From 9bc8b3fce34595256ed0f2b14907c9753737daa6 Mon Sep 17 00:00:00 2001 From: Cole Speelman Date: Sat, 10 Oct 2026 13:39:56 -0400 Subject: [PATCH] Record verified Sized 2.0.0 publication and download acceptance --- SHIPMENT.md | 56 +++++++++++++++++++++++++++++++++++++++++++++-------- TODO.md | 36 ++++++++++++++++++++++++++++------ 2 files changed, 78 insertions(+), 14 deletions(-) diff --git a/SHIPMENT.md b/SHIPMENT.md index 44206aa..63ba1ef 100644 --- a/SHIPMENT.md +++ b/SHIPMENT.md @@ -132,14 +132,11 @@ matching source and never overwrite a published asset with different bytes. ## 3. Distribution channels -The existing public Gitea v1.0.0 release contains a macOS arm64 executable, -man page and completions, plus generated source archives. It predates the -scanner hardening branch. No architecture-labelled binary archive, `.deb` or -verified Homebrew tap is currently offered. - -Future public releases need their own reviewed version, source, target-specific -archives, checksums and installation acceptance. Do not replace historical -v1.0.0 assets with newly built bytes. Add a new version only after review. +Sized 2.0.0 provides Apple silicon Mac (signed DMG), Linux x86-64 and Linux ARM64 +archives, matching vendored source and SHA-256 checksums through +[Gitea](https://gitea.speelman.ca/gamertan/sized/releases/tag/v2.0.0), linked from +[Gamertan](https://gamertan.com/projects/sized/). No verified Homebrew tap or +`.deb` installer is offered. Historical v1.0.0 assets remain unchanged. Debian/Alpine packaging is separate from the portable host archive. Do not implicitly invoke `cargo deb` or `abuild` just because they are installed: a Mac @@ -161,3 +158,46 @@ Defaults to `PREFIX=/usr/local`. Overridable via `PREFIX=/your/path make install ## 6. Contributions The project accepts contributions under the terms of the [Contributor License Agreement](CLA.md). All pull requests must acknowledge agreement with these terms. + +## Sized 2.0.0 — 10 October 2026 + +Released source/tag: `9f36122e37ea3aefbd22ded08950e8858538e44b` / `v2.0.0`. +[PR #2](https://gitea.speelman.ca/gamertan/sized/pulls/2) was fast-forward merged. +The pinned core is `fb63e96266dcb8ffbca53b73c6c0f738ac3e827d`; the core forge +remains private, while `CORE-SNAPSHOT.json` verifies the public source copy. + +| Public file | SHA-256 | +| --- | --- | +| sized-v2.0.0-aarch64-apple-darwin.dmg | `ded20af5dbcb425d2afcd04033c2256977eb10ca06e6ae29db27bb88b5f8fa7b` | +| sized-v2.0.0-aarch64-unknown-linux-gnu.tar.gz | `2e2476267cd37bd2ceee8809daad57a6597a0053f913ff0ae566f1032b0f619e` | +| sized-v2.0.0-x86_64-unknown-linux-gnu.tar.gz | `9eefe83aebabb580b4e28a9d5a9688c2ca845ffe22b0d4109c552701bb0df09f` | +| sized-v2.0.0-source.tar.gz | `0969ec29a2c994008dd2e41da7f13314f523b980466848f12019616af6088544` | + +The fifth attachment is `SHA256SUMS`. All five were downloaded publicly and +compared with the retained release files. Do not replace them with rebuilt bytes. +The source archive includes the exact core and locked registry sources/notices. +It excludes Mac archive metadata/AppleDouble files; Linux extraction verifies +snapshot hashes. See [dependency review](docs/RELEASE-LICENSING.md). + +- Mac: scanner/CLI passed 33 tests and strict workspace Clippy; final archived + source passed an empty-cache offline check. Built with Rust 1.98.0 on macOS + 26.6.2, deployment target 11.0, only system dylibs. Developer ID signing, + notarization, stapling and Gatekeeper passed. The actual Chrome download kept + quarantine and passed installation, `--version` and a complete fixture scan. +- Linux: native ARM64 Docker and native AMD64 on cliff-mads each passed 35 tests, + including both real mount tests, formatting, strict Clippy, release smoke and + archive/executable/overwrite guards. Release packages were built from the + extracted matching source archive, offline, as UID 65532, with Rust 1.88.0 on + Debian 12. Supported package baseline: glibc 2.36+. No musl claims. +- Provider CI on exact source: [push 1071](https://gitea.speelman.ca/gamertan/sized/actions/runs/1071) + and [PR 1072](https://gitea.speelman.ca/gamertan/sized/actions/runs/1072) passed. +- CMS project revision 10 supplies downloads and upgrade guidance, retaining + the shared status sidebar. Desktop/320px mobile fit without page overflow. + +Local evidence: ignored `target/release-audit/` logs and +`target/distribution/2.0.0-portable/` retain packages, source, public-download +copies and the notarization result. Website evidence is in its +`.local/releases/sized-2.0.0/`. No personal scan data was used in release tests. +Older macOS and fresh-machine acceptance remain pending; no Intel Mac, Windows, +App Store or package-manager distribution is included. SizeQueen's released +binary and private core repository visibility were not changed. diff --git a/TODO.md b/TODO.md index f0dad4c..f0a3d27 100644 --- a/TODO.md +++ b/TODO.md @@ -18,7 +18,7 @@ Keep the existing CLI useful and preserve the GPL-3.0-only license. user, including actual mount boundaries, strict Clippy and a release smoke test. - [x] Commit the scanner hardening and Linux check tooling; push the existing `sizequeen-scan-hardening` review branch. Remote equality is verified. - PR #2 is open; release/tag/package publication remains separate. + PR #2 was subsequently merged for the approved 2.0.0 release below. - [x] Enable repository Actions and run the same Linux checks on the existing cliff-mads runner. Keep its container isolation and other jobs unchanged; verify a real workflow result before treating CI as proven. @@ -48,19 +48,43 @@ on SizeQueen. Website delivery is tracked in that repository's existing queue. The owner authorizes pinned core adoption, the public source snapshot while keeping the core forge private, and merge/push/publication after checks pass. -- [ ] Replace the local scanner with the exact SizeQueen core pin, verify snapshot +- [x] Replace the local scanner with the exact SizeQueen core pin, verify snapshot hashes and review the CLI/API migration and 2.0 compatibility notes. -- [ ] Verify Mac arm64 and Linux binaries, source rebuilds without forge access, +- [x] Verify Mac arm64 and Linux binaries, source rebuilds without forge access, dependency notices, package contents and installation. Sign/notarize the Mac DMG. -- [ ] Merge PR #2, tag 2.0.0, publish immutable binary/source assets and update the +- [x] Merge PR #2, tag 2.0.0, publish immutable binary/source assets and update the shared CMS project. Verify downloaded bytes and record release evidence. Windows, additional features and package-manager registries remain deferred. ## Resume note -Current: preparing the approved 2.0.0 migration and release above. No 2.0.0 -assets or tag have been published yet. Previous delivery evidence follows. +Sized 2.0.0 is released at [Gamertan](https://gamertan.com/projects/sized/) and +[Gitea](https://gitea.speelman.ca/gamertan/sized/releases/tag/v2.0.0). +PR #2 fast-forwarded into main; annotated tag `v2.0.0` resolves to +`9f36122e37ea3aefbd22ded08950e8858538e44b`. Public Sized includes the exact core +`fb63e96266dcb8ffbca53b73c6c0f738ac3e827d` snapshot. The core forge remains private. + +Mac arm64 passed 33 tests; Linux ARM64 and native AMD64 each passed 35, including +real mount boundaries, strict Clippy and extracted-package checks. Final source +passes offline builds without private credentials. Gitea push/PR runs +[1071](https://gitea.speelman.ca/gamertan/sized/actions/runs/1071) and +[1072](https://gitea.speelman.ca/gamertan/sized/actions/runs/1072) pass. +The Mac DMG is Developer ID signed, notarized and stapled; its Chrome-downloaded, +quarantined copy passed Gatekeeper, installation and an actual fixture scan. +All five public downloads match the verified release files. The shared CMS page +is published at revision 10 and fits desktop and 320px mobile. See +[SHIPMENT.md](SHIPMENT.md#sized-200--10-october-2026) for artifacts and limits. + +No approved release work remains. Next: collect ordinary-user feedback and +older/fresh-Mac acceptance before broadening supported platforms or adding +installers. Core changes should land upstream first, then advance the full pin +and public snapshot deliberately. No scanner or SizeQueen rebuild is required +for these documentation records. + +### Earlier project-page delivery + +The following record predates the completed 2.0.0 release above. The approved Sized project page and release cleanup are delivered. Source checkpoint `77b11a8c29b5ca3435fdd962717f8e8285abe972` is pushed on