Maintain Linux as the Sandwich Hime release target #1

Merged
gamertan merged 1 commits from codex/linux-release-policy into main 2026-08-16 17:58:47 -04:00
14 changed files with 142 additions and 250 deletions
+17
View File
@@ -6,6 +6,23 @@ Sandwich Hime follows semantic versioning after final v1. Compiler and nested
runtime releases are versioned independently and listed together when they form runtime releases are versioned independently and listed together when they form
one coordinated release. one coordinated release.
## Unreleased
### Changed
- Linux/amd64 is the maintained execution, verification, artifact, and release
target. WSL remains a Linux development environment; native Windows, macOS,
and other targets are best-effort portability surfaces rather than release
gates or compatibility promises.
- Release preflight now builds the supported Linux/amd64 candidate only and
requires Linux platform evidence for RC/final publication.
### Removed
- The native Windows PowerShell verifier and private multi-OS release-gate
workflow. Historical platform evidence and best-effort portability code are
retained without creating a support obligation.
## v1.0.0-beta.2 — 2026-08-12 ## v1.0.0-beta.2 — 2026-08-12
Compiler-only release; the unchanged Apache runtime remains Compiler-only release; the unchanged Apache runtime remains
+1 -1
View File
@@ -1 +1 @@
{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":90,"allowlist_sha256":"393ee598dc7e12cdbb603887bf06599e46b40d7c19e4ff693a818cc32afb01ec","manifest_sha256":"38a02b05cec70c82076df0f40de8b98edfc9280f54c12fa0cbe84949da253fdf"} {"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":89,"allowlist_sha256":"2947ef034f9bfe9bd20c00e67d0033f0ff5e62e55fc2db0952696485d9eeec40","manifest_sha256":"5005a799e84f5cbb66cc9d0ced03c5897924de1b9c28adf8aaf06b2ddb4affff"}
+11 -12
View File
@@ -2,7 +2,7 @@
658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes 658ba4b4645426f8c3249337f47669074ae9249a31703dcd9ea4c1afec45e20b ./.gitattributes
d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore d5ae411fb422b2388cac220f9655900eecbc49ece961b2bb2a6610347733b756 ./.gitignore
98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md 98f663ab0f376b4550094465ec2e06192d1e0b0707604ec6794f20b0d10952c1 ./AI_CONTRIBUTIONS.md
0828545d3aa440e1ec5dce4b934de6800413f55a925988b60923c5ee9b700a4e ./CHANGELOG.md 5bc3db089eb243640adc2e4bae62d94754aff420d1eb64057036032dfd9a626b ./CHANGELOG.md
b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md b696cab3cf482ff5737501371cca749369b119351383e698ced42bcdbcbfc8ae ./CLA.md
797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md 797e884105738fc931b585b695424f43ec5f296d8ab9bba5191b096e87a9e2c2 ./CONTRIBUTING.md
86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT 86d7e49d5d90e0f98a4ad0f14b5d8b9f11ed09a1e29ecdf27388316b28e195e8 ./COPYRIGHT
@@ -13,10 +13,10 @@ a4570d054f072d33b8f17b0c8b162a6ee0ca37d7df2b1aee7e4b728ab350a892 ./GOVERNANCE.m
47d857e49f89596bac9b09fc8ca57a668a33d01e2b51508acfc92ed321cdc27f ./LICENSES.md 47d857e49f89596bac9b09fc8ca57a668a33d01e2b51508acfc92ed321cdc27f ./LICENSES.md
b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS.md
6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md 6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md
c3ac873ae2e6248e1d86dd542a11557b24b8dba80e4785f3bc1018152020235c ./README.md fbc4a7c118ac983a1ea49dc3a9d714f5130ace21a8af59ab9fcabd6519cb6b97 ./README.md
2751674c180f15a42c1d2b40cf149be4138aa6cf247d7be176f1f0c468103c24 ./RELEASE.md fafa1494fa1a5a5cf3b3d371155f0448d46f1f13cd394555e06396b336bc102a ./RELEASE.md
209decb6769646eb2f58e312fbcd9c497c26234f3d3115bae3f20493b8178584 ./ROADMAP.md c0e65a8bffcba71cd42d6122be25fd4993c04c8cba8c5e69108c9f5dbaca9243 ./ROADMAP.md
0fef473ac46b71215d1eb7922da4594210ffbbb8bb2dedd5e531fb3bd09396e1 ./SECURITY.md 17e10aaab589d40b479e374523982117d2c7ffac95306493cfa4e3171108a1a8 ./SECURITY.md
53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md 53bd6eda804d6b782bdb07115ec197c890813cf2d5d0125dfe8f47f5f92f75b0 ./SPEC.md
3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md 3d9e680cdfe147df7cc9ff29ecf1d3e566e9cd559ae84db4880e559b9c7c7205 ./TRADEMARKS.md
8cd8db68e1300f9b78cc7235855853cbc7aeb499a921419e23a22e4d22826fcb ./cmd/himesan/main.go 8cd8db68e1300f9b78cc7235855853cbc7aeb499a921419e23a22e4d22826fcb ./cmd/himesan/main.go
@@ -24,13 +24,13 @@ c3ac873ae2e6248e1d86dd542a11557b24b8dba80e4785f3bc1018152020235c ./README.md
1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md 1ecbba46f8b1b2d548a01d7e98afae17b2dd17a814338ff1f88db885655d1c07 ./docs/ARCHITECTURE.md
9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md 9c598559a89fa4a9bdd2311bd1ed8330992d0a0f74ec8b29ac151fc0ff8fef16 ./docs/BENCHMARKS.md
5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md 5c3a62fed80ca28d56558b8c75e8b5be8ba7d2554127adf4609d96da314e85b0 ./docs/BRAND.md
2b815d3b815b8d338560183c6f0af46f761c2465309783c93870b8ac8d022d03 ./docs/COMPATIBILITY.md a88ae86f046779db2ee4e0e7458510d782c459ab898efb8b58decaec53f72743 ./docs/COMPATIBILITY.md
5f4ac209a16ab110baeaa64a40c19d9239c903e17550c3f05e1e1473ddcc33a3 ./docs/DEVELOPMENT_SERVER.md 5f4ac209a16ab110baeaa64a40c19d9239c903e17550c3f05e1e1473ddcc33a3 ./docs/DEVELOPMENT_SERVER.md
51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md 51aa57a81131b64f76c45552122de842f22be92d81c8bba8f6fd38a18a7670d6 ./docs/DIAGNOSTICS.md
a62cc7174f3c92d8ef77e4bd9607fbf5d4b80bc514ff05bd433c02a9b0578f18 ./docs/LANGUAGE_SERVER.md a62cc7174f3c92d8ef77e4bd9607fbf5d4b80bc514ff05bd433c02a9b0578f18 ./docs/LANGUAGE_SERVER.md
091d40da988d61e0f2f13fa022363a2113aea626a45785ddd348eca2817be56c ./docs/SECURITY_EVIDENCE.md f2622e0eba601470624e862caf717060c7b73037f13f0b7bd6e9792a49463480 ./docs/SECURITY_EVIDENCE.md
d969c7b5486ee93e54232fd69d9db06f3b4dc1bba63001596ec48545073c2680 ./docs/THREAT_MODEL.md f2423c325ebe5371af43db6b09b11ea5a4ea3d3d3c14098f9d0ccd89110ea03d ./docs/THREAT_MODEL.md
738258ba8f7e5ffea67d3f00eb70839590171971a9946a55b013ca95baf7aafb ./docs/V1_RELEASE_PLAN.md bb2fde5ffd9736ef2a46b2931484bcec7b872353c7c20821a8fa7a32946fa97d ./docs/V1_RELEASE_PLAN.md
f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod f27c46ca63707bb8cc570eab1ea521824e94bc59b1d153998a5e91c2c7340d16 ./go.mod
ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go ca0bf5051d356d2602f46201fb1637ce48b629ad42161877eec13f743f215dc5 ./internal/compiler/abi_test.go
d891b9b075617050471b2ca34de73d926aaebde4ec638a5039b0d5001d3172f4 ./internal/compiler/analysis.go d891b9b075617050471b2ca34de73d926aaebde4ec638a5039b0d5001d3172f4 ./internal/compiler/analysis.go
@@ -82,9 +82,8 @@ ff76daee5b642ad84af31701833246d68b54d09580192312d750a7a2e893a692 ./sando/go.mod
80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go 80ff53787919e809b8085d6ad9c3e183c9c7c1d74cfeda73369ac5c4607c236f ./sando/trust.go
85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go 85621a44c730582f4410ac2c70418b739fb55e916f7e6b73a1a619982c459572 ./sando/write.go
b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go b188917e258890e6b6e4840a6fd946fc9a77cabc2068da3764f221e4a6a5df97 ./sando/write_test.go
c4a161faba46ce5b508c0788078256a520277a573a3ace0e85ae0c26b16d298b ./scripts/README.md 36265470310f8463895761bb53a2137583d395d4b19b0190d038eecce1f4ce25 ./scripts/README.md
0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh 0bc796f71c863aa898674a26c56f055e3d81cf20629ca7b32fbae87d8841e0a8 ./scripts/check-licenses.sh
1b003062799b99bfe271b47438397a8cce5875c60c982a0117eb11c3babcadf0 ./scripts/release-check.sh 03d58bea32691d6d503983ddcf979fb88091eed4cb322e74a9eeb4ee434bacec ./scripts/release-check.sh
78a64c7fb3a039b15a1d08b4c0b873952852287a07f670247b081e59dbb09a30 ./scripts/verify-public-install.sh 78a64c7fb3a039b15a1d08b4c0b873952852287a07f670247b081e59dbb09a30 ./scripts/verify-public-install.sh
24ed3c9a1d37e46a856cbbd68e5c58ae04c6c9852902b99ed675e1f428339a9f ./scripts/verify.ps1
f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh f0cbd86759fa729064cb1c69991db2ac291792dadb6b1e1ba83794f2e390404d ./scripts/verify.sh
+11 -7
View File
@@ -48,13 +48,17 @@ semantic-version prerelease: source syntax, generated output, the runtime API,
and CLI behavior may change before final v1, and this beta is not recommended and CLI behavior may change before final v1, and this beta is not recommended
for production deployment. for production deployment.
The exact Beta 1 source passed maintainer-run native Windows and executed Linux Linux/amd64 is the maintained execution and release target. Required release
matrices with Go 1.25.12 and Go 1.26.5. Native macOS validation is still evidence runs on Linux with the supported Go lines. WSL is a useful Linux
pending, so macOS support is provisional in this beta. Mac learners and Go development environment, but it does not turn native Windows into a supported
developers are warmly invited to try it and share their macOS version, target. Native Windows, macOS, and other operating systems may happen to build
architecture, Go version, command, and smallest useful reproduction. Community or work and portability reports are welcome; they are not release gates or a
reports broaden the evidence; maintainers remain responsible for security maintained compatibility promise.
review, triage, fixes, and release decisions.
The evidence ledger retains the exact Beta 1 Windows and Linux observations as
historical facts. Those past results do not expand the current support policy.
Maintainers remain responsible for security review, triage, fixes, and release
decisions on the supported Linux target.
Inside an application module, add the small runtime first: Inside an application module, add the small runtime first:
+19 -16
View File
@@ -21,11 +21,11 @@ while it is the current prerelease, but it is not recommended or supported as a
production-stable dependency. Syntax, generated output, runtime APIs, CLI production-stable dependency. Syntax, generated output, runtime APIs, CLI
behavior, and diagnostics may change in a later prerelease. behavior, and diagnostics may change in a later prerelease.
Beta 1 may publish with native macOS validation pending when Windows and Linux Current and future beta release gates run on Linux/amd64. WSL may be used as a
have passed the exact-candidate matrix and macOS is clearly marked provisional. Linux development environment, but native Windows, macOS, and other targets
Community Mac results are valuable compatibility input; they do not transfer are not release blockers or maintained compatibility promises. Portability
security review, triage, remediation, or release responsibility away from the reports remain useful input; they do not transfer security review, triage,
maintainers. remediation, or release responsibility away from the maintainers.
Beta tags are signed, annotated, and immutable. Beta 1 is a source/module Beta tags are signed, annotated, and immutable. Beta 1 is a source/module
release installed through the Go toolchain; it does not promise downloadable release installed through the Go toolchain; it does not promise downloadable
@@ -37,9 +37,9 @@ final v1.
An RC means the intended v1 source, runtime, CLI, diagnostics, schemas, and An RC means the intended v1 source, runtime, CLI, diagnostics, schemas, and
generated contract are frozen except for release-blocking fixes. An RC requires generated contract are frozen except for release-blocking fixes. An RC requires
maintainer-run native Linux, macOS, and Windows evidence, complete release maintainer-run Linux/amd64 evidence, complete release artifacts and provenance,
artifacts and provenance, signed tags, clean direct/proxy installs, and every RC signed tags, clean direct/proxy installs, and every RC gate in this repository.
gate in this repository. Findings produce a new RC rather than a moved tag. Findings produce a new RC rather than a moved tag.
### Final v1 ### Final v1
@@ -49,7 +49,11 @@ published assurance gap, and the documented RC observation period. A
deployment, example, classroom project, or case study in another repository is deployment, example, classroom project, or case study in another repository is
neither imported nor required as release evidence. neither imported nor required as release evidence.
## Beta 1 publication gates ## Beta 1 publication gates (historical)
The first beta used a broader one-time platform campaign. The completed items
below are retained as publication history; they do not define future platform
support.
Before `sando/v1.0.0-beta.1` and `v1.0.0-beta.1` are created: Before `sando/v1.0.0-beta.1` and `v1.0.0-beta.1` are created:
@@ -99,8 +103,7 @@ In addition to every Beta 1 compiler/security/determinism gate:
nested-module boundaries, completion scope, and component definitions; nested-module boundaries, completion scope, and component definitions;
2. prove the language-server package does not write, execute project code, 2. prove the language-server package does not write, execute project code,
invoke Go, fetch, access the network, or start the development supervisor; invoke Go, fetch, access the network, or start the development supervisor;
3. run the exact candidate on supported Go lines under executed Linux and 3. run the exact candidate on supported Go lines under executed Linux/amd64;
native Windows, with native macOS status stated explicitly;
4. build an exact version-stamped candidate and assert the additive 4. build an exact version-stamped candidate and assert the additive
`features: ["lsp-stdio"]` JSON identity; `features: ["lsp-stdio"]` JSON identity;
5. publish a signed annotated compiler tag only after the reviewed sanitized 5. publish a signed annotated compiler tag only after the reviewed sanitized
@@ -111,16 +114,16 @@ In addition to every Beta 1 compiler/security/determinism gate:
## RC and final gates ## RC and final gates
No release candidate or v1.0.0 release occurs until every applicable gate in No release candidate or v1.0.0 release occurs until every applicable gate in
this repository is evidenced, including cross-platform deterministic this repository is evidenced, including deterministic generation on supported
generation, temporary-module compilation, fuzz/adversarial suites, Linux and Go lanes, temporary-module compilation, fuzz/adversarial suites,
race/vet/vulnerability/license checks on the latest two supported Go lines, race/vet/vulnerability/license checks on the latest two supported Go lines,
development-supervisor failure tests, and reproducible repository-owned development-supervisor failure tests, and reproducible repository-owned
benchmark and security results. benchmark and security results.
Release candidates require a clean canonical checkout, reviewed changelog, Release candidates require a clean canonical checkout, reviewed changelog,
compatible vanity-import metadata, reproducible binaries, signed annotated compatible vanity-import metadata, reproducible Linux/amd64 binaries, signed
tags, checksums, SBOMs, vulnerability results, and verification on Linux, annotated tags, checksums, SBOMs, vulnerability results, and verification on
macOS, and Windows. Linux/amd64.
## Public source and artifacts ## Public source and artifacts
+9 -11
View File
@@ -7,31 +7,29 @@ necessarily blockers for an earlier prerelease. The ordered initiative,
repository topology, release-candidate sequence, and definition of confidence repository topology, release-candidate sequence, and definition of confidence
are maintained in [docs/V1_RELEASE_PLAN.md](docs/V1_RELEASE_PLAN.md). are maintained in [docs/V1_RELEASE_PLAN.md](docs/V1_RELEASE_PLAN.md).
## Beta 1: public learning and evaluation ## Beta 1: public learning and evaluation (historical)
Beta 1 deliberately ships before the final-v1 compatibility and artifact gates. Beta 1 deliberately ships before the final-v1 compatibility and artifact gates.
Its scope is classroom use, learning, prototypes, and compatibility feedback; Its scope is classroom use, learning, prototypes, and compatibility feedback;
it is not a production-stability promise. it is not a production-stability promise.
- [x] Define beta versus RC/final support and compatibility policy. - [x] Define beta versus RC/final support and compatibility policy.
- [x] Establish a public pre-beta Linux/Windows matrix on Go 1.25 and Go 1.26. - [x] Establish a one-time public pre-beta Linux/Windows evidence matrix on Go
- [x] Document macOS as provisional and invite useful community reports while 1.25 and Go 1.26.
retaining maintainer responsibility for security and releases. - [x] Record the untested macOS boundary without presenting it as evidence.
- [x] Rerun all required Windows/Linux checks and deterministic generation on - [x] Rerun the historical Windows/Linux campaign and deterministic generation
the exact Beta 1 candidate. on the exact Beta 1 candidate.
- [x] Publish immutable `sando/v1.0.0-beta.1`, then - [x] Publish immutable `sando/v1.0.0-beta.1`, then
`v1.0.0-beta.1`, from the reviewed public commit. `v1.0.0-beta.1`, from the reviewed public commit.
- [x] Verify clean runtime-first direct and public-proxy installs after - [x] Verify clean runtime-first direct and public-proxy installs after
publication. publication.
- [ ] Complete native macOS maintainer validation. This is an RC/final gate,
not a Beta 1 gate.
## Compiler and runtime for RC/final ## Compiler and runtime for RC/final
- [ ] Freeze and machine-check the compiler, CLI, diagnostic, schema, generated, - [ ] Freeze and machine-check the compiler, CLI, diagnostic, schema, generated,
and runtime compatibility contracts. and runtime compatibility contracts.
- [ ] Repeat compiler-owned deterministic golden output across Linux, macOS, - [ ] Repeat compiler-owned deterministic golden output across the supported
and Windows on the exact candidate. Linux and Go lanes on the exact candidate.
- [ ] Compile temporary consumer modules using committed Go and only the Apache - [ ] Compile temporary consumer modules using committed Go and only the Apache
runtime. runtime.
- [ ] Run the parser, delimiter, context, path, and source-map release fuzz - [ ] Run the parser, delimiter, context, path, and source-map release fuzz
@@ -75,5 +73,5 @@ it is not a production-stability promise.
machines. machines.
- [ ] Confirm the sanitized public Gitea source contains no private paths, - [ ] Confirm the sanitized public Gitea source contains no private paths,
identifiers, history, or unsupported claims. identifiers, history, or unsupported claims.
- [ ] Publish and observe a signed RC on every supported native platform. - [ ] Publish and observe a signed RC on the supported Linux/amd64 target.
- [ ] Publish `sando/v1.0.0`, then `v1.0.0`, without moving either tag. - [ ] Publish `sando/v1.0.0`, then `v1.0.0`, without moving either tag.
+3 -2
View File
@@ -9,7 +9,8 @@ Security reports are welcome and receive best-effort maintainer assessment and
fixes while this pair is current. This is not production support, fixes while this pair is current. This is not production support,
an SLA, a fitness guarantee, or a promise that a fix will preserve beta APIs. an SLA, a fitness guarantee, or a promise that a fix will preserve beta APIs.
The community is invited to help find compatibility gaps, especially on macOS. The community is invited to help find portability gaps outside the maintained
Linux target, but those reports do not create a support or release commitment.
That invitation does not outsource security assurance. Maintainers retain That invitation does not outsource security assurance. Maintainers retain
responsibility for vulnerability review, triage, remediation decisions, responsibility for vulnerability review, triage, remediation decisions,
advisories, and release decisions. advisories, and release decisions.
@@ -35,7 +36,7 @@ public issue.
If that new mailbox rejects or bounces a message, retain the report and open a If that new mailbox rejects or bounces a message, retain the report and open a
canonical Gitea issue containing only the fact that the private security contact canonical Gitea issue containing only the fact that the private security contact
failed. Do not include technical details or sensitive data. The maintainer will failed. Do not include technical details or sensitive data. The maintainer will
publish a corrected private route. Ordinary usage, classroom, and macOS publish a corrected private route. Ordinary usage, classroom, and portability
compatibility reports that do not reveal a vulnerability may use a public issue. compatibility reports that do not reveal a vulnerability may use a public issue.
Helpful reports include: Helpful reports include:
+22 -15
View File
@@ -32,9 +32,17 @@ payloads before final v1, or hand-edited generated files.
## Go and platform support ## Go and platform support
The current beta targets Go 1.25 and Go 1.26. Support is based on point-in-time, The current beta targets Go 1.25 and Go 1.26 on Linux/amd64. Required release
maintainer-run release matrices, not an implication of continuous CI coverage. evidence runs in Linux CI and on Linux deployment hosts. WSL is treated as a
A Go support change is announced in release notes before it takes effect. Linux development environment. Native Windows, macOS, and other targets are
not maintained release targets or release blockers; a successful build there
is useful portability evidence, not a compatibility promise. A Go or platform
support change is announced in release notes before it takes effect.
### Historical Beta 1 observations
The following table is retained because the tests genuinely ran. It records a
point-in-time Beta 1 campaign and does not define the current support matrix.
The current public evidence is the exact Beta 1 source at commit The current public evidence is the exact Beta 1 source at commit
`b7a84054d755e42285e50298e41e47f06a8325a5` (tree `b7a84054d755e42285e50298e41e47f06a8325a5` (tree
@@ -45,26 +53,25 @@ The current public evidence is the exact Beta 1 source at commit
| Windows 11/amd64 on NTFS | 1.25.12, 1.26.5 | Native tests, race, vet, builds, generation, process cleanup, watcher boundaries, and temporary consumer compilation passed; privileged symlink and POSIX-only permission cases were not exercised | | Windows 11/amd64 on NTFS | 1.25.12, 1.26.5 | Native tests, race, vet, builds, generation, process cleanup, watcher boundaries, and temporary consumer compilation passed; privileged symlink and POSIX-only permission cases were not exercised |
| Linux/amd64 on WSL2 with an ext4 checkout | 1.25.12, 1.26.5 | Tests, race, vet, builds, generation, focused filesystem/development cases, and license checks passed | | Linux/amd64 on WSL2 with an ext4 checkout | 1.25.12, 1.26.5 | Tests, race, vet, builds, generation, focused filesystem/development cases, and license checks passed |
| Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | The earlier pre-beta baseline passed tests, race, vet, builds, deterministic generation, and license checks; this was not rerun on the exact Beta 1 commit | | Linux/amd64 in isolated containers on a Linux server | 1.25.12, 1.26.5 | The earlier pre-beta baseline passed tests, race, vet, builds, deterministic generation, and license checks; this was not rerun on the exact Beta 1 commit |
| macOS | — | Native maintainer validation pending; provisional for Beta 1 | | macOS | — | Not executed during the Beta 1 campaign |
The golden generated file had SHA-256 The golden generated file had SHA-256
`63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f` `63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`
on every tested Windows and Linux lane. on every tested Windows and Linux lane in that historical campaign.
The signed Beta tags and fresh direct/public-proxy installation were verified The signed Beta tags and fresh direct/public-proxy installation were verified
after publication. For Beta 1, add the nested runtime to an application module after publication. For Beta 1, add the nested runtime to an application module
before installing the parent compiler at the same version; this avoids a Go before installing the parent compiler at the same version; this avoids a Go
module-cache path-selection ambiguity observed in the reverse order. module-cache path-selection ambiguity observed in the reverse order.
## macOS feedback ## Portability feedback
Mac learners, teachers, and Go developers are warmly invited to try the beta. Developers may try the beta on an unsupported target and report useful gaps. A
A useful compatibility report includes the macOS version, Intel or Apple good report includes the operating system and architecture, `go version`, the
Silicon architecture, `go version`, the exact command, and a minimal exact command, and a minimal reproduction or diagnostic output. Ordinary
reproduction or diagnostic output. Ordinary compatibility reports belong on portability reports belong on the canonical Gitea project. Suspected
the canonical Gitea project. Suspected vulnerabilities must use the private vulnerabilities must use the private route in [SECURITY.md](../SECURITY.md).
route in [SECURITY.md](../SECURITY.md).
Community reports can reveal gaps and help prioritize maintainer testing. They Community reports can reveal gaps and help prioritize future work. They do not
do not constitute an independent audit or shift responsibility for security constitute an independent audit, create a support promise, or shift
review, triage, fixes, and release decisions to the community. responsibility for security review, triage, fixes, and release decisions.
+20 -17
View File
@@ -23,8 +23,10 @@ The named Windows and WSL2 platform runs used the exact public commit and tree
above. The isolated server-container matrix preceded the final candidate and above. The isolated server-container matrix preceded the final candidate and
is retained only as supplementary Linux evidence. Hostnames, network addresses, is retained only as supplementary Linux evidence. Hostnames, network addresses,
account names, private paths, private repository identities, and private commit account names, private paths, private repository identities, and private commit
mappings are intentionally absent from this public ledger. Native macOS mappings are intentionally absent from this public ledger. These platform
execution remains pending and is provisional for the beta. observations are historical evidence, not the current support matrix.
Linux/amd64 is now the maintained release target; WSL is a Linux development
environment, while native Windows and macOS are not release blockers.
## Beta 2 compiler publication addendum ## Beta 2 compiler publication addendum
@@ -48,7 +50,8 @@ focused process-tree/watcher/consumer tests, candidate-stamped version checks,
and deterministic generation on Go 1.25.12 and Go 1.26.5. Clean isolated and deterministic generation on Go 1.25.12 and Go 1.26.5. Clean isolated
`GOPROXY=direct` and public-proxy-only installs produced `GOPROXY=direct` and public-proxy-only installs produced
`features:["lsp-stdio"]`; the public-proxy path also verified the retained `features:["lsp-stdio"]`; the public-proxy path also verified the retained
runtime through `sum.golang.org`. Native macOS execution remains provisional. runtime through `sum.golang.org`. The Windows result is retained as historical
portability evidence and does not create an ongoing support promise.
The Beta 2 language server is additive development tooling. Its tested The Beta 2 language server is additive development tooling. Its tested
security boundary includes protocol-only stdout; bounded header and message security boundary includes protocol-only stdout; bounded header and message
@@ -83,7 +86,7 @@ baseline commit.
| URL scheme handling | ordinary/trusted URL test matrix | Pass for enumerated cases | | URL scheme handling | ordinary/trusted URL test matrix | Pass for enumerated cases |
| Filesystem boundaries | symlink, nested-module, VCS, ownership, stale-output tests | Pass for tested cases; see open findings | | Filesystem boundaries | symlink, nested-module, VCS, ownership, stale-output tests | Pass for tested cases; see open findings |
| Development proxy browser boundary | Host, Origin, Fetch Metadata, CSP, fragment and response tests | Pass for tested cases | | Development proxy browser boundary | Host, Origin, Fetch Metadata, CSP, fragment and response tests | Pass for tested cases |
| Platform behavior | Exact-candidate native Windows and executed Linux matrices; macOS cross-compilation | Windows/Linux pass for tested lanes; native macOS pending | | Platform behavior | Historical exact-candidate native Windows and executed Linux matrices | Windows/Linux passed for the tested lanes; current releases require Linux/amd64 evidence |
Coverage measures statements executed by tests. It is not branch completeness Coverage measures statements executed by tests. It is not branch completeness
and is not evidence that the executed behavior is secure. and is not evidence that the executed behavior is secure.
@@ -92,7 +95,7 @@ and is not evidence that the executed behavior is secure.
and reachable through its analysis. A clean result cannot detect unknown flaws, and reachable through its analysis. A clean result cannot detect unknown flaws,
design errors, or vulnerabilities outside its model. design errors, or vulnerabilities outside its model.
## Beta 1 native compatibility matrix ## Historical Beta 1 compatibility matrix
These are maintainer-run, point-in-time results, not continuous CI and not an These are maintainer-run, point-in-time results, not continuous CI and not an
independent audit. independent audit.
@@ -102,7 +105,7 @@ independent audit.
| Windows 11/amd64, NTFS | 1.25.12, 1.26.5 | Native PowerShell verifier with race; root/runtime tests, vet, trimpath build, freshness, two generation passes, process-tree cleanup, watcher boundaries, and temporary consumer compilation | Pass. Symlink-output rejection skipped because the test account lacked symlink privilege; the read-only-directory case is POSIX-only | | Windows 11/amd64, NTFS | 1.25.12, 1.26.5 | Native PowerShell verifier with race; root/runtime tests, vet, trimpath build, freshness, two generation passes, process-tree cleanup, watcher boundaries, and temporary consumer compilation | Pass. Symlink-output rejection skipped because the test account lacked symlink privilege; the read-only-directory case is POSIX-only |
| Ubuntu 20.04/amd64 under WSL2, native ext4 checkout | 1.25.12, 1.26.5 | Race-enabled verifier; root/runtime tests, vet, build, two generation passes, ten focused filesystem cases, five focused development-process/watcher cases, and license check | Pass. This is Linux execution under WSL2, not bare-metal or Linux/arm64 evidence | | Ubuntu 20.04/amd64 under WSL2, native ext4 checkout | 1.25.12, 1.26.5 | Race-enabled verifier; root/runtime tests, vet, build, two generation passes, ten focused filesystem cases, five focused development-process/watcher cases, and license check | Pass. This is Linux execution under WSL2, not bare-metal or Linux/arm64 evidence |
| Linux/amd64 server containers | 1.25.12, 1.26.5 | Earlier pre-beta root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass on the earlier baseline only. Container resources were capped at 1 CPU and 2 GiB; this is supplementary evidence, not an exact Beta 1 lane or Linux/arm64 evidence | | Linux/amd64 server containers | 1.25.12, 1.26.5 | Earlier pre-beta root/runtime tests, vet, builds, race, licensing, and deterministic generation in sequential isolated official Go containers | Pass on the earlier baseline only. Container resources were capped at 1 CPU and 2 GiB; this is supplementary evidence, not an exact Beta 1 lane or Linux/arm64 evidence |
| macOS | — | Cross-compilation only | Native maintainer execution pending; provisional for Beta 1 | | macOS | — | Cross-compilation only | No native Beta 1 evidence; not a maintained release target |
The generated golden `basic.sando.go` was 1,399 bytes and had SHA-256 The generated golden `basic.sando.go` was 1,399 bytes and had SHA-256
`63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f` `63fa75a3049a3a8a12d769d7f9b6b510dfe763baacf706775b75cef2c57a984f`
@@ -110,12 +113,12 @@ on every tested Windows and Linux lane. Repeated generation also preserved its
timestamp. This demonstrates cross-host agreement for one compiler-owned timestamp. This demonstrates cross-host agreement for one compiler-owned
fixture, not equivalence for every possible template. fixture, not equivalence for every possible template.
Mac learners and Go developers are warmly invited to report ordinary Portability reports for unsupported targets may include the operating system,
compatibility results with macOS version, architecture, `go version`, exact architecture, `go version`, exact command, and a minimal reproduction.
command, and a minimal reproduction. Suspected vulnerabilities use the private Suspected vulnerabilities use the private route in
route in [SECURITY.md](../SECURITY.md). Community reports help find gaps; [SECURITY.md](../SECURITY.md). Such reports help find gaps but do not create a
maintainers remain responsible for reproducing security-relevant behavior, support promise; maintainers remain responsible for security triage and fixes
triage, remediation, and release decisions. on the supported Linux target.
## Security-relevant design evidence ## Security-relevant design evidence
@@ -203,8 +206,9 @@ known-vulnerability scans, candidate-version provenance checks, native Windows
and executed Linux matrices, and Windows/macOS cross-compilation on 2026-08-12. and executed Linux matrices, and Windows/macOS cross-compilation on 2026-08-12.
Signed annotated runtime and compiler tags were then published from that commit Signed annotated runtime and compiler tags were then published from that commit
in that order. Fresh runtime-first installation passed through both direct Git in that order. Fresh runtime-first installation passed through both direct Git
resolution and the public Go proxy after normal proxy propagation. Native resolution and the public Go proxy after normal proxy propagation. Future
macOS and the other gaps below remain separate release decisions. release decisions use the current Linux-only support policy rather than
requiring this historical multi-platform campaign.
## Open assurance gaps ## Open assurance gaps
@@ -214,9 +218,8 @@ macOS and the other gaps below remain separate release decisions.
- the signed annotated Beta tags and their common peeled commit were verified; - the signed annotated Beta tags and their common peeled commit were verified;
prebuilt-artifact signing, checksums, SBOM, reproducible provenance, and key prebuilt-artifact signing, checksums, SBOM, reproducible provenance, and key
recovery remain incomplete; recovery remain incomplete;
- native macOS, Linux/arm64, and Windows/arm64 execution remain outstanding; - Linux/arm64 and non-Linux portability are outside the current maintained
- Windows symlink rejection was not natively exercised because the test account release target;
lacked symlink privilege;
- browser-parser differential and semantic property testing need expansion; - browser-parser differential and semantic property testing need expansion;
- compiler input size, CPU, and memory have no built-in hard budget; - compiler input size, CPU, and memory have no built-in hard budget;
- filesystem checks do not defend against a hostile local actor racing path - filesystem checks do not defend against a hostile local actor racing path
+1 -1
View File
@@ -177,7 +177,7 @@ Sandwich Hime does not:
## Open release work ## Open release work
- broaden semantic and browser-parser differential testing; - broaden semantic and browser-parser differential testing;
- execute the native Windows/macOS security and process-lifecycle matrix; - execute the Linux/amd64 security and process-lifecycle release matrix;
- complete signed release provenance, checksums, and SBOM evidence; - complete signed release provenance, checksums, and SBOM evidence;
- test the confidential reporting and signing-key recovery procedures; and - test the confidential reporting and signing-key recovery procedures; and
- close or explicitly accept every finding listed in the evidence ledger before - close or explicitly accept every finding listed in the evidence ledger before
+17 -19
View File
@@ -28,17 +28,18 @@ private history or an indiscriminate Git mirror.
Beta 1 is deliberately earlier than a release candidate. It creates a real, Beta 1 is deliberately earlier than a release candidate. It creates a real,
repeatable install for learners and evaluators without claiming that the final repeatable install for learners and evaluators without claiming that the final
v1 compatibility, native-platform, artifact, signing, or soak gates are v1 compatibility, Linux release, artifact, signing, or soak gates are complete.
complete.
### Demonstrated for Beta 1 ### Demonstrated for Beta 1
Public commit `b7a84054d755e42285e50298e41e47f06a8325a5` (tree Public commit `b7a84054d755e42285e50298e41e47f06a8325a5` (tree
`be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run Go `be9e118e38dfebed19f60403ededdadabe07d2aa`) passed maintainer-run Go
1.25.12 and Go 1.26.5 matrices on native Windows/amd64, Linux/amd64 under WSL2, 1.25.12 and Go 1.26.5 matrices on native Windows/amd64 and Linux/amd64 under
with the earlier pre-beta server-container run retained only as supplementary WSL2, with the earlier pre-beta server-container run retained only as
Linux evidence. The same generated golden SHA-256 was observed across the exact supplementary Linux evidence. The same generated golden SHA-256 was observed
Beta Windows and Linux lanes. across the exact Beta Windows and Linux lanes. This is historical evidence,
not the current support definition; Linux/amd64 is now the maintained release
target.
Other demonstrated controls include: Other demonstrated controls include:
@@ -52,7 +53,7 @@ Other demonstrated controls include:
### Not demonstrated yet ### Not demonstrated yet
- native maintainer-run macOS execution; macOS is provisional for Beta 1; - final Linux/amd64 release-candidate evidence on the exact candidate;
- stable final-v1 API, CLI, schema, diagnostic, and generated snapshots; - stable final-v1 API, CLI, schema, diagnostic, and generated snapshots;
- systematic browser-parser and `html/template` differential testing; - systematic browser-parser and `html/template` differential testing;
- a long semantic fuzz campaign beyond bounded no-panic smoke; - a long semantic fuzz campaign beyond bounded no-panic smoke;
@@ -60,7 +61,7 @@ Other demonstrated controls include:
- complete real-browser development-supervisor evidence; - complete real-browser development-supervisor evidence;
- deterministic prebuilt archives, checksums, SBOMs, signed binaries, and - deterministic prebuilt archives, checksums, SBOMs, signed binaries, and
tested signing/recovery procedures; or tested signing/recovery procedures; or
- native macOS installation of the published Beta 1 tags. - independently reproduced Linux release artifacts, checksums, and SBOMs.
## Beta 1 publication lane ## Beta 1 publication lane
@@ -68,9 +69,8 @@ Beta 1 is supported for learning, classroom projects, evaluation, prototypes,
and compatibility feedback. It is not recommended as a production-stable and compatibility feedback. It is not recommended as a production-stable
dependency, and its interfaces may change. dependency, and its interfaces may change.
- [x] Define beta support, security, compatibility, and macOS-provisional - [x] Define beta support, security, and compatibility language.
language. - [x] Establish the historical public pre-beta Linux/Windows evidence baseline.
- [x] Establish the named public pre-beta Linux/Windows baseline.
- [x] Rerun the supported Go matrix and deterministic generation on the exact - [x] Rerun the supported Go matrix and deterministic generation on the exact
Beta 1 candidate. Beta 1 candidate.
- [x] Run the candidate-version freshness, bounded fuzz, vulnerability, and - [x] Run the candidate-version freshness, bounded fuzz, vulnerability, and
@@ -79,12 +79,10 @@ dependency, and its interfaces may change.
`v1.0.0-beta.1`, from the same reviewed public commit. `v1.0.0-beta.1`, from the same reviewed public commit.
- [x] Verify clean runtime-first direct and public-proxy installs and record the - [x] Verify clean runtime-first direct and public-proxy installs and record the
result. result.
- [ ] Add native macOS maintainer evidence before RC; community reports inform
that work but do not replace maintainer responsibility.
## Milestone 1: contract freeze ## Milestone 1: contract freeze
Required before security/platform release-candidate work is declared complete: Required before security/Linux release-candidate work is declared complete:
- [ ] Decide and specify whether generic component function signatures are v1. - [ ] Decide and specify whether generic component function signatures are v1.
- [ ] Inventory and freeze every exported `sando` symbol, trusted type, - [ ] Inventory and freeze every exported `sando` symbol, trusted type,
@@ -97,11 +95,11 @@ Required before security/platform release-candidate work is declared complete:
output compatibility snapshots. output compatibility snapshots.
- [ ] Define the v1 deprecation and security-support policy. - [ ] Define the v1 deprecation and security-support policy.
## Milestone 2: security and native-platform evidence ## Milestone 2: security and Linux release evidence
- [ ] Run the minimum supported Go line and the latest two stable Go lines on - [ ] Run the minimum supported Go line and the latest two stable Go lines on
native Linux, macOS, and Windows hosts. Linux/amd64 runners and a Linux deployment-class host.
- [ ] Prove identical generated bytes across those hosts and exercise native - [ ] Prove identical generated bytes across those Linux lanes and exercise
path, replacement, permission, race, process-tree, and watcher behavior. path, replacement, permission, race, process-tree, and watcher behavior.
- [ ] Build a systematic differential corpus against Go's documented - [ ] Build a systematic differential corpus against Go's documented
`html/template` safety baseline for overlapping supported contexts. `html/template` safety baseline for overlapping supported contexts.
@@ -147,7 +145,7 @@ Required before security/platform release-candidate work is declared complete:
2. Publish signed `sando/v1.0.0-rc.1`, then signed `v1.0.0-rc.1` from the same 2. Publish signed `sando/v1.0.0-rc.1`, then signed `v1.0.0-rc.1` from the same
reviewed public Gitea commit. reviewed public Gitea commit.
3. Verify documented installs through fresh `GOPROXY=direct` and 3. Verify documented installs through fresh `GOPROXY=direct` and
`proxy.golang.org` caches on supported Go versions and native platforms. `proxy.golang.org` caches on supported Go versions under Linux/amd64.
4. Run the complete evidence suite again from the exact public commit. 4. Run the complete evidence suite again from the exact public commit.
5. Operate the official Sandwich Hime website on the RC runtime for a 14-day 5. Operate the official Sandwich Hime website on the RC runtime for a 14-day
observation period with no unresolved Hime render, security, accessibility, observation period with no unresolved Hime render, security, accessibility,
@@ -172,6 +170,6 @@ marketing. New features do not outrank a small stable contract.
## Definition of confidence ## Definition of confidence
“Ready for v1” means a reviewer can trace each promise to a stable public “Ready for v1” means a reviewer can trace each promise to a stable public
contract, executable evidence from supported native environments, and a signed contract, executable evidence from supported Linux environments, and a signed
artifact built from the exact canonical source. It does not mean perfect, artifact built from the exact canonical source. It does not mean perfect,
invulnerable, or finished forever. invulnerable, or finished forever.
+7 -3
View File
@@ -2,10 +2,11 @@
# Repository verification tools # Repository verification tools
These scripts are intentionally understandable shell and PowerShell rather than a release framework with hidden defaults. These scripts are intentionally understandable shell rather than a release
framework with hidden defaults. The maintained verification and release path
is Linux.
- `verify.sh` runs root and nested-module tests and vet, builds `himesan`, checks the compiler-owned golden output, and proves two generation passes leave the same bytes and unchanged modification times. Set `HIMESAN_RACE=1` for race tests. - `verify.sh` runs root and nested-module tests and vet, builds `himesan`, checks the compiler-owned golden output, and proves two generation passes leave the same bytes and unchanged modification times. Set `HIMESAN_RACE=1` for race tests.
- `verify.ps1` provides the equivalent native Windows lane; pass `-Race` to include the race detector.
- `check-licenses.sh` enforces the AGPL compiler / Apache runtime boundary and prevents generated application Go from inheriting an AGPL identifier. - `check-licenses.sh` enforces the AGPL compiler / Apache runtime boundary and prevents generated application Go from inheriting an AGPL identifier.
- `release-check.sh --version vX.Y.Z` is a clean-checkout technical preflight, including exact candidate-version and generated-provenance checks. Beta publication follows the narrower prerelease gates in `RELEASE.md`; release candidates and final v1 additionally use `--public` with a human-reviewed `HIMESAN_RELEASE_EVIDENCE_DIR`. The script never tags, pushes, publishes, or deploys. - `release-check.sh --version vX.Y.Z` is a clean-checkout technical preflight, including exact candidate-version and generated-provenance checks. Beta publication follows the narrower prerelease gates in `RELEASE.md`; release candidates and final v1 additionally use `--public` with a human-reviewed `HIMESAN_RELEASE_EVIDENCE_DIR`. The script never tags, pushes, publishes, or deploys.
- `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes, adds the nested runtime before installing the parent compiler, and exercises fresh direct-fetch and public-proxy caches without interactive Git credentials. - `verify-public-install.sh --version vX.Y.Z` is a post-tag/publication check. It verifies exact `go-get=1` package routes, adds the nested runtime before installing the parent compiler, and exercises fresh direct-fetch and public-proxy caches without interactive Git credentials.
@@ -16,6 +17,9 @@ The release preflight invokes `govulncheck` from the official Go vulnerability p
## Preview automation status ## Preview automation status
Forge workflows are intentionally excluded from the sanitized pre-1.0 public snapshot until the project has confirmed its own Gitea runner availability and reviewed locally hosted or otherwise pinned dependencies. Local `verify.sh`, `verify.ps1`, license, and release-preflight results are the preview gates. Forge workflows are intentionally excluded from the sanitized pre-1.0 public
snapshot. The private development repository uses pinned Linux runners; the
public source remains independently verifiable with `verify.sh`, the license
check, and the Linux release preflight.
If Gitea automation is later added to the public repository, pin every external action to a reviewed immutable commit, document its provenance, grant minimum permissions, and keep a local verification path. A secondary forge may host a sanitized, read-only discovery snapshot, but hosted workflows stay disabled there and it does not become a release or contribution authority. If Gitea automation is later added to the public repository, pin every external action to a reviewed immutable commit, document its provenance, grant minimum permissions, and keep a local verification path. A secondary forge may host a sanitized, read-only discovery snapshot, but hosted workflows stay disabled there and it does not become a release or contribution authority.
+4 -13
View File
@@ -253,23 +253,14 @@ go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./...
go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./... go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./...
) )
printf '\n==> cross-compiling release binary smoke set\n' printf '\n==> building supported Linux release binary\n'
for target in \ for target in \
linux/amd64 \ linux/amd64; do
linux/arm64 \
darwin/amd64 \
darwin/arm64 \
windows/amd64 \
windows/arm64; do
target_os=${target%/*} target_os=${target%/*}
target_arch=${target#*/} target_arch=${target#*/}
extension=''
if [[ "$target_os" == windows ]]; then
extension='.exe'
fi
CGO_ENABLED=0 GOOS="$target_os" GOARCH="$target_arch" \ CGO_ENABLED=0 GOOS="$target_os" GOARCH="$target_arch" \
go build -trimpath -ldflags "$compiler_linker_flags" \ go build -trimpath -ldflags "$compiler_linker_flags" \
-o "$artifact_dir/himesan-$target_os-$target_arch$extension" ./cmd/himesan -o "$artifact_dir/himesan-$target_os-$target_arch" ./cmd/himesan
done done
for required in \ for required in \
@@ -289,7 +280,7 @@ if (( public_release == 1 )); then
fi fi
for evidence in \ for evidence in \
legal-review.md \ legal-review.md \
cross-platform.md \ linux-platform.md \
security.md \ security.md \
development-supervisor.md \ development-supervisor.md \
benchmark-methodology.md \ benchmark-methodology.md \
-133
View File
@@ -1,133 +0,0 @@
# SPDX-License-Identifier: AGPL-3.0-only
[CmdletBinding()]
param(
[switch]$Race
)
$ErrorActionPreference = "Stop"
$RepoRoot = (Resolve-Path (Join-Path $PSScriptRoot "..")).Path
Set-Location $RepoRoot
function Invoke-Checked {
param(
[Parameter(Mandatory = $true)]
[string]$Label,
[Parameter(Mandatory = $true)]
[scriptblock]$Command
)
Write-Host "`n==> $Label"
& $Command
if ($LASTEXITCODE -ne 0) {
throw "$Label failed with exit code $LASTEXITCODE"
}
}
function Invoke-ModuleChecks {
param(
[Parameter(Mandatory = $true)]
[string]$Directory,
[Parameter(Mandatory = $true)]
[string]$Label
)
Push-Location $Directory
try {
Invoke-Checked "$Label`: go test" { go test ./... }
Invoke-Checked "$Label`: go vet" { go vet ./... }
}
finally {
Pop-Location
}
}
function Get-SandoSources {
if (-not (Test-Path "internal/compiler/testdata/golden" -PathType Container)) {
return @()
}
return @(Get-ChildItem "internal/compiler/testdata/golden" -File -Filter "*.sando" |
Sort-Object FullName)
}
function Get-GeneratedManifest {
$lines = foreach ($source in (Get-SandoSources)) {
$output = "$($source.FullName).go"
if (-not (Test-Path $output -PathType Leaf)) {
"missing $output"
continue
}
$hash = (Get-FileHash -Algorithm SHA256 $output).Hash.ToLowerInvariant()
$modified = (Get-Item -LiteralPath $output).LastWriteTimeUtc.Ticks
"$hash $modified $output"
}
return ($lines -join "`n")
}
$TempRoot = Join-Path ([System.IO.Path]::GetTempPath()) ("himesan-verify-" + [guid]::NewGuid())
New-Item -ItemType Directory -Path $TempRoot | Out-Null
try {
Invoke-ModuleChecks "." "compiler module"
Invoke-Checked "compiler module: go build" {
go build -trimpath -o (Join-Path $TempRoot "himesan.exe") ./cmd/himesan
}
if (-not (Test-Path "sando/go.mod" -PathType Leaf)) {
throw "nested Apache runtime module sando/go.mod is missing"
}
Invoke-ModuleChecks "sando" "sando runtime module"
$Sources = @(Get-SandoSources)
if ($Sources.Count -eq 0) {
throw "compiler-owned golden .sando fixture is missing"
}
else {
$SourcePaths = @($Sources | ForEach-Object { $_.FullName })
$CheckArgs = @("run", "./cmd/himesan", "check") + $SourcePaths
$GenerateArgs = @("run", "./cmd/himesan", "generate") + $SourcePaths
Invoke-Checked "golden generation: read-only freshness check" {
& go $CheckArgs
}
$Before = Get-GeneratedManifest
Invoke-Checked "golden generation: first deterministic pass" {
& go $GenerateArgs
}
$First = Get-GeneratedManifest
if ($Before -cne $First) {
throw "generation changed committed output after check declared it fresh"
}
Invoke-Checked "golden generation: second deterministic pass" {
& go $GenerateArgs
}
$Second = Get-GeneratedManifest
if ($First -cne $Second) {
throw "repeated generation changed output bytes or an unchanged timestamp"
}
Invoke-Checked "golden generation: final freshness check" {
& go $CheckArgs
}
}
if ($Race) {
Invoke-Checked "compiler module: race tests" { go test -race ./... }
Push-Location "sando"
try {
Invoke-Checked "sando runtime module: race tests" { go test -race ./... }
}
finally {
Pop-Location
}
}
Write-Host "`n==> verification complete"
}
finally {
if (Test-Path $TempRoot -PathType Container) {
Remove-Item -LiteralPath $TempRoot -Recurse -Force
}
}