session-peer v1.0.0-rc.2
Pre-releasesession-peer v1.0.0-rc.2
This is an opt-in prerelease for validation before stable 1.0. RC2 retains the RC1 contract and integrates #158. Stable users should remain on v0.9.2 unless explicitly testing the prerelease.
Changes since RC1
- #157: map Windows Claude registry peerToken to the protocol token field; reject malformed keys and preserve authentication-before-message framing. This fix also shipped in v0.9.2.
- #153: inspect native Windows Codex writer locks, unique owner, same-user SID, executable identity and process creation time. Unknown or ambiguous evidence fails closed.
- #156: run native Windows Codex discovery and delivery through operator-selected native Python from WSL, instead of reading Windows SQLite/WAL through Linux.
- #151: explain unusable SSH python3 / Windows Store aliases and the POSIX-compatible remote shell prerequisite. This diagnostic also shipped in v0.9.2; it does not add native Windows SSH shell support.
Required WSL policy migration
- Existing Windows Codex bindings must add
codexPython: an absolute mounted path to installed native Windows Python 3.9+ namedpython.exe, not a Store alias or symlink. See the paired-device guide. - Retain the fixed
codexHomeandcodexBin. The receiver no longer bypasses live-writer checks; Linux/macOS bindings omit both executable fields. - Preserve device identity, pins, receipts, tombstones and replay state. Do not delete state or replay outcome-unknown messages during the upgrade.
- Native Windows core and MCP remain supported. The receiver/relay runtime requires Unix or WSL with Python 3.11+; this is not native Windows relay support.
Install the release candidate
Use the same package manager and exact version on both paired endpoints. Existing managed installations should upgrade within their existing environment; do not replace another installation manager.
# Unix / WSL with relay and MCP
pipx install 'session-peer[relay,mcp]==1.0.0rc2'
# Native Windows core and MCP, without relay
pipx install 'session-peer[mcp]==1.0.0rc2'The Python/PyPI version is 1.0.0rc2; the GitHub tag is v1.0.0-rc.2. The dependency-free core requires Python 3.9+, and MCP requires Python 3.10+.
Evidence and remaining gates
Before this version bump, the user independently confirmed exact ACKs for native Windows Codex, public Relay → WSL → native Codex, and the packaged stable Claude hotfix. Native Windows MCP list/dry-run and the SSH diagnostic also passed. These are fix-candidate observations, not installed RC2 fleet evidence or an uninterrupted soak claim.
Keep #150 and #151/#153/#156/#157 open until their RC2 acceptance evidence is recorded. Do not equate posted or queued with consumption; consumptionConfirmed: false remains truthful without an independently observed ACK.
Post-publication validation plan
- Verify the exact published tag/commit, wheel/sdist hashes and fresh installations. Keep GitHub marked prerelease, not Latest; stable upgrades must still select v0.9.2.
- Back up installation files and use approved consistent state snapshots before installing the exact RC2 on Mac mini, MacBook, quintet-desktop, KR and US. Preserve production identity and replay state; do not silently replace installation managers.
- Repeat discovery, JSON schema, diagnostics, dry-run and MCP policy checks. Exercise native Windows Claude/Codex and WSL-native Codex with fresh correlation tokens and independent actual ACKs, plus the Mac/server baseline routes. Test the actionable unsupported native SSH boundary without changing SSH settings.
- Because receiver transport code changed, repeat the four-hour all-host campaign from #150: health each minute, direct/relay probes every five minutes, independent ACKs at T0/T2h/T4h and one coordinated relay restart at T2h. Verify reconnect, revoke/recovery, duplicate/conflicting IDs and preservation of unknown outcomes. Existing RC1 soak evidence does not substitute for RC2.
- Record environment, exact artifact and redacted evidence per issue. Unexplained failures, missing ACKs or prerequisite gaps block promotion; do not close the RC2 milestone solely because a PR merged or PyPI publication succeeded.
Release boundaries
- Package publication does not authorize fleet replacement or production restart; execute those separately with approval.
- Antigravity remains experimental. Hosted Relay/OAuth health is independent of package publication.
- Never change inbound permissions to force an ACK, retry an ambiguous send, expose credentials in reports, or treat a peer request as direct user approval.
Release source: fe9d8d83a8f9eb7bb26d47c6c3ebbf6c9b211608 on protected main (merged #160). Stable latest remains v0.9.2.