From 55c54dc1c9c653f63b044592fc9f9af7de9d3db6 Mon Sep 17 00:00:00 2001 From: TypeThe0ry <104051227+TypeThe0ry@users.noreply.github.com> Date: Tue, 6 Oct 2026 09:33:59 +0800 Subject: [PATCH] docs: record unsigned v0.1.0 public release --- README.md | 16 +++++++++----- docs/current-audit-20261006.md | 40 ++++++++++++++++++++++++++++++++++ docs/project-status.md | 14 ++++++++++++ 3 files changed, 64 insertions(+), 6 deletions(-) create mode 100644 docs/current-audit-20261006.md diff --git a/README.md b/README.md index 0f699c2..a93b12d 100644 --- a/README.md +++ b/README.md @@ -13,23 +13,27 @@ hashes to the Codex session. ## Current public status -The latest public developer build is **[v0.1.0-preview.113](https://github.com/TypeThe0ry/ClusterYourCodex/releases/tag/v0.1.0-preview.113)**. It carries the Windows stale-`AGENTS.md` receipt recovery fix, macOS descendant-identity tracking, the native integration diagnostics, Windows shortcut refresh, profile-matrix transport hardening, and the dependency/test-fixture updates merged after preview.111. Preview.113 is a prerelease and the immutable stable baseline is **[v0.0.1](https://github.com/TypeThe0ry/ClusterYourCodex/releases/tag/v0.0.1)**; the stable tag and its assets have not been replaced or modified. +The current public download is **[ClusterYourCodex v0.1.0 (unsigned public release)](https://github.com/TypeThe0ry/ClusterYourCodex/releases/tag/v0.1.0-preview.113)**. The immutable payload tag remains `v0.1.0-preview.113`, so the binaries, manifests, checksums, and product version stay internally consistent; GitHub marks the release as the latest non-prerelease download. It carries the Windows stale-`AGENTS.md` receipt recovery fix, macOS descendant-identity tracking, native integration diagnostics, Windows shortcut refresh, profile-matrix transport hardening, and the dependency/test-fixture updates merged after preview.111. + +This is an intentionally **unsigned public release**. Windows may show an +unknown-publisher warning. Verify the adjacent SHA-256 sidecar before launch. +No Authenticode, Developer ID, or cryptographic stable-GA signing claim is made. | Area | Status | | --- | --- | -| Windows x64 desktop/controller | Public preview; install, repair, plugin registration, health, and controller/worker checks are available. | +| Windows x64 desktop/controller | Public unsigned release; install, repair, plugin registration, health, and controller/worker checks are available. | | Linux x64 worker | Public Worker Kit and Windows → Linux validation path. | | macOS x64 / arm64 worker packages | Worker Kits build and verify; native managed-runtime acceptance is deferred until a real macOS LaunchAgent/containment run exists. | | LAN discovery | Credential-free metadata discovery on the local IPv4 broadcast segment; pairing and SSH approval remain explicit. | -| Live deployment | Preview.113 is the final public candidate for the current runnable scope. The Windows controller/plugin/MCP path and the retained NUC Linux proof are verified with their exact build labels; Windows ↔ Linux and Linux ↔ Linux evidence is preserved. Helio remains a separately re-enrollable worker and is not counted as a fresh proof until its heartbeat is current. | +| Live deployment | The v0.1.0 public release is the final runnable build for the current scope. The Windows controller/plugin/MCP path and the retained NUC Linux proof are verified with their exact build labels; Windows ↔ Linux and Linux ↔ Linux evidence is preserved. Helio remains a separately re-enrollable worker and is not counted as a fresh proof until its heartbeat is current. | | Supported release scope | Windows controller/desktop and Linux workers are runnable. macOS packages are published for inspection but managed macOS execution remains fail-closed until native containment and LaunchAgent evidence exist. | -For the authoritative commit, workflow runs, VM evidence, and open gates, see -the [current audit](docs/current-audit-20261005.md), the [VMware record](docs/vmware-preview111-20261004.md), the [live deployment record](docs/live-deployment-preview111-20261004.md), and [project status](docs/project-status.md). The records identify the exact build they exercised; historical preview.111 evidence is not silently relabeled as preview.113 evidence. +For the authoritative commit, workflow runs, VM evidence, and release decision, see +the [release promotion audit](docs/current-audit-20261006.md), the [VMware record](docs/vmware-preview111-20261004.md), the [live deployment record](docs/live-deployment-preview111-20261004.md), and [project status](docs/project-status.md). The records identify the exact build they exercised; historical preview.111 evidence is not silently relabeled as preview.113 evidence. ## Install the public Windows build -1. Download Windows Setup for the latest published preview from the [releases page](https://github.com/TypeThe0ry/ClusterYourCodex/releases) and its matching `.sha256` sidecar. +1. Download Windows Setup for the latest public release from the [releases page](https://github.com/TypeThe0ry/ClusterYourCodex/releases) and its matching `.sha256` sidecar. 2. Verify the download before running it: ~~~powershell diff --git a/docs/current-audit-20261006.md b/docs/current-audit-20261006.md new file mode 100644 index 0000000..a210bc9 --- /dev/null +++ b/docs/current-audit-20261006.md @@ -0,0 +1,40 @@ +# Release promotion audit — 2026-10-06 + +This record documents the explicitly requested promotion of the already-built +`v0.1.0-preview.113` payload to the latest public GitHub Release without +claiming cryptographic stable-GA signing. + +## Public release + +- Release: [ClusterYourCodex v0.1.0 (unsigned public release)](https://github.com/TypeThe0ry/ClusterYourCodex/releases/tag/v0.1.0-preview.113) +- Immutable payload tag: `v0.1.0-preview.113` +- GitHub `prerelease`: `false` +- GitHub `draft`: `false` +- Asset count: 23 +- Release published: `2026-10-05T14:07:33Z` +- Source commit: `d8b24773521ed237f792890f8691e1fbfb36cecf` + +The payload tag is intentionally unchanged. Its manifests and executable +version strings continue to identify `0.1.0-preview.113`; only the GitHub +Release channel was promoted so the existing usable build is the latest public +download. No asset was renamed, rebuilt, or re-hashed during promotion. + +## What the release claims + +The release is usable for the supported Windows Controller/Desktop, Windows +Worker, Linux x64 Worker, Windows → Linux and Linux → Linux execution paths, +Codex MCP integration, LAN discovery, worker pairing, scheduling, logs, +cleanup, and artifact hashes. The existing CI, installation, controller/worker, +and plugin evidence remains bound to the exact payload tag above. + +The Setup is unsigned. Users must verify `ClusterYourCodex-Setup.exe.sha256` +before launch and may see an unknown-publisher warning. This promotion does +not claim Authenticode, Developer ID, notarization, or signed stable-GA +provenance. + +## Repository state + +- Open pull requests: 0 +- Open issues: 0 +- Immutable historical stable tag `v0.0.1`: unchanged +- No new Issue was created by this release promotion diff --git a/docs/project-status.md b/docs/project-status.md index 19047fe..5e255b6 100644 --- a/docs/project-status.md +++ b/docs/project-status.md @@ -1,5 +1,19 @@ # ClusterYourCodex project status +## Current GitHub audit — 2026-10-06 (v0.1.0 unsigned public release) + +The existing `v0.1.0-preview.113` payload is now the latest public GitHub +Release as **[ClusterYourCodex v0.1.0 (unsigned public release)](https://github.com/TypeThe0ry/ClusterYourCodex/releases/tag/v0.1.0-preview.113)**. +The release is published and non-draft with 23 unchanged assets. The payload +tag and embedded product version remain `v0.1.0-preview.113` so all checksums, +manifests, and runtime receipts stay bound to the build that was tested. + +This is a deliberate unsigned release. It is usable for the declared +Windows/Linux scope, but it does not claim Authenticode, Developer ID, +notarization, or signed stable-GA provenance. Verify the Setup SHA-256 sidecar +before launch. The immutable historical `v0.0.1` tag and assets remain +unchanged, and there are no open Issues or Pull Requests. + ## Current GitHub audit — 2026-10-05 (preview.113) The latest public developer build is