Skip to content

release(v1.30.0): ship complete desktop at-rest encryption authority and verify migration/recovery #926

Description

@qnbs

CURRENT HARD PRE-TAG PUBLICATION BLOCK — 2026-10-09 (supersedes older fallback wording)

RELEASE = v1.30.0 / NOT ADMITTED
NEXT_V_STAR_TAG_ALLOWED = NO until #911 / QNB-162 mechanical publish gate is implemented, tested and TERMINAL
TAURI_GITHUB_RELEASE_PUBLICATION = BLOCKED pending fresh successful exact-tag OSV gate
GHCR_VERSION_MINOR_LATEST_PUSH = BLOCKED pending fresh successful exact-tag OSV gate
PROCEDURAL_CANCEL_OR_WATCH_SUBSTITUTION = NOT ACCEPTED for next release
R15_GATES_4D_4E_5_6_7 = RETAIN existing sequence/maintainer approval

GitHub #911 / Linear QNB-162 is an unconditional release-tag prerequisite, not simply a preferred improvement: no next release tag, Tauri/GitHub Release, GHCR version/minor/latest push, updater metadata publication or cutover-related release publishing until the independent per-workflow tag-SHA OSV security dependencies and negative/positive tests are proven. Old #926 wording allowing a maintainer-approved procedural watch was temporary for v1.29.1 and is not valid for the next tag. A mere healthy candidate or separate ci.yml Security Audit does not close #911. Gate 4D must not be preempted to implement this; schedule after Gate 6 and before the candidate/tag boundary, with #911 terminal before any tag. Preserve explicit Gate-7 authority and all other Release prerequisites. When #911 closes, the release owner independently re-reads workflow DAG, both failure-path proofs, issue/Linear relations, and exact resulting-main CI/CodeQL/Production/retention evidence before lifting this gate.


CURRENT CONTROL-PLANE CHECKPOINT — 2026-10-06 — v1.30 RELEASE OWNER GATED

CURRENT_MAIN = bf745090f7e980e167b1bbf01c7f6dea51fb451f
RESULTING_MAIN_CI_CD = 37434052556 / SUCCESS
RESULTING_MAIN_CODEQL = 37434052501 / SUCCESS
VERCEL_PRODUCTION = dpl_75HQcQhuYP6CxX43EjMov8Sjosdb / READY / exact CURRENT_MAIN / canonical HTTP 200
OPEN_PULL_REQUESTS = 0
DEPENDENCY_TRAIN = TERMINAL
FINAL_RETENTION = TERMINAL
ACTIVE_LANE = Gate 4D / #359 / QNB-11 — fresh read-only R4 admission
B2A = TERMINAL
B2 = NOT TERMINAL
RELEASE_EXECUTION_ALLOWED = NO
REQUIRED_SEQUENCE = complete Gate 4 → Gate 5 → Gate 6 → #948/QNB-182 → explicit Gate 7 → #932/QNB-176 + security/release truth gates → publication/verification
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

The release train has returned from dependency/retention housekeeping to the semantic R-15 critical path. No tag or release publication is admitted yet.


HISTORICAL / SUPERSEDED CONTROL-PLANE CHECKPOINT — 2026-10-04 — SUCCESSOR B / PR #954 ACTIVE

CURRENT_MAIN = 2001e63f3b7b1fbf2faa0270238f0de43ba84db1
PR_953 = MERGED / Successor A read-snapshot slice landed
PR_954 = OPEN / DRAFT / MERGEABLE
PR_954_HEAD = 93384b5a71f8bed4f2cde1428b762d2db0b13790
PR_954_BASE = 2001e63f3b7b1fbf2faa0270238f0de43ba84db1
PR_954_SCOPE = Successor B — Mutation / Root-Recovery / Lifecycle Closure
PR_954_SIZE = 16 files / 2 commits / +2121 -100
CODEANT = Quality / Coverage / SCR / SAST / SCA SUCCESS exact head
CODERABBIT = status SUCCESS, but Draft PR auto-review is disabled; do not call review clean
DEEPSOURCE = Python / Shell / Docker SUCCESS; review grade A; Rust status not inferred
VERCEL_PREVIEW = dpl_2JuoEypL2STM2hXvq9ESVa1Gmz9N BUILDING exact head
CI_CD = IN PROGRESS / not yet terminally proven here
CODEQL = not yet terminally proven here
REVIEWS = no submitted reviewer epoch yet
UNRESOLVED_REVIEW_THREADS = 0 at this checkpoint
PR_952 = OPEN / DRAFT / FROZEN PROVENANCE — DO NOT MERGE
GATE_4B = ACTIVE
4C / 4D / 4E = PENDING
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

Successor B is correctly based on the #953 resulting main and carries the semantic A+B union: #953 SessionBinding/rebind semantics plus the mutation/root-recovery/lifecycle mechanisms extracted from frozen #952. The prepared-root Step-F same-instance recovery R1–R5 proof remains this PR's material closure scope.

Do not close Gate 4B, #922, #445, or advance #359/4D until #954 converges on its exact final head, merges normally, and the exact resulting-main CI/CD + CodeQL + Vercel Production gate is terminal.


HISTORICAL / SUPERSEDED — Successor A exact-head checkpoint — PR #953 — 2026-10-03

PR = #953
HEAD = e9bd7556ab0f8111f843b78038fa56078792a097
BASE = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
FILES = 15
COMMITS = 3 signed
MEANINGFUL_LINES = 1870
PR_952 = OPEN / DRAFT / frozen provenance
CODEQL = SUCCESS
CHANGELOG/TEXT GUARDS = SUCCESS
CODEANT = all gates SUCCESS
CI_CD = IN_PROGRESS; all Rust/Node/platform/signature/security/build jobs green, E2E/VRT downstream still running
VERCEL = SUCCESS exact head
CODEX_EXACT_HEAD = one new P2 race remains open
MERGE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

The Terra/Codex closure commit e9bd7556... is now on the remote despite the executor's final report having observed a delayed remote ref. The earlier transport blocker is therefore RESOLVED / transient.

The three P2s from 12cf7833... are implemented and their threads are now resolved:

  • steady-state validated same-key external forward rebind;
  • lifetime-contract cross-process barrier wording;
  • admitted snapshot-backed catalog enumeration with raw production list/load paths gated away.

Fresh exact-head Codex review on e9bd7556... found one additional VALID same-slice blocker: a mid-capture TOCTOU can occur when provider.state() observes the old runtime as Unlocked, another process commits root N+1, then the subsequent anchor read sees N+1. Current code publishes N+1 into AuthorityCell.current before proving the provider is bound to N+1; resolve_ref then returns Locked, and future retry cannot take the strict-forward rebind path because N+1 has already poisoned current.

Required invariant for closure: never publish a newer snapshot into current before provider/key usability for that exact anchor is established. Prefer rebinding/validation before publication, or otherwise restore/retain the previous snapshot on resolution failure. Preserve explicit-lock, route-change/rotation, rollback, same-generation mismatch and incompatible-authority refusals.

This is still Read/Snapshot scope, but anti-cascade remains binding. One surgical race fix with a deterministic mid-capture regression is admissible; if it needs broad provider redesign or another architectural expansion, stop/split rather than cascade.

The new CodeScene Large Method warning on the 134-line cross-process integration test is non-material and resolved by evidence; no suppression or proof weakening.

Resource horizon remains unchanged: after #953 protected merge + exact resulting-main CI/CD/CodeQL/Vercel Production + cleanup/retention, executor reports and STOPs. No successor B or 4C.


CURRENT EXECUTION MODE — 2026-10-03 — RESOURCE-BOUNDED GATE 4B SPLIT

CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
PR_952 = OPEN / DRAFT / FROZEN PROVENANCE
PR_952_HEAD = e34aae28bba31269a814a9a2778346e568c3577e
PR_952_BUDGET = 16 files / 3000 meaningful lines / 5 signed commits
PR_952_MERGE = FORBIDDEN — validated prepared-root recovery gap remains
GATE_4B_SPLIT = ADMITTED
SUCCESSOR_A = Read/Snapshot Admission Closure
SUCCESSOR_B = Mutation/Root-Recovery/Lifecycle Closure
CURRENT_AGENT_HORIZON = SUCCESSOR_A ONLY → merge → exact resulting-main proof → cleanup/retention → STOP
CONTROL_PLANE_WRITES = ChatGPT session only; coding agent read-only except successor-PR operations
4C = PENDING
4D = PENDING via WorldScript-Studio#359 / QNB-11
4E = PENDING
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

Anti-cascade/resource decision: PR #952 is no longer a correction target. It is the immutable reviewed extraction source. The current coding-agent run is deliberately bounded to the first successor PR only and must stop after its normal protected merge, exact resulting-main CI/CD + CodeQL + Vercel Production verification, worktree/branch cleanup, and safe Vercel retention. It must not start successor B or 4C in the same execution epoch.

Control-plane ownership is also split deliberately: GitHub issue, Linear, milestone, release-program and checkpoint curation is performed from the ChatGPT control-plane session; the coding agent should only read those records when needed and should not spend token/week quota duplicating status maintenance.

The prepared-root Step-F coordinator-recovery Critical is Gate 4B successor-B scope, not Gate 4D. Gate 4D remains crash-resumable rotation/rekey after 4B and 4C. #360/QNB-12 remains open until complete Gate 4B closure.


CURRENT R-15 CHECKPOINT — PR 952 / e34aae2 — recovery finding blocks merge

CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
4A = TERMINAL via 950
4B_FOUNDATION = TERMINAL via 951
4B_INTEGRATION = ACTIVE / PR 952
PR_952_HEAD = e34aae28bba31269a814a9a2778346e568c3577e
PR_BUDGET = 16 files / 3000 meaningful lines / 5 signed commits
CODEQL = 37132489430 SUCCESS
CI_CD = 37132489420 SUCCESS — all required exact-head jobs terminal green
VERCEL_PREVIEW = dpl_FBpTZftnpnum9ZahLkPCeMfAWUtz READY exact head
CODEX = exact e34aae28 review reports no major issue
CODERABBIT = current incremental review 401b81b8 to e34aae28 complete / no actionable finding
CODEANT_QUALITY_SCR = FAILURE — valid material recovery finding is not dismissed
CODEANT = fresh full review completed; validated prepared-root recovery gap remains OPEN
MERGE_READY = NO
GH_360 = OPEN / QNB-12 In Progress
GATE_4 = ACTIVE / QNB-168 In Progress / M3 Active
4C = PENDING
4D = PENDING via 359 / QNB-11
4E = PENDING
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

The minimal stale-CAS correction is signed/pushed and locally verified: success and reconciled stale CAS clear the local mutation latch only after physical/writer/admission revalidation; all uncertain errors remain fail-closed. Normal Git transport works; no sandbox/protection/signing bypass occurred.

New material finding: after an injected step-F COMMIT failure, the public coordinator reconciliation returns PreparationPending even when the provider fault is removed. Existing authenticated recover_root is not integrated into the provider-owning coordinator operation API. Lock/shutdown correctly refuse, but same-instance recovery is incomplete. Diagnostic proof is retained locally; temporary probes were removed from source. Do not merge or close 360/QNB-12 until this is fixed with fault proof and fresh exact-head convergence.

No-op RootBusy is separately proved retryable after contention release; its conservative latch is not the prepared-root recovery defect. Remaining DeepSource Rust / CodeScene reds are understood test-only advisory findings, not green. No 4C journal, 4D rekey, collector, deletion, current-app authority change or Gate-7 switch was introduced. At saturated budget, establish a bounded mutation/root-recovery/lifecycle proof slice rather than expand or delete meaningful safety evidence.

HISTORICAL / SUPERSEDED — prior Gate-4B foundation checkpoint

CURRENT R-15 CHECKPOINT — 2026-10-03 — GATE 4B FOUNDATION TERMINAL VIA #951

CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
RESULTING_MAIN_VERIFICATION = TERMINAL
4A = TERMINAL via #950
4B_FOUNDATION = TERMINAL via #951
PR_951_FINAL_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
PR_951_MERGED_AT = 2026-10-03T04:51:40Z
RESULTING_MAIN_CI_CD = 37097936085 SUCCESS
RESULTING_MAIN_CODEQL = 37097936105 SUCCESS
VERCEL_PRODUCTION = dpl_9W7p2XZ4dscci5d2sXasPHK7iibz READY / PROMOTED exact CURRENT_MAIN / HTTP 200
HOUSEKEEPING = COMPLETE — clean local main; merged branch/tracking ref removed; other worktrees preserved
RETENTION = COMPLETE — 3 stale predecessor previews deleted; all 15 protected IDs and alias bindings verified
4B_OVERALL = ACTIVE / #360 / QNB-12
4B_INTEGRATION = NEXT — protected operation / authority-key / snapshot / lifecycle integration
GH_360 = OPEN until complete 4B acceptance
4C = PENDING / authenticated journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
GATE_4 = ACTIVE
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

All resulting-main CI/CD jobs succeeded, including Security Audit, Verified Signatures, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows platform evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, CI Success and Pages. Final-head CodeRabbit/CodeAnt/Codex review converged with no actionable finding and no unresolved thread. The two DeepSource test false positives remain evidence-dispositioned advisory red, not green; unavailable reviewer quotas remain recorded.

This terminal checkpoint is for the kernel admission foundation only. It does not complete issue 360, Gate 4B overall, Gate 4 or production Core authority. The next bounded engineering owner remains 4B integration, not 4C.

HISTORICAL / SUPERSEDED — #951 merged, post-merge proof was pending

CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
LAST_VERIFIED_MAIN = 4f33d7786076c1d00e73d5db9c527fbd1ea31693
4A = TERMINAL via #950
4B = ACTIVE / #360 / QNB-12
4B_FOUNDATION_PR = #951 MERGED at 2026-10-03T04:51:40Z
PR_951_FINAL_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
4B_FOUNDATION_TERMINAL = NO — resulting-main + Production + housekeeping pending
RESULTING_MAIN_CI_CD = 37097936085 IN_PROGRESS
RESULTING_MAIN_CODEQL = 37097936105 IN_PROGRESS
VERCEL_PRODUCTION_EXACT_CURRENT_MAIN = PENDING VERIFICATION
GH_360 = OPEN until complete 4B integration acceptance
NEXT_ENGINEERING = 4B protected-operation integration, only after foundation terminal proof
4C = PENDING / journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
GATE_4 = ACTIVE
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

Final-head CI/CD and CodeQL succeeded; CodeRabbit, CodeAnt and Codex reviewed the final delta/head without remaining actionable findings. All review threads are resolved. The two DeepSource test findings remain evidence-dispositioned advisory false positives, not a green status; quotas are recorded as unavailable. The normal protected squash merge did not close #360 or switch production Core authority. No next semantic slice or retention deletion starts before the exact resulting-main gate.

HISTORICAL / SUPERSEDED — pre-merge #951 checkpoint

CURRENT_MAIN = 4f33d7786076c1d00e73d5db9c527fbd1ea31693
GATE_3 = TERMINAL via #949
GATE_4 = ACTIVE via #922
4A = TERMINAL via #950
PR_950_FINAL_HEAD = f2dde0e65bb4dacfd6753f16a6bce1e28bf13078
RESULTING_MAIN_CI_CD = 36994420903 SUCCESS
RESULTING_MAIN_CODEQL = 36994420828 SUCCESS
VERCEL_PRODUCTION = dpl_7Z1r45ckAp4YeYpdHWtHdzQ8BWNN READY exact CURRENT_MAIN
4B = ACTIVE / #360 / QNB-12 / PR #951 kernel admission foundation; protected-operation integration follows
PR_951_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
PR_951_STATUS = OPEN / exact-head CI and review pending / not terminal
GH_360 = OPEN until full 4B acceptance
4C = PENDING / journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
NEXT = 4B → 4C → 4D → 4E → Gate 5 → Gate 6 → explicit Gate 7 authorization
PRE_GATE_7_RESIDUAL = #948
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

Live reconciliation confirms Gate 4A terminal, including exact resulting-main CI/CD, CodeQL and Production evidence. Gate 4B is the current renderer-neutral admission/fencing owner. Historical legacy filesystem defects remain provenance; this checkpoint does not claim a production authority switch or Gate 4 closure.

HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-02 10:21 CEST — superseded by verified Gate 4A terminal checkpoint

The release-critical lane remains R-15. Do not pull the deferred Dependabot/governance/editorial train ahead of Gate 4 absent a fresh material security/data-loss/release blocker. #950 is in its initial exact-head epoch and is not yet merge-ready.

HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-01 23:12 CEST — superseded 2026-10-02 10:21 CEST

TARGET = v1.30.0
M0 = TERMINAL
M1 = TERMINAL
M2 = ACTIVE — Gate 3 / #921 / QNB-167

CURRENT_MAIN = 03a24786f1c9fda76656dbbd2a635e324331ec81 (#941 resulting main)
RESULTING_MAIN_VERIFICATION = TERMINAL
CURRENT_MAIN_CI / CODEQL / SECURITY / SIGNATURES = SUCCESS
VERCEL_PRODUCTION = READY on exact CURRENT_MAIN

GATE_3A = TERMINAL via #930
GATE_3B = TERMINAL via #937 + #940
GATE_3C_PART_1 = TERMINAL via #941
GATE_3C_PART_2 = ACTIVE via #942 @ 48525c99ed20c88774df161b8d8c0d474a785302
NEXT = #942 terminal → 3C part 3 → Gate 3/#357 closure → Gate 4 → Gate 5 → Gate 6 → explicit Gate 7 authorization → Gate 7
PRE_RELEASE_DOC_TRUTH_GATE = #932 / QNB-176 after Gate 7
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

The release-critical lane remains R-15. #941 is terminal; #942 is active and not merge-ready at the latest readback. Do not pull Dependabot/governance/editorial work ahead of this lane absent a fresh material security/data-loss/release blocker. #911 remains a preferred pre-tag publication-security prerequisite, not a Gate 3–6 preemption.

HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-01 — superseded 2026-10-01 23:12 CEST

TARGET = v1.30.0
M0 = TERMINAL
M1 = TERMINAL — Gate 2
M2 = ACTIVE — Gate 3 / #921

CURRENT_MAIN = e43559b9bd6c5a8b6f5ba06ed9a2da42079551e1 (#940 resulting main)
RESULTING_MAIN_VERIFICATION = TERMINAL
CURRENT_MAIN_CI / CODEQL / SECURITY / SIGNATURES = SUCCESS
VERCEL_PRODUCTION = READY on exact CURRENT_MAIN

GATE_3A = TERMINAL via #930
GATE_3B_PART_1 = TERMINAL via #937
GATE_3B_PART_2 = TERMINAL via #940
GATE_3C_PART_1 = ACTIVE via #941, head 7a1edcf1527947e7b75cc8e8c6fbe6e1ea11a701
NEXT = #941 terminal → 3C part 2 → 3C part 3 / #357 reconciliation → Gate 4 → Gate 5 → Gate 6 → explicit Gate 7 approval → Gate 7
PRE_RELEASE_DOC_TRUTH_GATE = #932 / QNB-176 after Gate 7 and before candidate/tag freeze
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

The release-critical lane remains R-15. Gate 3B is now terminal; do not describe #936/#937/#940 as active prerequisites. Current execution is Gate 3C through #941. #941 remains in exact-head convergence and is not merge-ready at the latest readback because current reviewer findings still need correction/disposition and Node 22/24 are still running.

Primary execution sequence — current

  1. TERMINAL — dependency-security blocker security(deps): raise axios and DOMPurify floors after fresh OSV gate failure #918/fix(deps): raise the axios and DOMPurify override floors (fresh OSV findings, #918) #919.
  2. TERMINAL — Gate 2 via feat(core): add the Gate 2 typed record-identity registry (#445) #917/feat(core): add the Gate 2 identity-bound record codec (#445) #928/feat(core): close Gate 2 with the §10.4.1 record-class disposition (#445) #929.
  3. TERMINAL — Gate 3A via feat(core): add Gate 3 slice 3A durable staging and promotion (#445) #930.
  4. TERMINAL — ci(docs-truth): machine-check R-15 gate status agreement between the contract and the Core Migration Ledger #933/ci(docs-truth): machine-check R-15 gate status across the contract and the ledger (#933) #934 and R-15 gate status guard: strict canonical-block grammar and fuller prose parsing (follow-up to #933) #935/fix(docs-truth): strict R-15 status block grammar and fuller prose parsing (#935) #936 docs-truth support.
  5. TERMINAL — Gate 3B via feat(core): add the Gate 3 slice 3B record-commit marker codec (#445) #937 + feat(core): add the Gate 3 slice 3B commit protocol and startup reconciliation (#445) #940; resulting main e43559b9... fully proven.
  6. ACTIVE — Gate 3C part 1 via feat(core): add the Gate 3 slice 3C authority-root digests (#445) #941.
  7. NEXT — 3C parts 2/3 and Desktop atomic writes: fsync temp file + parent directory before/after rename for true crash durability #357 reconciliation; then Gate 3 terminal.
  8. Gate 4 security(core/R-15): Gate 4 — journal, admission, rekey/recovery and cross-process serialization #922 → Gate 5 security(core/R-15): Gate 5 — fence every protected writer and complete inventory/migration readiness #923 → Gate 6 security(core/R-15): Gate 6 — packaged shadow/compatibility qualification on Linux, Windows and macOS #924.
  9. Explicit maintainer authorization checkpoint for Gate 7.
  10. Gate 7 security(core/R-15): Gate 7 — explicit production authority switch, legacy migration and cutover #925.
  11. docs(release): pre-v1.30 public-doc parity, DEV.to discoverability and bounded housekeeping checkpoint #932 pre-release source/public-truth checkpoint.
  12. Freeze exact candidate and execute v1.30.0 qualification/publication through this owner.

HISTORICAL / SUPERSEDED — release checkpoint before Gate 3B completion — 2026-10-01

TARGET = v1.30.0
M0 = TERMINAL
M1 = TERMINAL — Gate 2
M2 = ACTIVE — Gate 3 (#921)
M2_3A = TERMINAL via #930
CURRENT_MAIN = cd12c1041fc5e6e7197484bd81c88597f6974fa6 (#936 resulting main)
#933/#934 = TERMINAL
#935/#936 = MERGED
RESULTING_MAIN_VERIFICATION = IN PROGRESS
CODEQL / SECURITY / SIGNATURES = SUCCESS
VERCEL_PRODUCTION = READY on exact CURRENT_MAIN
NODE_22 / NODE_24 = RUNNING at latest readback
NEXT = resulting-main terminal proof → Gate 3B → 3C → Gate 4 → Gate 5 → Gate 6 → explicit Gate 7 approval → Gate 7
PRE_RELEASE_DOC_TRUTH_GATE = #932 / QNB-176 after Gate 7, before release freeze
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

The active release-critical lane remains R-15. #935/#936 is merged support history now, not an active release-preparation lane. Complete exact-SHA resulting-main proof and continue directly to Gate 3B.

Pre-release documentation/housekeeping gate — #932

After Gate 7 / #925 is merged and its resulting-main authority state is proven, but before candidate/tag freeze, complete #932:

#925 Gate 7 resulting-main proof
→ #932 README/GitBook/DeepWiki/DEV.to + bounded docs housekeeping
→ resulting-main proof
→ release freeze/tag/publish

#932 is a release-truth checkpoint, not a broad housekeeping detour. #877/#927 remain the larger post-release cleanup/reset owners.

In particular, do not change current README desktop-at-rest-encryption claims before Gate 7 makes those claims stale.

Milestone mission

Make v1.30.0 the focused milestone release that completes and ships the renderer-neutral desktop at-rest encryption program owned by #445.

A minor-version bump from v1.29.1 to v1.30.0 is intentional: this is a substantial new production security/storage capability and migration boundary, not a patch-only correction.

MILESTONE = COMPLETE_DESKTOP_AT_REST_ENCRYPTION
TARGET_VERSION = 1.30.0
PRIMARY_PROGRAM = #445 / R-15
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO until Gate 7 authorization

Primary execution sequence

  1. TERMINAL — dependency-security blocker security(deps): raise axios and DOMPurify floors after fresh OSV gate failure #918 / PR fix(deps): raise the axios and DOMPurify override floors (fresh OSV findings, #918) #919.
  2. TERMINAL — Gate 2 via feat(core): add the Gate 2 typed record-identity registry (#445) #917 → feat(core): add the Gate 2 identity-bound record codec (#445) #928 → feat(core): close Gate 2 with the §10.4.1 record-class disposition (#445) #929; security(core/R-15): Gate 2 — complete identity-bound adapters and AAD closure #920 closed.
  3. TERMINAL — Gate 3A via feat(core): add Gate 3 slice 3A durable staging and promotion (#445) #930.
  4. TERMINAL — ci(docs-truth): machine-check R-15 gate status agreement between the contract and the Core Migration Ledger #933 / PR ci(docs-truth): machine-check R-15 gate status across the contract and the ledger (#933) #934 deterministic R-15 gate-status truth guard; resulting main c4240125... proven.
  5. TERMINAL/MERGED — R-15 gate status guard: strict canonical-block grammar and fuller prose parsing (follow-up to #933) #935 / PR fix(docs-truth): strict R-15 status block grammar and fuller prose parsing (#935) #936 parser hardening; resulting-main verification is completing on cd12c104....
  6. NEXT — Gate 3B, then 3C / Desktop atomic writes: fsync temp file + parent directory before/after rename for true crash durability #357 reconciliation.
  7. Gate 4 via security(core/R-15): Gate 4 — journal, admission, rekey/recovery and cross-process serialization #922 — journal/admission/rekey/recovery/cross-process serialization / Desktop fs-data key-rotation migration is not crash-resumable (mixed-key state possible) #359/Desktop fs reads/writes don't participate in the encryption-migration admission lock (race window during disable/rotate) #360.
  8. Gate 5 via security(core/R-15): Gate 5 — fence every protected writer and complete inventory/migration readiness #923 — all protected classes fenced + inventory-complete migration readiness.
  9. Gate 6 via security(core/R-15): Gate 6 — packaged shadow/compatibility qualification on Linux, Windows and macOS #924 — packaged shadow/compatibility qualification using test(native): automate packaged-state release qualification for built Tauri desktop artifacts #906.
  10. Explicit maintainer authorization checkpoint for Gate 7.
  11. Gate 7 via security(core/R-15): Gate 7 — explicit production authority switch, legacy migration and cutover #925 — production authority switch + preserve-first legacy migration; Bind desktop fs-backed ciphertext to its record identity (AAD) to prevent cross-file substitution #361 closes only with shipped-authority evidence.
  12. docs(release): pre-v1.30 public-doc parity, DEV.to discoverability and bounded housekeeping checkpoint #932 pre-release public/source-truth checkpoint.
  13. Freeze exact release candidate and execute release qualification/publication through this owner.

No unrelated roadmap expansion should preempt this lane unless a fresh P0/P1 security/data-loss/release blocker requires it.

Mandatory release prerequisites

Product/security

Packaging / qualification

Release pipeline

  • release: make tag-time publishing depend on the security audit (Tauri release + GHCR) #911 / QNB-162 MUST be terminal before the next v tag*: exact tag-time OSV Security Audit is a hard mechanical dependency for Tauri/GitHub Release and all GHCR pushes/moving aliases; a procedural watch or manual cancellation does not satisfy this gate;
  • exact candidate Security Audit, CI/CD and CodeQL green;
  • updater/release metadata correct;
  • GHCR semantic tags/aliases verified;
  • signed tag; never move/reuse a failed tag.

Compliance / distribution

Release execution

freeze exact candidate SHA
→ resulting-main CI/CD + CodeQL
→ fresh side-effect-free Security Audit
→ exact-SHA packaged builds
→ packaged at-rest qualification matrix
→ release-truth/docs final check
→ signed v1.30.0 tag
→ tag-time security gate
→ Tauri/GitHub Release + GHCR publication
→ verify assets/digests/updater metadata
→ verify canonical web/production health
→ verify upgrade path from v1.29.1
→ declare v1.30.0 VERIFIED

Terminal definition

Do not close on tag creation alone. v1.30.0 VERIFIED requires published desktop assets, correct GHCR state, verified signed tag, exact released commit, packaged migration/reopen proof, no stored-data regression, at-rest claims proven against real released artifacts, healthy post-release main and mirrored Linear evidence.

After terminal release

Immediately hand off to #927 for the dedicated post-v1.30 source-truth/audit/housekeeping reset, then resume the highest-priority non-R-15 roadmap work from a freshly audited control plane.

Activity

  1. qnbs commented on Sep 30, 2026

    @qnbs
    OwnerAuthor

    Linear control-plane mirror

    GitHub remains the implementation/evidence source of truth; Linear tracks sequencing, priority, dependencies and milestone progress.

  2. qnbs commented on Oct 3, 2026

    @qnbs
    OwnerAuthor

    PR #953 final-head checkpoint — 3c118bc652210a5861fe408e9d89e4893a66a3a0.

    • 15 files / 1925 meaningful lines / 4 signed commits
    • final mid-capture publication/rebind race fixed in one-file commit fix(core): make snapshot publication rebind atomic (#445)
    • deterministic interleaving test proves N→N+1 external commit between state observation and anchor read cannot poison AuthorityCell.current; exact key usability and exact anchor equality are proven before publication; subsequent capture remains usable
    • earlier read/snapshot P2s remain closed
    • CodeAnt legacy-write observation is partially valid but explicitly deferred to Successor B mutation/writer-admission owner; it does not invalidate the immutable pinned read proof and does not admit mutation scope into feat(core): admit protected reads through pinned snapshots (#445) #953
    • CodeQL, CodeAnt gates, Vercel, CHANGELOG/Text guards are green exact-head
    • DeepSource Rust and CodeScene remain advisory reds for already-dispositioned test-fixture/test-method metrics; no suppression or proof weakening
    • CI/CD still converging (Node 22/24 currently running at this checkpoint)
    • fresh Codex review on exact 3c118bc6... still pending
    • MERGE_READY = NO until terminal CI + fresh exact-head reviewer convergence
    • no Successor B / 4C; production authority switch remains NO
  3. qnbs commented on Oct 4, 2026

    @qnbs
    OwnerAuthor

    PR #953 continuation authorization — 2026-10-04.

    Fresh Codex exact-head review on 3c118bc652210a5861fe408e9d89e4893a66a3a0 produced three VALID Read/Rebind P2s:

    1. prepared-only anchor changes can currently lock/strand a reader even though committed read authority did not change;
    2. KeyState::Locked cannot distinguish explicit lock from a stale previously-unlocked session, so same-key forward auto-rebind can violate explicit-lock refusal;
    3. before first capture, current=None provides no baseline, so a stale previously-unlocked runtime cannot rebind after an external same-key advance.

    NEW EXECUTION POLICY: these findings are explicitly authorized for further correction on #953. Do NOT stop merely because another fixable same-slice P2 appears. Continue correction → local proof → signed push → fresh exact-head review/CI cycles until #953 genuinely converges and can be merged normally. Only an unfixable platform/auth/protection blocker or a scope change into Successor-B mutation/root-recovery/4C may stop execution.

    Preferred common design direction: preserve a non-secret provider session-binding witness (scope + committed root, or equivalent) that survives stale-root detection but is cleared by explicit lock. Use it to distinguish explicit lock from stale binding and to establish a safe pre-first-capture baseline. Prepared-root-only changes must not be treated as read-authority changes; compare/revalidate the committed read-authority projection rather than the whole AnchorState where appropriate.

    #360 / QNB-12 remain open. Successor B remains mutation/root-recovery/lifecycle. PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions