Skip to content

Stiff 0.2.0

Pre-release
Pre-release

Choose a tag to compare

@BrianLYS BrianLYS released this 21 Sep 14:23

Stiff 0.2.0 completes the native framework checklist and adds a runnable persistent notes API that combines path parameters, nested schemas, observable handlers, SQLite versioned writes and durable operation receipts.

Included:

  • Parameter routing, structured field/schema validation and consistent error envelopes.
  • Bounded request/response streaming, SSE and explicit connection reuse.
  • Native process cancellation, CPU limits, Linux cgroup memory isolation and bounded best-effort logging.
  • Atomic local writes, idempotent results, restart/crash recovery and reconciliation of lost acknowledgements.
  • The supported compiler-profile ASan/UBSan build with a narrow calling-convention mitigation, plus the retained-callback lifetime fix.
  • Compatibility/upgrade guidance, Linux deployment units and native application archives with provenance and checksums.

Verification is tied to source revision 4b20f169249b601d807b2d6aaeddda07a59532a2. The platform result and workload reports are linked from the current checklist. Independent QA exercised the integrated application and reverified two corrected input-boundary findings. Two 600-second persistent workloads completed 90,000 checked requests with zero drops, timeouts or semantic failures; both passed fresh writes and restart/replay checks. These are shared-host loopback measurements, not deployment-capacity claims.

The macOS arm64 archive contains app, notes, stiff-run, deployment examples, licenses, dependency provenance and SHA-256 checksums. It was built from a clean source tree and verified outside the checkout without build tools on PATH. It dynamically requires libcurl, json-c and SQLite; libevent is included statically. Other platforms build from the pinned source. See the notes walkthrough.

This is an experimental pre-1.0 release. Bend 2.0.20 and libevent 2.2.2-alpha remain pinned. Pure proofs do not verify native dependencies or full memory safety; the upstream Clang preserve_none defect is not claimed fixed. Hard resident-memory isolation is a Linux cgroup contract. Notes binds to loopback and is a single-workspace example, not an authentication system. SSE covers the demonstrated streaming need; WebSockets and HTTP/2 are outside this release. Local receipts do not provide distributed exactly-once semantics.