Skip to content

Permesh 0.1.0-alpha.3 — evaluation prerelease

Pre-release
Pre-release

Choose a tag to compare

@Cylop Cylop released this 09 Sep 14:56
add7a72

Permesh 0.1.0-alpha.3 — evaluation prerelease

Evaluation prerelease, not a stable release. These are the original qualified
artifacts from exact source add7a725745f5e05415b330e8d6be61fcaaf5d67 and
attested workflow 34351503021.
Published alpha.1 and alpha.2 assets remain unchanged.

Changes since alpha.2

  • Explicit stable-account identity mappings and pinned JSON identity inventories.
  • Private versioned snapshots, offline inspection and scope-aware diffs.
  • Read-only offboarding assessment, advisory plans and JSON/HTML verification.
  • Resource queries, focused local policies and offline provider development tools.
  • Scoped native-provider approvals, launch integrity checks, negotiated discovery,
    explicit network context and portable target-specific executable pins.
  • Host-owned exact-field credentials from 1Password Connect and separately
    dispatched Vault/OpenBao KV v2; explicitly selected temporary AWS profiles.
  • Seven separate provider 0.2.0 candidates: GitHub, Google Workspace, Cloudflare,
    AWS IAM, GitLab, Entra and AWS Identity Center. They are distributed separately and are not bundled with the CLI.

Compatibility and migration

Access JSON uses schema 2; control commands
retain schema 1. Local snapshot, diff and offboarding artifacts have independent
versioned contracts. Consumers must check the command, schema, completeness and
limitations. No SDK or negotiated protocol stability is declared.

Legacy bundled provider execution is removed. Follow the explicit
GitHub and Google migration
instructions. Legacy GitHub 0.1.0 remains available; negotiated-v1 providers
require separately distributed 0.2.0 packages. Downloading or updating a package
does not authorize execution, adopt workspace pins or deliver credentials.
The exact alpha.3/0.2.0 pair below passed local packaged acceptance. This does
not establish the oldest compatible host version. Public catalog availability
and acceptance are recorded separately below.

Upgrade the CLI to alpha.3 before using the expanded provider catalog. Alpha.2
rejects negotiated-v1 catalog metadata, including when requesting legacy 0.1.0.
Adding catalog entries does not change existing installed packages, trust or
workspace pins. Separately, upgrading from alpha.2 leaves legacy approval records
stored but requires one fresh scoped review and explicit approval before provider
health checks or queries; old approval authority is not carried into alpha.3.

Qualification and promotion

The reviewed candidate source is
add7a725745f5e05415b330e8d6be61fcaaf5d67,
merged by PR 41 after
three-platform CI, minimum-Rust, dependency checks and all five native PR jobs
passed. Its tree matches reviewed head 4e32264bb646f542d0b9b692cc4f08b58078ac27.
The exact-main attested run 34351503021
passed all five native jobs and its downstream signed-provenance verification.
The exact merged revision also passed
CI and
dependency checks.

On 2026-09-09, all 20 original archive/inventory/checksum subjects were downloaded
and independently verified. Checks covered GitHub upload SHA-256 digests, strict
archive/file allowlists, native architecture, binary/inventory/locked dependency
bindings, registry checksums and dependency notice-content hashes. All 20 subjects
also passed both distributed-bundle and public repository attestation verification
against this exact source/signer SHA, the attested workflow identity,
refs/heads/main, SLSA v1 predicate and hosted-runner requirement.
The original bundle and 20 subjects are retained without rebuilding or recompression.
The release assets are those exact original workflow files.

Packaged acceptance

The exact Apple Silicon executable SHA-256 is
33d366c9b7481bed551b9de41a81af95324984f36d145a03288cf9b2147630a8.
It passed the following local checks:

  • Public catalog GitHub 0.1.0 install, update check and idempotent exact-version
    update; workspace bytes stayed unchanged and no trust/approval state appeared.
  • All 35 provider 0.2.0 archives from
    run 34349822945,
    source fde7472c2c32a30bbd885f7c8db6d73b178f4aa1, passed the alpha.3 host
    PackageStore validator through a separately compiled source-matched harness.
    This is five-target package-format acceptance on macOS, not execution of foreign
    target binaries.
  • All seven native macOS providers passed credential-free protocol descriptions
    and handshakes, then actual declarative setup through the packaged CLI, explicit
    executable trust, no automatic workspace approval, wrong-fingerprint rejection,
    exact approval and missing-credential rejection. Reviewed five-target digest maps
    and the native resolved digest matched the validated packages; missing and changed
    native pins failed before credential delivery.
  • Portable maps were explicitly applied to the setup-generated local configuration.
    The production catalog URL was unchanged. This does not exercise public
    guided installation/update of 0.2.0 entries; subsequent public acceptance is
    recorded below.
  • Synthetic identity/resource queries, private snapshots, inspection/diff,
    offboarding assessment/plan/verification with local HTML and policy findings
    exit 6 passed. Snapshot, plan and HTML modes were 0600 and queries preserved
    workspace bytes. Four controlling-PTY checks passed: organization input,
    nonprompting JSON, hidden-input EOF and terminal echo restoration.
  • A uniquely named synthetic macOS Keychain entry passed CLI absence, store,
    status and deletion. An independent /usr/bin/security value read exceeded its
    20-second deadline. Cleanup ran and a separate CLI status confirmed absence.
    The independent value comparison and full interactive desktop acceptance remain
    incomplete; the timeout is not recorded as a successful comparison.

The same CLI and the exact GitHub 0.2.0 executable
9f2b82992c62767229af9af93dc5ddc3520d4e43e0a61513f621de1bb4688f02
passed the previously authorized NIPE-Solutions-only read-only health,
provider-status and stable-account JSON query. Credentials and raw reports stayed
out of logs/artifacts; temporary trust/configuration state was removed. Visibility
limitations remained explicit, with no inferred verified email or canonical
identity. This binds that limited live result to exact packaged bytes; it does
not qualify other tenants, providers, API paths or targets.

Original candidate files

This release carries the following original files.
The bundle authenticates the 20 subjects; it is not itself a signed subject or a
platform code signature. Compare downloaded release bytes against these hashes.

File Bytes SHA-256
permesh-0.1.0-alpha.3-aarch64-apple-darwin.dependencies.json 106788 d4b300d4816ebb47b86dad66264967c27cac83a70cd62fbed3c13830133aeb73
permesh-0.1.0-alpha.3-aarch64-apple-darwin.dependencies.json.sha256 127 072ec0907305c106ed416b83a1b019fe84ecea6f8c1dae1ebf896285ae082d00
permesh-0.1.0-alpha.3-aarch64-apple-darwin.tar.gz 5090688 ec20f27a4aa4c9f776d0475861094bbd83ce884e1cae1cd35d67708617eed250
permesh-0.1.0-alpha.3-aarch64-apple-darwin.tar.gz.sha256 116 fdd7d84fd9ad7997118f2438c742cc804e302c4efac245ce1afe4f33012941c2
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.dependencies.json 139919 afa791bb3b78be3243787e7a602db3c1fbdecb9ac5809fea3000ec8039352c49
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.dependencies.json.sha256 132 ce70fc24ab5373d45dfa97c2cf738a47d962aa5a13234c8072d4540dd45e9ce5
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.tar.gz 6260494 3296fb6acced1e34b41cb1a4131cbba86ec1fc990debdc2094bc84c8e8fd5d51
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.tar.gz.sha256 121 31c439a37c6ff5ac49540e3b65687a18f99746c908568a3d95b1b210bb54b0b9
permesh-0.1.0-alpha.3-x86_64-apple-darwin.dependencies.json 108684 780ecc00a5035a7e8cf93065fda4b1f0653b47dae950db500de4089aa799a4dd
permesh-0.1.0-alpha.3-x86_64-apple-darwin.dependencies.json.sha256 126 9cea3f9485eeaff8d35392e07a72edeb14c6d2366de8e5fef35dbaeb2af7013e
permesh-0.1.0-alpha.3-x86_64-apple-darwin.tar.gz 5501325 bf4128c027c7317c0aac0b73460c80561661bd3605e5c3f972b98e861e1d0221
permesh-0.1.0-alpha.3-x86_64-apple-darwin.tar.gz.sha256 115 17d0305a6b5c2597fba199b6d1761a573b8536842f83dbb78ac1ab667ad7314e
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.dependencies.json 113331 15794c109a0c6738104109bd03c36c1dace10f2e27a6b77ca61239b4777fa832
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.dependencies.json.sha256 129 e0aaa48eb8c041814ae454d69b79be69dda624162355dce5098f295461f0782f
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.zip 5898540 3fcea03f5d39d1d1856f2196da9b5dd83d69f8bd5c8885126b5be18fbef018e6
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.zip.sha256 115 a963cdb144955bce1f9f89417b08a8b15bda2f130c6423fcb12b6a77fef799d7
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.dependencies.json 141815 a52bfd2647e42b83081563d4ca3cd375d3a90e0946fe0aa958a2b050ca6fb400
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.dependencies.json.sha256 131 2d88e6c92f5b89f7047da27c9d9f2e7c8033953bf5c8717eaa9b01f5136cf67c
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.tar.gz 6720564 c82ecf7c12f73b625e5b69226185d160e37ec3ab96af8a47bc03e9f7836eabc9
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.tar.gz.sha256 120 eb2d5c7546ebe81909505dc36063434a7038e483d9b7969e0c4d3902fd2018ac
attestation-bundle.json 15218 ef8ecd818713c16edbc69ccbfc46fe0875c8f69d3eefa23d6a11455ac5c7b956

Follow the release verification procedure
with source SHA add7a725745f5e05415b330e8d6be61fcaaf5d67. Platform code signing
and notarization are absent; GitHub build provenance is a separate assurance.

Published asset verification

On 2026-09-09, all 21 authenticated draft downloads and all 21 unauthenticated
public release downloads matched the original file names, sizes and SHA-256
values above. The release tag resolves to add7a725745f5e05415b330e8d6be61fcaaf5d67.
All 20 draft subjects passed signed-bundle verification. All 20 public release
subjects then passed both signed-bundle and public API verification, each reporting
Validated and verified signed provenance for all 20 candidate files.

To repeat the public checks, use the verifier and Cargo.lock from the exact source
revision above. Put the 20 archive/inventory/checksum files in release-subjects/
and the original bundle beside that directory, then run from that source checkout:

python3.12 scripts/verify_candidates.py release-subjects \
  --version 0.1.0-alpha.3 --lockfile Cargo.lock \
  --source-sha add7a725745f5e05415b330e8d6be61fcaaf5d67 \
  --bundle attestation-bundle.json
python3.12 scripts/verify_candidates.py release-subjects \
  --version 0.1.0-alpha.3 --lockfile Cargo.lock \
  --source-sha add7a725745f5e05415b330e8d6be61fcaaf5d67

The verifier requires authenticated GitHub CLI for repository attestation lookup
and pins workflow identity, source/signer digest, main ref, SLSA v1 and hosted
runners. The two modes verified the same public release subjects.

Public catalog acceptance

Provider catalog PR 23
added the 35 original 0.2.0 entries, preserving the five legacy GitHub entries.
On 2026-09-09, the exact publicly downloaded Apple Silicon alpha.3 CLI passed
public catalog installation and idempotent exact-version update for all seven
native 0.2.0 packages. Every installed executable matched its original digest.

GitHub, Google, Cloudflare and AWS IAM passed guided provider add --portable:
missing consent was rejected; explicit consent completed native trust and
workspace approval; all five target pins and native resolution matched the
catalog. GitLab, Entra and Identity Center passed public installation followed
by explicit native trust, negotiated setup, review and approval. Their five-target
maps were reviewed and applied explicitly; alpha.3 does not offer guided add for
these three types. Wrong approval fingerprints were rejected on that path.
All seven rejected absent credentials before provider API access.

With alpha.3, a GitHub 0.1.0 workspace retained its bytes, selected pin, review
fingerprint and approval after provider update --check found 0.2.0 and an
explicit provider update downloaded it. Downloading did not adopt the new pin.
This checks provider update within alpha.3, not migration of alpha.2 approvals.
Temporary acceptance state was removed. No live credentials or provider API
calls were used; the earlier limited NIPE-Solutions acceptance remains the
only live evidence and binds to the identical released executable hashes.

Evaluation limits

Only the limited NIPE-Solutions GitHub checks above have live candidate evidence.
Broader GitHub checks,
Google, Cloudflare, AWS, GitLab and Entra tenants and separately authorized
Connect/Vault/OpenBao services remain prerequisites. Synthetic API fixtures do
not establish real API permissions or complete effective authorization.

Interactive desktop credential stores and Windows terminals require separate
acceptance. Apple/Windows platform signing and notarization are absent. GitHub
provenance authenticates build subjects, not platform reputation, live-provider
correctness or reproducible builds. The dependency inventory is not a standards
SBOM. MIT remains the project license; required dependency notices ship separately.

No remote remediation, backend, telemetry, hidden update, automatic credential
refresh or infrastructure mutation is introduced. Future phases 6–7 remain
roadmap/ADR work. No verified sponsorship destination is available.