Skip to content

Commit 131d3f7

Browse files
authored
chore(release): prepare VaultSync 2.0.0 build 36 (#130)
Bump the app and widget to 2.0.0 / build 36 and turn the CHANGELOG's unreleased section into the 2.0.0 entry, led by the explicit Controlled Diagnostics roundtrip check. StoreKit, bundle IDs, signing, and entitlements are untouched. The XCFramework was rebuilt from this exact tree; the complete plan (431/438, zero failed or skipped), the Release-configuration simulator build, and the Go, notify, relay, and lint gates ran green against it. The physical-device smoke remains not executed under the owner-approved waiver with recorded substitute evidence.
1 parent a126ac9 commit 131d3f7

2 files changed

Lines changed: 7 additions & 5 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,12 @@ All notable changes to VaultSync are documented here.
44

55
---
66

7-
## [Unreleased]
7+
## [2.0.0] — 2026-07-15
88

99
### Added
1010

11+
- **An explicit Controlled Diagnostics check can prove an honest end-to-end roundtrip with your own server helper** ([#125](https://github.com/psimaker/vaultsync/pull/125), [#126](https://github.com/psimaker/vaultsync/pull/126), [#127](https://github.com/psimaker/vaultsync/pull/127), [#128](https://github.com/psimaker/vaultsync/pull/128)) — after explicit QR pairing, an operator-side one-shot creation of the visible `VaultSync Diagnostics` area, and localized consent, one tap creates one signed 256-byte test file, accepts only the paired helper's exact signed confirmation as upload evidence, then authorizes exactly one signed helper response file and accepts only its fresh synchronized arrival with complete validation as download evidence. A causal roundtrip is confirmed solely from that one check's upload and download; results never claim global sync health, partial and failed outcomes stay visible without upgrades, and a late, copied, stale, or tampered artifact can never change a result. Nothing is created, paired, trusted, or changed without these explicit steps; upgrading alone changes nothing, and old helpers report the capability as unavailable instead of failing. Localized in English, German, Spanish, and Simplified Chinese.
12+
1113
- **A dormant response and authenticated-cleanup foundation implements Decision 024 message types 6–9 for local testing** — exact app-signed response authorization can bind the confined M5 request and helper attestation, create one immutable helper-signed response containing exactly 256 random payload bytes before acceptance, and drive digest-targeted, identity-checked, idempotent cleanup with a signed per-target acknowledgement. Go/Swift golden, parser, fuzz, model, privacy, Linux crash/restart/race, and confinement tests cover this test-only boundary. It has no listener, endpoint, advertised capability, app callsite, packaging, publication, controlled-download evidence, or roundtrip claim.
1214
- **A dormant upload-attestation foundation implements the Decision 024 upload leg for local testing** — helper-only code can open and validate one exact app-signed 256-byte request through the confined M4 namespace, enforce canonical CBOR, Ed25519, digest, binding, epoch, TTL, rate, replay, and single-flight rules, atomically persist one immutable helper attestation, and return those same bytes idempotently. Go/Swift golden vectors, parser/fuzz/model/privacy tests, Linux crash/race/restart tests, and a network-isolated two-instance Syncthing E2E cover this upload-only boundary. It is not called by the installed helper or app, advertises no capability, exposes no endpoint or listener, and implements no response authorization, download, cleanup protocol, or roundtrip evidence.
1315
- **A dormant diagnostics-namespace safety foundation is available for review and testing** — internal helper code now models the fixed `VaultSync Diagnostics` ownership records, stable opaque installation bindings, a separate atomic state store, collision-safe explicit preparation, descriptor-relative Linux confinement, and bounded create-once cleanup. A local Docker harness proves only an exact existing host-bind subdirectory with a read-only container root, separate state, read-only config, dropped capabilities, no network, and mount-swap rejection. The installed app/helper does not call this code, creates no folder or state, changes no Syncthing configuration, and exposes no listener or product flow. Named-volume Docker, rootless Docker, NAS, Linux host packaging, macOS, and Windows remain unsupported for this future capability.

‎ios/project.yml‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -64,8 +64,8 @@ targets:
6464
info:
6565
path: VaultSync/Info.plist
6666
properties:
67-
CFBundleShortVersionString: "1.8.2"
68-
CFBundleVersion: "35"
67+
CFBundleShortVersionString: "2.0.0"
68+
CFBundleVersion: "36"
6969
UILaunchScreen: {}
7070
UIApplicationSceneManifest:
7171
UIApplicationSupportsMultipleScenes: false
@@ -138,8 +138,8 @@ targets:
138138
info:
139139
path: VaultSyncWidget/Info.plist
140140
properties:
141-
CFBundleShortVersionString: "1.8.2"
142-
CFBundleVersion: "35"
141+
CFBundleShortVersionString: "2.0.0"
142+
CFBundleVersion: "36"
143143
CFBundleDisplayName: VaultSync Widget
144144
NSExtension:
145145
NSExtensionPointIdentifier: com.apple.widgetkit-extension

0 commit comments

Comments
 (0)