diff --git a/BEARING.md b/BEARING.md index 6ffc0d9..1772f32 100644 --- a/BEARING.md +++ b/BEARING.md @@ -14,7 +14,7 @@ timeline ## Current State -`v6.5.10` shipped on `2026-08-24`. +`v6.5.11` shipped on `2026-10-02`. Published Plumbing 3.3.2 now classifies closed mktree transport input for the existing bounded immutable-object retry; producer errors and mutable-ref semantics are unchanged. Application asset, bundle, page, cache, expiry, witness, and repository-diagnostics APIs sit above mutable root sets and the low-level CAS pipeline. Direct bundle-reference reads and bounded diff --git a/README.md b/README.md index 74d3b65..a026e3b 100644 --- a/README.md +++ b/README.md @@ -53,9 +53,9 @@ Unlike traditional LFS which moves files to external servers, `git-cas` treats t Existing v5 users should read [UPGRADING.md](./UPGRADING.md) and run `npm run upgrade` in dry-run mode before restoring old encrypted vault entries. For the release overview, see the -[v6.5.10 Release Notes](./docs/releases/v6.5.10.md). +[v6.5.11 Release Notes](./docs/releases/v6.5.11.md). -The v6.5.11 candidate adopts published Plumbing 3.3.2 for bounded recovery from closed mktree transports after external Git GC. It preserves producer error identity and existing object formats; see [v6.5.11 Release Notes](./docs/releases/v6.5.11.md). Registry publication is pending release verification and merge. +Published v6.5.11 adopts published Plumbing 3.3.2 for bounded recovery from closed mktree transports after external Git GC. It preserves producer error identity and existing object formats; see [v6.5.11 Release Notes](./docs/releases/v6.5.11.md). Publication and independent registry-consumer evidence are recorded in the [release record](https://github.com/git-stunts/git-cas/pull/132). ### 1. CLI Usage diff --git a/STATUS.md b/STATUS.md index 69c0149..c38cdfe 100644 --- a/STATUS.md +++ b/STATUS.md @@ -1,8 +1,8 @@ # STATUS -**Last tagged release:** `v6.5.10` (`2026-08-24`) -**Current release state:** `v6.5.10` is published to npm and GitHub Releases. -**Latest verification:** reviewed release merge `4316f4ec` passed 14/14 release-verifier stages with 7,192 observed tests; signed tag `v6.5.10` peels to that merge, and release workflow `32782415971` published the matching npm artifact plus final GitHub Release. +**Last tagged release:** `v6.5.11` (`2026-10-02`) +**Current release state:** `v6.5.11` is published to npm and GitHub Releases. +**Latest verification:** reviewed merge `1bcd6311` passed 14/14 release gates with 7,224 observations across runtimes. Signed tag `v6.5.11`, npm gitHead and release workflow `37008258240` agree; a fresh registry consumer passed six recovery checks, store/restore and CLI verification. **Playback truth:** `main` **Runtimes:** Node.js 22.x, Bun, Deno **Current planning method:** [WORKFLOW.md](./WORKFLOW.md) @@ -18,11 +18,12 @@ - The machine-facing `git cas agent` surface exists and now supports OS-keychain passphrase sources for vault-derived key flows, but parity and portability are still partial. +- **v6.5.11 artifact posture** — published Plumbing 3.3.2 supplies bounded mktree transport recovery through the existing CAS retry. [Publication evidence](docs/design/0062-mktree-transport-recovery/witness/release-publication.md) pins the merged source, tag, registry integrity and Docker consumer proof. No stored format, handle, mutable-ref retry or application migration changes. Git-warp attachment adoption remains separate. - **v6.5.10 artifact posture** — implementation PR [#128](https://github.com/git-stunts/git-cas/pull/128) and release PR [#129](https://github.com/git-stunts/git-cas/pull/129) merged normally. Signed tag `v6.5.10` resolves to reviewed release merge `4316f4ec`; npm - reports `@git-stunts/git-cas@6.5.10` as `latest` with publish and SLSA + retains `@git-stunts/git-cas@6.5.10` with publish and SLSA provenance, and release workflow `32782415971` published the final GitHub Release. The additive contract admits bounded asset waves into the compound scope and can retain exact selected terminal roots without changing stored diff --git a/docs/design/0062-mktree-transport-recovery/mktree-transport-recovery.md b/docs/design/0062-mktree-transport-recovery/mktree-transport-recovery.md index 5b73325..1c5d166 100644 --- a/docs/design/0062-mktree-transport-recovery/mktree-transport-recovery.md +++ b/docs/design/0062-mktree-transport-recovery/mktree-transport-recovery.md @@ -136,7 +136,7 @@ This dependency repair does not restore git-warp Runtime/Lane node/edge attachme ## Retrospective -Record after merge and publication, with PR and release receipts. +See the [post-release retrospective](../../method/retro/0062-mktree-transport-recovery/mktree-transport-recovery.md) and [publication witness](witness/release-publication.md). ## Data / State Model diff --git a/docs/design/0062-mktree-transport-recovery/witness/publication.json b/docs/design/0062-mktree-transport-recovery/witness/publication.json new file mode 100644 index 0000000..40fdbd7 --- /dev/null +++ b/docs/design/0062-mktree-transport-recovery/witness/publication.json @@ -0,0 +1,33 @@ +{ + "version": "6.5.11", + "sourceCommit": "1bcd6311e93ca9782e2f4a25af106af0651813fb", + "tag": "v6.5.11", + "tagObject": "a77ebbdff9b5e2bbce73f90e8d51a5d0cd71b98d", + "releaseRun": 37008258240, + "registry": { + "integrity": "sha512-C6coWmKmOeRZ+X5nP5Ek7spwYpA5q6mgif09u9dDO0ISQQ+Hz4KVxAXrOPRRhNJzLEP74Ndbra55fxX5Cms5gw==", + "shasum": "184c18fce40629afd28a897cbf3672cb4cc0d43e", + "tarball": "https://registry.npmjs.org/@git-stunts/git-cas/-/git-cas-6.5.11.tgz", + "attestations": { + "url": "https://registry.npmjs.org/-/npm/v1/attestations/@git-stunts%2fgit-cas@6.5.11", + "provenance": { + "predicateType": "https://slsa.dev/provenance/v1" + } + } + }, + "plumbingVersion": "3.3.2", + "releaseVerification": { + "stagesPassed": 14, + "stagesSkipped": 0, + "observedTests": 7224, + "rawLogSha256": "cdefc3ed121de8e861b984c31cf5ee48d73aea05eca0632d1de3972864e71e09" + }, + "publicConsumer": { + "recoveryTestsPassed": 6, + "storeRestore": "passed", + "cliVersion": "6.5.11+1bcd631", + "verifiedSignatures": 63, + "verifiedAttestations": 31, + "rawLogSha256": "42d7195c11774f9c2cc0aff0b55d72372383f30a24e98774548acb732c3c81c2" + } +} diff --git a/docs/design/0062-mktree-transport-recovery/witness/release-publication.md b/docs/design/0062-mktree-transport-recovery/witness/release-publication.md new file mode 100644 index 0000000..d588038 --- /dev/null +++ b/docs/design/0062-mktree-transport-recovery/witness/release-publication.md @@ -0,0 +1,21 @@ +# v6.5.11 publication witness + +PR [#132](https://github.com/git-stunts/git-cas/pull/132) merged as `1bcd6311e93ca9782e2f4a25af106af0651813fb`. Signed annotated tag `v6.5.11` has object `a77ebbdff9b5e2bbce73f90e8d51a5d0cd71b98d` and peels to that exact merge; its SSH signature was verified before push. [Release workflow 37008258240](https://github.com/git-stunts/git-cas/actions/runs/37008258240) completed successfully and created the [GitHub release](https://github.com/git-stunts/git-cas/releases/tag/v6.5.11). + +## Registry identity + +Npm reports `@git-stunts/git-cas@6.5.11` with gitHead `1bcd6311e93ca9782e2f4a25af106af0651813fb` and integrity `sha512-C6coWmKmOeRZ+X5nP5Ek7spwYpA5q6mgif09u9dDO0ISQQ+Hz4KVxAXrOPRRhNJzLEP74Ndbra55fxX5Cms5gw==`. The artifact requires published Plumbing `^3.3.2`. Initial cached metadata returned 404 after publication; fresh registry metadata and a subsequent clean installation established visibility. No tag or version was rewritten. + +## Merged-main verification + +All 14 canonical release gates passed inside COPY-based Docker, without host repository or Git mounts. Node and Bun each passed 2,204 unit tests with three existing skips; Deno passed 2,195 with twelve existing skips. Each runtime passed 207 integration tests. Three maintained examples, public types, lint, metadata stamping, npm pack and JSR dry-run passed. The 7,224 total counts observations across runtimes, not unique tests. JSR was validated but is not a publication target of this workflow. + +## Independent public consumer + +A new Docker image installed the exact npm versions of git-cas 6.5.11 and Plumbing 3.3.2, with no checkout dependencies, patches or host mounts. All six deterministic transport-recovery tests passed. The public store/restore example returned matching bytes and passed integrity verification; the installed CLI reported `6.5.11+1bcd631`. Npm verified 63 registry signatures and 31 attestations across this consumer installation, which includes Vitest as test tooling. Those counts are specific to this fixture, not a package dependency-count guarantee. + +## Limits and follow-through + +Synthetic transport failures establish bounded retries and error identity; they do not prove every concurrent external-GC race. Git-warp [#923](https://github.com/git-stunts/git-warp/issues/923) owns attachment/GC adoption and evidence. This release does not implement git-warp Runtime/Lane attachments or complete its bounded streaming issue. Deno dependency installation reported an ESLint9 deprecation warning; no warning-free validation claim is made. + +The [machine-readable receipt](publication.json) records immutable identities and raw-log SHA-256 digests. Historical preparation and candidate receipts retain their original source coordinates. diff --git a/docs/method/retro/0062-mktree-transport-recovery/mktree-transport-recovery.md b/docs/method/retro/0062-mktree-transport-recovery/mktree-transport-recovery.md new file mode 100644 index 0000000..d540bd9 --- /dev/null +++ b/docs/method/retro/0062-mktree-transport-recovery/mktree-transport-recovery.md @@ -0,0 +1,21 @@ +# Retro — 0062 Mktree transport recovery + +## Drift check + +The fix stayed at the owning dependency boundary: Plumbing classifies transport failures; CAS retains its existing one-retry immutable-object policy. No duplicate runtime patch, mutable-ref retry, stored format change or attachment API claim was introduced. + +## Shipped result + +PR #132 merged as `1bcd6311e93ca9782e2f4a25af106af0651813fb`. The signed v6.5.11 tag, npm artifact and successful release workflow agree on that commit. Full merged-main verification passed all 14 gates in Docker, followed by an independent public registry consumer. The publication witness records identities and proof limits. + +## What the audit caught + +The release gate caught the stale CLI version export. A separate self-audit found the legacy host BATS dispatcher and replaced it with direct Docker orchestration. Independent review identified a temporary validation Dockerfile in the JSR dry-run payload; removing that private harness input restored a clean payload. An approved review did not replace further scrutiny. + +## Remaining work and debt + +Git-warp #923 owns dependency adoption and real attachment/GC acceptance; #818 and #901 own bounded streams and public attachment capability. Synthetic fault recovery is not a claim about every GC interleaving. Deno installation emitted an ESLint9 deprecation warning; all lint and runtime checks still passed. Existing runtime-specific skips remain explicit in the release witness. + +## Next release process + +Advance the CLI version export alongside metadata, inspect every executable validation entry point, and keep generated validation Dockerfiles outside publishable source. Separate candidate evidence, publication evidence, and downstream capability evidence by immutable source coordinates. diff --git a/docs/releases/v6.5.11.md b/docs/releases/v6.5.11.md index 6572540..8872972 100644 --- a/docs/releases/v6.5.11.md +++ b/docs/releases/v6.5.11.md @@ -12,4 +12,4 @@ All tests and benchmarks require a physical Docker marker before test modules lo ## Evidence And Delivery -Issue [#131](https://github.com/git-stunts/git-cas/issues/131) and PR [#132](https://github.com/git-stunts/git-cas/pull/132) own delivery. [Preparatory evidence](../design/0062-mktree-transport-recovery/witness/preparation.md) pins candidate behavior separately from registry delivery. The six recovery checks fail in four cases against Plumbing 3.3.0 and pass against published Plumbing 3.3.2. Full release verification, merge, signed tag, npm publication and registry consumer evidence remain required; this candidate document claims no published 6.5.11 artifact. +Issue [#131](https://github.com/git-stunts/git-cas/issues/131) and PR [#132](https://github.com/git-stunts/git-cas/pull/132) own delivery. [Preparatory evidence](https://github.com/git-stunts/git-cas/blob/243592ce1b72865ce4f1fd552f504e9488780246/docs/design/0062-mktree-transport-recovery/witness/preparation.md) pins candidate behavior separately from registry delivery. The six recovery checks fail in four cases against Plumbing 3.3.0 and pass against published Plumbing 3.3.2. The reviewed merge passed all 14 release gates; signed tag, trusted npm/GitHub publication and independent public-consumer verification are recorded in the [publication witness](https://github.com/git-stunts/git-cas/pull/132). JSR dry-run passed; JSR publication is not part of the release workflow. diff --git a/test/unit/docs/package-docs.test.js b/test/unit/docs/package-docs.test.js index f0c35c3..6914cf3 100644 --- a/test/unit/docs/package-docs.test.js +++ b/test/unit/docs/package-docs.test.js @@ -106,6 +106,7 @@ function publicPackagedMarkdownFiles(files) { 'docs/releases/v6.5.8.md', 'docs/releases/v6.5.9.md', 'docs/releases/v6.5.10.md', + 'docs/releases/v6.5.11.md', 'docs/THREAT_MODEL.md', 'docs/WALKTHROUGH.md', ].filter((file) => files.has(file)); diff --git a/test/unit/docs/release-state.test.js b/test/unit/docs/release-state.test.js index 6e9ec7b..81d5111 100644 --- a/test/unit/docs/release-state.test.js +++ b/test/unit/docs/release-state.test.js @@ -474,7 +474,6 @@ function expectV6510CandidateEvidence(candidate, releaseNotes) { } function expectV6510PublishedEvidence(status, publication) { - expect(status).toContain('**Last tagged release:** `v6.5.10` (`2026-08-24`)'); expect(status).toContain('**v6.5.10 artifact posture**'); expect(status).toContain('4316f4ec'); expect(status).toContain('32782415971'); @@ -847,3 +846,17 @@ describe('historical v6 release evidence', () => { expect(releaseCard).not.toContain('Push the final pre-tag `main` commit'); }); }); + + +describe('current publication identity', () => { + it('distinguishes the latest published release from retained historical evidence', () => { + const status = read('STATUS.md'); + const receipt = JSON.parse(read('docs/design/0062-mktree-transport-recovery/witness/publication.json')); + expect(status).toContain(`**Last tagged release:** \`${receipt.tag}\``); + expect(receipt.version).toBe(JSON.parse(read('package.json')).version); + expect(receipt.sourceCommit).toBe('1bcd6311e93ca9782e2f4a25af106af0651813fb'); + expect(receipt.releaseVerification.stagesPassed).toBe(14); + expect(receipt.publicConsumer.cliVersion).toBe('6.5.11+1bcd631'); + expect(status).toContain('**v6.5.10 artifact posture**'); + }); +});