From 05e73a9c0d37fcf17d5c0c979f90d60165e369fa Mon Sep 17 00:00:00 2001 From: Reidar Date: Sun, 13 Sep 2026 03:38:51 +0200 Subject: [PATCH] release: prepare v1.4.6 --- .github/release-manifest.json | 17 ++++++++++++++++- CHANGELOG.md | 6 +++++- Resources/Info.plist | 4 ++-- docs/release-status.md | 6 +++--- 4 files changed, 26 insertions(+), 7 deletions(-) diff --git a/.github/release-manifest.json b/.github/release-manifest.json index 66387d6a..69a6bb83 100644 --- a/.github/release-manifest.json +++ b/.github/release-manifest.json @@ -81,5 +81,20 @@ "manualCompatibility": "pending", "manualCompatibilityScope": null }, - "candidate": null + "candidate": { + "version": "1.4.6", + "build": 14, + "tag": "v1.4.6", + "artifact": "Vifty-v1.4.6.zip", + "checksumAsset": "Vifty-v1.4.6.zip.sha256", + "artifactSummary": "Vifty-v1.4.6-artifact-summary.json", + "releaseChecklist": "Vifty-v1.4.6-release-checklist.md", + "sha256": null, + "artifactTrust": "pending", + "signingTrust": "pending", + "tagTrust": "signed-required", + "installedReleaseReview": "pending", + "manualCompatibility": "pending", + "manualCompatibilityScope": null + } } diff --git a/CHANGELOG.md b/CHANGELOG.md index 65351878..64ad44f5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,9 +7,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [1.4.6] - 2026-09-13 + ### Fixed -- Make the existing `.active` journal prerequisite explicit in the idempotent re-apply branch, bound manual and Auto-restore XPC identifiers and reasons by UTF-8 bytes, cap untrusted fan collections at the ten-fan hardware domain before traversal, and keep Codex usage an explicit opt-in rather than a default custom menu-bar field. +- Declare AppleSMC write payload sizes and confirm bounded target/mode readback, including the guarded protected-mode fallback, so Fixed/Curve writes and Auto restore are applied reliably on supported Apple Silicon. +- Repair helper replacement and control-service recovery while preserving the fail-closed lifecycle and diagnostic gates after a signed install. +- Make the existing `.active` journal prerequisite explicit in the idempotent re-apply branch, bind manual and Auto-restore XPC identifiers and reasons by UTF-8 bytes, cap untrusted fan collections at the ten-fan hardware domain before traversal, and keep Codex usage an explicit opt-in rather than a default custom menu-bar field. ## [1.4.5] - 2026-08-08 diff --git a/Resources/Info.plist b/Resources/Info.plist index 6a54600d..36f5dccb 100644 --- a/Resources/Info.plist +++ b/Resources/Info.plist @@ -17,9 +17,9 @@ CFBundlePackageType APPL CFBundleShortVersionString - 1.4.5 + 1.4.6 CFBundleVersion - 13 + 14 LSMinimumSystemVersion 15.0 LSApplicationCategoryType diff --git a/docs/release-status.md b/docs/release-status.md index 88393645..85b78b2c 100644 --- a/docs/release-status.md +++ b/docs/release-status.md @@ -14,7 +14,7 @@ This page is the current public trust status for Vifty releases. Update it whene ## Current Status -As of 2026-08-09, `v1.4.5` is the current published Developer ID release. Its immutable annotated tag object is `ffd6fdc11a77b460ce1e629b1ec43f3b7ebf582e` at commit `174dcd28a343de7f797d682d02c0f70e26b72c2e`, source CI run `31283125895` passed, signed/notarized Release run `31284620552` passed, and the four canonical trust assets are public at the [v1.4.5 GitHub Release](https://github.com/Reedtrullz/Vifty/releases/tag/v1.4.5). `v1.4.4` and `v1.3.2` are previous published Developer ID releases (recorded in `historicalReleases`), and `v1.1.1` remains the published source-first fallback; its immutable tag resolves to `a82f2237ff39c24a6b366dca8f95a17ee54fd972`. +As of 2026-09-13, `v1.4.5` is the current published Developer ID release. Its immutable annotated tag object is `ffd6fdc11a77b460ce1e629b1ec43f3b7ebf582e` at commit `174dcd28a343de7f797d682d02c0f70e26b72c2e`, source CI run `31283125895` passed, signed/notarized Release run `31284620552` passed, and the four canonical trust assets are public at the [v1.4.5 GitHub Release](https://github.com/Reedtrullz/Vifty/releases/tag/v1.4.5). The repaired source is staged as the pending `v1.4.6` build `14` candidate; it is not a public release until the signed-tag workflow and artifact checks pass. `v1.4.4` and `v1.3.2` are previous published Developer ID releases (recorded in `historicalReleases`), and `v1.1.1` remains the published source-first fallback; its immutable tag resolves to `a82f2237ff39c24a6b366dca8f95a17ee54fd972`. The supervised `v1.3.1` manual smoke is not a passed compatibility claim. Fixed and Curve control reached their targets and the right-fan curve line rendered, but selecting Auto during an in-flight Curve tick could briefly show Auto active before the suspended write resumed and returned both fans to Forced mode. Operator recovery after quitting Vifty restored and read-only diagnostics confirmed hardware Auto. The exact public v1.3.2 build repeated the sequence and passed without later reassertion; prior-version evidence remains historical and does not substitute for the v1.3.2 review. @@ -28,7 +28,7 @@ The separate supported-hardware review also passed with `manualSmokeTestResult: Future Developer ID publication uses an explicit solo-maintainer governance boundary rather than pretending an unavailable peer review exists. There is no eligible second human release reviewer today: zero required approvals is not a reviewer pass and must never be recorded as one. As of the 2026-07-18 administrator readback, active GitHub ruleset `18940029` (`Immutable Vifty release tags`) covers `refs/tags/v*`, prevents update and deletion, has a visible empty bypass list, and reports that the current administrator cannot bypass it. The live `release` environment has no required-reviewer rule and administrator bypass is disabled. Its deployment admission is now tag-only: `protected_branches: false`, `custom_branch_policies: true`, no branch policy, and exactly one custom policy (`54991885`) with type `tag` and pattern `v*`. Both the administrator and workflow-public environment checkers passed that exact state. This readback resolves the prior protected-branch-only blocker; every release must still acquire fresh pre-tag governance evidence after exact-main CI rather than treating this point-in-time statement as permanent proof. -Protected `main` requires a pull request with zero approvals and no bypass actors, strict Actions-owned `SwiftPM checks` for administrators, conversation resolution, and forbids force pushes and deletion. The existing six release secret names remain deliberately repository-scoped for this solo-maintainer workflow; the environment contains no same-name copies, and the checked-in workflow contract restricts every secret reference to the protected `sign-notarize` job after its non-secret checks. Only after release prep merge and successful push CI on that exact `main` SHA may `scripts/create-signed-release-tag.sh` run. The creator requires both the signer allowlist and `.github/release-gh-toolchain.json` to be byte-identical to the exact first parent, runs the exact committed manifest-history and workflow-contract gates, copies and verifies the pinned Darwin arm64 `gh` bytes before token access, rechecks exact-main CI, invokes the exact committed `scripts/check-release-governance.sh`, proves tag absence and the privileged facts, embeds those exact live `administrator-pretag` bytes plus the verifier/policy hashes in the signed annotated tag, and repeats the full live readback before reporting success. Despite its retained filename, `scripts/push-and-dispatch-signed-release-tag.sh` does not dispatch: it revalidates those facts, creates only the exact absent annotated tag with a compare-and-swap push, reads it back, and observes the `Release ` run that GitHub automatically creates for that tag push. It requires exactly one `push`-event run at attempt 1 and verifies its actor ID/login, repository, workflow path/ID, tag, commit, URL, and creation time. Immediately before the push boundary it creates a checkout-independent retired-tag marker and private receipt under `~/Library/Application Support/Vifty/ReleaseTransactions/Reedtrullz-Vifty//`. Those files are inspection evidence only and never retry authorization. A failure conclusively before both marker creation and remote mutation may be retried with fresh gates and proven exact-ref absence; once the marker exists or the tag may exist, a second helper invocation, manual dispatch, workflow rerun, or deleting/moving/reusing that tag is forbidden. Inspect the original marker, receipt, immutable tag, first-attempt run, and release state while the outcome is inconclusive; cut a new patch version only after the original transaction is conclusively shown not to have published. The workflow validates the embedded evidence with the committed `scripts/validate-release-governance-evidence.rb`, carries a current-fresh admission record in a complete inventoried candidate handoff, requires the signed ruleset ID to match the narrower public ruleset readback, and rechecks the same public revision and its own no-bypass state before and after promotion. The manifest candidate remains `null` until a separate release-prep pull request passes exact-main CI; no release is authorized by candidate metadata alone. +Protected `main` requires a pull request with zero approvals and no bypass actors, strict Actions-owned `SwiftPM checks` for administrators, conversation resolution, and forbids force pushes and deletion. The existing six release secret names remain deliberately repository-scoped for this solo-maintainer workflow; the environment contains no same-name copies, and the checked-in workflow contract restricts every secret reference to the protected `sign-notarize` job after its non-secret checks. Only after release prep merge and successful push CI on that exact `main` SHA may `scripts/create-signed-release-tag.sh` run. The creator requires both the signer allowlist and `.github/release-gh-toolchain.json` to be byte-identical to the exact first parent, runs the exact committed manifest-history and workflow-contract gates, copies and verifies the pinned Darwin arm64 `gh` bytes before token access, rechecks exact-main CI, invokes the exact committed `scripts/check-release-governance.sh`, proves tag absence and the privileged facts, embeds those exact live `administrator-pretag` bytes plus the verifier/policy hashes in the signed annotated tag, and repeats the full live readback before reporting success. Despite its retained filename, `scripts/push-and-dispatch-signed-release-tag.sh` does not dispatch: it revalidates those facts, creates only the exact absent annotated tag with a compare-and-swap push, reads it back, and observes the `Release ` run that GitHub automatically creates for that tag push. It requires exactly one `push`-event run at attempt 1 and verifies its actor ID/login, repository, workflow path/ID, tag, commit, URL, and creation time. Immediately before the push boundary it creates a checkout-independent retired-tag marker and private receipt under `~/Library/Application Support/Vifty/ReleaseTransactions/Reedtrullz-Vifty//`. Those files are inspection evidence only and never retry authorization. A failure conclusively before both marker creation and remote mutation may be retried with fresh gates and proven exact-ref absence; once the marker exists or the tag may exist, a second helper invocation, manual dispatch, workflow rerun, or deleting/moving/reusing that tag is forbidden. Inspect the original marker, receipt, immutable tag, first-attempt run, and release state while the outcome is inconclusive; cut a new patch version only after the original transaction is conclusively shown not to have published. The workflow validates the embedded evidence with the committed `scripts/validate-release-governance-evidence.rb`, carries a current-fresh admission record in a complete inventoried candidate handoff, requires the signed ruleset ID to match the narrower public ruleset readback, and rechecks the same public revision and its own no-bypass state before and after promotion. The manifest candidate records `v1.4.6` build `14` as pending until exact-main CI and signed-tag publication; no release is authorized by candidate metadata alone. The prior `v1.4.0` candidate is retired without publication. Its one-shot transaction created immutable annotated tag object `08259da0ad43b720938246848a5dae3bfc2221e0` at commit `8b39f8701ec3ea3d3e946de335f7cf95ee0b1908` and observed automatic first-attempt push run `29658220561`. That run passed its `Validate candidate version and signed tag` step and the complete unsigned build/inventory job, but the protected signing job failed during `Verify release environment protection` because the checker was invoked outside the nested trusted Git worktree. It exited before the required-secret check, Developer ID certificate import, signing, notarization, verified-asset upload, or publication; the publish job was skipped, and no draft, prerelease, or published `v1.4.0` GitHub Release exists. Do not rerun that workflow or delete, move, or reuse the tag. Recovery advances to `v1.4.1` build `9`; candidate metadata alone does not authorize a release. @@ -48,7 +48,7 @@ Update status: the exact public `v1.3.2` binary has no update checker and cannot Public release facts: - The public `Vifty-v1.4.5.zip` and checked-in cask both resolve to SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`. -- Release metadata in `Resources/Info.plist` and `Casks/vifty.rb` is aligned at `1.4.5` build `13` with SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`; installed release-mode and hardware compatibility evidence remain pending. +- Release candidate metadata in `Resources/Info.plist` is staged at `1.4.6` build `14`, while `Casks/vifty.rb` remains pinned to published `1.4.5` with SHA-256 `13fa763cbfdca3e77fcf6f657df6d51b32e19a4d25dd17a79614635fe844b0d5`; candidate signing, installation, and hardware evidence remain pending. - Source CI run `29284751837` passed on release commit `6a771c2ea10386bf7a0a8369a759930f01d56062`, and Release run `29285576026` passed all signing, notarization, pre-publication verification, checklist, and publication steps. - The GitHub Release publishes `Vifty-v1.3.2.zip`, `Vifty-v1.3.2.zip.sha256`, `Vifty-v1.3.2-artifact-summary.json`, and `Vifty-v1.3.2-release-checklist.md`. - The published workflow summary and an independent downloaded-artifact verification both passed with TeamID `X88J3853S2`, no signature skips, and no notarization skips.