Maintain Linux as the Sandwich Hime release target #1

Merged
gamertan merged 1 commits from codex/linux-release-policy into main 2026-08-16 17:58:47 -04:00
14 changed files with 142 additions and 250 deletions
+17
View File
@@ -6,6 +6,23 @@ Sandwich Hime follows semantic versioning after final v1. Compiler and nested
runtime releases are versioned independently and listed together when they form
one coordinated release.
## Unreleased
### Changed
- Linux/amd64 is the maintained execution, verification, artifact, and release
target. WSL remains a Linux development environment; native Windows, macOS,
and other targets are best-effort portability surfaces rather than release
gates or compatibility promises.
- Release preflight now builds the supported Linux/amd64 candidate only and
requires Linux platform evidence for RC/final publication.
### Removed
- The native Windows PowerShell verifier and private multi-OS release-gate
workflow. Historical platform evidence and best-effort portability code are
retained without creating a support obligation.
## v1.0.0-beta.2 — 2026-08-12
Compiler-only release; the unchanged Apache runtime remains
+1 -1
View File
@@ -1 +1 @@
{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":90,"allowlist_sha256":"393ee598dc7e12cdbb603887bf06599e46b40d7c19e4ff693a818cc32afb01ec","manifest_sha256":"38a02b05cec70c82076df0f40de8b98edfc9280f54c12fa0cbe84949da253fdf"}
{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":89,"allowlist_sha256":"2947ef034f9bfe9bd20c00e67d0033f0ff5e62e55fc2db0952696485d9eeec40","manifest_sha256":"5005a799e84f5cbb66cc9d0ced03c5897924de1b9c28adf8aaf06b2ddb4affff"}
+11 -12
View File
@@ -2,7 +2,7 @@
658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes
d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore
98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md
0828545d3aa440e1ec5dce4b934de6800413f55a925988b60923c5ee9b700a4e ./CHANGELOG.md
5bc3db089eb243640adc2e4bae62d94754aff420d1eb64057036032dfd9a626b ./CHANGELOG.md
b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md
797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md
86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT
@@ -13,10 +13,10 @@ a4570d054f072d33b8f17b0c8b162a6ee0ca37d7df2b1aee7e4b728ab350a892 ./GOVERNANCE.m
47d857e49f89596bac9b09fc8ca57a668a33d01e2b51508acfc92ed321cdc27f ./LICENSES.md
b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md
6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md
c3ac873ae2e6248e1d86dd542a11557b24b8dba80e4785f3bc1018152020235c ./README.md
2751674c180f15a42c1d2b40cf149be4138aa6cf247d7be176f1f0c468103c24 ./RELEASE.md
209decb6769646eb2f58e312fbcd9c497c26234f3d3115bae3f20493b8178584 ./ROADMAP.md
0fef473ac46b71215d1eb7922da4594210ffbbb8bb2dedd5e531fb3bd09396e1 ./SECURITY.md
fbc4a7c118ac983a1ea49dc3a9d714f5130ace21a8af59ab9fcabd6519cb6b97 ./README.md
fafa1494fa1a5a5cf3b3d371155f0448d46f1f13cd394555e06396b336bc102a ./RELEASE.md
c0e65a8bffcba71cd42d6122be25fd4993c04c8cba8c5e69108c9f5dbaca9243 ./ROADMAP.md
17e10aaab589d40b479e374523982117d2c7ffac95306493cfa4e3171108a1a8 ./SECURITY.md
53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md
3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md
8cd8db68e1300f9b78cc7235855853cbc7aeb499a921419e23a22e4d22826fcb ./cmd/himesan/main.go
@@ -24,13 +24,13 @@ c3ac873ae2e6248e1d86dd542a11557b24b8dba80e4785f3bc1018152020235c ./README.md
1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md
9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md
5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md
2b815d3b815b8d338560183c6f0af46f761c2465309783c93870b8ac8d022d03 ./docs/COMPATIBILITY.md
a88ae86f046779db2ee4e0e7458510d782c459ab898efb8b58decaec53f72743 ./docs/COMPATIBILITY.md
5f4ac209a16ab110baeaa64a40c19d9239c903e17550c3f05e1e1473ddcc33a3 ./docs/DEVELOPMENT_SERVER.md
51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md
a62cc7174f3c92d8ef77e4bd9607fbf5d4b80bc514ff05bd433c02a9b0578f18 ./docs/LANGUAGE_SERVER.md
091d40da988d61e0f2f13fa022363a2113aea626a45785ddd348eca2817be56c ./docs/SECURITY_EVIDENCE.md
d969c7b5486ee93e54232fd69d9db06f3b4dc1bba63001596ec48545073c2680 ./docs/THREAT_MODEL.md
738258ba8f7e5ffea67d3f00eb70839590171971a9946a55b013ca95baf7aafb ./docs/V1_RELEASE_PLAN.md
f2622e0eba601470624e862caf717060c7b73037f13f0b7bd6e9792a49463480 ./docs/SECURITY_EVIDENCE.md
f2423c325ebe5371af43db6b09b11ea5a4ea3d3d3c14098f9d0ccd89110ea03d ./docs/THREAT_MODEL.md
bb2fde5ffd9736ef2a46b2931484bcec7b872353c7c20821a8fa7a32946fa97d ./docs/V1_RELEASE_PLAN.md
f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod
ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go
d891b9b075617050471b2ca34de73d926aaebde4ec638a5039b0d5001d3172f4 ./internal/compiler/analysis.go
@@ -82,9 +82,8 @@ ff76daee5b642ad84af31701833246d68b54d09580192312d750a7a2e893a692 ./sando/go.mod
80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go
85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go
b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go
c4a161faba46ce5b508c0788078256a520277a573a3ace0e85ae0c26b16d298b ./scripts/README.md
36265470310f8463895761bb53a2137583d395d4b19b0190d038eecce1f4ce25 ./scripts/README.md
0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh
1b003062799b99bfe271b47438397a8cce5875c60c982a0117eb11c3babcadf0 ./scripts/release-check.sh
03d58bea32691d6d503983ddcf979fb88091eed4cb322e74a9eeb4ee434bacec ./scripts/release-check.sh
78a64c7fb3a039b15a1d08b4c0b873952852287a07f670247b081e59dbb09a30 ./scripts/verify-public-install.sh
24ed3c9a1d37e46a856cbbd68e5c58ae04c6c9852902b99ed675e1f428339a9f ./scripts/verify.ps1
f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh
+11 -7
View File
@@ -48,13 +48,17 @@ semantic-version prerelease: source syntax, generated output, the runtime API,
and CLI behavior may change before final v1, and this beta is not recommended
for production deployment.
The exact Beta 1 source passed maintainer-run native Windows and executed Linux
matrices with Go 1.25.12 and Go 1.26.5. Native macOS validation is still
pending, so macOS support is provisional in this beta. Mac learners and Go
developers are warmly invited to try it and share their macOS version,
architecture, Go version, command, and smallest useful reproduction. Community
reports broaden the evidence; maintainers remain responsible for security
review, triage, fixes, and release decisions.
Linux/amd64 is the maintained execution and release target. Required release
evidence runs on Linux with the supported Go lines. WSL is a useful Linux
development environment, but it does not turn native Windows into a supported
target. Native Windows, macOS, and other operating systems may happen to build
or work and portability reports are welcome; they are not release gates or a
maintained compatibility promise.
The evidence ledger retains the exact Beta 1 Windows and Linux observations as
historical facts. Those past results do not expand the current support policy.
Maintainers remain responsible for security review, triage, fixes, and release
decisions on the supported Linux target.
Inside an application module, add the small runtime first:
+19 -16
View File
@@ -21,11 +21,11 @@ while it is the current prerelease, but it is not recommended or supported as a
production-stable dependency. Syntax, generated output, runtime APIs, CLI
behavior, and diagnostics may change in a later prerelease.
Beta 1 may publish with native macOS validation pending when Windows and Linux
have passed the exact-candidate matrix and macOS is clearly marked provisional.
Community Mac results are valuable compatibility input; they do not transfer
security review, triage, remediation, or release responsibility away from the
maintainers.
Current and future beta release gates run on Linux/amd64. WSL may be used as a
Linux development environment, but native Windows, macOS, and other targets
are not release blockers or maintained compatibility promises. Portability
reports remain useful input; they do not transfer security review, triage,
remediation, or release responsibility away from the maintainers.
Beta tags are signed, annotated, and immutable. Beta 1 is a source/module
release installed through the Go toolchain; it does not promise downloadable
@@ -37,9 +37,9 @@ final v1.
An RC means the intended v1 source, runtime, CLI, diagnostics, schemas, and
generated contract are frozen except for release-blocking fixes. An RC requires
maintainer-run native Linux, macOS, and Windows evidence, complete release
artifacts and provenance, signed tags, clean direct/proxy installs, and every RC
gate in this repository. Findings produce a new RC rather than a moved tag.
maintainer-run Linux/amd64 evidence, complete release artifacts and provenance,
signed tags, clean direct/proxy installs, and every RC gate in this repository.
Findings produce a new RC rather than a moved tag.
### Final v1
@@ -49,7 +49,11 @@ published assurance gap, and the documented RC observation period. A
deployment, example, classroom project, or case study in another repository is
neither imported nor required as release evidence.
## Beta 1 publication gates
## Beta 1 publication gates (historical)
The first beta used a broader one-time platform campaign. The completed items
below are retained as publication history; they do not define future platform
support.
Before `sando/v1.0.0-beta.1` and `v1.0.0-beta.1` are created:
@@ -99,8 +103,7 @@ In addition to every Beta 1 compiler/security/determinism gate:
nested-module boundaries, completion scope, and component definitions;
2. prove the language-server package does not write, execute project code,
invoke Go, fetch, access the network, or start the development supervisor;
3. run the exact candidate on supported Go lines under executed Linux and
native Windows, with native macOS status stated explicitly;
3. run the exact candidate on supported Go lines under executed Linux/amd64;
4. build an exact version-stamped candidate and assert the additive
`features: ["lsp-stdio"]` JSON identity;
5. publish a signed annotated compiler tag only after the reviewed sanitized
@@ -111,16 +114,16 @@ In addition to every Beta 1 compiler/security/determinism gate:
## RC and final gates
No release candidate or v1.0.0 release occurs until every applicable gate in
this repository is evidenced, including cross-platform deterministic
generation, temporary-module compilation, fuzz/adversarial suites,
this repository is evidenced, including deterministic generation on supported
Linux and Go lanes, temporary-module compilation, fuzz/adversarial suites,
race/vet/vulnerability/license checks on the latest two supported Go lines,
development-supervisor failure tests, and reproducible repository-owned
benchmark and security results.
Release candidates require a clean canonical checkout, reviewed changelog,
compatible vanity-import metadata, reproducible binaries, signed annotated
tags, checksums, SBOMs, vulnerability results, and verification on Linux,
macOS, and Windows.
compatible vanity-import metadata, reproducible Linux/amd64 binaries, signed
annotated tags, checksums, SBOMs, vulnerability results, and verification on
Linux/amd64.
## Public source and artifacts
+9 -11
View File
@@ -7,31 +7,29 @@ necessarily blockers for an earlier prerelease. The ordered initiative,
repository topology, release-candidate sequence, and definition of confidence
are maintained in [docs/V1_RELEASE_PLAN.md](docs/V1_RELEASE_PLAN.md).
## Beta 1: public learning and evaluation
## Beta 1: public learning and evaluation (historical)
Beta 1 deliberately ships before the final-v1 compatibility and artifact gates.
Its scope is classroom use, learning, prototypes, and compatibility feedback;
it is not a production-stability promise.
- [x] Define beta versus RC/final support and compatibility policy.
- [x] Establish a public pre-beta Linux/Windows matrix on Go 1.25 and Go 1.26.
- [x] Document macOS as provisional and invite useful community reports while
retaining maintainer responsibility for security and releases.
- [x] Rerun all required Windows/Linux checks and deterministic generation on
the exact Beta 1 candidate.
- [x] Establish a one-time public pre-beta Linux/Windows evidence matrix on Go
1.25 and Go 1.26.
- [x] Record the untested macOS boundary without presenting it as evidence.
- [x] Rerun the historical Windows/Linux campaign and deterministic generation
on the exact Beta 1 candidate.
- [x] Publish immutable `sando/v1.0.0-beta.1`, then
`v1.0.0-beta.1`, from the reviewed public commit.
- [x] Verify clean runtime-first direct and public-proxy installs after
publication.
- [ ] Complete native macOS maintainer validation. This is an RC/final gate,
not a Beta 1 gate.
## Compiler and runtime for RC/final
- [ ] Freeze and machine-check the compiler, CLI, diagnostic, schema, generated,
and runtime compatibility contracts.
- [ ] Repeat compiler-owned deterministic golden output across Linux, macOS,
and Windows on the exact candidate.
- [ ] Repeat compiler-owned deterministic golden output across the supported
Linux and Go lanes on the exact candidate.
- [ ] Compile temporary consumer modules using committed Go and only the Apache
runtime.
- [ ] Run the parser, delimiter, context, path, and source-map release fuzz
@@ -75,5 +73,5 @@ it is not a production-stability promise.
machines.
- [ ] Confirm the sanitized public Gitea source contains no private paths,
identifiers, history, or unsupported claims.
- [ ] Publish and observe a signed RC on every supported native platform.
- [ ] Publish and observe a signed RC on the supported Linux/amd64 target.
- [ ] Publish `sando/v1.0.0`, then `v1.0.0`, without moving either tag.
+3 -2
View File
@@ -9,7 +9,8 @@ Security reports are welcome and receive best-effort maintainer assessment and
fixes while this pair is current. This is not production support,
an SLA, a fitness guarantee, or a promise that a fix will preserve beta APIs.
The community is invited to help find compatibility gaps, especially on macOS.
The community is invited to help find portability gaps outside the maintained
Linux target, but those reports do not create a support or release commitment.
That invitation does not outsource security assurance. Maintainers retain
responsibility for vulnerability review, triage, remediation decisions,
advisories, and release decisions.
@@ -35,7 +36,7 @@ public issue.
If that new mailbox rejects or bounces a message, retain the report and open a
canonical Gitea issue containing only the fact that the private security contact
failed. Do not include technical details or sensitive data. The maintainer will
publish a corrected private route. Ordinary usage, classroom, and macOS
publish a corrected private route. Ordinary usage, classroom, and portability
compatibility reports that do not reveal a vulnerability may use a public issue.
Helpful reports include:
+22 -15
View File
@@ -32,9 +32,17 @@ payloads before final v1, or hand-edited generated files.
## Go and platform support
The current beta targets Go 1.25 and Go 1.26. Support is based on point-in-time,
maintainer-run release matrices, not an implication of continuous CI coverage.
A Go support change is announced in release notes before it takes effect.
The current beta targets Go 1.25 and Go 1.26 on Linux/amd64. Required release
evidence runs in Linux CI and on Linux deployment hosts. WSL is treated as a
Linux development environment. Native Windows, macOS, and other targets are
not maintained release targets or release blockers; a successful build there
is useful portability evidence, not a compatibility promise. A Go or platform
support change is announced in release notes before it takes effect.
### Historical Beta 1 observations
The following table is retained because the tests genuinely ran. It records a
point-in-time Beta 1 campaign and does not define the current support matrix.
The current public evidence is the exact Beta 1 source at commit
`b7a84054d755e42285e50298e41e47f06a8325a5` (tree
@@ -45,26 +53,25 @@ The current public evidence is the exact Beta 1 source at commit
| Windows 11/amd64 on NTFS | 1.25.12, 1.26.5 | Native tests, race, vet, builds, generation, process cleanup, watcher boundaries, and temporary consumer compilation passed; privileged symlink and POSIX-only permission cases were not exercised |
| Linux/amd64 on WSL2 with an ext4 checkout | 1.25.12, 1.26.5 | Tests, race, vet, builds, generation, focused filesystem/development cases, and license checks passed |
| Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | The earlier pre-beta baseline passed tests, race, vet, builds, deterministic generation, and license checks; this was not rerun on the exact Beta 1 commit |
| macOS | — | Native maintainer validation pending; provisional for Beta 1 |
| macOS | — | Not executed during the Beta 1 campaign |
The golden generated file had SHA-256
`63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`
on every tested Windows and Linux lane.
on every tested Windows and Linux lane in that historical campaign.
The signed Beta tags and fresh direct/public-proxy installation were verified
after publication. For Beta 1, add the nested runtime to an application module
before installing the parent compiler at the same version; this avoids a Go
module-cache path-selection ambiguity observed in the reverse order.
## macOS feedback
## Portability feedback
Mac learners, teachers, and Go developers are warmly invited to try the beta.
A useful compatibility report includes the macOS version, Intel or Apple
Silicon architecture, `go version`, the exact command, and a minimal
reproduction or diagnostic output. Ordinary compatibility reports belong on
the canonical Gitea project. Suspected vulnerabilities must use the private
route in [SECURITY.md](../SECURITY.md).
Developers may try the beta on an unsupported target and report useful gaps. A
good report includes the operating system and architecture, `go version`, the
exact command, and a minimal reproduction or diagnostic output. Ordinary
portability reports belong on the canonical Gitea project. Suspected
vulnerabilities must use the private route in [SECURITY.md](../SECURITY.md).
Community reports can reveal gaps and help prioritize maintainer testing. They
do not constitute an independent audit or shift responsibility for security
review, triage, fixes, and release decisions to the community.
Community reports can reveal gaps and help prioritize future work. They do not
constitute an independent audit, create a support promise, or shift
responsibility for security review, triage, fixes, and release decisions.
+20 -17
View File
@@ -23,8 +23,10 @@ The named Windows and WSL2 platform runs used the exact public commit and tree
above. The isolated server-container matrix preceded the final candidate and
is retained only as supplementary Linux evidence. Hostnames, network addresses,
account names, private paths, private repository identities, and private commit
mappings are intentionally absent from this public ledger. Native macOS
execution remains pending and is provisional for the beta.
mappings are intentionally absent from this public ledger. These platform
observations are historical evidence, not the current support matrix.
Linux/amd64 is now the maintained release target; WSL is a Linux development
environment, while native Windows and macOS are not release blockers.
## Beta 2 compiler publication addendum
@@ -48,7 +50,8 @@ focused process-tree/watcher/consumer tests, candidate-stamped version checks,
and deterministic generation on Go 1.25.12 and Go 1.26.5. Clean isolated
`GOPROXY=direct` and public-proxy-only installs produced
`features:["lsp-stdio"]`; the public-proxy path also verified the retained
runtime through `sum.golang.org`. Native macOS execution remains provisional.
runtime through `sum.golang.org`. The Windows result is retained as historical
portability evidence and does not create an ongoing support promise.
The Beta 2 language server is additive development tooling. Its tested
security boundary includes protocol-only stdout; bounded header and message
@@ -83,7 +86,7 @@ baseline commit.
| URL scheme handling | ordinary/trusted URL test matrix | Pass for enumerated cases |
| Filesystem boundaries | symlink, nested-module, VCS, ownership, stale-output tests | Pass for tested cases; see open findings |
| Development proxy browser boundary | Host, Origin, Fetch Metadata, CSP, fragment and response tests | Pass for tested cases |
| Platform behavior | Exact-candidate native Windows and executed Linux matrices; macOS cross-compilation | Windows/Linux pass for tested lanes; native macOS pending |
| Platform behavior | Historical exact-candidate native Windows and executed Linux matrices | Windows/Linux passed for the tested lanes; current releases require Linux/amd64 evidence |
Coverage measures statements executed by tests. It is not branch completeness
and is not evidence that the executed behavior is secure.
@@ -92,7 +95,7 @@ and is not evidence that the executed behavior is secure.
and reachable through its analysis. A clean result cannot detect unknown flaws,
design errors, or vulnerabilities outside its model.
## Beta 1 native compatibility matrix
## Historical Beta 1 compatibility matrix
These are maintainer-run, point-in-time results, not continuous CI and not an
independent audit.
@@ -102,7 +105,7 @@ independent audit.
| Windows 11/amd64, NTFS | 1.25.12, 1.26.5 | Native PowerShell verifier with race; root/runtime tests, vet, trimpath build, freshness, two generation passes, process-tree cleanup, watcher boundaries, and temporary consumer compilation | Pass. Symlink-output rejection skipped because the test account lacked symlink privilege; the read-only-directory case is POSIX-only |
| Ubuntu 20.04/amd64 under WSL2, native ext4 checkout | 1.25.12, 1.26.5 | Race-enabled verifier; root/runtime tests, vet, build, two generation passes, ten focused filesystem cases, five focused development-process/watcher cases, and license check | Pass. This is Linux execution under WSL2, not bare-metal or Linux/arm64 evidence |
| Linux/amd64 server containers | 1.25.12, 1.26.5 | Earlier pre-beta root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass on the earlier baseline only. Container resources were capped at 1 CPU and 2 GiB; this is supplementary evidence, not an exact Beta 1 lane or Linux/arm64 evidence |
| macOS | — | Cross-compilation only | Native maintainer execution pending; provisional for Beta 1 |
| macOS | — | Cross-compilation only | No native Beta 1 evidence; not a maintained release target |
The generated golden `basic.sando.go` was 1,399 bytes and had SHA-256
`63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`
@@ -110,12 +113,12 @@ on every tested Windows and Linux lane. Repeated generation also preserved its
timestamp. This demonstrates cross-host agreement for one compiler-owned
fixture, not equivalence for every possible template.
Mac learners and Go developers are warmly invited to report ordinary
compatibility results with macOS version, architecture, `go version`, exact
command, and a minimal reproduction. Suspected vulnerabilities use the private
route in [SECURITY.md](../SECURITY.md). Community reports help find gaps;
maintainers remain responsible for reproducing security-relevant behavior,
triage, remediation, and release decisions.
Portability reports for unsupported targets may include the operating system,
architecture, `go version`, exact command, and a minimal reproduction.
Suspected vulnerabilities use the private route in
[SECURITY.md](../SECURITY.md). Such reports help find gaps but do not create a
support promise; maintainers remain responsible for security triage and fixes
on the supported Linux target.
## Security-relevant design evidence
@@ -203,8 +206,9 @@ known-vulnerability scans, candidate-version provenance checks, native Windows
and executed Linux matrices, and Windows/macOS cross-compilation on 2026-08-12.
Signed annotated runtime and compiler tags were then published from that commit
in that order. Fresh runtime-first installation passed through both direct Git
resolution and the public Go proxy after normal proxy propagation. Native
macOS and the other gaps below remain separate release decisions.
resolution and the public Go proxy after normal proxy propagation. Future
release decisions use the current Linux-only support policy rather than
requiring this historical multi-platform campaign.
## Open assurance gaps
@@ -214,9 +218,8 @@ macOS and the other gaps below remain separate release decisions.
- the signed annotated Beta tags and their common peeled commit were verified;
prebuilt-artifact signing, checksums, SBOM, reproducible provenance, and key
recovery remain incomplete;
- native macOS, Linux/arm64, and Windows/arm64 execution remain outstanding;
- Windows symlink rejection was not natively exercised because the test account
lacked symlink privilege;
- Linux/arm64 and non-Linux portability are outside the current maintained
release target;
- browser-parser differential and semantic property testing need expansion;
- compiler input size, CPU, and memory have no built-in hard budget;
- filesystem checks do not defend against a hostile local actor racing path
+1 -1
View File
@@ -177,7 +177,7 @@ Sandwich Hime does not:
## Open release work
- broaden semantic and browser-parser differential testing;
- execute the native Windows/macOS security and process-lifecycle matrix;
- execute the Linux/amd64 security and process-lifecycle release matrix;
- complete signed release provenance, checksums, and SBOM evidence;
- test the confidential reporting and signing-key recovery procedures; and
- close or explicitly accept every finding listed in the evidence ledger before
+17 -19
View File
@@ -28,17 +28,18 @@ private history or an indiscriminate Git mirror.
Beta 1 is deliberately earlier than a release candidate. It creates a real,
repeatable install for learners and evaluators without claiming that the final
v1 compatibility, native-platform, artifact, signing, or soak gates are
complete.
v1 compatibility, Linux release, artifact, signing, or soak gates are complete.
### Demonstrated for Beta 1
Public commit `b7a84054d755e42285e50298e41e47f06a8325a5` (tree
`be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run Go
1.25.12 and Go 1.26.5 matrices on native Windows/amd64, Linux/amd64 under WSL2,
with the earlier pre-beta server-container run retained only as supplementary
Linux evidence. The same generated golden SHA-256 was observed across the exact
Beta Windows and Linux lanes.
1.25.12 and Go 1.26.5 matrices on native Windows/amd64 and Linux/amd64 under
WSL2, with the earlier pre-beta server-container run retained only as
supplementary Linux evidence. The same generated golden SHA-256 was observed
across the exact Beta Windows and Linux lanes. This is historical evidence,
not the current support definition; Linux/amd64 is now the maintained release
target.
Other demonstrated controls include:
@@ -52,7 +53,7 @@ Other demonstrated controls include:
### Not demonstrated yet
- native maintainer-run macOS execution; macOS is provisional for Beta 1;
- final Linux/amd64 release-candidate evidence on the exact candidate;
- stable final-v1 API, CLI, schema, diagnostic, and generated snapshots;
- systematic browser-parser and `html/template` differential testing;
- a long semantic fuzz campaign beyond bounded no-panic smoke;
@@ -60,7 +61,7 @@ Other demonstrated controls include:
- complete real-browser development-supervisor evidence;
- deterministic prebuilt archives, checksums, SBOMs, signed binaries, and
tested signing/recovery procedures; or
- native macOS installation of the published Beta 1 tags.
- independently reproduced Linux release artifacts, checksums, and SBOMs.
## Beta 1 publication lane
@@ -68,9 +69,8 @@ Beta 1 is supported for learning, classroom projects, evaluation, prototypes,
and compatibility feedback. It is not recommended as a production-stable
dependency, and its interfaces may change.
- [x] Define beta support, security, compatibility, and macOS-provisional
language.
- [x] Establish the named public pre-beta Linux/Windows baseline.
- [x] Define beta support, security, and compatibility language.
- [x] Establish the historical public pre-beta Linux/Windows evidence baseline.
- [x] Rerun the supported Go matrix and deterministic generation on the exact
Beta 1 candidate.
- [x] Run the candidate-version freshness, bounded fuzz, vulnerability, and
@@ -79,12 +79,10 @@ dependency, and its interfaces may change.
`v1.0.0-beta.1`, from the same reviewed public commit.
- [x] Verify clean runtime-first direct and public-proxy installs and record the
result.
- [ ] Add native macOS maintainer evidence before RC; community reports inform
that work but do not replace maintainer responsibility.
## Milestone 1: contract freeze
Required before security/platform release-candidate work is declared complete:
Required before security/Linux release-candidate work is declared complete:
- [ ] Decide and specify whether generic component function signatures are v1.
- [ ] Inventory and freeze every exported `sando` symbol, trusted type,
@@ -97,11 +95,11 @@ Required before security/platform release-candidate work is declared complete:
output compatibility snapshots.
- [ ] Define the v1 deprecation and security-support policy.
## Milestone 2: security and native-platform evidence
## Milestone 2: security and Linux release evidence
- [ ] Run the minimum supported Go line and the latest two stable Go lines on
native Linux, macOS, and Windows hosts.
- [ ] Prove identical generated bytes across those hosts and exercise native
Linux/amd64 runners and a Linux deployment-class host.
- [ ] Prove identical generated bytes across those Linux lanes and exercise
path, replacement, permission, race, process-tree, and watcher behavior.
- [ ] Build a systematic differential corpus against Go's documented
`html/template` safety baseline for overlapping supported contexts.
@@ -147,7 +145,7 @@ Required before security/platform release-candidate work is declared complete:
2. Publish signed `sando/v1.0.0-rc.1`, then signed `v1.0.0-rc.1` from the same
reviewed public Gitea commit.
3. Verify documented installs through fresh `GOPROXY=direct` and
`proxy.golang.org` caches on supported Go versions and native platforms.
`proxy.golang.org` caches on supported Go versions under Linux/amd64.
4. Run the complete evidence suite again from the exact public commit.
5. Operate the official Sandwich Hime website on the RC runtime for a 14-day
observation period with no unresolved Hime render, security, accessibility,
@@ -172,6 +170,6 @@ marketing. New features do not outrank a small stable contract.
## Definition of confidence
“Ready for v1” means a reviewer can trace each promise to a stable public
contract, executable evidence from supported native environments, and a signed
contract, executable evidence from supported Linux environments, and a signed
artifact built from the exact canonical source. It does not mean perfect,
invulnerable, or finished forever.
+7 -3
View File
@@ -2,10 +2,11 @@
# Repository verification tools
These scripts are intentionally understandable shell and PowerShell rather than a release framework with hidden defaults.
These scripts are intentionally understandable shell rather than a release
framework with hidden defaults. The maintained verification and release path
is Linux.
- `verify.sh` runs root and nested-module tests and vet, builds `himesan`, checks the compiler-owned golden output, and proves two generation passes leave the same bytes and unchanged modification times. Set `HIMESAN_RACE=1` for race tests.
- `verify.ps1` provides the equivalent native Windows lane; pass `-Race` to include the race detector.
- `check-licenses.sh` enforces the AGPL compiler / Apache runtime boundary and prevents generated application Go from inheriting an AGPL identifier.
- `release-check.sh --version vX.Y.Z` is a clean-checkout technical preflight, including exact candidate-version and generated-provenance checks. Beta publication follows the narrower prerelease gates in `RELEASE.md`; release candidates and final v1 additionally use `--public` with a human-reviewed `HIMESAN_RELEASE_EVIDENCE_DIR`. The script never tags, pushes, publishes, or deploys.
- `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes, adds the nested runtime before installing the parent compiler, and exercises fresh direct-fetch and public-proxy caches without interactive Git credentials.
@@ -16,6 +17,9 @@ The release preflight invokes `govulncheck` from the official Go vulnerability p
## Preview automation status
Forge workflows are intentionally excluded from the sanitized pre-1.0 public snapshot until the project has confirmed its own Gitea runner availability and reviewed locally hosted or otherwise pinned dependencies. Local `verify.sh`, `verify.ps1`, license, and release-preflight results are the preview gates.
Forge workflows are intentionally excluded from the sanitized pre-1.0 public
snapshot. The private development repository uses pinned Linux runners; the
public source remains independently verifiable with `verify.sh`, the license
check, and the Linux release preflight.
If Gitea automation is later added to the public repository, pin every external action to a reviewed immutable commit, document its provenance, grant minimum permissions, and keep a local verification path. A secondary forge may host a sanitized, read-only discovery snapshot, but hosted workflows stay disabled there and it does not become a release or contribution authority.
+4 -13
View File
@@ -253,23 +253,14 @@ go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./...
go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./...
)
printf '\n==> cross-compiling release binary smoke set\n'
printf '\n==> building supported Linux release binary\n'
for target in \
linux/amd64 \
linux/arm64 \
darwin/amd64 \
darwin/arm64 \
windows/amd64 \
windows/arm64; do
linux/amd64; do
target_os=${target%/*}
target_arch=${target#*/}
extension=''
if [[ "$target_os" == windows ]]; then
extension='.exe'
fi
CGO_ENABLED=0 GOOS="$target_os" GOARCH="$target_arch" \
go build -trimpath -ldflags "$compiler_linker_flags" \
-o "$artifact_dir/himesan-$target_os-$target_arch$extension" ./cmd/himesan
-o "$artifact_dir/himesan-$target_os-$target_arch" ./cmd/himesan
done
for required in \
@@ -289,7 +280,7 @@ if (( public_release == 1 )); then
fi
for evidence in \
legal-review.md \
cross-platform.md \
linux-platform.md \
security.md \
development-supervisor.md \
benchmark-methodology.md \
-133
View File
@@ -1,133 +0,0 @@
# SPDX-License-Identifier: AGPL-3.0-only
[CmdletBinding()]
param(
[switch]$Race
)
$ErrorActionPreference = "Stop"
$RepoRoot = (Resolve-Path (Join-Path $PSScriptRoot "..")).Path
Set-Location $RepoRoot
function Invoke-Checked {
param(
[Parameter(Mandatory = $true)]
[string]$Label,
[Parameter(Mandatory = $true)]
[scriptblock]$Command
)
Write-Host "`n==> $Label"
& $Command
if ($LASTEXITCODE -ne 0) {
throw "$Label failed with exit code $LASTEXITCODE"
}
}
function Invoke-ModuleChecks {
param(
[Parameter(Mandatory = $true)]
[string]$Directory,
[Parameter(Mandatory = $true)]
[string]$Label
)
Push-Location $Directory
try {
Invoke-Checked "$Label`: go test" { go test ./... }
Invoke-Checked "$Label`: go vet" { go vet ./... }
}
finally {
Pop-Location
}
}
function Get-SandoSources {
if (-not (Test-Path "internal/compiler/testdata/golden" -PathType Container)) {
return @()
}
return @(Get-ChildItem "internal/compiler/testdata/golden" -File -Filter "*.sando" |
Sort-Object FullName)
}
function Get-GeneratedManifest {
$lines = foreach ($source in (Get-SandoSources)) {
$output = "$($source.FullName).go"
if (-not (Test-Path $output -PathType Leaf)) {
"missing $output"
continue
}
$hash = (Get-FileHash -Algorithm SHA256 $output).Hash.ToLowerInvariant()
$modified = (Get-Item -LiteralPath $output).LastWriteTimeUtc.Ticks
"$hash $modified $output"
}
return ($lines -join "`n")
}
$TempRoot = Join-Path ([System.IO.Path]::GetTempPath()) ("himesan-verify-" + [guid]::NewGuid())
New-Item -ItemType Directory -Path $TempRoot | Out-Null
try {
Invoke-ModuleChecks "." "compiler module"
Invoke-Checked "compiler module: go build" {
go build -trimpath -o (Join-Path $TempRoot "himesan.exe") ./cmd/himesan
}
if (-not (Test-Path "sando/go.mod" -PathType Leaf)) {
throw "nested Apache runtime module sando/go.mod is missing"
}
Invoke-ModuleChecks "sando" "sando runtime module"
$Sources = @(Get-SandoSources)
if ($Sources.Count -eq 0) {
throw "compiler-owned golden .sando fixture is missing"
}
else {
$SourcePaths = @($Sources | ForEach-Object { $_.FullName })
$CheckArgs = @("run", "./cmd/himesan", "check") + $SourcePaths
$GenerateArgs = @("run", "./cmd/himesan", "generate") + $SourcePaths
Invoke-Checked "golden generation: read-only freshness check" {
& go $CheckArgs
}
$Before = Get-GeneratedManifest
Invoke-Checked "golden generation: first deterministic pass" {
& go $GenerateArgs
}
$First = Get-GeneratedManifest
if ($Before -cne $First) {
throw "generation changed committed output after check declared it fresh"
}
Invoke-Checked "golden generation: second deterministic pass" {
& go $GenerateArgs
}
$Second = Get-GeneratedManifest
if ($First -cne $Second) {
throw "repeated generation changed output bytes or an unchanged timestamp"
}
Invoke-Checked "golden generation: final freshness check" {
& go $CheckArgs
}
}
if ($Race) {
Invoke-Checked "compiler module: race tests" { go test -race ./... }
Push-Location "sando"
try {
Invoke-Checked "sando runtime module: race tests" { go test -race ./... }
}
finally {
Pop-Location
}
}
Write-Host "`n==> verification complete"
}
finally {
if (Test-Path $TempRoot -PathType Container) {
Remove-Item -LiteralPath $TempRoot -Recurse -Force
}
}