From 7f21c12b519ad48299e76968800dfa05fe568e67 Mon Sep 17 00:00:00 2001 From: leyoonafr Date: Mon, 24 Aug 2026 07:13:22 +0800 Subject: [PATCH 1/5] release: prepare Phase 1 experimental 0.4.3 (#210) --- .claude-plugin/marketplace.json | 2 +- .github/workflows/release.yml | 2 +- CHANGELOG.md | 30 ++++++++ .../launchrally/.claude-plugin/plugin.json | 2 +- adapters/claude/launchrally/README.md | 4 +- .../host-adapter/authenticated-journey.js | 2 +- adapters/claude/launchrally/package.json | 4 +- .../launchrally/skills/launchrally/SKILL.md | 4 +- .../launchrally/references/cli-contract.md | 8 +- .../references/reference-journey.json | 10 +-- .../references/reference-journey.md | 2 +- .../launchrally/.codex-plugin/plugin.json | 2 +- adapters/codex/launchrally/README.md | 6 +- .../host-adapter/authenticated-journey.js | 2 +- adapters/codex/launchrally/package.json | 4 +- .../launchrally/skills/launchrally/SKILL.md | 4 +- .../launchrally/references/cli-contract.md | 8 +- .../references/reference-journey.json | 10 +-- .../references/reference-journey.md | 2 +- docs/getting-started/install.md | 2 +- docs/getting-started/quickstart.md | 2 +- .../experimental-0.4.3-announcement.md | 22 ++++++ .../experimental-0.4.3-p1-evidence.md | 22 ++++++ docs/maintainers/p1-acceptance.md | 2 +- docs/maintainers/p1-external-verification.md | 20 ++--- docs/maintainers/p1-migration-notes.md | 77 +++++++++---------- docs/maintainers/release-runbook.md | 6 +- package-lock.json | 24 +++--- package.json | 2 +- packages/cli/README.md | 8 +- packages/cli/bin/version.js | 2 +- packages/cli/package.json | 6 +- packages/contracts/README.md | 4 +- packages/contracts/package.json | 2 +- packages/core/README.md | 6 +- packages/core/package.json | 4 +- packages/core/src/architecture-journey.js | 2 +- packages/core/src/architecture-package.js | 4 +- release/p1-acceptance.json | 2 +- release/p1-external-verification.json | 4 +- release/p1-release-candidate.json | 24 +++--- release/p1.json | 6 +- skills/launchrally/SKILL.md | 4 +- skills/launchrally/references/cli-contract.md | 8 +- .../references/reference-journey.json | 10 +-- .../references/reference-journey.md | 2 +- test/reference-journey.test.js | 4 +- test/scaffold.test.js | 8 +- 48 files changed, 235 insertions(+), 162 deletions(-) create mode 100644 docs/maintainers/experimental-0.4.3-announcement.md create mode 100644 docs/maintainers/experimental-0.4.3-p1-evidence.md diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json index 244af22..1faf698 100644 --- a/.claude-plugin/marketplace.json +++ b/.claude-plugin/marketplace.json @@ -12,7 +12,7 @@ "source": { "source": "npm", "package": "@launchrally/claude-plugin", - "version": "0.4.2" + "version": "0.4.3" }, "description": "Audit and verify production launch readiness from an existing repository.", "category": "development", diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 83c6fa2..4b3bf3f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -165,7 +165,7 @@ jobs: - name: Create Experimental GitHub prerelease env: GH_TOKEN: ${{ github.token }} - run: gh release create "$GITHUB_REF_NAME" --verify-tag --prerelease --notes-file docs/maintainers/experimental-0.4.2-announcement.md --title "LaunchRally $GITHUB_REF_NAME (Phase 1 Experimental)" + run: gh release create "$GITHUB_REF_NAME" --verify-tag --prerelease --notes-file docs/maintainers/experimental-0.4.3-announcement.md --title "LaunchRally $GITHUB_REF_NAME (Phase 1 Experimental)" stable-promotion: if: github.event_name == 'workflow_dispatch' diff --git a/CHANGELOG.md b/CHANGELOG.md index a54806d..793e1c1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,35 @@ # Changelog +## 0.4.3 — Phase 1 Experimental + +LaunchRally 0.4.3 is a corrective Experimental Phase 1 release that completes +the remaining Human Mode command surfaces while preserving the separately +supported Phase 0 Stable 0.3.2 line on npm `latest`. + +### Improved + +- Added concise styled Version output through the public Launcher and selected + Project Engine without changing the structured Agent response. +- Completed the Handoff Human journey through executor selection, authority + review, receipt handling, partial execution, and an executable fresh Verify + continuation while keeping opaque resume tokens internal. +- Added a default-safe in-process Project Toolchain migration preview, + complete exact-diff review, confirmation, and completion flow. +- Added an exact 0.4.2-to-0.4.3 Project Toolchain migration guide and stronger + version-drift checks across documentation and generated Skills. +- Preserved supply-chain checks in ordinary CI and documented the independent + GitHub release-note control. + +### Release boundary + +- 0.4.3 publishes only on npm `experimental` and as a GitHub prerelease. +- Exact 0.4.3 external CLI, Codex, and Claude verification remains a separate + post-publication gate; publication does not make Phase 1 Validated or Stable. +- Phase 0 Stable 0.3.2 remains on npm `latest`. + +See [the Phase 1 migration notes](docs/maintainers/p1-migration-notes.md) for +the exact update, retained-data, and recovery boundaries. + ## 0.4.2 — Phase 1 Experimental LaunchRally 0.4.2 is a corrective Experimental Phase 1 release that strengthens diff --git a/adapters/claude/launchrally/.claude-plugin/plugin.json b/adapters/claude/launchrally/.claude-plugin/plugin.json index 4ba4754..f46e16b 100644 --- a/adapters/claude/launchrally/.claude-plugin/plugin.json +++ b/adapters/claude/launchrally/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "launchrally", "description": "Audit and verify production launch readiness from an existing repository.", - "version": "0.4.2", + "version": "0.4.3", "author": { "name": "codeacme17" } diff --git a/adapters/claude/launchrally/README.md b/adapters/claude/launchrally/README.md index c94f88a..c145406 100644 --- a/adapters/claude/launchrally/README.md +++ b/adapters/claude/launchrally/README.md @@ -10,7 +10,7 @@ The optional `@launchrally/claude-plugin/resume` host adapter atomically saves v ## Status -LaunchRally 0.4.2 is an **Experimental Phase 1** release. It adds the Phase 1 Skill and host bridges while Phase 0 Stable 0.3.2 remains on npm `latest`. Publication does not make Phase 1 Validated or Stable. +LaunchRally 0.4.3 is an **Experimental Phase 1** release. It adds the Phase 1 Skill and host bridges while Phase 0 Stable 0.3.2 remains on npm `latest`. Publication does not make Phase 1 Validated or Stable. Phase 0 0.3.2 remains a **Stable** release. It is Product Complete, P0 Validated, and published on the stable channel. @@ -20,7 +20,7 @@ CLI installation and Plugin installation are separate. Before installing this Pl ## Plugin installation and use -The `0.4.2` marketplace catalog pins `@launchrally/claude-plugin@0.4.2`. Add it and install at explicit user scope: +The `0.4.3` marketplace catalog pins `@launchrally/claude-plugin@0.4.3`. Add it and install at explicit user scope: ```sh claude plugin marketplace add codeacme17/launchrally --scope user diff --git a/adapters/claude/launchrally/host-adapter/authenticated-journey.js b/adapters/claude/launchrally/host-adapter/authenticated-journey.js index cb42cda..1b0087c 100644 --- a/adapters/claude/launchrally/host-adapter/authenticated-journey.js +++ b/adapters/claude/launchrally/host-adapter/authenticated-journey.js @@ -4,6 +4,6 @@ export function resumeAuthenticatedJourney(options) { return resumeAuthenticatedJourneyFromHost({ ...options, host: "claude", - version: "0.4.2", + version: "0.4.3", }); } diff --git a/adapters/claude/launchrally/package.json b/adapters/claude/launchrally/package.json index d6af2a7..2939ee0 100644 --- a/adapters/claude/launchrally/package.json +++ b/adapters/claude/launchrally/package.json @@ -1,6 +1,6 @@ { "name": "@launchrally/claude-plugin", - "version": "0.4.2", + "version": "0.4.3", "description": "LaunchRally Plugin adapter for Claude Code", "keywords": [ "launchrally", @@ -24,7 +24,7 @@ "./resume": "./host-adapter/resume.js" }, "dependencies": { - "@launchrally/core": "0.4.2" + "@launchrally/core": "0.4.3" }, "repository": { "type": "git", diff --git a/adapters/claude/launchrally/skills/launchrally/SKILL.md b/adapters/claude/launchrally/skills/launchrally/SKILL.md index f3729a1..21bdea7 100644 --- a/adapters/claude/launchrally/skills/launchrally/SKILL.md +++ b/adapters/claude/launchrally/skills/launchrally/SKILL.md @@ -20,7 +20,7 @@ Use the local CLI as the only authority for Checks, Evidence, Severity, release - When Audit or Verify returns an authenticated Core Journey request, read [references/protected-journeys.md](references/protected-journeys.md). - When a completed Audit or Verify contains `provider_tool_recoveries`, read [references/provider-tool-recovery.md](references/provider-tool-recovery.md). - When invoking the CLI or handling its states, read [references/cli-contract.md](references/cli-contract.md). -- For an exact Experimental 0.4.1-to-0.4.2 Project Toolchain update, follow the [version-specific migration authority](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042) and the typed lifecycle router in [references/cli-contract.md](references/cli-contract.md). +- For an exact Experimental 0.4.2-to-0.4.3 Project Toolchain update, follow the [version-specific migration authority](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043) and the typed lifecycle router in [references/cli-contract.md](references/cli-contract.md). - When inspecting or exchanging a Phase 1 architecture record, read [references/phase-1-contracts.md](references/phase-1-contracts.md). Contract availability alone does not make a Phase 1 operation executable. - When a typed `architect` interaction enters Product Intent discovery, read [references/product-intent.md](references/product-intent.md) before presenting semantic-analysis permission or confirmation. - When presenting a Capability Catalog, derived obligations, a Capability Graph, or an Integration Contract, read [references/capability-model.md](references/capability-model.md). @@ -55,7 +55,7 @@ Use the local CLI as the only authority for Checks, Evidence, Severity, release 1. Resolve the exact repository root without changing files. 2. Make `rally --version --json --cwd ` the first discovery operation. Do not probe for or invoke a Project Toolchain Engine directly. -3. If `rally` is absent, explain that CLI installation and Plugin installation are separate, link to the repository's single Install authority, present exactly `npm install --global @launchrally/cli@0.4.2` and the structured verification command, then stop before Audit and wait for the user. Do not run the install, automatically substitute the separate exact-version npm-exec trial/CI entry, or change npm prefixes or shell profiles. +3. If `rally` is absent, explain that CLI installation and Plugin installation are separate, link to the repository's single Install authority, present exactly `npm install --global @launchrally/cli@0.4.3` and the structured verification command, then stop before Audit and wait for the user. Do not run the install, automatically substitute the separate exact-version npm-exec trial/CI entry, or change npm prefixes or shell profiles. 4. Validate the complete version response and `launchrally.dev/execution-authority/v1` object through the compatibility matrix and typed authority router in [references/cli-contract.md](references/cli-contract.md). Plugin, Launcher, selected Engine, and project-pin versions are separate facts and need not be equal when each is supported. 5. For `ready`, invoke every repository operation through `rally` so the Launcher follows the selected Engine. For restore, migrate, or clean, show the exact operation, permissions, targets, and effects and wait for explicit user approval before Agent execution. 6. Invoke Agent Mode with structured output and handle the returned state. Stop on unknown contracts or versions, invalid descriptors or paths, and malformed output. diff --git a/adapters/claude/launchrally/skills/launchrally/references/cli-contract.md b/adapters/claude/launchrally/skills/launchrally/references/cli-contract.md index 064cc0e..62d66cb 100644 --- a/adapters/claude/launchrally/skills/launchrally/references/cli-contract.md +++ b/adapters/claude/launchrally/skills/launchrally/references/cli-contract.md @@ -7,7 +7,7 @@ Invoke Agent Mode with `--json`. Require `contract: "launchrally.dev/cli/v2"`, t CLI installation is a prerequisite separate from Plugin installation. Invoke `rally --version --json --cwd ` as the first discovery operation. If spawning `rally` reports that the executable is missing, present the exact user-managed PATH installation and verification commands below, then stop before Audit and wait: ```bash -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json --cwd ``` @@ -17,10 +17,10 @@ This Skill release uses this explicit compatibility matrix: | Layer | Supported value | Meaning | | --- | --- | --- | -| Plugin version | `0.4.2` | Interaction guidance only; never an execution candidate. | -| Launcher version | `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, or `0.4.2`, only when the running implementation declares v1 | A supported user-managed `rally` dispatcher implementing the contracts below. Historical published `0.2.2` direct binaries predate v1 interception and do not qualify. | +| Plugin version | `0.4.3` | Interaction guidance only; never an execution candidate. | +| Launcher version | `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, `0.4.2`, or `0.4.3`, only when the running implementation declares v1 | A supported user-managed `rally` dispatcher implementing the contracts below. Historical published `0.2.2` direct binaries predate v1 interception and do not qualify. | | Execution Authority contract | `launchrally.dev/execution-authority/v1` | The only supported Engine-selection contract. | -| Selected Engine version and contract | `0.2.2`, `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, or `0.4.2` with the declared compatibility path and CLI interaction `launchrally.dev/cli/v2` | The Engine selected by validated authority. A descriptor-free `0.2.2` project is accepted only through the legacy row below. | +| Selected Engine version and contract | `0.2.2`, `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, `0.4.2`, or `0.4.3` with the declared compatibility path and CLI interaction `launchrally.dev/cli/v2` | The Engine selected by validated authority. A descriptor-free `0.2.2` project is accepted only through the legacy row below. | | Legacy project pin | `0.2.2`, authority descriptor absent, `compatibility: "legacy_adapter"` | Supported only through the Launcher's allowlisted legacy adapter after explicit restore when materialization is missing. | Keep the Plugin version, Launcher version, selected Engine version, and project pin as separate facts. Read `launcher_version` from the version result, the selected Engine from `cli_version` and `authority.engine`, and the project pin from the validated `project_toolchain` authority. Do not require these versions to be equal; continue only when each value and contract is explicitly supported by the matrix. Any unknown or malformed version must stop before a journey operation. diff --git a/adapters/claude/launchrally/skills/launchrally/references/reference-journey.json b/adapters/claude/launchrally/skills/launchrally/references/reference-journey.json index a5d7480..8b8f24d 100644 --- a/adapters/claude/launchrally/skills/launchrally/references/reference-journey.json +++ b/adapters/claude/launchrally/skills/launchrally/references/reference-journey.json @@ -2,19 +2,19 @@ "schema_version": "launchrally.dev/reference-journey/v3", "compatibility": { "plugin": { - "version": "0.4.2", + "version": "0.4.3", "role": "interaction_only" }, "launcher": { "package": "@launchrally/cli", - "supported_versions": ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2"] + "supported_versions": ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", "0.4.3"] }, "execution_authority": { "supported_contracts": ["launchrally.dev/execution-authority/v1"] }, "engine": { "package": "@launchrally/cli", - "supported_versions": ["0.2.2", "0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2"], + "supported_versions": ["0.2.2", "0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", "0.4.3"], "authority_contracts": ["launchrally.dev/execution-authority/v1"], "interaction_contracts": ["launchrally.dev/cli/v2"] }, @@ -31,7 +31,7 @@ "installation": { "owner": "user", "executable": "npm", - "arguments": ["install", "--global", "@launchrally/cli@0.4.2"] + "arguments": ["install", "--global", "@launchrally/cli@0.4.3"] }, "verification": { "arguments": ["--version", "--json", "--cwd", "{repository_root}"] @@ -57,7 +57,7 @@ }, "cli": { "package": "@launchrally/cli", - "version": "0.4.2", + "version": "0.4.3", "contract": "launchrally.dev/cli/v2" }, "protected_journeys": { diff --git a/adapters/claude/launchrally/skills/launchrally/references/reference-journey.md b/adapters/claude/launchrally/skills/launchrally/references/reference-journey.md index fb0633a..361fec6 100644 --- a/adapters/claude/launchrally/skills/launchrally/references/reference-journey.md +++ b/adapters/claude/launchrally/skills/launchrally/references/reference-journey.md @@ -9,7 +9,7 @@ The user-managed `rally` Launcher is a prerequisite separate from the Codex or C If `rally` is absent, present these exact user-managed commands, stop before Audit, and wait: ```bash -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json --cwd ``` diff --git a/adapters/codex/launchrally/.codex-plugin/plugin.json b/adapters/codex/launchrally/.codex-plugin/plugin.json index ffa2db2..1201e42 100644 --- a/adapters/codex/launchrally/.codex-plugin/plugin.json +++ b/adapters/codex/launchrally/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "launchrally", - "version": "0.4.2", + "version": "0.4.3", "description": "Audit and verify production launch readiness from an existing repository.", "author": { "name": "codeacme17", diff --git a/adapters/codex/launchrally/README.md b/adapters/codex/launchrally/README.md index 97951a5..e4e92d8 100644 --- a/adapters/codex/launchrally/README.md +++ b/adapters/codex/launchrally/README.md @@ -10,7 +10,7 @@ The optional `@launchrally/codex-plugin/resume` host adapter atomically saves va ## Status -LaunchRally 0.4.2 is an **Experimental Phase 1** release. It adds the Phase 1 Skill and host bridges while Phase 0 Stable 0.3.2 remains on npm `latest`. Publication does not make Phase 1 Validated or Stable. +LaunchRally 0.4.3 is an **Experimental Phase 1** release. It adds the Phase 1 Skill and host bridges while Phase 0 Stable 0.3.2 remains on npm `latest`. Publication does not make Phase 1 Validated or Stable. Phase 0 0.3.2 remains a **Stable** release. It is Product Complete, P0 Validated, and published on the stable channel. @@ -23,7 +23,7 @@ CLI installation and Plugin installation are separate. Before installing this Pl Codex installs Plugins at user scope. Pin the marketplace to the exact release tag, then install LaunchRally: ```sh -codex plugin marketplace add codeacme17/launchrally --ref v0.4.2 +codex plugin marketplace add codeacme17/launchrally --ref v0.4.3 codex plugin add launchrally@launchrally codex plugin list --json ``` @@ -37,7 +37,7 @@ Replace the installed Plugin and exact marketplace checkout deliberately: ```sh codex plugin remove launchrally@launchrally codex plugin marketplace remove launchrally -codex plugin marketplace add codeacme17/launchrally --ref v0.4.2 +codex plugin marketplace add codeacme17/launchrally --ref v0.4.3 codex plugin add launchrally@launchrally ``` diff --git a/adapters/codex/launchrally/host-adapter/authenticated-journey.js b/adapters/codex/launchrally/host-adapter/authenticated-journey.js index b4d64e9..f2c55eb 100644 --- a/adapters/codex/launchrally/host-adapter/authenticated-journey.js +++ b/adapters/codex/launchrally/host-adapter/authenticated-journey.js @@ -4,6 +4,6 @@ export function resumeAuthenticatedJourney(options) { return resumeAuthenticatedJourneyFromHost({ ...options, host: "codex", - version: "0.4.2", + version: "0.4.3", }); } diff --git a/adapters/codex/launchrally/package.json b/adapters/codex/launchrally/package.json index 218b7da..beae143 100644 --- a/adapters/codex/launchrally/package.json +++ b/adapters/codex/launchrally/package.json @@ -1,6 +1,6 @@ { "name": "@launchrally/codex-plugin", - "version": "0.4.2", + "version": "0.4.3", "description": "LaunchRally Plugin adapter for Codex", "keywords": [ "launchrally", @@ -24,7 +24,7 @@ "./resume": "./host-adapter/resume.js" }, "dependencies": { - "@launchrally/core": "0.4.2" + "@launchrally/core": "0.4.3" }, "repository": { "type": "git", diff --git a/adapters/codex/launchrally/skills/launchrally/SKILL.md b/adapters/codex/launchrally/skills/launchrally/SKILL.md index 0e7d181..40d4fb8 100644 --- a/adapters/codex/launchrally/skills/launchrally/SKILL.md +++ b/adapters/codex/launchrally/skills/launchrally/SKILL.md @@ -19,7 +19,7 @@ Use the local CLI as the only authority for Checks, Evidence, Severity, release - When Audit or Verify returns an authenticated Core Journey request, read [references/protected-journeys.md](references/protected-journeys.md). - When a completed Audit or Verify contains `provider_tool_recoveries`, read [references/provider-tool-recovery.md](references/provider-tool-recovery.md). - When invoking the CLI or handling its states, read [references/cli-contract.md](references/cli-contract.md). -- For an exact Experimental 0.4.1-to-0.4.2 Project Toolchain update, follow the [version-specific migration authority](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042) and the typed lifecycle router in [references/cli-contract.md](references/cli-contract.md). +- For an exact Experimental 0.4.2-to-0.4.3 Project Toolchain update, follow the [version-specific migration authority](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043) and the typed lifecycle router in [references/cli-contract.md](references/cli-contract.md). - When inspecting or exchanging a Phase 1 architecture record, read [references/phase-1-contracts.md](references/phase-1-contracts.md). Contract availability alone does not make a Phase 1 operation executable. - When a typed `architect` interaction enters Product Intent discovery, read [references/product-intent.md](references/product-intent.md) before presenting semantic-analysis permission or confirmation. - When presenting a Capability Catalog, derived obligations, a Capability Graph, or an Integration Contract, read [references/capability-model.md](references/capability-model.md). @@ -54,7 +54,7 @@ Use the local CLI as the only authority for Checks, Evidence, Severity, release 1. Resolve the exact repository root without changing files. 2. Make `rally --version --json --cwd ` the first discovery operation. Do not probe for or invoke a Project Toolchain Engine directly. -3. If `rally` is absent, explain that CLI installation and Plugin installation are separate, link to the repository's single Install authority, present exactly `npm install --global @launchrally/cli@0.4.2` and the structured verification command, then stop before Audit and wait for the user. Do not run the install, automatically substitute the separate exact-version npm-exec trial/CI entry, or change npm prefixes or shell profiles. +3. If `rally` is absent, explain that CLI installation and Plugin installation are separate, link to the repository's single Install authority, present exactly `npm install --global @launchrally/cli@0.4.3` and the structured verification command, then stop before Audit and wait for the user. Do not run the install, automatically substitute the separate exact-version npm-exec trial/CI entry, or change npm prefixes or shell profiles. 4. Validate the complete version response and `launchrally.dev/execution-authority/v1` object through the compatibility matrix and typed authority router in [references/cli-contract.md](references/cli-contract.md). Plugin, Launcher, selected Engine, and project-pin versions are separate facts and need not be equal when each is supported. 5. For `ready`, invoke every repository operation through `rally` so the Launcher follows the selected Engine. For restore, migrate, or clean, show the exact operation, permissions, targets, and effects and wait for explicit user approval before Agent execution. 6. Invoke Agent Mode with structured output and handle the returned state. Stop on unknown contracts or versions, invalid descriptors or paths, and malformed output. diff --git a/adapters/codex/launchrally/skills/launchrally/references/cli-contract.md b/adapters/codex/launchrally/skills/launchrally/references/cli-contract.md index 064cc0e..62d66cb 100644 --- a/adapters/codex/launchrally/skills/launchrally/references/cli-contract.md +++ b/adapters/codex/launchrally/skills/launchrally/references/cli-contract.md @@ -7,7 +7,7 @@ Invoke Agent Mode with `--json`. Require `contract: "launchrally.dev/cli/v2"`, t CLI installation is a prerequisite separate from Plugin installation. Invoke `rally --version --json --cwd ` as the first discovery operation. If spawning `rally` reports that the executable is missing, present the exact user-managed PATH installation and verification commands below, then stop before Audit and wait: ```bash -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json --cwd ``` @@ -17,10 +17,10 @@ This Skill release uses this explicit compatibility matrix: | Layer | Supported value | Meaning | | --- | --- | --- | -| Plugin version | `0.4.2` | Interaction guidance only; never an execution candidate. | -| Launcher version | `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, or `0.4.2`, only when the running implementation declares v1 | A supported user-managed `rally` dispatcher implementing the contracts below. Historical published `0.2.2` direct binaries predate v1 interception and do not qualify. | +| Plugin version | `0.4.3` | Interaction guidance only; never an execution candidate. | +| Launcher version | `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, `0.4.2`, or `0.4.3`, only when the running implementation declares v1 | A supported user-managed `rally` dispatcher implementing the contracts below. Historical published `0.2.2` direct binaries predate v1 interception and do not qualify. | | Execution Authority contract | `launchrally.dev/execution-authority/v1` | The only supported Engine-selection contract. | -| Selected Engine version and contract | `0.2.2`, `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, or `0.4.2` with the declared compatibility path and CLI interaction `launchrally.dev/cli/v2` | The Engine selected by validated authority. A descriptor-free `0.2.2` project is accepted only through the legacy row below. | +| Selected Engine version and contract | `0.2.2`, `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, `0.4.2`, or `0.4.3` with the declared compatibility path and CLI interaction `launchrally.dev/cli/v2` | The Engine selected by validated authority. A descriptor-free `0.2.2` project is accepted only through the legacy row below. | | Legacy project pin | `0.2.2`, authority descriptor absent, `compatibility: "legacy_adapter"` | Supported only through the Launcher's allowlisted legacy adapter after explicit restore when materialization is missing. | Keep the Plugin version, Launcher version, selected Engine version, and project pin as separate facts. Read `launcher_version` from the version result, the selected Engine from `cli_version` and `authority.engine`, and the project pin from the validated `project_toolchain` authority. Do not require these versions to be equal; continue only when each value and contract is explicitly supported by the matrix. Any unknown or malformed version must stop before a journey operation. diff --git a/adapters/codex/launchrally/skills/launchrally/references/reference-journey.json b/adapters/codex/launchrally/skills/launchrally/references/reference-journey.json index a5d7480..8b8f24d 100644 --- a/adapters/codex/launchrally/skills/launchrally/references/reference-journey.json +++ b/adapters/codex/launchrally/skills/launchrally/references/reference-journey.json @@ -2,19 +2,19 @@ "schema_version": "launchrally.dev/reference-journey/v3", "compatibility": { "plugin": { - "version": "0.4.2", + "version": "0.4.3", "role": "interaction_only" }, "launcher": { "package": "@launchrally/cli", - "supported_versions": ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2"] + "supported_versions": ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", "0.4.3"] }, "execution_authority": { "supported_contracts": ["launchrally.dev/execution-authority/v1"] }, "engine": { "package": "@launchrally/cli", - "supported_versions": ["0.2.2", "0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2"], + "supported_versions": ["0.2.2", "0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", "0.4.3"], "authority_contracts": ["launchrally.dev/execution-authority/v1"], "interaction_contracts": ["launchrally.dev/cli/v2"] }, @@ -31,7 +31,7 @@ "installation": { "owner": "user", "executable": "npm", - "arguments": ["install", "--global", "@launchrally/cli@0.4.2"] + "arguments": ["install", "--global", "@launchrally/cli@0.4.3"] }, "verification": { "arguments": ["--version", "--json", "--cwd", "{repository_root}"] @@ -57,7 +57,7 @@ }, "cli": { "package": "@launchrally/cli", - "version": "0.4.2", + "version": "0.4.3", "contract": "launchrally.dev/cli/v2" }, "protected_journeys": { diff --git a/adapters/codex/launchrally/skills/launchrally/references/reference-journey.md b/adapters/codex/launchrally/skills/launchrally/references/reference-journey.md index fb0633a..361fec6 100644 --- a/adapters/codex/launchrally/skills/launchrally/references/reference-journey.md +++ b/adapters/codex/launchrally/skills/launchrally/references/reference-journey.md @@ -9,7 +9,7 @@ The user-managed `rally` Launcher is a prerequisite separate from the Codex or C If `rally` is absent, present these exact user-managed commands, stop before Audit, and wait: ```bash -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json --cwd ``` diff --git a/docs/getting-started/install.md b/docs/getting-started/install.md index 336f3cf..21add4e 100644 --- a/docs/getting-started/install.md +++ b/docs/getting-started/install.md @@ -3,7 +3,7 @@ LaunchRally `0.3.2` is the exact Stable release used by this guide. Stable availability follows the reviewed P0 Validated decision and satisfied Quality Floor. Updating an initialized Experimental `0.4.1` project is a separate path. Follow -the [exact 0.4.1-to-0.4.2 Project Toolchain migration](../maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042) +the [exact 0.4.2-to-0.4.3 Project Toolchain migration](../maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043) without relabeling this Stable `0.3.2` installation path. ## Supported environments diff --git a/docs/getting-started/quickstart.md b/docs/getting-started/quickstart.md index fe79d1b..3036afa 100644 --- a/docs/getting-started/quickstart.md +++ b/docs/getting-started/quickstart.md @@ -3,7 +3,7 @@ LaunchRally `0.3.2` is a public Stable release. Run it against a repository you control and review every disclosed read or write boundary before confirming it. Stable means the reviewed P0 Validated decision and Quality Floor requirements are satisfied. Already using an initialized Experimental `0.4.1` project? Use the separate -[exact 0.4.1-to-0.4.2 Project Toolchain migration](../maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042). +[exact 0.4.2-to-0.4.3 Project Toolchain migration](../maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043). That path keeps Launcher, selected Engine, project pin, Plugin, and release channel distinct; it does not change the Stable quickstart below. diff --git a/docs/maintainers/experimental-0.4.3-announcement.md b/docs/maintainers/experimental-0.4.3-announcement.md new file mode 100644 index 0000000..e4951f9 --- /dev/null +++ b/docs/maintainers/experimental-0.4.3-announcement.md @@ -0,0 +1,22 @@ +# LaunchRally 0.4.3 — Phase 1 Experimental + +LaunchRally 0.4.3 publishes a corrective Phase 1 candidate on npm's non-stable +`experimental` channel. It completes styled Human Mode for Version, Handoff, +and Project Toolchain migration while preserving the exact Agent/JSON resume +contracts. It also adds an exact 0.4.2-to-0.4.3 migration path and strengthens +release-note and supply-chain validation. + +At publication time, this exact Phase 1 candidate remains **Product Incomplete** +until its independent external verification through separate clean CLI, Codex, +and Claude journeys is reviewed and linked. The release is **Experimental**, +**not P1 Validated**, and **not Stable**. Publication, CI, downloads, and +elapsed time do not change those states. + +Phase 0 remains independently Product Complete, P0 Validated, and Stable at +0.3.2. npm `latest` continues to resolve to 0.3.2; 0.4.3 is available only from +`experimental` or by exact version. + +Review the [0.4.3 changelog](../../CHANGELOG.md), [exact 0.4.2-to-0.4.3 Project +Toolchain migration](p1-migration-notes.md#project-toolchain-migration-042-to-043), +and [external verification record](experimental-0.4.3-p1-evidence.md) before +adoption. diff --git a/docs/maintainers/experimental-0.4.3-p1-evidence.md b/docs/maintainers/experimental-0.4.3-p1-evidence.md new file mode 100644 index 0000000..31a0d9c --- /dev/null +++ b/docs/maintainers/experimental-0.4.3-p1-evidence.md @@ -0,0 +1,22 @@ +# Phase 1 Experimental 0.4.3 external verification + +Status: pending publication and independent external verification. + +This record is intentionally incomplete in the Release Candidate. It must be +updated only after the protected `v0.4.3` workflow publishes all five exact +artifacts on npm `experimental`, verifies their candidate digests and +provenance, and the clean direct CLI, Codex, and Claude journeys complete. + +The final record will contain only aggregate, non-sensitive conclusions and +public release links. Raw host transcripts, resume tokens, Reports, Evidence, +repository paths, target details, credentials, and personal data must not be +committed or uploaded. + +The machine-readable aggregate is `release/p1-external-verification.json`. +While publication or any external host journey is incomplete, that record +must remain `pending`; it can become `completed` only from three distinct +signed CLI, Codex, and Claude host envelopes accepted by +`scripts/verify-p1-external-results.mjs`. + +Publication does not imply Phase 1 Validated or Stable. Phase 0 Stable 0.3.2 +must remain on npm `latest` throughout the Experimental publication. diff --git a/docs/maintainers/p1-acceptance.md b/docs/maintainers/p1-acceptance.md index 865cfec..ac62b3a 100644 --- a/docs/maintainers/p1-acceptance.md +++ b/docs/maintainers/p1-acceptance.md @@ -49,7 +49,7 @@ open requirement or pending mandatory gate. | P1-HOST-01 | Codex and Claude resume exact Architecture and Handoff state without prose reconstruction | Claude Handoff state resumes in Codex from one validated local artifact | #136 | Complete | | P1-COVERAGE-01 | Representative Provider-neutral Packs preserve honest depth for managed and generic implementations | reference packs cover every product shape and integration family without Provider semantics | #137 | Complete | | P1-DOCS-01 | Agent and Human users can follow the complete authority-aware Phase 1 journey | documented Phase 1 commands are equivalent across POSIX and PowerShell | #138 | Complete | -| P1-RELEASE-01 | Exact P1 artifacts publish only as Experimental before separate external verification and Stable promotion | P1 Experimental publication readiness permits only external verification to remain open; P1 external verification cannot complete without its signed aggregate record; published P1 artifacts match candidate digests, provenance, and the preserved latest line; the P1 announcement and external Agent procedure preserve every lifecycle boundary; external Phase 1 results require machine-checked CLI, Codex, and Claude scenario coverage; packed artifacts complete installation, delegation, lifecycle, and full verification journeys | #201 | Open | +| P1-RELEASE-01 | Exact P1 artifacts publish only as Experimental before separate external verification and Stable promotion | P1 Experimental publication readiness permits only external verification to remain open; P1 external verification cannot complete without its signed aggregate record; published P1 artifacts match candidate digests, provenance, and the preserved latest line; the P1 announcement and external Agent procedure preserve every lifecycle boundary; external Phase 1 results require machine-checked CLI, Codex, and Claude scenario coverage; packed artifacts complete installation, delegation, lifecycle, and full verification journeys | #210 | Open | | P1-VALIDATION-01 | Phase 1 qualitative learning remains append-only, telemetry-free, aggregate, and lifecycle-separated | the Phase 1 Validation Log remains collecting, not validated, Experimental, and not approved | #195 | Complete | ## Independent lifecycle diff --git a/docs/maintainers/p1-external-verification.md b/docs/maintainers/p1-external-verification.md index 1892687..64fe8a8 100644 --- a/docs/maintainers/p1-external-verification.md +++ b/docs/maintainers/p1-external-verification.md @@ -1,6 +1,6 @@ # Phase 1 external verification procedure -Run this procedure only after the protected `v0.4.2` workflow has published +Run this procedure only after the protected `v0.4.3` workflow has published all five packages and its public smoke plus provenance checks are green. Use a fresh local account or disposable VM for each host. Do not copy tokens, cookies, configuration, Reports, Evidence, repository data, or host state from @@ -16,7 +16,7 @@ authored `$PHASE1_FIXTURE` is accepted. ```bash PHASE1_RELEASE="$(mktemp -d)/launchrally" -git clone --depth 1 --branch v0.4.2 https://github.com/codeacme17/launchrally.git "$PHASE1_RELEASE" +git clone --depth 1 --branch v0.4.3 https://github.com/codeacme17/launchrally.git "$PHASE1_RELEASE" cd "$PHASE1_RELEASE" npm ci --ignore-scripts node scripts/verify-experimental-release.mjs --phase published --json @@ -27,7 +27,7 @@ node scripts/record-p1-external-host.mjs \ --output /tmp/launchrally-p1-cli.json ``` -The result must identify 0.4.2 on `experimental`, retain 0.3.2 on `latest`, and +The result must identify 0.4.3 on `experimental`, retain 0.3.2 on `latest`, and match all five committed integrity values and the GitHub release-workflow SLSA provenance. Stop if any identity, digest, tag, commit, or channel differs. @@ -37,7 +37,7 @@ Use the clean host's own authenticated Codex session; never export its credential into the fixture or transcript. ```bash -codex plugin marketplace add codeacme17/launchrally --ref v0.4.2 +codex plugin marketplace add codeacme17/launchrally --ref v0.4.3 codex plugin add launchrally@launchrally CODEX_CHALLENGE="$(openssl rand -hex 32)" codex -C "$PHASE1_RELEASE" "Use the installed LaunchRally Skill. Run exactly: node scripts/record-p1-external-host.mjs --host codex --challenge $CODEX_CHALLENGE --output /tmp/launchrally-p1-codex.json. Do not replace the command with prose. Report success only if the command exits zero." @@ -51,7 +51,7 @@ Use the clean host's own authenticated Claude Code session with the Plugin installed at explicit user scope. ```bash -claude plugin marketplace add codeacme17/launchrally@v0.4.2 --scope user +claude plugin marketplace add codeacme17/launchrally@v0.4.3 --scope user claude plugin install launchrally@launchrally --scope user cd "$PHASE1_RELEASE" CLAUDE_CHALLENGE="$(openssl rand -hex 32)" @@ -77,7 +77,7 @@ Generate the exact review statement from all three envelopes: ```bash node scripts/verify-p1-external-results.mjs \ - --version 0.4.2 \ + --version 0.4.3 \ --cli /tmp/launchrally-p1-cli.json \ --codex /tmp/launchrally-p1-codex.json \ --claude /tmp/launchrally-p1-claude.json \ @@ -85,7 +85,7 @@ node scripts/verify-p1-external-results.mjs \ ``` An independent external reviewer must have observed the three native -invocations and post that exact statement as a comment on issue #141. The +invocations and post that exact statement as a comment on issue #210. The reviewer must not be the actor who triggered the protected release workflow. The final verifier reads both identities from GitHub and rejects self-review. @@ -94,12 +94,12 @@ prose. Replace both placeholders with exact public URLs: ```bash node scripts/verify-p1-external-results.mjs \ - --version 0.4.2 \ + --version 0.4.3 \ --cli /tmp/launchrally-p1-cli.json \ --codex /tmp/launchrally-p1-codex.json \ --claude /tmp/launchrally-p1-claude.json \ --workflow-url https://github.com/codeacme17/launchrally/actions/runs/REPLACE_WITH_RUN_ID \ - --release-url https://github.com/codeacme17/launchrally/releases/tag/v0.4.2 \ + --release-url https://github.com/codeacme17/launchrally/releases/tag/v0.4.3 \ --review-url https://github.com/codeacme17/launchrally/issues/141#issuecomment-REPLACE_WITH_COMMENT_ID \ --output /tmp/launchrally-p1-external-verification.json \ --json @@ -120,7 +120,7 @@ Receipt cannot replace independently observed zero-exit Agent invocations and their machine-checked envelopes. Record only these non-sensitive conclusions in -`experimental-0.4.2-p1-evidence.md`: host and exact version, public workflow +`experimental-0.4.3-p1-evidence.md`: host and exact version, public workflow URL, public release/package links, scenario status, typed boundary reached, and whether the fresh Verify result was qualifying. Independently review that record before changing `P1-RELEASE-01`, `p1_external_verification`, or Product diff --git a/docs/maintainers/p1-migration-notes.md b/docs/maintainers/p1-migration-notes.md index 7ca4819..96ad7b5 100644 --- a/docs/maintainers/p1-migration-notes.md +++ b/docs/maintainers/p1-migration-notes.md @@ -1,12 +1,12 @@ # Phase 1 Experimental migration notes -LaunchRally 0.4.2 continues the additive Phase 1 layer. Existing Phase 0 +LaunchRally 0.4.3 continues the additive Phase 1 layer. Existing Phase 0 projects and the public 0.3.2 Stable line remain independently valid. -## Project Toolchain migration: 0.4.1 to 0.4.2 +## Project Toolchain migration: 0.4.2 to 0.4.3 This procedure is only for an initialized project whose established Engine pin -is `0.4.1`. LaunchRally 0.4.2 remains **Experimental** on npm's +is `0.4.2`. LaunchRally 0.4.3 remains **Experimental** on npm's `experimental` channel; completing this migration does not make Phase 1 P1 Validated or Stable. Phase 0 `0.3.2` remains the release on npm `latest`. @@ -19,11 +19,11 @@ Treat these as five separate facts and lifecycles: repository-owned Project Toolchain; - a Codex or Claude **Plugin** supplies host interaction guidance and never selects or replaces the Engine; and -- `0.4.2` is on the **Experimental** channel, independently of those versions. +- `0.4.3` is on the **Experimental** channel, independently of those versions. Updating the Launcher does not update an initialized project's valid pin. Thus, after the first install below, structured version output with -`launcher_version: "0.4.2"`, `cli_version: "0.4.1"`, and +`launcher_version: "0.4.3"`, `cli_version: "0.4.2"`, and `authority.source: "project_toolchain"` is expected. It proves that the newer Launcher followed the established Engine; it is not a failed installation. Only an explicitly confirmed `toolchain migrate` changes that pin. `init` is @@ -41,20 +41,19 @@ Keep the original Manifest-bound source Audit Report used by confirmed Init. In the examples, set `SOURCE_REPORT` to that external JSON file, not to the prior or new `.launchrally/reports//record.json` current Report. -### Current 0.4.2 confirmation behavior +### Current 0.4.3 confirmation behavior -The shipped 0.4.2 `toolchain migrate` command does not provide a styled -in-process prompt. In default TTY Human Mode it emits the typed JSON permission -or migration preview and exits. Review that complete JSON, preserve its opaque -`interaction.resume_token`, and run the explicit resume command shown below. -The optional registry permission and the migration confirmation are separate -decisions. This is the current 0.4.2 behavior; it does not promise the future -in-process interaction tracked by issue #204. +In an interactive TTY, the shipped 0.4.3 `toolchain migrate` command keeps its +resume token internal, renders a styled concise preview, defaults to decline, +allows the complete exact diff to be reviewed, and returns to the same prompt +before completing a confirmed migration in-process. Cancellation, denial, or a +stale preview changes no Project Toolchain state. -Agent/CI Mode may add `--json` and follow the same -`launchrally.dev/toolchain-lifecycle/v1` states. An Agent must validate typed -fields and preserve tokens verbatim rather than parse Human prose or infer a -permission or confirmation. +The copy-pasteable procedures below intentionally use Agent/CI `--json` so the +complete `launchrally.dev/toolchain-lifecycle/v1` protocol remains explicit +and shell-equivalent. Validate every typed field, preserve each opaque token +verbatim, and keep the optional registry permission separate from migration +confirmation. Never parse Human prose or infer either decision. ### POSIX @@ -64,29 +63,29 @@ delete them yourself after the migration if they are no longer needed. ```sh PROJECT_ROOT=/path/to/project SOURCE_REPORT=/path/to/original-manifest-bound-audit-report.json -MIGRATION_RESPONSE=./launchrally-0.4.2-migration-response.json +MIGRATION_RESPONSE=./launchrally-0.4.3-migration-response.json -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json rally --version --json --cwd "$PROJECT_ROOT" rally toolchain status --json --cwd "$PROJECT_ROOT" -rally toolchain migrate --to 0.4.2 --cwd "$PROJECT_ROOT" > "$MIGRATION_RESPONSE" +rally toolchain migrate --to 0.4.3 --json --cwd "$PROJECT_ROOT" > "$MIGRATION_RESPONSE" node -e 'const fs = require("node:fs"); const value = JSON.parse(fs.readFileSync(process.argv[1], "utf8")); console.log(value.status); console.log(JSON.stringify(value.request ?? {}, null, 2));' "$MIGRATION_RESPONSE" ``` Before migrating, require the repository-scoped version and status results to -identify the established 0.4.1 project pin and selected Engine separately from -the 0.4.2 Launcher. +identify the established 0.4.2 project pin and selected Engine separately from +the 0.4.3 Launcher. If the status is `needs_permission`, review the exact `npm_registry_read` request. To deny it, replace `approved` with `denied`; denial preserves the -0.4.1 pin and returns `registry_permission_denied`. To approve only that bounded +0.4.2 pin and returns `registry_permission_denied`. To approve only that bounded read and obtain the migration preview: ```sh MIGRATION_TOKEN="$(node -e 'const fs = require("node:fs"); const value = JSON.parse(fs.readFileSync(process.argv[1], "utf8")); process.stdout.write(value.interaction.resume_token);' "$MIGRATION_RESPONSE")" -rally toolchain migrate --to 0.4.2 --cwd "$PROJECT_ROOT" --resume "$MIGRATION_TOKEN" --permissions '{"npm_registry_read":"approved"}' > "$MIGRATION_RESPONSE" +rally toolchain migrate --to 0.4.3 --json --cwd "$PROJECT_ROOT" --resume "$MIGRATION_TOKEN" --permissions '{"npm_registry_read":"approved"}' > "$MIGRATION_RESPONSE" node -e 'const fs = require("node:fs"); const value = JSON.parse(fs.readFileSync(process.argv[1], "utf8")); console.log(value.status); console.log(JSON.stringify(value.preview ?? {}, null, 2));' "$MIGRATION_RESPONSE" ``` @@ -96,14 +95,14 @@ that exact preview: ```sh MIGRATION_TOKEN="$(node -e 'const fs = require("node:fs"); const value = JSON.parse(fs.readFileSync(process.argv[1], "utf8")); process.stdout.write(value.interaction.resume_token);' "$MIGRATION_RESPONSE")" -rally toolchain migrate --to 0.4.2 --cwd "$PROJECT_ROOT" --resume "$MIGRATION_TOKEN" --confirm confirm +rally toolchain migrate --to 0.4.3 --json --cwd "$PROJECT_ROOT" --resume "$MIGRATION_TOKEN" --confirm confirm rally --version --json --cwd "$PROJECT_ROOT" rally verify --cwd "$PROJECT_ROOT" --report "$SOURCE_REPORT" --scope full ``` Require `authority.state: "ready"`, `authority.source: "project_toolchain"`, -`launcher_version: "0.4.2"`, and `cli_version: "0.4.2"` before Verify. A +`launcher_version: "0.4.3"`, and `cli_version: "0.4.3"` before Verify. A completed Verify creates a new current Report. Use the exact current Report path printed by completion for Plan or Architect; retain `SOURCE_REPORT` as the Manifest-bound input to future whole-release Verify runs. @@ -113,25 +112,25 @@ Manifest-bound input to future whole-release Verify runs. ```powershell $ProjectRoot = 'C:\path\to\project' $SourceReport = 'C:\path\to\original-manifest-bound-audit-report.json' -$MigrationResponse = '.\launchrally-0.4.2-migration-response.json' +$MigrationResponse = '.\launchrally-0.4.3-migration-response.json' -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json rally --version --json --cwd $ProjectRoot rally toolchain status --json --cwd $ProjectRoot -rally toolchain migrate --to 0.4.2 --cwd $ProjectRoot | Set-Content -Encoding utf8 $MigrationResponse +rally toolchain migrate --to 0.4.3 --json --cwd $ProjectRoot | Set-Content -Encoding utf8 $MigrationResponse $Migration = Get-Content -Raw $MigrationResponse | ConvertFrom-Json $Migration.status $Migration.request | ConvertTo-Json -Depth 20 ``` If `$Migration.status` is `needs_permission`, review the exact -`npm_registry_read` request. Use `denied` to preserve the 0.4.1 pin, or approve +`npm_registry_read` request. Use `denied` to preserve the 0.4.2 pin, or approve only that request and obtain the preview: ```powershell -rally toolchain migrate --to 0.4.2 --cwd $ProjectRoot --resume $Migration.interaction.resume_token --permissions '{"npm_registry_read":"approved"}' | Set-Content -Encoding utf8 $MigrationResponse +rally toolchain migrate --to 0.4.3 --json --cwd $ProjectRoot --resume $Migration.interaction.resume_token --permissions '{"npm_registry_read":"approved"}' | Set-Content -Encoding utf8 $MigrationResponse $Migration = Get-Content -Raw $MigrationResponse | ConvertFrom-Json $Migration.status $Migration.preview | ConvertTo-Json -Depth 20 @@ -142,7 +141,7 @@ When the response is `needs_confirmation`, inspect every confirm the exact preview: ```powershell -rally toolchain migrate --to 0.4.2 --cwd $ProjectRoot --resume $Migration.interaction.resume_token --confirm confirm +rally toolchain migrate --to 0.4.3 --json --cwd $ProjectRoot --resume $Migration.interaction.resume_token --confirm confirm rally --version --json --cwd $ProjectRoot rally verify --cwd $ProjectRoot --report $SourceReport --scope full @@ -154,7 +153,7 @@ Plan or Architect, and keep `$SourceReport` for future whole-release Verify. ### Denial, recovery, restore, and downgrade - A denied registry read, `--confirm decline`, an abandoned preview, or Ctrl-C - before adoption preserves the 0.4.1 project authority. Start a new migrate + before adoption preserves the 0.4.2 project authority. Start a new migrate operation if an opaque token is lost or invalid; never reconstruct it. - Missing registry access is not permission to use `sudo`, a floating version, a silent npm action, a changed npm prefix or shell profile, a copied @@ -168,10 +167,10 @@ Plan or Architect, and keep `$SourceReport` for future whole-release Verify. - `rally toolchain restore --cwd ` only rebuilds the established exact pin; it does not undo a completed migration. It may independently request the same bounded registry read. -- With Launcher 0.4.2, the only supported downgrade target is the allowlisted +- With Launcher 0.4.3, the only supported downgrade target is the allowlisted legacy Engine: `rally toolchain migrate --to 0.2.2 --cwd `. It uses the same preview/resume protocol, makes the prior current Report non-current, - and requires fresh full Verify. A 0.4.1 direct downgrade is unsupported by + and requires fresh full Verify. A 0.4.2 direct downgrade is unsupported by the shipped lifecycle; `restore` cannot be used to bypass that restriction. There is no automatic rollback or arbitrary unsupported-version bypass. @@ -188,7 +187,7 @@ exact release tag: ```sh codex plugin remove launchrally@launchrally codex plugin marketplace remove launchrally -codex plugin marketplace add codeacme17/launchrally --ref v0.4.2 +codex plugin marketplace add codeacme17/launchrally --ref v0.4.3 codex plugin add launchrally@launchrally codex plugin list --json ``` @@ -196,12 +195,12 @@ codex plugin list --json #### Claude Plugin Replace the installed Claude Plugin and marketplace checkout, pinning the -repository to the exact `v0.4.2` tag at explicit user scope: +repository to the exact `v0.4.3` tag at explicit user scope: ```sh claude plugin uninstall launchrally@launchrally --scope user claude plugin marketplace remove launchrally -claude plugin marketplace add codeacme17/launchrally@v0.4.2 --scope user +claude plugin marketplace add codeacme17/launchrally@v0.4.3 --scope user claude plugin install launchrally@launchrally --scope user claude plugin list --json ``` @@ -218,7 +217,7 @@ Project Toolchain migration. ## Adoption -Install 0.4.2 only by selecting the non-stable `experimental` channel or the +Install 0.4.3 only by selecting the non-stable `experimental` channel or the exact version. Architect previews a versioned Phase 1 adoption before any project write. Confirmation creates only the disclosed `.launchrally/phase-1` records and retains existing Phase 0 bytes. Denial and interruption leave the diff --git a/docs/maintainers/release-runbook.md b/docs/maintainers/release-runbook.md index f402a9e..14b67f2 100644 --- a/docs/maintainers/release-runbook.md +++ b/docs/maintainers/release-runbook.md @@ -66,8 +66,8 @@ Create a protected annotated tag on that exact `main` commit and push only the tag: ```bash -git tag --annotate v0.4.2 --message "LaunchRally 0.4.2 Phase 1 Experimental" -git push origin v0.4.2 +git tag --annotate v0.4.3 --message "LaunchRally 0.4.3 Phase 1 Experimental" +git push origin v0.4.3 ``` The release workflow independently rejects a lightweight tag, a tag whose @@ -93,7 +93,7 @@ that every new page shows its package-specific README and keywords during the public smoke check; source changes alone do not update the registry pages. Attach the successful workflow URL, five public package URLs, attestation -result, exact CLI result, and both Plugin results to issue #201. Keep Phase 1 +result, exact CLI result, and both Plugin results to issue #210. Keep Phase 1 Incomplete, Experimental, and Not Validated until those external results have been independently reviewed and merged into the P1 evidence and governance records. Publication never moves npm `latest`; Phase 0 Stable 0.3.2 remains diff --git a/package-lock.json b/package-lock.json index a48b110..1bae098 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "launchrally", - "version": "0.4.2", + "version": "0.4.3", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "launchrally", - "version": "0.4.2", + "version": "0.4.3", "license": "Apache-2.0", "workspaces": [ "packages/*", @@ -22,18 +22,18 @@ }, "adapters/claude/launchrally": { "name": "@launchrally/claude-plugin", - "version": "0.4.2", + "version": "0.4.3", "license": "Apache-2.0", "dependencies": { - "@launchrally/core": "0.4.2" + "@launchrally/core": "0.4.3" } }, "adapters/codex/launchrally": { "name": "@launchrally/codex-plugin", - "version": "0.4.2", + "version": "0.4.3", "license": "Apache-2.0", "dependencies": { - "@launchrally/core": "0.4.2" + "@launchrally/core": "0.4.3" } }, "node_modules/@anthropic-ai/claude-code": { @@ -393,13 +393,13 @@ }, "packages/cli": { "name": "@launchrally/cli", - "version": "0.4.2", + "version": "0.4.3", "license": "Apache-2.0", "dependencies": { "@clack/core": "1.4.3", "@clack/prompts": "1.7.0", - "@launchrally/contracts": "0.4.2", - "@launchrally/core": "0.4.2" + "@launchrally/contracts": "0.4.3", + "@launchrally/core": "0.4.3" }, "bin": { "rally": "bin/rally.js" @@ -410,15 +410,15 @@ }, "packages/contracts": { "name": "@launchrally/contracts", - "version": "0.4.2", + "version": "0.4.3", "license": "Apache-2.0" }, "packages/core": { "name": "@launchrally/core", - "version": "0.4.2", + "version": "0.4.3", "license": "Apache-2.0", "dependencies": { - "@launchrally/contracts": "0.4.2" + "@launchrally/contracts": "0.4.3" } } } diff --git a/package.json b/package.json index f54d8b5..cb7d9cf 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "launchrally", - "version": "0.4.2", + "version": "0.4.3", "private": true, "description": "Local-first launch readiness audit and verification", "license": "Apache-2.0", diff --git a/packages/cli/README.md b/packages/cli/README.md index 8bcce1e..1d972cb 100644 --- a/packages/cli/README.md +++ b/packages/cli/README.md @@ -4,7 +4,7 @@ The LaunchRally CLI provides the `rally` Launcher and deterministic Engine for a ## Status -LaunchRally 0.4.2 is an **Experimental Phase 1** release. Phase 1 adds Product Intent, Provider-neutral Architecture, bounded Executor coordination, and fresh assurance without relabeling Phase 0 Stable 0.3.2 on npm `latest`. Phase 1 publication does not imply Validated or Stable. Review every disclosed permission and preview before continuing. +LaunchRally 0.4.3 is an **Experimental Phase 1** release. Phase 1 adds Product Intent, Provider-neutral Architecture, bounded Executor coordination, and fresh assurance without relabeling Phase 0 Stable 0.3.2 on npm `latest`. Phase 1 publication does not imply Validated or Stable. Review every disclosed permission and preview before continuing. Phase 0 0.3.2 remains a **Stable** release. P0 is Product Complete and P0 Validated with the Quality Floor satisfied. @@ -13,7 +13,7 @@ Phase 0 0.3.2 remains a **Stable** release. P0 is Product Complete and P0 Valida Install the exact Launcher through your current user-writable npm prefix and verify it before entering a repository: ```sh -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json ``` @@ -38,7 +38,7 @@ Ordinary Init preserves an existing Manifest while it may preview adoption of a Exact-version npm-exec remains a no-install trial and CI fallback. Keep its full prefix on every follow-up; see the [Quickstart](https://github.com/codeacme17/launchrally/blob/main/docs/getting-started/quickstart.md) for the directly executable sequence. -For an initialized Experimental 0.4.1 project, follow the [exact 0.4.1-to-0.4.2 Project Toolchain migration](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042). Updating the Launcher, project pin, and optional Plugin are separate actions. +For an initialized Experimental 0.4.2 project, follow the [exact 0.4.2-to-0.4.3 Project Toolchain migration](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043). Updating the Launcher, project pin, and optional Plugin are separate actions. ## Compatibility and boundaries @@ -52,7 +52,7 @@ When an approved read cannot find its official Provider executable, the Report p - [Install, lifecycle, and troubleshooting](https://github.com/codeacme17/launchrally/blob/main/docs/getting-started/install.md) - [Quickstart](https://github.com/codeacme17/launchrally/blob/main/docs/getting-started/quickstart.md) -- [0.4.1-to-0.4.2 Project Toolchain migration](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042) +- [0.4.2-to-0.4.3 Project Toolchain migration](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043) - [Privacy boundary](https://github.com/codeacme17/launchrally/blob/main/docs/concepts/privacy.md) - [Project data model](https://github.com/codeacme17/launchrally/blob/main/docs/concepts/data-model.md) diff --git a/packages/cli/bin/version.js b/packages/cli/bin/version.js index 2391cca..bf562a1 100644 --- a/packages/cli/bin/version.js +++ b/packages/cli/bin/version.js @@ -1 +1 @@ -export const VERSION = "0.4.2"; +export const VERSION = "0.4.3"; diff --git a/packages/cli/package.json b/packages/cli/package.json index f1c4be6..8d596ad 100644 --- a/packages/cli/package.json +++ b/packages/cli/package.json @@ -1,6 +1,6 @@ { "name": "@launchrally/cli", - "version": "0.4.2", + "version": "0.4.3", "description": "LaunchRally local-first audit CLI", "keywords": [ "launch-readiness", @@ -28,8 +28,8 @@ "dependencies": { "@clack/core": "1.4.3", "@clack/prompts": "1.7.0", - "@launchrally/contracts": "0.4.2", - "@launchrally/core": "0.4.2" + "@launchrally/contracts": "0.4.3", + "@launchrally/core": "0.4.3" }, "repository": { "type": "git", diff --git a/packages/contracts/README.md b/packages/contracts/README.md index 5b02160..b11c2fc 100644 --- a/packages/contracts/README.md +++ b/packages/contracts/README.md @@ -14,14 +14,14 @@ The authenticated Journey Evidence contract qualifies only structurally validate ## Status -LaunchRally 0.4.2 is an **Experimental Phase 1** release. Its public contracts are versioned independently from package release status. Phase 0 Stable 0.3.2 remains on npm `latest`; publishing Phase 1 does not make it Validated or Stable. Consumers should reject unsupported contract major versions and pin the exact package version they have tested. +LaunchRally 0.4.3 is an **Experimental Phase 1** release. Its public contracts are versioned independently from package release status. Phase 0 Stable 0.3.2 remains on npm `latest`; publishing Phase 1 does not make it Validated or Stable. Consumers should reject unsupported contract major versions and pin the exact package version they have tested. Phase 0 0.3.2 remains a **Stable** release. Stable availability follows the reviewed P0 Validated decision and satisfied Quality Floor. ## Install and import ```sh -npm install @launchrally/contracts@0.4.2 +npm install @launchrally/contracts@0.4.3 ``` ```js diff --git a/packages/contracts/package.json b/packages/contracts/package.json index 0bd5145..106364c 100644 --- a/packages/contracts/package.json +++ b/packages/contracts/package.json @@ -1,6 +1,6 @@ { "name": "@launchrally/contracts", - "version": "0.4.2", + "version": "0.4.3", "description": "Versioned LaunchRally CLI and report contracts", "keywords": [ "launchrally", diff --git a/packages/core/README.md b/packages/core/README.md index c7f4520..13af036 100644 --- a/packages/core/README.md +++ b/packages/core/README.md @@ -4,7 +4,7 @@ ## Status -LaunchRally 0.4.2 is an **Experimental Phase 1** release. It adds the local-first Phase 1 decision, coordination, and assurance layer while Phase 0 Stable 0.3.2 remains available on npm `latest`. Publication does not make Phase 1 Validated or Stable. Pin the exact version and review release changes before upgrading. +LaunchRally 0.4.3 is an **Experimental Phase 1** release. It adds the local-first Phase 1 decision, coordination, and assurance layer while Phase 0 Stable 0.3.2 remains available on npm `latest`. Publication does not make Phase 1 Validated or Stable. Pin the exact version and review release changes before upgrading. Phase 0 0.3.2 remains a **Stable** release. The package is Product Complete, P0 Validated, and published on the stable channel. @@ -31,13 +31,13 @@ Confirmed decisions can be materialized with `createArchitecturePackageBundle`. ## Install and use ```sh -npm install @launchrally/core@0.4.2 +npm install @launchrally/core@0.4.3 ``` ```js import { runAudit } from "@launchrally/core"; -const interaction = await runAudit(process.cwd(), "0.4.2"); +const interaction = await runAudit(process.cwd(), "0.4.3"); console.log(interaction.status, interaction.next); ``` diff --git a/packages/core/package.json b/packages/core/package.json index 6947b85..b24214e 100644 --- a/packages/core/package.json +++ b/packages/core/package.json @@ -1,6 +1,6 @@ { "name": "@launchrally/core", - "version": "0.4.2", + "version": "0.4.3", "description": "Deterministic LaunchRally audit and verification core", "keywords": [ "launchrally", @@ -21,7 +21,7 @@ "src/" ], "dependencies": { - "@launchrally/contracts": "0.4.2" + "@launchrally/contracts": "0.4.3" }, "repository": { "type": "git", diff --git a/packages/core/src/architecture-journey.js b/packages/core/src/architecture-journey.js index 4a65c16..6794afa 100644 --- a/packages/core/src/architecture-journey.js +++ b/packages/core/src/architecture-journey.js @@ -175,7 +175,7 @@ async function applyAdoption(state, fileOperations = {}) { export async function runArchitectureJourney(cwd, source = {}, options = {}, dependencies = {}) { const selectedRoot = path.resolve(cwd); const root = await realpath(selectedRoot); - const launcherVersion = options.launcher_version ?? "0.4.2"; + const launcherVersion = options.launcher_version ?? "0.4.3"; if (options.resume_token) { const candidate = (dependencies.load_state ?? loadArchitectureState)(options.resume_token); const state = candidate?.state_version === STATE_VERSION ? candidate : null; diff --git a/packages/core/src/architecture-package.js b/packages/core/src/architecture-package.js index 3a008a8..db60c0b 100644 --- a/packages/core/src/architecture-package.js +++ b/packages/core/src/architecture-package.js @@ -540,7 +540,7 @@ export async function previewArchitecturePackagePersistence(root, bundle, option const resolvedRoot = await repositoryRoot(root); const initialized = await initializedProject( resolvedRoot, - options.launcher_version ?? "0.4.2", + options.launcher_version ?? "0.4.3", ); if (!initialized && !options.output_path) { return { mode: "output_only", requires_confirmation: false, files: [] }; @@ -748,7 +748,7 @@ async function persistInitializedArchitecturePackage( preview, options, ) { - if (!await initializedProject(resolvedRoot, options.launcher_version ?? "0.4.2")) { + if (!await initializedProject(resolvedRoot, options.launcher_version ?? "0.4.3")) { const error = new Error("The repository was no longer initialized at confirmation time."); error.code = "architecture_persistence_scope_changed"; throw error; diff --git a/release/p1-acceptance.json b/release/p1-acceptance.json index 76bd946..ecfc4b2 100644 --- a/release/p1-acceptance.json +++ b/release/p1-acceptance.json @@ -115,7 +115,7 @@ "id": "P1-DOCS-01", "requirement": "Agent and Human users can follow the complete authority-aware Phase 1 journey", "contracts": ["skills/launchrally/references/phase-1-command-examples.json"], "implementation": ["docs/getting-started/phase-1.md"], "tests": [{"path": "test/phase-1-documentation.test.js", "name": "documented Phase 1 commands are equivalent across POSIX and PowerShell"}], "tracking": "#138", "status": "complete", "gates": ["p1_traceability", "p1_quality_floor", "p1_exact_artifacts"] }, { - "id": "P1-RELEASE-01", "requirement": "Exact P1 artifacts publish only as Experimental before separate external verification and Stable promotion", "contracts": ["release/p1.json", "release/p1-regression-registry.json", "release/p1-release-candidate.json", "release/p1-external-verification.json"], "implementation": ["scripts/release-version.mjs", "scripts/validate-p0.mjs", "scripts/validate-p1.mjs", "scripts/test-release-artifacts.mjs", "scripts/verify-experimental-release.mjs", "scripts/record-p1-external-host.mjs", "scripts/verify-p1-external-results.mjs", ".github/workflows/ci.yml", ".github/workflows/release.yml", "CHANGELOG.md", "docs/maintainers/p1-migration-notes.md", "docs/maintainers/p1-external-verification.md", "docs/maintainers/experimental-0.4.2-announcement.md", "docs/maintainers/experimental-0.4.2-p1-evidence.md"], "tests": [{"path": "test/p0-release.test.js", "name": "P0 Stable remains valid only when a later Experimental P1 candidate preserves its exact line"}, {"path": "test/p1-governance.test.js", "name": "P1 Experimental publication readiness permits only external verification to remain open"}, {"path": "test/p1-governance.test.js", "name": "P0 Stable never promotes P1 beyond Experimental without separate approval"}, {"path": "test/p1-governance.test.js", "name": "P1 regression assignments remain append-only against the reviewed Git baseline"}, {"path": "test/p1-governance.test.js", "name": "CI compares the P1 regression registry with every reviewed base"}, {"path": "test/p1-governance.test.js", "name": "P1 external verification cannot complete without its signed aggregate record"}, {"path": "test/release.test.js", "name": "the P1 artifact matrix rejects a CI target that does not match the runtime"}, {"path": "test/release.test.js", "name": "release CI runs every exact P1 platform and shell target"}, {"path": "test/release.test.js", "name": "packed artifacts complete installation, delegation, lifecycle, and full verification journeys"}, {"path": "test/release.test.js", "name": "Experimental P1 publication is gated independently from the P0 Stable channel"}, {"path": "test/release.test.js", "name": "the P1 Experimental candidate advances coherently without moving P0 latest"}, {"path": "test/release.test.js", "name": "published P1 artifacts match candidate digests, provenance, and the preserved latest line"}, {"path": "test/release.test.js", "name": "the P1 announcement and external Agent procedure preserve every lifecycle boundary"}, {"path": "test/release.test.js", "name": "external Phase 1 results require machine-checked CLI, Codex, and Claude scenario coverage"}], "tracking": "#201", "status": "open", "gates": ["p1_traceability", "p1_quality_floor", "p1_supply_chain", "p1_exact_artifacts", "p1_external_verification"] + "id": "P1-RELEASE-01", "requirement": "Exact P1 artifacts publish only as Experimental before separate external verification and Stable promotion", "contracts": ["release/p1.json", "release/p1-regression-registry.json", "release/p1-release-candidate.json", "release/p1-external-verification.json"], "implementation": ["scripts/release-version.mjs", "scripts/validate-p0.mjs", "scripts/validate-p1.mjs", "scripts/test-release-artifacts.mjs", "scripts/verify-experimental-release.mjs", "scripts/record-p1-external-host.mjs", "scripts/verify-p1-external-results.mjs", ".github/workflows/ci.yml", ".github/workflows/release.yml", "CHANGELOG.md", "docs/maintainers/p1-migration-notes.md", "docs/maintainers/p1-external-verification.md", "docs/maintainers/experimental-0.4.3-announcement.md", "docs/maintainers/experimental-0.4.3-p1-evidence.md"], "tests": [{"path": "test/p0-release.test.js", "name": "P0 Stable remains valid only when a later Experimental P1 candidate preserves its exact line"}, {"path": "test/p1-governance.test.js", "name": "P1 Experimental publication readiness permits only external verification to remain open"}, {"path": "test/p1-governance.test.js", "name": "P0 Stable never promotes P1 beyond Experimental without separate approval"}, {"path": "test/p1-governance.test.js", "name": "P1 regression assignments remain append-only against the reviewed Git baseline"}, {"path": "test/p1-governance.test.js", "name": "CI compares the P1 regression registry with every reviewed base"}, {"path": "test/p1-governance.test.js", "name": "P1 external verification cannot complete without its signed aggregate record"}, {"path": "test/release.test.js", "name": "the P1 artifact matrix rejects a CI target that does not match the runtime"}, {"path": "test/release.test.js", "name": "release CI runs every exact P1 platform and shell target"}, {"path": "test/release.test.js", "name": "packed artifacts complete installation, delegation, lifecycle, and full verification journeys"}, {"path": "test/release.test.js", "name": "Experimental P1 publication is gated independently from the P0 Stable channel"}, {"path": "test/release.test.js", "name": "the P1 Experimental candidate advances coherently without moving P0 latest"}, {"path": "test/release.test.js", "name": "published P1 artifacts match candidate digests, provenance, and the preserved latest line"}, {"path": "test/release.test.js", "name": "the P1 announcement and external Agent procedure preserve every lifecycle boundary"}, {"path": "test/release.test.js", "name": "external Phase 1 results require machine-checked CLI, Codex, and Claude scenario coverage"}], "tracking": "#210", "status": "open", "gates": ["p1_traceability", "p1_quality_floor", "p1_supply_chain", "p1_exact_artifacts", "p1_external_verification"] }, { "id": "P1-VALIDATION-01", "requirement": "Phase 1 qualitative learning remains append-only, telemetry-free, aggregate, and lifecycle-separated", "contracts": ["release/p1.json", "release/p1-regression-registry.json", "docs/maintainers/phase-1-validation-log.json"], "implementation": ["scripts/p1-validation-log-contract.mjs", "scripts/validation-log-shared.mjs", "scripts/validate-p1.mjs", "docs/maintainers/phase-1-validation.md"], "tests": [{"path": "test/p1-validation.test.js", "name": "the Phase 1 Validation Log remains collecting, not validated, Experimental, and not approved"}, {"path": "test/p1-validation.test.js", "name": "the Phase 1 Validation Log rejects historical mutation against the reviewed Git baseline"}, {"path": "test/p1-validation.test.js", "name": "a Phase 1 Quality Floor regression suspends only its declared authority and preserves P0 Stable"}], "tracking": "#195", "status": "complete", "gates": ["p1_traceability", "p1_quality_floor"] diff --git a/release/p1-external-verification.json b/release/p1-external-verification.json index fd3bbff..6316fa4 100644 --- a/release/p1-external-verification.json +++ b/release/p1-external-verification.json @@ -1,8 +1,8 @@ { "schema_version": "launchrally.dev/p1-external-verification/v1", "status": "pending", - "version": "0.4.2", - "tag": "v0.4.2", + "version": "0.4.3", + "tag": "v0.4.3", "channel": "experimental", "verified_at": null, "workflow_url": null, diff --git a/release/p1-release-candidate.json b/release/p1-release-candidate.json index 6fc8107..0c16e40 100644 --- a/release/p1-release-candidate.json +++ b/release/p1-release-candidate.json @@ -1,35 +1,35 @@ { "schema_version": "launchrally.dev/p1-release-candidate/v1", - "version": "0.4.2", - "tag": "v0.4.2", + "version": "0.4.3", + "tag": "v0.4.3", "channel": "experimental", "stable_channel": "latest", "p0_stable_version": "0.3.2", "packages": [ { "name": "@launchrally/contracts", - "integrity": "sha512-CoLhtUkm9WOvPVxBPpR+K5RSJ7IzD9jWrnBv+fi4iUjmV1ZUMcelYcuwbHcaf8q0AOa9ZOOuUcViZq0AkL2w3A==", - "shasum": "39730edc2edd1f8c4e380f8971accfa92eb1f00e" + "integrity": "sha512-Fq3WbaAUuOBfgbqTd4jcPGuBllom0yiLuhEremTJTY3PdZlMNS+R//z3VeclSsKyd6r9QOFjyzYlZfWWk08uwA==", + "shasum": "1c82c3b8ea3240a0eb5cc3b11659489f72528c26" }, { "name": "@launchrally/core", - "integrity": "sha512-sm+0w859ZwCA64WqF2ITZJZwCvCy+g/Q/IyZnHgePCJKrHqFj4XMpmh70kXmgLj8W3YGI+CKmSXXeK+LK6Wq7A==", - "shasum": "b15be4d57b37d14f1ae71d70ce7d465bdd9834ea" + "integrity": "sha512-4a+H4qoWvni3hfymrjaS12OMX3zH6YNQoHxus+b9BJZcFG0ZmW0WtVPourOVeQPFXRpVX3ixXEI7moLqP9ndWQ==", + "shasum": "65e0e341af2ad354bda4e527ee0d211d68fe6491" }, { "name": "@launchrally/cli", - "integrity": "sha512-sz4t58uCztF8GKXTp6OunFGhcilftKODgO5/+D24vIlTsBaA6Jg9ct4W0ODonXFBuoR5mzNvyMPp60SyJIVRBA==", - "shasum": "ec514c0f4b12a02cad87b9d050c2d81f3e567f3c" + "integrity": "sha512-SnIEcpfi7BBEbg2wzkqaECEHPQLEwQtcA9SY0oQcu7PlFY4iKXlkpJfF4X1D/6g79jYmYsHFVXLuMYwVV+jFlw==", + "shasum": "356de9dea048332a44c3b40febb6aab6bad94afb" }, { "name": "@launchrally/codex-plugin", - "integrity": "sha512-vKp+tv+cPXixoF+82qeHrFRw/LkA+MCQEFWxmO4nUxlrac8fDoF10IXDk/tl2dxLGQfMGcMwKLqhfTu8kHI1cQ==", - "shasum": "3535b401a968d9d644e078b38f6f252a78c153a4" + "integrity": "sha512-0v3ufyUbXmV1gt5ALwwBSxL6Ls1cQEkERqOvmbRGOwW1JKICGJT7EEeZXAXLlhJyXdjkSYbfoHwVQ3SbH7gsaA==", + "shasum": "bd4c84d4c049ff4f7672965e984f75a7a6547b59" }, { "name": "@launchrally/claude-plugin", - "integrity": "sha512-x68P7ATFRAhN7Br6LhozCKpBJW/U1//8/gL2Pu5+X9tk0/kd0J3RPxPPVQ9EbFdGg4dNHxhn4sT7TAkOETSu0g==", - "shasum": "747fd623cbd821c7c1cf365abb8b494da610c9c5" + "integrity": "sha512-QB3T4XTPCl1+UeUCIyS3ARS5WBzFzqqU/i1cMudlJvWlCZi3a2cj0461A6z1guEA+sNXGC4Mxp1LK0/Hujotiw==", + "shasum": "76691e766732cabbd7df7375b7f66201b9abe08c" } ] } diff --git a/release/p1.json b/release/p1.json index c1f0343..a62eb33 100644 --- a/release/p1.json +++ b/release/p1.json @@ -19,15 +19,15 @@ "approved_tag": null }, "experimental_publication": { - "announcement": "docs/maintainers/experimental-0.4.2-announcement.md", - "candidate_tag": "v0.4.2", + "announcement": "docs/maintainers/experimental-0.4.3-announcement.md", + "candidate_tag": "v0.4.3", "channel": "experimental", "stable_channel": "latest", "p0_stable_tag": "v0.3.2", "candidate_manifest": "release/p1-release-candidate.json", "changelog": "CHANGELOG.md", "migration_notes": "docs/maintainers/p1-migration-notes.md", - "evidence_record": "docs/maintainers/experimental-0.4.2-p1-evidence.md" + "evidence_record": "docs/maintainers/experimental-0.4.3-p1-evidence.md" }, "acceptance_requirement_ids": [ "P1-INTENT-01", "P1-INTENT-02", "P1-INTENT-03", diff --git a/skills/launchrally/SKILL.md b/skills/launchrally/SKILL.md index 0e7d181..40d4fb8 100644 --- a/skills/launchrally/SKILL.md +++ b/skills/launchrally/SKILL.md @@ -19,7 +19,7 @@ Use the local CLI as the only authority for Checks, Evidence, Severity, release - When Audit or Verify returns an authenticated Core Journey request, read [references/protected-journeys.md](references/protected-journeys.md). - When a completed Audit or Verify contains `provider_tool_recoveries`, read [references/provider-tool-recovery.md](references/provider-tool-recovery.md). - When invoking the CLI or handling its states, read [references/cli-contract.md](references/cli-contract.md). -- For an exact Experimental 0.4.1-to-0.4.2 Project Toolchain update, follow the [version-specific migration authority](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042) and the typed lifecycle router in [references/cli-contract.md](references/cli-contract.md). +- For an exact Experimental 0.4.2-to-0.4.3 Project Toolchain update, follow the [version-specific migration authority](https://github.com/codeacme17/launchrally/blob/main/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043) and the typed lifecycle router in [references/cli-contract.md](references/cli-contract.md). - When inspecting or exchanging a Phase 1 architecture record, read [references/phase-1-contracts.md](references/phase-1-contracts.md). Contract availability alone does not make a Phase 1 operation executable. - When a typed `architect` interaction enters Product Intent discovery, read [references/product-intent.md](references/product-intent.md) before presenting semantic-analysis permission or confirmation. - When presenting a Capability Catalog, derived obligations, a Capability Graph, or an Integration Contract, read [references/capability-model.md](references/capability-model.md). @@ -54,7 +54,7 @@ Use the local CLI as the only authority for Checks, Evidence, Severity, release 1. Resolve the exact repository root without changing files. 2. Make `rally --version --json --cwd ` the first discovery operation. Do not probe for or invoke a Project Toolchain Engine directly. -3. If `rally` is absent, explain that CLI installation and Plugin installation are separate, link to the repository's single Install authority, present exactly `npm install --global @launchrally/cli@0.4.2` and the structured verification command, then stop before Audit and wait for the user. Do not run the install, automatically substitute the separate exact-version npm-exec trial/CI entry, or change npm prefixes or shell profiles. +3. If `rally` is absent, explain that CLI installation and Plugin installation are separate, link to the repository's single Install authority, present exactly `npm install --global @launchrally/cli@0.4.3` and the structured verification command, then stop before Audit and wait for the user. Do not run the install, automatically substitute the separate exact-version npm-exec trial/CI entry, or change npm prefixes or shell profiles. 4. Validate the complete version response and `launchrally.dev/execution-authority/v1` object through the compatibility matrix and typed authority router in [references/cli-contract.md](references/cli-contract.md). Plugin, Launcher, selected Engine, and project-pin versions are separate facts and need not be equal when each is supported. 5. For `ready`, invoke every repository operation through `rally` so the Launcher follows the selected Engine. For restore, migrate, or clean, show the exact operation, permissions, targets, and effects and wait for explicit user approval before Agent execution. 6. Invoke Agent Mode with structured output and handle the returned state. Stop on unknown contracts or versions, invalid descriptors or paths, and malformed output. diff --git a/skills/launchrally/references/cli-contract.md b/skills/launchrally/references/cli-contract.md index 064cc0e..62d66cb 100644 --- a/skills/launchrally/references/cli-contract.md +++ b/skills/launchrally/references/cli-contract.md @@ -7,7 +7,7 @@ Invoke Agent Mode with `--json`. Require `contract: "launchrally.dev/cli/v2"`, t CLI installation is a prerequisite separate from Plugin installation. Invoke `rally --version --json --cwd ` as the first discovery operation. If spawning `rally` reports that the executable is missing, present the exact user-managed PATH installation and verification commands below, then stop before Audit and wait: ```bash -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json --cwd ``` @@ -17,10 +17,10 @@ This Skill release uses this explicit compatibility matrix: | Layer | Supported value | Meaning | | --- | --- | --- | -| Plugin version | `0.4.2` | Interaction guidance only; never an execution candidate. | -| Launcher version | `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, or `0.4.2`, only when the running implementation declares v1 | A supported user-managed `rally` dispatcher implementing the contracts below. Historical published `0.2.2` direct binaries predate v1 interception and do not qualify. | +| Plugin version | `0.4.3` | Interaction guidance only; never an execution candidate. | +| Launcher version | `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, `0.4.2`, or `0.4.3`, only when the running implementation declares v1 | A supported user-managed `rally` dispatcher implementing the contracts below. Historical published `0.2.2` direct binaries predate v1 interception and do not qualify. | | Execution Authority contract | `launchrally.dev/execution-authority/v1` | The only supported Engine-selection contract. | -| Selected Engine version and contract | `0.2.2`, `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, or `0.4.2` with the declared compatibility path and CLI interaction `launchrally.dev/cli/v2` | The Engine selected by validated authority. A descriptor-free `0.2.2` project is accepted only through the legacy row below. | +| Selected Engine version and contract | `0.2.2`, `0.3.0`, `0.3.1`, `0.3.2`, `0.4.0`, `0.4.1`, `0.4.2`, or `0.4.3` with the declared compatibility path and CLI interaction `launchrally.dev/cli/v2` | The Engine selected by validated authority. A descriptor-free `0.2.2` project is accepted only through the legacy row below. | | Legacy project pin | `0.2.2`, authority descriptor absent, `compatibility: "legacy_adapter"` | Supported only through the Launcher's allowlisted legacy adapter after explicit restore when materialization is missing. | Keep the Plugin version, Launcher version, selected Engine version, and project pin as separate facts. Read `launcher_version` from the version result, the selected Engine from `cli_version` and `authority.engine`, and the project pin from the validated `project_toolchain` authority. Do not require these versions to be equal; continue only when each value and contract is explicitly supported by the matrix. Any unknown or malformed version must stop before a journey operation. diff --git a/skills/launchrally/references/reference-journey.json b/skills/launchrally/references/reference-journey.json index a5d7480..8b8f24d 100644 --- a/skills/launchrally/references/reference-journey.json +++ b/skills/launchrally/references/reference-journey.json @@ -2,19 +2,19 @@ "schema_version": "launchrally.dev/reference-journey/v3", "compatibility": { "plugin": { - "version": "0.4.2", + "version": "0.4.3", "role": "interaction_only" }, "launcher": { "package": "@launchrally/cli", - "supported_versions": ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2"] + "supported_versions": ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", "0.4.3"] }, "execution_authority": { "supported_contracts": ["launchrally.dev/execution-authority/v1"] }, "engine": { "package": "@launchrally/cli", - "supported_versions": ["0.2.2", "0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2"], + "supported_versions": ["0.2.2", "0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", "0.4.3"], "authority_contracts": ["launchrally.dev/execution-authority/v1"], "interaction_contracts": ["launchrally.dev/cli/v2"] }, @@ -31,7 +31,7 @@ "installation": { "owner": "user", "executable": "npm", - "arguments": ["install", "--global", "@launchrally/cli@0.4.2"] + "arguments": ["install", "--global", "@launchrally/cli@0.4.3"] }, "verification": { "arguments": ["--version", "--json", "--cwd", "{repository_root}"] @@ -57,7 +57,7 @@ }, "cli": { "package": "@launchrally/cli", - "version": "0.4.2", + "version": "0.4.3", "contract": "launchrally.dev/cli/v2" }, "protected_journeys": { diff --git a/skills/launchrally/references/reference-journey.md b/skills/launchrally/references/reference-journey.md index fb0633a..361fec6 100644 --- a/skills/launchrally/references/reference-journey.md +++ b/skills/launchrally/references/reference-journey.md @@ -9,7 +9,7 @@ The user-managed `rally` Launcher is a prerequisite separate from the Codex or C If `rally` is absent, present these exact user-managed commands, stop before Audit, and wait: ```bash -npm install --global @launchrally/cli@0.4.2 +npm install --global @launchrally/cli@0.4.3 rally --version --json --cwd ``` diff --git a/test/reference-journey.test.js b/test/reference-journey.test.js index b192346..c64273f 100644 --- a/test/reference-journey.test.js +++ b/test/reference-journey.test.js @@ -854,14 +854,14 @@ test("the canonical Skill declares Launcher compatibility and typed authority li }, launcher: { package: "@launchrally/cli", - supported_versions: ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", cliPackage.version], + supported_versions: ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", cliPackage.version], }, execution_authority: { supported_contracts: ["launchrally.dev/execution-authority/v1"], }, engine: { package: "@launchrally/cli", - supported_versions: ["0.2.2", "0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", cliPackage.version], + supported_versions: ["0.2.2", "0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", cliPackage.version], authority_contracts: ["launchrally.dev/execution-authority/v1"], interaction_contracts: ["launchrally.dev/cli/v2"], }, diff --git a/test/scaffold.test.js b/test/scaffold.test.js index a231607..6a57b36 100644 --- a/test/scaffold.test.js +++ b/test/scaffold.test.js @@ -545,8 +545,8 @@ test("audit excludes Architecture history without hiding protected LaunchRally i "schema_version: launchrally.dev/manifest/v2\n", ); - const initial = await runAudit(fixture, "0.4.2"); - const confirmation = await runAudit(fixture, "0.4.2", { + const initial = await runAudit(fixture, "0.4.3"); + const confirmation = await runAudit(fixture, "0.4.3", { resume_token: initial.interaction.resume_token, answers: { intended_environment: "production", @@ -556,11 +556,11 @@ test("audit excludes Architecture history without hiding protected LaunchRally i support_layers: [], }, }); - const permission = await runAudit(fixture, "0.4.2", { + const permission = await runAudit(fixture, "0.4.3", { resume_token: confirmation.interaction.resume_token, confirmation: "confirm", }); - const result = await runAudit(fixture, "0.4.2", { + const result = await runAudit(fixture, "0.4.3", { resume_token: permission.interaction.resume_token, permission_decisions: { public_verification: "denied" }, }); From 720fb42ed6b7d1305d232299d1bda2eb35a1e48f Mon Sep 17 00:00:00 2001 From: leyoonafr Date: Mon, 24 Aug 2026 07:34:59 +0800 Subject: [PATCH 2/5] docs: complete 0.4.3 release inventory (#210) --- .../experimental-0.4.3-announcement.md | 26 ++++++++++++++++--- 1 file changed, 22 insertions(+), 4 deletions(-) diff --git a/docs/maintainers/experimental-0.4.3-announcement.md b/docs/maintainers/experimental-0.4.3-announcement.md index e4951f9..f086fc7 100644 --- a/docs/maintainers/experimental-0.4.3-announcement.md +++ b/docs/maintainers/experimental-0.4.3-announcement.md @@ -16,7 +16,25 @@ Phase 0 remains independently Product Complete, P0 Validated, and Stable at 0.3.2. npm `latest` continues to resolve to 0.3.2; 0.4.3 is available only from `experimental` or by exact version. -Review the [0.4.3 changelog](../../CHANGELOG.md), [exact 0.4.2-to-0.4.3 Project -Toolchain migration](p1-migration-notes.md#project-toolchain-migration-042-to-043), -and [external verification record](experimental-0.4.3-p1-evidence.md) before -adoption. +Review the [0.4.3 changelog](https://github.com/codeacme17/launchrally/blob/v0.4.3/CHANGELOG.md), +[exact 0.4.2-to-0.4.3 Project Toolchain migration](https://github.com/codeacme17/launchrally/blob/v0.4.3/docs/maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043), +and [external verification record](https://github.com/codeacme17/launchrally/blob/v0.4.3/docs/maintainers/experimental-0.4.3-p1-evidence.md) +before adoption. + +## Resolved issues + +- [#187 — Style the complete Architect Human Mode decision flow](https://github.com/codeacme17/launchrally/issues/187) +- [#204 — Complete Project Toolchain lifecycle Human Mode interactions](https://github.com/codeacme17/launchrally/issues/204) +- [#205 — Add an exact 0.4.1-to-0.4.2 Project Toolchain migration guide](https://github.com/codeacme17/launchrally/issues/205) +- [#210 — Publish and verify Phase 1 Experimental 0.4.3](https://github.com/codeacme17/launchrally/issues/210) + +## Merged pull requests + +- [#206 — Keep release validation current and document release notes](https://github.com/codeacme17/launchrally/pull/206) +- [#207 — Complete Project Toolchain migrate Human Mode](https://github.com/codeacme17/launchrally/pull/207) +- [#208 — Add exact 0.4.1-to-0.4.2 migration guide](https://github.com/codeacme17/launchrally/pull/208) +- [#209 — Complete remaining Phase 1 Human Mode flows](https://github.com/codeacme17/launchrally/pull/209) + +## Contributors + +- [@codeacme17](https://github.com/codeacme17) — [#206](https://github.com/codeacme17/launchrally/pull/206), [#207](https://github.com/codeacme17/launchrally/pull/207), [#208](https://github.com/codeacme17/launchrally/pull/208), [#209](https://github.com/codeacme17/launchrally/pull/209) From 1f27a6ef2151765e50d07cfbf1276a548bdeb3f6 Mon Sep 17 00:00:00 2001 From: leyoonafr Date: Mon, 24 Aug 2026 07:36:55 +0800 Subject: [PATCH 3/5] docs: preserve historical migration guidance (#210) --- docs/getting-started/install.md | 8 +- docs/getting-started/quickstart.md | 5 +- docs/maintainers/p1-migration-notes.md | 121 +++++++++++++++++++++++++ 3 files changed, 129 insertions(+), 5 deletions(-) diff --git a/docs/getting-started/install.md b/docs/getting-started/install.md index 21add4e..9f79a6b 100644 --- a/docs/getting-started/install.md +++ b/docs/getting-started/install.md @@ -2,9 +2,11 @@ LaunchRally `0.3.2` is the exact Stable release used by this guide. Stable availability follows the reviewed P0 Validated decision and satisfied Quality Floor. -Updating an initialized Experimental `0.4.1` project is a separate path. Follow -the [exact 0.4.2-to-0.4.3 Project Toolchain migration](../maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043) -without relabeling this Stable `0.3.2` installation path. +Updating an initialized Experimental project is a separate path. Follow the +exact Project Toolchain migration for the established Engine pin: +[0.4.1 to 0.4.2](../maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042) +or [0.4.2 to 0.4.3](../maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043). +Neither path relabels this Stable `0.3.2` installation guide. ## Supported environments diff --git a/docs/getting-started/quickstart.md b/docs/getting-started/quickstart.md index 3036afa..e361c57 100644 --- a/docs/getting-started/quickstart.md +++ b/docs/getting-started/quickstart.md @@ -2,8 +2,9 @@ LaunchRally `0.3.2` is a public Stable release. Run it against a repository you control and review every disclosed read or write boundary before confirming it. Stable means the reviewed P0 Validated decision and Quality Floor requirements are satisfied. -Already using an initialized Experimental `0.4.1` project? Use the separate -[exact 0.4.2-to-0.4.3 Project Toolchain migration](../maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043). +Already using an initialized Experimental project? Use the separate exact +Project Toolchain migration for [0.4.1 to 0.4.2](../maintainers/p1-migration-notes.md#project-toolchain-migration-041-to-042) +or [0.4.2 to 0.4.3](../maintainers/p1-migration-notes.md#project-toolchain-migration-042-to-043). That path keeps Launcher, selected Engine, project pin, Plugin, and release channel distinct; it does not change the Stable quickstart below. diff --git a/docs/maintainers/p1-migration-notes.md b/docs/maintainers/p1-migration-notes.md index 96ad7b5..f4d45b9 100644 --- a/docs/maintainers/p1-migration-notes.md +++ b/docs/maintainers/p1-migration-notes.md @@ -215,6 +215,127 @@ and owner-restricted host resume registry unchanged. Removing that separate host registry invalidates retained resumable host artifacts; it is not part of Project Toolchain migration. +## Project Toolchain migration: 0.4.1 to 0.4.2 + +This historical procedure remains available for an initialized project whose +established Engine pin is `0.4.1`. LaunchRally 0.4.2 is Experimental; Phase 0 +Stable remains `0.3.2` on npm `latest`. Updating the global Launcher does not +change a valid project pin, so `launcher_version: "0.4.2"` together with +`cli_version: "0.4.1"` and `authority.source: "project_toolchain"` is expected +before migration. Only an explicitly confirmed `toolchain migrate` changes the +pin; `init` is not a migration mechanism. + +Migration changes only the owned Project Toolchain package, lock, authority +descriptor, and rebuildable materialization. It preserves the Manifest, +immutable Reports, Evidence, Architecture history, Provider intent, +application dependencies and source, and external saved Reports. It marks the +prior current Report non-current with `execution_authority_changed`, requiring +a fresh full Verify against the original Manifest-bound source Audit Report. + +The shipped 0.4.2 default TTY flow emits typed permission and confirmation +states and requires explicit resume commands. Review every field, keep opaque +resume tokens outside the repository, and treat registry permission and +migration confirmation as separate decisions. + +### POSIX + +```sh +PROJECT_ROOT=/path/to/project +SOURCE_REPORT=/path/to/original-manifest-bound-audit-report.json +MIGRATION_RESPONSE=./launchrally-0.4.2-migration-response.json + +npm install --global @launchrally/cli@0.4.2 +rally --version --json +rally --version --json --cwd "$PROJECT_ROOT" +rally toolchain status --json --cwd "$PROJECT_ROOT" + +rally toolchain migrate --to 0.4.2 --cwd "$PROJECT_ROOT" > "$MIGRATION_RESPONSE" +node -e 'const fs = require("node:fs"); const value = JSON.parse(fs.readFileSync(process.argv[1], "utf8")); console.log(value.status); console.log(JSON.stringify(value.request ?? {}, null, 2));' "$MIGRATION_RESPONSE" +``` + +If the response is `needs_permission`, review the exact `npm_registry_read` +request. Denial preserves the 0.4.1 pin. Approval authorizes only that bounded +read and returns the exact migration preview: + +```sh +MIGRATION_TOKEN="$(node -e 'const fs = require("node:fs"); const value = JSON.parse(fs.readFileSync(process.argv[1], "utf8")); process.stdout.write(value.interaction.resume_token);' "$MIGRATION_RESPONSE")" +rally toolchain migrate --to 0.4.2 --cwd "$PROJECT_ROOT" --resume "$MIGRATION_TOKEN" --permissions '{"npm_registry_read":"approved"}' > "$MIGRATION_RESPONSE" +node -e 'const fs = require("node:fs"); const value = JSON.parse(fs.readFileSync(process.argv[1], "utf8")); console.log(value.status); console.log(JSON.stringify(value.preview ?? {}, null, 2));' "$MIGRATION_RESPONSE" +``` + +When the response is `needs_confirmation`, inspect every +`preview.changes` entry. Resume with `decline` to change nothing, or confirm the +exact preview and perform the mandatory full Verify: + +```sh +MIGRATION_TOKEN="$(node -e 'const fs = require("node:fs"); const value = JSON.parse(fs.readFileSync(process.argv[1], "utf8")); process.stdout.write(value.interaction.resume_token);' "$MIGRATION_RESPONSE")" +rally toolchain migrate --to 0.4.2 --cwd "$PROJECT_ROOT" --resume "$MIGRATION_TOKEN" --confirm confirm +rally --version --json --cwd "$PROJECT_ROOT" +rally verify --cwd "$PROJECT_ROOT" --report "$SOURCE_REPORT" --scope full +``` + +### PowerShell + +```powershell +$ProjectRoot = 'C:\path\to\project' +$SourceReport = 'C:\path\to\original-manifest-bound-audit-report.json' +$MigrationResponse = '.\launchrally-0.4.2-migration-response.json' + +npm install --global @launchrally/cli@0.4.2 +rally --version --json +rally --version --json --cwd $ProjectRoot +rally toolchain status --json --cwd $ProjectRoot + +rally toolchain migrate --to 0.4.2 --cwd $ProjectRoot | Set-Content -Encoding utf8 $MigrationResponse +$Migration = Get-Content -Raw $MigrationResponse | ConvertFrom-Json +$Migration.status +$Migration.request | ConvertTo-Json -Depth 20 +``` + +Approve only the exact registry request when required, then inspect and confirm +the exact preview: + +```powershell +rally toolchain migrate --to 0.4.2 --cwd $ProjectRoot --resume $Migration.interaction.resume_token --permissions '{"npm_registry_read":"approved"}' | Set-Content -Encoding utf8 $MigrationResponse +$Migration = Get-Content -Raw $MigrationResponse | ConvertFrom-Json +$Migration.preview | ConvertTo-Json -Depth 20 + +rally toolchain migrate --to 0.4.2 --cwd $ProjectRoot --resume $Migration.interaction.resume_token --confirm confirm +rally --version --json --cwd $ProjectRoot +rally verify --cwd $ProjectRoot --report $SourceReport --scope full +``` + +After migration require ready `project_toolchain` authority and both Launcher +and selected Engine at 0.4.2. Use the new current Report printed by Verify for +Plan or Architect, while retaining the Manifest-bound source Report for future +whole-release Verify runs. + +Denial, cancellation, abandoned or stale previews, and missing registry access +preserve the 0.4.1 pin. Interrupted transactions recover only when their state +is safely recognizable; malformed state fails closed. `restore` rebuilds the +established pin and is not a downgrade. Launcher 0.4.2 supports only the +allowlisted legacy downgrade target `0.2.2`; direct downgrade to 0.4.1 is +unsupported. + +Update an installed Plugin separately and pin its checkout to the exact tag: + +```sh +codex plugin remove launchrally@launchrally +codex plugin marketplace remove launchrally +codex plugin marketplace add codeacme17/launchrally --ref v0.4.2 +codex plugin add launchrally@launchrally +codex plugin list --json + +claude plugin uninstall launchrally@launchrally --scope user +claude plugin marketplace remove launchrally +claude plugin marketplace add codeacme17/launchrally@v0.4.2 --scope user +claude plugin install launchrally@launchrally --scope user +claude plugin list --json +``` + +Plugin update or removal does not change the Launcher, Project Toolchain, +project-owned data, application source, or owner-restricted host resume state. + ## Adoption Install 0.4.3 only by selecting the non-stable `experimental` channel or the From 99aa0c5a9e5b3abe545fb0214a4fb82d700e3ca8 Mon Sep 17 00:00:00 2001 From: leyoonafr Date: Mon, 24 Aug 2026 07:38:46 +0800 Subject: [PATCH 4/5] docs: include release promotion pull requests (#210) --- docs/maintainers/experimental-0.4.3-announcement.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/maintainers/experimental-0.4.3-announcement.md b/docs/maintainers/experimental-0.4.3-announcement.md index f086fc7..32ba6b9 100644 --- a/docs/maintainers/experimental-0.4.3-announcement.md +++ b/docs/maintainers/experimental-0.4.3-announcement.md @@ -34,7 +34,9 @@ before adoption. - [#207 — Complete Project Toolchain migrate Human Mode](https://github.com/codeacme17/launchrally/pull/207) - [#208 — Add exact 0.4.1-to-0.4.2 migration guide](https://github.com/codeacme17/launchrally/pull/208) - [#209 — Complete remaining Phase 1 Human Mode flows](https://github.com/codeacme17/launchrally/pull/209) +- [#211 — Prepare Phase 1 Experimental 0.4.3](https://github.com/codeacme17/launchrally/pull/211) +- [#212 — Promote Phase 1 Experimental 0.4.3](https://github.com/codeacme17/launchrally/pull/212) ## Contributors -- [@codeacme17](https://github.com/codeacme17) — [#206](https://github.com/codeacme17/launchrally/pull/206), [#207](https://github.com/codeacme17/launchrally/pull/207), [#208](https://github.com/codeacme17/launchrally/pull/208), [#209](https://github.com/codeacme17/launchrally/pull/209) +- [@codeacme17](https://github.com/codeacme17) — [#206](https://github.com/codeacme17/launchrally/pull/206), [#207](https://github.com/codeacme17/launchrally/pull/207), [#208](https://github.com/codeacme17/launchrally/pull/208), [#209](https://github.com/codeacme17/launchrally/pull/209), [#211](https://github.com/codeacme17/launchrally/pull/211), [#212](https://github.com/codeacme17/launchrally/pull/212) From 82c9c0bb41e4c43ada6adeecb58adf06c7f0e9fa Mon Sep 17 00:00:00 2001 From: leyoonafr Date: Mon, 24 Aug 2026 07:43:56 +0800 Subject: [PATCH 5/5] test: derive current lifecycle version (#210) --- test/reference-journey.test.js | 2 +- test/toolchain-lifecycle.test.js | 66 ++++++++++++++++---------------- 2 files changed, 35 insertions(+), 33 deletions(-) diff --git a/test/reference-journey.test.js b/test/reference-journey.test.js index c64273f..be62e6e 100644 --- a/test/reference-journey.test.js +++ b/test/reference-journey.test.js @@ -873,7 +873,7 @@ test("the canonical Skill declares Launcher compatibility and typed authority li }); assert.deepEqual( journey.compatibility.launcher.supported_versions, - ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", journey.compatibility.plugin.version], + ["0.3.0", "0.3.1", "0.3.2", "0.4.0", "0.4.1", "0.4.2", journey.compatibility.plugin.version], "a pre-authority direct binary cannot be treated as a supported Launcher", ); assert.notEqual( diff --git a/test/toolchain-lifecycle.test.js b/test/toolchain-lifecycle.test.js index 447480d..462780c 100644 --- a/test/toolchain-lifecycle.test.js +++ b/test/toolchain-lifecycle.test.js @@ -20,6 +20,7 @@ import { promisify } from "node:util"; import { assertValidToolchainLifecycle } from "../packages/contracts/src/index.js"; import { runToolchainLifecycle } from "../packages/core/src/index.js"; +import { VERSION } from "../packages/cli/bin/version.js"; import { materializeExactToolchain, writeExactToolchain, @@ -27,6 +28,7 @@ import { const execFileAsync = promisify(execFile); const cli = path.resolve("packages/cli/bin/rally.js"); +const escapedVersion = VERSION.replaceAll(".", "\\."); const pythonAvailable = process.platform !== "win32" && spawnSync("python3", ["--version"]).status === 0; const migrationPtyRunner = [ @@ -289,7 +291,7 @@ test("TTY Human toolchain migrate previews and confirms exact authority in one p const repository = await repositoryFixture(); await writeProject(repository, "0.2.2"); await materializeExactToolchain(repository, "0.2.2"); - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); const { stdout } = await execFileAsync("python3", [ @@ -301,7 +303,7 @@ test("TTY Human toolchain migrate previews and confirms exact authority in one p "toolchain", "migrate", "--to", - "0.4.2", + VERSION, "--plain", "--cwd", repository, @@ -315,7 +317,7 @@ test("TTY Human toolchain migrate previews and confirms exact authority in one p }); assert.match(stdout, /LaunchRally Project Toolchain Migration Preview/u); - assert.match(stdout, /Engine: 0\.2\.2 -> 0\.4\.2/u); + assert.match(stdout, new RegExp(`Engine: 0\\.2\\.2 -> ${escapedVersion}`, "u")); assert.match(stdout, /Authoritative files:/u); assert.match(stdout, /Materialization: 9 packages/u); assert.match(stdout, /1\. Confirm/u); @@ -329,10 +331,10 @@ test("TTY Human toolchain migrate previews and confirms exact authority in one p assert.match(stdout, /verify --scope full/u); assert.doesNotMatch(stdout, /resume_token|"contract"|"preview"/u); - const status = await runToolchainLifecycle(repository, "0.4.2", { + const status = await runToolchainLifecycle(repository, VERSION, { operation: "status", }); - assert.equal(status.authority.engine.version, "0.4.2"); + assert.equal(status.authority.engine.version, VERSION); assert.equal(status.authority.state, "ready"); }); @@ -342,13 +344,13 @@ test("default styled TTY migration confirms and completes", { const repository = await repositoryFixture(); await writeProject(repository, "0.2.2"); await materializeExactToolchain(repository, "0.2.2"); - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); const packagePath = path.join(repository, ".launchrally/toolchain/package.json"); const { stdout } = await execFileAsync("python3", [ "-c", styledMigrationPtyRunner, "confirm", packagePath, process.execPath, cli, - "toolchain", "migrate", "--to", "0.4.2", "--cwd", repository, + "toolchain", "migrate", "--to", VERSION, "--cwd", repository, ], { env: { ...process.env, @@ -377,12 +379,12 @@ test("default styled TTY migration handles registry permission and cancellation const repository = await repositoryFixture(); await writeProject(repository, "0.2.2"); await materializeExactToolchain(repository, "0.2.2"); - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); const packagePath = path.join(repository, ".launchrally/toolchain/package.json"); const run = execFileAsync("python3", [ "-c", styledMigrationPtyRunner, scenario.mode, packagePath, process.execPath, cli, - "toolchain", "migrate", "--to", "0.4.2", "--cwd", repository, + "toolchain", "migrate", "--to", VERSION, "--cwd", repository, ], { env: { ...process.env, @@ -402,7 +404,7 @@ test("default styled TTY migration handles registry permission and cancellation assert.match(error.stdout, scenario.summary); return true; }); - assert.equal((await runToolchainLifecycle(repository, "0.4.2", { + assert.equal((await runToolchainLifecycle(repository, VERSION, { operation: "status", })).authority.engine.version, "0.2.2"); assert.deepEqual(await storedLifecycleStates(repository), []); @@ -416,12 +418,12 @@ test("TTY Human toolchain migrate shows the full exact diff and returns to confi const repository = await repositoryFixture(); await writeProject(repository, "0.2.2"); await materializeExactToolchain(repository, "0.2.2"); - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); const { stdout } = await execFileAsync("python3", [ "-c", migrationPtyRunner, "3,1", process.execPath, cli, - "toolchain", "migrate", "--to", "0.4.2", "--plain", "--cwd", repository, + "toolchain", "migrate", "--to", VERSION, "--plain", "--cwd", repository, ], { env: { ...process.env, @@ -448,13 +450,13 @@ test("TTY Human toolchain migrate safely declines by default and can cancel", { const repository = await repositoryFixture(); await writeProject(repository, "0.2.2"); await materializeExactToolchain(repository, "0.2.2"); - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); let output; try { output = (await execFileAsync("python3", [ "-c", migrationPtyRunner, scenario.answer, process.execPath, cli, - "toolchain", "migrate", "--to", "0.4.2", "--plain", "--cwd", repository, + "toolchain", "migrate", "--to", VERSION, "--plain", "--cwd", repository, ], { env: { ...process.env, @@ -470,7 +472,7 @@ test("TTY Human toolchain migrate safely declines by default and can cancel", { } assert.match(output, scenario.summary); assert.doesNotMatch(output, /resume_token/u); - const status = await runToolchainLifecycle(repository, "0.4.2", { operation: "status" }); + const status = await runToolchainLifecycle(repository, VERSION, { operation: "status" }); assert.equal(status.authority.engine.version, "0.2.2"); assert.deepEqual(await storedLifecycleStates(repository), []); } @@ -482,13 +484,13 @@ test("TTY Human toolchain migrate fails a stale preview closed with a concise re const repository = await repositoryFixture(); await writeProject(repository, "0.2.2"); await materializeExactToolchain(repository, "0.2.2"); - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); const packagePath = path.join(repository, ".launchrally/toolchain/package.json"); await assert.rejects(execFileAsync("python3", [ "-c", staleMigrationPtyRunner, packagePath, process.execPath, cli, - "toolchain", "migrate", "--to", "0.4.2", "--plain", "--cwd", repository, + "toolchain", "migrate", "--to", VERSION, "--plain", "--cwd", repository, ], { env: { ...process.env, @@ -503,7 +505,7 @@ test("TTY Human toolchain migrate fails a stale preview closed with a concise re assert.doesNotMatch(error.stdout, /"error"|resume_token/u); return true; }); - assert.equal((await runToolchainLifecycle(repository, "0.4.2", { + assert.equal((await runToolchainLifecycle(repository, VERSION, { operation: "status", })).authority.engine.version, "0.2.2"); }); @@ -519,12 +521,12 @@ test("TTY Human toolchain migrate requests registry permission and rolls back co await mkdir(path.join(repository, ".launchrally/cache"), { recursive: true }); await writeFile(path.join(repository, ".launchrally/cache/current-report.json"), "not-json\n"); } - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); try { const { stdout } = await execFileAsync("python3", [ "-c", migrationPtyRunner, "y,1", process.execPath, cli, - "toolchain", "migrate", "--to", "0.4.2", "--plain", "--cwd", repository, + "toolchain", "migrate", "--to", VERSION, "--plain", "--cwd", repository, ], { env: { ...process.env, @@ -542,7 +544,7 @@ test("TTY Human toolchain migrate requests registry permission and rolls back co assert.equal(error.code, 2); assert.match(error.stdout, /Migration Could Not Complete/u); assert.match(error.stdout, /prior project authority was preserved/iu); - assert.equal((await runToolchainLifecycle(repository, "0.4.2", { + assert.equal((await runToolchainLifecycle(repository, VERSION, { operation: "status", })).authority.engine.version, "0.2.2"); } @@ -555,12 +557,12 @@ test("TTY Human toolchain migrate denies registry permission without changing au const repository = await repositoryFixture(); await writeProject(repository, "0.2.2"); await materializeExactToolchain(repository, "0.2.2"); - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); await assert.rejects(execFileAsync("python3", [ "-c", migrationPtyRunner, "n", process.execPath, cli, - "toolchain", "migrate", "--to", "0.4.2", "--plain", "--cwd", repository, + "toolchain", "migrate", "--to", VERSION, "--plain", "--cwd", repository, ], { env: { ...process.env, @@ -577,7 +579,7 @@ test("TTY Human toolchain migrate denies registry permission without changing au assert.doesNotMatch(error.stdout, /resume_token/u); return true; }); - assert.equal((await runToolchainLifecycle(repository, "0.4.2", { + assert.equal((await runToolchainLifecycle(repository, VERSION, { operation: "status", })).authority.engine.version, "0.2.2"); }); @@ -588,18 +590,18 @@ test("non-TTY Human migration fails safely with a complete Agent command", async await materializeExactToolchain(repository, "0.2.2"); await assert.rejects(execFileAsync(process.execPath, [ - cli, "toolchain", "migrate", "--to", "0.4.2", "--cwd", repository, + cli, "toolchain", "migrate", "--to", VERSION, "--cwd", repository, ]), (error) => { assert.equal(error.code, 2); assert.match(error.stderr, /Non-TTY Human Mode cannot confirm/u); assert.match( error.stderr, - /['"]?toolchain['"]?\s+['"]?migrate['"]?\s+['"]?--to['"]?\s+['"]?0\.4\.2['"]?\s+['"]?--json['"]?\s+['"]?--cwd['"]?/u, + new RegExp(String.raw`['"]?toolchain['"]?\s+['"]?migrate['"]?\s+['"]?--to['"]?\s+['"]?${escapedVersion}['"]?\s+['"]?--json['"]?\s+['"]?--cwd['"]?`, "u"), ); assert.doesNotMatch(error.stdout, /needs_confirmation|resume_token/u); return true; }); - assert.equal((await runToolchainLifecycle(repository, "0.4.2", { + assert.equal((await runToolchainLifecycle(repository, VERSION, { operation: "status", })).authority.engine.version, "0.2.2"); }); @@ -612,7 +614,7 @@ test("non-TTY structured migration prints the complete corrected Agent command", "toolchain", "migrate", "--to", - "0.4.2", + VERSION, "--cwd", repository, "--resume", @@ -626,7 +628,7 @@ test("non-TTY structured migration prints the complete corrected Agent command", assert.match(error.stderr, /Use this complete Agent\/JSON command/u); assert.match( error.stderr, - /['"]?toolchain['"]?\s+['"]?migrate['"]?\s+['"]?--to['"]?\s+['"]?0\.4\.2['"]?\s+['"]?--json['"]?\s+['"]?--cwd['"]?/u, + new RegExp(String.raw`['"]?toolchain['"]?\s+['"]?migrate['"]?\s+['"]?--to['"]?\s+['"]?${escapedVersion}['"]?\s+['"]?--json['"]?\s+['"]?--cwd['"]?`, "u"), ); assert.match( error.stderr, @@ -675,7 +677,7 @@ test("Agent JSON toolchain migrate preserves the exact resumable protocol", asyn const repository = await repositoryFixture(); await writeProject(repository, "0.2.2"); await materializeExactToolchain(repository, "0.2.2"); - const prepared = await preparedToolchain("0.4.2"); + const prepared = await preparedToolchain(VERSION); const npmDirectory = await npmFixture(prepared); const environment = { ...process.env, @@ -684,7 +686,7 @@ test("Agent JSON toolchain migrate preserves the exact resumable protocol", asyn }; const preview = JSON.parse((await execFileAsync(process.execPath, [ - cli, "toolchain", "migrate", "--to", "0.4.2", "--json", "--cwd", repository, + cli, "toolchain", "migrate", "--to", VERSION, "--json", "--cwd", repository, ], { env: environment })).stdout); assert.equal(preview.contract, "launchrally.dev/toolchain-lifecycle/v1"); assert.equal(preview.status, "needs_confirmation"); @@ -698,7 +700,7 @@ test("Agent JSON toolchain migrate preserves the exact resumable protocol", asyn "toolchain", "migrate", "--to", - "0.4.2", + VERSION, "--json", "--cwd", repository,