170 lines
10 KiB
Markdown
170 lines
10 KiB
Markdown
# Live queue
|
||
|
||
## Current scope
|
||
|
||
Harden Sized for reuse by the native SpaceMonger-inspired SizeQueen project.
|
||
The user authorized fixes and updates discovered during that investigation.
|
||
Keep the existing CLI useful and preserve the GPL-3.0-only license.
|
||
|
||
- [x] Correct allocated-size totals for hard links; retain apparent per-path
|
||
sizes and define deterministic ownership within each scan.
|
||
- [x] Preserve scan errors and expose incomplete results instead of silently
|
||
treating missing paths as accessible empty directories.
|
||
- [x] Expose cancellable scans, progress counters, per-scan worker selection,
|
||
and an optional filesystem boundary for the native UI.
|
||
- [x] Add accounting and control regressions; run the existing CLI tests and
|
||
compare bounded release-build scan measurements.
|
||
- [x] Run reproducible Linux ARM64 and AMD64 Docker checks as an unprivileged
|
||
user, including actual mount boundaries, strict Clippy and a release smoke test.
|
||
- [x] Commit the scanner hardening and Linux check tooling; push the existing
|
||
`sizequeen-scan-hardening` review branch. Remote equality is verified.
|
||
PR #2 is open; release/tag/package publication remains separate.
|
||
- [x] Enable repository Actions and run the same Linux checks on the existing
|
||
cliff-mads runner. Keep its container isolation and other jobs unchanged;
|
||
verify a real workflow result before treating CI as proven.
|
||
|
||
## Approved project page and release cleanup
|
||
|
||
The owner approved a Sized project page in the shared Gamertan CMS, truthful
|
||
installation/release guidance, packaging repairs, and a Built on Sized section
|
||
on SizeQueen. Website delivery is tracked in that repository's existing queue.
|
||
|
||
- [x] Inspect the public v1.0.0 assets; the unlabelled executable is macOS arm64,
|
||
ad hoc signed, SHA-256 `50fde4d8215babbb64f4a4f55e030dd5c941a97ed1bedfa80392e4301c52d2bf`.
|
||
There are no attached Linux binaries, labelled archives or Debian packages.
|
||
- [x] Replace stale GitLab/unsupported package-manager installation claims with
|
||
explicit review-branch source builds; explain the published release boundary.
|
||
- [x] Package the executable before the archive; include licence/docs/build
|
||
provenance, target-labelled names and checksums. Reject output replacement.
|
||
Remove incidental installer generation; host binaries must not become `.deb`s.
|
||
- [x] Verify archive contents/checksum, run the extracted CLI and test overwrite
|
||
refusal on macOS arm64. Add the same verification to Linux CI.
|
||
- [x] Verify the updated cliff-mads workflow, push the review checkpoint and
|
||
record the public CMS delivery. PR #2 is open; no new version, release assets
|
||
or merge. Historical v1.0.0 notes are corrected and asset bytes preserved.
|
||
|
||
## Approved Sized 2.0.0 release
|
||
|
||
The owner authorizes pinned core adoption, the public source snapshot while
|
||
keeping the core forge private, and merge/push/publication after checks pass.
|
||
|
||
- [ ] Replace the local scanner with the exact SizeQueen core pin, verify snapshot
|
||
hashes and review the CLI/API migration and 2.0 compatibility notes.
|
||
- [ ] Verify Mac arm64 and Linux binaries, source rebuilds without forge access,
|
||
dependency notices, package contents and installation. Sign/notarize the Mac DMG.
|
||
- [ ] Merge PR #2, tag 2.0.0, publish immutable binary/source assets and update the
|
||
shared CMS project. Verify downloaded bytes and record release evidence.
|
||
|
||
Windows, additional features and package-manager registries remain deferred.
|
||
|
||
## Resume note
|
||
|
||
Current: preparing the approved 2.0.0 migration and release above. No 2.0.0
|
||
assets or tag have been published yet. Previous delivery evidence follows.
|
||
|
||
The approved Sized project page and release cleanup are delivered. Source
|
||
checkpoint `77b11a8c29b5ca3435fdd962717f8e8285abe972` is pushed on
|
||
`sizequeen-scan-hardening`; [PR #2](https://gitea.speelman.ca/gamertan/sized/pulls/2)
|
||
is open against unchanged `main`. Repository visibility remains public.
|
||
|
||
Final cliff-mads checks passed for both events:
|
||
[push run 1065](https://gitea.speelman.ca/gamertan/sized/actions/runs/1065)
|
||
(4m 57s) and
|
||
[PR run 1066](https://gitea.speelman.ca/gamertan/sized/actions/runs/1066)
|
||
(5m 0s). Rust 1.88.0 / Linux AMD64 / UID 65532 passed all 23 tests, formatting,
|
||
strict Clippy, optimized smoke, archive extraction/checksum/executable and
|
||
existing-output/dangling-symlink guards, plus unchanged-checkout verification.
|
||
Mac arm64 passed the same package checks and documented Cargo/Make installs into
|
||
temporary prefixes. Ignored local evidence is in `target/release-audit/`,
|
||
including `gitea-run-1065.txt`, `package-macos.log` and `install-macos.log`.
|
||
|
||
[Sized](https://gamertan.com/projects/sized/) is published through the shared
|
||
Gamertan project template (CMS revision 6), with a compact status sidebar,
|
||
verified synthetic CLI example, source instructions and accurate release limits.
|
||
It appears on the homepage, project index and sitemap. SizeQueen's
|
||
[Built on Sized section](https://gamertan.com/projects/sizequeen/) is published
|
||
in revision 14; all prior sections and app downloads are preserved. Desktop
|
||
and 320px mobile checks passed. Website evidence and recovery are recorded in
|
||
`../gamertancom-web-foundations/docs/PRODUCTION_SANDBOX_2026-09-04.md` under
|
||
“Sized project and Built on Sized — 10 October 2026”.
|
||
|
||
Historical v1.0.0 release notes now identify the attached executable as macOS
|
||
arm64 and distinguish the newer review branch. Asset IDs, lengths and executable
|
||
SHA-256 above remain unchanged. No new binary release, tag, merge or private-core
|
||
source publication occurred. Next: review PR #2's CLI exit status, JSON and
|
||
library API changes, then choose a release version and complete corresponding
|
||
source/dependency notices before authorizing new binary publication.
|
||
|
||
### Earlier verification history
|
||
|
||
The records below describe previous checkpoints; current delivery and next
|
||
actions are above.
|
||
|
||
Previous CI checkpoint: repository Actions is enabled and a real native AMD64
|
||
push run passed on cliff-mads. [Gitea run 1048 (number 2)](https://gitea.speelman.ca/gamertan/sized/actions/runs/1048)
|
||
tested `74b30bbf750417121f3b0c26017d2f011a2a8286` on
|
||
`cliff-himesan-linux-amd64` (`gitea-runner v3.1.0`): all 23 tests, formatting,
|
||
strict Clippy, optimized-binary smoke and unchanged-checkout verification passed
|
||
as UID 65532 with Rust 1.88.0. It finished in 3m 30s. Filtered local evidence is
|
||
in ignored `target/linux-checks/gitea-run-1048.log`; full logs remain in Gitea.
|
||
The initial checkout failed because the repository directory was root-owned;
|
||
the corrected runtime pre-owns it for the job user. The workflow reuses the
|
||
existing `himesan-node24` label and a local, pinned Rust/Node image. Runner
|
||
configuration, other jobs and repository visibility are unchanged. Temporary
|
||
setup credentials were revoked and their files removed. Push execution is
|
||
proven; PR execution was subsequently proven in run 1066; manual dispatch remains
|
||
configured but not independently exercised.
|
||
|
||
Linux validation and the requested remote review branch are complete.
|
||
Scanner hardening is `8b177e2`; repeatable Linux checks and equivalent format
|
||
interpolations are `988aad9`. Both implementation commits are pushed to
|
||
`origin/sizequeen-scan-hardening`, followed by CI setup `67fe175` and the
|
||
unprivileged checkout fix `74b30bb`. The source checkpoint is verified remotely
|
||
at `74b30bbf750417121f3b0c26017d2f011a2a8286`; later documentation-only
|
||
checkpoint commits do not rerun the source checks. Gitea main remains `9c8d1d4`.
|
||
The repository was already public (`private: false`); visibility is unchanged.
|
||
At that checkpoint, no PR, merge, tag, package publication or release occurred.
|
||
|
||
`scripts/check-linux.sh` owns the container workflow. Linux ARM64 (native in
|
||
Docker's VM) and AMD64 (emulated on this Mac) each passed 23 tests as UID 65532:
|
||
5 library, 6 CLI, 11 scan integrations and one explicitly enabled real-mount
|
||
integration. `tests/linux_mount.rs` checks two distinct tmpfs devices through
|
||
the library and CLI, with boundaries enabled and disabled. Formatting, strict
|
||
all-target Clippy and an optimized-binary fixture smoke test passed on both.
|
||
Mac passed its 22 applicable tests, formatting and strict Clippy. Commands are
|
||
documented in README/SHIPMENT; full local logs are in ignored
|
||
`target/linux-checks/{arm64,amd64}.log`. Cargo.lock and unrelated `.DS_Store`
|
||
hashes are unchanged; only source inputs and owned fixtures enter the checks.
|
||
|
||
Rust 1.88 Clippy identified format-string style warnings; equivalent
|
||
interpolations fix those without suppressions. SizeQueen's included scanner
|
||
still matches `8b177e2` exactly; the follow-up changes only one scanner Display
|
||
format string, not scan behaviour. SizeQueen itself was unchanged in this pass.
|
||
The planned PR and packaging repairs are now complete; review and version
|
||
selection remain next. These checks do not prove desktop X11/Wayland interaction,
|
||
Windows allocation or performance on very large/cold/remote trees.
|
||
|
||
Previous local checkpoint: baseline `9c8d1d4` matched Gitea main;
|
||
branch `sizequeen-scan-hardening`.
|
||
All six baseline tests passed. SizeQueen's independent probe reproduced
|
||
hard-link overcount and missing-path misclassification, and confirmed sparse
|
||
allocation, symlink leaf handling, and hidden-file inclusion. Source inspection
|
||
found discarded walker errors and no scan control API. These scoped corrections
|
||
are implemented locally, with no push, tag, or release. `cargo test --locked`
|
||
passed 22 tests (5 library, 6 CLI, 11 scan integrations); strict all-target
|
||
Clippy passed. The independent SizeQueen probe passed 6 accounting tests.
|
||
Man page was regenerated. Cargo.lock is unchanged and unrelated `.DS_Store`
|
||
was preserved.
|
||
|
||
Release probes on the Mac took 49–56ms for 20,000 files; sorting, identity
|
||
tracking, diagnostics and control cost more than the baseline (29–39ms for
|
||
the grouped tree). Inline Node size grew from 88 to 136 bytes; whole-process
|
||
peak RSS was about 8.2MiB grouped / 16.7MiB wide. These are bounded warm-metadata
|
||
fixtures, not evidence for million-entry, cold-disk, or remote-filesystem speed.
|
||
Cancellation is cooperative between filesystem calls. Allocation is reported
|
||
blocks, not guaranteed bytes recoverable from shared extents or snapshots.
|
||
|
||
Detailed audit and bounded probes are maintained in the sibling SizeQueen
|
||
project at `../sizequeen/research/SIZED-AUDIT.md`; that project's product queue
|
||
remains separate from this backend's fix queue.
|