Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/ISSUE_TEMPLATE/install-failure.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ body:
Simulator Broker is **Alpha**, **macOS-only**, and needs **Xcode** to
create or run iOS Simulators. Install the CLI with
`brew install fiveonecode/simulator-broker/simbroker` or
`npm install -g` of the `simbroker-0.1.0-alpha.4.tgz` from GitHub
`npm install -g` of the `simbroker-0.1.0-alpha.5.tgz` from GitHub
Releases. Install the operator app with
`brew install --cask fiveonecode/simulator-broker/simulator-broker`.

Expand All @@ -23,7 +23,7 @@ body:
label: What install path did you use?
options:
- Homebrew (`brew install fiveonecode/simulator-broker/simbroker`)
- npm (`npm install -g` of `simbroker-0.1.0-alpha.4.tgz` from GitHub Releases)
- npm (`npm install -g` of `simbroker-0.1.0-alpha.5.tgz` from GitHub Releases)
- Homebrew cask (`brew install --cask fiveonecode/simulator-broker/simulator-broker`)
- CLI-only (`bash scripts/install_local.sh --cli-only`)
- Contributor app + CLI (`npm run install:local`)
Expand Down
29 changes: 29 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,37 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.1.0-alpha.5] - 2026-09-01

Alpha 5 is the provenance-safe recovery release for the immutable failed
Alpha 4 tag. It keeps the same four-custom-asset contract and rebuilds every
asset from the corrected source tree.

### Fixed

- RR19 distinguishes a documented hosted-runner path from a private
runtime-home leak while retaining positive and negative public-source
regression coverage.
- RR20 packages the CLI README as literal data, so Markdown command examples
cannot execute or capture checkout-root output during archive creation.
- RR21 generates the app dSYM before stripping deployment debug records, then
rejects build paths, STABS, embedded DWARF, unexpected architectures, and
leaks in the complete Mach-O container or either required slice.
- RR22 makes CLI packaging emit portable raw USTAR with normalized ownership,
safe paths and modes, no AppleDouble or PAX metadata, and stale-output
cleanup, with the same contract exercised on macOS and Ubuntu.
- RR23 gives cask ZIP packaging explicit metadata-suppression flags and a
validated hidden candidate, rejecting AppleDouble, unsafe or extra roots,
unsupported entry types, and stale public outputs before final publication.

## [0.1.0-alpha.4] - 2026-08-31

The `v0.1.0-alpha.4` tag is preserved as immutable failed-release evidence.
Its workflow stopped before creating a GitHub Release or uploading any custom
asset because the public-source check treated a documented hosted-runner path
as a private home-path leak. The tag must not be republished; Alpha 5
supersedes it.

This release hardens the public install, upgrade, and dashboard paths used for
the first broader Simulator Broker announcement. It also makes the complete
GitHub Release inventory explicit: CLI archive, CLI checksum, npm tarball, and
Expand Down
4 changes: 2 additions & 2 deletions Casks/simulator-broker.rb
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
cask "simulator-broker" do
version "0.1.0-alpha.4"
sha256 "d44c4ba8318338c5e009ed2e71aa6fea03e6167698a4a60df7ce5b865f5e3963"
version "0.1.0-alpha.5"
sha256 "4fcad6743f4a4d6e8cf3fe427d43814c2e4348e9709bbe264a7d275bb252c30a"

url "https://github.com/fiveonecode/simulator-broker/releases/download/v#{version}/Simulator-Broker-#{version}.zip"
name "Simulator Broker"
Expand Down
4 changes: 2 additions & 2 deletions Formula/simbroker.rb
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
class Simbroker < Formula
desc "Local iOS Simulator control plane CLI"
homepage "https://github.com/fiveonecode/simulator-broker"
url "https://github.com/fiveonecode/simulator-broker/releases/download/v0.1.0-alpha.4/simulator-broker-0.1.0-alpha.4-cli.tar.gz"
sha256 "1e04e4e9f7c0b372722b80e057b63dda87e12d7d5cbf7043d084826f0ea57503"
url "https://github.com/fiveonecode/simulator-broker/releases/download/v0.1.0-alpha.5/simulator-broker-0.1.0-alpha.5-cli.tar.gz"
sha256 "429c6477ff3a85f90a660693bda5527963a89942a8e8052eee31086a5ecc3ddd"
license "MIT"

depends_on macos: :sonoma
Expand Down
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -79,7 +79,7 @@ simbroker idle enable --grace-seconds <60-86400> --actor-type human --actor-id <
Other CLI install options:

```bash
npm install -g https://github.com/fiveonecode/simulator-broker/releases/download/v0.1.0-alpha.4/simbroker-0.1.0-alpha.4.tgz
npm install -g https://github.com/fiveonecode/simulator-broker/releases/download/v0.1.0-alpha.5/simbroker-0.1.0-alpha.5.tgz
simbroker --help
```

Expand All @@ -102,8 +102,8 @@ are also attached to those releases. The archive contains a versioned top-level
directory:

```bash
tar -xzf simulator-broker-0.1.0-alpha.4-cli.tar.gz
./simulator-broker-0.1.0-alpha.4-cli/bin/simbroker --help
tar -xzf simulator-broker-0.1.0-alpha.5-cli.tar.gz
./simulator-broker-0.1.0-alpha.5-cli/bin/simbroker --help
```

`simbroker` help and `simbroker doctor` print human-readable text by default.
Expand Down
10 changes: 5 additions & 5 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,13 +3,13 @@
## Supported Versions

Security fixes are considered for the current `main` branch and for the latest
tagged Alpha (`0.1.0-alpha.4`). Older Alpha tags are not supported. The
tagged Alpha (`0.1.0-alpha.5`). Older Alpha tags are not supported. The
published Alpha has exactly four custom GitHub Release assets:

1. `simulator-broker-0.1.0-alpha.4-cli.tar.gz`
2. `simulator-broker-0.1.0-alpha.4-cli.tar.gz.sha256`
3. `simbroker-0.1.0-alpha.4.tgz`
4. `Simulator-Broker-0.1.0-alpha.4.zip`
1. `simulator-broker-0.1.0-alpha.5-cli.tar.gz`
2. `simulator-broker-0.1.0-alpha.5-cli.tar.gz.sha256`
3. `simbroker-0.1.0-alpha.5.tgz`
4. `Simulator-Broker-0.1.0-alpha.5.zip`

The Homebrew formula and cask install the matching CLI and signed, notarized
app archives. GitHub's generated source archives appear separately.
Expand Down
6 changes: 3 additions & 3 deletions docs/getting-started.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ does not require XcodeGen. The app still needs the CLI installed separately.
## Install the CLI with npm

```bash
npm install -g https://github.com/fiveonecode/simulator-broker/releases/download/v0.1.0-alpha.4/simbroker-0.1.0-alpha.4.tgz
npm install -g https://github.com/fiveonecode/simulator-broker/releases/download/v0.1.0-alpha.5/simbroker-0.1.0-alpha.5.tgz
command -v simbroker
simbroker --help
```
Expand All @@ -76,8 +76,8 @@ To install from a tagged Alpha without cloning, download
then run:

```bash
tar -xzf simulator-broker-0.1.0-alpha.4-cli.tar.gz
./simulator-broker-0.1.0-alpha.4-cli/bin/simbroker --help
tar -xzf simulator-broker-0.1.0-alpha.5-cli.tar.gz
./simulator-broker-0.1.0-alpha.5-cli/bin/simbroker --help
```

The archive is the Node CLI only and contains that versioned top-level
Expand Down
4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@
"test:package-smoke": "bash ./scripts/package_smoke.sh",
"verify:public-surface": "node client/public-surface.mjs"
},
"version": "0.1.0-alpha.4",
"version": "0.1.0-alpha.5",
Comment thread
VladimirBrejcha marked this conversation as resolved.
Comment thread
VladimirBrejcha marked this conversation as resolved.
"description": "Local simulator broker and macOS operator app for coordinated iOS Simulator workflows",
"license": "MIT",
"repository": {
Expand Down
2 changes: 1 addition & 1 deletion packages/simbroker/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Alpha CLI for Simulator Broker. Node.js 20 or newer is required. Creating and
running iOS Simulators still requires macOS and Xcode.

```bash
npm install -g https://github.com/fiveonecode/simulator-broker/releases/download/v0.1.0-alpha.4/simbroker-0.1.0-alpha.4.tgz
npm install -g https://github.com/fiveonecode/simulator-broker/releases/download/v0.1.0-alpha.5/simbroker-0.1.0-alpha.5.tgz
simbroker --help
```

Expand Down
2 changes: 1 addition & 1 deletion packages/simbroker/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "simbroker",
"version": "0.1.0-alpha.4",
"version": "0.1.0-alpha.5",
"private": false,
"description": "CLI for the local iOS Simulator control plane",
"license": "MIT",
Expand Down
2 changes: 1 addition & 1 deletion spec/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ This repo exists to develop a reusable local simulator broker:
- local install, local-debug portable packaging, Release distribution packaging, and onboarding flows now exist through `install_local.sh`, `install_local.sh --cli-only`, `package_local.sh`, `package_distribution.sh`, `test:install-smoke`, `test:package-smoke`, `host init --bootstrap-config`, and `project init`
- the published onboarding docs now distinguish CLI-only install, repo-local contributor app+CLI install, local-debug portable bundling, and signed distribution packaging; a new login shell should resolve `simbroker` after install without sourcing `env.sh`
- `CONTRIBUTING.md` publishes a public-patch track (Node.js 20 and the Node test suites, no harness session) and a labeled maintainer/agent harness track; `agent:complete` enforcement is unchanged
- tagged Alpha `0.1.0-alpha.4` publishes exactly four custom GitHub Release assets: a CLI tarball from `scripts/package_cli.sh`, its SHA-256 checksum, the packable npm CLI, and a notarized operator app zip. The tag workflow runs the public docs, public-surface, broker-core, client, and harness-adoption checks on GitHub-hosted Ubuntu before attaching the first three assets; the operator attaches the app zip after Developer ID signing and notarization. GitHub's generated source archives are not custom assets. Public pull-request CI remains split between Ubuntu and macOS, while the macOS app suite and home-path public-surface scan stay local.
- tagged Alpha `0.1.0-alpha.5` publishes exactly four custom GitHub Release assets: a CLI tarball from `scripts/package_cli.sh`, its SHA-256 checksum, the packable npm CLI, and a notarized operator app zip. The tag workflow runs the public docs, public-surface, broker-core, client, and harness-adoption checks on GitHub-hosted Ubuntu before attaching the first three assets; the operator attaches the app zip after Developer ID signing and notarization. GitHub's generated source archives are not custom assets. Public pull-request CI remains split between Ubuntu and macOS, while the macOS app suite and home-path public-surface scan stay local.
- public pull-request CI and the tagged-release workflow run `npm run test:docs`
so archive paths, install guidance, and workflow gates cannot drift without a
failing check
Expand Down
7 changes: 4 additions & 3 deletions spec/build-and-test.md
Original file line number Diff line number Diff line change
Expand Up @@ -159,7 +159,7 @@ A first extracted implementation slice now exists:
fixtures inject `processController.currentPid` so hardcoded fixture
PIDs cannot match the GitHub Actions test-runner pid. Containment still
skips the live `process.pid` when `currentPid` is omitted.
- tagged versions such as `v0.1.0-alpha.4` attach exactly four custom assets
- tagged versions such as `v0.1.0-alpha.5` attach exactly four custom assets
to a GitHub Release: the CLI tarball, its `.sha256` checksum, the packable
`simbroker-<version>.tgz`, and the notarized
`Simulator-Broker-<version>.zip`. GitHub-generated source archives are not
Expand Down Expand Up @@ -253,8 +253,9 @@ not reinstall a live machine.

1. Bump `package.json` / lock / `packages/simbroker`, `CHANGELOG.md`,
newcomer docs, `Formula/simbroker.rb` URL, and
`Casks/simulator-broker.rb` version. Leave the cask `sha256` on the
previous zip until the new zip exists.
`Casks/simulator-broker.rb` version. Replace both Homebrew checksums with
an explicit 64-zero prebuild placeholder so stale prior-release bytes
cannot appear pinned to the new version.
2. Run `npm run agent:verify -- --profile spec-only` for the changed
paths.
3. Run `npm run package:cli` and `npm run package:npm`. Pin
Expand Down