Complete first release candidate audit (#107)
Some checks failed
API and SemVer surface / api-surface (push) Failing after 1m34s
Native code generation / deterministic (push) Has been cancelled
Concurrency and resource soak audit / soak (push) Has been cancelled
Documentation / documentation (push) Has been cancelled
performance evidence / audit (push) Has been cancelled
First release candidate / non-fuzz-release-gate (push) Has been cancelled
Release platform and feature matrix / audit (push) Has been cancelled
Release platform and feature matrix / matrix (false, linux-stable-minimal, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, macos-stable-portable, x86_64-apple-darwin, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, windows-stable-portable, x86_64-pc-windows-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-msrv-portable, x86_64-unknown-linux-gnu, 1.96.0) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-default, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-features, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-release-surface, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Dependency and supply-chain audit / audit (push) Has been cancelled
Native release artifact audit / audit (push) Has been cancelled
Imaging and meshing gate / native (push) Failing after 53s
JPEG 2000 feature / linux (push) Successful in 2m49s
Native Rust workspace compile / compile (push) Failing after 59s
Skia feature / linux (push) Has been cancelled

This commit is contained in:
2026-08-12 14:44:28 +00:00
parent dceb394378
commit c9a1170a27
140 changed files with 82175 additions and 27179 deletions

View File

@@ -25,6 +25,24 @@ GRID_PASSWORD=...
GRID_LOGIN_URL=https://compatible-grid.example/login
```
The 19 compatibility cases require an additional explicit opt-in and never
infer consent merely because credentials exist:
```sh
RUN_LIVE_TESTS=1 cargo test --locked -p libremetaverse-compat-tests \
--test inventory_live_semantics \
--test appearance_live_semantics \
--test world_live_semantics \
--test network_semantics -- --nocapture
```
With the opt-in and all three `.env` values present, every live case is compiled
without `#[ignore]`. The test run must report zero ignored cases. Test bodies do
not print-and-return on missing OpenSim data: a missing inventory item, outfit
link, appearance update, covenant response, current-region lookup, capability,
or object packet is a real failure. Login uses the account's OpenSim `last`
location instead of a hardcoded Second Life region.
`GRID_LOGIN_URL` is used directly as the LLSD login endpoint; the harness does
not substitute a Second Life login host or path. The login request includes the
OpenSim response options for avatar search, classified fee, currency label,

82
docs/release-candidate.md Normal file
View File

@@ -0,0 +1,82 @@
# MetaCrate 0.0.1 release candidate
MetaCrate 0.0.1 is the first native Rust release candidate for the pinned
LibreMetaverse compatibility surface. It is releasable only when the native
`release-candidate-audit` reports `status: "ok"`; a generated `blocked` report
is evidence of remaining work, never permission to waive it.
## Supported platform boundary
- Linux x86-64 is the fully built and executed release platform. All Gitea
Actions jobs run on `ubuntu-latest` as required by repository policy.
- Portable, default-feature-disabled library surfaces are cross-compiled from
Ubuntu for Windows GNU x86-64 and macOS x86-64. Those checks do not claim
native runtime, installer, physical-device, CoreAudio, or WASAPI validation.
- Rust 1.97.1 is the release toolchain. Rust 1.96.0 is exercised separately and
only supports the minimum-version compatibility claim.
## Features and prerequisites
The default `libremetaverse` build uses the pure-Rust `dds-bc67` image path.
Optional boundaries are explicit:
| Feature | Capability | Native/build prerequisite |
| --- | --- | --- |
| `jpeg2000` | J2K/JP2 through the safe OpenJPEG adapter | OpenJPEG 2.5.4 or newer |
| `skia` | PNG/JPEG/WebP and other Skia formats | Skia 0.99 target cache or documented source tools |
| `vorbis` | PCM to Ogg Vorbis | the locked `vorbis_rs` native build stack |
| default WebRTC | native ICE/DTLS/SRTP/RTP/SCTP and Opus | system libopus 1.3 or newer |
| `real-audio` | physical microphone/speaker I/O | ALSA on Linux, CoreAudio on macOS, WASAPI on Windows |
OpenJPEG and Opus are dynamically discovered through the reviewed adapters;
Skia and Vorbis can contribute bundled native material and therefore carry the
notices documented in `release/THIRD-PARTY-NOTICES.md`.
## Compatibility and intentional differences
The release maps 3,066 public types and 30,789 members from upstream commit
`2aa70bb68513b39795da5d13c88f31b86e85a3ba`. Rust naming, ownership, async,
event, cancellation, error, overload, and feature decisions are fixed in the
SemVer baseline. In particular, Rust uses snake-case methods, typed overload
names, `Result`, native futures, subscription guards, project-owned boundary
traits, and unknown-bit-retaining flags instead of reproducing C# syntax or CLR
runtime types. The 80 delegate/APM replacements are intentional and compiled by
the independent downstream fixture. Full recipes are in
[`api/SEMVER-AUDIT.md`](../api/SEMVER-AUDIT.md).
Vivox support is a native protocol adapter and does not bundle the proprietary
Vivox service. Physical audio and proprietary service validation remain manual.
Live grid validation targets the exact `GRID_LOGIN_URL` from `.env`; it uses
OpenSim response options and does not substitute a Second Life endpoint.
## Evidence and approval
The policy in `ci/release-candidate-policy.json` verifies, without silent
waivers:
- all 16 release/source packages share version 0.0.1 and all ten shipped native
binaries remain in the artifact inventory;
- all 1,289 compatibility cases remain reviewed: 1,266 deterministic cases, 19
explicit live cases, four benchmark cases, and zero pending/unreviewed/drift;
- production Rust contains zero `not_implemented`, `unimplemented_api!`,
`todo!`, or `unimplemented!` failure paths;
- live tests contain no print-and-return success paths, fake and dedicated
OpenSim evidence each contain nine unique successful sanitized stages, and
the prior API/artifact/concurrency/documentation/provenance evidence remains
valid;
- the release notes, checksums, Rust 1.97 toolchain, and Ubuntu-only workflows
match policy.
Run the status gate with:
```sh
cargo run --locked -p metacrate-ci-matrix -- \
release-candidate-audit --evidence /tmp/metacrate-release-candidate.json
```
The command uses create-new evidence semantics. It writes a complete blocker
inventory before returning failure, which makes an incomplete release visible
in CI. Fuzz-smoke is the sole check currently marked `deferred_by_user`; it is
not presented as passed and is not silently executed. No signing identity is
configured for 0.0.1, so `release/SHA256SUMS`, Gitea artifact retention, and the
provenance/license manifests are the configured authenticity controls.