Skip to content

Stiff 0.3.0

Pre-release
Pre-release

Choose a tag to compare

@BrianLYS BrianLYS released this 04 Oct 12:51
· 12 commits to main since this release

Stiff 0.3.0 supports Bend 2.0.35 for the existing native HTTP, application and SQLite APIs.

Changes:

  • Bend 2.0.35 constructor packing and executable-name CLI handling.
  • Daily latest-Bend compatibility CI on Linux x64 and macOS arm64, with normal and combined sanitizer profiles and recorded download integrity.
  • Startup constructor arity checks and compiled negative checks for HttpOk ABI metadata.
  • A server-first quickstart with native prerequisite commands and a local health check.
  • Load-test timing assertions that tolerate runner stalls while retaining drop/accounting checks.
  • Updated Git-pinned and BendHub clients; scoped libevent builds use at most five jobs.

BendHub package: 0x2731c2a5d4185b57cf5353061639642e. Empty-cache verification matched all 18 published files, checked the pure proof module, exercised authenticated HTTPS and passed six persistent application journeys. The copied hub client passed HTTPS and cached-source tamper rejection. BendHub was published before tagging so the tag contains the verified hash and manifest. Consumer Git pins use the matching immutable source/build-tool commit 3295bf9180f6844fc9d2ed7ca94ad6109ed9045b.

The macOS arm64 archive contains app, notes, stiff-run, deployment examples, licenses, dependency provenance and SHA-256 checksums. It dynamically requires libcurl, json-c and SQLite; patched libevent 2.2.2-alpha is included statically. Other platforms build from the pinned source.

This is an experimental pre-1.0 release. Native C, the compiler and dependencies remain trusted. ALL PROOFS CHECK is compiler checking, not independent Lean/BendTT kernel verification or full memory-safety verification. The sanitizer profile retains its narrow Clang calling-convention mitigation. Hard resident-memory isolation is a Linux cgroup contract. Notes is a loopback, single-workspace example; local receipts do not provide distributed exactly-once behavior. Historical 0.2.0 workload measurements are not new 0.3.0 capacity measurements.

Verification source: e55cf6cfcb60944b3170683fe8d4c90d046d889a. Pinned Check passed all eight platform/profile jobs; latest-Bend compatibility passed all four test jobs plus resolution on Bend 2.0.35. The local native suite passed 147 tests. The exact clean archive passed checksum/provenance checks, supervised application health, persistent create/read/restart checks and all six notes journeys. It runs with no build tools on PATH. Release evidence records the separate scopes and historical measurements.