Export the reviewed allowlisted snapshot from private source commit 8aab3db43f35e6a49aa497f45d73701b13fc9f32 and tree 992132ea4703437dc13ffdbb04a077816c02caf9. This includes routed singleton continuity, deployment evidence, strict schema-2 configuration, restricted transport, and the independently compilable public-tree guard. AI-Assisted: OpenAI Codex Signed-off-by: Cole Speelman <crspeelman@gmail.com>
44 lines
2.3 KiB
Markdown
44 lines
2.3 KiB
Markdown
# Preview release policy
|
|
|
|
`v0.1.0-preview.2` may be published only after one identical candidate Tend
|
|
binary has successfully completed maintenance releases for Gamertan and the
|
|
Sandwich Hime website, including injected-failure restoration and explicit
|
|
rollback proof. The August 14, 2026 campaign met that gate; the scoped,
|
|
sanitized record is in `docs/DOGFOOD_EVIDENCE.md`.
|
|
|
|
Before a preview tag:
|
|
|
|
1. Run `./scripts/verify.sh` from a clean pushed private-development commit.
|
|
2. Review dependency, license, race, filesystem, archive, and rollback evidence.
|
|
3. Export the exact allowlisted public tree into a new root commit.
|
|
4. Verify canonical Gitea and GitHub discovery trees are byte-identical.
|
|
5. Sign the canonical Gitea tag and attach checksums and an SPDX SBOM.
|
|
6. Verify a fresh public checkout before advertising installation.
|
|
|
|
The release tag and attached candidate must be built from the final reviewed
|
|
source commit. Documentation-only changes after the recorded campaign require
|
|
one final identical-candidate maintenance pass before tagging.
|
|
|
|
`v0.2.0-preview.1` is an immutable, additive release line. It requires schema 2,
|
|
the restricted `push`/`receive` transport, root-owned environment-file
|
|
references, host-wide activation serialization, and HTTPS public-origin smoke.
|
|
Its exact released source remains unchanged.
|
|
|
|
`v0.2.0-preview.2` adds bounded deployment-event JSONL, routed-origin
|
|
activation continuity, rollback annotations, and the reviewed operational
|
|
friction record. It must preserve every Preview 1 security and release gate.
|
|
The exact same Preview 2 binary must deploy, roll back, and reactivate
|
|
Gamertan, the Sandwich Hime website, and Gamertan Observatory before the tag is
|
|
created. EQL is not part of this generic gate; its SQLite/catalog publication
|
|
needs a dedicated adapter rather than arbitrary hooks.
|
|
|
|
`v0.1.0-preview.1` is immutable but withdrawn: its source and module checksums
|
|
are valid, while a fresh `go install` reports the development identity because
|
|
the CLI did not yet adopt the tagged module version from Go build information.
|
|
Preview 2 adds that identity path and its regression tests; preview 1 is never
|
|
retagged or rewritten.
|
|
|
|
The canonical public origin is `ssh://git@gitea.speelman.ca:2222/gamertan/tend.git`.
|
|
GitHub is a read-only discovery snapshot. Private development history is not
|
|
published or merged into either public history.
|