Releases: KooshaPari/HeliosLite
Release list
v2.13.21-h.0.2.9
Validation release for the 45-minute UDF retry window.
Extends the Update Distribution Files retry window from ~5 minutes to 45 minutes at 30s intervals, sized to observed Multi Channel Release attach times of 27m21s and 33m29s (both workflows trigger on release: published). The ~5-minute window in h.0.2.5-8 was structurally too short. Adds a workflow_dispatch trigger with a required tag input so distribution manifests can be regenerated against an already-published release without cutting a new cycle.
Also validated in this cycle:
- rmcp 1.8.0 -> 3.4.0 dependency migration (closes 3 dependabot alerts): AuthorizationRequest builder, unified ContentBlock union, ClientConfig rename; process-wrap 10 transitively (bfdaa88)
- vite ^5.4.0 -> ^8.3.0 for the landing app (closes 3 dependabot alerts)
- install.sh, Homebrew, Chocolatey, and Scoop packaging repairs (dcdbb17)
- Distribution manifest digests cross-verified against release asset checksums
v2.13.21-h.0.2.8
Validation release for the Update Distribution Files race fix.
Release assets were being attached concurrently by Multi Channel Release while Update Distribution Files downloaded SHA256 checksums, both triggering on release: published. When the manifest job won the race, checksum downloads failed with no assets to download (h.0.2.7, run 35422470734). The download step now retries for up to ~5 minutes before failing, and a genuinely absent checksum still fails the run.
Also validated in this cycle:
- install.sh, Homebrew, Chocolatey, and Scoop packaging repairs (dcdbb17)
- rustls 0.23.45 (CVE-2024-6119 advisory bump)
- sign_release
contents: writepermission ceiling fix
v2.13.21-h.0.2.7
HeliosLite v2.13.21-h.0.2.7 — ships the language-server fixes
Cut from db571577d (all 14 workflows green; code that matters: a8ad28703, plus the PhenoShared duplicate-key manifest repair b2d06d53 now consumed by this pin and the forge_ci generator alignment db571577d).
Fixes shipped since v2.13.21-h.0.2.6
These are all in the forge / helioslite binaries — crates/forge_main/Cargo.toml:109 links
forge_lsp, and forge_main builds the released forge target.
McpWatcherHandle::stopno longer hangs. The background task parks inrx.recv()waiting for
the next filesystem event, andstop()only set a flag, so shutdown blocked until an unrelated
file event arrived (or the caller's timeout expired). Adds ashutdownNotifyand selects on it
in both the event wait and the debounce drain (d9a5871a9). Observed before/after on the same
test: a deterministic 10.29s hang vs 13/13 tests passing in 1.07s.ProcessLspClient::did_openandServer::open_document. Language servers only serve requests
for documents they know about; withouttextDocument/didOpen, rust-analyzer answered definition
requests with-32603 file not found. The LSP e2e test also writes a minimal manifest and polls,
because rust-analyzer answers while it is still loading (3b1ebf4e7).- File-scoped CLI commands work on a cold server.
forge_lsp::commands::run_commandnow
registers the target document (Server::open_document_file) andCommand::Definitionwaits for
the project to load. Before:lsp server error: file not found (code -32603); after: a real
location (be581d8c9,77607f74c).
CI fixes carried in this release line
sign_releasecaller permission raised tocontents: write(reusable workflows cannot elevate
beyond the caller grant — this was the originalstartup_failure).- Windows signing is skipped with a warning when
SIGNPATH_*credentials are absent, instead of
failing the whole release; Windows binaries are therefore unsigned until those secrets and
variables are configured. platform-tests/test.yml/helios-lite-nightly: the rust-analyzer installer no longer writes
into$HOME/.cargo/bin, whererust-analyzeris a symlink torustupand the redirect was
overwritingrustupitself (this broke every cargo shim on macOS and ubuntu)..config/nextest.tomlkeeps its 30sterminate-afterdefault; the two LSP e2e binaries get a 90s
override because they legitimately wait for a language server to load a project.cvpno longer compares the PhenoShared rev against a hard-coded value; it asserts the three
cross-consumed dependencies agree.- Denied-lint (
clippy::indexing_slicing) violations cleared inforge_sharecliandforge_config.
Verified before publishing
Release v2.13.21-h.0.2.6 (same code line minus the LSP fixes) was validated end to end: assets
downloaded anonymously, checksums matched, the macOS arm64 binaries executed, and the signature
verified with codesign --verify --strict under Developer ID Koosha Paridehpour (GCT2BN8WLL).
Expect the same 55 assets here (27 binaries + 27 .sha256 + sbom.cdx.json) across all 9 targets.
v2.13.21-h.0.2.6
Verification release: Windows signing optional without SIGNPATH credentials
Resolves the sign job failure from v2.13.21-h.0.2.5:
Missing signing configuration: SIGNPATH_API_TOKEN.
Changes
- sign-release.yml: when SIGNPATH config is incomplete (no SIGNPATH_API_TOKEN/ORGANIZATION_ID/PROJECT_SLUG/SIGNING_POLICY_SLUG), skip Windows signing and attach unsigned Windows binaries instead of failing the release pipeline. macOS signing remains strict.
- Windows builds confirmed PASSING with PhenoShared cf914698 (run 35314533985: 7 of 9 build jobs succeeded before sign failure)
Prior fixes carried in this release line
- PhenoShared Windows-invalid-char fix (cf914698): 21 filenames renamed
- PhenoShared path-too-long fix (c8715972 + 62368071): 0 MAX_PATH violators
- rustls 0.23.45 (RUSTSEC)
- sign_release caller permission contents: write
- Platform tests fixed on macos/windows runners (ae28295)
v2.13.21-h.0.2.5
Verification release: PhenoShared Windows-invalid-char fix
Resolves the Windows aarch64/x86_64-pc-windows-msvc build failure from v2.13.21-h.0.2.4:
cannot checkout to invalid path '.kilo/audits/<REDACTED>-absorption-2026-06-18.md'; class=Checkout (20).
Windows git checkout rejects any path segment containing <>:"|?*. PhenoShared had 21 such filenames.
Changes
- PhenoShared (KooshaPari/PhenoShared): repinned
62368071→cf914698cf914698— replace<REDACTED>withREDACTEDin 21 filenames (launchd plists, audit findings, kilo audit note)- 0 Windows-invalid-char files remain at new HEAD
- Cargo.lock: regenerated to track PhenoShared cf914698
Prior fixes carried in this release line
- PhenoShared path-too-long fix (
c8715972+62368071): 0 MAX_PATH violators - rustls 0.23.45 (Cargo Security Advisories RUSTSEC)
sign_releasecaller permissioncontents: write(reusable workflow cannot elevate beyond caller grant)- Platform tests fixed on macos/windows runners (
ae282957e)
v2.13.21-h.0.2.4
Verification release: PhenoShared path-too-long fix
Resolves the Windows aarch64-pc-windows-msvc build failure from v2.13.21-h.0.2.3:
error: failed to get phenotype-observability as a dependency of forge_app → unable to update PhenoShared.git?rev=68beca26 (path-too-long).
Changes
- PhenoShared (KooshaPari/PhenoShared): repinned
68beca26→62368071c8715972— shorten snapshot paths under 260 chars for Windows cargo62368071— collapse duplicated segment chains from snapshot rename (44 renames)- 0 MAX_PATH violations remain at new HEAD (68-char cargo checkout prefix + path ≤ 260)
- Cargo.lock: regenerated to track PhenoShared 62368071
- Platform tests (from parallel session
ae282957e): fixed macos/windows runner failures
Prior fixes carried in this release line
- rustls 0.23.45 (Cargo Security Advisories RUSTSEC)
sign_releasecaller permissioncontents: write(reusable workflow cannot elevate beyond caller grant)
v2.13.21-h.0.2.3
Patch release. Main HEAD c059601. rustls 0.23.45 (RUSTSEC-2026-0285), sign_release permission ceiling fix (contents:write) to unblock Multi Channel Release asset publishing.
v2.13.21-h.0.2.2
Patch release. Main HEAD 3242ae9, 0 open PRs. PhenoShared shared-crate wiring + CVP workflow, cargo-nextest CI fixes (PATH/CARGO_HOME), cargo-deny git-source allow, lockfile regen, Gate 6+7 rebrand merge. Release workflow auto-attaches platform binaries + SBOM on publish.
v2.13.21-h.0.2.1
v2.13.21-h.0.1.8
What's Changed
- test(sharecli+tracera): integration smoke test for sharecli -> tracera interop by @KooshaPari in #300
- release(version): bump to 2.13.21-h.0.1.8 for P0-P3 backlog by @KooshaPari in #299
Full Changelog: v2.13.21-h.0.2.0...v2.13.21-h.0.1.8