10 KiB
Live queue
Current scope
Harden Sized for reuse by the native SpaceMonger-inspired SizeQueen project. The user authorized fixes and updates discovered during that investigation. Keep the existing CLI useful and preserve the GPL-3.0-only license.
- Correct allocated-size totals for hard links; retain apparent per-path sizes and define deterministic ownership within each scan.
- Preserve scan errors and expose incomplete results instead of silently treating missing paths as accessible empty directories.
- Expose cancellable scans, progress counters, per-scan worker selection, and an optional filesystem boundary for the native UI.
- Add accounting and control regressions; run the existing CLI tests and compare bounded release-build scan measurements.
- Run reproducible Linux ARM64 and AMD64 Docker checks as an unprivileged user, including actual mount boundaries, strict Clippy and a release smoke test.
- Commit the scanner hardening and Linux check tooling; push the existing
sizequeen-scan-hardeningreview branch. Remote equality is verified. PR #2 is open; release/tag/package publication remains separate. - Enable repository Actions and run the same Linux checks on the existing cliff-mads runner. Keep its container isolation and other jobs unchanged; verify a real workflow result before treating CI as proven.
Approved project page and release cleanup
The owner approved a Sized project page in the shared Gamertan CMS, truthful installation/release guidance, packaging repairs, and a Built on Sized section on SizeQueen. Website delivery is tracked in that repository's existing queue.
- Inspect the public v1.0.0 assets; the unlabelled executable is macOS arm64,
ad hoc signed, SHA-256
50fde4d8215babbb64f4a4f55e030dd5c941a97ed1bedfa80392e4301c52d2bf. There are no attached Linux binaries, labelled archives or Debian packages. - Replace stale GitLab/unsupported package-manager installation claims with explicit review-branch source builds; explain the published release boundary.
- Package the executable before the archive; include licence/docs/build
provenance, target-labelled names and checksums. Reject output replacement.
Remove incidental installer generation; host binaries must not become
.debs. - Verify archive contents/checksum, run the extracted CLI and test overwrite refusal on macOS arm64. Add the same verification to Linux CI.
- Verify the updated cliff-mads workflow, push the review checkpoint and record the public CMS delivery. PR #2 is open; no new version, release assets or merge. Historical v1.0.0 notes are corrected and asset bytes preserved.
Approved Sized 2.0.0 release
The owner authorizes pinned core adoption, the public source snapshot while keeping the core forge private, and merge/push/publication after checks pass.
- Replace the local scanner with the exact SizeQueen core pin, verify snapshot hashes and review the CLI/API migration and 2.0 compatibility notes.
- Verify Mac arm64 and Linux binaries, source rebuilds without forge access, dependency notices, package contents and installation. Sign/notarize the Mac DMG.
- Merge PR #2, tag 2.0.0, publish immutable binary/source assets and update the shared CMS project. Verify downloaded bytes and record release evidence.
Windows, additional features and package-manager registries remain deferred.
Resume note
Current: preparing the approved 2.0.0 migration and release above. No 2.0.0 assets or tag have been published yet. Previous delivery evidence follows.
The approved Sized project page and release cleanup are delivered. Source
checkpoint 77b11a8c29b5ca3435fdd962717f8e8285abe972 is pushed on
sizequeen-scan-hardening; PR #2
is open against unchanged main. Repository visibility remains public.
Final cliff-mads checks passed for both events:
push run 1065
(4m 57s) and
PR run 1066
(5m 0s). Rust 1.88.0 / Linux AMD64 / UID 65532 passed all 23 tests, formatting,
strict Clippy, optimized smoke, archive extraction/checksum/executable and
existing-output/dangling-symlink guards, plus unchanged-checkout verification.
Mac arm64 passed the same package checks and documented Cargo/Make installs into
temporary prefixes. Ignored local evidence is in target/release-audit/,
including gitea-run-1065.txt, package-macos.log and install-macos.log.
Sized is published through the shared
Gamertan project template (CMS revision 6), with a compact status sidebar,
verified synthetic CLI example, source instructions and accurate release limits.
It appears on the homepage, project index and sitemap. SizeQueen's
Built on Sized section is published
in revision 14; all prior sections and app downloads are preserved. Desktop
and 320px mobile checks passed. Website evidence and recovery are recorded in
../gamertancom-web-foundations/docs/PRODUCTION_SANDBOX_2026-09-04.md under
“Sized project and Built on Sized — 10 October 2026”.
Historical v1.0.0 release notes now identify the attached executable as macOS arm64 and distinguish the newer review branch. Asset IDs, lengths and executable SHA-256 above remain unchanged. No new binary release, tag, merge or private-core source publication occurred. Next: review PR #2's CLI exit status, JSON and library API changes, then choose a release version and complete corresponding source/dependency notices before authorizing new binary publication.
Earlier verification history
The records below describe previous checkpoints; current delivery and next actions are above.
Previous CI checkpoint: repository Actions is enabled and a real native AMD64
push run passed on cliff-mads. Gitea run 1048 (number 2)
tested 74b30bbf750417121f3b0c26017d2f011a2a8286 on
cliff-himesan-linux-amd64 (gitea-runner v3.1.0): all 23 tests, formatting,
strict Clippy, optimized-binary smoke and unchanged-checkout verification passed
as UID 65532 with Rust 1.88.0. It finished in 3m 30s. Filtered local evidence is
in ignored target/linux-checks/gitea-run-1048.log; full logs remain in Gitea.
The initial checkout failed because the repository directory was root-owned;
the corrected runtime pre-owns it for the job user. The workflow reuses the
existing himesan-node24 label and a local, pinned Rust/Node image. Runner
configuration, other jobs and repository visibility are unchanged. Temporary
setup credentials were revoked and their files removed. Push execution is
proven; PR execution was subsequently proven in run 1066; manual dispatch remains
configured but not independently exercised.
Linux validation and the requested remote review branch are complete.
Scanner hardening is 8b177e2; repeatable Linux checks and equivalent format
interpolations are 988aad9. Both implementation commits are pushed to
origin/sizequeen-scan-hardening, followed by CI setup 67fe175 and the
unprivileged checkout fix 74b30bb. The source checkpoint is verified remotely
at 74b30bbf750417121f3b0c26017d2f011a2a8286; later documentation-only
checkpoint commits do not rerun the source checks. Gitea main remains 9c8d1d4.
The repository was already public (private: false); visibility is unchanged.
At that checkpoint, no PR, merge, tag, package publication or release occurred.
scripts/check-linux.sh owns the container workflow. Linux ARM64 (native in
Docker's VM) and AMD64 (emulated on this Mac) each passed 23 tests as UID 65532:
5 library, 6 CLI, 11 scan integrations and one explicitly enabled real-mount
integration. tests/linux_mount.rs checks two distinct tmpfs devices through
the library and CLI, with boundaries enabled and disabled. Formatting, strict
all-target Clippy and an optimized-binary fixture smoke test passed on both.
Mac passed its 22 applicable tests, formatting and strict Clippy. Commands are
documented in README/SHIPMENT; full local logs are in ignored
target/linux-checks/{arm64,amd64}.log. Cargo.lock and unrelated .DS_Store
hashes are unchanged; only source inputs and owned fixtures enter the checks.
Rust 1.88 Clippy identified format-string style warnings; equivalent
interpolations fix those without suppressions. SizeQueen's included scanner
still matches 8b177e2 exactly; the follow-up changes only one scanner Display
format string, not scan behaviour. SizeQueen itself was unchanged in this pass.
The planned PR and packaging repairs are now complete; review and version
selection remain next. These checks do not prove desktop X11/Wayland interaction,
Windows allocation or performance on very large/cold/remote trees.
Previous local checkpoint: baseline 9c8d1d4 matched Gitea main;
branch sizequeen-scan-hardening.
All six baseline tests passed. SizeQueen's independent probe reproduced
hard-link overcount and missing-path misclassification, and confirmed sparse
allocation, symlink leaf handling, and hidden-file inclusion. Source inspection
found discarded walker errors and no scan control API. These scoped corrections
are implemented locally, with no push, tag, or release. cargo test --locked
passed 22 tests (5 library, 6 CLI, 11 scan integrations); strict all-target
Clippy passed. The independent SizeQueen probe passed 6 accounting tests.
Man page was regenerated. Cargo.lock is unchanged and unrelated .DS_Store
was preserved.
Release probes on the Mac took 49–56ms for 20,000 files; sorting, identity tracking, diagnostics and control cost more than the baseline (29–39ms for the grouped tree). Inline Node size grew from 88 to 136 bytes; whole-process peak RSS was about 8.2MiB grouped / 16.7MiB wide. These are bounded warm-metadata fixtures, not evidence for million-entry, cold-disk, or remote-filesystem speed. Cancellation is cooperative between filesystem calls. Allocation is reported blocks, not guaranteed bytes recoverable from shared extents or snapshots.
Detailed audit and bounded probes are maintained in the sibling SizeQueen
project at ../sizequeen/research/SIZED-AUDIT.md; that project's product queue
remains separate from this backend's fix queue.