Skip to content

release(v1.30.0): ship complete desktop at-rest encryption authority and verify migration/recovery #926

Description

@qnbs

CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-01

TARGET = v1.30.0
M0 = TERMINAL (#919 security predecessor + #917 Gate 2 slice 1)
M1 = ACTIVE (#920 Gate 2; Slice A PR #928)
M2..M6 = NOT YET ACTIVE
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

The active release-critical engineering lane is #920. PR #928 is the first bounded M1 slice; after it, #920 continues with legacy source-locator adapters and final Gate 2/#361 closure. Do not start release preparation merely because M0 is complete. The v1.30.0 cut remains downstream of Gates 2–7 and real packaged qualification.

Milestone mission

Make v1.30.0 the focused milestone release that completes and ships the renderer-neutral desktop at-rest encryption program owned by #445.

A minor-version bump from v1.29.1 to v1.30.0 is intentional: this is a substantial new production security/storage capability and migration boundary, not a patch-only correction.

MILESTONE = COMPLETE_DESKTOP_AT_REST_ENCRYPTION
TARGET_VERSION = 1.30.0
PRIMARY_PROGRAM = #445 / R-15
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO until Gate 7 authorization

Primary execution sequence

  1. TERMINAL — security(deps): raise axios and DOMPurify floors after fresh OSV gate failure #918 via PR fix(deps): raise the axios and DOMPurify override floors (fresh OSV findings, #918) #919 merged and resulting main proven.
  2. TERMINAL — PR feat(core): add the Gate 2 typed record-identity registry (#445) #917 Gate 2 typed identity-registry slice merged and resulting main proven.
  3. ACTIVE — finish Gate 2 via security(core/R-15): Gate 2 — complete identity-bound adapters and AAD closure #920 bounded slices (Slice A PR feat(core): add the Gate 2 identity-bound record codec (#445) #928 → Slice B source-locator adapters → Slice C/Bind desktop fs-backed ciphertext to its record identity (AAD) to prevent cross-file substitution #361 closure).
  4. Gate 3 via security(core/R-15): Gate 3 — durable protected-record adapter and crash-durability proof #921 — durable protected adapter / Desktop atomic writes: fsync temp file + parent directory before/after rename for true crash durability #357 reconciliation.
  5. Gate 4 via security(core/R-15): Gate 4 — journal, admission, rekey/recovery and cross-process serialization #922 — journal/admission/rekey/recovery/cross-process serialization / Desktop fs-data key-rotation migration is not crash-resumable (mixed-key state possible) #359/Desktop fs reads/writes don't participate in the encryption-migration admission lock (race window during disable/rotate) #360.
  6. Gate 5 via security(core/R-15): Gate 5 — fence every protected writer and complete inventory/migration readiness #923 — all protected classes fenced + inventory-complete migration readiness.
  7. Gate 6 via security(core/R-15): Gate 6 — packaged shadow/compatibility qualification on Linux, Windows and macOS #924 — packaged shadow/compatibility qualification using test(native): automate packaged-state release qualification for built Tauri desktop artifacts #906.
  8. Explicit maintainer authorization checkpoint for Gate 7.
  9. Gate 7 via security(core/R-15): Gate 7 — explicit production authority switch, legacy migration and cutover #925 — production authority switch + preserve-first legacy migration.
  10. Freeze release candidate and execute release qualification.

No unrelated roadmap expansion should preempt this lane unless a fresh P0/P1 security/data-loss/release blocker requires it.

Mandatory release prerequisites

Product/security

Packaging / qualification

Release pipeline

  • release: make tag-time publishing depend on the security audit (Tauri release + GHCR) #911 should be resolved before v1.30.0 tag unless a documented maintainer decision explicitly accepts the old procedural watch as a temporary exception; preferred target is machine-gated Tauri + GHCR publication on fresh tag-time Security Audit;
  • exact candidate Security Audit, CI/CD and CodeQL green;
  • updater/release metadata correct;
  • GHCR semantic tags/aliases verified;
  • signed tag; never move/reuse a failed tag.

Compliance / distribution

Release execution

freeze exact candidate SHA
→ resulting-main CI/CD + CodeQL
→ fresh side-effect-free Security Audit
→ exact-SHA packaged builds
→ packaged at-rest qualification matrix
→ release-truth/docs final check
→ signed v1.30.0 tag
→ tag-time security gate
→ Tauri/GitHub Release + GHCR publication
→ verify assets/digests/updater metadata
→ verify canonical web/production health
→ verify upgrade path from v1.29.1
→ declare v1.30.0 VERIFIED

Terminal definition

Do not close on tag creation alone. v1.30.0 VERIFIED requires published desktop assets, correct GHCR state, verified signed tag, exact released commit, packaged migration/reopen proof, no stored-data regression, at-rest claims proven against real released artifacts, healthy post-release main and mirrored Linear evidence.

After terminal release

Immediately hand off to #927 for the dedicated post-v1.30 source-truth/audit/housekeeping reset, then resume the highest-priority non-R-15 roadmap work from a freshly audited control plane.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions