Skip to content

Epic: qualify a stable v1.0 capability-review release from the exact shipped distribution #572

Description

@pengfei-threemoonslab

Release decision — 2026-09-08

No-go for v1.0 at main 452bdeb80. This issue owns the release decision and sequencing, not a second scanner verdict or an instruction to close every open epic. The audit covers all 45 open issues (the three open Dependabot PRs are separate), recent implementation, stability/distribution contracts, release workflows and the recorded user/corpus evidence.

What v1.0 promises

A developer or platform reviewer can review a supported repository-declared agent capability change, see exact base/head evidence and coverage limits, and follow a truthful next action. Local/static operation and advisory-first CI remain the defaults. The stable CLI, reports and control contracts must mean the same thing in the downloaded build and its generated CI.

Do not claim runtime-effective permission, universal MCP/tool coverage, proven organizational adoption, or authenticated GitHub continuation without the separate evidence those claims require. Existing human-owned stops remain human-owned.

Blocking work

Evidence and authority

The selected product contract

Freeze and actual release

Dependency order and parallel work

  1. Now: close the contract/document contradictions (Reconcile live qualification instructions and delivery contracts with the approved 38/80 policy #566); name owners for release, benchmark signing, human labeling, security/support and pilot execution. A role is an obligation, not an invented assignee.
  2. Parallel engineering: current-control can return merge authority after the workspace or comparison base changes during the read #567; Qualification: hash and parse the same artifact bytes before scoring release evidence #559; Fixed-history release regression: establish reviewed scope for refused monorepo cases #563 and Miner: preserve new and renamed project directories when building the base verifier input #564; Diff attribution: establish dependency coverage before excluding a standing finding #557Scope the verdict to the diff by default, with an opt-in whole-tree mode #515; Separate prose-only instruction touches from the generic trust-root review route #545Deprecate instruction-weakening judgments for prose edits; retain structured permission and execution changes #516; The first discovery decision rejects supported host-only repositories before they reach Route H #568/A released wheel permanently generates CI pinned to the previous release #570 with bounded recovery. Keep discovery's integration-surface enumeration in parity with the runtime contract #553, minimum The accepted architecture record contradicts the product entering the v1.0 freeze #493/Define the v1.0 maintenance, security response and release recovery contract #494 and Enforce the repository and publication controls the release runbook already requires #573's effective publication controls and Pilot recovery: use a baseline path that satisfies the non-symlink identity contract on macOS #550's macOS pilot recipe can progress alongside them. Partition shared files when implementing.
  3. Parallel evidence: start Deliverable 2: the 80-case human-labeled beta corpus required for 1.0 (#456) #512's beta sourcing and blind human labeling immediately. A 0.16 tag or completed 38-case pre-1.0 corpus is not a prerequisite for 1.0. An explicitly unqualified preview can support Run the existing Route H pilot on an installable candidate and decide the v1.0 adoption claim #571; its four-week repeat-change observation overlaps engineering/corpus work.
  4. Converge: rerun the fixed history and supported cold-user/CI paths; finish Freeze the report 1.0 contract and prove migration before calling the product v1.0 #569, including active pre-1.0 tier retirement with historical readability before final wheel freeze. An unpublished RC can supply the compatibility exercise. Freeze the exact source, workflows, version, policy and wheel only after the selected behavior is settled.
  5. Qualify and rehearse: collect final-wheel receipts, score the unchanged beta policy, independently sign/promote through Cut D: exact-candidate evidence, independent qualification promotion and publication handoff (#456) #509, and rehearse Rehearse substantive qualification rejection and the exact final candidate before publication (#456) #510. Negative fixture preparation can happen earlier. Any final candidate change invalidates affected receipts/rehearsal evidence.
  6. Go/no-go and rollout: all pre-publication criteria met, product claims decided, release/support owner records the decision. Publish only the qualified bytes through the existing protected workflow. Complete A released wheel permanently generates CI pinned to the previous release #570's real tag/PyPI smoke and recovery checks before announcing rollout complete.

The 80-case beta policy retains 30 passed / 20 review-required / 30 blocked, at least 32 qualifying origins, κ≥0.80, per-stratum holdout≥20%, zero unsafe auto-passes, blocked exact30/30, safe≥27/30 and review≥19/20. Expected-IE is not a ground-truth class; actual IE remains a coverage/exact-score miss. The required report schema must deliberately follow #569's reviewed freeze. Neither a favorable pilot nor the 19-case history substitutes for beta qualification.

The existing external beta rollout condition — three distinct design partners and four weeks for affected profiles — is separate from the pilot decision ladder and machine qualification. A finite pilot shortfall or narrower launch language does not satisfy or waive it. Record evidence and applicability, or obtain an explicit reviewed policy decision. #570's pre-publication implementation/candidate smoke is a tag prerequisite; its real-channel smoke completes rollout after publication, so whole-issue closure is not required before the tag.

Conditional and deferred

#555#337#504 is mandatory only if authenticated GitHub recording/continuation is included in v1.0. The recommended first release withholds that claim; current request/evaluator/presentation do not establish independent human approval. #293 requires an actual host attestor. Keep #338 open for the broader autonomous workflow.

#511 remains non-gating participant validation. Do not block the release on all dependency bumps, general module decomposition, type/complexity budgets, schema relocation, a benchmark database, OWASP mapping, new adapters, committed organization state or a hosted control plane. Address a concrete candidate failure where demonstrated.

Done when

A linked release record identifies the exact candidate, unchanged approved beta evidence, named owners, compatibility/migration validation, both rehearsal outcomes, publication/channel verification and the explicit product claim. Every unresolved issue has an accurate hard/conditional/deferred classification. A milestone deadline, closed measurement issue, passing ordinary CI or missing private artifact in Git is never substituted for that record.

Release planning record

The full evidence audit and disposition of the original 45 open issues are in docs/engineering/v1-release-readiness.md. ROADMAP.md carries the 0–30 / 30–60 / 60–90-day parallel work and exact handoff order. Delivery PR: #574 (merged at 0aac28671e43586eec04eee14ddb9c6b04006bfd; one GitHub coding-agent review/address round and final CI, including combined coverage, passed). These capacity windows do not override the exit gates.

Implementation progress — 2026-09-08

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Next after P0; blocks other work or ships a misleading resultarea:releaseRelease pipeline, packaging, and safety qualificationepicTracking issue coordinating a group of related issues

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions