Skip to content

Release: promote development to main for v0.2.0 - #336

Merged
jscott3201 merged 54 commits into
mainfrom
development
Oct 6, 2026
Merged

jscott3201 merged 54 commits into
mainfrom
development

Conversation

@jscott3201

Copy link
Copy Markdown
Owner

Promotes development to main for v0.2.0 (CONTRIBUTING release checklist, step 2). Merge with a merge commit, never squash.

Release checklist

What 0.2.0 carries: stabilized state-continuation and portability contracts, canonical exact replay records, a published compatibility manifest, a refreshed native strict-bit receipt, GitHub Actions as primary CI (pr-gate and release-gate), and the M0-05 library rule-state continuation proof. Full list: CHANGELOG.md § 0.2.0.

🤖 Generated with Claude Code

https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ


Generated by Claude Code

jscott3201 and others added 30 commits August 15, 2026 02:36
* docs(api): define Pre host-tick profile

* docs: link execution profile

* fix(conformance): scope Pre profile evidence

* docs(conformance): qualify G36 reference source

* docs: align verification layer count

* docs(conformance): qualify generator evidence

* docs(conformance): qualify reference fields

* docs(conformance): generalize exact comparator
Recover missing changelog records for #288, #296, #300, and #301, and correct the seven-recovery history before promotion.

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>
Pin active-leaf parameter grounding under cross-sibling activity marking for both ordinary hasParameter and classified hasInstance routes. Add exact goldens, byte-identical dialect parity, public contract corrections, changelog coverage, and a recomputed corpus census.

Closes #252.

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>
* test(cxf): preserve member control cardinality

Replace the confounded Ramp pair with six-member Sin twins that differ only by one node-less member name. Pin the exact source relation, resolver golden, and API diagnostics.

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* docs: record count-preserving member control

Record PR #304 in the unreleased CXF history and state the exact source-pair evidence for the unclassifiable-member refusal.

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(cxf): pin node-less member shape

Expand document prefixes before inspecting graph identities and require each Sin control twin to retain exactly five node-bearing members. This catches compact-IRI nodes that would reintroduce the node-presence confound while preserving raw source equality.

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(cxf): expand whole-token member aliases

Match the resolver's whole-token context substitution before compact-IRI expansion so an aliased graph node cannot bypass the node-less fixture guard.

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(cxf): mirror context identity precedence

Accept inline context maps and ordered map lists, preserve scheme-slash absolute IRIs, and use the same expansion for owner lookup and graph-node shape. This closes the remaining alias escape in the control proof.

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

---------

Co-authored-by: OpenAI GPT-5.6 Sol <noreply@openai.com>
* test(conformance): add Line evidence generator

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): support hosted Docker image metadata

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): retain Line differential evidence

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): close Line evidence provenance

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): refresh Line native evidence

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): complete Line native input closure

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): retain complete Line provenance

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): close Line source and toolchain records

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): retain Line native run semantics

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): refresh closed Line evidence

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(cxf): close Line flag control endpoint

Pin the retained flag-control value at both above-range rows so the final endpoint cannot drift behind the mismatch-index assertion.

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): execute Line projection control

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): retain Line keep-first evidence

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

---------

Co-authored-by: OpenAI GPT-5.6 Sol <noreply@openai.com>
…308)

* test(conformance): prepare Reliefs native evidence

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): invoke Reliefs runner through shell

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): exclude projection source metadata

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): validate Reliefs evidence closure

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): retain Reliefs OpenModelica evidence

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): close Reliefs generation provenance

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* ci(conformance): transport corrected Reliefs candidates

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): ratify corrected Reliefs evidence

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* ci: preserve generation ancestry in gate checkouts

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): close Reliefs retained evidence validation

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): pin Reliefs clamp control inputs

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* test(conformance): ratify closed Reliefs evidence

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

* fix(conformance): satisfy closed-log lint

Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>

---------

Co-authored-by: OpenAI GPT-5.6 Sol <noreply@openai.com>
* docs: capture stability baseline and pin ledger

* fix(tools): require Python 3.11 for baseline verifier

* docs: include stability baseline in mdBook navigation

* chore: retrigger pull request checks
Add a tracked public-surface contract and exhaustive machine-checked ledger for oce-api and oce-store. Reconcile issue #254 without changing runtime behavior or signatures, and add hostile drift, external-adapter, evidence-anchor, and published-doc controls.
* docs: define package and publication policy

* fix(ci): harden package publication guards

* fix(ci): scope release workflow authorization guards

* fix(ci): parse release workflow structure fail closed

* fix(ci): pin approved release workflow bytes
* feat(docs): enforce authority claim and supersession consistency

* fix(docs): keep authority literals inert through site rendering
* refactor(api): remove deferred facade surfaces

* fix(docs): correct removed facade claims in README
Co-authored-by: GPT-6 Astra <noreply@openai.com>
* docs: ratify complete generation-atomic frame contract

* fix(docs): include frame contract in book
Expose bounded typed catalog/export identities and a canonical public-fact compatibility receipt while retaining executable, generation, and state-wire identities as private later-work concerns.
* test(conformance): add strict-bit evidence matrix

* test(conformance): retain native Linux strict-bit qualification

* test(conformance): bind strict-bit checker provenance

* test(conformance): admit checker-complete Linux evidence

* docs(conformance): narrow retained source integrity claim
)

* feat(api)!: stabilize state continuation contract

* fix(docs): include state contract in book
* feat(api): add canonical exact replay records

* fix(docs): include replay record in book
* test(compatibility): retain fail-closed candidate evidence

* test(compatibility): bind enforcement sources to evidence
Forgejo becomes the primary host and runs CI; the GitHub repository is a
public push mirror with Actions disabled.

- .forgejo/workflows/ci.yml: Linux port of the per-PR gate into
  development. The aarch64 legs of the determinism and strict-bit
  matrices are cross-compiled and run under QEMU user-mode emulation in
  the same x86_64 job, so the cross-architecture byte comparisons keep
  running without artifact hand-off. A final `CI OK` job aggregates every
  gating job for branch protection.
- release-gate.yml and advisories.yml move to .forgejo/workflows, with
  their own `CI OK` aggregate on the release gate.
- docs-pages: PR validation moves to Forgejo; the GitHub Pages publish
  stays on GitHub as a manual-only workflow.
- .github/workflows/ci.yml stays byte-identical and dormant: it is a
  bound source of the retained native strict-bit evidence, as are
  .config/nextest.toml and .agents/gate.sh, so none of them change. The
  emulated legs use scripts/ci/nextest-emulated.toml instead.
- check-workflow-gates.sh now checks the Forgejo workflows; its fixtures
  follow the new topology.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Forgejo `origin` is primary for branches, PRs and CI; GitHub is the
public push mirror (never pushed to directly) and the public issue
tracker, synced with Forgejo. Update the agent guide, contributor
guide, project facts, testing standard and CI/evidence docs to point at
.forgejo/workflows, the `CI OK` required status, the emulated aarch64
legs, and the files bound to the retained strict-bit evidence. Replace
`gh pr` release-checklist steps with a host-neutral git log comparison.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
jscott3201 and others added 23 commits September 29, 2026 15:55
The live runner labels now live in .forgejo/workflows/ci.yml; the
.github copy is a dormant, byte-frozen strict-bit source. Admit the
`.forgejo` root in the closed path schema and regenerate the projection.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- CI OK in ci.yml and release-gate.yml now accepts only `success`; no
  gating job has a job-level `if:`, so a skip is never legitimate. The
  hard-coded job counts are replaced by a static check.
- check-workflow-gates.sh asserts that each CI OK `needs:` equals the
  workflow's other top-level jobs and that no gating job carries a
  job-level `if:`, and pins the emulated aarch64 release-codegen
  determinism leg and strict-bit cells. New fixtures prove an omitted
  need, a conditional gating job and a dropped cell all fail.
- Drop the best-effort strict-bit upload-artifact step; Forgejo artifact
  v4 support is unverified and the step could not fail the job anyway.
- Drop the stale paths-filter contrast from the release-gate header.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Per-PR hosted cells are x86_64 native and aarch64 QEMU-emulated and run
on every PR, not "native" cells on non-draft PRs. State that CI does not
retain strict-bit captures, that Forgejo PR runs test the PR head, and
that docs-pages validation is path-filtered and outside CI OK.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Move every workspace member and the internal path+version dependency
table from 0.1.0 to 0.2.0, and refresh Cargo.lock for the 17 members.

The compatibility descriptor carries `oce-api-version` from
CARGO_PKG_VERSION, so the hand-assembled descriptor goldens
(compatibility.txt, compatibility_export.txt and the doctest) now read
0.2.0, and the replay goldens that embed that descriptor follow. The
mutation controls that derive hostile versions from the current string
(compatibility_tests.rs, replay_codec.rs) keep the same shapes against
the new version. No behaviour, catalog, schema, state, or replay format
revision changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
The release-compatibility checker binds the live implementation boundary
to one reviewed baseline. The version bump changes that boundary (root
manifest, lockfile and the descriptor doctest), so re-select it at
3a7bdf0: 326 files, sha256 dc0eda90...8c04. The matrix is regenerated
from `check.py --candidate`; only the baseline identity, the current
package and descriptor version (0.2.0), and the digests of the three
evidence files the bump touched change. The 36 directed rows, the
fail-closed/no-N-1 policy, the historical v0.1.0 receipt and its digest
are unchanged, and `--verify-history` still passes.

test_check.py now expects current package 0.2.0 against historical
0.1.0. The prose drops the "both package strings are 0.1.0" claim,
which the bump makes false, while keeping the point it illustrated.

If this branch is squash-merged, re-point BASELINE (and the matrix) at
the squash commit so `--verify-history` can resolve it; the ordinary
check does not depend on the commit being reachable.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Add docs/compatibility-manifest.json, the artifact to attach to a tagged
release, and its owner test crates/oce-api/tests/compatibility_manifest.rs.
It records, for the tagged source:

- the canonical CompatibilityDescriptor text and its ten fields;
- each contract domain's schema revision and an FNV-1a-128 tag over the
  packaged schema bytes (after checking the packaged file is the served
  one);
- the CXF import contract, MAX_CXF_BYTES, the vendored Modelica Buildings
  and modelica-json commits, the composite rule ids, the cxf:fnv1a128
  content-id scheme and the catalog content id;
- the content id of each complete export in the 47-document swept G36
  corpus (34), and the byte tag plus deferral-warning count of each
  incomplete one (13), from a live load-and-export;
- the state and replay format revisions and the selected
  release-compatibility baseline, read from the matrix after checking
  its descriptor equals the live one.

The test renders twice for determinism and compares the checked-in file
byte-for-byte; OCE_BLESS=1 regenerates it, following the existing
export-content-oracle convention. Every corpus entry agrees with
crates/oce-cxf/tests/fixtures/expectations/g36_export_content.txt.
The manifest is descriptive: it grants nothing beyond the
release-compatibility policy, and its FNV tags are not signatures.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Move every Unreleased entry under a 0.2.0 section and leave an empty
Unreleased above it. The header no longer says nothing has been
released: releases are git tags, v0.1.0 was a pre-changelog git pin,
and nothing is on crates.io.

Currency, checked the way the header prescribes: of the PR numbers in
`git log origin/main..origin/development`, 22 were absent (#308-#331;
#311 and #312 were superseded and never merged). Each now has an entry
written from its merged PR description:

- Host facade: complete frames (#321, #322, #323), catalog and
  diagnostic receipt contracts (#317), bounded CXF admission (#318),
  the compatibility descriptor (#326), state continuation (#328) and
  replay records (#329).
- Facade contraction: the existing frame-only and source-break entries
  now cite #325 and #316.
- Verification: strict-bit evidence (#327), release-compatibility
  evidence (#330), composition ordering identity (#331), integer golden
  domain (#324); the Reliefs entry cites its PR #308 beside issue #307.
- Documentation and tooling: product contract (#315, #320), public
  surface, package and authority policies (#310, #313, #314), the
  stability baseline (#309) and agent guidance (#319).

A Release subsection records this preparation: the 0.2.0 bump, the
compatibility manifest, the re-selected compatibility baseline, and the
strict-bit receipt refresh the bump requires.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Drive two unedited open-control-library fault rules through the durable
restart path a host uses: state_snapshot, a host-envelope approval
stand-in, EngineStateSnapshot::from_bytes, a freshly loaded engine and
restore_state inside the startup window.

- AHU-0016: Logical.TrueDelay persistence timer (900 s).
- AHU-0004: Integers.Change, a 3600 s Reals.MovingAverage window and a
  3600 s Logical.TrueDelay.

Across all 16 Library scenarios, a restart after load and after every
tick, and a chained restart after every tick, reproduce the uninterrupted
run bit for bit: boundary and internal outputs and canonical state bytes.
Named mid-dwell and mid-window restarts are paired with cold-start
divergence controls, the uninterrupted run meets every Library
expectation window, and advanced or foreign targets refuse with typed
errors and no mutation. No engine behavior changes.

The CXF graphs and vectors are byte copies from Library commit d90f63b
with provenance, hashes and license recorded in the fixture README. The
state contract doc gains a short section on the result and on restore
continuing model time across an outage, which is host frame policy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Forgejo already used #332, so GitHub PR numbers are marked explicitly.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Forgejo is retired and its push mirror to GitHub is off, so GitHub is
the primary host again for code, PRs, issues and CI. The Forgejo
workflows only ran there, so they move to .github/workflows and
.forgejo/workflows is deleted.

- pr-gate.yml: the per-PR light gate (ported from the Forgejo ci.yml),
  on PRs into and pushes to development, ending in the single `CI OK`
  aggregate. The aarch64 determinism and strict-bit legs stay under
  QEMU emulation in the x86_64 job; apt now runs via sudo on hosted
  runners.
- release-gate.yml and advisories.yml move back from .forgejo; the
  release gate also runs on pushes to main and keeps its own `CI OK`.
- docs-pages.yml validates docs PRs/pushes again and deploys main to
  Pages on push or dispatch.
- Actions in these workflows are pinned to commit SHAs, checkouts do
  not persist the token, and every workflow declares
  `contents: read`. check-workflow-gates.sh now reads
  .github/workflows/pr-gate.yml and refuses a tag-referenced action in
  the gating workflows, with a new hostile fixture.
- .github/workflows/ci.yml stays byte-identical: it is a bound source
  of the retained native strict-bit evidence, so editing it would turn
  the retained-evidence test red until a new native receipt is
  admitted. It is to be disabled in the Actions settings instead.
  release.yml and the OpenModelica evidence workflows are byte-bound by
  their own approvals and are left unchanged.
- The authority-claims platforms verifier rebinds to pr-gate.yml.
- Agent, contributor, testing and CI docs describe GitHub as primary
  and record the PR-number convention: GitHub PRs are cited as
  `(GitHub #N)` because GitHub numbers collide with Forgejo's.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
ci: make GitHub Actions the primary CI and retire Forgejo
Brings in GitHub #334 (GitHub Actions primary, Forgejo retired). The 0.2.0
changelog keeps the recovered #308-#331 entries and gains the #334 entry
and the (Forgejo #332) citation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
The workspace 0.2.0 version bump changed the Cargo.toml and Cargo.lock
bytes that the retained native strict-bit evidence binds, so the retained
qualification test refused with "source digest changed: Cargo.lock".

ci.yml run 37382761120 on head f8dcaeb (synthetic merge fbae3b9) captured
all four native Linux cells (x86_64 and ubuntu-24.04-arm, debug and
release): 21 signals, 161 samples per run, byte-identical repeats and a
zero-mismatch cross-cell comparison. Every cell failed only the receipt
check, as the documented collection run does.

Admission is data-only: receipts.json.current now pins the merge checkout
and the strict-bits-matrix digest, the previous qualified-linux/ captures
(run 35494403523) were removed and the downloaded captures admitted
through the ignored admission test. The release-compatibility matrix's
receipts.json evidence digest follows. No bound source changed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
test(api): prove durable state continuation over Library fault rules
Brings in GitHub #332 (Library-rule state continuation test and docs).
Its CHANGELOG entry joins the 0.2.0 Verification section; none of the
35 strict-bit bound sources change, so the admitted receipt stands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
chore(release): prepare v0.2.0 with a compatibility manifest
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Brings the five earlier promotion merge commits (#220, #223, #265, #289, #297)
into development so the promotion PR is up to date with main, as the new
branch rule requires. No content change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
…pment

Merge main into development before the v0.2.0 promotion
@jscott3201
jscott3201 merged commit 4063202 into main Oct 6, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants