diff --git a/docs/next-release-20260930.md b/docs/next-release-20260930.md index 0c2a60f9..7d89c969 100644 --- a/docs/next-release-20260930.md +++ b/docs/next-release-20260930.md @@ -1,6 +1,10 @@ # Next OTA and raw ISO after 1.8.21 -**Status: implementation and acceptance in progress; NOT ready to release.** +**Status: implementation and final OTA/raw ISO acceptance passed; draft upload verification and offline signing/publication remain.** + +Current acceptance evidence: [1.8.22 release acceptance](release-1.8.22-acceptance.md). +The chronological notes below retain earlier failures and superseded candidates; +the final tested source is `6d5f3ffb`. This is the consolidated execution checklist for the operator's chat requests. A targeted node repair is not completion of the release. Finish the remaining @@ -45,16 +49,18 @@ completed. See PR review for the accepted scope and coverage limits. ## Final release checklist -- [ ] Finish all new-scope implementation and specific acceptance above. +- [x] Finish new-scope implementation and release acceptance; full-chain Angor + indexing still depends on the dev node finishing initial sync. - [x] Remove disposable fixtures and temporary test overrides; verify native Bitcoin/LND identity and start-state baselines remain protected. - [x] Commit and push completed source changes to git and ngit. -- [ ] Run final backend/UI/regression/release gates on the final source; inspect +- [x] Run final backend/UI/regression/release gates on the final source; inspect skipped tests and report actual hardware/runtime coverage. - [ ] Prepare compatible signed app catalog; old runtimes must not apply a migration before they have backup/recovery support. - [ ] Version/changelog and OTA payload prepared, validated and signed by user. -- [ ] Raw ISO built; payload hashes/content verified; installer boot tested. +- [x] Raw ISO built; payload hashes/content verified; full installation and + installed-system boot tested in QEMU/KVM without network. - [ ] User signs ISO checksums; publish OTA and ISO plus verification files on git and ngit; independently read back hashes and update discovery. - [ ] Provide LAN scp command for the new raw ISO. @@ -430,3 +436,24 @@ ignored, through the isolated runner. This includes all new port-selection cases and the existing companion security/configuration and lifecycle regressions. Rebuild the release binary and UI metadata, deploy those exact OTA bytes to both boxes, and require actual kiosk hard-refresh/Launch acceptance before ISO assembly. + + +## Final accepted artifacts — 1.8.22-alpha + +Source `6d5f3ffb` passed 1,617 backend tests (four explicit opt-in exclusions), +1,133 frontend tests and final release gates. Exact OTA bytes were deployed to +both boxes. Actual X250 kiosk NPM Launch, version/pruning, desktop/mobile +readiness/AIUI, production Portainer Git/Compose and 12-minute stability checks +on both boxes passed. No installed app was restarted by the safe diagnostics, +and the Cuprate orphan stayed absent. Native Bitcoin/LND and the production site +were preserved during final management deployment. + +The raw ISO passed mounted payload checks and matches all 653 OTA frontend/runtime +files plus the backend. Full offline installation and installed UEFI boot to the +visible setup screen passed in a disposable QEMU/KVM VM. Both installed doctor +paths and the installed backend have the expected hashes. No VM wallet was set up. + +See `release-1.8.22-acceptance.md` for exact artifact hashes, hardware/runtime +coverage and limits. Draft upload verification, offline signatures, publication +and public readback remain; the fleet still advertises 1.8.21 until those gates +finish. Do not confuse a draft asset or source push with completed publication. diff --git a/docs/release-1.8.22-acceptance.md b/docs/release-1.8.22-acceptance.md new file mode 100644 index 00000000..abc60629 --- /dev/null +++ b/docs/release-1.8.22-acceptance.md @@ -0,0 +1,83 @@ +# Archipelago 1.8.22-alpha acceptance + +Source: `6d5f3ffb850bfd3dcd396bac986ba770935d1daa`. + +## Verified application and runtime changes + +- Full isolated backend suite: 1,617 passed, zero failed, four explicit opt-in exclusions. +- Frontend suite: 1,133 passed. Final frontend and AIUI production builds succeeded. +- Container suite: 79 passed. Catalog compatibility/trust, release manifest, build contexts, pruning, Lightning readiness, NPM migration, safe doctor, companion recovery and ISO doctor-overlay regressions passed. +- Six companion dashboard images built using the current registry. +- Final OTA backend SHA-256: `e108b78bbbd21cb7d5d47c8d0b7b9b19b63fb0c44678773603202440ec7d6f5b`. +- Final OTA frontend SHA-256: `2da485a2da75ff2fbe4aba52d6f217150e303be43a031723480c9c4ff9d43f41`. + +## Live acceptance + +The exact OTA bytes were deployed to the development box and ThinkPad X250. +Native Bitcoin/LND and the X250 production site retained their container identity +and start time during these final management deployments. Both boxes completed +12-minute observations including scheduled diagnostics with running containers +and persistent mounts unchanged. The orphaned Cuprate dashboard stayed absent. + +Actual X250 Chromium kiosk: hard refresh, NPM Launch to the correct admin URL, +visible login/admin page, readable inline Bitcoin version choices and pruning +checkbox passed. No Bitcoin installation was triggered by this test. + +Final desktop/mobile checks passed for Bitcoin's IBD dashboard, one Mempool card, +headless Phoenixd, LND waiting/unknown-balance behavior and all five transparent +AIUI embedding layers. Standalone AIUI retains its wallpaper. + +Portainer's actual production network namespace fetched Git refs and the Compose +file after final deployment. Original mounts were preserved. Earlier disposable +fresh/reverse-install and migration/rollback tests, and the production host's +operator-initiated reboot check, passed. + +Live Tor-only Cashu paid-file acceptance verified a one-satoshi net purchase, +change, rejected-payment refund, exact file bytes, Files access and free repeat +delivery. No native Bitcoin/LND funds were moved. PRs 161/162 are merged and +closed; the open pull-request list is empty. + +## Boundaries + +- Angor's real dev API, fees, block tip, CORS and rootless/headless configuration + passed. Full-chain indexing remains dependent on initial Bitcoin sync finishing. +- Optional live AI providers, physical RNode hardware, the opt-in Reticulum TCP + subprocess test and creation of a production Minibits profile were not run. +- The previously recorded unsafe-doctor incident changed X250 container start + times before the final fix. Persistent databases were present after recovery, + but no pre-incident cryptographic wallet-identity baseline was available. + Do not describe recovery evidence as an exact pre-incident balance comparison. +- No claim of perfect behavior on every device, network or future failure is made. + +## Raw ISO acceptance + +The raw ISO is 2,755,072,000 bytes. SHA-256: +`cf7be6378dcd52f6f62774523341fa75dd453fa73a9cadff5390846f483e0140`. + +Mounted-artifact smoke checks passed, including BIOS/UEFI boot files, live-boot +hooks, build contexts, current doctor overlay, crash-capture configuration, +version and frontend payload. The ISO backend and all 653 OTA frontend/runtime +files match exactly. AIUI metadata names the tested source commit. + +A disposable QEMU/KVM x86_64 VM with UEFI firmware, 3 GiB RAM, two vCPUs, a fresh +64 GiB NVMe virtual disk and no network completed the full installation. This +covered partitioning, LUKS2 data encryption, swap, system configuration, UEFI +bootloader and initramfs generation. Cold boot with the ISO detached reached the +visible Welcome to Archipelago setup screen. The installed backend and both +historical/current doctor paths matched source hashes. Backend/nginx were active; +health reported RPC/sessions ready, crash recovery complete and version 1.8.22. +No wallet was initialized in this disposable VM. + +The first automatic VM reboot selected the still-attached installer ISO. That +was corrected in the test configuration by detaching the ISO and explicitly +booting NVMe. It was not accepted as an installed-system boot. The subsequent +cold boot above is the successful acceptance run. + +The dev native Bitcoin/LND identity/start-time baseline also remained unchanged +after the ISO build and VM acceptance. + +## Publication pending + +Artifacts are staged in a draft release. Upload/readback verification and the +operator's offline signatures must complete before promoting the fleet manifest +and signed app catalog or publishing the Git/ngit releases.