Skip to content

Close release lineage and proof boundary gaps - #82

Merged
iperev merged 2 commits into
mainfrom
fix/release-migration-lineage
Jul 31, 2026
Merged

Close release lineage and proof boundary gaps#82
iperev merged 2 commits into
mainfrom
fix/release-migration-lineage

Conversation

@iperev

@iperev iperev commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Establish the 0.2.0 release-history support baseline and enforce npm predecessor lineage for new and idempotent release candidates.
  • Close 30 formally validated admission, CLI, proof-binding, browser, workflow, and release-authority defects from the external audit and adversarial re-review cycles.
  • Keep four unproven hypotheses rejected: candidate-only route coverage, the explicit adapter JSON compatibility selector, proof-obligation structural operators as satisfaction verdicts, and deferred/waived structural records as exception effects.

Key Changes

  • Add a typed repository-owned npm registry evidence producer and require exact bilateral package identity and byte closure before publication metadata is promoted.
  • Make OSV source findings fail closed while preserving event-authority separation for provider uploads.
  • Centralize typed JSON, sorted text/path, SHA reference, secret-shaped path, Windows executable alias, trust-rank, and virtual witness-path admission.
  • Make descriptor-owned singleton, presence, mutual-exclusion, enum-domain, and value-dependent CLI constraints authoritative across runtime, generated help, and cli-contract.v2.json.
  • Strengthen Go witness anti-vacuity, exact critical selectors, delegation authority, coverage-universe uniqueness, retained-evidence reachability, and committed-object source gates.
  • Close browser authority, response-header, and served-byte-length contracts.
  • Synchronize requirements, bindings, witness plans, contract projections, documentation, and the 0.2.1 change record.

Audit Closure

  • Atomic ledger: 34 adjudicated rows, 30 fixed, 4 rejected with explicit owner-contract reasons.
  • Three independent final rechecks found no residual defects in their assigned scopes after the last fixes.
  • Reports and generated outputs remain evidence projections, not merge, publication, rollout, or production-readiness authority.

Verification

  • npm run check passed on the final working-tree bytes.
  • npm run check passed again on committed object 7cd4176f3c2cae6865fbec459f1c6431579dc882.
  • go test ./... passed.
  • go run ./internal/tools/commandcontractgen --check passed.
  • go run ./internal/tools/commandfamilygen --check passed.
  • git diff --check and staged diff checks passed.
  • sem diff --format markdown --no-cosmetics was reviewed for entity-level structural drift.

Non-Claims

This PR does not prove provider publication, registry ingestion, deployment, rollout, consumer adoption, or production readiness. GitHub checks on the final commit remain the remote closeout authority.

@iperev iperev changed the title Enforce release predecessor lineage Close release lineage and proof boundary gaps Jul 31, 2026
@iperev
iperev merged commit ceaff46 into main Jul 31, 2026
9 checks passed
@iperev
iperev deleted the fix/release-migration-lineage branch July 31, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant