@ -214,9 +218,8 @@ macOS and the other gaps below remain separate release decisions. - the signed annotated Beta tags and their common peeled commit were verified; prebuilt-artifact signing, checksums, SBOM, reproducible provenance, and key recovery remain incomplete; -- native macOS, Linux/arm64, and Windows/arm64 execution remain outstanding; -- Windows symlink rejection was not natively exercised because the test account - lacked symlink privilege; +- Linux/arm64 and non-Linux portability are outside the current maintained + release target; - browser-parser differential and semantic property testing need expansion; - compiler input size, CPU, and memory have no built-in hard budget; - filesystem checks do not defend against a hostile local actor racing path diff --git a/docs/THREAT_MODEL.md b/docs/THREAT_MODEL.md index 18f1889..042fd27 100644 --- a/docs/THREAT_MODEL.md +++ b/docs/THREAT_MODEL.md @@ -177,7 +177,7 @@ Sandwich Hime does not: ## Open release work - broaden semantic and browser-parser differential testing; -- execute the native Windows/macOS security and process-lifecycle matrix; +- execute the Linux/amd64 security and process-lifecycle release matrix; - complete signed release provenance, checksums, and SBOM evidence; - test the confidential reporting and signing-key recovery procedures; and - close or explicitly accept every finding listed in the evidence ledger before diff --git a/docs/V1_RELEASE_PLAN.md b/docs/V1_RELEASE_PLAN.md index 8cd5d76..c1af097 100644 --- a/docs/V1_RELEASE_PLAN.md +++ b/docs/V1_RELEASE_PLAN.md @@ -28,17 +28,18 @@ private history or an indiscriminate Git mirror. Beta 1 is deliberately earlier than a release candidate. It creates a real, repeatable install for learners and evaluators without claiming that the final -v1 compatibility, native-platform, artifact, signing, or soak gates are -complete. +v1 compatibility, Linux release, artifact, signing, or soak gates are complete. ### Demonstrated for Beta 1 Public commit `b7a84054d755e42285e50298e41e47f06a8325a5` (tree `be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run Go -1.25.12 and Go 1.26.5 matrices on native Windows/amd64, Linux/amd64 under WSL2, -with the earlier pre-beta server-container run retained only as supplementary -Linux evidence. The same generated golden SHA-256 was observed across the exact -Beta Windows and Linux lanes. +1.25.12 and Go 1.26.5 matrices on native Windows/amd64 and Linux/amd64 under +WSL2, with the earlier pre-beta server-container run retained only as +supplementary Linux evidence. The same generated golden SHA-256 was observed +across the exact Beta Windows and Linux lanes. This is historical evidence, +not the current support definition; Linux/amd64 is now the maintained release +target. Other demonstrated controls include: @@ -52,7 +53,7 @@ Other demonstrated controls include: ### Not demonstrated yet -- native maintainer-run macOS execution; macOS is provisional for Beta 1; +- final Linux/amd64 release-candidate evidence on the exact candidate; - stable final-v1 API, CLI, schema, diagnostic, and generated snapshots; - systematic browser-parser and `html/template` differential testing; - a long semantic fuzz campaign beyond bounded no-panic smoke; @@ -60,7 +61,7 @@ Other demonstrated controls include: - complete real-browser development-supervisor evidence; - deterministic prebuilt archives, checksums, SBOMs, signed binaries, and tested signing/recovery procedures; or -- native macOS installation of the published Beta 1 tags. +- independently reproduced Linux release artifacts, checksums, and SBOMs. ## Beta 1 publication lane @@ -68,9 +69,8 @@ Beta 1 is supported for learning, classroom projects, evaluation, prototypes, and compatibility feedback. It is not recommended as a production-stable dependency, and its interfaces may change. -- [x] Define beta support, security, compatibility, and macOS-provisional - language. -- [x] Establish the named public pre-beta Linux/Windows baseline. +- [x] Define beta support, security, and compatibility language. +- [x] Establish the historical public pre-beta Linux/Windows evidence baseline. - [x] Rerun the supported Go matrix and deterministic generation on the exact Beta 1 candidate. - [x] Run the candidate-version freshness, bounded fuzz, vulnerability, and @@ -79,12 +79,10 @@ dependency, and its interfaces may change. `v1.0.0-beta.1`, from the same reviewed public commit. - [x] Verify clean runtime-first direct and public-proxy installs and record the result. -- [ ] Add native macOS maintainer evidence before RC; community reports inform - that work but do not replace maintainer responsibility. ## Milestone 1: contract freeze -Required before security/platform release-candidate work is declared complete: +Required before security/Linux release-candidate work is declared complete: - [ ] Decide and specify whether generic component function signatures are v1. - [ ] Inventory and freeze every exported `sando` symbol, trusted type, @@ -97,11 +95,11 @@ Required before security/platform release-candidate work is declared complete: output compatibility snapshots. - [ ] Define the v1 deprecation and security-support policy. -## Milestone 2: security and native-platform evidence +## Milestone 2: security and Linux release evidence - [ ] Run the minimum supported Go line and the latest two stable Go lines on - native Linux, macOS, and Windows hosts. -- [ ] Prove identical generated bytes across those hosts and exercise native + Linux/amd64 runners and a Linux deployment-class host. +- [ ] Prove identical generated bytes across those Linux lanes and exercise path, replacement, permission, race, process-tree, and watcher behavior. - [ ] Build a systematic differential corpus against Go's documented `html/template` safety baseline for overlapping supported contexts. @@ -147,7 +145,7 @@ Required before security/platform release-candidate work is declared complete: 2. Publish signed `sando/v1.0.0-rc.1`, then signed `v1.0.0-rc.1` from the same reviewed public Gitea commit. 3. Verify documented installs through fresh `GOPROXY=direct` and - `proxy.golang.org` caches on supported Go versions and native platforms. + `proxy.golang.org` caches on supported Go versions under Linux/amd64. 4. Run the complete evidence suite again from the exact public commit. 5. Operate the official Sandwich Hime website on the RC runtime for a 14-day observation period with no unresolved Hime render, security, accessibility, @@ -172,6 +170,6 @@ marketing. New features do not outrank a small stable contract. ## Definition of confidence “Ready for v1” means a reviewer can trace each promise to a stable public -contract, executable evidence from supported native environments, and a signed +contract, executable evidence from supported Linux environments, and a signed artifact built from the exact canonical source. It does not mean perfect, invulnerable, or finished forever. diff --git a/scripts/README.md b/scripts/README.md index cc2f6e2..0747564 100644 --- a/scripts/README.md +++ b/scripts/README.md @@ -2,10 +2,11 @@ # Repository verification tools -These scripts are intentionally understandable shell and PowerShell rather than a release framework with hidden defaults. +These scripts are intentionally understandable shell rather than a release +framework with hidden defaults. The maintained verification and release path +is Linux. - `verify.sh` runs root and nested-module tests and vet, builds `himesan`, checks the compiler-owned golden output, and proves two generation passes leave the same bytes and unchanged modification times. Set `HIMESAN_RACE=1` for race tests. -- `verify.ps1` provides the equivalent native Windows lane; pass `-Race` to include the race detector. - `check-licenses.sh` enforces the AGPL compiler / Apache runtime boundary and prevents generated application Go from inheriting an AGPL identifier. - `release-check.sh --version vX.Y.Z` is a clean-checkout technical preflight, including exact candidate-version and generated-provenance checks. Beta publication follows the narrower prerelease gates in `RELEASE.md`; release candidates and final v1 additionally use `--public` with a human-reviewed `HIMESAN_RELEASE_EVIDENCE_DIR`. The script never tags, pushes, publishes, or deploys. - `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes, adds the nested runtime before installing the parent compiler, and exercises fresh direct-fetch and public-proxy caches without interactive Git credentials. @@ -16,6 +17,9 @@ The release preflight invokes `govulncheck` from the official Go vulnerability p ## Preview automation status -Forge workflows are intentionally excluded from the sanitized pre-1.0 public snapshot until the project has confirmed its own Gitea runner availability and reviewed locally hosted or otherwise pinned dependencies. Local `verify.sh`, `verify.ps1`, license, and release-preflight results are the preview gates. +Forge workflows are intentionally excluded from the sanitized pre-1.0 public +snapshot. The private development repository uses pinned Linux runners; the +public source remains independently verifiable with `verify.sh`, the license +check, and the Linux release preflight. If Gitea automation is later added to the public repository, pin every external action to a reviewed immutable commit, document its provenance, grant minimum permissions, and keep a local verification path. A secondary forge may host a sanitized, read-only discovery snapshot, but hosted workflows stay disabled there and it does not become a release or contribution authority. diff --git a/scripts/release-check.sh b/scripts/release-check.sh index 1dbe9fc..93d863e 100755 --- a/scripts/release-check.sh +++ b/scripts/release-check.sh @@ -253,23 +253,14 @@ go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./... go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./... ) -printf '\n==> cross-compiling release binary smoke set\n' +printf '\n==> building supported Linux release binary\n' for target in \ - linux/amd64 \ - linux/arm64 \ - darwin/amd64 \ - darwin/arm64 \ - windows/amd64 \ - windows/arm64; do + linux/amd64; do target_os=${target%/*} target_arch=${target#*/} - extension='' - if [[ "$target_os" == windows ]]; then - extension='.exe' - fi CGO_ENABLED=0 GOOS="$target_os" GOARCH="$target_arch" \ go build -trimpath -ldflags "$compiler_linker_flags" \ - -o "$artifact_dir/himesan-$target_os-$target_arch$extension" ./cmd/himesan + -o "$artifact_dir/himesan-$target_os-$target_arch" ./cmd/himesan done for required in \ @@ -289,7 +280,7 @@ if (( public_release == 1 )); then fi for evidence in \ legal-review.md \ - cross-platform.md \ + linux-platform.md \ security.md \ development-supervisor.md \ benchmark-methodology.md \ diff --git a/scripts/verify.ps1 b/scripts/verify.ps1 deleted file mode 100644 index 8f16b9b..0000000 --- a/scripts/verify.ps1 +++ /dev/null @@ -1,133 +0,0 @@ -# SPDX-License-Identifier: AGPL-3.0-only - -[CmdletBinding()] -param( - [switch]$Race -) - -$ErrorActionPreference = "Stop" -$RepoRoot = (Resolve-Path (Join-Path $PSScriptRoot "..")).Path -Set-Location $RepoRoot - -function Invoke-Checked { - param( - [Parameter(Mandatory = $true)] - [string]$Label, - [Parameter(Mandatory = $true)] - [scriptblock]$Command - ) - - Write-Host "`n==> $Label" - & $Command - if ($LASTEXITCODE -ne 0) { - throw "$Label failed with exit code $LASTEXITCODE" - } -} - -function Invoke-ModuleChecks { - param( - [Parameter(Mandatory = $true)] - [string]$Directory, - [Parameter(Mandatory = $true)] - [string]$Label - ) - - Push-Location $Directory - try { - Invoke-Checked "$Label`: go test" { go test ./... } - Invoke-Checked "$Label`: go vet" { go vet ./... } - } - finally { - Pop-Location - } -} - -function Get-SandoSources { - if (-not (Test-Path "internal/compiler/testdata/golden" -PathType Container)) { - return @() - } - - return @(Get-ChildItem "internal/compiler/testdata/golden" -File -Filter "*.sando" | - Sort-Object FullName) -} - -function Get-GeneratedManifest { - $lines = foreach ($source in (Get-SandoSources)) { - $output = "$($source.FullName).go" - if (-not (Test-Path $output -PathType Leaf)) { - "missing $output" - continue - } - $hash = (Get-FileHash -Algorithm SHA256 $output).Hash.ToLowerInvariant() - $modified = (Get-Item -LiteralPath $output).LastWriteTimeUtc.Ticks - "$hash $modified $output" - } - return ($lines -join "`n") -} - -$TempRoot = Join-Path ([System.IO.Path]::GetTempPath()) ("himesan-verify-" + [guid]::NewGuid()) -New-Item -ItemType Directory -Path $TempRoot | Out-Null - -try { - Invoke-ModuleChecks "." "compiler module" - Invoke-Checked "compiler module: go build" { - go build -trimpath -o (Join-Path $TempRoot "himesan.exe") ./cmd/himesan - } - - if (-not (Test-Path "sando/go.mod" -PathType Leaf)) { - throw "nested Apache runtime module sando/go.mod is missing" - } - Invoke-ModuleChecks "sando" "sando runtime module" - - $Sources = @(Get-SandoSources) - if ($Sources.Count -eq 0) { - throw "compiler-owned golden .sando fixture is missing" - } - else { - $SourcePaths = @($Sources | ForEach-Object { $_.FullName }) - $CheckArgs = @("run", "./cmd/himesan", "check") + $SourcePaths - $GenerateArgs = @("run", "./cmd/himesan", "generate") + $SourcePaths - Invoke-Checked "golden generation: read-only freshness check" { - & go $CheckArgs - } - $Before = Get-GeneratedManifest - - Invoke-Checked "golden generation: first deterministic pass" { - & go $GenerateArgs - } - $First = Get-GeneratedManifest - if ($Before -cne $First) { - throw "generation changed committed output after check declared it fresh" - } - - Invoke-Checked "golden generation: second deterministic pass" { - & go $GenerateArgs - } - $Second = Get-GeneratedManifest - if ($First -cne $Second) { - throw "repeated generation changed output bytes or an unchanged timestamp" - } - - Invoke-Checked "golden generation: final freshness check" { - & go $CheckArgs - } - } - - if ($Race) { - Invoke-Checked "compiler module: race tests" { go test -race ./... } - Push-Location "sando" - try { - Invoke-Checked "sando runtime module: race tests" { go test -race ./... } - } - finally { - Pop-Location - } - } - - Write-Host "`n==> verification complete" -} -finally { - if (Test-Path $TempRoot -PathType Container) { - Remove-Item -LiteralPath $TempRoot -Recurse -Force - } -} -- 2.54.0