6.1 KiB
Proof-in-the-pudding roadmap
Unchecked items are release blockers for the milestone that contains them, not necessarily blockers for an earlier prerelease. The ordered initiative, repository topology, release-candidate sequence, and definition of confidence are maintained in docs/V1_RELEASE_PLAN.md.
Beta 1: public learning and evaluation (historical)
Beta 1 deliberately ships before the final-v1 compatibility and artifact gates. Its scope is classroom use, learning, prototypes, and compatibility feedback; it is not a production-stability promise.
- Define beta versus RC/final support and compatibility policy.
- Establish a one-time public pre-beta Linux/Windows evidence matrix on Go 1.25 and Go 1.26.
- Record the untested macOS boundary without presenting it as evidence.
- Rerun the historical Windows/Linux campaign and deterministic generation on the exact Beta 1 candidate.
- Publish immutable
sando/v1.0.0-beta.1, thenv1.0.0-beta.1, from the reviewed public commit. - Verify clean runtime-first direct and public-proxy installs after publication.
Compiler and runtime for RC/final
- Freeze and machine-check the compiler, CLI, diagnostic, schema, generated, and runtime compatibility contracts.
- Repeat compiler-owned deterministic golden output across the supported Linux and macOS Go lanes on the exact candidate.
- Compile temporary consumer modules using committed Go and only the Apache runtime.
- Run the parser, delimiter, context, path, and source-map release fuzz campaign.
- Evidence adversarial escaping and filesystem cases.
- Pass test, race, vet, vulnerability, and license gates on the latest two supported Go lines.
- Reproduce compiler/runtime release artifacts, checksums, and SBOMs; sign and notarize the macOS distribution outside runner authority.
Development supervisor for RC/final
- Generation/build/start/health failures keep the previous healthy server live.
- SSE reconnect/reload and mapped overlay diagnostics pass browser-level tests.
- CSP hash injection, fragment/API/download exclusion, and cache disabling pass.
- Replaced and interrupted child processes leave no descendants on supported systems.
Repository-owned release evidence
- Differentially test contextual escaping against Go's documented
html/templatesafety baseline. - Reproduce repository-owned synthetic benchmark cases and methodology from a clean checkout.
- Review generated output for stable provenance, source mappings, and absence of compiler-license headers.
- Document the production boundary: committed generated Go plus the Apache runtime, with no compiler or development supervisor in the deployed binary.
- Keep unsupported or unmeasured performance and production claims out of release materials.
Final public launch
Final-release preparation is active. Preserve the existing reviewed public history and append allowlisted updates; keep operator and archival records outside the public snapshot. Completed native and signing evidence remains bound to its exact candidate, not automatically to a later documentation or export-tool update. Final tags and artifacts have not been published.
Use RELEASE.md for the remaining final-publication requirements. Passing CI is evidence for that review, not an automatic publication decision.
- Finalize the maintainer-approved individual contribution agreement version 1.0 and explicit prospective acceptance process. Preserve the AGPL compiler, Apache runtime, chosen application license and existing DCO/output grants. Publication is not contributor acceptance or retroactive assent. The maintainer chose to proceed without an outside legal-review prerequisite; see the rationale.
- Record the maintainer's approval to proceed with ownership notices, output permission, reciprocal contribution terms and pre-registration naming scope. This is not a statement of external legal review or guaranteed enforceability.
- Record the maintainer's decision to proceed with Sandwich Hime as the primary project identity and Hime-san as its tool name. This is acceptance of the documented name-review limitations, not formal trademark clearance, completed similarity analysis or a registration requirement.
- Complete final security/signing readiness review. Distinguish successful signing from the explicitly deferred recovery drills below.
- Verify
gamertan.comvanity metadata and documented RC installs using clean direct-fetch and public-proxy caches. Final-version installs remain post-tag checks; an independent Mac installation is an accepted follow-up below. - Confirm the sanitized public Gitea source contains no private paths, identifiers, history, or unsupported claims.
- Publish signed RC.1 artifacts on Linux/amd64 and Darwin/arm64.
- Record the maintainer's v1 acceptance of existing live dogfooding despite missing timed checkpoint notes. This is an explicit assurance-gap acceptance, not reconstructed reviews or a claim of measured error-free operation. Missing notes alone do not restart the observation period or block release.
- Publish
sando/v1.0.0, thenv1.0.0, without moving either tag.
Accepted assurance follow-ups
- Exercise the published Mac download/install and CLI on independent Apple Silicon hardware when available. The maintainer accepted this gap for v1 and prefers an independent machine over another profile on the development Mac. Record the result in documentation; fix any reproduced defect in an appropriate patch release. This is not a current launch blocker or completed install test.
- Exercise offline signing-key restoration and independent second-person credential recovery/verification. The maintainer explicitly deferred these for v1.0.0; they are not launch blockers or completed recovery evidence. Loss of the current credentials or operator access remains an incident-response risk until these drills and independent access are proven.