docs: record phased release verification
This commit is contained in:
@@ -17,10 +17,10 @@ Branch: `codex/phased-next-steps`
|
||||
| 9. Spline loft provenance | done | task09_spline_loft | this commit | approved after review-fix pass; no Critical/Important/Minor findings | digest e46ceba9; doc loft 10, kernel loft 18, UI 440, app 518; 228-step two-process RADV drive deterministic; exact exit-1 control; failed-preview retry latch verified |
|
||||
| 10. L3 rod holder | done | task10_l3_rod_holder | this commit | approved after review-fix pass; no Critical/Important/Minor findings | public-command oracle + 261-step writer/46-step reader; complete two-pair RADV positive and exact exit-1 negative; imported historical-edit provenance regression focused/release green; first full gate failed at that now-fixed regression, second stopped partial by user-approved shortened-testing policy; no full-gate green claimed; source digest b9272299 |
|
||||
| 11. Performance measurement | done | task11_performance | 582ee82 | approved after review-fix pass; no remaining findings | focused CLI contracts green; exact release artifact bd3d3834; L3 measured bottleneck about 220 ms; no full gate under shortened policy |
|
||||
| 12. CI/software renderer | done | task12_ci_renderer | 064e6b7 | approved after review-fix pass; no remaining findings | shared 143-step adapter selection; Python 7/7 and focused golden green; 13.45s representative RADV positive/exact exit-1 control; lavapipe absent and explicitly unverified |
|
||||
| 12. CI/software renderer | done | task12_ci_renderer | 064e6b7 | approved after review-fix pass; no remaining findings | shared 143-step adapter selection at Task 12, now 144 with Task 15 packaging row; Python 7/7 and focused golden green; 13.45s representative RADV positive/exact exit-1 control; lavapipe absent and explicitly unverified |
|
||||
| 13. C++ sanitizer evidence | done with explicit runtime boundary | task13_sanitizers | 3370872 | approved after one documentation correction | 14 generated cxxbridge warnings; no project-owned warning; one sanitizer link attempt failed before tests because runtimes were omitted under -nodefaultlibs; no sanitizer-clean claim or suppression |
|
||||
| 14. Vendored static OCCT | done | task14_static_occt | 9eae002 | approved after review-fix pass; no remaining findings | official V7_9_3 at a016080b; 26 static archives built once; app/worker have no libTK dynamic deps; 236-step RADV workflow deterministic with STEP/STL/reopen |
|
||||
| 15. AppImage | done | task15_appimage | 0fb96da + 2d31698 auditor fix | auditor/integration fix approved; no remaining findings | artifact f02aea20 at 0fb96da; corrected structural/dependency smoke green; frame-0 RADV readback exit 0 and nonblank; same-artifact bounded worker-ready evidence with no survivor; no duplicate driven workflows under shortened policy |
|
||||
| 16. Integrated verification | pending | controller | — | pending | — |
|
||||
| 16. Integrated verification | source freeze ready; final gate pending | controller | — | whole-branch source review approved; no Critical/Important findings | roadmap reconciled; one complete detached gate and two staged package workflows remain |
|
||||
|
||||
The MikroB dashboard was unavailable at `localhost:3420`; this branch-local ledger is the execution authority. No dashboard database is mutated directly.
|
||||
|
||||
@@ -30,6 +30,37 @@ pointer or keyboard input into the native Wayland window.
|
||||
Neither release was removed. The current alpha still dynamically resolves system
|
||||
OCCT and is not yet the portable AppImage.
|
||||
|
||||
## Phased release candidate — source-freeze status 2026-09-15
|
||||
|
||||
The managed launcher is deliberately still unchanged at the `0.0.3-alpha`
|
||||
release above. The candidate branch has completed focused review and acceptance
|
||||
for generation-owned previews, imported-topology refusals, atomic saved
|
||||
camera/section restoration, exact spline sweeps and ruled lofts, the revised L3
|
||||
rod holder, representative L2–L4 performance measurement, shared local/CI gate
|
||||
selection, static OCCT linkage, and AppImage packaging.
|
||||
|
||||
The one Task 15 certification artifact was built from packaging revision
|
||||
`0fb96da2668a7bf75b3044bb15f9e98bc373e8fa` and has SHA-256
|
||||
`f02aea202b32c6aa91f4cc61712f662f3e036090848dc98184d4921cd53c1f35`.
|
||||
It passed corrected structural/dependency smoke, bounded bundled-worker
|
||||
startup/cleanup, and a nonblank 1280×720 RADV native readback. It is evidence for
|
||||
the packaging design, not the install candidate: the release AppImage and
|
||||
managed binaries must be rebuilt from the final source commit after the single
|
||||
complete gate passes.
|
||||
|
||||
Known evidence boundaries remain explicit: this host has no lavapipe ICD, so no
|
||||
software-renderer tolerance was measured; the ASan/UBSan attempt failed to link
|
||||
before tests, so no sanitizer-clean claim exists; and native readback proves
|
||||
launch/render rather than native Wayland pointer or keyboard interaction.
|
||||
|
||||
After the final detached gate, the candidate is staged with the AppImage's exact
|
||||
static-OCCT app/worker pair and only the release-smoke and L3 workflows are
|
||||
repeated against that pair. The complete gate already covers the narrower
|
||||
preview, saved-view, and file-command workflows at the same source revision.
|
||||
Only then may `scripts/install-local.sh` atomically advance `current`; it must
|
||||
preserve the release above as `previous`. The live launcher symlinks and
|
||||
`.vernier-release` manifest are authoritative after that post-freeze operation.
|
||||
|
||||
## Previous release record — 2026-09-10
|
||||
|
||||
Installed: `8dfd8a4309c7bfd5afbe4794ce21bb2c2d6e650b`, the merge of main into the
|
||||
|
||||
@@ -40,27 +40,9 @@ and exported geometry are the acceptance path.
|
||||
`a61054391048090b17e1e34b8467f5eb705acacf112c08ed5840119b992a2d9b`
|
||||
for `vernier-worker`.
|
||||
|
||||
## Verified gaps
|
||||
## Phase 2 — implemented and focused-verified
|
||||
|
||||
- Disposable previews do not yet have one generation identity and invalidation
|
||||
rule across every feature, body tool, sketch-point, and push/pull path.
|
||||
- Imported-body capabilities do not yet reach every readiness surface, so some
|
||||
unsupported parametric edits can be refused only after dispatch.
|
||||
- Saved camera and section state do not yet have a paired fresh-process,
|
||||
validate-then-commit restoration gate.
|
||||
- Exact open spline paths, exact closed cubic-spline profiles, and exact spline
|
||||
sections are not yet admitted across the complete document, OCCT, shell,
|
||||
persistence, and export path.
|
||||
- Generated `cxxbridge` `-Wmaybe-uninitialized` warnings remain open. They are
|
||||
not evidence of a runtime defect and require sanitizer-backed investigation.
|
||||
- The current release dynamically resolves system OCCT. It is a managed local
|
||||
alpha, not the portable AppImage promised by the release design.
|
||||
- Representative L2–L4 latency, memory, CI parity, and software-renderer golden
|
||||
tolerance still need the measurements specified below.
|
||||
|
||||
## Phase 2
|
||||
|
||||
Close daily-use reliability gaps before extending modeling scope:
|
||||
The daily-use reliability work is complete in the release candidate:
|
||||
|
||||
1. Give every disposable preview a monotonically increasing generation and one
|
||||
discard path, including failure, cancel, apply, history, and file transitions.
|
||||
@@ -69,13 +51,24 @@ Close daily-use reliability gaps before extending modeling scope:
|
||||
3. Make saved-view and saved-section restoration atomic, migration-backed, and
|
||||
proven across separate writer and reader processes.
|
||||
|
||||
Each change must preserve authored document and naming state on refusal or
|
||||
cancel, include a realistic positive control, and finish with driven geometry and
|
||||
fresh-process persistence evidence.
|
||||
Generation-owned previews cover feature edits, body tools, spline-point drags,
|
||||
and the existing push/pull lifecycle. Stale, failed, cancelled, applied, history,
|
||||
and file-transition replies cannot replace current geometry; refusal and cancel
|
||||
preserve authored document and naming bytes. Imported topology remains available
|
||||
for inspection and supported whole-body operations, while every persistent
|
||||
face/edge operation is capability-filtered and revalidated before dispatch.
|
||||
Saved cameras and sections persist plane, signed offset, flip, enabled/cutaway,
|
||||
and target body through atomic validation and separate writer/reader processes.
|
||||
The conservative document-directory lock is unchanged.
|
||||
|
||||
## Phase 3
|
||||
The focused real-shell workflows cover rapid parameter changes,
|
||||
preview/apply/cancel, actionable refusals, undo/redo, save/reopen, and exported
|
||||
geometry. They remain subject to the one final integrated gate described under
|
||||
Verified gaps below.
|
||||
|
||||
Make exact spline sweeps usable through the real shell:
|
||||
## Phase 3 — implemented and focused-verified
|
||||
|
||||
Exact spline sweeps are usable through the real shell:
|
||||
|
||||
1. Admit exact open planar fit-point and cubic spline paths through document and
|
||||
OCCT validation, without replacing curves with polylines.
|
||||
@@ -84,17 +77,27 @@ Make exact spline sweeps usable through the real shell:
|
||||
3. Admit exact closed cubic-spline profiles while keeping fit-point splines
|
||||
open-only unless their document representation gains an explicit closed form.
|
||||
|
||||
Spline-plus-guide remains a named refusal: the measured auxiliary-spine route can
|
||||
Open planar fit-point and cubic paths, existing closed profiles, and exact closed
|
||||
cubic-spline profiles are admitted through document validation, OCCT geometry,
|
||||
history naming, selection, orientation/scale, disposable preview, apply,
|
||||
upstream editing, save/reopen, and STEP/STL export. Fit-point and open-cubic
|
||||
spline profiles remain explicitly refused; no polygonal fallback is used.
|
||||
|
||||
Spline-plus-guide remains a named refusal: the measured auxiliary-spline route can
|
||||
hang, and a single spline edge can contain internal C0 corners. Phase 3 does not
|
||||
promise smooth guided lofts, G1/G2 continuity, periodic lofts, or arbitrary 3D
|
||||
spline drawing.
|
||||
|
||||
## Phase 4
|
||||
## Phase 4 — implemented and focused-verified
|
||||
|
||||
Add exact spline-section ruled lofts with deterministic section orientation and
|
||||
OCCT-history-derived provenance, then complete the 2026-09-14 L3 rod-holder gate.
|
||||
Exact spline-section ruled lofts with deterministic section orientation and
|
||||
OCCT-history-derived provenance have landed with the 2026-09-14 L3 rod-holder gate.
|
||||
|
||||
The L3 acceptance is exactly: an exact spline sweep, a spline-section ruled loft,
|
||||
The ruled loft accepts exact fit-point and cubic-spline sections while preserving
|
||||
the equal authored-curve-count rule. Section pairing follows OCCT history after
|
||||
compatibility reorientation.
|
||||
|
||||
The completed L3 acceptance is exactly: an exact spline sweep, a spline-section ruled loft,
|
||||
an edge fillet, a direct edit, and an upstream dimension change, built through the
|
||||
real shell and checked after save/reopen and STEP/STL export. This supersedes the
|
||||
older guided-rail/delete-face L3 composition. Delete-face remains a separate
|
||||
@@ -105,20 +108,42 @@ The Phase 3/4 boundary is deliberate: Phase 4 adds ruled lofts from exact spline
|
||||
sections, not smooth guided lofts, G1/G2 continuity, periodic lofts, or arbitrary
|
||||
3D spline drawing.
|
||||
|
||||
## Phase 5
|
||||
## Phase 5 — measurement and packaging complete; final integration pending
|
||||
|
||||
Strengthen performance and release confidence after L3:
|
||||
Completed and focused-verified work:
|
||||
|
||||
1. Measure cold compile, preview, apply, tail-edit latency, and peak RSS on
|
||||
representative L2, L3, and multi-body L4 fixtures in fresh processes.
|
||||
2. Make local and CI acceptance consume one machine-readable gate manifest, then
|
||||
calibrate software-renderer golden tolerances only from actual measurements.
|
||||
3. Inventory the generated C++ warnings and run the relevant OCCT paths under
|
||||
ASan/UBSan before suppressing or fixing anything.
|
||||
4. Pin and build OCCT for static release linkage, then build and certify a
|
||||
reproducible VernierCAD AppImage containing both app and worker.
|
||||
5. Run the complete integrated gate and staged installed-worker workflows before
|
||||
moving the managed launcher again; retain the rollback release.
|
||||
1. Fresh-process L2, L3, and L4 measurements now include cold, preview, apply,
|
||||
tail-edit, peak RSS, and topology workload data. L3 is the measured bottleneck
|
||||
at about 220 ms for preview/apply; no speculative optimization was made.
|
||||
2. Local and CI acceptance consume one validated 144-command-per-adapter
|
||||
manifest with exact expected exits, determinism checks, and negative controls.
|
||||
RADV goldens are byte-exact at a zero-pixel/zero-channel-delta budget.
|
||||
3. The 14 current `-Wmaybe-uninitialized` diagnostics are generated `cxxbridge`
|
||||
warnings, not project-owned `facade.cpp` diagnostics. They were not suppressed.
|
||||
4. Official OCCT V7_9_3 is pinned at `a016080b`; a static 26-toolkit closure built,
|
||||
linked, and passed a cross-process save/reopen plus STEP/STL workflow with no
|
||||
dynamic OCCT dependency.
|
||||
5. A reproducible AppImage containing app, worker, resources, licenses, fonts,
|
||||
and its dependency closure passed structural/dependency smoke, bounded bundled
|
||||
worker startup/cleanup, and native nonblank RADV readback.
|
||||
|
||||
## Verified gaps
|
||||
|
||||
- At this source-freeze checkpoint, the release candidate has not yet completed
|
||||
its single final clean integrated gate, final-SHA AppImage rebuild, staged
|
||||
installed-worker smoke, or managed-launcher switch. The installed release stays
|
||||
at `c111f856929f6c6370cb4ff5cd094bdb39f699f2` until those checks pass.
|
||||
- Lavapipe is absent from this host. Software-renderer execution, cross-adapter
|
||||
drift, and a measured software PNG tolerance remain unverified; no RADV budget
|
||||
is presented as a software-renderer budget.
|
||||
- The single ASan/UBSan attempt stopped at link time because Rust's
|
||||
`-nodefaultlibs` command omitted the sanitizer runtimes. No sanitizer test ran,
|
||||
so there is no sanitizer-clean claim.
|
||||
- The measured L3 rebuild is not internally profiled or optimized, and the
|
||||
measurements are one warm-machine baseline rather than a cross-machine SLO.
|
||||
- Native readback verifies launch/render, not native pointer or keyboard input on
|
||||
this Wayland session. Driven egui input plus exported geometry remains the
|
||||
interaction oracle.
|
||||
|
||||
## Deliberate exclusions
|
||||
|
||||
|
||||
@@ -945,11 +945,11 @@ Expected: the manifest revision equals the detached worktree's exact source comm
|
||||
- Consumes: all task commits and phase evidence.
|
||||
- Produces: final full-gate report, clean AppImage certification, managed local release with rollback, and roadmap statuses backed by exact evidence.
|
||||
|
||||
- [ ] **Step 1: Request whole-branch review before freezing the release source**
|
||||
- [x] **Step 1: Request whole-branch review before freezing the release source**
|
||||
|
||||
Review the immutable diff from `c111f856929f6c6370cb4ff5cd094bdb39f699f2` to current HEAD for spec compliance, preview/naming atomicity, imported-body authority, exact spline geometry, provenance, negative controls, release reproducibility, and exclusions. Resolve every Critical and Important finding and rerun the affected tests. Rebuild the AppImage after any source change.
|
||||
|
||||
- [ ] **Step 2: Reconcile roadmap status and commit the final source**
|
||||
- [x] **Step 2: Reconcile roadmap status and commit the final source**
|
||||
|
||||
Mark only evidenced work complete. Keep any failed or unavailable software-renderer/AppImage environment check in `Verified gaps` with its exact blocker and never turn it into a success claim.
|
||||
|
||||
@@ -973,7 +973,7 @@ Expected: exit 0; all positive and negative controls behave as declared.
|
||||
|
||||
- [ ] **Step 4: Rebuild the AppImage and stage the local release from that same SHA**
|
||||
|
||||
In the detached worktree, build and certify the static-OCCT AppImage again, then build app and worker from the exact same final SHA and install them under an isolated prefix. Run `file-commands-actual`, `local-linux-release`, `preview-latest-only`, `saved-view-section-roundtrip`, `spline-sweep`, and `l3-rod-holder` with the staged installed worker, then run the native launcher with `VERNIER_READBACK`.
|
||||
In the detached worktree, build and certify the static-OCCT AppImage again, then extract its exact app/worker pair into an isolated release directory. Under the user-requested shortened policy, do not repeat all six narrower workflows already covered by the complete gate at this same source SHA. Run only `local-linux-release` as the broad save/reopen/STEP/STL release smoke and the `l3-rod-holder` positive/negative fresh-process pair as the highest-risk exact-spline/naming workflow, both with the staged bundled worker, then run the staged native launcher with `VERNIER_READBACK`.
|
||||
|
||||
- [ ] **Step 5: Switch the managed launcher only after all detached and staged checks pass**
|
||||
|
||||
|
||||
Reference in New Issue
Block a user