release-publish-prep: publish prep complete — metadata audit (descriptions/keywords/categories, homepage+docs omitted per family precedent), core package + publish dry-run verified cargo-native, engines verified from reconstructed exact-list packaged trees (registry verification is core-first by construction, captured error evidence), publish-exclusion verification clean (no fuzz/sidecar/suite leakage; in-src fuzz-surface probe tests expected), sqlite substrate PROVENANCE + dual-license notice confirmed riding the package, path-dep version bounds verified (0.y pin form per the amended ADR-017 §1), the manual publish checklist of record written; all gates + fuzz replay green; task -> completed
This commit is contained in:
1 parent
85f15175dd
commit
4a7520c817
1 file changed
+159
-10
+159
-10
@@ -1,7 +1,7 @@
|
||||
---
|
||||
id: release-publish-prep
|
||||
name: Publish prep — package verification, exclusion check, publish records
|
||||
status: pending
|
||||
status: completed
|
||||
depends_on: [release-readme, release-flake-investigation]
|
||||
scope: moderate
|
||||
risk: medium
|
||||
@@ -56,19 +56,19 @@ publish is the user's action, post-gate).
|
||||
|
||||
## Acceptance Criteria
|
||||
|
||||
- [ ] `description` landed on all four published crates; optional
|
||||
- [x] `description` landed on all four published crates; optional
|
||||
metadata decisions recorded
|
||||
- [ ] `cargo package` clean per published crate (verification posture
|
||||
- [x] `cargo package` clean per published crate (verification posture
|
||||
recorded); `.crate` contents inspected
|
||||
- [ ] Publish-exclusion verification recorded: no fuzz/sidecar/
|
||||
- [x] Publish-exclusion verification recorded: no fuzz/sidecar/
|
||||
contract-suite paths in any package's file list
|
||||
- [ ] Path-dep version bounds verified; publish order + version
|
||||
- [x] Path-dep version bounds verified; publish order + version
|
||||
decision recorded
|
||||
- [ ] Substrate PROVENANCE + license notice confirmed in the
|
||||
- [x] Substrate PROVENANCE + license notice confirmed in the
|
||||
`alkstore-sqlite` package
|
||||
- [ ] The manual publish checklist of record written (commands in
|
||||
- [x] The manual publish checklist of record written (commands in
|
||||
order, evidence attached)
|
||||
- [ ] Workspace gates + the fuzz corpus-replay gate green at session
|
||||
- [x] Workspace gates + the fuzz corpus-replay gate green at session
|
||||
end
|
||||
|
||||
## References
|
||||
@@ -86,8 +86,157 @@ publish is the user's action, post-gate).
|
||||
|
||||
## Notes
|
||||
|
||||
> To be filled by implementation agent
|
||||
### Decisions of record
|
||||
|
||||
1. **Release version — 0.1.0, by user decision at this task
|
||||
(2026-10-11).** This contradicted ADR-017 §1's "the initial release
|
||||
is 1.0.0" pin, so a **pre-release class-1 amendment** was recorded
|
||||
inline in ADR-017 §1 (the window this release closes): contract
|
||||
v1's content ships whole in 0.1.0; the §4.1 manifest pins take the
|
||||
ADR's own pre-1.0 `0.y` form (`alkstore = { version = "0.1", path
|
||||
= … }`); breaking changes bump `0.y`, additions `0.y.z`; the
|
||||
full coupling binds at the future 1.0. Motive recorded: the
|
||||
family's 0.x-initial precedent (alkcall 0.8.1, alktunnels 0.2.1,
|
||||
alksocks 0.1.0, alkblobs 0.1.0). This task's description itself
|
||||
assumed "0.1.0" — the CHANGELOG (release-readme) had seeded it, but
|
||||
the ADR pin was never dispositioned; the discrepancy was raised
|
||||
with the user rather than landing silently in either direction.
|
||||
2. **Optional metadata — `homepage` / `documentation` omitted.** The
|
||||
family precedent (alkcall/alktunnels/alksocks/alktty/alkblobs)
|
||||
carries neither field on any published crate; docs.rs links are
|
||||
automatic on crates.io and `repository` is the de-facto homepage.
|
||||
`keywords` + `categories` landed per crate (≤5 keywords,
|
||||
lowercase; valid crates.io category slugs). Descriptions follow
|
||||
the family's colon-form one-liners.
|
||||
3. **License texts ride the packages — per-crate `LICENSE-MIT` /
|
||||
`LICENSE-APACHE` copies.** The texts live at the workspace root,
|
||||
and cargo (1.99) does **not** package workspace-root license files
|
||||
into member `.crate`s: workspace-inherited `license-files` was
|
||||
tried first and proved a packaging no-op (verified in a sandbox —
|
||||
the field is accepted and inherited, but cargo's rewrite drops it
|
||||
and the tarball carries no texts), so the field was reverted and
|
||||
the canonical texts copied into the four published crate dirs,
|
||||
where cargo's auto-detect (`LICENSE*` in the package dir) packages
|
||||
them. The sqlite substrate's separate in-src bundled notice
|
||||
(`src/substrate/LICENSE`) is unaffected — ADR-018's carrier.
|
||||
4. **Verification posture.** `cargo package` verification (registry
|
||||
resolution + verify build) is core-first by construction:
|
||||
for the engines, the packaged manifest drops the path dep, so
|
||||
packaging/verification must resolve `alkstore = "0.1"` from the
|
||||
index — which fails pre-core-publish with
|
||||
`no matching package named 'alkstore' found … searched: crates.io
|
||||
index` (captured twice: `cargo package -p alkstore-postgres` and
|
||||
`cargo publish --dry-run -p alkstore-mem`). Posture: **core got the
|
||||
full cargo-native path** (`cargo package` clean, verification build
|
||||
green, `cargo publish --dry-run` green to the "aborting upload due
|
||||
to dry run" line); **engines got reconstructed-tree verification**:
|
||||
per engine, the exact `cargo package --list` file set + a
|
||||
hand-normalized publish-shaped manifest (the only semantic deltas
|
||||
from the workspace manifest: the workspace-inheritance
|
||||
concretization and the core dep's registry edge restored as its
|
||||
publish-legal `version = "0.1", path = "../alkstore"` form — the
|
||||
substitution; the suite stays a path-only dev-dep in the published
|
||||
shape, which consumers never fetch) → `cargo build` + `cargo test`
|
||||
green in each. The engines' registry-side verification happens
|
||||
live, in order, at the publish session (checklist below).
|
||||
|
||||
### Field audit (the evidence)
|
||||
|
||||
- `cargo package --list` per crate saved at the time of the run; the
|
||||
core `.crate` (the real cargo artifact,
|
||||
`target/package/alkstore-0.1.0.crate`, 30 files) inspected: license
|
||||
texts at the tarball root, README, the normalized `Cargo.toml`
|
||||
(concrete fields, path dep dropped), no stray paths.
|
||||
- **Exclusion verification (review-wave-7 item 4(iii)) — clean.** Each
|
||||
package's file list diffed against its directory contents (identical
|
||||
mod sort order): **no `fuzz/` paths, no `alkstore-fuzz-shared`
|
||||
references, no grown corpora/artifacts in any package**; the suite
|
||||
(`publish = false`) appears in no `[dependencies]` — engines carry
|
||||
it only as a path-only dev-dep, and it is not a package itself. The
|
||||
workspace `exclude = ["fuzz"]` holds (fuzz is a separate, excluded
|
||||
workspace). The engines' `src/fuzz_surface_tests.rs` files DO ride
|
||||
their packages — expected: they are the documented doc-hidden
|
||||
re-export probe tests *inside the crate* (release-crate-docs), not
|
||||
sidecar leakage.
|
||||
- **`alkstore-sqlite` substrate — both carriers confirmed in the
|
||||
package**: `src/substrate/PROVENANCE.md` (the full register with
|
||||
fork-point statement and delta entries) and
|
||||
`src/substrate/LICENSE` (the dual MIT+Apache text + fork-point +
|
||||
modification statements); `substrate/mod.rs`'s module doc names
|
||||
both, and the crate README + root README point at the notice — the
|
||||
package is honest about carrying them (ADR-013 §3 / ADR-018 §1).
|
||||
- **Path-dep version bounds verified**: `alkstore = { version = "0.1",
|
||||
path = "../alkstore" }` on all three engines (the §4.1 carrier 1
|
||||
manifest pin, pre-1.0 `0.y` form) and on the suite's dep; no
|
||||
versioned path dep missing its bound.
|
||||
- Packaged-source test evidence (all green, 2026-10-11): core
|
||||
`.crate` extracted → 25 + 0 doc-tests; sqlite tree 193 + 25 suite
|
||||
rows + 0; mem tree 102 + 25 + 1 doctest; postgres tree 127 + 25 + 9
|
||||
+ 0 (postgres rows skip-green without a server env, the same posture
|
||||
as the workspace test run).
|
||||
|
||||
### The manual publish checklist of record (the user's publish session)
|
||||
|
||||
Run from the workspace root; gates are assumed green (this task's
|
||||
evidence; re-run if any later commit touched code):
|
||||
|
||||
```
|
||||
cargo build
|
||||
cargo test
|
||||
cargo test --manifest-path fuzz/shared/Cargo.toml
|
||||
cargo clippy --all-targets -- -D warnings
|
||||
cargo fmt --check
|
||||
RUSTDOCFLAGS="-D warnings" cargo doc --no-deps
|
||||
```
|
||||
|
||||
```
|
||||
# 1. Core first — the engines' packaged manifests resolve `alkstore
|
||||
# = "0.1"` from the index; until this lands, cargo package/publish
|
||||
# for the engines is impossible (the error this task captured).
|
||||
cargo package -p alkstore && tar tf target/package/alkstore-0.1.0.crate
|
||||
# eyeball: LICENSE-MIT/LICENSE-APACHE at the tarball root, README,
|
||||
# no stray paths (this task's evidence: 30 files, all clean).
|
||||
cargo publish -p alkstore
|
||||
# wait for index availability (a minute or two;
|
||||
# `cargo search alkstore` resolving is the readiness probe).
|
||||
|
||||
# 2. Engines — any order among them (mutually independent); each now
|
||||
# packages + verifies fully against the live core:
|
||||
cargo package -p alkstore-sqlite
|
||||
tar tf target/package/alkstore-sqlite-0.1.0.crate | grep -E 'LICENSE|substrate'
|
||||
# eyeball: LICENSE-MIT/LICENSE-APACHE at the tarball root AND
|
||||
# src/substrate/{PROVENANCE.md,LICENSE} riding in-tree.
|
||||
cargo publish -p alkstore-sqlite
|
||||
|
||||
cargo package -p alkstore-postgres && cargo publish -p alkstore-postgres
|
||||
cargo package -p alkstore-mem && cargo publish -p alkstore-mem
|
||||
|
||||
# 3. Tag + forge release: v0.1.0 (the CHANGELOG's tag link points here).
|
||||
```
|
||||
|
||||
## Summary
|
||||
|
||||
> To be filled on completion
|
||||
Landed (2026-10-11): ADR-017 §1's pre-release class-1 amendment (initial
|
||||
release 0.1.0, user decision — family 0.x-initial precedent, §4.1 pins
|
||||
stay the pre-1.0 `0.y` form); package metadata on the four published
|
||||
crates (colon-form descriptions, keywords ≤5, categories; homepage/
|
||||
documentation omitted per family precedent); per-crate LICENSE-MIT +
|
||||
LICENSE-APACHE copies (workspace-inherited `license-files` proved a
|
||||
cargo-1.99 packaging no-op in a sandbox, reverted — the copies are what
|
||||
cargo's auto-detect packages). Package verification: core full
|
||||
cargo-native (package + verify build + `publish --dry-run` clean, 30
|
||||
files); engines blocked pre-core-publish by construction (captured
|
||||
error) — verified from reconstructed exact-`--list` trees with the
|
||||
publish-shaped manifests (core dep as its publish-legal version+path
|
||||
form), all green (sqlite 193+25, mem 102+25+1, postgres 127+25+9).
|
||||
Publish-exclusion verification clean: no fuzz/sidecar/corpora/ suite
|
||||
paths in any package's file list (engines' in-src
|
||||
`fuzz_surface_tests.rs` are the documented crate-internal probe tests,
|
||||
not leakage); sqlite's package carries `src/substrate/PROVENANCE.md` +
|
||||
the dual-license `src/substrate/LICENSE`, documented in `mod.rs` and
|
||||
the readmes. Path-dep bounds verified on all engines + suite; the
|
||||
manual publish checklist of record (core → engines, per-crate package
|
||||
→ eyeball → publish, plus the gates) written into Notes. Gates at
|
||||
session end: build, full `cargo test` (15 result blocks green),
|
||||
clippy `--all-targets -- -D warnings`, fmt --check, doc gate
|
||||
(`RUSTDOCFLAGS="-D warnings"`), fuzz corpus replay — all green.
|
||||
Reference in new issue
Block a user