Skip to content

Latest commit

 

History

History
134 lines (110 loc) · 6.76 KB

File metadata and controls

134 lines (110 loc) · 6.76 KB

DeskOS D1L release checklist

This tracks public product deliverables. Controlled peers, credentials, admin passwords, soak runs, internal evidence, and qualification firmware are not release deliverables and must not appear in the public package.

The current production profile is full_feature with conditional storage: SD-primary retained history when prepared storage is ready, visible live-only operation otherwise, and without silent default-NVS fallback. Historical RC2 artifacts remain bound to their original core_1_0 profile.

1.8.0 production release

The maintainer re-enabled GitHub Actions for this production release. Use the existing workflow's exact-source signed package; the attached D1L remains the physical acceptance target on the Pi 5.

  • Check actual legacy/current companion message frames for zero, one and multiple hops, including two/three-byte path hashes and retained rows.
  • Repeat the official-phone telemetry request that overflowed RC5's worker; require the same boot identity, a live radio and measured stack headroom.
  • Verify a newly received channel message in the official app, then release the phone with test settings restored.
  • Reproduce BUSY timeout and expander read failure in the native driver checks; verify no SPI after a latched fault, exclusive reset, timer reuse, profile restoration and companion rejection before publishing.
  • Run the complete host suite and the focused native radio, companion, storage, update, connectivity, map, and startup checks in the existing Actions jobs.
  • Build the exact clean source with the pinned ESP-IDF SDK, full_feature, conditional, and all four reviewed BSP patches. Record the Actions run.
  • Package and verify both ESP32 install paths, the complete production RP2040 UF2, and the signed SD update using the existing production signer.
  • Use only the stable D1L USB identity. Preserve identity, settings and SD data; verify application bytes before changing the boot selector.
  • Check the candidate's version, health, radio, connectivity, retained storage, normal UI screens, and direct-message/repeater behavior on the attached D1L. Record phone-app results with the version actually tested; earlier results are not new-candidate phone acceptance.
  • Exercise the actual flasher console against the D1L and verify its normal update, clean-install, failure and storage readiness paths locally.
  • Publish v1.8.0 as the latest stable release tied to the tested source. Freshly download and compare every public asset, update the product page and flasher, and verify public downloads and desktop/mobile layouts.
  • Retain the signed release, a device recovery copy and deployment rollback; remove obsolete task build outputs after publication.

The release notes and GitHub release record the observed results. A checklist item or an older screenshot is not proof of a new device run.

1.0 / RC1 record

  • v1.0.0-rc.1, v1.0.0, and the v1.0.1 packaging correction are published.
  • The package provides an app update BIN, full clean 8 MB BIN, complete RP2040 UF2, checksums, and Windows/Linux instructions.
  • All nine v1.0.1 public assets were freshly downloaded and matched staging byte-for-byte.

Release record: source b796f5eeb080f520ab162e37430e69a1845dcfbe, main Actions run 31260655342.

1.2 / RC2 corrective publication

Product and documentation

  • The parity ledger covers every current mobile area and primary action.
  • #320 implementation opens the selected enabled channel conversation.
  • #321 implementation provides Contacts search, four useful sort orders, direct Message/Manage actions, companion DM, and repeater/room management.
  • The production framebuffer export is read-only and independent of test or qualification hooks.
  • Firmware and generated package docs identify version 1.2.0 from runtime source truth.
  • 1.0/RC1 remains historical; 1.2/RC2 is corrective; 1.5/RC3 remains the deferred expansion line.
  • README embeds fresh 480x480 Home, Channels, Contacts, Map, and Settings captures from the attached D1L (#323); Map was captured at 9/9 local SD tile cache hits and 9/9 rendered.

Exact public artifacts

  • The exact final commit has a successful GitHub Actions build/package run.
  • The attached D1L runs production 1.2.0; its version receipt identifies the exact Actions-built firmware commit. No separate validation firmware or controlled-peer gate is required.
  • The public package contains only production/user files and includes:
    • app update BIN for an existing DeskOS installation;
    • full clean 8 MB BIN for a blank/non-DeskOS device;
    • one complete RP2040 UF2 for either path;
    • START_HERE.md, user docs, and checksums.
  • PR #325 is merged and the exact main artifact is published as 1.2/RC2.
  • Every release asset is freshly downloaded and matches the published checksums.
  • Issues #320, #321, #322, and #323 are closed with links to the shipped release.

1.5 / RC3 boundary

BLE companion transport, richer QR/deep-link sharing, signed update/recovery, localization expansion, broad UI architecture, optional telemetry, and debt in RC3_BACKLOG.md remain outside RC2.

1.6 release boundary

The 1.6 release keeps the established full-feature radio and storage safety boundaries. Its release proof requires green host and Actions checks, exact-SHA artifacts, a non-erasing flash to the stable D1L USB identity, and physical 480x480 UI acceptance. It never formats SD or substitutes an arbitrary serial device.

1.7 release boundary

The 1.7 release keeps every 1.6 radio, storage, update, and device-safety boundary. The animated opening must remain non-blocking, allocation failure must fall through to Home, and the exact Actions-built 1.7.0 image must pass a non-erasing flash and physical D1L UI check on the stable USB identity.

1.7.1 release boundary

The exact Actions-built 1.7.1 image must pass the complete host suite, the 105-view UI audit, a 1,000-transition UI lifecycle run, a non-erasing flash to the stable D1L USB identity, and physical checks of direct Login, masked entry, saved-password reuse, command navigation, pending animation, and result/error states. Qualification must not expose a password, format SD, or transmit an unrequested public message.

1.7.5 release boundary

The exact Actions-built 1.7.5 image must preserve every 1.7.1 safety boundary and prove flood login packet construction, manager return navigation, saved-name neighbour rendering, ten-minute display lock, top-layer lock coverage, button wake/double-press behavior, and cache-only map pacing. Device acceptance uses a non-erasing flash to the stable D1L USB identity. Automated tests do not send RF; the button advert is checked physically only after an explicit double press.