From 551136be2886d3d614181e564c66730384d74c4f Mon Sep 17 00:00:00 2001 From: Reidar Date: Sun, 9 Aug 2026 02:17:19 +0200 Subject: [PATCH] Promote v1.4.5 to published release with cask handoff Append v1.4.4 and v1.3.2 to historicalReleases (ascending), promote v1.4.5 (build 13, tag ffd6fdc1..., commit 174dcd28..., CI 31283125895, Release 31284620552, SHA 13fa763c...) as publishedRelease with signed-verified tag trust, advance the Homebrew cask to the released checksum, and refresh current-release prose across the docs and issue templates. Installed release-mode review and manual hardware compatibility remain pending. --- .../ISSUE_TEMPLATE/hardware-validation.yml | 2 +- .github/ISSUE_TEMPLATE/release-trust.yml | 6 +-- .github/release-manifest.json | 52 ++++++++++--------- AGENTS.md | 2 +- Casks/vifty.rb | 4 +- README.md | 16 +++--- SECURITY.md | 11 ++-- SUPPORT.md | 8 +-- docs/auto-update.md | 10 ++-- docs/compatibility.md | 8 +-- docs/competitive-analysis.md | 10 ++-- docs/release-status.md | 20 +++---- docs/release.md | 10 ++-- docs/support-triage.md | 4 +- docs/trust-model.md | 10 ++-- 15 files changed, 89 insertions(+), 84 deletions(-) diff --git a/.github/ISSUE_TEMPLATE/hardware-validation.yml b/.github/ISSUE_TEMPLATE/hardware-validation.yml index 780de4d6..13af10e6 100644 --- a/.github/ISSUE_TEMPLATE/hardware-validation.yml +++ b/.github/ISSUE_TEMPLATE/hardware-validation.yml @@ -43,7 +43,7 @@ body: id: install-source attributes: label: Install source - description: How did you install this build? For v1.1.1, prefer Source build from tag or Source-first unsigned-dev zip. For current main/local builds, choose Local ad-hoc build with the exact source SHA. Choose notarized or Homebrew only for an exact published trusted-binary artifact such as v1.4.4. + description: How did you install this build? For v1.1.1, prefer Source build from tag or Source-first unsigned-dev zip. For current main/local builds, choose Local ad-hoc build with the exact source SHA. Choose notarized or Homebrew only for an exact published trusted-binary artifact such as v1.4.5. options: - Source build from tag - Source-first unsigned-dev zip diff --git a/.github/ISSUE_TEMPLATE/release-trust.yml b/.github/ISSUE_TEMPLATE/release-trust.yml index bce483f2..a8e83785 100644 --- a/.github/ISSUE_TEMPLATE/release-trust.yml +++ b/.github/ISSUE_TEMPLATE/release-trust.yml @@ -10,7 +10,7 @@ body: Please collect read-only evidence. Do not bypass Gatekeeper, edit the cask SHA manually, disable verifier signature/notarization checks, or run fan-write smoke tests to diagnose a release-trust issue. - Vifty v1.4.4 build 12 is the current arm64-only Developer ID release. Its signed/notarized GitHub Release artifact and matching Homebrew cask checksum pass the release-level verifier as recorded in .github/release-manifest.json. Exact-build installed release review and manual Fixed/Curve/Auto validation remain pending for v1.4.4; the historical v1.3.2 build 7 holds passed installed and hardware claims on MacBookPro18,1, and neither result transfers to another build or model. Report any local mismatch with those facts here. A source tag, passing CI run, unsigned-dev convenience build, local signing smoke build, or CI artifact alone is not a trusted public binary release. + Vifty v1.4.5 build 13 is the current arm64-only Developer ID release. Its signed/notarized GitHub Release artifact and matching Homebrew cask checksum pass the release-level verifier as recorded in .github/release-manifest.json. Exact-build installed release review and manual Fixed/Curve/Auto validation remain pending for v1.4.5; the historical v1.3.2 build 7 holds passed installed and hardware claims on MacBookPro18,1, and neither result transfers to another build or model. Report any local mismatch with those facts here. A source tag, passing CI run, unsigned-dev convenience build, local signing smoke build, or CI artifact alone is not a trusted public binary release. The published v1.1.0 source/unsigned-dev release has a known helper-unreachable issue that was fixed by v1.1.1. Do not retag v1.1.0 or replace its unsigned-dev assets with a main build; report it here and use the v1.1.1 source-first hotfix path. @@ -19,7 +19,7 @@ body: attributes: label: Release version description: Which Vifty release is affected? - placeholder: e.g. 1.4.4 + placeholder: e.g. 1.4.5 validations: required: true @@ -83,7 +83,7 @@ body: brew install --cask vifty git fetch origin main --tags scripts/check-release-readiness.sh --mode source-first --version 1.1.1 --repo Reedtrullz/Vifty --json - scripts/check-release-readiness.sh --mode developer-id --version 1.4.4 --repo Reedtrullz/Vifty --require-source-ref v1.4.4 --json + scripts/check-release-readiness.sh --mode developer-id --version 1.4.5 --repo Reedtrullz/Vifty --require-source-ref v1.4.5 --json scripts/verify-release-artifact.sh --team-id "$APPLE_TEAM_ID" validations: required: true diff --git a/.github/release-manifest.json b/.github/release-manifest.json index 228c727d..66387d6a 100644 --- a/.github/release-manifest.json +++ b/.github/release-manifest.json @@ -41,41 +41,45 @@ "reviewReport": "docs/validation-reports/2026-07-14-v1.3.2-macbookpro18-supported/review-result.json", "attestation": "docs/validation-reports/2026-07-14-v1.3.2-macbookpro18-supported/manual-smoke-attestation.md" } + }, + { + "version": "1.4.4", + "build": 12, + "tag": "v1.4.4", + "sourceCommit": "0ac7842483a602a30900671904f76fd7b06e2370", + "sourceCIRunID": 31252163922, + "releaseWorkflowRunID": 31253285103, + "artifact": "Vifty-v1.4.4.zip", + "checksumAsset": "Vifty-v1.4.4.zip.sha256", + "artifactSummary": "Vifty-v1.4.4-artifact-summary.json", + "releaseChecklist": "Vifty-v1.4.4-release-checklist.md", + "sha256": "d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f", + "artifactTrust": "passed", + "signingTrust": "developer-id-notarized", + "tagTrust": "signed-verified", + "installedReleaseReview": "pending", + "manualCompatibility": "pending", + "manualCompatibilityScope": null } ], "publishedRelease": { - "version": "1.4.4", - "build": 12, - "tag": "v1.4.4", - "sourceCommit": "0ac7842483a602a30900671904f76fd7b06e2370", - "sourceCIRunID": 31252163922, - "releaseWorkflowRunID": 31253285103, - "artifact": "Vifty-v1.4.4.zip", - "checksumAsset": "Vifty-v1.4.4.zip.sha256", - "artifactSummary": "Vifty-v1.4.4-artifact-summary.json", - "releaseChecklist": "Vifty-v1.4.4-release-checklist.md", - "sha256": "d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f", - "artifactTrust": "passed", - "signingTrust": "developer-id-notarized", - "tagTrust": "signed-verified", - "installedReleaseReview": "pending", - "manualCompatibility": "pending", - "manualCompatibilityScope": null - }, - "candidate": { "version": "1.4.5", "build": 13, "tag": "v1.4.5", + "sourceCommit": "174dcd28a343de7f797d682d02c0f70e26b72c2e", + "sourceCIRunID": 31283125895, + "releaseWorkflowRunID": 31284620552, "artifact": "Vifty-v1.4.5.zip", "checksumAsset": "Vifty-v1.4.5.zip.sha256", "artifactSummary": "Vifty-v1.4.5-artifact-summary.json", "releaseChecklist": "Vifty-v1.4.5-release-checklist.md", - "sha256": null, - "artifactTrust": "pending", - "signingTrust": "pending", - "tagTrust": "signed-required", + "sha256": "13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5", + "artifactTrust": "passed", + "signingTrust": "developer-id-notarized", + "tagTrust": "signed-verified", "installedReleaseReview": "pending", "manualCompatibility": "pending", "manualCompatibilityScope": null - } + }, + "candidate": null } diff --git a/AGENTS.md b/AGENTS.md index 0af35c2d..269a44ad 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -158,7 +158,7 @@ ViftyCore is the shared library consumed by Vifty app, ViftyDaemon, ViftyHelper, 16. **Protected/system fan mode is explicit** — SMC mode value `3` represents macOS/System-managed control. If direct manual mode writes are rejected and `Ftst` exists, helper writes may use a guarded unlock/retry path; restoring Auto should return `Ftst` to `0` when available. 17. **Agent JSON is a contract** — capabilities, read-only audit export, readiness diagnostics, command errors, and rate-limit responses must stay machine-readable. Preserve policy fields, source schema paths, bundled schema resource paths, schema ID references, `policySource`, `daemonStatusAvailable`, `policyStatusAvailable`, `supportsForceRetry`, `runLifecycle`, readiness check IDs, state strings, `recommendedAgentAction`, `recommendedRecoveryAction`, `safeToRequestCooling`, `safeToProceed`, `readOnly`, `coolingCommandsRun`, and `retryAfterSeconds` across Codable and XPC dictionary coding. `capabilities --json` must remain parseable when daemon status is unavailable, but it must fail closed with `exitCodes.unavailable`, `policyStatusAvailable: false`, and a disabled fallback policy. Agents must not trust `policy.*` duration/RPM limits unless `policyStatusAvailable` is true. 18. **Release XPC hardening is build-configured** — local builds leave `VIFTY_XPC_ALLOWED_TEAM_ID` empty for ad-hoc signing; release builds should set it so the daemon requires matching signing identifiers and the configured TeamID. -19. **Separate source-first from trusted binaries** — `v1.1.1` remains the immutable source-first hotfix and `v1.1.0` is superseded; neither may be retagged or refreshed from later source. `v1.4.4` is the published Developer ID release; its exact public artifact, cask checksum, release evidence, notarization, stapling, TeamID, and Gatekeeper checks passed. Signed-helper parity, installed release-mode review, explicit Auto restoration, and manual Fixed/Curve hardware compatibility remain separate claims for the exact `v1.4.4` binary; prior-version proof does not transfer. The historical `v1.3.2` release holds passed installed and hardware claims on `MacBookPro18,1` only; the supervised `v1.3.1` smoke exposed an in-flight Curve-to-Auto race and is not compatibility proof. Do not flatten source-first, local-build, or prior-version proof into current trusted-binary claims. Trusted binary releases use `.github/workflows/release.yml`. +19. **Separate source-first from trusted binaries** — `v1.1.1` remains the immutable source-first hotfix and `v1.1.0` is superseded; neither may be retagged or refreshed from later source. `v1.4.5` is the published Developer ID release; its exact public artifact, cask checksum, release evidence, notarization, stapling, TeamID, and Gatekeeper checks passed. Signed-helper parity, installed release-mode review, explicit Auto restoration, and manual Fixed/Curve hardware compatibility remain separate claims for the exact `v1.4.5` binary; prior-version proof does not transfer. The historical `v1.4.4` release cannot migrate a v1.3.2 install on macOS 26, and the historical `v1.3.2` release holds passed installed and hardware claims on `MacBookPro18,1` only; the supervised `v1.3.1` smoke exposed an in-flight Curve-to-Auto race and is not compatibility proof. Do not flatten source-first, local-build, or prior-version proof into current trusted-binary claims. Trusted binary releases use `.github/workflows/release.yml`. 20. **Diagnostics are read-only** — `viftyctl diagnose` must not prepare leases, restore Auto, or perform SMC writes. It may read daemon snapshots, thermal pressure, and agent-control status only. 21. **Run command preflight comes before cooling** — `viftyctl run` must resolve/validate the child command before preparing a lease, then execute the resolved path directly only if prepare returns a matching active lease. While the child is active, handled terminal/session signals should be forwarded to the child so the wrapper can still restore Auto before exiting. Auto-restore failures after child exit must be visible to agents through stderr and a nonzero wrapper exit when the child itself succeeded. 22. **Local persistence is private by default** — agent-control stores, curve profiles/backups, and manual-control markers must keep directories at `0o700` and files at `0o600`, including when tightening permissions on legacy files from older builds. diff --git a/Casks/vifty.rb b/Casks/vifty.rb index b50dc188..8fa1241b 100644 --- a/Casks/vifty.rb +++ b/Casks/vifty.rb @@ -1,6 +1,6 @@ cask "vifty" do - version "1.4.4" - sha256 "d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f" + version "1.4.5" + sha256 "13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5" url "https://github.com/Reedtrullz/Vifty/releases/download/v#{version}/Vifty-v#{version}.zip" name "Vifty" diff --git a/README.md b/README.md index 710950b9..a9c6c368 100644 --- a/README.md +++ b/README.md @@ -2,11 +2,11 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. @@ -77,9 +77,9 @@ The checked-in [v1.3.2 MacBookPro18,1 report](docs/validation-reports/2026-07-14 ### Current release trust status -Vifty `v1.4.4` is the current published Developer ID release. Its immutable annotated tag object is `8c364558f4e0e9a75c129e4d08adf470b7f32bec` at commit `0ac7842483a602a30900671904f76fd7b06e2370`, source CI run `31252163922` passed, signed/notarized Release run `31253285103` passed, and the canonical zip, checksum, verifier summary, and release checklist are published at the [v1.4.4 GitHub Release](https://github.com/Reedtrullz/Vifty/releases/tag/v1.4.4). +Vifty `v1.4.5` is the current published Developer ID release. Its immutable annotated tag object is `ffd6fdc11a77b460ce1e629b1ec43f3b7ebf582e` at commit `174dcd28a343de7f797d682d02c0f70e26b72c2e`, source CI run `31283125895` passed, signed/notarized Release run `31284620552` passed, and the canonical zip, checksum, verifier summary, and release checklist are published at the [v1.4.5 GitHub Release](https://github.com/Reedtrullz/Vifty/releases/tag/v1.4.5). -The exact public zip and the checked-in cask both resolve to SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. The publication workflow summary records that this exact artifact passed bundle-version, required-executable and bundled-schema, Developer ID TeamID, LaunchDaemon allowlist, stapling, and Gatekeeper checks without skip flags. This is release evidence, not a claim that a fresh verifier run has succeeded on every current host. The exact installed public `v1.3.2` build also passed release-mode review and human-supervised Fixed → Auto → Curve → Auto validation on `MacBookPro18,1`; see the [release review](docs/validation-reports/2026-07-14-v1.3.2-macbookpro18-release/review-result.json) and [hardware attestation](docs/validation-reports/2026-07-14-v1.3.2-macbookpro18-supported/manual-smoke-attestation.md). Installed-binary parity, explicit Auto restoration, and manual hardware compatibility are now separately reviewed for that exact build on `MacBookPro18,1`; they are not broad model-family or future-release proof, and installed release-mode review and manual hardware compatibility for `v1.4.4` remain pending and are not claimed. `v1.1.1` remains the published source-first fallback; see [docs/release-status.md](docs/release-status.md). +The exact public zip and the checked-in cask both resolve to SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. The publication workflow summary records that this exact artifact passed bundle-version, required-executable and bundled-schema, Developer ID TeamID, LaunchDaemon allowlist, stapling, and Gatekeeper checks without skip flags. This is release evidence, not a claim that a fresh verifier run has succeeded on every current host. The exact installed public `v1.3.2` build also passed release-mode review and human-supervised Fixed → Auto → Curve → Auto validation on `MacBookPro18,1`; see the [release review](docs/validation-reports/2026-07-14-v1.3.2-macbookpro18-release/review-result.json) and [hardware attestation](docs/validation-reports/2026-07-14-v1.3.2-macbookpro18-supported/manual-smoke-attestation.md). Installed-binary parity, explicit Auto restoration, and manual hardware compatibility are now separately reviewed for that exact build on `MacBookPro18,1`; they are not broad model-family or future-release proof, and installed release-mode review and manual hardware compatibility for `v1.4.5` remain pending and are not claimed. `v1.1.1` remains the published source-first fallback; see [docs/release-status.md](docs/release-status.md). The immutable `v1.1.1` source tag is `a82f2237ff39c24a6b366dca8f95a17ee54fd972`. Later `main` commits may contain post-release hardening, but they are not part of the published `v1.1.1` source release unless a future release is cut. @@ -87,7 +87,7 @@ An optional `Vifty-v1.1.1-unsigned-dev.zip` convenience app is attached to the G Superseded release: the published `v1.1.0` source/unsigned-dev release predates helper-install hardening and may leave the app showing "Fan helper unreachable" after update. Do not retag `v1.1.0` or silently replace its assets; use the `v1.1.1` source-first hotfix release instead. -The exact public `v1.3.2` binary could not gain the update checker retroactively. The exact public `v1.4.4` binary contains the advisory release-availability checker but no executable downloader or in-place installer, and must be installed manually. Eligible Developer ID builds check GitHub's fixed latest-release endpoint at most daily, with an opt-out, and open the matching fixed tag page through **Update to latest version**. This validates availability metadata and expected filenames only; it does not verify archive bytes, checksum contents, a signed tag, or notarization. Local ad-hoc, CI, source-first, and unsigned-dev builds make no update requests. This is a browser handoff only: Vifty does not download executable assets, silently replace the app, or yet provide a Sparkle installer. See [docs/auto-update.md](docs/auto-update.md). +The exact public `v1.3.2` binary could not gain the update checker retroactively. The exact public `v1.4.5` binary contains the advisory release-availability checker but no executable downloader or in-place installer, and must be installed manually. Eligible Developer ID builds check GitHub's fixed latest-release endpoint at most daily, with an opt-out, and open the matching fixed tag page through **Update to latest version**. This validates availability metadata and expected filenames only; it does not verify archive bytes, checksum contents, a signed tag, or notarization. Local ad-hoc, CI, source-first, and unsigned-dev builds make no update requests. This is a browser handoff only: Vifty does not download executable assets, silently replace the app, or yet provide a Sparkle installer. See [docs/auto-update.md](docs/auto-update.md). ### Install trust levels @@ -145,7 +145,7 @@ To audit the already-published `v1.1.0` boundary, check out `v1.1.0` and set `RE ### Homebrew -The Homebrew cask now points at the published `v1.4.4` notarized zip with SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. The publication-time workflow recorded a pass for that exact artifact using the cask checksum; this is not a fresh current-host verifier claim. Installed-binary parity, explicit Auto restoration, and manual hardware compatibility remain pending for the exact `v1.4.4` build and are not claimed; the historical `v1.3.2` build was separately reviewed on `MacBookPro18,1`. Keep compatibility claims gated by [docs/release-status.md](docs/release-status.md), and never point the cask at an unsigned-dev artifact. +The Homebrew cask now points at the published `v1.4.5` notarized zip with SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. The publication-time workflow recorded a pass for that exact artifact using the cask checksum; this is not a fresh current-host verifier claim. Installed-binary parity, explicit Auto restoration, and manual hardware compatibility remain pending for the exact `v1.4.5` build and are not claimed; the historical `v1.3.2` build was separately reviewed on `MacBookPro18,1`. Keep compatibility claims gated by [docs/release-status.md](docs/release-status.md), and never point the cask at an unsigned-dev artifact. ## Build and verify diff --git a/SECURITY.md b/SECURITY.md index 7cb4ca48..a773ef55 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,11 +2,11 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. @@ -14,7 +14,8 @@ | Version | Supported | | ------- | --------- | -| 1.4.4 | Supported Developer ID signed/notarized release; installed release review and manual Fixed/Curve/Auto validation pending | +| 1.4.5 | Supported Developer ID signed/notarized release; installed release review and manual Fixed/Curve/Auto validation pending | +| 1.4.4 | Historical Developer ID signed/notarized release; migration to it from v1.3.2 is blocked on macOS 26 | | 1.3.2 | Historical Developer ID signed/notarized release; installed release review passed and manual Fixed/Curve/Auto validation passed on MacBookPro18,1 | | 1.1.x source/tag | Supported source-first fallback; unsigned assets are not trust-complete | | 1.0.x public asset | Not trust-complete; use source or a corrected 1.1.x release path | diff --git a/SUPPORT.md b/SUPPORT.md index 8d216f39..5fe14295 100644 --- a/SUPPORT.md +++ b/SUPPORT.md @@ -2,11 +2,11 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. diff --git a/docs/auto-update.md b/docs/auto-update.md index bb86c541..5f48d5ea 100644 --- a/docs/auto-update.md +++ b/docs/auto-update.md @@ -2,15 +2,15 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. -Auto-update is not enabled for `v1.4.4`; its exact public binary contains the advisory release-availability checker but no executable downloader or in-place installer. The first public release that contains the current update-checking code must therefore be installed manually. Source-first, unsigned-dev, local ad-hoc, CI, and other ineligible builds do not make update requests. +Auto-update is not enabled for `v1.4.5`; its exact public binary contains the advisory release-availability checker but no executable downloader or in-place installer. The first public release that contains the current update-checking code must therefore be installed manually. Source-first, unsigned-dev, local ad-hoc, CI, and other ineligible builds do not make update requests. Current source implements an advisory release-availability checker for future exact Vifty Developer ID builds. It does not download executable code, replace `Vifty.app`, run an installer, or silently change the privileged helper. A separate in-place updater has a higher trust bar and has not been implemented. diff --git a/docs/compatibility.md b/docs/compatibility.md index de26e887..53c94543 100644 --- a/docs/compatibility.md +++ b/docs/compatibility.md @@ -2,11 +2,11 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. diff --git a/docs/competitive-analysis.md b/docs/competitive-analysis.md index 84918aed..fb9f47f3 100644 --- a/docs/competitive-analysis.md +++ b/docs/competitive-analysis.md @@ -2,11 +2,11 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. @@ -48,7 +48,7 @@ Priority order: trusted release story, hardware validation evidence, daemon safe The concrete execution plan for the next cycle is [plans/2026-06-13-next-workplan.md](plans/2026-06-13-next-workplan.md). It starts with M1 Pro validation on available hardware, keeps untested model families as "Needs report," and sequences UI/helper/menu-bar/observability work before future trusted-binary updater work. -1. **Trusted release story:** preserve the verified `v1.4.4` Developer ID artifact and historical `v1.1.1` source-first boundary; every future candidate must pass the manifest, signed-tag, checksum, verifier, and Homebrew handoff gates as a new immutable release. +1. **Trusted release story:** preserve the verified `v1.4.5` Developer ID artifact and historical `v1.1.1` source-first boundary; every future candidate must pass the manifest, signed-tag, checksum, verifier, and Homebrew handoff gates as a new immutable release. 2. **Hardware validation evidence:** publish only generated compatibility evidence from reviewed reports; keep unvalidated rows as "Needs report." 3. **Helper repair clarity:** keep first-run, approval, unreachable, telemetry-only, repair, unsupported, and healthy states distinct in the app and support docs. 4. **Human UI polish:** prioritize small-window scrolling, full-height operational panes, main-window settings, a compact/readiness-oriented menu-bar popover, compact power/history/temperature surfaces, and a better screenshot/demo. diff --git a/docs/release-status.md b/docs/release-status.md index 3ccff8c1..88393645 100644 --- a/docs/release-status.md +++ b/docs/release-status.md @@ -2,11 +2,11 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. @@ -14,7 +14,7 @@ This page is the current public trust status for Vifty releases. Update it whene ## Current Status -As of 2026-08-08, `v1.4.4` is the current published Developer ID release. Its immutable annotated tag object is `8c364558f4e0e9a75c129e4d08adf470b7f32bec` at commit `0ac7842483a602a30900671904f76fd7b06e2370`, source CI run `31252163922` passed, signed/notarized Release run `31253285103` passed, and the four canonical trust assets are public at the [v1.4.4 GitHub Release](https://github.com/Reedtrullz/Vifty/releases/tag/v1.4.4). `v1.3.2` is the previous published Developer ID release (recorded in `historicalReleases`), and `v1.1.1` remains the published source-first fallback; its immutable tag resolves to `a82f2237ff39c24a6b366dca8f95a17ee54fd972`. +As of 2026-08-09, `v1.4.5` is the current published Developer ID release. Its immutable annotated tag object is `ffd6fdc11a77b460ce1e629b1ec43f3b7ebf582e` at commit `174dcd28a343de7f797d682d02c0f70e26b72c2e`, source CI run `31283125895` passed, signed/notarized Release run `31284620552` passed, and the four canonical trust assets are public at the [v1.4.5 GitHub Release](https://github.com/Reedtrullz/Vifty/releases/tag/v1.4.5). `v1.4.4` and `v1.3.2` are previous published Developer ID releases (recorded in `historicalReleases`), and `v1.1.1` remains the published source-first fallback; its immutable tag resolves to `a82f2237ff39c24a6b366dca8f95a17ee54fd972`. The supervised `v1.3.1` manual smoke is not a passed compatibility claim. Fixed and Curve control reached their targets and the right-fan curve line rendered, but selecting Auto during an in-flight Curve tick could briefly show Auto active before the suspended write resumed and returned both fans to Forced mode. Operator recovery after quitting Vifty restored and read-only diagnostics confirmed hardware Auto. The exact public v1.3.2 build repeated the sequence and passed without later reassertion; prior-version evidence remains historical and does not substitute for the v1.3.2 review. @@ -28,7 +28,7 @@ The separate supported-hardware review also passed with `manualSmokeTestResult: Future Developer ID publication uses an explicit solo-maintainer governance boundary rather than pretending an unavailable peer review exists. There is no eligible second human release reviewer today: zero required approvals is not a reviewer pass and must never be recorded as one. As of the 2026-07-18 administrator readback, active GitHub ruleset `18940029` (`Immutable Vifty release tags`) covers `refs/tags/v*`, prevents update and deletion, has a visible empty bypass list, and reports that the current administrator cannot bypass it. The live `release` environment has no required-reviewer rule and administrator bypass is disabled. Its deployment admission is now tag-only: `protected_branches: false`, `custom_branch_policies: true`, no branch policy, and exactly one custom policy (`54991885`) with type `tag` and pattern `v*`. Both the administrator and workflow-public environment checkers passed that exact state. This readback resolves the prior protected-branch-only blocker; every release must still acquire fresh pre-tag governance evidence after exact-main CI rather than treating this point-in-time statement as permanent proof. -Protected `main` requires a pull request with zero approvals and no bypass actors, strict Actions-owned `SwiftPM checks` for administrators, conversation resolution, and forbids force pushes and deletion. The existing six release secret names remain deliberately repository-scoped for this solo-maintainer workflow; the environment contains no same-name copies, and the checked-in workflow contract restricts every secret reference to the protected `sign-notarize` job after its non-secret checks. Only after release prep merge and successful push CI on that exact `main` SHA may `scripts/create-signed-release-tag.sh` run. The creator requires both the signer allowlist and `.github/release-gh-toolchain.json` to be byte-identical to the exact first parent, runs the exact committed manifest-history and workflow-contract gates, copies and verifies the pinned Darwin arm64 `gh` bytes before token access, rechecks exact-main CI, invokes the exact committed `scripts/check-release-governance.sh`, proves tag absence and the privileged facts, embeds those exact live `administrator-pretag` bytes plus the verifier/policy hashes in the signed annotated tag, and repeats the full live readback before reporting success. Despite its retained filename, `scripts/push-and-dispatch-signed-release-tag.sh` does not dispatch: it revalidates those facts, creates only the exact absent annotated tag with a compare-and-swap push, reads it back, and observes the `Release ` run that GitHub automatically creates for that tag push. It requires exactly one `push`-event run at attempt 1 and verifies its actor ID/login, repository, workflow path/ID, tag, commit, URL, and creation time. Immediately before the push boundary it creates a checkout-independent retired-tag marker and private receipt under `~/Library/Application Support/Vifty/ReleaseTransactions/Reedtrullz-Vifty//`. Those files are inspection evidence only and never retry authorization. A failure conclusively before both marker creation and remote mutation may be retried with fresh gates and proven exact-ref absence; once the marker exists or the tag may exist, a second helper invocation, manual dispatch, workflow rerun, or deleting/moving/reusing that tag is forbidden. Inspect the original marker, receipt, immutable tag, first-attempt run, and release state while the outcome is inconclusive; cut a new patch version only after the original transaction is conclusively shown not to have published. The workflow validates the embedded evidence with the committed `scripts/validate-release-governance-evidence.rb`, carries a current-fresh admission record in a complete inventoried candidate handoff, requires the signed ruleset ID to match the narrower public ruleset readback, and rechecks the same public revision and its own no-bypass state before and after promotion. The manifest candidate records `v1.4.5` build `13` as pending until exact-main CI and signed-tag publication; no release is authorized by candidate metadata alone. +Protected `main` requires a pull request with zero approvals and no bypass actors, strict Actions-owned `SwiftPM checks` for administrators, conversation resolution, and forbids force pushes and deletion. The existing six release secret names remain deliberately repository-scoped for this solo-maintainer workflow; the environment contains no same-name copies, and the checked-in workflow contract restricts every secret reference to the protected `sign-notarize` job after its non-secret checks. Only after release prep merge and successful push CI on that exact `main` SHA may `scripts/create-signed-release-tag.sh` run. The creator requires both the signer allowlist and `.github/release-gh-toolchain.json` to be byte-identical to the exact first parent, runs the exact committed manifest-history and workflow-contract gates, copies and verifies the pinned Darwin arm64 `gh` bytes before token access, rechecks exact-main CI, invokes the exact committed `scripts/check-release-governance.sh`, proves tag absence and the privileged facts, embeds those exact live `administrator-pretag` bytes plus the verifier/policy hashes in the signed annotated tag, and repeats the full live readback before reporting success. Despite its retained filename, `scripts/push-and-dispatch-signed-release-tag.sh` does not dispatch: it revalidates those facts, creates only the exact absent annotated tag with a compare-and-swap push, reads it back, and observes the `Release ` run that GitHub automatically creates for that tag push. It requires exactly one `push`-event run at attempt 1 and verifies its actor ID/login, repository, workflow path/ID, tag, commit, URL, and creation time. Immediately before the push boundary it creates a checkout-independent retired-tag marker and private receipt under `~/Library/Application Support/Vifty/ReleaseTransactions/Reedtrullz-Vifty//`. Those files are inspection evidence only and never retry authorization. A failure conclusively before both marker creation and remote mutation may be retried with fresh gates and proven exact-ref absence; once the marker exists or the tag may exist, a second helper invocation, manual dispatch, workflow rerun, or deleting/moving/reusing that tag is forbidden. Inspect the original marker, receipt, immutable tag, first-attempt run, and release state while the outcome is inconclusive; cut a new patch version only after the original transaction is conclusively shown not to have published. The workflow validates the embedded evidence with the committed `scripts/validate-release-governance-evidence.rb`, carries a current-fresh admission record in a complete inventoried candidate handoff, requires the signed ruleset ID to match the narrower public ruleset readback, and rechecks the same public revision and its own no-bypass state before and after promotion. The manifest candidate remains `null` until a separate release-prep pull request passes exact-main CI; no release is authorized by candidate metadata alone. The prior `v1.4.0` candidate is retired without publication. Its one-shot transaction created immutable annotated tag object `08259da0ad43b720938246848a5dae3bfc2221e0` at commit `8b39f8701ec3ea3d3e946de335f7cf95ee0b1908` and observed automatic first-attempt push run `29658220561`. That run passed its `Validate candidate version and signed tag` step and the complete unsigned build/inventory job, but the protected signing job failed during `Verify release environment protection` because the checker was invoked outside the nested trusted Git worktree. It exited before the required-secret check, Developer ID certificate import, signing, notarization, verified-asset upload, or publication; the publish job was skipped, and no draft, prerelease, or published `v1.4.0` GitHub Release exists. Do not rerun that workflow or delete, move, or reuse the tag. Recovery advances to `v1.4.1` build `9`; candidate metadata alone does not authorize a release. @@ -39,16 +39,16 @@ This solo-maintainer design has an explicit remote-proof limit. GitHub can verif Release lanes: -1. **Published Developer ID release:** `v1.4.4` public artifact and cask trust checks passed for the tagged workflow, canonical assets, checksum handoff, public verifier, release readiness, TeamID, notarization, stapling, and Gatekeeper. Installed helper parity, explicit Auto restoration, and manual Fixed/Curve compatibility remain pending for the exact build 12 and are not claimed; the historical `v1.3.2` build 7 holds separately reviewed installed and hardware claims on `MacBookPro18,1` that do not transfer. +1. **Published Developer ID release:** `v1.4.5` public artifact and cask trust checks passed for the tagged workflow, canonical assets, checksum handoff, public verifier, release readiness, TeamID, notarization, stapling, and Gatekeeper. Installed helper parity, explicit Auto restoration, and manual Fixed/Curve compatibility remain pending for the exact build 13 and are not claimed; the historical `v1.3.2` build 7 holds separately reviewed installed and hardware claims on `MacBookPro18,1` that do not transfer. 2. **Source release:** `v1.1.1` remains the published source-first fallback. Do not claim it or any unsigned-dev artifact is Developer ID signed, notarized, stapled, Gatekeeper-approved, or Homebrew-trusted. 3. **Unsigned convenience app zip:** optional tester convenience only. The attached hotfix artifact is named `Vifty-v1.1.1-unsigned-dev.zip` with `Vifty-v1.1.1-unsigned-dev.zip.sha256`. The unsigned-dev zip is valid only with its `.sha256` sidecar, and the SHA-256 digest in that sidecar must match the zip bytes. It is ad-hoc signed, not notarized, not the official trusted binary, and may trigger macOS Gatekeeper warnings. -Update status: the exact public `v1.3.2` binary has no update checker and cannot gain one retroactively. Update status: the exact public `v1.4.4` binary contains the advisory release-availability checker but no executable downloader or in-place installer, and must be installed manually. Eligible builds may check only the fixed GitHub latest-release endpoint at most daily with an opt-out; availability metadata is accepted only when its stable version and exact four canonical uploaded nonempty asset records validate, and **Update to latest version** opens the locally constructed tag page. The checker does not download or install executable code, and its filename/size checks are not archive, checksum, signed-tag, or notarization proof. Current source also provides a separate manual operator bridge, `scripts/install-vifty.sh --public-release-archive /absolute/path/Vifty-vX.Y.Z.zip`, for promoted `v1.4.0` and newer releases whose bundles carry the root snapshot binding contract. It performs no network request, selects only the reviewed checkout's current `publishedRelease`, verifies its exact pinned checksum, signed tag, and Developer ID/notarization evidence without skips, and feeds bounded extraction into the existing fail-closed app-replacement transaction. It cannot install `v1.3.2`, a candidate, historical release, direct app bundle, URL, or API-selected asset. Local ad-hoc, CI, source-first, and unsigned-dev builds make zero update requests. A future Sparkle signed-appcast installer remains separate work and must use Vifty's existing app-replacement transaction; see [auto-update.md](auto-update.md). +Update status: the exact public `v1.3.2` binary has no update checker and cannot gain one retroactively. Update status: the exact public `v1.4.5` binary contains the advisory release-availability checker but no executable downloader or in-place installer, and must be installed manually. Eligible builds may check only the fixed GitHub latest-release endpoint at most daily with an opt-out; availability metadata is accepted only when its stable version and exact four canonical uploaded nonempty asset records validate, and **Update to latest version** opens the locally constructed tag page. The checker does not download or install executable code, and its filename/size checks are not archive, checksum, signed-tag, or notarization proof. Current source also provides a separate manual operator bridge, `scripts/install-vifty.sh --public-release-archive /absolute/path/Vifty-vX.Y.Z.zip`, for promoted `v1.4.0` and newer releases whose bundles carry the root snapshot binding contract. It performs no network request, selects only the reviewed checkout's current `publishedRelease`, verifies its exact pinned checksum, signed tag, and Developer ID/notarization evidence without skips, and feeds bounded extraction into the existing fail-closed app-replacement transaction. It cannot install `v1.3.2`, a candidate, historical release, direct app bundle, URL, or API-selected asset. Local ad-hoc, CI, source-first, and unsigned-dev builds make zero update requests. A future Sparkle signed-appcast installer remains separate work and must use Vifty's existing app-replacement transaction; see [auto-update.md](auto-update.md). Public release facts: -- The public `Vifty-v1.4.4.zip` and checked-in cask both resolve to SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -- Release candidate metadata in `Resources/Info.plist` is staged at `1.4.5` build `13`, while `Casks/vifty.rb` remains pinned to published `1.4.4` with SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`; candidate signing, installation, and hardware evidence remain pending. +- The public `Vifty-v1.4.5.zip` and checked-in cask both resolve to SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +- Release metadata in `Resources/Info.plist` and `Casks/vifty.rb` is aligned at `1.4.5` build `13` with SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`; installed release-mode and hardware compatibility evidence remain pending. - Source CI run `29284751837` passed on release commit `6a771c2ea10386bf7a0a8369a759930f01d56062`, and Release run `29285576026` passed all signing, notarization, pre-publication verification, checklist, and publication steps. - The GitHub Release publishes `Vifty-v1.3.2.zip`, `Vifty-v1.3.2.zip.sha256`, `Vifty-v1.3.2-artifact-summary.json`, and `Vifty-v1.3.2-release-checklist.md`. - The published workflow summary and an independent downloaded-artifact verification both passed with TeamID `X88J3853S2`, no signature skips, and no notarization skips. diff --git a/docs/release.md b/docs/release.md index 486ad125..36d6260f 100644 --- a/docs/release.md +++ b/docs/release.md @@ -2,11 +2,11 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. @@ -17,7 +17,7 @@ Vifty has two release modes: For the current public release trust state, see [release-status.md](release-status.md). Keep that page updated when a release workflow fails, succeeds, or when the cask checksum is updated. -Release-availability checking, manual public-archive installation, and future in-place updating are three separate trust lanes. Source-first, unsigned-dev, local ad-hoc, and CI builds must remain ineligible and make zero update requests. The checker is present in the current `v1.4.4` artifact. The manual bridge takes only an operator-supplied archive selected as the reviewed checkout's current `publishedRelease`, performs no download, verifies the manifest-pinned SHA plus Developer ID/notarization evidence, and enters the existing fail-closed replacement transaction. Do not enable Sparkle for those artifacts; the checker, manual bridge, and future installer requirements live in [auto-update.md](auto-update.md). +Release-availability checking, manual public-archive installation, and future in-place updating are three separate trust lanes. Source-first, unsigned-dev, local ad-hoc, and CI builds must remain ineligible and make zero update requests. The checker is present in the current `v1.4.5` artifact. The manual bridge takes only an operator-supplied archive selected as the reviewed checkout's current `publishedRelease`, performs no download, verifies the manifest-pinned SHA plus Developer ID/notarization evidence, and enters the existing fail-closed replacement transaction. Do not enable Sparkle for those artifacts; the checker, manual bridge, and future installer requirements live in [auto-update.md](auto-update.md). ## Manual Published-Archive Install diff --git a/docs/support-triage.md b/docs/support-triage.md index 6f144697..78615f20 100644 --- a/docs/support-triage.md +++ b/docs/support-triage.md @@ -113,7 +113,7 @@ scripts/collect-validation-evidence.sh --app /Applications/Vifty.app make validation-evidence-review VALIDATION_EVIDENCE_BUNDLE= VALIDATION_EVIDENCE_REVIEW_MODE=release VALIDATION_EVIDENCE_REVIEW_SUMMARY=/review-result.json ``` -For `v1.1.1`, source-first release issues should focus on source tag/CI readiness, release-note warnings, unsigned-dev artifact naming/checksum, and the explicit source-first trust boundary. Do not ask users to verify Developer ID signing, notarization, stapling, or Homebrew trust for `v1.1.1`; those checks apply to Developer ID releases such as the current `v1.4.4` artifact. +For `v1.1.1`, source-first release issues should focus on source tag/CI readiness, release-note warnings, unsigned-dev artifact naming/checksum, and the explicit source-first trust boundary. Do not ask users to verify Developer ID signing, notarization, stapling, or Homebrew trust for `v1.1.1`; those checks apply to Developer ID releases such as the current `v1.4.5` artifact. If a `v1.1.0` user reports "Fan helper unreachable" after updating, first collect the read-only agent evidence bundle, `diagnose --json`, `status --json`, and launchd/collector evidence. If the report matches the published helper issue, do not replace `v1.1.0` assets from `main`; direct the user to the `v1.1.1` source-first hotfix release. When `appInfo.shortVersion` is `1.1.0`, blocked `diagnose` recommends `repairHelper`, and accepted structured `HELPER_UNREACHABLE` command errors are present, the lightweight reviewer warns that this is the known v1.1.0 helper-unreachable issue; use the v1.1.1 source-first hotfix and do not retag v1.1.0 or replace its unsigned-dev assets. @@ -134,7 +134,7 @@ evidence bundle and the fuller validation evidence bundle. | Release trust | Source-first warning drift, unsigned-dev artifact naming/checksum, known source-first helper issue, Gatekeeper, notarization, cask SHA, TeamID, missing release assets, release-readiness blocker, stale release tag, or bundle-version mismatch | Release Trust Report issue, `scripts/check-release-readiness.sh --mode source-first --version --repo Reedtrullz/Vifty --json`, optional `--require-source-ref ` for unpublished candidates, Developer ID `--mode developer-id` readiness, `scripts/verify-release-artifact.sh --team-id `, collector bundle, `review-result.json` | Do not promote the release or cask until the correct mode's readiness passes; do not treat unsigned-dev artifacts as trusted binaries, and cut a new source-first hotfix instead of retagging a flawed source release. | | Hardware validation | New Apple Silicon MacBook Pro model, missing compatibility row, or smoke-test report | Hardware Validation Report issue, `diagnose --json`, `probeLocal`, collector bundle | Keep the model as needs validation until review passes and manual smoke records Auto restore. | | Unsupported hardware safe block | Unsupported Apple Silicon reports `blocked`; Intel reports the public arm64 binary unavailable | `diagnose --json` and optional collector bundle only when the binary can execute; [unsupported-hardware.md](unsupported-hardware.md) | Treat an Apple Silicon safe block or Intel binary unavailability as expected; do not suggest bypasses or imply Intel compatibility. | -| Helper install or approval | `HELPER_UNREACHABLE`, helper unreachable UI, fallback fan telemetry with daemon not responding, Login Items approval, empty fan snapshot, manual controls blocked by helper state, or a blocked helper-maintenance phase record | Read-only agent evidence bundle, `diagnose --json`, `status --json`, helper recovery text from the app, launchd status from collector, and the fixed root execution record when the lifecycle reports one | Ask the user to run Repair/Reinstall Helper again, or use `make repair-helper` from an operator-trusted source checkout, and approve the explicit administrator prompt. Never bypass a blocked receipt, exact-helper proof, signature check, literal service-disabled readback, or post-freeze Auto proof. A prompt cancellation before root freeze leaves service/manual state untouched. If protocol-v2 authorization was consumed, retry while its exact receipt is current. A missing or expired protocol-v2 receipt never downgrades by itself; offline recovery requires an explicit protocol-mismatch report, or a fresh helper-unreachable report plus root verification of the exact published v1.4.4 daemon when no valid receipt remains. Approve Login Items if macOS asks, then rerun read-only diagnostics. | +| Helper install or approval | `HELPER_UNREACHABLE`, helper unreachable UI, fallback fan telemetry with daemon not responding, Login Items approval, empty fan snapshot, manual controls blocked by helper state, or a blocked helper-maintenance phase record | Read-only agent evidence bundle, `diagnose --json`, `status --json`, helper recovery text from the app, launchd status from collector, and the fixed root execution record when the lifecycle reports one | Ask the user to run Repair/Reinstall Helper again, or use `make repair-helper` from an operator-trusted source checkout, and approve the explicit administrator prompt. Never bypass a blocked receipt, exact-helper proof, signature check, literal service-disabled readback, or post-freeze Auto proof. A prompt cancellation before root freeze leaves service/manual state untouched. If protocol-v2 authorization was consumed, retry while its exact receipt is current. A missing or expired protocol-v2 receipt never downgrades by itself; offline recovery requires an explicit protocol-mismatch report, or a fresh helper-unreachable report plus root verification of the exact published v1.4.5 daemon when no valid receipt remains. Approve Login Items if macOS asks, then rerun read-only diagnostics. | | SMC key or fan telemetry drift | Fan count/range/mode missing, `hardwareMode` unknown, fan mode-key casing drift, no controllable fans on supported hardware | `probeLocal`, `diagnose --json`, model identifier, macOS version | Keep fan writes blocked until fan IDs, ranges, mode-key casing, and mode/target telemetry are understood. | | Agent-cooling lifecycle | `prepare`, `run`, restore failure, expired lease, rate limit, guarded wrapper refusal, or child-command preflight issue | Agent Cooling Report issue, exact `viftyctl` or guarded-wrapper command, stdout/stderr, read-only agent evidence bundle with `--guarded-run-stderr-file ` when wrapper stderr exists or `--guarded-run-preflight ... -- ` when the exact workload should be checked without side effects, or manual `diagnose --json`, `capabilities --json`, `status --json`, `audit --limit 20 --json`; preflight bundles should include a matching `guarded-run-preflight` row in both `manifest.tsv` and `agent-cooling-evidence-summary.json`, and the reviewer rejects incomplete preflight status/stdout/stderr envelopes; `guardedRunDecision.captureMode` separates copied transcripts from collector-run preflight evidence; on supported hardware with safe readiness, optional `make agent-run-smoke-evidence-current-build` for current source checkouts or `make agent-run-smoke-evidence VIFTYCTL=/Applications/Vifty.app/Contents/MacOS/viftyctl` for installed-app smoke bundles | Follow [safe-agent-cooling.md](safe-agent-cooling.md); do not start another lease while restore is pending, and use the supervised smoke target only after readiness is safe. | | UI or copy | Confusing owner/helper state, profile preset behavior, power/thermal display | screenshot, macOS version, `diagnose --json` if fan state is involved | Fix copy/state without changing SMC behavior unless evidence shows a control bug. | diff --git a/docs/trust-model.md b/docs/trust-model.md index 717efeb7..baea5758 100644 --- a/docs/trust-model.md +++ b/docs/trust-model.md @@ -2,11 +2,11 @@ > Release facts authority: `.github/release-manifest.json` (schema `docs/schemas/release-manifest.schema.json`). -> Published: `v1.4.4` (version `1.4.4`, build `12`), `arm64` only, minimum macOS `15.0`. +> Published: `v1.4.5` (version `1.4.5`, build `13`), `arm64` only, minimum macOS `15.0`. > Runtime identities: app `tech.reidar.vifty`, daemon `tech.reidar.vifty.daemon`, helper `tech.reidar.vifty.helper`, CLI `tech.reidar.vifty.ctl`. -> Canonical artifact: `Vifty-v1.4.4.zip` with checksum asset `Vifty-v1.4.4.zip.sha256` and SHA-256 `d35c7326166d128c3596f0b84b87f283a54dedd1483a854a37bcbef888af713f`. -> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `0ac7842483a602a30900671904f76fd7b06e2370`, CI run `31252163922`, Release run `31253285103`. -> Tag policy: `v1.4.4` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. +> Canonical artifact: `Vifty-v1.4.5.zip` with checksum asset `Vifty-v1.4.5.zip.sha256` and SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. +> Public artifact trust: `passed` / `developer-id-notarized` for TeamID `X88J3853S2`; source `174dcd28a343de7f797d682d02c0f70e26b72c2e`, CI run `31283125895`, Release run `31284620552`. +> Tag policy: `v1.4.5` remains recorded as `signed-verified` evidence; signed tags are mandatory from version `1.3.3` onward. > Separate exact-build claims: installed release review `pending`; manual Fixed/Curve/Auto compatibility `pending`. @@ -177,7 +177,7 @@ The archive was downloaded to fresh scratch storage, hashed before extraction, e Before any legacy code runs, the installer also requires `anchor apple generic`, the Developer ID Application leaf/intermediate certificate OIDs, leaf OU `X88J3853S2`, exact signing identifiers, and a valid deep app seal. It copies the pinned CLI and sibling daemon into a private `0700` run directory, rechecks their signatures and byte identities there, and executes only that private CLI copy. Its Auto/System evidence is a fresh point-in-time snapshot rather than a daemon-held quiescence lease; the existing daemon continues to own any concurrent bounded lease, expiry, and Auto restoration during the app-only rename swap. -The generated fact block above is authoritative for the current public version, build, architecture, identities, checksum, TeamID, and trust state. The exact `v1.4.4` public artifact passes release-level signing/notarization checks; installed release-mode review and human-supervised Fixed → Auto → Curve → Auto validation remain pending for it. The historical `v1.3.2` build passed installed release-mode review and human-supervised Fixed → Auto → Curve → Auto validation on `MacBookPro18,1`; the [release review](validation-reports/2026-07-14-v1.3.2-macbookpro18-release/review-result.json) and [manual-smoke attestation](validation-reports/2026-07-14-v1.3.2-macbookpro18-supported/manual-smoke-attestation.md) scope those claims to that exact binary and model; they do not validate the current branch or broad Apple Silicon compatibility. `v1.1.1` remains the source-first fallback and supersedes `v1.1.0` for users who hit the helper-unreachable update issue. Any `Vifty-v-unsigned-dev.zip` attachment is not Developer ID signed, not notarized, not Homebrew-trusted, and must not use the canonical `Vifty-v.zip` release artifact name. +The generated fact block above is authoritative for the current public version, build, architecture, identities, checksum, TeamID, and trust state. The exact `v1.4.5` public artifact passes release-level signing/notarization checks; installed release-mode review and human-supervised Fixed → Auto → Curve → Auto validation remain pending for it. The historical `v1.3.2` build passed installed release-mode review and human-supervised Fixed → Auto → Curve → Auto validation on `MacBookPro18,1`; the [release review](validation-reports/2026-07-14-v1.3.2-macbookpro18-release/review-result.json) and [manual-smoke attestation](validation-reports/2026-07-14-v1.3.2-macbookpro18-supported/manual-smoke-attestation.md) scope those claims to that exact binary and model; they do not validate the current branch or broad Apple Silicon compatibility. `v1.1.1` remains the source-first fallback and supersedes `v1.1.0` for users who hit the helper-unreachable update issue. Any `Vifty-v-unsigned-dev.zip` attachment is not Developer ID signed, not notarized, not Homebrew-trusted, and must not use the canonical `Vifty-v.zip` release artifact name. The current release trust state is tracked in [release-status.md](release-status.md). Do not promote Homebrew or a GitHub asset as trust-complete unless that status page points to a signed, notarized, stapled artifact whose checksum and verifier summary match the cask.