You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Release 1 source:#1. The master specification is referenced, not modified by this ticket.
Execution signal:ready-for-agent means this issue is implementation-ready once every native GitHub blocker below is closed.
Outcome
Rebuild and independently compare every required payload; validate locked inputs, SPDX/CycloneDX SBOMs, provenance, signatures, checksums, target and compatibility identities, advisory/license/ban policy, secret scans, revocation, security support, offline verification, complete Release Manifest, and refusal of partial or mismatched sets.
Scope and semantic ownership
Milestone:M6
Global sequence:147 / 149
Semantic owner:Release Engineering
Highest useful behavior seam:Qualify reproducibility and supply-chain trust
Affected registered scopes:positron-release, Release Trust and all registered artifact scopes
Expected project size / estimate:XL / 13
Completion status rule: An exact cell may become Qualified only when the frozen candidate passes the complete real-target gate and immutable evidence is retained. Any failed, missing, stale, unsupported, inconclusive, or exceptional required cell remains release-blocking.
No weaker document, implementation convenience, partial target, emulator, local diagnostic, or green subset may reinterpret the binding contract.
The native blocked-by graph is authoritative for execution order. Do not start implementation while a blocker is open, while an affected scope remains unlawfully scaffold-only, or while a required decision/review is missing.
If implementation would change caller knowledge, semantic ownership, a public or durable format, compatibility, a non-waivable invariant, or Release 1 scope, stop and land the required accepted superseding ADR together with its contract, migration, tests, and gates.
Do not weaken, skip, rename, path-filter, delete, reclassify, or silently bypass a gate, target, threshold, owner, test, corpus, fixture, hook, workflow, or evidence field.
Affected Qualification Cells
Q-BUILD-001
Q-DIST-001
Q-DIST-002
Q-DIST-003
Q-API-001
Q-SDK-001
Q-COMPAT-001
Q-SUPPLY-001
Q-SECURITY-001
Q-PERF-001
Q-SOAK-001
Each cell remains independently reportable. A passing child cannot hide a failed, unsupported, missing, unresolved, or inconclusive sibling.
Required implementation contract
Deliver the outcome exactly as stated above, through the named semantic owner and highest useful behavior seam.
Bind every exact artifact, target, compatibility claim, evidence attempt, SBOM, provenance statement, signature, and registry publication to one Release Manifest identity.
Make offline verification, revocation, security support, and compatibility refusals independently testable.
Keep implementation completion, qualification, publication, and release as separate authorized states.
If any affected code or artifact scope is still scaffold, activate it atomically with its owner, exact edges, risk gates, test commands, measured coverage/mutation baselines, and required threat model or format/API decision before adding behavior.
Preserve the registered acyclic dependency graph and keep provider/protocol/distribution types behind their adapters.
Return closed typed outcomes with safe details, retry class, completion state, and source context. Never use strings for control flow.
Declare every externally reachable input, work, memory, allocation, copy, I/O, task, queue, cache, lease, retry, and latency bound plus overload behavior.
Add no dependency without the complete review required by CONTRIBUTING.md.
Keep generated output generated and prove clean deterministic regeneration.
Update user/operator compatibility, migration, failure, recovery, and release-note documentation where behavior is visible.
Evidence aggregation proving every required cell and target is independently present and no failed attempt is hidden.
Include positive, boundary, negative, and adversarial cases at the lowest interface that proves the contract.
Assert returned outcomes, durable externally readable state, published artifacts, or public behavior—not private fields, helper calls, queue layout, or incidental ordering.
Keep tests hermetic, deterministic, parallel-safe, bounded, and retain seeds, clocks, entropy, schedules, fault plans, fixtures, and minimized failures.
A reproducible defect fix begins with a failing regression test and retains the reproducer.
Run all scope-selected unit, compile-fail, contract, property, integration, end-to-end, compatibility, platform, real-target, fuzz, model, fault, sanitizer, and soak suites that apply.
Evidence and completion
Run the authoritative cargo xtask quality profile required by the change and retain its exact revision-bound evidence.
Record exact source revision, artifact digests, target/environment, configuration, fixtures, dataset/workload, fault schedule, toolchain, command, duration, raw measurements, safe logs/metrics, result, owner, and verifier as applicable.
Retain passing, failing, inconclusive, exceptional, timeout, cancellation, and missing-tool attempts. A later pass must not erase a failure.
Verify no panic/unwrap/expect, unchecked indexing, ignored result, detached task, unbounded resource, ambient authority, prohibited unsafe code, secret leak, or hidden best-effort path was introduced.
Verify the working tree and generated artifacts are clean after the authoritative runner.
Do not close this issue from an ad hoc command, mock-only proof, emulator-only proof, local dirty evidence, or partial Qualification Cell.
Explicit non-goals
No publication, tag, deployment, or release without separate explicit authorization.
No umbrella qualification, mutable evidence, or claim derived from a local/dirty diagnostic run.
No Release 1 Metrics or Profiles implementation.
No replication, consensus, HA, automatic failover, follower reads, clustering, or live shard split/merge.
No hidden feature flags, placeholder APIs, empty adapters, speculative modules, or disabled deferred behavior.
Agent handoff checklist
Re-read the referenced contracts and ADRs before changing code.
Identify the exact semantic owner, caller-visible seam, durable publication owner, and affected Qualification Cells in the implementation PR.
Explain the lifecycle and failure boundaries before editing.
Keep implementation, qualification, publication, deployment, and release as separate states and authorizations.
Leave an evidence-backed status if blocked; never fabricate Implemented, Qualified, or merge eligibility.
Outcome
Rebuild and independently compare every required payload; validate locked inputs, SPDX/CycloneDX SBOMs, provenance, signatures, checksums, target and compatibility identities, advisory/license/ban policy, secret scans, revocation, security support, offline verification, complete Release Manifest, and refusal of partial or mismatched sets.
Scope and semantic ownership
M6147 / 149positron-release,Release Trust and all registered artifact scopesXL/13Qualifiedonly when the frozen candidate passes the complete real-target gate and immutable evidence is retained. Any failed, missing, stale, unsupported, inconclusive, or exceptional required cell remains release-blocking.No weaker document, implementation convenience, partial target, emulator, local diagnostic, or green subset may reinterpret the binding contract.
Native blockers
M6-02M6-03M6-04M6-05M6-06M6-07M6-08M6-09M6-10M6-11M6-12M6-13The native blocked-by graph is authoritative for execution order. Do not start implementation while a blocker is open, while an affected scope remains unlawfully scaffold-only, or while a required decision/review is missing.
Binding product and architecture references
Accepted ADRs
If implementation would change caller knowledge, semantic ownership, a public or durable format, compatibility, a non-waivable invariant, or Release 1 scope, stop and land the required accepted superseding ADR together with its contract, migration, tests, and gates.
Engineering invariants and gates
ARC-01,ARC-05,RUST-01,RUST-02,RUST-04,ERR-04,SEC-01,SEC-04,SEC-05,DOC-02,DOC-03,DOC-04,TEST-03,TEST-07,PERF-02,PERF-03,PERF-04EG-00,EG-ARCH,EG-BUILD,EG-DEPS,EG-DOCS,EG-ERROR,EG-EVIDENCE,EG-POLICY,EG-RUST,EG-SAFETY,EG-SECRETS,EG-SUPPLY,EG-TEST,EG-MATRIX,EG-PERF,EG-SECURITY,EG-SOAKcargo xtask qualityDo not weaken, skip, rename, path-filter, delete, reclassify, or silently bypass a gate, target, threshold, owner, test, corpus, fixture, hook, workflow, or evidence field.
Affected Qualification Cells
Q-BUILD-001Q-DIST-001Q-DIST-002Q-DIST-003Q-API-001Q-SDK-001Q-COMPAT-001Q-SUPPLY-001Q-SECURITY-001Q-PERF-001Q-SOAK-001Each cell remains independently reportable. A passing child cannot hide a failed, unsupported, missing, unresolved, or inconclusive sibling.
Required implementation contract
scaffold, activate it atomically with its owner, exact edges, risk gates, test commands, measured coverage/mutation baselines, and required threat model or format/API decision before adding behavior.CONTRIBUTING.md.Required tests
Evidence and completion
cargo xtask qualityprofile required by the change and retain its exact revision-bound evidence.Explicit non-goals
Agent handoff checklist
Implemented,Qualified, or merge eligibility.