You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Prepare, merge and freeze the complete v0.1.0 release candidate before the independent DM-073 audit. This card owns every repository mutation needed to make a commit releasable: final version/build metadata, closure/evidence manifests, changelog and release notes, compatibility/migration policy, SBOM/license/provenance inputs, packaged documentation and the deterministic artifact-verification path.
The observable result is an exact commit already on the protected default branch from which all proposed release bytes reproduce. DM-073 reviews that commit and those bytes. DM-076 does not create a release tag, publish assets or authorize deployment.
This split is required by the one-issue/one-claim/one-PR protocol: candidate preparation must close before security review, while DM-075 remains the later publication ceremony.
Blocked by
DM-055, DM-061, DM-071, and DM-074.
Those direct gates transitively require the remaining V0 implementation, Matrix↔Cluster, canary, Tribe cutover, harness and documentation work. At claim time audit every release-candidate roadmap/Kanban issue anyway; later publication and source-archive operations remain explicitly sequenced open, while a missing or deferred required V0 behavior fails closed even if it was not represented by a dependency edge.
Allowed scope
Final package/version/build configuration, bounded dependency locks and public CI release-candidate jobs.
Checked-in release/evidence manifests, schema/domain/ID/API registries, compatibility tables, changelog/release notes, operator/developer docs and generated public metadata.
Status/navigation documents needed to describe the exact candidate.
No new identity, ledger, crypto, messaging, memory, species, adapter, Cluster, canary or migration behavior belongs here. A discovered implementation gap reopens its owning focused issue and keeps DM-076 blocked.
V0 closure audit
Create a machine-readable and rendered closure matrix for every release-candidate V0 DM card, plus explicit sequenced-open entries for the later publication and source-archive cards, containing:
issue, signed claim/receipt, PR, merge SHA and exact independent review verdict/head;
acceptance-criterion evidence and canonical spec/schema/vector/test/runbook/doc paths/digests;
required scenario result, exact command/count/platform and any skips/limitations;
security/canary/cutover/recovery evidence and residual-risk owner;
final disposition proving no required release-candidate behavior was deferred and later external operations are dependency-sequenced rather than waived.
Reconcile ROADMAP.md, ISSUES.md, Project 9 and live GitHub issue states. Add DM-076 and the corrected order DM-074 -> DM-076 -> DM-073 -> DM-075. No missing, duplicate, stale-minimal, contradictory or unowned required card may remain.
Candidate content
Version is exactly 0.1.0; intended tag is exactly v0.1.0.
Freeze every public V0 media type/domain/tag, typed ID prefix, schema $id, signature/preimage domain, CLI/MCP method, exit/error/receipt status and DM-018 adapter contract in a generated registry checked against source.
State the V0 compatibility policy: accepted V0 bytes are immutable; additive code cannot reinterpret them; unknown versions/features and unauthorized downgrades fail closed; incompatible changes require a new version/domain plus receipt-bound migration.
Publish supported Python/runtime/OS/database/crypto/build-tool ranges and exact lock digest.
Publish exact tested Matrix↔Cluster combinations and required genuine signer/CAS/fence/dual-gate behavior; deployment evidence grants no Matrix authority.
Publish DM-074 harness evidence levels and pinned tested versions; vendor docs alone are never live support.
Finalize changelog/release notes, install/verify/configure/operate/backup/restore/disable/uninstall docs and empty-start/Tribe non-import policy.
Release-candidate manifest
Check in a closed, content-addressed daimon-matrix-release-manifest/v0 binding:
repository, exact source commit/tree (filled with or deterministically verified against the merge candidate), version/tag intent and clean-tree assertion;
declared artifact filenames, sizes and digests produced from the exact merged commit;
closure matrix, required-scenario report, canary/cutover/recovery evidence and public residual-risk register inputs;
Matrix↔Cluster and harness compatibility tables;
secret/private-state scan policy and redacted deployment/config-template digests;
instructions for DM-073 to independently rebuild and for DM-075 to verify/tag/publish without changing candidate bytes.
If embedding the final commit hash in a file would create a self-reference, bind the Git tree hash plus externally generated signed candidate statement; never insert a guessed SHA or mutate the tree after audit.
Reproducible artifacts and installed verification
Build sdist, wheel and every supported optional bundle twice from independent clean exports of the exact default-branch candidate, with fixed environment/network policy. Required reproducible formats are byte-identical and SHA-256-equal.
Install only the wheel into a fresh environment/state root and run CLI/MCP version/self-check plus the complete required synthetic/contract suite.
Run artifact/package/log/report secret scans, adapter-disablement checks, ledger/CAS reconstruction and encrypted-backup restore with the candidate package.
Generate SBOM/license/provenance subjects deterministically or document the content-addressed external attestation step that DM-075 will perform without changing artifacts.
Treat GitHub-generated source archives as unreviewed convenience outputs, not canonical reviewed release assets.
Candidate merge and freeze
The single DM-076 PR contains all candidate-affecting changes and Closes this issue. It receives its normal independent component review, merges, and then the exact resulting default-branch commit/tree becomes the DM-073 candidate. Rebuild all declared artifacts from that merged commit and record public digests in the DM-073 handoff/evidence manifest.
After freeze:
no code/schema/dependency/build/config/fixture/doc/release-metadata change may land on the candidate;
DM-073 REQUEST_CHANGES sends fixes to focused issues/PRs, after which DM-076 evidence is regenerated or a scoped successor preparation card is opened and the candidate refreezes;
only exact-head DM-073 APPROVE plus human same-candidate GO lets DM-075 publish;
branch protection, CI retention or an external draft release is not an authority substitute.
Acceptance criteria
Every required release-candidate V0 card/criterion is closed with exact implementation/review/evidence; none is deferred to ship, while later publication/source-archive cards remain explicitly blocked in their intended order.
Project/docs dependency graph includes DM-076 and has no final-audit/release cycle.
Final version, registries, compatibility/migration policies, Matrix↔Cluster/harness matrices, changelog and release docs are present before audit.
Candidate manifest closes over the exact merged tree and proposed artifact/evidence set without self-referential or mutable inputs.
Two clean builds reproduce; artifact-only install, full suite, secret scan, adapter-disablement and both recovery drills succeed.
SBOM/license/provenance inputs and artifact/member allowlists are complete and independently checkable.
A single reviewed PR merges all preparation changes and hands DM-073 the exact default-branch candidate SHA/tree and digests.
No tag, GitHub release, asset publication, live deployment or human GO is performed by this card.
Security and rollback
Use synthetic/public inputs and validated disposable roots. No live keys, tokens, databases, messages, memories, participant data, endpoints or private config enter builds/reports.
Release/signing credentials remain absent; CI uses read-only permissions and no publishing token.
A failed build/audit leaves the commit unreleased. Corrections are forward commits under focused claims; never rewrite canonical state, force a tag or hide a finding.
Preserve failing artifact/evidence digests for review while removing only validated disposable local roots.
Deployment: N/A. This card prepares bytes; it neither publishes nor deploys them.
Do not claim until every named blocker is closed, the live V0 closure audit finds no required open candidate behavior (later publication/source-archive operations excepted), and active claims/worktrees show no candidate-affecting overlap. The claim owns the release-preparation files and protocol registry paths explicitly; it does not own implementation fixes or external publication.
Expected PR
One PR closes DM-076 and produces the already-merged exact candidate consumed by DM-073. DM-075 later creates the tag/release and a separate postflight record; it must not alter this candidate.
Outcome
Prepare, merge and freeze the complete
v0.1.0release candidate before the independent DM-073 audit. This card owns every repository mutation needed to make a commit releasable: final version/build metadata, closure/evidence manifests, changelog and release notes, compatibility/migration policy, SBOM/license/provenance inputs, packaged documentation and the deterministic artifact-verification path.The observable result is an exact commit already on the protected default branch from which all proposed release bytes reproduce. DM-073 reviews that commit and those bytes. DM-076 does not create a release tag, publish assets or authorize deployment.
This split is required by the one-issue/one-claim/one-PR protocol: candidate preparation must close before security review, while DM-075 remains the later publication ceremony.
Blocked by
DM-055, DM-061, DM-071, and DM-074.
Those direct gates transitively require the remaining V0 implementation, Matrix↔Cluster, canary, Tribe cutover, harness and documentation work. At claim time audit every release-candidate roadmap/Kanban issue anyway; later publication and source-archive operations remain explicitly sequenced open, while a missing or deferred required V0 behavior fails closed even if it was not represented by a dependency edge.
Allowed scope
No new identity, ledger, crypto, messaging, memory, species, adapter, Cluster, canary or migration behavior belongs here. A discovered implementation gap reopens its owning focused issue and keeps DM-076 blocked.
V0 closure audit
Create a machine-readable and rendered closure matrix for every release-candidate V0 DM card, plus explicit sequenced-open entries for the later publication and source-archive cards, containing:
Reconcile
ROADMAP.md,ISSUES.md, Project 9 and live GitHub issue states. Add DM-076 and the corrected orderDM-074 -> DM-076 -> DM-073 -> DM-075. No missing, duplicate, stale-minimal, contradictory or unowned required card may remain.Candidate content
0.1.0; intended tag is exactlyv0.1.0.$id, signature/preimage domain, CLI/MCP method, exit/error/receipt status and DM-018 adapter contract in a generated registry checked against source.Release-candidate manifest
Check in a closed, content-addressed
daimon-matrix-release-manifest/v0binding:If embedding the final commit hash in a file would create a self-reference, bind the Git tree hash plus externally generated signed candidate statement; never insert a guessed SHA or mutate the tree after audit.
Reproducible artifacts and installed verification
Candidate merge and freeze
The single DM-076 PR contains all candidate-affecting changes and
Closesthis issue. It receives its normal independent component review, merges, and then the exact resulting default-branch commit/tree becomes the DM-073 candidate. Rebuild all declared artifacts from that merged commit and record public digests in the DM-073 handoff/evidence manifest.After freeze:
REQUEST_CHANGESsends fixes to focused issues/PRs, after which DM-076 evidence is regenerated or a scoped successor preparation card is opened and the candidate refreezes;APPROVEplus human same-candidateGOlets DM-075 publish;Acceptance criteria
GOis performed by this card.Security and rollback
Deployment: N/A. This card prepares bytes; it neither publishes nor deploys them.
Canonical references
Concurrent-work gate
Do not claim until every named blocker is closed, the live V0 closure audit finds no required open candidate behavior (later publication/source-archive operations excepted), and active claims/worktrees show no candidate-affecting overlap. The claim owns the release-preparation files and protocol registry paths explicitly; it does not own implementation fixes or external publication.
Expected PR
One PR closes DM-076 and produces the already-merged exact candidate consumed by DM-073. DM-075 later creates the tag/release and a separate postflight record; it must not alter this candidate.