Skip to content

Maintainers Releases and Distribution

arena-ai-coding-agent edited this page Sep 26, 2026 · 2 revisions

Releases and distribution

Status: PARTIAL. What ships today is honest and small: tags, source, and release-served archives. The standalone product is COMING. This page draws the line between the two precisely — docs/migration/STATUS.md is the authoritative record.

What a release is today

  • Git tags + CHANGELOG.md on hyperpolymath/MetaManifold-WebUI, source archives generated by the forge (v0.1.0 notes in docs/release-notes/v0.1.0.md).
  • Release-served pinned tool archives — e.g. the FastQC archive is served from this repository's releases (issue #54) so install.sh fetches a byte-exact, sha256-verified binary rather than chasing upstream URLs.
  • Users install from source (Install and First Run).

A source ZIP is not the standalone product — the distinction is called out in the migration record precisely because it will matter to regulators and core facilities.

The standalone product (COMING — agreed, not built)

Target shape (agreed requirements; none validated end-to-end yet):

  • Standalone offline-first release archives, native Linux x86-64 and ARM64. Guix builds the environment; end users never install Guix.
  • Bundled: mise, just, Bun, Julia + packages, R + Bioconductor (RCall), the Python/native/Java scientific tools (cutadapt, swarm, vsearch, cd-hit-est, FastQC/MultiQC), and the prebuilt web assets. Users supply sequencing data and reference databases only.
  • Unprivileged launcher; writable state outside the immutable release; existing browser remains the UI. Nothing is built or installed at first launch.
  • Proven relocatable offline execution — including paths with spaces, lazy scientific functionality, no /gnu/store dependency — with measured artefact sizes and published kernel/CPU baselines.
  • Published per-architecture: archives, hashes, signed metadata, and a component/licence inventory on GitHub Releases.

Workstream B's remaining steps (numbered in docs/migration/STATUS.md): runtime-closure audit (every lazy-download path and its licence obligation), pinned Guix recipes + mise/just build tasks, architecture-specific assembly, the unprivileged launcher, relocatability proof, native verification then explicit WSL2 tests (Linux-filesystem install, Windows-browser localhost access), then publication. WSL1 and native Windows are out of scope; WSL2 is secondary and currently unvalidated.

The coordinated updater (COMING)

Agreed shape: one tested, pinned combination (no independent in-place component upgrades), stable-version discovery through release tooling, signed trust metadata, transactional switch with health checks and rollback, and startup that works offline. Signing/trust-key provisioning and the release metadata format are open workstreams — publication secrets must be configured securely before anything is signed.

Distribution obligations already honoured

  • No third-party binaries are vendored in the repository; tools are fetched from upstream under their own licences (table in NOTICE: MIT/GPL v2+/LGPL v3 as applicable).
  • The archive-served FastQC lane still respects FastQC's GPL v3 — the release asset and its licence obligations travel together (see docs/compliance/vendored-archives.md).
  • The standalone release must ship the same component/licence inventory discipline — that inventory is a release artefact, not an afterthought.

Maintainer checklist for a release (today)

  1. just ci green on the release commit (the proof lane).
  2. CHANGELOG.md entry; docs/release-notes/ note for significant releases.
  3. Tag (immutable by ruleset), push, verify the source archive.
  4. If a pinned tool archive changed: re-verify sha256 records in config/defaults/tool_versions.yml match what the release serves.
  5. Wiki Status and Roadmap still matches reality (update IN PLACE/COMING markers if the release moves any).

Clone this wiki locally