Skip to content

Releases: fraylabs/stiff

Stiff 0.4.0

Stiff 0.4.0 Pre-release
Pre-release

Choose a tag to compare

@BrianLYS BrianLYS released this 05 Oct 15:57

Stiff 0.4.0 adds pure HTTP contracts and a proven two-account ledger example, pinned to Bend 2.0.35.

  • Compiler-checked route laws cover selected protected routes, complete modeled GET/HEAD state preservation, and 404/405 decisions. Applications can prove their declared statuses and response bodies.
  • Ledger laws cover conservation, overdraft rejection, unchanged rejection and idempotency. Twelve ordinarily typechecked mistakes fail the proof gate before any mutant binary is built. Fifteen native ledger journeys passed.
  • Fresh consumer setup runs in CI; load and shutdown timing checks tolerate scheduler stalls while retaining arrival accounting and deadline checks.
  • Native example archives are available for macOS arm64 and Linux x64/arm64. Linux builds run on hosted Ubuntu 24.04 runners. Each exact archive passed provenance/checksum checks, supervised application health, create/read/restart checks and all six persistent notes journeys with no build tools on PATH.

BendHub package: 0x4ee0ec16258e9b8ad6ef37e5b8c4f95e. Empty-cache verification matched all 20 published files, required ALL PROOFS CHECK, exercised authenticated HTTPS and passed six persistent application journeys. The copied hub client passed HTTPS and cached-source tamper rejection. Consumer source/build-tool pins name be078621ad69303546de258fd8db578fc8c9b0f6; the tagged library and native build sources match that anchor.

The archives contain app, notes, stiff-run, deployment examples, licenses, dependency provenance and SHA-256 checksums. They dynamically require libcurl, json-c and SQLite; patched libevent 2.2.2-alpha is included statically. They are platform-specific examples, not static executables.

Proofs cover pure modeled decisions. Credential validation, decoding, path matching, original receipt selection, serialization, SQLite integration, native effects, the compiler/runtime, dependencies and operating system remain trusted/tested. A modeled status law does not prove every socket response has that status. ALL PROOFS CHECK denotes compiler checking; this release verification does not repeat the ledger's earlier independent BendTT check or establish end-to-end verification or memory safety. The sanitizer profile retains its documented Clang calling-convention mitigation. Hard resident-memory isolation is a Linux cgroup contract. The ledger is a bounded demo, with no real authentication system or external payments. Local durable receipts do not establish distributed exactly-once behavior.

The local suite ran 147 tests: 145 passed, fresh setup was skipped, and the RSS benchmark failed because the sandbox blocks /bin/ps. Hosted CI supplies the full-suite result. Historical workload measurements are not new 0.4.0 capacity measurements. Release evidence records exact revisions and separate verification scopes.

Release source: 945e73b4fd2a2b3b25e41fa696f3b908b7677e7e. Pinned CI passed all eight Linux/macOS platform/profile jobs. Final Linux archive workflow built and verified both Linux assets; workflow rehearsal passed before release use.

Stiff 0.3.0

Stiff 0.3.0 Pre-release
Pre-release

Choose a tag to compare

@BrianLYS BrianLYS released this 04 Oct 12:51

Stiff 0.3.0 supports Bend 2.0.35 for the existing native HTTP, application and SQLite APIs.

Changes:

  • Bend 2.0.35 constructor packing and executable-name CLI handling.
  • Daily latest-Bend compatibility CI on Linux x64 and macOS arm64, with normal and combined sanitizer profiles and recorded download integrity.
  • Startup constructor arity checks and compiled negative checks for HttpOk ABI metadata.
  • A server-first quickstart with native prerequisite commands and a local health check.
  • Load-test timing assertions that tolerate runner stalls while retaining drop/accounting checks.
  • Updated Git-pinned and BendHub clients; scoped libevent builds use at most five jobs.

BendHub package: 0x2731c2a5d4185b57cf5353061639642e. Empty-cache verification matched all 18 published files, checked the pure proof module, exercised authenticated HTTPS and passed six persistent application journeys. The copied hub client passed HTTPS and cached-source tamper rejection. BendHub was published before tagging so the tag contains the verified hash and manifest. Consumer Git pins use the matching immutable source/build-tool commit 3295bf9180f6844fc9d2ed7ca94ad6109ed9045b.

The macOS arm64 archive contains app, notes, stiff-run, deployment examples, licenses, dependency provenance and SHA-256 checksums. It dynamically requires libcurl, json-c and SQLite; patched libevent 2.2.2-alpha is included statically. Other platforms build from the pinned source.

This is an experimental pre-1.0 release. Native C, the compiler and dependencies remain trusted. ALL PROOFS CHECK is compiler checking, not independent Lean/BendTT kernel verification or full memory-safety verification. The sanitizer profile retains its narrow Clang calling-convention mitigation. Hard resident-memory isolation is a Linux cgroup contract. Notes is a loopback, single-workspace example; local receipts do not provide distributed exactly-once behavior. Historical 0.2.0 workload measurements are not new 0.3.0 capacity measurements.

Verification source: e55cf6cfcb60944b3170683fe8d4c90d046d889a. Pinned Check passed all eight platform/profile jobs; latest-Bend compatibility passed all four test jobs plus resolution on Bend 2.0.35. The local native suite passed 147 tests. The exact clean archive passed checksum/provenance checks, supervised application health, persistent create/read/restart checks and all six notes journeys. It runs with no build tools on PATH. Release evidence records the separate scopes and historical measurements.

Stiff 0.2.0

Stiff 0.2.0 Pre-release
Pre-release

Choose a tag to compare

@BrianLYS BrianLYS released this 21 Sep 14:23

Stiff 0.2.0 completes the native framework checklist and adds a runnable persistent notes API that combines path parameters, nested schemas, observable handlers, SQLite versioned writes and durable operation receipts.

Included:

  • Parameter routing, structured field/schema validation and consistent error envelopes.
  • Bounded request/response streaming, SSE and explicit connection reuse.
  • Native process cancellation, CPU limits, Linux cgroup memory isolation and bounded best-effort logging.
  • Atomic local writes, idempotent results, restart/crash recovery and reconciliation of lost acknowledgements.
  • The supported compiler-profile ASan/UBSan build with a narrow calling-convention mitigation, plus the retained-callback lifetime fix.
  • Compatibility/upgrade guidance, Linux deployment units and native application archives with provenance and checksums.

Verification is tied to source revision 4b20f169249b601d807b2d6aaeddda07a59532a2. The platform result and workload reports are linked from the current checklist. Independent QA exercised the integrated application and reverified two corrected input-boundary findings. Two 600-second persistent workloads completed 90,000 checked requests with zero drops, timeouts or semantic failures; both passed fresh writes and restart/replay checks. These are shared-host loopback measurements, not deployment-capacity claims.

The macOS arm64 archive contains app, notes, stiff-run, deployment examples, licenses, dependency provenance and SHA-256 checksums. It was built from a clean source tree and verified outside the checkout without build tools on PATH. It dynamically requires libcurl, json-c and SQLite; libevent is included statically. Other platforms build from the pinned source. See the notes walkthrough.

This is an experimental pre-1.0 release. Bend 2.0.20 and libevent 2.2.2-alpha remain pinned. Pure proofs do not verify native dependencies or full memory safety; the upstream Clang preserve_none defect is not claimed fixed. Hard resident-memory isolation is a Linux cgroup contract. Notes binds to loopback and is a single-workspace example, not an authentication system. SSE covers the demonstrated streaming need; WebSockets and HTTP/2 are outside this release. Local receipts do not provide distributed exactly-once semantics.