Skip to content

ShadowCode 0.33.1: reliable workflows and authenticated Linux releases - #4

Merged
Shadowfetchapps merged 148 commits into
mainfrom
flagship/reliability-foundation
Sep 28, 2026
Merged

Shadowfetchapps merged 148 commits into
mainfrom
flagship/reliability-foundation

Conversation

@Shadowfetchapps

@Shadowfetchapps Shadowfetchapps commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

ShadowCode 0.33.1 adds revision-checked editing and recoverable drafts, bounded context inspection, explicit Run a check receipts, safer Compare and workspace mutation handling, and provider task/sign-in isolation. It also adds authenticated Linux release and installation with protected signing and immutable artifact verification.

Published release: v0.33.1, frozen at e15c4480e65db5650af012bb2a9773dbe89acf84. The branch includes a subsequent publication-tooling retry fix and documentation of actual release/installation results; those changes do not alter the tag or shipped application bytes.

Validation:

  • Checks 36418625715 and Native desktop 36418625663 passed on the release source, including source checks, UI, native behavior/endurance, package builds, offline first launch and packaged integrations.
  • Release run 36427024374, attempt 1, passed all 15 build gates and protected signing. The publication job failed because the newly created draft was briefly absent from the release listing. Its failure is retained. Publication resumed locally through the exact frozen publisher and original signed artifact 10987931982, validating receipts and all seven remote assets before making the release public. A fresh public download matched all signed artifact bytes and passed offline signature/source verification.
  • The authenticated installer replaced the local 0.32.0 application with the published AppImage. Launcher/version, desktop source identity, accepted signature receipt, removal of superseded app/runtime, settings and database history preservation all passed. The installed app passed 20 native-window interaction groups and cleanup; normal user-profile desktop startup was also observed.
  • The post-release publisher fix retries only successful empty draft listings after creation, with bounded delays. It never repeats creation or retries API errors. All 70 focused publisher/signing/verification tests passed. Secret scan and whitespace checks passed.

Published package SHA-256:

  • AppImage: 434853525c1df842d5b8a749989dccd32d3b8ff3df34bdee94c857f26646519b
  • Debian: 4f93c63092e0a2e832839e5796afc1a208b29ea5dd18adbaae7cc9c6b17d30af
  • Runtime sources: 909ee4d387f09e587be3d7a48bfa13ad6e5277b01c2d75d701c22cf1a53a5ec7

Remaining acceptance limits: physical COSMIC/Wayland resizing failed its earlier check; broader clipboard/IME/DPI, GPU endurance, full live provider login-expiry/cancellation/continuation, ACP entitlement and repeated local-model coding quality remain open. Small live tasks and isolated fixtures do not establish those broader claims. See the evidence ledger.

The failed unpublished v0.33.0 tag is preserved unchanged. PR #4 remains open; publication did not merge it. Current-head follow-up CI is separate from the frozen release-source results above.

Unreleased follow-up: visible check evidence now refreshes after editor saves, editor-observed disk changes and relevant same-session engine events. A reproduced stale-green badge and an in-flight response race are covered by five new regressions; all 512 UI tests, TypeScript, production build and test-transport exclusion pass. This change is not in published 0.33.1 packages; general filesystem/other-session continuous invalidation and new package qualification remain open.

Additional released-package evidence: the authenticated public Debian snapshot passed installation, exact package/CLI version, MCP stdio, offline status and a visible first window in a network-disabled runtime-only container without Node/Rust/Cargo. The host OS was unchanged. Setup failures were retained and corrected; this is not Debian upgrade/rollback or GPU qualification.

@Shadowfetchapps Shadowfetchapps changed the title Harden task recovery, provider workflows, and native release qualification Prepare ShadowCode 0.33.0: reliable workflows and authenticated Linux releases Sep 28, 2026
@Shadowfetchapps
Shadowfetchapps marked this pull request as ready for review September 28, 2026 11:01
@Shadowfetchapps Shadowfetchapps changed the title Prepare ShadowCode 0.33.0: reliable workflows and authenticated Linux releases Prepare ShadowCode 0.33.1: reliable workflows and authenticated Linux releases Sep 28, 2026
@Shadowfetchapps Shadowfetchapps changed the title Prepare ShadowCode 0.33.1: reliable workflows and authenticated Linux releases ShadowCode 0.33.1: reliable workflows and authenticated Linux releases Sep 28, 2026
Shadowfetchapps and others added 4 commits September 28, 2026 14:14
Ported from the calmer-workspace draft (wip/calmer-workspace-draft):
reasoning effort, Compare and Worktree move into a More disclosure with
Escape and outside-click dismissal; blocked actions explain themselves
without closing the menu. Works alongside the existing wrap-at-any-width
composer layout.

The existing com.shadowfetch.shadowcode.appdata.xml gains a feature
list, bug tracker, developer, content rating and release history; the
draft's duplicate metainfo file is dropped. check-native-package now
validates strictly and requires the newest <release> to be the packaged
version.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Recovered from uncommitted work in a second clone
(Documents/Codex/2026-09-26/find), left after c04bdc6.
POST /api/jobs/verification-refresh reassesses 1-32 jobs with one shared
workspace fingerprint per request; visible summaries refresh together on
a shared five-second cadence, offscreen cards and hidden windows don't
poll, and superseded responses are discarded.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Shadowfetchapps
Shadowfetchapps merged commit b800c1f into main Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant