Skip to content

Release v20.0.0: memory safety, public attachments, and registry closure #876

Description

@flyingrobots

Completed — v20.0.0 (October 3, 2026)

1. Background Context

At the original planning decision, published stable npm was v19.1.0. Main at 94b40dac64034cd8caab9bb05efe14a0c22bd735 already contains the breaking lifecycle and interpretation semantics integrated through #889 (#893/#910). The former v19.2.0 minor-release thesis is superseded by the accepted v20.0.0 major-release boundary.

The inventory (#873/#875), atomic admission (#871), package payload (#867), registry closure (#866), release policy (#890), and security documentation (#892) are integrated foundations. Historical preflight and publication-rehearsal reports in this issue/comments do not establish the readiness of a new release head.

2. Problem Description

Ship the current mainline under an honest major version with memory/correctness failures resolved and supported node/edge byte attachment operations restored. Consumers must receive a usable published artifact, an explicit interpretation/migration boundary, and executable attachment examples.

2b. Proposed Solution

Use the v20.0.0 Linear/GitHub milestone thesis and complete assigned scope; no assigned issue may slip. Land each prerequisite through its own coherent, independently verified PR, then prepare one release PR with synchronized versions and signposts. Publish and verify from the reviewed immutable tag through the repository release process.

2c. Alternatives considered and rejected

  • Publishing breaking main as v19.2.0 would misstate the compatibility boundary.
  • A compatible v19 maintenance release would require an explicitly isolated maintenance line; this roadmap does not initiate one.
  • Root/index/recursive storage migration and witnessed braid collapse belong to later major-release waves, rather than delaying the immediate attachment/correctness outcome.

2d. Acceptance Criteria

  • Every assigned implementation issue and its prerequisites are completed, merged and verified; Bounded node liveness read counts a tail add as live when a checkpoint remove observed its dot #894 is reproduced and fixed or disproved with a deterministic witness.
  • Unsafe membership retirement is prevented without rejecting genuinely concurrent additions; existing containment is preserved.
  • Node and edge attachment attach/replace/clear/metadata/stream operations pass installed-package consumer and cancellation/atomicity checks.
  • No assigned issue remains unfinished, and no issue was moved out, untargeted or prematurely closed to make release-prep pass. Tracking cards satisfy their stated completion criteria; the executable milestone guard is not weakened.
  • All declared version sources, changelog, public documentation, architecture and operator guidance describe v20.0.0 and its actual compatibility boundary.
  • Normal release review, required CI and Docker validation pass on the exact release source; registry closure verifies artifact identity, availability and supported consumers.
  • Publication evidence and the post-release retrospective are recorded before the next release train activates.

2e. Test Plan

Use the repository release profile and preflight/guard workflow. Exercise producer byte-budget rejection before large allocations, node-liveness and failure-cause contracts, stale-replica compaction safety, locked multi-runtime Docker installation, and supported attachment consumers. Include memory-negative controls and stream cancellation/size mismatch failures.

All tests and benchmarks execute in COPY-based Docker containers without host repository or Git-directory mounts. The original planning edit did not execute runtime tests; the completed release evidence linked above records the actual Docker validation and its limits.

3. Prerequisites

The complete assigned issue set in the v20.0.0 milestone is required. No may-slip category remains. PR #914 (worktree-relative hooks) and PR #915 (Docker isolation) completed normal review/CI before dependent delivery work. This release container does not own their implementation or manufacture additional task-DAG edges.

4. Scope

In: the next mainline major release, current interpretation/lifecycle migration guidance, urgent allocation/correctness outcomes, supported public byte attachments, registry visibility and release closure.

Out: new retained indexed storage, complete recursive WARP execution, public workspace extraction, braid collapse, Think production-store changes, retained-mind migration, and unrelated optional backlog.

Safe intermediate state: every implementation PR is independently green. This tracking card aggregates release closure and does not replace its child PRs.

5. Why now

Maintainer ordering is memory correctness, restored node/edge attachments, then eligible PR delivery. Current main requires a major boundary before publication. The v19.2.0 and v19.3.0 mainline plans are superseded; restart-stable occurrence relations #854 move to v20.1.0.

6. Risks

Known dependency edges are incomplete evidence of independence. Candidate scopes and external contracts need validation before activation. Preserve truthful distinction between byte assets, finite structural ownership and external/live references. Do not claim later retained-storage or merge capabilities in this release.

7. Definition of Done

A reviewed v20.0.0 release source, immutable tag, verified npm/JSR publication, supported consumer evidence and completed retrospective are linked here. The maintainer authorized release execution on October 3, 2026; publication, registry verification and the formal retrospective are now complete.

8. Stakeholders

James Ross: release owner and assignee. Application and Think consumers: verified public inventory, atomic writes and attachments. Operators: honest compatibility and recovery guidance.

9. Related Issues

All cards assigned to the corresponding milestone are required, including formerly may-slip cards. Required-disposition and container classifications describe the kind of completion evidence, not an exemption from release completion. #905 remains the broader attachment/recursive-ownership tracker; #824 and #565 retain later streaming/recursive roadmap ownership. #854 belongs to v20.1.0; #814-#823 belong to the v21.0.0 retained-storage release. Existing issue comments and edit history retain historical release evidence.

Maintainer release gate — 2026-10-02

Planning policy (maintainer decision, 2026-10-02): Every issue assigned to v20.0.0 is a release commitment. None may slip. Complete and merge all required implementation work with its acceptance evidence before publication. Do not move issues to later milestones, remove release targets, or close unfinished work merely to clear the release gate. Tracking and release cards must finish their stated closure work; they do not add duplicate implementation PRs. An investigated defect may close with a deterministic disproof only when that satisfies its stated acceptance criteria. Preserve normal review, Docker validation, registry verification and retrospective gates. Any future scope change requires an explicit maintainer decision.

Activity

  1. added this to the v19.2.0 milestone on Sep 7, 2026
  2. added
    type:releaseRelease operation or release gate work.
    priority:nextNext in line after active work.
    area:releasePrimary work area: release.
    status:availableOpen and available for prioritization; not blocked or actively in progress.
    on Sep 7, 2026
  3. added a commit that references this issue on Sep 14, 2026
  4. added
    status:blockedBlocked by an explicit dependency or external condition.
    and removed
    status:availableOpen and available for prioritization; not blocked or actively in progress.
    on Sep 30, 2026
  5. self-assigned this
    on Oct 1, 2026
  6. added
    status:availableOpen and available for prioritization; not blocked or actively in progress.
    and removed
    status:blockedBlocked by an explicit dependency or external condition.
    on Oct 1, 2026
  7. 17 remaining items

  8. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Release preparation is pushed and open as PR #953, a normal non-draft PR targeting main.

    Exact head: 43af831b558bba1dbb2175d8b559679f67999da8; tree 636135e517f2940395bbab28a2903599104e5e54. The normal unskipped Docker push passed all gates: 8,669 tests in 785 passing files, with two existing skipped tests/one skipped file. Six shard totals are 304, 974, 902, 3,139, 2,100 and 1,250; the controlled nested fixture is excluded from those outer totals. Fresh stock COPY image identity and all 2,506 tracked path/mode/blob comparisons match the committed source. GitHub remote head confirms the same commit.

    Independent signpost correction approval supplements the complete metadata/docs and actual integration reviews. The previous failing push remains genuine RED evidence; only the corrected source passed. Current PR CI, full feedback and actual hosted package review are now underway.

    All 39 implementation cards remain closed; this release-operations card remains In Progress through publication verification and retrospective. The pending global ASAP priority decision is unchanged. No tag or registry publication has occurred.

  9. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Final v20 milestone completion inventory — read-only

    No new demonstrated acceptance gap or premature closure found in the assigned 40-issue inventory. This does not authorize closing release issue876.

    Snapshot 2026-10-03T07:39:50.433981+00:00; actual main cf7038c0f9697fbe4f5806deb7a5946456a8d759, tree 92c3a6b1fbcedc5fc90c4a2de4d3bb2ee2ec0f6e. Live REST milestone pagination yields 40 actual issues:39 closed and only876 open. Closed PR930 is separately excluded; GitHub headline41 is not41 executable issues. Canonical structured evidence: canonical-40-inventory.json in the retained final-inventory evidence bundle.

    Counts and planning truth

    The39 closed records comprise 35 delivered issue outcomes, one obsolete-code-removal disposition (#387), one accepted superseding-policy disposition (#135), and two accepted historical tracking consolidations (#136→824 and435→523). The remaining record is the open release-operations card876. These count issue outcomes, not new commits, unique PRs or39 independently implemented features; #837/#839 share a coherent PR, #903 delivers a contract/reference model, and stacked source merges preserve several issue boundaries. No closed executable outcome is treated as complete solely because its state is closed.

    Both successor campaigns824/523 are live open v21 tracking containers, explicitly not extra executable PRs. #136 remains unfinished out-of-core architecture; #435 does not complete all serialization paydown. Their closure comments explicitly preserve those limits. #135 adopts current regression policy and does not claim separate old eager/hash microbenchmarks. These dispositions were recorded Sep30/Oct1 before the Oct2 no-slip execution decision; no issue was newly moved, de-scoped or closed by this audit.

    The current milestone thesis requires safe producer allocation, correctness repairs, restored supported node/edge byte attachments, truthful major lifecycle/interpretation migration and normal registry closure. Its out-of-scope paragraph excludes new indexed retained-state representation, full recursive traversal, package extraction and braid collapse. Its required-all/no-slip wording is preserved: the historical duplicate dispositions are not promoted into new v20 commitments or silently described as completed implementations. #911 explicitly allows sufficient preservation/refusal, rather than demanding nonexistent safe retirement. #903 explicitly requires the agreed contract/model before claiming production recursive compliance, with encoding/traversal/retention819/820/821 separately owned.

    Canonical 40-issue matrix

    Issue Current disposition Acceptance / traceability
    #118 Delivered outcome PR#946 Documented COPY Deno command uses the packed public Runtime and real Git; broken import, wrong-node and forged-marker controls refuse. Existing Deno matrix retained. Evidence
    #125 Delivered outcome PR#940 Consumer installation, root import/CLI, supported engines, contributor prepare/hooks and Docker isolation are executable and truthful. Repeated prepare/version/conflict controls; both CPU-rounding locations corrected. Evidence
    #135 Superseded proposal Accepted replacement is current CPU/Git/RSS/heap/streaming performance policy and base/head CI. Legacy eager/hash microbenchmarks are not claimed. Evidence
    #136 Historical consolidation Historical duplicate consolidated into open v21 tracking container #824. Out-of-core execution remains unfinished, explicitly outside current thesis. Evidence
    #189 Delivered outcome PR#949 ORSet/LWW constructors validate and copy inputs; floating tombstones, joins/permutations and replay preserved. Both readers refuse corruption and preserve real historical decode→index/shard/tail admission. Serialization remains at named boundaries. Independent 6,751 tests/534 files, all 22 complete touched runtime modules 100%. Evidence
    #205 Delivered outcome PR#942 Writer/counter runtime validation and defensive Map copy, zero normalization and preserved joins/dominance;77 focused checks and touched modules100%. Evidence
    #221 Delivered outcome PR#943 Per-instance injected hashing/probe authority replaces shared ambient state; independent-instance, missing/wrong capability and receiver controls preserve known Git identities. 89 tests/7 files; both complete helpers 100%. Evidence
    #260 Delivered outcome Obsolete consumer removed; supported Runtime/Lane/Observer/receipt type consumer replaces the historical graph-first/materialize contract. Evidence
    #379 Delivered outcome PR#732 General CRDT encoding extracted from checkpoint orchestrator; current codec lives at infrastructure adapter boundary after subsequent graduation. Evidence
    #387 Obsolete code removed Named builder/serializeMergedShard target deleted. No manufactured unreachable JSON error test or new streaming implementation claimed. Evidence
    #435 Historical consolidation Maintainer-approved serializer series consolidation into open v21 campaign #523; residual provenance/index paydown explicitly remains. Evidence
    #706 Delivered outcome PR#947 Current-observer reads batch at most four distinct demands; deduplication, captured basis, original guard ordering/refusal and all-or-nothing admission survive delayed/failing providers. Old sequential and wrong-order controls; 79 tests/7 files, both complete modules 100%. Evidence
    #818 Delivered outcome PR#926 Stream-only/bounded collectors; declared plaintext accounting including framed encryption;2 GiB plain+framed96 MiBheap/384 MiBcontainer witness vs eagerOOM137. #646/#737 counterpart closures are recorded, not a claim all legacy storage metadata disappeared. Evidence
    #837 Delivered outcome PR#838 Allocation, receipt-authoritative occurrences, sequential causal order and concurrent incomparable deterministic ordering; supplied-subject compatibility and public integration witnesses. Evidence
    #839 Delivered outcome PR#838 Actual AST equality predicate handles both operand orders and parenthesized forms; WeakMap/callback prohibitions retained. Historical nonexistent test:fast corrected to real stable runner. Evidence
    #840 Delivered outcome PR#846 Bounded aggregate scanner plus split-token/UTF8/header/truncation/identity/ordering/deadline refusals; current source contains meaningful tiny-window and malformed controls. Evidence
    #843 Delivered outcome PR#842 Validated frozen64-patch default, inclusive threshold, explicitnull retained through detached/fork; invalid policy refusal and unchanged state hash. Evidence
    #865 Delivered outcome PR#941 Frozen npm-ci stage copies root lock and all three workspace manifests before unchanged Bun 1.2.23 runtime. Two original clean-build/API witnesses; missing/drift/version controls fail closed. Current per-dependent graph independently matches 849 edges, 70 absent optional dependencies; native/runtime compatibility recorded. Evidence
    #869 Delivered outcome PR#944 Public CLI direct/strand authority and restart evidence;10 BATS cases,7 mutations normal+PYTHONOPTIMIZE,26 processes. #870 dependency landed before main closeout. Evidence
    #870 Delivered outcome PR#937 Distinct render/shutdown/reclaim deadlines, native PID ownership before await, cancellation cleanup and real browser-close RED/GREEN. Linux-controlled Windows policy; no actual Windows execution claim. Evidence
    #876 OPEN release operations Release PR953/current checks/artifact, actual final preflight/policy, immutable tag/registry verification/retrospective remain root-owned; not completed by implementation/mainline inventory. Evidence
    #882 Delivered outcome PR#939 Actual instrumented-worker capacity calibration establishes startup cause and bounded repair. Incomplete, failed, empty and erroneous runs cannot write the ratchet; explicit-argv reporting/ratchet routes and cleanup/retry controls pass. Current same-tree full coverage completes 8,879 tests/821 files, zero errors, reporting-only ratchet unchanged. Evidence
    #891 Delivered outcome PR#914 Prepare/pack preserves relative hooks and explicit caller overrides across real worktrees; legacy path repair and exact staged/path protection; corrected8089 count retained. Evidence
    #894 Delivered outcome PR#935 Floating removed-dot liveness parity/refusal through real checkpoint writer/locator; receipt identity, corruption/missing receipt refusal and independent surviving additions. Evidence
    #895 Delivered outcome PR#934 Existing checkpoint-basis-unavailable cause is registered and accepted by enrichment schema; all three no-bounded-basis helpers use the closed cause type. Four old-schema RED regressions and three invalid-cause compiler controls are load-bearing. Verifier→enricher witness is composed, not invented public routing. Evidence
    #900 Delivered outcome PR#936 Executable guard resolves real module/invocation paths; real file/directory/relative/spaced symlink calls produce output once. Import/foreign/unresolvable argv remains inert; two symlink RED cases, compiled/source GREEN and migration regressions preserved. Evidence
    #901 Delivered outcome PR#927 Public node/edge stage/attach/replace/clear/captured stream, atomic publication/recovery/strand, typed failures and packed lifecycle/reopen/GC proof. Two independently verified fixes included. Evidence
    #902 Delivered outcome PR#929 Historical supported-packageRED plus installed NodeNext/Bundler operation and syntax isolation, both owner lifecycles/concurrency/receipts/history/GC; required CI aggregate and release packed gate. Evidence
    #903 Delivered outcome PR#932 Paper-backed finite ownership/descendant/conflict/atomic contract with14 test-only model witnesses and4 negative laws. No recursive public Runtime/PaperII production compliance claim. Evidence
    #904 Delivered outcome PR#938 Truthful byte/property/structural/external distinctions, supported executable reused lifecycle example and migration; packed links pinned and installed consumer passes. Evidence
    #906 Delivered outcome PR#892 Direct inventory aligns manifest, unused directelkjs removed, peer bitmap provenance explicit,4 expired risk acceptances retained pending owner decision rather than renewed. Evidence
    #907 Delivered outcome PR#893 Incremental property updater delegates validated reader; raw full-state decoding at infrastructure boundary; malformed entries refuse; scoped codec/updater100% and quarantine graduation recorded. Evidence
    #911 Delivered outcome PR#930 Conservative eager/trie no-op preservation suppresses stale node/edge rejoin and retains genuine concurrency through GC/checkpoint; no safe retirement or metadata bound. WholeTrieCursor92.54line limit disclosed as narrow bugfix. Evidence
    #913 Delivered outcome PR#933 Four known label-contract failures repaired from DSL/domain/provider evidence, with actual logical bitmap reader. Default logical labels versus empty commit-DAG sentinel, direction and duplicate (label,neighbor) controls preserved; contract suite participates in the normal runner. Broken-parent normal-shard control fails. Evidence
    #916 Delivered outcome PR#931 Exact pre-allocation16 MiB canonical descriptor budget/one-byte-over, UTF8/escaping/substitution parity and no writer publication;2 bounded/eager32 MiBheap pairs; reader/sequence100%, no wholeIntent100% claim. Evidence
    #921 Delivered outcome PR#915 COPY runner/direct refusals, executablePATH/watch/snapshot/evidence/coverage exports and owned cleanup. RealwatchPASSFAILPASS and failedstatus preserved; registry lifecycle owned separately922 nowmain. Evidence
    #922 Delivered outcome PR#945 Exact-version public install/signature/import/CLI consumer runs inside owned COPY Docker; host/forged isolation refuses. Shared aggregate deadline, bounded cleanup and truthful receipt/log export have 30 BATS plus 26 selective calibrations and an actual anonymous immutable-registry consumer witness. Manual/CI boundary agrees; Node20 retirement is integrated. Evidence
    #923 Delivered outcome PR#925 PublishedCAS6.5.11/Plumbing3.3.2 bounded mktree transport recovery:1retry/2attempts, producer identity, exhaustion plus realGC/readback; inverse manifest golden proof. Evidence
    #948 Delivered outcome PR#950 Fresh locked full audit is zero; vulnerable 42-package tooling chain removed with exact-version/content declarations and trailer behavior preserved. Clean/repeat/conflict/version tests plus real kernel partial-write RED→GREEN establish private complete-write/no-clobber publication and usable retry; races and cleanup/error identity tested. Installer 31 + hooks 13 = 44/2; whole installer 100%. Evidence
    #951 Delivered outcome PR#952 Rendered full Compose matrix is exactly Node22/Bun/Deno; Node22 profile remains one service. Unsupported Node20 script/service/image/test enumeration removed, engine >=22 preserved. Sixteen context tests, reintroduction control, current Node22 30 BATS/26 calibration and full normal/hosted evidence accepted by independent root review. Evidence

    Independent bounded checks and retained proofs

    Explicit evidence limits and remaining gates

    This is an inventory/acceptance-evidence audit, not a new adversarial review of every transitive production path, a test run, a historical registry recertification or a green current release artifact. Historical raw run counts remain pinned to their owning heads; author/previous reviewer executions are inspected records, not executions repeated by this audit. Some older issue bodies/PR text preserve unchecked boxes or pre-merge wording; later exact-head review, actual merge ancestry and explicit closeout receipts establish delivery rather than those stale checkboxes. #839 names a historically nonexistent test:fast command; its recorded correction to the actual stable runner and retained fixture coverage is explicit.

    Two whole-module coverage boundaries remain disclosed and are not silently waived or promoted to100%: #911 changed preservation behavior is a narrow accepted bugfix while wholeTrieCursor line coverage92.54%; #916 reader/sequence reach100% while wholeIntent has a disclosed descriptor-getter fallback gap. #870 actual Windows runtime remains unverified; Linux controlled Windows taskkill policy is the evidence. #903 model compliance is not production PaperII/DPOI compliance. #906 risk acceptance renewal remains an owner decision, excluded from its honest-inventory outcome. The known unused dangling Dockerfile convenience alias remains a separate surfaced retrospective observation with valid named supported build routes.

    The live issue876 remains the only unfinished assigned release card. Current PR953 CI/artifact/feedback is owned by the separate reviewer and is not duplicated here; final current-source normal/hosted evidence, global ASAP policy decision and final exact-main preflight, guarded immutable tag, actual registry publication/verification, release closure and prescribed retrospective remain outstanding or owner-monitored. This inventory cannot grant priority consent, publish registries or close876. No source, labels, milestones, issues, Linear state or global guard changed.

    Final bounded conclusion: all39 closed milestone records have a supported delivered outcome or explicit historical disposition, and their implementation source integrations are on actual main. No new issue-specific acceptance blocker found. Release issue876 remains OPEN until its own complete release/registry/retrospective outcome passes.

  10. added
    status:blockedBlocked by an explicit dependency or external condition.
    and removed
    status:activeSomeone is actively working this issue.
    on Oct 3, 2026
  11. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    PR #953 is technically ready at dd5a3e0eb4d8de4f66387f58fa91f140427ed19a: complete final independent source, CI, actual artifact and feedback approval. All seven required trusted checks pass. Coverage completed all 822 selected files with zero errors and an unchanged ratchet; 8,879 passed tests/821 passing files plus the existing skips. Actual package: 746,153 compressed bytes, 3,257,239 unpacked bytes, 971 files, all bound to fresh exact-source compilation. Byte headroom remains tight, within unchanged limits. Both documentation findings are fixed, independently approved and resolved.

    Release operations are marked status:blocked solely on the pending priority decision. The unchanged global zero-ASAP guard still counts open v21 cards #819, #820, #821 and #905. The concrete decision already requested is whether to change only those four GitHub priorities to priority:next, matching their existing Linear High priority, or retain ASAP and hold v20 publication. Scope, milestones, dependencies and ownership would remain unchanged. No decision has been assumed and no priorities or guard were changed.

    The Linear workflow has no separate Blocked state, so FLY-248 retains In Progress with status:blocked and this explanation. This is a publication-policy hold, not a failed CI or unresolved code finding. No release PR merge, immutable tag, registry publication or final release closure has occurred. After the policy decision, actual main/tag alignment, guarded publication, public npm/JSR verification and the prescribed retrospective still remain necessary. The retrospective is prepared only as an unpublished draft with pending registry fields.

    Canonical 40-card scope audit: 35 delivered outcomes, one obsolete-code removal, three historical supersession/consolidation dispositions, and this open release-operations card. No additional issue-specific acceptance blocker was found.

  12. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Maintainer decision, October 3, 2026: explicitly approved changing #819, #820, #821, and #905 from priority:asap to priority:next, retaining their open v21 scope and prerequisites, then completing v20 publication, registry verification, and the formal retrospective. The global release guard is unchanged. V20 delivers byte attachments and the ownership contract; production recursive references/traversal/retention remain v21 work. #905 has been reconciled to distinguish completed children from the remaining work. No unfinished v20 issue was moved to clear the gate. Release operations resume under #876; publication is still pending.

  13. added
    status:activeSomeone is actively working this issue.
    and removed
    status:blockedBlocked by an explicit dependency or external condition.
    on Oct 3, 2026
  14. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Release preparation PR #953 merged at ceb58e656ec5bc85f0ae5991bf2a55599693bbb3 after all required current-head checks, CodeRabbit approval, independent source/artifact/feedback review, and Code Lawyer admission. Current review: #953 (comment). Gate record: #953 (comment).

    Automatic final-main preflight/tag workflow: https://github.com/git-stunts/git-warp/actions/runs/37147341756. Tag creation, registry publication, installed-consumer closure and the formal retrospective remain pending. Issue stays active/open until those receipts exist. Four v21 issues remain open at priority:next under the approved decision; none was closed or removed from its milestone.

  15. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Final main preflight passed: https://github.com/git-stunts/git-warp/actions/runs/37147341756.

    Annotated tag v20.0.0 (tag object 3ec9c1ce9b0d54a6db0cb4c99855ffbf25de10a8) points exactly at reviewed main merge ceb58e656ec5bc85f0ae5991bf2a55599693bbb3. Its tree is identical to the approved PR head. Main CI and main performance also passed.

    Maintainer-dispatched publication is running: https://github.com/git-stunts/git-warp/actions/runs/37148457531 (GitHub actor flyingrobots; dispatch ref v20.0.0). npm/JSR publication, installed public-registry closure and the retrospective remain pending. This is tagged status, not a claim of verified publication.

  16. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Independent actual-main integration admission

    Source APPROVE at actual main ceb58e656ec5bc85f0ae5991bf2a55599693bbb3, tree cb7ef882bf0b8a48cb84b6bb0db240de69706525. Authorized root merged PR953 at19:17:12Z. This read-only independent Codex audit applies the complete agy protocol; no tests repeated, source/trackers edited, comments published, workflow restarted/dispatched, tag/registry or merge mutation performed.

    Preserved complete current c1ca source/hosted/artifact/full-feedback report and Code Lawyer closure carry all unchanged source paths, earlier merges, fixes, raw claims, constants, error transitions, SSJS, numerical/coverage limits and owning reports. The release source is identical to the fully reviewed/tested c1ca tree; no independent repeated suite is necessary for this merge. Actual final-main tag/performance observations remain a separate addendum after original jobs finish.

    Complete applicable receiving-head checklist

    • Every merge/whole parent/tree/source. GitHub primary Git object API independently verifies exact ordered parents oldmain cf7038c0f9697fbe4f5806deb7a5946456a8d759 and incoming c1ca3fe20dd988dd430f6fd010b4c3e585239bb0. Actual main treecb7ef882 is exactly incoming reviewed treecb7ef882. Git tree identity covers every2,506 path/mode/blob including the sole symlink; prior c1ca independent actual COPY oracle/compile binds all entries. No conflict resolution, caller rerouting, extra/deleted source or runtime/test/package change. Live branch main API points ceb58. Actual synthetic c1ca preflight tree was also identical, so this receiving tree has the same whole-source/payload semantics that passed before merge.
    • Every delivery path/inherited invariants. All17 effective release paths and the latest33-line topic delta retain their complete production/parallel-path maps in the full report. Metadata versions/private workspaces/lock-only fields/node floor/exports, existing historical migration tests, property-clear versus OR membership rules, staging storage-versus-graph causality/cardinality, receipts/replay, byte streaming, atomic admission/refusal, captured removal/guard ordering/exhaustiveness, validated historical/strict modern CRDT boundaries and atomic installer fault recovery remain exact c1ca. No new runtime branch at merge.
    • No trusted claims/previous feedback. Source admission follows actual ordered parents/tree and current whole-image/archive evidence, not merge text. Previous valid43af documentation findings and obsolete-release oracle remain actually fixed; old requests dismissed only after evidence. Current premerge fresh feedback fully exhausted six globals/four reviews/three inline/one resolved thread, current CodeRabbit5402331782 APPROVED/no actionable comments. Body-only final issue-reference also passed, making21 successful c1ca checks after the earlier20 snapshot; no new source change. Complete current c1ca full independent approval and seven main required trusted contexts were green before the authorized merge.
    • Every constant/number bound. No constant, profile, dependency, schema, byte/cardinality/memory/time limit or threshold changes in receiving tree. Preserve unchanged760000/3300000/1050 payload ceilings/85%warning/95%critical, declared64KiB/64MiB/16MiB/50k and retained GC/history limitations. Actual premerge artifact11283275000/run37146192175 at c1ca measured746153compressed/3257239unpacked/971files, SHA1bcaf9a3a76530c3d4d00d5d5dbd6e959dcc5e47a; every tar byte equals fresh exact source build, report/inventory/SHA512/modes/top10/groups/source/regeneration/preview checked. Identical receiving tree retains those source/payload inputs; this is not a yet-unmeasured final-main registry artifact claim.
    • Errors/state transitions/current law. No source transition changes. Existing uncertainty/absence/refusal/cancellation/typed errors, staging unreferenced storage and no automatic upload audit, all-or-nothing graph publication, installer partial-write prevention and coverage owned-candidate cleanup retain owning exact-source regression proof. Explicit user approval and comment8765972369500 authorize priority reconciliation and completing release/registry/retrospective; live globalASAP0 and40milestoneissues/39closed/876onlyactiveopen observed before merge. Former policy HOLD is superseded. Final tag/registry closure remains real operational work, not inferred from premerge prep-pr guard, which skips live zero gates.
    • Standards/execution/numeric honesty. No source refactor or doctrine delta. Full manual SSJS/Anti-Sludge/SSTS source proof preserved; no cast/quarantine/exclusion/false whole100% claim. Exact premerge coverage8879passed/2existingtestskips,821passingfiles/1skip,822selectedcomplete/zeroerrors/CIratchetunchanged and94/87.75/96.93/94.08 global are inspected current original execution, not newly rerun on main. Root/current CI unit8669/785+2/1skip, integration149/41, optic20/1, BATS48, Bun82/17, Deno18; static51diagrams/eightfiles/78MarkdownFILES retain their actual units. Critical payload headroom, class coverage gaps, dangling unused Dockerfile alias and unexecuted Windows/power-loss tests remain disclosed. No test/benchmark on host, repo/Git mounts or isolation bypass. Actual source preservation needs no duplicate local test.
    • Original current-main jobs observed; final operational boundary explicit. Original Main Push Release Branch Check37147341756/attempt1, main performance37147341763/attempt1, main core37147341758 and link37147341785; link SUCCESS, tag final preflight and performance initially in progress. Source check inspects unchanged workflow routes: main release detector/metadata20.0.0 → full final-local preflight → annotated tag object at actual GITHUB_SHA ceb58 → immutable ref creation (no force) → manual maintainer registry dispatch. Main performance resolves concrete push-before cf7038 and head ceb58; expected runtime/fixture bytes are identical to the approved c1ca comparison against cf7038. Must read completed original raw logs/output to confirm actual outcome; no tag, performance-number or registry claim before it occurs.

    Raw receiving receipts: merge-commit.json, main-initial.json, original runs-initial.json, tag-run-initial.json, current tag/performance jobs/steps, complete published owning review5972625935 and post-body current check/PR snapshots. Primary API is used rather than mutating another author's checkout. No publication or root action is performed by this reviewer.

    APPROVE

    Original main performance addendum

    Original performance run37147341763, attempt1, completed SUCCESS at exact merged head ceb58. Actual retained artifact11283261613 (v19-performance-ceb58e656ec5bc85f0ae5991bf2a55599693bbb3) was independently downloaded; API ZIP digest sha256:f96b04438e43acf862f83df17612c9151a6522049724cc79ee4ac3b58b55e112 and byte length matched the actual download. Its twelve entries had no duplicate or unsafe paths. Actual materialization source coordinates are base cf7038 and head ceb58; six-record execution order is base-A/head-A/head-B/base-B/head-streaming/base-streaming. The legacy v19-labelled workflow/gate remains the current unchanged performance contract, not a claim that package version is19.

    An independent COPY Docker receipt validator parsed the actual comparison through current source schemas and evaluated the unchanged benchmarks/v19/policy.json; zero failures, regenerated current-policy summary byte-identical to the uploaded summary. Head cold/warm/incremental CPU medians1740/1210/1630ms versus base1740/1200/1620ms; Git medians50/25/60 on both, within unchanged absolute/relative gates. Wall is diagnostic, not upgraded into a new blocking claim. Head oversized observer proof streamed268435456 logical bytes under67108864 old-space bytes with hostile-control OOM evidence, current gate PASS. These are actual hosted measurements, not a new locally rerun benchmark.

    Actual migrated-read receipt independently parsed current schema; environment package20.0.0/head ceb58, pinned historical v18 package18.2.1, five measured and one warmup runs,18 retained fixture patches. All24 metric distributions were independently recomputed from their five raw samples (median/minimum/maximum); embedded policy exactly matched current unchanged benchmarks/v19/migrated-read-policy.json. Current evaluator returned no failures/PASS, and regenerated migration summary was byte-identical. Migration preparation1535.971388ms remains excluded from read samples; no migration-time speed claim or invented uniform hardware guarantee. Legacy v19Commit field holds actual ceb58, not a historical package identity.

    Validator container was networknone, mounts[],2CPU/1GiB, exit0/no OOM; unique image/source inherited only exact approved COPY bytes. Receipts: performance-artifact.json, performance-bundle.zip, original performance.log/performance-clean.log, performance-verify.log, performance-verify-container.json, performance-proof.json, and independent verifier source/context. Initial inspector's completed container cannot accept docker exec; that read-only probe failed and was not acceptance. Before executing the successful validator, draft aggregation field names were corrected to actual schema minimum/maximum; no source/test/policy changed. No worker, full suite or benchmark was repeated.

    Performance consistency APPROVE. The original tag run37147341756 still has final release preflight in progress and tag creation pending at this snapshot. Source/performance approval does not claim completed tag, registry publication, GitHub release or retrospective. Those operations remain release-owner work.

    Completed original final-main preflight and annotated tag

    Original Main Push Release Branch Check37147341756, attempt1/job111273902918, completed SUCCESS at actual main ceb58. Final release preflight, Create release tag and Manual release dispatch summary each completed SUCCESS; Skip summary was skipped, so this is actual creation after full preflight, not an existing-tag/no-release skip. Primary API annotated object 3ec9c1ce9b0d54a6db0cb4c99855ffbf25de10a8 is named v20.0.0 and peels to commit ceb58e656ec5bc85f0ae5991bf2a55599693bbb3. Live main remains the same exact reviewed treecb7ef882. No tag rewrite or source mutation was performed by this reviewer.

    Actual original raw final-local guard passed version20.0.0 lockstep, clean checkout, exact HEAD==origin/main ceb58, dated CHANGELOG/current topology, readable labels, global ASAP-zero, target milestone exists/non-release-operation-zero, valid prior milestones/prior-release-zero. All required preflight checks passed: lint/Mermaid51diagrams/eightfiles/78MarkdownFILES, types/policy/surface, full coverage8879passingtests+twoexistingtestskips/821passingfiles+oneskippedfile/822selected, package payload, actual packed public consumers and import/removal/lifecycle calibrations, npm publish dry-run, JSR publish dry-run, and locked runtime/development npm audit zero vulnerabilities. Current preflight coverage is real original hosted execution, not a duplicate reviewer suite; nested completion fixture is excluded from top-level totals. Audit-zero is only a time-specific dependency graph result, not an exhaustive security proof. Previously surfaced warning/coverage/platform/storage limits remain unchanged in preserved owning reports.

    Raw receipts: tag-run-current.json, tag-final.log, tag-final-clean.log, tag-ref.json, tag-object.json, main-final.json, tag-proof.json, actual merge receipt plus published full review5972625935. Complete seven-area receiving/source checklist above remains applicable unchanged; final tag/performance boundary is now verified.

    APPROVE — actual merged main source, original main performance and annotated-tag/preflight consistency. Registry publication, GitHub release, installed-package closure and formal retrospective remain distinct operational closure. Root dispatched release run37148457531; reviewer may observe its original jobs and actual closure artifact but performs no dispatch/publication and no duplicate consumer execution.

  17. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Independent public registry closure admission — v20.0.0

    APPROVE — actual public closure at tagged source ceb58e656ec5bc85f0ae5991bf2a55599693bbb3, tree cb7ef882bf0b8a48cb84b6bb0db240de69706525, original release workflow37148457531 attempt2. This read-only independent Codex audit applies the complete agy protocol to the operational delta; no publication, dispatch/rerun, tag/branch/source/tracker mutation, new consumer or repeated full suite/benchmark. Root performed the authorized publication and failed-job recovery. Formal retrospective/tracker closure remains root-owned.

    Preserve the entire current release source/hosted/artifact/feedback approval, Code Lawyer closure, and actual-main/tag/performance admission. These carry every prior source path, merge, raw number, decision and limitation; this closure has no source delta.

    Complete applicable checklist

    • Every source/merge/parallel delivery path. Actual main ordered parents cf7038+c1ca and treecb7 identical incoming c1ca were independently verified before publication; all2,506 source path/mode/blob entries and all971 packed file bytes retain exact current source binding. Annotated tag object 3ec9c1ce9b0d54a6db0cb4c99855ffbf25de10a8 still peels ceb58; final tag-ref API unchanged. Release verify raw HEAD/tag both ceb58,20.0.0 package/JSR lockstep, current green main performance evidence. No merge or new call path during closure. npm/JSR/GitHub release/registry closure are inspected separately rather than inferred from aggregate green status.
    • No trust/actual evidence and recovery. Attempt1 verify111277131216, npm111279605506, JSR111279605518 and GitHub release111280589336 all SUCCESS. npm actual first publish succeeded under latest with signed provenance, SHA1bcaf9a3a76530c3d4d00d5d5dbd6e959dcc5e47a/971files; JSR actual log Successfully published20.0.0. Original closure111280608013 failed registry visibility after six attempts at19:56:31Z, before any consumer. Actual immutable artifact11283825716 (629ZIPbytes/onefile/digestcd7ae3db8504e736c70f23474e77d55eeb50c7f5188d7038e1121d676c049fba) independently inspected: statusfailed/stageregistry, known tag/run/GitHub release identities, npm/JSR metadata null,720-second total budget not exhausted, no consumer evidence. npm raw publication explicitly warned the package was being processed and could take minutes; contemporaneous E404 followed by exact public metadata visibility corroborates propagation. No deterministic parser/identity corruption demonstrated. Root waited visibility then reran ONLY failed closure; successful dependency job timestamps remain their original19:35–19:55 executions, so no republishing or repeated verification was inferred from new inherited job IDs.
    • Actual current attempt/artifact provenance. Current run37148457531 attempt2 completed SUCCESS, actual closure111281172973 at19:58:46–19:59:13Z, actual successful closure line19:59:10Z. New retained artifact11283845963 (release-closure-v20.0.0) has7,660ZIPbytes/ninefiles and digest sha256:f94db3d5995e0c2289ec19df6a7859c480d8358b3387f8e718b0079e04bf22c8. Independent download byte length/digest/API exact run/head checked; no duplicates/unsafe paths. Current job upload ID/time matches new artifact, so the older failed same-name artifact is not confused with it or overwritten. Actual JSON schema git-warp/release-closure@1/statusverified/stagecomplete, v20.0.0/version20.0.0/sourceceb58, exact publishing run/path, public GitHub release402668157/tagv20.0.0/nondraft, unexhausted720-second budget. All five current result rows SUCCESS; original publication outputs retained.
    • Numbers/constants/integrity/ownership. npm public metadata20.0.0/gitHeadceb58, SHA1bcaf9a3a… and full integrity sha512-ANuhcXlMA2S4QJutSdN3EhlwSDl17geLmrAtkObiT1kb5VVOrCppgj371RBFmUweJbrdwAZTgvwv38eKCsSUIQ== exactly match independently source-bound current c1ca archive (746153compressed/3257239unpacked/971files; all971bytes previously matched fresh compile). Actual installed npm lockfile/integrity checks plus this full immutable payload hash preserve public npm source binding. Public latest is20.0.0, ownershipRequired=true/ownsTag=true; maintenance-v16 remains16.0.1 from fresh packument. JSR shim @jsr/git-stunts__git-warp20.0.0 actual archive downloaded and SHA512-checked by original closure; receipt integrity sha512-5ymqgGWLLchpoaYCaOaDPMA2PRw3KsPp2OmN0QV/N+QFdGKMKu8mroeQK8NkJ78KE1VjPGbD0uBRe2PETjmoPg==. No separate per-file source-byte or graph-consumer claim for JSR. No policy, payload, retry or deadline constants changed to make recovery green. Current release verify original8879tests/821files+2/1existing skips,822complete,94/87.75/96.93/94.08 global; actual npm prepack outer8669tests/785files+2/1skips, excluding nested1pass/1skip. These are original required executions, not reviewer reruns.
    • Actual consumer/error transitions/state/cleanup. Current receipt rootImportpassed, privateStorageFirewallpassed, clipassed, registrySignaturesverified; actual diagnostics say25packages verified registry signatures and14verified attestations. Installed git-cas6.5.11/plumbing3.3.2, real CLI help retained. Actual current source consumer invokes exact public npm install with ignored scripts, checks HTTPS public registry lockfile/immutable version-integrity/no links, npm audit signatures, exactly Runtime root export, expected ERR_PACKAGE_PATH_NOT_EXPORTED private storage refusal and executable CLI help. Producer actual copied tools/metadata-only Docker route2CPU/2GiB has no host repository/Git mount; executionboundarycopy-docker/evidencecomplete/cleanupcomplete. Eight retained diagnostic logs include build/create/start/container/export/install/signatures/CLI; actual export log records owned container/image deletion. Empty start/container stdout is compatible with successful silent import assertions; not missing execution evidence. First attempt cannot be relabelled consumer PASS. This installed registry consumer exercises imports/firewall/CLI/signatures/dependencies; advanced graph, node/edge attachments/64MiB streaming/atomic receipts/retained-history proofs are explicitly pre-publication packed consumers and original runtime tests. No claim of repeating those after publication. No wholesale datastore/security/crash proof from audit/signatures.
    • Standards/SSJS/execution/limits. No source/refactor/type/quarantine/suppression change; full prior agy/Anti-Sludge/SSTS/manual SSJS/path/history/coverage limits preserved exactly. Actual npm/JSR publication warnings (existing dynamic-import analysis), existing CLI v19-capability labels and CI deprecations are not hidden by a warning-free claim. Prior whole-module coverage exceptions/platform/storage limits remain disclosed. Independent actual ZIP/static receipt checkers ran unique COPY Docker images,1CPU/512MiB/networknone/mounts[]/exit0/noOOM; source-bound npm payload proof is inherited only exact bytes. No host tests, consumer reexecution or isolation bypass. Downloaded metadata/primary API/static reads are read-only. Initial diagnostic scratch Dockerfile was written to the wrong directory (prebuild failure, retained); corrected COPY build succeeded. An unsupported direct JSR per-version HTTP route returned404 while the actual npm-compatible full packument exposed20.0.0; it is not a package-absence finding. Initial GitHub job-log display refused escape sequences; explicit raw download corrected it, no skipped source gate. These reviewer collection mistakes are excluded from positive acceptance.

    Receipts: attempt1/attempt2 original run snapshots/logs, immutable artifacts and metadata, current public npm/JSR packuments, actual GitHub release record, closure-diagnose.log, closure-attempt2-verify.log, closure-attempt2-details.log, nine extracted current artifact files/eight diagnostic SHA256s, independent COPY context/scripts/container inspect receipts, registry-proof.json, final tag-ref/run APIs. All public links above use actual source/operations coordinates; portable receipt basenames only.

    APPROVE

  18. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Release retrospective: v20.0.0

    Completed October 3, 2026. Release owner: James Ross. Report prepared by Codex from actual source, workflow and public-registry evidence. V20.0.0 is published to npm and JSR; the registry closure receipt is verified after a verification-only retry for npm processing delay. No tag or immutable package was replaced.

    Released

    The published v20 release delivers:

    • Public node and edge byte attachments: applications stage Runtime-owned content, publish attach/replace/clear intents, and stream captured readings through supported package exports. Installed-package witnesses cover both owners, concurrency, foreign provenance refusal, failed producers, retained history, collection/reopen and a generated 64 MiB payload. Staging performs storage I/O; it is not a causal graph write or a durable retention guarantee. The subsequent admitted write establishes the association and graph receipt.
    • Correct lifecycle interpretation and admission: observed removal membership, node property clears, floating tombstones and historical checkpoint identities are interpreted consistently at their validated boundaries. Admission refuses malformed registers and non-record event metadata instead of silently inventing a valid identity or dropping a corrupt property. The major upgrade needs coordinated writers, backups, rebuild/replay and receipt verification; it is not merely a metadata version bump.
    • Allocation safeguards: eager collectors, Git reads and atomic intent descriptors enforce limits before unbounded allocation. Streaming bytes and atomic descriptor size are distinct contracts. Safe compaction preserves causal membership evidence; the release does not establish safe arbitrary tombstone retirement.
    • Operational and consumer safeguards: COPY-only unit/watch/coverage/performance and registry-consumer execution, bounded worker allocation and coverage completion, owned Mermaid browser cleanup, locked dependency parity in the Bun image, atomic declaration installation, Deno installed consumers, bounded guard input, symlink-safe migration entry points and package payload inspection. The supported Node floor stays 22; the retained unsupported Node20 route was retired.
    • Dependency and documentation truth: published Plumbing 3.3.2 and git-cas 6.5.11 repairs are prerequisites consumed by git-warp, not an unverified local substitute. Current version signposts and the lifecycle/attachment/ownership documents distinguish v20 source behavior from historical releases and v21 production recursion.

    Both exact versions are publicly visible. The final receipt binds npm gitHead, tag and publishing run to ceb58e656ec5bc85f0ae5991bf2a55599693bbb3, validates npm signatures/provenance and JSR archive integrity, and records a successful COPY-Docker npm consumer. The pre-publication packed attachment tests and post-publication consumer have distinct coverage, detailed below.

    Not released

    Production typed recursive graph references, cycle-safe cross-graph traversal, recursive retention across CAS authorities, indexed retained-state selection and the global memory proof remain open v21 work. The structural ownership contract has executable test-only reference laws; it does not create a recursive public Runtime API or establish Paper II implementation compliance. Preserving OR-Set evidence can still grow retained metadata. Generator-shaped reads and bounded payload witnesses do not prove a graph-size-independent total process-memory bound.

    Ordinary branch push/pull is not an attachment synchronization guarantee. Operators currently name WARP refspecs and close/reopen Runtime resources after fetching. The installed attachment witnesses establish same-repository behavior, not the complete cross-repository setup/transfer workflow. The filed fallout below addresses that ergonomic and proof gap without claiming a new network protocol or live refresh.

    No assigned v20 issue was moved forward to evade its acceptance criteria. Historical disposition cards are accounted for below rather than counted as additional implementations.

    Plan vs actual

    The canonical milestone inventory contains 40 GitHub issues, excluding PR #930: 35 delivered issue outcomes, one obsolete-code removal (#387), one superseded proposal (#135), two accepted historical consolidations (#136 and #435), and one release-operations card (#876). At the completed implementation audit, 39 issues were closed and #876 remained open. These are issue outcomes, not 39 distinct implementations or 35 independent new PRs. In particular, #837 and #839 share owning delivery evidence; tracking containers do not add implementation credit.

    The 13 late implementation cards were checked against live acceptance criteria, owning evidence, exact source ancestry and Linear mappings before their closure after the actual main merge. The additional 26 already-closed cards were checked through full bodies, closure discussions and source/evidence links. The old #136/#435 dispositions were accepted before the no-slip decision; unfinished indexed/provenance architecture remains visibly open under v21 containers #824/#523. #135's obsolete proposal was superseded by a recorded performance policy, and #387's obsolete builder was removed. None is presented as newly implemented v20 functionality.

    The initial attachment repair expanded into dependency publication, runtime provenance/retention, installation, process ownership and release-consumer isolation. Independent failure controls found problems that ordinary green status had missed: partial declaration writes, malformed persisted identities, missing actual container tools, unsafe browser reclamation and unsupported retained test routes. Each retained defect was repaired and re-reviewed within its owning issue, preserving ordinary merge ancestry rather than rewriting history.

    The safe compaction direction changed from destructive retirement to preservation because stale concurrent joins can resurrect membership when required evidence disappears. Release messaging therefore narrows the claim to the proved safeguard rather than hiding the correctness/memory tradeoff.

    Finally, four open v21 cards still carried global ASAP labels while Linear already classified them High. The unchanged global release guard correctly held publication. The maintainer explicitly authorized #819/#820/#821/#905 to move to priority:next, preserve their scope/prerequisites, and reconcile #905's completed v20 byte-attachment children versus remaining v21 recursion. That is a recorded sequencing decision, not feature completion or a moved v20 commitment.

    An additional publication-time surprise was npm's asynchronous processing. The first upload succeeded at 19:55:22Z, but npm explicitly said availability could take minutes. The initial closure job exhausted six checks at 19:56:31Z before running any consumer. Once public metadata exposed 20.0.0 with the expected gitHead/latest, only the failed verification job was rerun. Attempt 2 completed successfully by 19:59:13Z. The failed receipt remains evidence; successful upload was not mistaken for public availability. The tag, npm package, JSR package and publication jobs were unchanged by recovery.

    Evidence

    Independent public registry closure approval verified both retained attempts and the published artifact identity.

    • Release tag: v20.0.0, published on GitHub at2026-10-03T19:55:28Z. Annotated tag object 3ec9c1ce9b0d54a6db0cb4c99855ffbf25de10a8 peels to reviewed merge ceb58e656ec5bc85f0ae5991bf2a55599693bbb3.
    • Source: release PR #953, with the same tree as approved head c1ca3fe2; complete current-head independent review, Code Lawyer admission, and actual main/tag/performance audit.
    • Scope: canonical40-issue audit and approved priority decision. No unfinished assigned v20 issue was moved to clear a gate.
    • Automatic final-main preflight and tag: run37147341756, successful. Main performance37147341763 and main CI also passed.
    • Publication and closure: release run37148457531, final conclusion success. Attempt 1 published both registries and failed only registry visibility; attempt2 reran only the failed closure job. Actor flyingrobots, source commit ceb58e65, workflow .github/workflows/release.yml.
    • npm: @git-stunts/git-warp20.0.0; exact version20.0.0, gitHead matches the tag, latest20.0.0. Existing maintenance-v16 remains16.0.1. Signed SLSA provenance and registry signatures verified.
    • JSR: @git-stunts/git-warp20.0.0; exact npm-compatible representation @jsr/git-stunts__git-warp@20.0.0 is visible and its downloaded archive passes SHA-512 integrity verification.
    • npm artifact:746,153 compressed bytes,3,257,239 unpacked bytes,971 files; SHA-1 bcaf9a3a76530c3d4d00d5d5dbd6e959dcc5e47a, matching the source-bound reviewed archive. npm SHA-512: sha512-ANuhcXlMA2S4QJutSdN3EhlwSDl17geLmrAtkObiT1kb5VVOrCppgj371RBFmUweJbrdwAZTgvwv38eKCsSUIQ==. Remaining budget:13,847 compressed bytes,42,761 unpacked bytes,79 files; both byte measures above95% utilization, passing without a raised limit.
    • JSR archive integrity: sha512-5ymqgGWLLchpoaYCaOaDPMA2PRw3KsPp2OmN0QV/N+QFdGKMKu8mroeQK8NkJ78KE1VjPGbD0uBRe2PETjmoPg==.
    • Coverage: actual current release-source coverage recorded8,879 passing tests in821 passing files, plus two existing skipped tests in one file; all822 selected files accounted for, zero errors, ratchet unchanged. Normal push/prepack unit surface passed8,669 tests/785files with the same existing skips. These overlap and are not a unique-test sum. Main and tagged-source checks ran through the required Docker routes.
    • Registry closure artifact: release-closure-v20.0.0, receipt schema git-warp/release-closure@1, status verified, stage complete,720-second budget not exhausted. COPY-Docker consumer execution, evidence export and cleanup all completed. It verified the exact npm installation/integrity, root Runtime import, private-storage export firewall, installed CLI, registry signatures and dependency versions git-cas6.5.11/Plumbing3.3.2.
    • Tagged changelog, upgrade guidance, and staging/attachment contract.

    Evidence limits: the registry consumer did not re-execute advanced attachment operations or install and run the JSR representation. Attachment/advanced-path proof comes from the pre-publication installed tarball; registry closure independently binds the published npm bytes/identity and verifies the JSR archive. No new Windows or physical power-loss claim is made. The non-required CodeRabbit docstring advisory and two JSR dynamic-import analysis warnings remain disclosed; required gates and registry verification passed. Global coverage is not100%, and none of these checks proves absence of all defects.

    Went well

    1. Failure controls challenged the proposed explanation. Eager OOM controls, malformed persistence probes, actual kernel partial writes and cancellation/race tests exposed meaningful failure modes. Keep each control tied to the supported caller and exact source, not a mirrored implementation assertion.
    2. Issue ownership survived integration. Separate coherent PRs and ordinary merge commits preserved the attachment, compaction, descriptor, consumer and release boundaries. Both-parent file/tree proofs made additive resolutions independently reviewable.
    3. Consumer evidence crossed the package boundary. Actual tarballs, strict public type consumers and upstream published dependency checks caught problems source imports could not. Preserve artifact-to-source identity and public consumer verification as separate admission gates.
    4. Runtime truth constrained the claims. Legacy admission stayed narrow, strict modern identities remained strict, and preservation was accepted where retirement lacked a safe contract. The ownership model was clearly labeled as test-only specification evidence.
    5. The full scope inventory prevented silent slips. All milestone issues, historical dispositions and containers were examined rather than relying on a short must-ship list or a closed-state count. Reuse this categorical accounting when closing the next milestone.

    Improve next time

    1. Reconcile priority and milestone policy before release preparation. Global ASAP checks and stale umbrella text caused a late explicit decision. Add the observed contradiction to existing COOL IDEA: validate the release state machine #691's advisory validator acceptance, including paginated inventory and GitHub/Linear mismatch reporting; never silently relabel to make a guard pass.
    2. Audit current versus historical release language at the version change. A full push caught v19.1 current-signpost assertions and review caught unreleased v20 wording. Existing Docs-Version-Sync Pre-Commit Check #120/Docs Consistency Preflight #119 own version-literal and documentation consistency automation; append these concrete failure cases there rather than creating another scanner. Historical migration guidance must remain accepted.
    3. Validate image metadata and supported tools as well as source bytes. Workdir/user changes, missing openssl/rg and a dangling convenience symlink complicated otherwise exact COPY proofs. Include executable modes and symlink targets in source oracles, and exercise the documented named Dockerfile route. The alias proposal is narrowly scoped below.
    4. Make transfer setup verifiable for application consumers. Naming a refspec in docs is insufficient for routine team operation. One opt-in selected-lane configuration/diagnostic workflow should preserve source mappings and writer ownership and prove attachment bytes across independent repositories; fetching still requires Runtime close/reopen.
    5. Budget for asynchronous registries and manage actual artifacts. Npm accepted the upload before exposing it publicly; the approximately50-second visibility polling window expired despite unused aggregate budget. Follow-up Handle asynchronous npm publication within the release closure budget #956 must retain bounded verification and strict identity checks while accommodating processing. The actual published artifact has 13,847 compressed and 42,761 unpacked bytes left under its limits, both above 95% utilization. The existing report already flags headroom; preserve the final published receipt and review the next train's payload delta before adding packaging automation or raising limits. Do not duplicate the completed Audit residual JavaScript payload outside supported runtime import roots #908 unreachable-JavaScript audit or promise safe pruning of reachable functionality.

    Fallout issues

    Filed three independently mergeable follow-ups, assigned to James Ross in GitHub and Linear, with one label per required axis and release milestone v20.2.0. They remain available work; this retrospective does not activate a new train.

    Issue Outcome Linear Labels
    #954 Remove the unused dangling Dockerfile alias and guard retained build aliases, preserving supported named routes. FLY-273 type:bug, priority:next, status:available, area:tooling
    #955 Opt-in selected-lane Git configuration/diagnostics plus installed attachment transfer proof across independent repositories. Preserve source ref behavior and writer ownership; require Runtime close/reopen. FLY-274 type:feature, priority:next, status:available, area:sync
    #956 Handle asynchronous npm visibility within the existing aggregate closure budget, with deterministic failure controls and classified diagnostics. No republishing or relaxed identity checks. FLY-275 type:bug, priority:next, status:available, area:release

    Added the actual global-ASAP/later-milestone contradiction and missing-evidence controls to existing #691, rather than creating a duplicate validator. Current-version consistency remains owned by #120/#119; retrospective scaffolding by #690. Existing package headroom reporting remains authoritative; tight passing limits alone did not justify a duplicate pruning issue. The workflow's curated-release-notes automation remains open under #803; this release's manually curated synopsis does not complete that automation.

    No dependency edge was invented from common release ancestry. These follow-ups do not require completion of v21 recursive graph work. Their bodies state scope, exclusions, safe intermediate state, acceptance and Docker validation boundaries.

    Next release recommendation

    With public registry verification complete, record this retrospective and close #876 and the v20 milestone. Preserve the explicit v20 byte-attachment / v21 production-recursion boundary. Before activating the next train, review the planned v20.1 observation thesis and v21 retained-state prerequisites with their actual acceptance owners; a large roadmap or closed issue count is not proof of an executable dependency graph.

    Keep #819/#820/#821/#905 open in v21 at priority:next. Prioritize the supported sync workflow as a compatible, independently mergeable follow-up in its recorded v20.2 bucket; changing that target should be a visible planning decision. No new train is activated by this retrospective, and no unfinished recursive capability is represented as shipped in v20.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions