DipTrace MCP 0.1.1 — Withdrawn
Pre-releaseWITHDRAWN: superseded by v0.1.2 because release documentation contained stale generated metrics and incomplete release-asset installation guidance. No critical runtime vulnerability was identified. Replacement: https://github.com/fireostendere/mcp_diptrace/releases/tag/v0.1.2 # Release Record: v0.1.1 ## Identity and frozen commit - Version: 0.1.1, tag: v0.1.1. - Frozen commit: the tip of main produced by the 0.1.1 release pull request and recorded in the annotated tag object v0.1.1. Verify with git rev-parse v0.1.1^{}. - Artifact hashes are published as the immutable release asset SHA256SUMS.txt; verify them with sha256sum -c SHA256SUMS.txt. ## Scope This patch release contains the Windows/WSL live-exchange-path fix, the Windows inherited-stdout cleanup fix, focused cross-platform path regressions, and the English/Russian documentation reconciliation for the completed live acceptance campaign. It does not expand the advertised native DipTrace writer surface. ## Approvals and exception - Release manager: @fireostendere (repository owner), 2026-08-01. - Independent reviewer: none exists. The owner approves this unsigned alpha release under the documented solo-maintainer development-release exception. - Private vulnerability reporting remains the security channel published in SECURITY.md. - No verified confidential conduct channel, signing identity, or independent release approver exists. The release must not be described as signed, independently reviewed, or production-ready. ## Verification - The complete GitHub Actions matrix passes on the release pull-request tree: Linux 3.10/3.13, Linux geometry plus coverage, Linux no-Shapely fallback, macOS, Windows, native Windows bridge build/smoke, and static/release audit. - Ruff, strict Mypy, generated skill contracts, the exact 159-tool snapshot, release allowlist, specification inventory, format coverage, probe pack, trust-neutral ingest, and acceptance-seed audit pass. - The direct wheel and the wheel rebuilt from the source distribution have the same member set and per-member SHA-256 values. - The frozen wheel installs into a clean environment, starts the CLI, completes a real MCP stdio handshake, exposes 159 tools, and answers a real tool call. - The unsigned Windows bridge is taken from the same successful CI run that built and smoke-ran it with --help. ## Real DipTrace acceptance evidence The 2026-07-31 DipTrace 5.2.0.4 Windows bridge тЖФ WSL MCP campaign completed with ACCEPTANCE: PASS and RELEASE BLOCKER: NO for its explicit matrix: - PCB apply, cancel, and wrong-SHA; - Schematic apply, cancel, and wrong-SHA; - GUI confirmation for applied changes; - PCB Save As plus independent XML re-export and semantic comparison; - stable connectivity/counts; - Windows-native exchange-path metadata; and - no phantom C:\mnt\c\... target. See LIVE_ACCEPTANCE_2026-07-31.md. This is operator-assisted evidence for the tested topology, not proof for every MCP tool, DipTrace version, XML object, native library writer, or optional external solver. ## Release assets - diptrace_mcp-0.1.1.tar.gz тАФ audited Python source distribution. - diptrace_mcp-0.1.1-py3-none-any.whl тАФ MCP server and eight packaged skills. - diptrace_mcp_bridge.exe тАФ unsigned Windows bridge built and smoke-run by CI. - diptrace_mcp_windows_plugin-0.1.1.zip тАФ bridge, installer, four settings profiles, license, and live-path documentation. - LIVE_ACCEPTANCE_2026-07-31.md and CODE_REVIEW_2026-07-31.md тАФ scoped evidence records. - SHA256SUMS.txt тАФ SHA-256 manifest for every attached asset above. ## Supported environments - Python 3.10тАУ3.13 on Linux, macOS, and Windows for the MCP server. - Offline XML analysis under WSL. - Live integration on Windows 10/11 with a DipTrace build that supports executable XML plug-ins; the accepted host matrix includes DipTrace 5.2.0.4, while separate schematic evidence exists for DipTrace 5.3.0.2. ## Known limitations - Not a replacement for the DipTrace GUI or native EDA engine. - get_capabilities remains authoritative for each document and installation. - Component and Pattern Editor bridge profiles remain read-only. - Native Component/Pattern Library mutation and native manufacturing output are not claimed. - Broad redistributable DipTrace 5.3 writer fixtures, native library writer acceptance, complete trust invalidation across every write path, and real external-solver matrices remain incomplete. - Artifacts are unsigned and no package-index publication is performed. ## Retention and rollback Release assets are immutable and are never replaced under the same version. A defect requires a new version or withdrawal under RELEASE_PROCESS.md. Security-sensitive incidents use the private channel in SECURITY.md.