Dev/v0.5.0 release plan#232
Merged
Merged
Conversation
added 28 commits
July 21, 2026 17:06
Record the published v0.4.0 tag, assets, hashes, and package baseline; close its release preparation and correct the changelog boundary. Accept ADR-0015 and establish the bounded v0.5.0 implementation, consumer, determinism, performance, and freeze gates. Signed-off-by: docushell-admin <hello@docushell.com>
Add ethos verify-batch for 1-1024 canonical citation requests against one validated native or OpenDataLoader source. Buffer canonical NDJSON reports before atomic output, preserve single-verify bytes per line, reject crop evidence, and retain aggregate exit semantics. Signed-off-by: docushell-admin <hello@docushell.com>
Add ethos report html for supported verification-report schemas. Render a self-contained escaped proof view with grounding-boundary wording, deterministic output, and fail-closed crop-root validation; cover determinism, injection, unsupported schema, and unsafe paths. Signed-off-by: docushell-admin <hello@docushell.com>
Add versioned trusted evidence contexts and structured model citation output with opaque handles, strict single-document locator validation, deterministic hydration, dedicated schemas/examples, and offline regression coverage while preserving citation-emission v1. Signed-off-by: docushell-admin <hello@docushell.com>
Bind projected evidence states to recomputed trusted hydration and internally consistent verification reports. Export generated npm declarations for Evidence Handle Bridge schemas and add deterministic projection/type-consumer coverage. Signed-off-by: docushell-admin <hello@docushell.com>
Add a deterministic model-free walkthrough from trusted retrieval records through opaque handles, hydration, recorded verification report binding, and evidence-state projection. Permit contextual pages on trusted element/span/table locators while retaining ambiguous-anchor rejection. Signed-off-by: docushell-admin <hello@docushell.com>
Advance the deterministic ethos-full builder from ADR proposal evidence to an accepted v0.5 release-candidate status while retaining explicit target-smoke and release-gate publication blocks. Signed-off-by: docushell-admin <hello@docushell.com>
Record deterministic hashes for every archive build input and reject unsafe PDFium notice paths before archive assembly. Signed-off-by: docushell-admin <hello@docushell.com>
Add a dedicated smoke helper that verifies the bundled launcher overrides ambient PDFium configuration, requires doctor success, and compares two fixture parses. Include an offline synthetic launcher regression test. Signed-off-by: docushell-admin <hello@docushell.com>
Add integration coverage for verify-batch byte equality with ordinary verify, stable ordering/double runs, aggregate ungrounded exit behavior, and atomic no-output malformed input failure. Signed-off-by: docushell-admin <hello@docushell.com>
Add a nonpublishing macOS arm64/Linux x64 release-candidate matrix that derives the workspace version and profile-pinned PDFium URL, double-builds archives, runs target-local smoke, and uploads only evidence artifacts. Signed-off-by: docushell-admin <hello@docushell.com>
Move Rust and Python source metadata and internal requirements to 0.5.0, regenerate the lockfile, and derive draft-artifact versions from the workspace manifest. Keep npm vendor/package metadata at 0.4.0 pending frozen core-A payload refresh. Reconcile approved public install wording to the published 0.4.0 baseline and extend release, package-inventory, and version-activation guards. Signed-off-by: docushell-admin <hello@docushell.com>
Require the target-host smoke helper to validate canonical archive checksums and inventories before safe extraction, bind payload targets to inventory metadata, and record archive evidence. Cover metadata mismatch and unsafe archive rejection. Signed-off-by: docushell-admin <hello@docushell.com>
Add an operator-only timing runner for the required 30 cold verification samples and 32-request batch comparison. It validates executable versions and canonical verification output, records bound internal evidence, and fails closed when either release threshold is exceeded. Signed-off-by: docushell-admin <hello@docushell.com>
Add fake-binary coverage for successful bound timing records and wrong-version rejection, and include it in v0.5 release-prep validation. Signed-off-by: docushell-admin <hello@docushell.com>
Allow only safe relative crop-root path segments before generating proof-report links, and cover URI schemes, traversal, encoding, inline-resource absence, and safe crop rendering. Signed-off-by: docushell-admin <hello@docushell.com>
Enforce the v1 1-to-1024 evidence-entry boundary and cover the existing fail-closed empty retrieval path. Signed-off-by: docushell-admin <hello@docushell.com>
Make Evidence Handle Bridge state projection reject incomplete reports, unknown statuses, extra check fields, invalid metadata, and malformed context evidence with stable fail-closed errors. Signed-off-by: docushell-admin <hello@docushell.com>
Collect repeated 32-request batch timings, derive a true batch median, and independently validate performance record shape, medians, hashes, and threshold derivations. Signed-off-by: docushell-admin <hello@docushell.com>
Run independent v0.5 performance-record validation after operator measurement. Signed-off-by: docushell-admin <hello@docushell.com>
Recompute source and citation hashes during independent v0.5 performance-record validation and cover fixture drift rejection. Signed-off-by: docushell-admin <hello@docushell.com>
Add a fail-closed validator requiring both macOS arm64 and Linux x64 ethos-full target-smoke records, canonical archive hashes, v0.5.0 version binding, and a full core commit id before npm B activation. Add contract tests, Makefile integration, and Unreleased changelog coverage while preserving the published 0.4.0 payload. Signed-off-by: docushell-admin <hello@docushell.com>
Run the v0.5.0 npm B frozen-core-A evidence contract in pull-request CI and assert the workflow wiring. Keep publication payloads unchanged while ensuring the new fail-closed guard cannot be bypassed by the normal merge gate. Signed-off-by: docushell-admin <hello@docushell.com>
Extend the v0.5 core activation guard to require package.json, package-lock.json, its root package entry, and vendor manifest to remain on the published 0.4.0 payload until frozen core-A refresh. Signed-off-by: docushell-admin <hello@docushell.com>
Require frozen core-A npm B evidence to match archive sizes in both target inventories and smoke records, with negative test coverage. Preserve fail-closed publication boundaries and changelog traceability. Signed-off-by: docushell-admin <hello@docushell.com>
Document the operator-only sequence for retaining core-A target evidence, refreshing npm metadata and vendor bytes, validating A-to-B bindings, freezing commit B, and completing publication closeout without advancing the current 0.4.0 payload. Signed-off-by: docushell-admin <hello@docushell.com>
Repair Evidence Handle Bridge validation and projection for canonical, hardened, partial, and stale reports; enforce structured-only citation semantics and run the shipped example against real fixtures. Complete HTML proof diagnostics with canonical labels, expand verify-batch acceptance coverage, correct performance sampling and environment evidence, and reject unsafe PDFium archive members. Regenerate npm declarations and add focused regression tests for every genuine finding. Signed-off-by: docushell-admin <hello@docushell.com>
Add the required boundary-exception changelog marker for the reviewed v0.5 release-boundary changes so the release-path guard can pass. Signed-off-by: docushell-admin <hello@docushell.com> Signed-off-by: docushell-admin <hello@docushell.com>
docushell-dev
force-pushed
the
dev/v0.5.0-release-plan
branch
from
July 21, 2026 11:36
5a2b674 to
d2c176e
Compare
added 2 commits
July 21, 2026 17:23
Index the v0.4.0 closeout record and reference its existing source commit so validation integrity accepts it. Synchronize the Python public API policy fixture with the Evidence Handle Bridge exports. Signed-off-by: docushell-admin <hello@docushell.com> Signed-off-by: docushell-admin <hello@docushell.com>
Update the checksum-pinned verification Action and its contract fixture to the published v0.4.0 Linux x64 archive and binary. Signed-off-by: docushell-admin <hello@docushell.com> Signed-off-by: docushell-admin <hello@docushell.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.