Skip to content

Releases: AChWorks/achrix

AChrix v0.3.0

AChrix v0.3.0 Pre-release
Pre-release

Choose a tag to compare

@ach1992 ach1992 released this 05 Oct 04:53
cbdbaac

Developer source release of the pre-v1 v0.3 line. New consumers should pin github.com/AChWorks/achrix@v0.3.0 and begin with the versioned product quick start.

Included

  • Optional Multi-Site exact-authority resolver (achrix.multisite.resolve ABI 1) in the shared Foundation release. Single-site products may omit it; products still own trusted ingress and all site-bound authorization/data/storage/configuration.
  • Media private SVG opt-in with immutable schema version 3. Default PNG/JPEG and the finite common profile remain unchanged; SVG remains a private attachment format, not a public-inline capability.
  • Bounded per-instance Identity/Audit/Media pool and operation admission configuration via MaxConns / MaxOperations, preserving documented finite defaults.
  • Separately authorized clean PNG/JPEG preparation (achrix.media.prepare-public-image ABI 1). It prepares a verified private derivative result but grants no original Read, publication, public URL, storage activation or future authorization.
  • Media and Identity/Audit public dependency-error boundaries now preserve only documented safe categories/context identities rather than private provider/destination wrapper text or unwrap objects, while retaining bounded diagnostics, cancellation and unknown-outcome/accountability behavior.
  • Versioned v0.3 consumption and v0.2 -> v0.3 migration guidance.

These packages still share one Go module/version. Products own domain/content schemas, permissions, composition, ingress, configuration, deployment, publication and real recovery policy. A source release does not migrate a database or activate/deploy a product.

Compatibility and migration from v0.2

This is a breaking v0 minor relative to v0.2, not a v0.2.x patch.

  • Replace positional Identity/Audit/Media Config literals with keyed fields before adopting v0.3. Zero resource fields keep documented bounded defaults; zero never means unlimited.
  • Media schema version 3 requires explicit migration. Quiesce old writers, preserve a coherent PostgreSQL metadata/ledger plus private-original capture, run the migration with a deadline, then start only the new composition.
  • Published v0.2 source expects the older Media ledger and rejects schema version 3. Source downgrade is not database rollback; use the reviewed forward source or restore a coherent pre-upgrade capture into a compatible target.
  • PreparePublicImage and Multi-Site are additive capability ABI 1 surfaces and do not upgrade unrelated existing capability ABI revisions.
  • Consumers must not depend on pgx/provider/destination-specific error unwrap objects as public Foundation API. Existing mutation acknowledgement/reconciliation semantics are unchanged.

Published v0.1.0 and v0.2.0 tags/source remain immutable.

Environment and limits

The existing supported environment and owning Module guides remain authoritative. The release is a source Foundation dependency, not a production application distribution. Whole-product recovery/update UI, production deployment, Rixa runtime isolation proof and later retained-state proof remain separately owned outcomes.

Verified source identity

  • Source commit: cbdbaac4ce868b1c9096ab7d7cfe23d8ac4006ee
  • Source tree: e9232801247167a9a863e219ad55e6abb3db7c90
  • Exact-main baseline: run 37263849757 — SUCCESS
  • Hosted preparation: run 37265041700 — SUCCESS
  • Runtime safety corrections: #83 / PR #86 and #84 / PR #87, each independently reviewed and post-main verified
  • v0.3 release documentation: #88 / PR #89, independently reviewed COMPLETE/APPROVE and post-main verified

AChrix v0.2.0

AChrix v0.2.0 Pre-release
Pre-release

Choose a tag to compare

@ach1992 ach1992 released this 03 Oct 02:13
6624e4b

Developer source release of the pre-v1 v0.2 line. New consumers should pin github.com/AChWorks/achrix@v0.2.0 and start with the product quick start.

Included

  • Minimal instance-owned Core with executable optional-capability admission and bounded/distinguishable authorization, readiness and lifecycle behavior.
  • Selectively composed Identity: product-local accounts, maintained Argon2id passwords and revocable server-side sessions, with a trusted same-origin HTTPS cookie/CSRF adapter.
  • Audit: accountable account mutations in the same supported PostgreSQL transaction plus separately authorized bounded query/export.
  • Private Media: retained original attachments, immutable metadata/migrations, explicit reconciliation and coherent quiesced fixture database/private-asset restore. PNG/JPEG remain the default; an explicit finite common profile admits supported image/document/archive/audio/video attachments. SVG/SVGZ and executable/HTML/macro-enabled Office formats are excluded; opaque recognition is not malware scanning or a safe-to-open guarantee.
  • Small Admin shell with real Identity-owned and Media-owned forms, English/Persian direction and bounded browser/transport behavior.

These packages share one Go module/version. Products own their domain/content model, schemas, profiles/roles, permission policy, selected composition, ingress, configuration, deployment and real recovery profile. Unneeded runtime Modules are not constructed; no generic runtime plugin loader or automatic product updater is introduced.

Compatibility and upgrades

This is a breaking v0 minor relative to v0.1, not a v0.1.x patch. Read the migration contract:

  • Use keyed Descriptor literals and review Optional dependency metadata.
  • Core authorization requires ABI 2. Explicit denial uses ErrDenied; evaluation failures are unavailable, not denial.
  • Every Authorize/Ready call needs a deadline; policies are concurrent-safe and cancellation-cooperative.
  • Stop ingress and drain product domain/transaction work before Application shutdown; arbitrary noncompliant in-process code cannot be forcibly interrupted.

The immutable v0.1.0 tag/source and v0.1.x patch compatibility commitments remain intact. v0.2 is the developer line for new consumers; this successor does not announce v0.1 retirement or permanent LTS/backports. Official Module Descriptor.Version values report the actual Foundation dependency via achrix.Version(), independently of capability ABI revisions and deprecated historical source-line constants.

Keep custom product code separately owned, use public contracts and deliberately update the dependency, validate affected behavior, rebuild and redeploy. Source updates do not activate an existing product, and code rollback does not reverse state/external effects.

Environment and limits

Operations owns the tested matrix: Go 1.27.1, ordinary PostgreSQL 18 UTF-8 and the documented Linux storage profile for Media. Read the owning Module guides for exact configuration, resource/permission boundaries and immutable migration requirements.

The source archive contains tracked documentation, fixtures and tooling; it includes no product executable or vendored dependency implementation. The SPDX inventory covers that exported source/manifest scope, not a deployed-runtime SBOM.

The isolated Notes consumer, real PostgreSQL/race/retained-state/private-asset checks and trusted HTTPS browser fixture provide bounded evidence. They do not establish stable-v1 API, production CMS, aggregate product capacity/SLO, public image delivery, whole-product/off-host/RPO/RTO recovery, remote activation or one-click updates. #19 remains paused under its independent owner/product gate; Search, Settings, Notifications and reusable Recovery await their real workflow/profile evidence. Multi-Site and Gateway Bridge remain owner-gated.

Verified identity and evidence

  • Source commit: 6624e4b40de33b92e3da0d187e10a667ca798981
  • Source tree: decd484e0a072882915b6303f3fd8d8120d63e48
  • Exact-main documentation baseline: 37088212996
  • Hosted preparation: 37088280799
  • Unchanged runtime full PostgreSQL/race/retained database/private-asset validation: 37086154981, source c904eca; intervening changes are docs only.
  • Review and complete release acceptance: Issue #73, PR #74; broad bounded source assessment #69 retains its original snapshot scope.

Attached archive, source SPDX inventory and release.json have SHA256SUMS and verified GitHub/Sigstore build provenance; the archive also has a verified SPDX SBOM attestation. The archive was checked against the deterministic Git export of the approved source before staging this release. Normal isolated v0.2.0 resolution/checksums and real executable Foundation/Module identities were verified before publication. First-party source is MPL-2.0; preserve covered source and the applicable third-party notices according to the licensing policy.

AChrix v0.1.0

AChrix v0.1.0 Pre-release
Pre-release

Choose a tag to compare

@ach1992 ach1992 released this 01 Oct 21:32
1798ee2

First developer-consumable source release of the initial AChrix v0.1.x development line.

Scope

  • Minimal Go Foundation public composition, Application authorization and lifecycle contracts.
  • Source-only developer dependency; no product executable, deployment distribution, UI/translation engine, universal updater or backup service is included.
  • The v0.1.x line is pre-v1. The compatibility/support and upgrade boundary is defined by docs/lifecycle/lifecycle-and-compatibility.md; the tested environment is owned by docs/operations/operability-performance.md in this source release.
  • Consumers should pin and deliberately validate the reviewed version, for example: go get github.com/AChWorks/achrix@v0.1.0.

Verified source identity

  • Commit: 1798ee2f38bd7a87ecdfffdccad1925b934e4134
  • Tree: fa8c41c918e16ae07c688da28b89bafd8cd4f829
  • Exact-main baseline: GitHub Actions run 36928072227
  • Hosted release preparation: GitHub Actions run 36928314073

The attached source archive, SPDX source inventory and release.json are covered by SHA256SUMS and GitHub/Sigstore provenance. The source archive also carries a verified SPDX SBOM attestation. The archive was independently checked byte-for-byte against a deterministic Git export of the commit above before staging this Release.

This Release does not claim stable-v1 compatibility or production-product readiness. Product update, deployment, backup/restore and related product lifecycle proof remain separately gated work.