Skip to content

v0.3.0 — the Executor Release

Choose a tag to compare

@TheWayWithin TheWayWithin released this 18 Jul 14:17

Executor File v0.3.0 — the Executor Release

An encrypted, self-hosted register of every account, asset, and liability you own, with what you want done about each one. No credentials stored, no service dependency: recovery needs only stock age and ssss, forever.

Schema: format 3 (format 2 registers still validate this version, with precise migrate steps — see the header of schema/estate.schema.yaml).

What's verified, and what isn't (honesty first)

Machine-verified, green at tag time: 115 scripted tests on macOS and Ubuntu CI, under both encryption mechanisms (age 1.3.1 age-plugin-batchpass, and expect driving stock interactive age — including distro age 1.1 interop on Ubuntu). Crypto round-trips proven byte-identical; the 2-of-3 share chain proven end-to-end on every setup; rotation proven to kill the old key; validators proven against planted defects.

Not yet human-verified: the two validation gates in RELEASE-CHECKLIST.md — a Windows dry run by a non-author from the printed sheets alone, and a physical fire drill with real printed shares — are still open. This release was published ahead of them by deliberate owner decision (2026-07-18) so the full pipeline can be tested live end-to-end. Findings from those sessions will land in v0.3.1. Until then: the Mac/Linux path is CI-proven; treat the printed Windows sheet as carefully written but not yet field-tested.

Highlights since v0.2

  • Share scheme locked at 2-of-3 (a real defect in configurable thresholds was verified and removed; scripts refuse -t/-n loudly).
  • Secret-display ceremony: shares shown one at a time with confirm-and-clear; honest close-the-terminal guidance (no false erasure claims).
  • Schema v3: settle/preserve actions, first_step, depends_on, beneficiary, billing_cycle, jurisdictions array, contacts + documents sections; last_confirmed required on active entries (unknown allowed). estate.schema.json is the single source of truth with a CI drift test.
  • render.sh: the executor triage report (markdown + printable HTML), dependency-aware, preserve-before-dispose.
  • make-guide.sh: the two-page printed Executor Instructions, filled from your register.
  • test-recovery.sh (fire drill), rotate-shares.sh (proves the old key dead), share-sheets.sh, doctor.sh, verify-copies.sh + .sha256 sidecars.
  • review.sh: staleness summary before you edit, honest freshness stamping after, calendar nudges (.ics).
  • docs/WINDOWS-RECOVERY.md (WSL end-to-end), docs/discovery-checklist.md, AGENTS.md, SECURITY.md, CONTRIBUTING.md.

Tool versions tested

age 1.3.1 (batchpass) and age 1.1.x (stock interactive, Ubuntu CI); ssss 0.5; shellcheck-clean scripts.

Checksum

9956fb0162960dcb33c3aaf6a1566339b3c845044b834f82e8b05eeed30d255a  executor-file-v0.3.0.tar.gz