refactor: Move Mihoto to system-level v1.0 management - #42
Merged
Merged
Conversation
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
Co-Authored-By: Codex GPT-5.6 Sol <noreply@openai.com> Co-Authored-By: Codex GPT-5.6 Luna <noreply@openai.com>
mihoto (0.15.0) — systemd timer, root model, TDD contracts
Pectics
marked this pull request as ready for review
July 30, 2026 13:45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Mihoto v1.0 replaces the former per-user Mihoro layout with a root-owned, systemd-only Mihomo manager. TUN, system service ownership, atomic recovery, verifiable installation, and release provenance are part of the stable product boundary.
Product changes
mihotowith system paths under/etc,/usr/local/bin, and/etc/systemd/system.SHA256SUMS, artifact smoke tests, and GitHub build provenance.pectos audit and remediation
Physical evidence is recorded by commit
67c9f1boncodex/pectos-audit-evidence-20260730.The Ubuntu 26.04 x86_64 run passed the repository systemd/TUN harnesses, init and idempotent init, permissions/capabilities, reboot restoration, component updates, apply, timer execution, recovery, and final cleanup. It also exposed two honest failures:
The P0 has a strict RED/GREEN lineage:
fa05bc7,106fbb7,35a7fff2ac52e2,0f9c0b8,eb601a1Mihoto now validates staged configuration with the installed Mihomo core before replacement. After restart it verifies both active state and a stable
NRestartscounter; failure atomically restores the previous config, resets the failed unit, recovers the old service, and returns non-zero.The release owner explicitly accepts this post-evidence remediation for v1.0. The physical-host workflow remains available as a manual self-hosted workflow; publication uses the versioned audit decision because the repository currently has no registered self-hosted runners.
Stable release
1.0.0v1.0.0docs/releases/v1.0.0.mddocs/audits/v1.0.0.mdVerification
Local fixed-toolchain gates on Rust 1.88.0:
cargo fmt --all -- --checkcargo clippy --all-targets -- -D warningscargo check --all-targetscargo test --all-targets: 54 unit + 5 CLI testscargo test --all-targets --no-default-features: 51 unit + 5 CLI testsscripts/check-system-scope.shscripts/check-release-workflow.shscripts/check-v1-contract.shscripts/test-installer-contract.shcargo build --locked --release;mihoto --versionreportsmihoto 1.0.0Remote CI must be green and review threads must be clear before merge. The PR must use a merge commit so the granular TDD and dual-attribution history remains intact.