sealr 0.1.0-alpha.8: portable Unicode and supported wheel evaluation
Pre-release
Pre-release
Immutable
release. Only release title and notes can be modified.
sealr 0.1.0-alpha.8
This eighth development preview ships the first supported portable Unicode ZIP interpretation and promotes the bounded Python wheel evaluator through the public library. It preserves the Alpha.7 research artifacts and the Alpha.6 reduced-authority Linux boundary.
It remains a preview. The default APIs still run in process, structural ZIP planning is not confined, successful supervised execution is limited to x86_64 Linux with Landlock ABI 3, and this release does not claim wheel installation, general ecosystem compatibility, process containment, or production readiness.
Portable UTF-8 ZIP profile
sealr.profile.zip.portable-utf8.v1supports ZIP32 Store and Deflate, optional exact data descriptors, and strict UTF-8 NFC member names.- The complete accepted flag language is
0x0000,0x0008,0x0800, and0x0808; non-ASCII names require bit 11. Every extra field is denied. - Dot components, invalid UTF-8, unflagged non-ASCII, non-NFC, Unicode 16.0 unassigned or private-use scalars, controls, Unicode 16 whitespace and bidi controls, reserved names, trailing dots or spaces, duplicate and full-default-case-fold-plus-NFC collisions, and components above 255 UTF-8 bytes or 255 UTF-16 code units fail closed. Exact dependency versions bind the Unicode data and algorithms into the profile identity.
- CP437 is not guessed. A future legacy compatibility profile requires its own identifier, mapping, corpus evidence, and vectors.
- The canonical profile digest is
acee86158d481adff96da0277a470ba753d6208ede74bc48586bb0134db5152e. Required CI tests the complete 16-bit flag and extra-field-ID domains and reproduces the fourth profile vector independently.
Supported wheel evaluation
sealr::wheel::evaluate_wheelaccepts an exact outer filename, an opaqueVerifiedArchive, and explicitWheelLimits. It requires the portable profile and returns admitted, denied, unsupported, or infrastructure failure without receiving a source path.- The evaluator validates bounded case-insensitive headers, the filename and complete PEP 440 version class, exact
.dist-infoand optional.datatopology,WHEEL, Core Metadata 2.1 through 2.4, strict selected-distributionRECORDbinding and signature exemptions, dotted entry points, relocation, generated command names, script transforms, portable target collisions, and checked semantic byte ceilings. - Public non-exhaustive records expose the artifact, evaluator-owned read-only scheme-relative install plan, findings, container facts, typed infrastructure failures, and distinct source, archive-tree, artifact, install-plan, and optional realization identities. Realization validates complete target coverage, topology, paths, hashes, and sizes before producing an identity.
- An exact downstream golden evaluates an NFC Unicode wheel after deleting the original source and pins the profile, consumer-profile, source, tree, artifact, and plan identities. A streaming fixture proves data-descriptor and UTF-8 flag composition, and a cross-platform test materializes and reads an NFC path.
- The extracted-package consumer exercises the same public evaluator through the authenticated Linux supervisor and exact packaged helper, including supervised readback of
demo/café.py.
Compatibility evidence
- The predecessor-bound v3 inventory replays all 20 pinned artifacts and 90,417,280 exact source bytes through the portable profile and public evaluator. It preserves the v2 outcome: sixteen admitted, two denied, and two unsupported.
- The cffi duplicate
Generator, Hatchling and wheel Core Metadata 2.5, and SciPy expansion-ratio clusters remain explicitly investigated. The profile and budget are not weakened to increase acceptance. - The supported plan reports 60 source-executable regular files instead of 61. One orjson member was created under ZIP creator system 0 and is no longer treated as Unix executable authority merely because its external attributes resemble a Unix mode.
- The cohort still contains no benign Unicode or
.dataartifact and no descriptor-bearing member. Dedicated adversarial and generated fixtures cover those rules, while targeted benign corpus expansion remains next.
Distribution and verification
- Only the
sealrlibrary crate is allowlisted for crates.io publication. Required CI verifies its exact 53-file package, package-root README and Apache-2.0 license, Rust 1.98 metadata, and separately locked extracted-package consumer. - The tag workflow produces exactly the Linux x86_64, macOS arm64, and Windows x64 native archives plus
SHA256SUMSand GitHub build-provenance attestations. It does not publish the crate to crates.io. - Promotion requires exact-main Required CI, exact-commit on-demand fuzz evidence, target-specific third-party license closure, release-candidate classification, draft-asset readback, and immutable-release verification.
Important limitations
apply()continues to select strict ASCII v1 for compatibility. Portable UTF-8 v1 is explicit.- No wheel install effect or CLI wheel mode exists. The evaluator produces a pure scheme-relative plan and does not resolve dependencies, execute metadata, generate platform launchers, compile bytecode, or write an environment.
- The 20-wheel pilot is judgmental and cannot establish PyPI prevalence or broad compatibility.
- NFKC, host-specific case tables, CP437, ZIP64, additional codecs, TAR, gzip, zstd, 7z, semantic locks, signed receipts, authenticated recovery, and complete durability remain outside this release.
- Stable API and identity review, targeted feature-rich wheel evidence, accumulated assurance history, an external adopter, and independent security review remain roadmap gates.
See the portable profile, wheel consumer profile, API contract, roadmap, and release verification commands for the exact boundary.