diff --git a/.seal/reviews/cr-2u4rcc/events.jsonl b/.seal/reviews/cr-2u4rcc/events.jsonl new file mode 100644 index 0000000..04ac2ca --- /dev/null +++ b/.seal/reviews/cr-2u4rcc/events.jsonl @@ -0,0 +1,4 @@ +{"ts":"2026-09-12T21:50:45.565153603Z","author":"sigil-dev","event":"ReviewCreated","data":{"review_id":"cr-2u4rcc","jj_change_id":"detached:2f5b83ff774a3a1881a4222fb03a6153a79b13fa","scm_kind":"git","scm_anchor":"detached:2f5b83ff774a3a1881a4222fb03a6153a79b13fa","initial_commit":"2f5b83ff774a3a1881a4222fb03a6153a79b13fa","base_commit":"103aed13cdc16f2d5e691ea16244e2d8f3560f4a","title":"bn-1php: Temporal 0.1.1 stable promotion","description":"Risk high release approval; exact whole stable-preparation range. Plugin package0.1.1 preserves accepted publish=false runtimecrate0.1.1-rc.1, Cargo.lock/runtime/helper/WIT unchanged; explicitversionregression replaces coupling; docs correct timeout/install and scope CAPI RC acceptance plus addendum. Check failures, edge cases, rollback, monitoring, validation. Candidate/publication still gated separately on accepted component BLAKE3b427ab70cb4643c771996a3610456872e4ed50e49f24fe8859186a654833a7b8, exact source/3asset tuple, protectedmain/immutablecontrols and public provenance. Review does not certify future artifact, native run, CAPIcallermerge, publication or stable consumption."}} +{"ts":"2026-09-12T21:50:45.565246753Z","author":"sigil-dev","event":"ReviewersRequested","data":{"review_id":"cr-2u4rcc","reviewers":["sigil-security"]}} +{"ts":"2026-09-12T21:55:16.171088943Z","author":"sigil-security","event":"ReviewerVoted","data":{"review_id":"cr-2u4rcc","vote":"lgtm","reason":"risk:high static LGTM for the full persisted 103aed13cdc16f2d5e691ea16244e2d8f3560f4a..2f5b83ff774a3a1881a4222fb03a6153a79b13fa two-commit range, tree c7d6efe0c69457b9fd8698380bc2da28e95285fc; no blockers. Failure modes: manifest/version drift is rejected by scripts/release-pack.py:25-36 and the publication predicate; source or lock drift invalidates the accepted-component claim, and RELEASING.md:42-48 requires exact component BLAKE3 b427ab70cb4643c771996a3610456872e4ed50e49f24fe8859186a654833a7b8 or a stop and new review/acceptance. Edge cases: plugin.toml:4 package 0.1.1 intentionally retains Cargo.toml:3,6 crate 0.1.1-rc.1 with publish=false, explicitly asserted at tests/test_release_pack.py:89-105; README.md:115-126 preserves 65s only for close-event History and 10s for Start, Describe, and all-events, with caller pagination. Rollback: before publication revert this preparation; after any external write RELEASING.md:102-110 burns the version and preserves partial evidence rather than overwriting or rerunning. Monitoring: RELEASING.md:83-100 requires first-attempt candidate identity, exact source/SemVer/three asset SHA-256 values, recorded component hash, immutable-control readback, and public verification; future stable publication remains gated on measuring the exact accepted component hash. Validation: reviewed every changed file plus direct packer, publisher, WIT, runtime exchange, and acceptance/addendum paths. Git proves Cargo.lock, runtime, helper, WIT, contract, packer, and workflows unchanged from the accepted base; WIT temporal.wit:179-186 remains exactly three exports and one grpc-unary import. The CAPI report supports five profiles, ten scenarios, 319 assertions and frozen REDs; the addendum explicitly did not rerun the suite and records the held caller. No tests, runtime execution, network, or containers were used. This source LGTM does not certify a future stable artifact or its BLAKE3, publication, caller merge, Rite handoff, or release approval.","target_commit":"2f5b83ff774a3a1881a4222fb03a6153a79b13fa"}} +{"ts":"2026-09-12T21:55:16.206766896Z","author":"sigil-security","event":"ReviewApproved","data":{"review_id":"cr-2u4rcc","target_commit":"2f5b83ff774a3a1881a4222fb03a6153a79b13fa"}} diff --git a/CHANGELOG.md b/CHANGELOG.md index d33df61..db1a174 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,22 @@ # Changelog -## 0.1.1-rc.1 — Unpublished release candidate +## 0.1.1 — Unpublished stable candidate + +- Prepare stable packaging of the accepted 0.1.1-rc.1 component and unchanged + project-side Lua companion; no runtime, helper, WIT or dependency changes. + Keep the unpublished runtime crate at 0.1.1-rc.1 to preserve accepted bytes. +- The official RC and exact companion passed CAPI acceptance on 2026-09-11: + five profiles, ten scenarios, 319 unchanged assertions and both frozen + expected-RED fingerprints. The 2026-09-12 addendum closed diagnostic evidence + without a full-suite rerun; the reviewed caller awaits stable under CAPI's + stable-only merge policy. Stable publication and artifact verification are + separate gates, not claims made by this source preparation. +- Retain Sigil >=0.35.0, exact Host API 1.3.0, schema 4 and fixed WIT/caller + identity 0.1.0. Continue validating against the pinned public minimum host. +- Correct the timeout wording below: only close-event History permits 65 + seconds; Start, Describe and all-events History cap at 10 seconds. + +## 0.1.1-rc.1 — release candidate - Require Sigil >=0.35.0 without an evaluator minor ceiling, while retaining exact Host API 1.3.0, schema 4 and the unchanged three-operation WIT 0.1.0. @@ -23,10 +39,11 @@ Include independent presence fixtures and regression coverage. - Provide a tested least-authority operator grant template with all three fixed aliases, explicit capabilities and the cumulative budget needed for - a 65-second Start; explain binary payload handling and JSON numeric limits. -- Schedule RC publication after supporting Sigil 0.35.1. Fresh official-lock - CAPI acceptance of this exact RC and any adopted helper source remains - required before a separately reviewed stable promotion. + 65-second close-event History; explain binary payload handling and JSON + numeric limits. Start, Describe and all-events History cap at 10 seconds. +- Published after supporting Sigil 0.35.1. Subsequent official-lock RC and + companion acceptance is recorded above; stable promotion remains a separate + reviewed candidate and immutable publication. ## 0.1.0 — stable diff --git a/README.md b/README.md index ab31765..1e173d9 100644 --- a/README.md +++ b/README.md @@ -3,16 +3,17 @@ The measured three-operation `wasm.temporal` component: start, describe and caller-paginated history. -This checkout prepares **0.1.1-rc.1 (unpublished release candidate)**, +This checkout prepares **0.1.1 (unpublished stable candidate)**, requiring **Sigil >=0.35.0** and exact Host API 1.3.0/schema 4. Published **0.1.0** still requires **Sigil 0.35.x**; its immutable manifest is not changed by this preparation. A version in this checkout is not evidence that its GitHub release exists. The official -locked **0.1.0-rc.1** passed CAPI caller-replacement -acceptance on **2026-09-10**: five profiles, ten scenarios, 319 unchanged -assertions and both exact expected-RED fingerprints. Its 0.1.0 stable promotion -preserved the component bytes but created a new manifest/package identity -requiring its own reviewed publication and verification. Routing, authority, TLS policy, +locked **0.1.1-rc.1** and byte-unchanged Lua companion passed CAPI acceptance +on **2026-09-11**: five profiles, ten scenarios, 319 unchanged assertions and +both exact expected-RED fingerprints. The **2026-09-12** addendum closed +diagnostic evidence without rerunning the suite. The caller is independently +reviewed but awaits stable under CAPI's stable-only merge policy; no caller +merge or stable publication is claimed here. Routing, authority, TLS policy, credentials and transport limits belong to the operator-frozen Sigil host profile. The component receives none of them. It performs no retries, redirects, reconnections, sleeps or implicit pagination. @@ -22,8 +23,8 @@ coupling, not host compatibility checks. Future stable versions must still support the exact schema and host interface. An admissible version range is not evidence that an unmeasured future host passed native or CAPI acceptance. Prerelease evaluators retain Sigil's checked last-stable compatibility rules; -they do not impersonate their own final versions. Install examples below stay -on published 0.1.0 until a new package is officially published and verified. +they do not impersonate their own final versions. The 0.1.1 install examples +below require that exact stable package to be officially published and verified. The application WIT and machine contract are copied without semantic change from reviewed Sigil source `7403a479a36dc7a2fadf38c47578d64ba37ed679`. @@ -37,10 +38,13 @@ Stable Temporal promotion additionally requires real CAPI replacement acceptance Existing CAPI assertions, exact expected-RED fingerprints and non-Temporal pins must not change to obtain a pass. -This RC is scheduled after supporting **Sigil 0.35.1** publication. The release -pipeline still validates against pinned public **0.35.0**, the minimum host; -that check does not substitute for fresh official-lock CAPI acceptance of this -RC on 0.35.1. It adds documented operator grants and Start semantics, the +The RC was accepted on supporting **Sigil 0.35.1**. The release pipeline still +validates against pinned public **0.35.0**, the minimum host. Stable packaging +retains the accepted unpublished runtime crate at **0.1.1-rc.1**; package and +crate versions are distinct, as in the prior 0.1.0 promotion. The candidate +must reproduce the exact accepted component identity before publication; a +stable manifest still creates a new package identity requiring its own +review and verification. The RC added operator grants and Start semantics, the opt-in [bounded Lua companion](examples/README.md#bounded-lua-companion), and minimum-only host compatibility without new component exports. @@ -220,8 +224,8 @@ without altering protobuf payloads or the interface contract. ```sh sigil plugin sync - sigil plugin install temporal@0.1.0 - sigil plugin add temporal@0.1.0 + sigil plugin install temporal@0.1.1 + sigil plugin add temporal@0.1.1 sigil plugin sync ``` diff --git a/RELEASING.md b/RELEASING.md index ddf6ab6..5447234 100644 --- a/RELEASING.md +++ b/RELEASING.md @@ -4,9 +4,12 @@ The authority is Sigil's P6 keyless provenance policy and its 2026-08-27 autonomous-publication amendment. The lead owns repository controls, release dispatch and external acceptance; workers do not publish. -## Unpublished 0.1.1-rc.1 preparation +## Unpublished 0.1.1 stable preparation -The manifest and runtime crate now prepare **0.1.1-rc.1**, not a published release. +The plugin manifest prepares **0.1.1**, not a published release. The +`publish = false` runtime crate and Cargo.lock remain at the accepted +**0.1.1-rc.1**: this is plugin-package promotion, not a Rust crate release. +Package/crate independence also preserved the component in the 0.1.0 promotion. Only `0.1.1` and canonical positive `0.1.1-rc.N` package versions are admitted by this checkout's packer and publisher. Historical 0.1.0 releases are never rebuilt under their old identities. Confirm the new version is unused before @@ -27,12 +30,25 @@ for official 0.1.1 packages. No local package acquires publication authority. All following independent review, provenance, immutability and acquisition gates remain required. Preparing this source does not authorize dispatch. -For this RC, publish supporting Sigil **0.35.1** before the official Temporal -publication and measure that host separately during fresh CAPI acceptance. -Keep the public **0.35.0** minimum validator and its hashes pinned; do not -change the manifest floor merely to express this release order. Prior 0.1.0 -CAPI acceptance and local 0.1.1 qualification do not certify this RC's new -source, component or package identity. The Lua companion is project-side +The official locked **0.1.1-rc.1** and exact companion from source +`103aed13cdc16f2d5e691ea16244e2d8f3560f4a` passed CAPI acceptance on +**2026-09-11**, using Sigil **0.35.1**: five profiles, ten scenarios, 319 +unchanged assertions and both frozen expected-RED fingerprints. Its +**2026-09-12** addendum closed diagnostic evidence without a full-suite rerun. +The caller is independently reviewed but deliberately held for stable under +CAPI's merge policy. That does not imply a missing RC service-acceptance gate +or an already-merged caller. + +Stable candidate and public readback MUST retain component BLAKE3 +`b427ab70cb4643c771996a3610456872e4ed50e49f24fe8859186a654833a7b8`. +Any different component stops this promotion; investigate and seek a new +review/acceptance decision, never relabel old evidence. Keep the accepted +runtime, helper, WIT, dependency locks and build settings unchanged and measure +the actual build. The stable manifest/package and source-bound sidecar acquire +new identities and still require exact-candidate review and public verification. + +Keep the public **0.35.0** minimum validator and its hashes pinned; the measured +0.35.1 host does not change the manifest floor. The Lua companion is project-side source copied explicitly by callers, not an added file inside the two-member plugin archive; CAPI must record the helper source revision when adopting it. diff --git a/plugin.toml b/plugin.toml index 74ecc3c..c9f4620 100644 --- a/plugin.toml +++ b/plugin.toml @@ -1,7 +1,7 @@ # Unpublished candidate manifest; publication remains an independently reviewed gate. schema_version = 4 name = "temporal" -version = "0.1.1-rc.1" +version = "0.1.1" description = "Bounded Temporal WorkflowService client" license = "MIT" diff --git a/tests/test_release_pack.py b/tests/test_release_pack.py index 2b31c48..a2b3bb1 100644 --- a/tests/test_release_pack.py +++ b/tests/test_release_pack.py @@ -20,9 +20,9 @@ class ReleaseContractTests(unittest.TestCase): def test_release_manifest_keeps_local_and_official_versions_separate(self): data = (ROOT / "plugin.toml").read_bytes() - self.assertEqual(release.validate_manifest(data)["version"], "0.1.1-rc.1") - version_line = b'version = "0.1.1-rc.1"' - release.validate_manifest(data.replace(version_line, b'version = "0.1.1"')) + self.assertEqual(release.validate_manifest(data)["version"], "0.1.1") + version_line = b'version = "0.1.1"' + release.validate_manifest(data.replace(version_line, b'version = "0.1.1-rc.1"')) for version in (b"0.1.0", b"0.1.0-rc.1", b"0.1.0-dev.1", b"0.1.1-dev.1", b"0.1.1-rc.0", b"0.1.1-rc.01", b"0.1.1+build", b"0.1.2", b"0.2.0"): with self.subTest(version=version), self.assertRaises(ValueError): @@ -76,7 +76,7 @@ def test_publisher_and_packer_admit_only_the_new_version_family(self): admitted = subprocess.run(["bash", "-c", rules[0]], env={**os.environ, "VERSION": version}, capture_output=True, timeout=5).returncode == 0 - candidate = data.replace(b'version = "0.1.1-rc.1"', + candidate = data.replace(b'version = "0.1.1"', f'version = "{version}"'.encode()) if version in ("0.1.1", "0.1.1-rc.1", "0.1.1-rc.23"): self.assertTrue(admitted) @@ -89,7 +89,10 @@ def test_publisher_and_packer_admit_only_the_new_version_family(self): def test_package_patch_keeps_the_frozen_client_and_minimum_validator(self): manifest = release.validate_manifest((ROOT / "plugin.toml").read_bytes()) crate = release.tomllib.loads((ROOT / "Cargo.toml").read_text()) - self.assertEqual(crate["package"]["version"], manifest["version"]) + # Stable plugin packaging is not a Rust crate release. Preserve the + # accepted, unpublished runtime crate and measure its component bytes. + self.assertEqual(crate["package"]["version"], "0.1.1-rc.1") + self.assertFalse(crate["package"]["publish"]) contract = json.loads((ROOT / "conformance/contract.json").read_text()) self.assertEqual(manifest["component"]["entrypoint"], contract["identity"]["entrypoint"]) self.assertEqual(manifest["schema_version"], contract["identity"]["manifest_schema"])