Repository navigation
Release: promote development to main for v0.2.0 - #336
Merged
Merged
Conversation
* docs(api): define Pre host-tick profile * docs: link execution profile * fix(conformance): scope Pre profile evidence * docs(conformance): qualify G36 reference source * docs: align verification layer count * docs(conformance): qualify generator evidence * docs(conformance): qualify reference fields * docs(conformance): generalize exact comparator
Pin active-leaf parameter grounding under cross-sibling activity marking for both ordinary hasParameter and classified hasInstance routes. Add exact goldens, byte-identical dialect parity, public contract corrections, changelog coverage, and a recomputed corpus census. Closes #252. Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com>
* test(cxf): preserve member control cardinality Replace the confounded Ramp pair with six-member Sin twins that differ only by one node-less member name. Pin the exact source relation, resolver golden, and API diagnostics. Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * docs: record count-preserving member control Record PR #304 in the unreleased CXF history and state the exact source-pair evidence for the unclassifiable-member refusal. Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(cxf): pin node-less member shape Expand document prefixes before inspecting graph identities and require each Sin control twin to retain exactly five node-bearing members. This catches compact-IRI nodes that would reintroduce the node-presence confound while preserving raw source equality. Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(cxf): expand whole-token member aliases Match the resolver's whole-token context substitution before compact-IRI expansion so an aliased graph node cannot bypass the node-less fixture guard. Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(cxf): mirror context identity precedence Accept inline context maps and ordered map lists, preserve scheme-slash absolute IRIs, and use the same expansion for owner lookup and graph-node shape. This closes the remaining alias escape in the control proof. Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> --------- Co-authored-by: OpenAI GPT-5.6 Sol <noreply@openai.com>
* test(conformance): add Line evidence generator Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): support hosted Docker image metadata Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): retain Line differential evidence Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): close Line evidence provenance Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): refresh Line native evidence Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): complete Line native input closure Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): retain complete Line provenance Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): close Line source and toolchain records Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): retain Line native run semantics Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): refresh closed Line evidence Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(cxf): close Line flag control endpoint Pin the retained flag-control value at both above-range rows so the final endpoint cannot drift behind the mismatch-index assertion. Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): execute Line projection control Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): retain Line keep-first evidence Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> --------- Co-authored-by: OpenAI GPT-5.6 Sol <noreply@openai.com>
…308) * test(conformance): prepare Reliefs native evidence Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): invoke Reliefs runner through shell Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): exclude projection source metadata Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): validate Reliefs evidence closure Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): retain Reliefs OpenModelica evidence Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): close Reliefs generation provenance Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * ci(conformance): transport corrected Reliefs candidates Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): ratify corrected Reliefs evidence Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * ci: preserve generation ancestry in gate checkouts Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): close Reliefs retained evidence validation Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): pin Reliefs clamp control inputs Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * test(conformance): ratify closed Reliefs evidence Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> * fix(conformance): satisfy closed-log lint Co-Authored-By: OpenAI GPT-5.6 Sol <noreply@openai.com> --------- Co-authored-by: OpenAI GPT-5.6 Sol <noreply@openai.com>
* docs: capture stability baseline and pin ledger * fix(tools): require Python 3.11 for baseline verifier * docs: include stability baseline in mdBook navigation * chore: retrigger pull request checks
Add a tracked public-surface contract and exhaustive machine-checked ledger for oce-api and oce-store. Reconcile issue #254 without changing runtime behavior or signatures, and add hostile drift, external-adapter, evidence-anchor, and published-doc controls.
* docs: define package and publication policy * fix(ci): harden package publication guards * fix(ci): scope release workflow authorization guards * fix(ci): parse release workflow structure fail closed * fix(ci): pin approved release workflow bytes
* feat(docs): enforce authority claim and supersession consistency * fix(docs): keep authority literals inert through site rendering
* refactor(api): remove deferred facade surfaces * fix(docs): correct removed facade claims in README
Co-authored-by: GPT-6 Astra <noreply@openai.com>
* docs: ratify complete generation-atomic frame contract * fix(docs): include frame contract in book
Expose bounded typed catalog/export identities and a canonical public-fact compatibility receipt while retaining executable, generation, and state-wire identities as private later-work concerns.
* test(conformance): add strict-bit evidence matrix * test(conformance): retain native Linux strict-bit qualification * test(conformance): bind strict-bit checker provenance * test(conformance): admit checker-complete Linux evidence * docs(conformance): narrow retained source integrity claim
* feat(api): add canonical exact replay records * fix(docs): include replay record in book
* test(compatibility): retain fail-closed candidate evidence * test(compatibility): bind enforcement sources to evidence
Forgejo becomes the primary host and runs CI; the GitHub repository is a public push mirror with Actions disabled. - .forgejo/workflows/ci.yml: Linux port of the per-PR gate into development. The aarch64 legs of the determinism and strict-bit matrices are cross-compiled and run under QEMU user-mode emulation in the same x86_64 job, so the cross-architecture byte comparisons keep running without artifact hand-off. A final `CI OK` job aggregates every gating job for branch protection. - release-gate.yml and advisories.yml move to .forgejo/workflows, with their own `CI OK` aggregate on the release gate. - docs-pages: PR validation moves to Forgejo; the GitHub Pages publish stays on GitHub as a manual-only workflow. - .github/workflows/ci.yml stays byte-identical and dormant: it is a bound source of the retained native strict-bit evidence, as are .config/nextest.toml and .agents/gate.sh, so none of them change. The emulated legs use scripts/ci/nextest-emulated.toml instead. - check-workflow-gates.sh now checks the Forgejo workflows; its fixtures follow the new topology. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Forgejo `origin` is primary for branches, PRs and CI; GitHub is the public push mirror (never pushed to directly) and the public issue tracker, synced with Forgejo. Update the agent guide, contributor guide, project facts, testing standard and CI/evidence docs to point at .forgejo/workflows, the `CI OK` required status, the emulated aarch64 legs, and the files bound to the retained strict-bit evidence. Replace `gh pr` release-checklist steps with a host-neutral git log comparison. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The live runner labels now live in .forgejo/workflows/ci.yml; the .github copy is a dormant, byte-frozen strict-bit source. Admit the `.forgejo` root in the closed path schema and regenerate the projection. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- CI OK in ci.yml and release-gate.yml now accepts only `success`; no gating job has a job-level `if:`, so a skip is never legitimate. The hard-coded job counts are replaced by a static check. - check-workflow-gates.sh asserts that each CI OK `needs:` equals the workflow's other top-level jobs and that no gating job carries a job-level `if:`, and pins the emulated aarch64 release-codegen determinism leg and strict-bit cells. New fixtures prove an omitted need, a conditional gating job and a dropped cell all fail. - Drop the best-effort strict-bit upload-artifact step; Forgejo artifact v4 support is unverified and the step could not fail the job anyway. - Drop the stale paths-filter contrast from the release-gate header. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Per-PR hosted cells are x86_64 native and aarch64 QEMU-emulated and run on every PR, not "native" cells on non-draft PRs. State that CI does not retain strict-bit captures, that Forgejo PR runs test the PR head, and that docs-pages validation is path-filtered and outside CI OK. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…from ci/forgejo-actions into development
Move every workspace member and the internal path+version dependency table from 0.1.0 to 0.2.0, and refresh Cargo.lock for the 17 members. The compatibility descriptor carries `oce-api-version` from CARGO_PKG_VERSION, so the hand-assembled descriptor goldens (compatibility.txt, compatibility_export.txt and the doctest) now read 0.2.0, and the replay goldens that embed that descriptor follow. The mutation controls that derive hostile versions from the current string (compatibility_tests.rs, replay_codec.rs) keep the same shapes against the new version. No behaviour, catalog, schema, state, or replay format revision changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
The release-compatibility checker binds the live implementation boundary to one reviewed baseline. The version bump changes that boundary (root manifest, lockfile and the descriptor doctest), so re-select it at 3a7bdf0: 326 files, sha256 dc0eda90...8c04. The matrix is regenerated from `check.py --candidate`; only the baseline identity, the current package and descriptor version (0.2.0), and the digests of the three evidence files the bump touched change. The 36 directed rows, the fail-closed/no-N-1 policy, the historical v0.1.0 receipt and its digest are unchanged, and `--verify-history` still passes. test_check.py now expects current package 0.2.0 against historical 0.1.0. The prose drops the "both package strings are 0.1.0" claim, which the bump makes false, while keeping the point it illustrated. If this branch is squash-merged, re-point BASELINE (and the matrix) at the squash commit so `--verify-history` can resolve it; the ordinary check does not depend on the commit being reachable. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Add docs/compatibility-manifest.json, the artifact to attach to a tagged release, and its owner test crates/oce-api/tests/compatibility_manifest.rs. It records, for the tagged source: - the canonical CompatibilityDescriptor text and its ten fields; - each contract domain's schema revision and an FNV-1a-128 tag over the packaged schema bytes (after checking the packaged file is the served one); - the CXF import contract, MAX_CXF_BYTES, the vendored Modelica Buildings and modelica-json commits, the composite rule ids, the cxf:fnv1a128 content-id scheme and the catalog content id; - the content id of each complete export in the 47-document swept G36 corpus (34), and the byte tag plus deferral-warning count of each incomplete one (13), from a live load-and-export; - the state and replay format revisions and the selected release-compatibility baseline, read from the matrix after checking its descriptor equals the live one. The test renders twice for determinism and compares the checked-in file byte-for-byte; OCE_BLESS=1 regenerates it, following the existing export-content-oracle convention. Every corpus entry agrees with crates/oce-cxf/tests/fixtures/expectations/g36_export_content.txt. The manifest is descriptive: it grants nothing beyond the release-compatibility policy, and its FNV tags are not signatures. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Move every Unreleased entry under a 0.2.0 section and leave an empty Unreleased above it. The header no longer says nothing has been released: releases are git tags, v0.1.0 was a pre-changelog git pin, and nothing is on crates.io. Currency, checked the way the header prescribes: of the PR numbers in `git log origin/main..origin/development`, 22 were absent (#308-#331; #311 and #312 were superseded and never merged). Each now has an entry written from its merged PR description: - Host facade: complete frames (#321, #322, #323), catalog and diagnostic receipt contracts (#317), bounded CXF admission (#318), the compatibility descriptor (#326), state continuation (#328) and replay records (#329). - Facade contraction: the existing frame-only and source-break entries now cite #325 and #316. - Verification: strict-bit evidence (#327), release-compatibility evidence (#330), composition ordering identity (#331), integer golden domain (#324); the Reliefs entry cites its PR #308 beside issue #307. - Documentation and tooling: product contract (#315, #320), public surface, package and authority policies (#310, #313, #314), the stability baseline (#309) and agent guidance (#319). A Release subsection records this preparation: the 0.2.0 bump, the compatibility manifest, the re-selected compatibility baseline, and the strict-bit receipt refresh the bump requires. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Drive two unedited open-control-library fault rules through the durable restart path a host uses: state_snapshot, a host-envelope approval stand-in, EngineStateSnapshot::from_bytes, a freshly loaded engine and restore_state inside the startup window. - AHU-0016: Logical.TrueDelay persistence timer (900 s). - AHU-0004: Integers.Change, a 3600 s Reals.MovingAverage window and a 3600 s Logical.TrueDelay. Across all 16 Library scenarios, a restart after load and after every tick, and a chained restart after every tick, reproduce the uninterrupted run bit for bit: boundary and internal outputs and canonical state bytes. Named mid-dwell and mid-window restarts are paired with cold-start divergence controls, the uninterrupted run meets every Library expectation window, and advanced or foreign targets refuse with typed errors and no mutation. No engine behavior changes. The CXF graphs and vectors are byte copies from Library commit d90f63b with provenance, hashes and license recorded in the fixture README. The state contract doc gains a short section on the result and on restore continuing model time across an outage, which is host frame policy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Forgejo already used #332, so GitHub PR numbers are marked explicitly. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Forgejo is retired and its push mirror to GitHub is off, so GitHub is the primary host again for code, PRs, issues and CI. The Forgejo workflows only ran there, so they move to .github/workflows and .forgejo/workflows is deleted. - pr-gate.yml: the per-PR light gate (ported from the Forgejo ci.yml), on PRs into and pushes to development, ending in the single `CI OK` aggregate. The aarch64 determinism and strict-bit legs stay under QEMU emulation in the x86_64 job; apt now runs via sudo on hosted runners. - release-gate.yml and advisories.yml move back from .forgejo; the release gate also runs on pushes to main and keeps its own `CI OK`. - docs-pages.yml validates docs PRs/pushes again and deploys main to Pages on push or dispatch. - Actions in these workflows are pinned to commit SHAs, checkouts do not persist the token, and every workflow declares `contents: read`. check-workflow-gates.sh now reads .github/workflows/pr-gate.yml and refuses a tag-referenced action in the gating workflows, with a new hostile fixture. - .github/workflows/ci.yml stays byte-identical: it is a bound source of the retained native strict-bit evidence, so editing it would turn the retained-evidence test red until a new native receipt is admitted. It is to be disabled in the Actions settings instead. release.yml and the OpenModelica evidence workflows are byte-bound by their own approvals and are left unchanged. - The authority-claims platforms verifier rebinds to pr-gate.yml. - Agent, contributor, testing and CI docs describe GitHub as primary and record the PR-number convention: GitHub PRs are cited as `(GitHub #N)` because GitHub numbers collide with Forgejo's. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
ci: make GitHub Actions the primary CI and retire Forgejo
Brings in GitHub #334 (GitHub Actions primary, Forgejo retired). The 0.2.0 changelog keeps the recovered #308-#331 entries and gains the #334 entry and the (Forgejo #332) citation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
The workspace 0.2.0 version bump changed the Cargo.toml and Cargo.lock bytes that the retained native strict-bit evidence binds, so the retained qualification test refused with "source digest changed: Cargo.lock". ci.yml run 37382761120 on head f8dcaeb (synthetic merge fbae3b9) captured all four native Linux cells (x86_64 and ubuntu-24.04-arm, debug and release): 21 signals, 161 samples per run, byte-identical repeats and a zero-mismatch cross-cell comparison. Every cell failed only the receipt check, as the documented collection run does. Admission is data-only: receipts.json.current now pins the merge checkout and the strict-bits-matrix digest, the previous qualified-linux/ captures (run 35494403523) were removed and the downloaded captures admitted through the ignored admission test. The release-compatibility matrix's receipts.json evidence digest follows. No bound source changed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
test(api): prove durable state continuation over Library fault rules
Brings in GitHub #332 (Library-rule state continuation test and docs). Its CHANGELOG entry joins the 0.2.0 Verification section; none of the 35 strict-bit bound sources change, so the admitted receipt stands. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
chore(release): prepare v0.2.0 with a compatibility manifest
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Cite GitHub #333 in the 0.2.0 changelog
Brings the five earlier promotion merge commits (#220, #223, #265, #289, #297) into development so the promotion PR is up to date with main, as the new branch rule requires. No content change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
…pment Merge main into development before the v0.2.0 promotion
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Promotes
developmenttomainfor v0.2.0 (CONTRIBUTING release checklist, step 2). Merge with a merge commit, never squash.Release checklist
mainis cited inCHANGELOG.md§ 0.2.0. That covers GitHub test(api): prove durable state continuation over Library fault rules #332, chore(release): prepare v0.2.0 with a compatibility manifest #333, ci: make GitHub Actions the primary CI and retire Forgejo #334 and Cite GitHub #333 in the 0.2.0 changelog #335, plus Forgejo test(api): prove durable state continuation over Library fault rules #332 and the earlier Forgejo-era PRs.release-gateCI OK is green.v0.2.0(annotated) on the merge commit and create the GitHub Release withdocs/compatibility-manifest.jsonattached. A tag push runsrelease.ymlverify only. No crates.io publish.What 0.2.0 carries: stabilized state-continuation and portability contracts, canonical exact replay records, a published compatibility manifest, a refreshed native strict-bit receipt, GitHub Actions as primary CI (
pr-gateandrelease-gate), and the M0-05 library rule-state continuation proof. Full list:CHANGELOG.md§ 0.2.0.🤖 Generated with Claude Code
https://claude.ai/code/session_017eKZATy4SSLSBFWZWZwFyZ
Generated by Claude Code