diff --git a/CHANGELOG.md b/CHANGELOG.md index 4961b73..e933c7f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,10 @@ ## Unreleased +- Reconciled current public issue status with the closed Windows/Linux scope + and recorded the public preview.113 local Setup commit, executable versions, + and healthy Controller/database without relabeling historical live jobs. + - Fixed macOS managed-process tracking so descendants observed before a reparenting/new-session transition remain addressable by their exact `(pid, lstart)` identity; a reused PID is still rejected. Added a regression diff --git a/README.md b/README.md index 55d3563..0f699c2 100644 --- a/README.md +++ b/README.md @@ -19,7 +19,7 @@ The latest public developer build is **[v0.1.0-preview.113](https://github.com/T | --- | --- | | Windows x64 desktop/controller | Public preview; install, repair, plugin registration, health, and controller/worker checks are available. | | Linux x64 worker | Public Worker Kit and Windows → Linux validation path. | -| macOS x64 / arm64 worker packages | Worker Kits build and verify; native managed-runtime acceptance is deferred in [Issue #3](https://github.com/TypeThe0ry/ClusterYourCodex/issues/3). | +| macOS x64 / arm64 worker packages | Worker Kits build and verify; native managed-runtime acceptance is deferred until a real macOS LaunchAgent/containment run exists. | | LAN discovery | Credential-free metadata discovery on the local IPv4 broadcast segment; pairing and SSH approval remain explicit. | | Live deployment | Preview.113 is the final public candidate for the current runnable scope. The Windows controller/plugin/MCP path and the retained NUC Linux proof are verified with their exact build labels; Windows ↔ Linux and Linux ↔ Linux evidence is preserved. Helio remains a separately re-enrollable worker and is not counted as a fresh proof until its heartbeat is current. | | Supported release scope | Windows controller/desktop and Linux workers are runnable. macOS packages are published for inspection but managed macOS execution remains fail-closed until native containment and LaunchAgent evidence exist. | @@ -156,10 +156,10 @@ The remaining non-blocking release evidence is a clean guest matrix covering Install → Repair → versioned Upgrade → interrupted Rollback → Uninstall, plus production Authenticode/tray signing. macOS remains deliberately fail-closed: its packages can be inspected, but managed execution is not enabled without a -native LaunchAgent/containment proof. The exact evidence and boundaries belong -in [Issue #2](https://github.com/TypeThe0ry/ClusterYourCodex/issues/2), -[Issue #3](https://github.com/TypeThe0ry/ClusterYourCodex/issues/3), and the -[current audit](docs/current-audit-20261005.md). +native LaunchAgent/containment proof. Issues #2 and #3 are closed for the +declared Windows/Linux runnable scope. The exact evidence and remaining +Certified GA boundaries are recorded in the [release checklist](RELEASE.md) +and [current audit](docs/current-audit-20261005.md). ## Develop diff --git a/docs/current-audit-20261005.md b/docs/current-audit-20261005.md index 95cb26e..2728a5d 100644 --- a/docs/current-audit-20261005.md +++ b/docs/current-audit-20261005.md @@ -30,13 +30,16 @@ operation is unchanged. ## Local Windows and Linux evidence The public preview.113 Setup is the final candidate for the current runnable -scope. The Windows controller -The controller health endpoint reported `status=ok`, `apiVersion=cyc.dev/v1`, -and `database=ok`. The native plugin contract, integrity, and MCP probes passed. +scope. The local Windows controller health endpoint reported `status=ok`, +`apiVersion=cyc.dev/v1`, and `database=ok`. The retained native plugin contract, +integrity, and MCP probes passed at the builds identified by their records. +The committed public Setup install is +recorded in [`local-install-preview113-20261005.md`](local-install-preview113-20261005.md). -The fresh same-host Windows controller/worker run reached +The retained same-host Windows controller/worker run reached `queued → running → succeeded`; all 14 checks passed, including artifact -verification, process cleanup, and secret scanning. The sanitized record is +verification, process cleanup, and secret scanning at source `60bb863` after +the preview.111 install. It is not relabeled as preview.113 evidence. The record is [`local-windows-roundtrip-20261005.md`](local-windows-roundtrip-20261005.md). The retained NUC Linux proof job completed with exit code 0 and a verified @@ -51,21 +54,18 @@ connections; no new Helio runtime success is claimed from that observation. The safe recovery path is native desktop re-enrollment, not plaintext secrets in a shell command or repository artifact. -## Remaining release gates +## Scope and remaining release gates -Issue #2's remaining evidence boundary is a clean current-source Windows 11 -VM run of `Install → Repair → Upgrade → Rollback → Uninstall`, plus production -Authenticode/tray acceptance. The installer, controller, Codex bridge, repair, -uninstall, LAN discovery, and Windows/Linux round-trip path are already -runnable and covered by hosted/VM evidence. +Issues #2 and #3 were closed on 2026-10-05 for the explicitly declared +Windows/Linux runnable scope. The installer, controller, Codex bridge, repair, +uninstall, LAN discovery, and Windows/Linux round-trip path are runnable and +covered by the published preview and retained evidence. -Issue #3's Linux worker path and package contracts are covered. The macOS -worker remains deliberately fail-closed until a real macOS host proves -LaunchAgent lifecycle, managed controller/worker execution, detached-process -cleanup, PID-reuse safety, and any required signing/notarization. The source -now retains observed macOS descendant identities across reparenting while -still rejecting a reused PID; this is unit-tested but not a substitute for a -native macOS run. - -Until those optional native/production gates have direct evidence, public -builds remain prereleases and `v0.0.1` remains untouched. +Certified GA remains a separate, stricter release channel. It still requires a +clean current-source Windows 11 version-changing matrix, production +Authenticode/tray acceptance, and a real macOS LaunchAgent/managed-runtime +run. The macOS worker therefore remains deliberately fail-closed; its +descendant identity and PID-reuse protections are unit-tested, but are not +presented as native macOS acceptance. Until those optional production gates +have direct evidence, `v0.1.0-preview.113` is the final runnable public build +and `v0.0.1` remains untouched. diff --git a/docs/local-install-preview113-20261005.md b/docs/local-install-preview113-20261005.md new file mode 100644 index 0000000..dd45472 --- /dev/null +++ b/docs/local-install-preview113-20261005.md @@ -0,0 +1,45 @@ +# Local Windows install — preview.113 + +This record captures the final local installation performed from the public +`v0.1.0-preview.113` Setup asset. It contains no credentials or bearer tokens. + +## Source and package + +- Release: [`v0.1.0-preview.113`](https://github.com/TypeThe0ry/ClusterYourCodex/releases/tag/v0.1.0-preview.113) +- Source commit: `11ca9d82c2782a93ec25a40958c480e818be3a51` +- Setup asset: `ClusterYourCodex-Setup.exe` +- The downloaded Setup SHA-256 matched its adjacent `.sha256` sidecar before execution. + +## Installation result + +- Install mode: silent `/S` +- Install root: `%LOCALAPPDATA%\Programs\ClusterYourCodex` +- Data root: `%LOCALAPPDATA%\ClusterYourCodex` +- Installer transaction: committed +- Installed product version: `0.1.0-preview.113` +- Scheduled task: `ClusterYourCodex Controller`, running + +The transaction first staged the payload and then committed the install +manifest. The existing `preview.112` binaries were not reported as upgraded +until the committed manifest and executable versions agreed. + +## Runtime probes + +Installed binaries all reported `0.1.0-preview.113`: + +```text +cyc 0.1.0-preview.113 +cyc-controller 0.1.0-preview.113 +cyc-worker 0.1.0-preview.113 +``` + +The authenticated CLI health probe returned: + +```json +{"apiVersion":"cyc.dev/v1","controllerVersion":"0.1.0-preview.113","database":"ok","status":"ok"} +``` + +This proves the local Windows Controller and database are running after the +public Setup install. It does not relabel the retained NUC Linux proof as a +preview.113 cross-node run; that evidence remains linked from the current +audit with its original build label. diff --git a/docs/project-status.md b/docs/project-status.md index 0307fb5..b73d227 100644 --- a/docs/project-status.md +++ b/docs/project-status.md @@ -17,10 +17,10 @@ remain native-desktop-only operations. The browser now labels this state as Tauri bridge. The current Windows installation of preview.113 has a healthy Controller and -database, a valid native plugin/MCP probe, and a fresh same-host Windows -controller/worker round trip with 14/14 checks passing. The local install and -round-trip records are retained in -[`local-install-preview111-20261005.md`](local-install-preview111-20261005.md) +database. The retained native plugin/MCP and same-host Windows +controller/worker proofs keep their original build labels; the retained +round trip passed 14/14 checks. The local install and round-trip records are in +[`local-install-preview113-20261005.md`](local-install-preview113-20261005.md) and [`local-windows-roundtrip-20261005.md`](local-windows-roundtrip-20261005.md). The NUC Linux worker also completed a proof job with exit code 0 under the retained preview.111 evidence record; that record is not relabeled as @@ -33,13 +33,14 @@ claimed from that observation. Re-enrollment must use the native desktop provisioning flow so credentials remain in the OS vault and out of logs. Issues [#2](https://github.com/TypeThe0ry/ClusterYourCodex/issues/2) and -[#3](https://github.com/TypeThe0ry/ClusterYourCodex/issues/3) remain open. The -supported Windows/Linux path is runnable; the remaining evidence boundary is -the clean current-source Windows version-changing `Install → Repair → Upgrade -→ Rollback → Uninstall` matrix plus production Authenticode/final packaged -acceptance. macOS remains fail-closed until native LaunchAgent/containment and -managed-runtime evidence exists. Hosted CI, a provisioned VM, or a browser -preview is not promoted to those stronger claims. +[#3](https://github.com/TypeThe0ry/ClusterYourCodex/issues/3) were closed on +2026-10-05 for the explicitly declared Windows/Linux runnable scope. The +remaining evidence boundary is the optional Certified GA path: a clean +current-source Windows version-changing `Install → Repair → Upgrade → +Rollback → Uninstall` matrix plus production Authenticode/final packaged +acceptance, and native macOS LaunchAgent/containment and managed-runtime +evidence. macOS remains fail-closed; hosted CI, a provisioned VM, or a browser +preview is not relabeled as native macOS proof. PR #208 additionally maps native integration failures to actionable localized diagnostics, preserves safe controller transport codes, disables native