Repository navigation
Qualify scoped ownership candidate and release-source guard #21
Description
Activity
Scoped source landed on main via #28 (squash
c6bd95b): Run telemetry label, ownership docs, and the release-source guard (mismatched SHA / dirty source / stale binary) with its 4 tests. CI passed on the PR. Remaining on this issue, unchanged: native screen verification (computer-use provider unavailable) and the signed/notarized release, which needs owner release authorization. The managed worktree was retired; its ignoredartifacts/release-readiness/receipts are underAgent Workspaces.noindex/retired/contextdaddy-release-ready-20261008.Checkpoint 2026-10-09 on main
c6bd95b(local checkout is clean and matches origin):scripts/test_release_source.py: 4/4 pass. That covers the mismatched-SHA, dirty-source and stale-binary guards.swift test: a clean run exited 0 with 182 tests passing (28 in 7 suites plus 154 in 34 suites). The opt-inrendersSyntheticCountsWithoutGlobalPreferenceWritesrender test is still skipped.- One earlier
swift testattempt on the same commit reported a failure in a ContextDaddyTests (Swift Testing) case. It ran underfleet-workspace runwhile other heavy jobs were active, I didn't capture which test failed, and the immediate rerun passed. Treat it as a possible flaky test until someone reproduces it.
Still open. Both remaining gates need things this session doesn't have:
- Native screen verification of first-value, navigation, Run telemetry and unavailable states, plus the policy preview/apply/recovery path using controlled data. This needs working computer-use/native UI access, and this session has no native UI tool.
- Signed/notarized 0.2.8 release through the existing app-owned release pipeline. The owner has to authorize the release explicitly. Then the pipeline needs to verify signing, notarization/stapling, DMG/manifest/public bytes, installed identity and update/download, and the new release-source guard must not be bypassed.
No source changes, packaging, signing or release in this pass.
0.2.8 build 18 released (owner-authorized, 2026-10-09)
Release: https://github.com/Significant-Hobbies/contextdaddy/releases/tag/v0.2.8-18 · protected run https://github.com/Significant-Hobbies/contextdaddy/actions/runs/37879125078 (success;
production-releaseapproved with the owner's authorization)Source. Tag
v0.2.8-18on main06ac896(includes #28's release-source guard and the #29 test fix, #30). Main CI on06ac896passed (test, shared_candidate, site). Site metadata recorded on main by the workflow in2517079.Qualification before dispatch (local, exact
06ac896clean checkout):swift test --skip DesignSnapshotTests: 26 + 154 tests pass;swift build -c release: arm64, minos 14.0.- Release-source guard:
scripts/test_release_source.py4/4 pass (mismatched SHA, dirty/untracked, stale binary).validate_release_sourcealso accepted the real release binary at06ac896and rejected a mismatched SHA. - Pinned shared tooling (
bdea255)test_candidate test_release_contract test_release_preflight test_publish_site: 16 pass.candidate.pyitself only runs on CI here (it pins the runner's Xcode 26.6 path); CI ran it on the release source.
Published artifact, checked independently after release:
https://context.daddyrad.com/downloadservesContextDaddy-0.2.8-18-arm64.dmg, 7,516,124 bytes, SHA-2566e15466433fd5a1c7c8bfa0e556e46d169696967594eea5834d7fac1046df94e. This matches the GitHub release asset,SHA256SUMSandsite/release.jsonon main.- DMG:
codesign --verify --strictvalid;spctl --assess --type openaccepted,source=Notarized Developer ID;stapler validateworked. Notary submissione920f3c7-3d6e-4f24-8967-c43a2af194f8Accepted. - App inside the DMG:
codesign --verify --deep --strictvalid, hardened runtime, Developer ID Application (team 8F7LXHTJZR);spctl --assess --type executeaccepted, Notarized Developer ID; bundled ccusage helper signature valid. - Info.plist:
CFBundleShortVersionString0.2.8,CFBundleVersion18,com.significanthobbies.contextdaddy,LSMinimumSystemVersion14.0, arm64.
Still open (owner)
- Native screen verification: first-value, navigation, Run telemetry and unavailable states, and the policy preview/apply/recovery path with controlled data.
- Applicable native design evidence; the opt-in
rendersSyntheticCountsWithoutGlobalPreferenceWritesrender test is still unqualified. - Install 0.2.8 over the current
/Applicationscopy and confirm installed identity/version and first launch. I did not install or replace the app.
Leaving this issue open until those are done.
Evidence check 2026-10-09. Verified: release v0.2.8-18 is published (not draft), its asset digests match the DMG SHA-256 in the earlier comment, and protected run 37879125078 concluded success on 06ac896. Source, guard, CI and signed/notarized release gates are satisfied. Not satisfied, left open:
- Native screen verification (first-value, navigation, Run telemetry, unavailable states, policy preview/apply/recovery with controlled data). Owner action, or an agent with working native UI access. No evidence of it exists.
- Native design evidence and the opt-in render test (rendersSyntheticCountsWithoutGlobalPreferenceWrites). Agent work once native UI access exists.
- Installed-over-/Applications check of 0.2.8. Superseded in practice: main now records v0.2.10-20 and /Applications has 0.2.10. The owner should either waive this item or fold it into native verification against the current build.
Scoped follow-up
Qualify the prepared ownership/Run telemetry/release-source-guard candidate. This is a new release-readiness follow-up; previously completed ContextDaddy issues remain closed.
ContextDaddy owns skills/plugins/MCP structural health, instruction/memory scope, persistent invocation/access policy, token history, provider allowance and run telemetry. Agent Inbox owns live thread status/battery, attention, replies and individual permission requests. PerformanceDaddy owns measured runtime/device diagnosis. Consumption alone does not establish activity, task success or a bottleneck.
Verified checkpoint, 8 October 2026
5d646c417fb35fdd555d32905e650f6d6df5c044; prepared branch:agent/contextdaddy-release-ready-20261008. Local source remains dirty/uncommitted. The original checkout's unrelated usage/quota work is preserved.f7396b2a886252c8b188c361c7c10bd19545db670a6fc4784a986c2e94d41bf0; all 114 receipt files are unchanged in continuation verification.Sky Computer Use native pipe startup failed, including fresh inventory/direct-app retries and session reset. Launch proof does not establish native acceptance.Remaining tasks
Candidate source receipt and unsigned review app remain in the managed worktree's
artifacts/release-readiness/. Full source locations, prior verification and publication authority are in the private three-app handoff. No production signing, publication or installation replacement was performed for this candidate.Related ownership/native gates: Agent Inbox #1, PerformanceDaddy #15.