fix(v1): harden legacy maintenance runtime - #1
Conversation
DF-wu
left a comment
There was a problem hiding this comment.
Self-review completed for maintenance/v1 head 6005264.
Reviewed the bounded legacy WebSocket/HTTP paths, per-connection recognition isolation, authentication ordering and redaction, subtitle carry fix, security-sensitive dependency updates, Ubuntu/Windows Python 3.10/3.12 matrix, and the maintenance/security/release documentation. The duplicate maintenance matrices and documented dependency audits are green, with no remaining blocking backport finding.
The model-backed, known-audio, accelerator, disposable-image, and real Windows desktop checks remain mandatory before cutting a legacy release.
Disposition: this is a standing comparison PR and must not be merged into immutable archive/v1-legacy. Continue fork-owned best-effort maintenance and releases directly from maintenance/v1 under fork-v1.* tags; this is not an upstream-supported release line.
DF-wu
left a comment
There was a problem hiding this comment.
Self-review completed for maintenance/v1 head 9090277.
Reviewed the Server/Client ownership rewrite, source-only RC notes, Compose build semantics, environment defaults, and every remaining capswriter-offline-server:latest reference. v1 now builds its own local image from the tagged source and cannot silently consume v2 latest. The Windows client claim is limited to the upstream-era start_client.py source; no v2 Web/CLI/TUI/universal-package or unqualified Windows binary is advertised.
Local Python 3.12 evidence is 45/45 tests plus compile, Compose, shell, and diff checks. Both duplicate hosted Ubuntu/Windows × Python 3.10/3.12 matrices are green at this exact head.
No blocking finding remains for a source-only fork-v1.0.0-rc.1 pre-release. The standing comparison PR must remain open and must not merge into immutable archive/v1-legacy.
DF-wu
left a comment
There was a problem hiding this comment.
Self-review completed for maintenance/v1 head efd24cb1bd1ea5e624561dd869aaea9c5d5c02a5.
Reviewed the legacy Server/API versus upstream-era start_client.py Client boundary, Compose container-bind/host-publish separation, source-only image policy, mutable hotword exclusions (including hot-rectify.txt), bilingual HTTP API guides, and precise release evidence wording. The English guide now has a working counterpart and the README no longer points at absent local changelog/license files.
Local evidence is 51/51 isolated tests, compile checks, entrypoint syntax, Compose validation, selected bilingual link validation, and clean diff checks. Both duplicate hosted push and pull-request matrices are green at this exact head (8/8 checks). The exact hosted workflow runs prove the matrix tests; Compose and entrypoint validation are limited to the Ubuntu 24.04 / Python 3.10 validation job as documented.
No blocking finding remains for a source-only fork-v1.0.0-rc.1 pre-release. Keep this standing comparison PR open and do not merge it into archive/v1-legacy. Release directly from this maintenance/v1 commit; model-backed, image, accelerator, and real Windows qualification remain explicitly required before a stable claim.
Summary
capswriter-offline-v1-local:source, passes explicit HTTP settings into the container, and never defaults to v2latest.hot-server.txt,hot.txt,hot-rule.txt, andhot-rectify.txtout of local image layers.Release boundary
fork-v1.0.0-rc.1is a source-only pre-release candidate from this exactmaintenance/v1head.start_client.pydesktop source.archive/v1-legacy.Local verification on
efd24cb1bd1ea5e624561dd869aaea9c5d5c02a5compileallfor supported Server/Client entry points passedbash -n docker/server/entrypoint.shpassedgit diff --checkpassedThe hosted push and pull-request matrices are the release evidence for this exact head. Every matrix leg runs the maintenance tests and compile checks; Compose and entrypoint validation run only in the Ubuntu 24.04 / Python 3.10 validation job.
Stable-release qualification still required