Skip to content

AChrix v0.2.0

Pre-release
Pre-release

Choose a tag to compare

@ach1992 ach1992 released this 03 Oct 02:13
6624e4b

Developer source release of the pre-v1 v0.2 line. New consumers should pin github.com/AChWorks/achrix@v0.2.0 and start with the product quick start.

Included

  • Minimal instance-owned Core with executable optional-capability admission and bounded/distinguishable authorization, readiness and lifecycle behavior.
  • Selectively composed Identity: product-local accounts, maintained Argon2id passwords and revocable server-side sessions, with a trusted same-origin HTTPS cookie/CSRF adapter.
  • Audit: accountable account mutations in the same supported PostgreSQL transaction plus separately authorized bounded query/export.
  • Private Media: retained original attachments, immutable metadata/migrations, explicit reconciliation and coherent quiesced fixture database/private-asset restore. PNG/JPEG remain the default; an explicit finite common profile admits supported image/document/archive/audio/video attachments. SVG/SVGZ and executable/HTML/macro-enabled Office formats are excluded; opaque recognition is not malware scanning or a safe-to-open guarantee.
  • Small Admin shell with real Identity-owned and Media-owned forms, English/Persian direction and bounded browser/transport behavior.

These packages share one Go module/version. Products own their domain/content model, schemas, profiles/roles, permission policy, selected composition, ingress, configuration, deployment and real recovery profile. Unneeded runtime Modules are not constructed; no generic runtime plugin loader or automatic product updater is introduced.

Compatibility and upgrades

This is a breaking v0 minor relative to v0.1, not a v0.1.x patch. Read the migration contract:

  • Use keyed Descriptor literals and review Optional dependency metadata.
  • Core authorization requires ABI 2. Explicit denial uses ErrDenied; evaluation failures are unavailable, not denial.
  • Every Authorize/Ready call needs a deadline; policies are concurrent-safe and cancellation-cooperative.
  • Stop ingress and drain product domain/transaction work before Application shutdown; arbitrary noncompliant in-process code cannot be forcibly interrupted.

The immutable v0.1.0 tag/source and v0.1.x patch compatibility commitments remain intact. v0.2 is the developer line for new consumers; this successor does not announce v0.1 retirement or permanent LTS/backports. Official Module Descriptor.Version values report the actual Foundation dependency via achrix.Version(), independently of capability ABI revisions and deprecated historical source-line constants.

Keep custom product code separately owned, use public contracts and deliberately update the dependency, validate affected behavior, rebuild and redeploy. Source updates do not activate an existing product, and code rollback does not reverse state/external effects.

Environment and limits

Operations owns the tested matrix: Go 1.27.1, ordinary PostgreSQL 18 UTF-8 and the documented Linux storage profile for Media. Read the owning Module guides for exact configuration, resource/permission boundaries and immutable migration requirements.

The source archive contains tracked documentation, fixtures and tooling; it includes no product executable or vendored dependency implementation. The SPDX inventory covers that exported source/manifest scope, not a deployed-runtime SBOM.

The isolated Notes consumer, real PostgreSQL/race/retained-state/private-asset checks and trusted HTTPS browser fixture provide bounded evidence. They do not establish stable-v1 API, production CMS, aggregate product capacity/SLO, public image delivery, whole-product/off-host/RPO/RTO recovery, remote activation or one-click updates. #19 remains paused under its independent owner/product gate; Search, Settings, Notifications and reusable Recovery await their real workflow/profile evidence. Multi-Site and Gateway Bridge remain owner-gated.

Verified identity and evidence

  • Source commit: 6624e4b40de33b92e3da0d187e10a667ca798981
  • Source tree: decd484e0a072882915b6303f3fd8d8120d63e48
  • Exact-main documentation baseline: 37088212996
  • Hosted preparation: 37088280799
  • Unchanged runtime full PostgreSQL/race/retained database/private-asset validation: 37086154981, source c904eca; intervening changes are docs only.
  • Review and complete release acceptance: Issue #73, PR #74; broad bounded source assessment #69 retains its original snapshot scope.

Attached archive, source SPDX inventory and release.json have SHA256SUMS and verified GitHub/Sigstore build provenance; the archive also has a verified SPDX SBOM attestation. The archive was checked against the deterministic Git export of the approved source before staging this release. Normal isolated v0.2.0 resolution/checksums and real executable Foundation/Module identities were verified before publication. First-party source is MPL-2.0; preserve covered source and the applicable third-party notices according to the licensing policy.