Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .seal/reviews/cr-2u4rcc/events.jsonl
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
{"ts":"2026-09-12T21:50:45.565153603Z","author":"sigil-dev","event":"ReviewCreated","data":{"review_id":"cr-2u4rcc","jj_change_id":"detached:2f5b83ff774a3a1881a4222fb03a6153a79b13fa","scm_kind":"git","scm_anchor":"detached:2f5b83ff774a3a1881a4222fb03a6153a79b13fa","initial_commit":"2f5b83ff774a3a1881a4222fb03a6153a79b13fa","base_commit":"103aed13cdc16f2d5e691ea16244e2d8f3560f4a","title":"bn-1php: Temporal 0.1.1 stable promotion","description":"Risk high release approval; exact whole stable-preparation range. Plugin package0.1.1 preserves accepted publish=false runtimecrate0.1.1-rc.1, Cargo.lock/runtime/helper/WIT unchanged; explicitversionregression replaces coupling; docs correct timeout/install and scope CAPI RC acceptance plus addendum. Check failures, edge cases, rollback, monitoring, validation. Candidate/publication still gated separately on accepted component BLAKE3b427ab70cb4643c771996a3610456872e4ed50e49f24fe8859186a654833a7b8, exact source/3asset tuple, protectedmain/immutablecontrols and public provenance. Review does not certify future artifact, native run, CAPIcallermerge, publication or stable consumption."}}
{"ts":"2026-09-12T21:50:45.565246753Z","author":"sigil-dev","event":"ReviewersRequested","data":{"review_id":"cr-2u4rcc","reviewers":["sigil-security"]}}
{"ts":"2026-09-12T21:55:16.171088943Z","author":"sigil-security","event":"ReviewerVoted","data":{"review_id":"cr-2u4rcc","vote":"lgtm","reason":"risk:high static LGTM for the full persisted 103aed13cdc16f2d5e691ea16244e2d8f3560f4a..2f5b83ff774a3a1881a4222fb03a6153a79b13fa two-commit range, tree c7d6efe0c69457b9fd8698380bc2da28e95285fc; no blockers. Failure modes: manifest/version drift is rejected by scripts/release-pack.py:25-36 and the publication predicate; source or lock drift invalidates the accepted-component claim, and RELEASING.md:42-48 requires exact component BLAKE3 b427ab70cb4643c771996a3610456872e4ed50e49f24fe8859186a654833a7b8 or a stop and new review/acceptance. Edge cases: plugin.toml:4 package 0.1.1 intentionally retains Cargo.toml:3,6 crate 0.1.1-rc.1 with publish=false, explicitly asserted at tests/test_release_pack.py:89-105; README.md:115-126 preserves 65s only for close-event History and 10s for Start, Describe, and all-events, with caller pagination. Rollback: before publication revert this preparation; after any external write RELEASING.md:102-110 burns the version and preserves partial evidence rather than overwriting or rerunning. Monitoring: RELEASING.md:83-100 requires first-attempt candidate identity, exact source/SemVer/three asset SHA-256 values, recorded component hash, immutable-control readback, and public verification; future stable publication remains gated on measuring the exact accepted component hash. Validation: reviewed every changed file plus direct packer, publisher, WIT, runtime exchange, and acceptance/addendum paths. Git proves Cargo.lock, runtime, helper, WIT, contract, packer, and workflows unchanged from the accepted base; WIT temporal.wit:179-186 remains exactly three exports and one grpc-unary import. The CAPI report supports five profiles, ten scenarios, 319 assertions and frozen REDs; the addendum explicitly did not rerun the suite and records the held caller. No tests, runtime execution, network, or containers were used. This source LGTM does not certify a future stable artifact or its BLAKE3, publication, caller merge, Rite handoff, or release approval.","target_commit":"2f5b83ff774a3a1881a4222fb03a6153a79b13fa"}}
{"ts":"2026-09-12T21:55:16.206766896Z","author":"sigil-security","event":"ReviewApproved","data":{"review_id":"cr-2u4rcc","target_commit":"2f5b83ff774a3a1881a4222fb03a6153a79b13fa"}}
27 changes: 22 additions & 5 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,22 @@
# Changelog

## 0.1.1-rc.1 — Unpublished release candidate
## 0.1.1 — Unpublished stable candidate

- Prepare stable packaging of the accepted 0.1.1-rc.1 component and unchanged
project-side Lua companion; no runtime, helper, WIT or dependency changes.
Keep the unpublished runtime crate at 0.1.1-rc.1 to preserve accepted bytes.
- The official RC and exact companion passed CAPI acceptance on 2026-09-11:
five profiles, ten scenarios, 319 unchanged assertions and both frozen
expected-RED fingerprints. The 2026-09-12 addendum closed diagnostic evidence
without a full-suite rerun; the reviewed caller awaits stable under CAPI's
stable-only merge policy. Stable publication and artifact verification are
separate gates, not claims made by this source preparation.
- Retain Sigil >=0.35.0, exact Host API 1.3.0, schema 4 and fixed WIT/caller
identity 0.1.0. Continue validating against the pinned public minimum host.
- Correct the timeout wording below: only close-event History permits 65
seconds; Start, Describe and all-events History cap at 10 seconds.

## 0.1.1-rc.1 — release candidate

- Require Sigil >=0.35.0 without an evaluator minor ceiling, while retaining
exact Host API 1.3.0, schema 4 and the unchanged three-operation WIT 0.1.0.
Expand All @@ -23,10 +39,11 @@
Include independent presence fixtures and regression coverage.
- Provide a tested least-authority operator grant template with all three
fixed aliases, explicit capabilities and the cumulative budget needed for
a 65-second Start; explain binary payload handling and JSON numeric limits.
- Schedule RC publication after supporting Sigil 0.35.1. Fresh official-lock
CAPI acceptance of this exact RC and any adopted helper source remains
required before a separately reviewed stable promotion.
65-second close-event History; explain binary payload handling and JSON
numeric limits. Start, Describe and all-events History cap at 10 seconds.
- Published after supporting Sigil 0.35.1. Subsequent official-lock RC and
companion acceptance is recorded above; stable promotion remains a separate
reviewed candidate and immutable publication.

## 0.1.0 — stable

Expand Down
32 changes: 18 additions & 14 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,16 +3,17 @@
The measured three-operation `wasm.temporal` component:
start, describe and caller-paginated history.

This checkout prepares **0.1.1-rc.1 (unpublished release candidate)**,
This checkout prepares **0.1.1 (unpublished stable candidate)**,
requiring **Sigil >=0.35.0**
and exact Host API 1.3.0/schema 4. Published **0.1.0** still requires **Sigil
0.35.x**; its immutable manifest is not changed by this preparation. A version
in this checkout is not evidence that its GitHub release exists. The official
locked **0.1.0-rc.1** passed CAPI caller-replacement
acceptance on **2026-09-10**: five profiles, ten scenarios, 319 unchanged
assertions and both exact expected-RED fingerprints. Its 0.1.0 stable promotion
preserved the component bytes but created a new manifest/package identity
requiring its own reviewed publication and verification. Routing, authority, TLS policy,
locked **0.1.1-rc.1** and byte-unchanged Lua companion passed CAPI acceptance
on **2026-09-11**: five profiles, ten scenarios, 319 unchanged assertions and
both exact expected-RED fingerprints. The **2026-09-12** addendum closed
diagnostic evidence without rerunning the suite. The caller is independently
reviewed but awaits stable under CAPI's stable-only merge policy; no caller
merge or stable publication is claimed here. Routing, authority, TLS policy,
credentials and transport limits belong
to the operator-frozen Sigil host profile. The component receives none of them.
It performs no retries, redirects, reconnections, sleeps or implicit pagination.
Expand All @@ -22,8 +23,8 @@ coupling, not host compatibility checks. Future stable versions must still
support the exact schema and host interface. An admissible version range is
not evidence that an unmeasured future host passed native or CAPI acceptance.
Prerelease evaluators retain Sigil's checked last-stable compatibility rules;
they do not impersonate their own final versions. Install examples below stay
on published 0.1.0 until a new package is officially published and verified.
they do not impersonate their own final versions. The 0.1.1 install examples
below require that exact stable package to be officially published and verified.

The application WIT and machine contract are copied without semantic change from
reviewed Sigil source `7403a479a36dc7a2fadf38c47578d64ba37ed679`.
Expand All @@ -37,10 +38,13 @@ Stable Temporal promotion additionally requires real CAPI replacement acceptance
Existing CAPI assertions, exact expected-RED fingerprints and non-Temporal pins
must not change to obtain a pass.

This RC is scheduled after supporting **Sigil 0.35.1** publication. The release
pipeline still validates against pinned public **0.35.0**, the minimum host;
that check does not substitute for fresh official-lock CAPI acceptance of this
RC on 0.35.1. It adds documented operator grants and Start semantics, the
The RC was accepted on supporting **Sigil 0.35.1**. The release pipeline still
validates against pinned public **0.35.0**, the minimum host. Stable packaging
retains the accepted unpublished runtime crate at **0.1.1-rc.1**; package and
crate versions are distinct, as in the prior 0.1.0 promotion. The candidate
must reproduce the exact accepted component identity before publication; a
stable manifest still creates a new package identity requiring its own
review and verification. The RC added operator grants and Start semantics, the
opt-in [bounded Lua companion](examples/README.md#bounded-lua-companion), and
minimum-only host compatibility without new component exports.

Expand Down Expand Up @@ -220,8 +224,8 @@ without altering protobuf payloads or the interface contract.

```sh
sigil plugin sync
sigil plugin install temporal@0.1.0
sigil plugin add temporal@0.1.0
sigil plugin install temporal@0.1.1
sigil plugin add temporal@0.1.1
sigil plugin sync
```

Expand Down
32 changes: 24 additions & 8 deletions RELEASING.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,12 @@ The authority is Sigil's P6 keyless provenance policy and its 2026-08-27
autonomous-publication amendment. The lead owns repository controls, release
dispatch and external acceptance; workers do not publish.

## Unpublished 0.1.1-rc.1 preparation
## Unpublished 0.1.1 stable preparation

The manifest and runtime crate now prepare **0.1.1-rc.1**, not a published release.
The plugin manifest prepares **0.1.1**, not a published release. The
`publish = false` runtime crate and Cargo.lock remain at the accepted
**0.1.1-rc.1**: this is plugin-package promotion, not a Rust crate release.
Package/crate independence also preserved the component in the 0.1.0 promotion.
Only `0.1.1` and canonical positive `0.1.1-rc.N` package versions are admitted
by this checkout's packer and publisher. Historical 0.1.0 releases are never
rebuilt under their old identities. Confirm the new version is unused before
Expand All @@ -27,12 +30,25 @@ for official 0.1.1 packages. No local package acquires publication authority.
All following independent review, provenance, immutability and acquisition
gates remain required. Preparing this source does not authorize dispatch.

For this RC, publish supporting Sigil **0.35.1** before the official Temporal
publication and measure that host separately during fresh CAPI acceptance.
Keep the public **0.35.0** minimum validator and its hashes pinned; do not
change the manifest floor merely to express this release order. Prior 0.1.0
CAPI acceptance and local 0.1.1 qualification do not certify this RC's new
source, component or package identity. The Lua companion is project-side
The official locked **0.1.1-rc.1** and exact companion from source
`103aed13cdc16f2d5e691ea16244e2d8f3560f4a` passed CAPI acceptance on
**2026-09-11**, using Sigil **0.35.1**: five profiles, ten scenarios, 319
unchanged assertions and both frozen expected-RED fingerprints. Its
**2026-09-12** addendum closed diagnostic evidence without a full-suite rerun.
The caller is independently reviewed but deliberately held for stable under
CAPI's merge policy. That does not imply a missing RC service-acceptance gate
or an already-merged caller.

Stable candidate and public readback MUST retain component BLAKE3
`b427ab70cb4643c771996a3610456872e4ed50e49f24fe8859186a654833a7b8`.
Any different component stops this promotion; investigate and seek a new
review/acceptance decision, never relabel old evidence. Keep the accepted
runtime, helper, WIT, dependency locks and build settings unchanged and measure
the actual build. The stable manifest/package and source-bound sidecar acquire
new identities and still require exact-candidate review and public verification.

Keep the public **0.35.0** minimum validator and its hashes pinned; the measured
0.35.1 host does not change the manifest floor. The Lua companion is project-side
source copied explicitly by callers, not an added file inside the two-member
plugin archive; CAPI must record the helper source revision when adopting it.

Expand Down
2 changes: 1 addition & 1 deletion plugin.toml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Unpublished candidate manifest; publication remains an independently reviewed gate.
schema_version = 4
name = "temporal"
version = "0.1.1-rc.1"
version = "0.1.1"
description = "Bounded Temporal WorkflowService client"
license = "MIT"

Expand Down
13 changes: 8 additions & 5 deletions tests/test_release_pack.py
Original file line number Diff line number Diff line change
Expand Up @@ -20,9 +20,9 @@
class ReleaseContractTests(unittest.TestCase):
def test_release_manifest_keeps_local_and_official_versions_separate(self):
data = (ROOT / "plugin.toml").read_bytes()
self.assertEqual(release.validate_manifest(data)["version"], "0.1.1-rc.1")
version_line = b'version = "0.1.1-rc.1"'
release.validate_manifest(data.replace(version_line, b'version = "0.1.1"'))
self.assertEqual(release.validate_manifest(data)["version"], "0.1.1")
version_line = b'version = "0.1.1"'
release.validate_manifest(data.replace(version_line, b'version = "0.1.1-rc.1"'))
for version in (b"0.1.0", b"0.1.0-rc.1", b"0.1.0-dev.1", b"0.1.1-dev.1",
b"0.1.1-rc.0", b"0.1.1-rc.01", b"0.1.1+build", b"0.1.2", b"0.2.0"):
with self.subTest(version=version), self.assertRaises(ValueError):
Expand Down Expand Up @@ -76,7 +76,7 @@ def test_publisher_and_packer_admit_only_the_new_version_family(self):
admitted = subprocess.run(["bash", "-c", rules[0]],
env={**os.environ, "VERSION": version},
capture_output=True, timeout=5).returncode == 0
candidate = data.replace(b'version = "0.1.1-rc.1"',
candidate = data.replace(b'version = "0.1.1"',
f'version = "{version}"'.encode())
if version in ("0.1.1", "0.1.1-rc.1", "0.1.1-rc.23"):
self.assertTrue(admitted)
Expand All @@ -89,7 +89,10 @@ def test_publisher_and_packer_admit_only_the_new_version_family(self):
def test_package_patch_keeps_the_frozen_client_and_minimum_validator(self):
manifest = release.validate_manifest((ROOT / "plugin.toml").read_bytes())
crate = release.tomllib.loads((ROOT / "Cargo.toml").read_text())
self.assertEqual(crate["package"]["version"], manifest["version"])
# Stable plugin packaging is not a Rust crate release. Preserve the
# accepted, unpublished runtime crate and measure its component bytes.
self.assertEqual(crate["package"]["version"], "0.1.1-rc.1")
self.assertFalse(crate["package"]["publish"])
contract = json.loads((ROOT / "conformance/contract.json").read_text())
self.assertEqual(manifest["component"]["entrypoint"], contract["identity"]["entrypoint"])
self.assertEqual(manifest["schema_version"], contract["identity"]["manifest_schema"])
Expand Down