Skip to content

release: AAA 0.17.1 product language hardening - #200

Merged
fantasyce merged 2 commits into
mainfrom
codex/release-v0.17.1
Aug 31, 2026
Merged

release: AAA 0.17.1 product language hardening#200
fantasyce merged 2 commits into
mainfrom
codex/release-v0.17.1

Conversation

@fantasyce

@fantasyce fantasyce commented Aug 31, 2026

Copy link
Copy Markdown
Owner

Summary

  • standardize active source, filenames, release checks, and public product copy on Across-owned Goal Contract and Goal review terminology
  • rename the four-component release-train lock schema, environment variable, script, test, and evidence filename
  • add a release-blocking product-language guard to the open-source check and coordinated four-repository acceptance
  • harden the guard against embedded identifiers, unreadable input, traversal failure, and absolute-path disclosure
  • bump AAA to 0.17.1 and correct the machine-readable Orchestrator release pointer to v0.12.2

Release train

Producer runtime versions are unchanged:

  • Across Orchestrator v0.12.2
  • Across Context v0.12.0
  • Across Autopilot v0.6.0

Local validation

  • product-language guard: four source trees passed
  • open-source check: passed
  • backend regression without a private provider override: 1578 passed
  • Swift behavior checks and package-lock verification: passed
  • Swift debug build and test build: passed
  • standalone and zero-host plugin boundary matrix: passed
  • installed App: v0.17.1, strict code-sign verification passed
  • packaged runtime: healthy with the three released producer versions
  • packaged cross-plugin lifecycle and Goal Contract E2E: passed
  • local live E2E through Codex CLI: 18/18 passed across minimal, REST, complex, and legacy-socket paths
  • live plugin probes: installed, available, integrity verified, and probe passed for all three producers

Hosted live-E2E boundary

A manual GitHub-hosted live-E2E run correctly stopped before task creation because the hosted macOS runner had neither a configured cloud provider nor a local Agent. Dependency installation and the real Orchestrator provider succeeded. No private model credential was injected and the provider gate was not weakened. The equivalent full live journey passed locally through Codex CLI.

Boundaries

  • no UI, Goal Contract, storage, plugin protocol, or producer runtime behavior changed
  • the release remains source-first and locally ad-hoc signed
  • published tag history is preserved; active default-branch and editable public copy are cleaned without rewriting immutable historical Git objects

@fantasyce

Copy link
Copy Markdown
Owner Author

Follow-up review fixes are in 80bb64c: embedded underscore identifiers and filenames are now blocked, scans fail closed on unreadable or non-UTF-8 source and traversal errors, diagnostics use repository labels plus relative paths only, and the default local provider path now resolves the sibling Across Orchestrator checkout. Evidence: focused release tests 23/23 passed; real-provider plus release-lock tests 15/15 passed without an environment override; full backend regression 1578/1578 passed without an override; the four-repository scan and open-source check passed.

@fantasyce
fantasyce merged commit 3663fa9 into main Aug 31, 2026
3 checks passed
@fantasyce
fantasyce deleted the codex/release-v0.17.1 branch August 31, 2026 18:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant