Immutable
release. Only release title and notes can be modified.
Tapid 0.0.10 release notes
Tapid 0.0.10 adds experimental policy-controlled root-script execution on macOS 26, restores upgrades using published GitHub releases, and checks executable documentation against source and release binaries. This is a development release, not a production-support or full npm-compatibility milestone.
Root-script execution
- Runs explicitly selected root
package.jsonscripts through default-on, fail-closed policy enforcement. - Requires checked-in
tapid.tomlpermissions and explicitassurance = "restricted"for the experimental macOS 26 Restricted backend. - Preserves forwarded arguments, including
tapid run dev -- --hostname 127.0.0.1 --port 3001. - Adds optional Node runtime selection, a byte-verified private Node snapshot, an allowlist-only environment, and controlled executable lookup.
- Reports launch enforcement and completion limitations through human-readable or JSON sandbox receipts.
- Keeps dependency lifecycle scripts disabled during installation.
Upgrades
- Restores
tapid upgradeagainst the canonical GitHub Releases API and the published platform archives withSHA256SUMSverification. - Prefers signed stable-channel discovery; the GitHub fallback applies when the default discovery endpoints are unavailable, not when explicit custom endpoints fail.
- Rejects invalid received signed-discovery metadata rather than treating a validation failure as an outage and falling back to weaker verification or cached recovery.
- Validates archive contents, stages executable replacement, preserves Unix executable permissions, and supports last-known-good recovery.
- Records whether release verification used signatures, checksums, or an unknown historical provenance.
- Adds documentation for
tapid upgrade --dry-run. Clients older than 0.0.10 can be upgraded by rerunning the public installer.
Documentation validation
- Adds executable documentation contracts with isolated source and published-binary lanes. The reviewed 0.0.10 capability expectation is not a claim that its unpublished artifacts have already passed validation.
- Adds a published Unix self-upgrade journey with an independently installed destination digest/version check and persisted verification-provenance checks. Release-time same-version replacement is distinct from previous-version upgrade evidence; Windows self-upgrade is not covered by this journey.
- Retains cross-platform package-installation smoke coverage. Actual 0.0.10 public results are a post-publication release gate, not inferred from source tests.
- Corrects outdated upgrade availability statements in the README, CLI documentation, release runbook, and threat model.
Limitations
- Native sandbox execution is experimental on macOS 26 and relies on deprecated/private Seatbelt interfaces. Support is behaviorally probed and unavailable required restrictions fail before target execution.
- Restricted does not guarantee complete descendant ownership or cleanup. Detached descendants can survive; process-group cleanup is best effort. Retained private runtime snapshots may consume temporary storage until safe host cleanup.
- ManagedTree, configured timeout/output/process/memory limits, and native Linux/Windows containment remain unsupported. No unsandboxed fallback or
--no-sandboxescape is implemented. network = truepermits unrestricted networking. Forwarded hostname and port arguments are application settings, not network policy enforcement.- GitHub archives and their checksums share the same provider trust boundary. The published release path provides integrity checking, not independent release authentication, platform code signing, or release provenance verification.
- Existing npm compatibility and package-management limitations remain; this release does not add workspaces, private-registry authentication, or dependency lifecycle-script approval.
Changed package versions
| Package | Version |
|---|---|
tapid-release-client |
0.0.3 |
tapid-runner |
0.0.4 |
tapid |
0.0.10 |
The release-client version changes because its public release-state model now records verification provenance and Fetcher requires an explicit typed fetch_metadata_with_limit implementation. Existing library consumers must implement that method when upgrading from 0.0.2; rejected responses must not be classified as fetch outages. The CLI dependency requirement selects the new version. Unchanged supporting crates retain their existing versions.