docs(release): register Android 0.1.13 candidate

This commit is contained in:
key
2026-07-29 12:18:00 +08:00
parent af8af2f6dd
commit cc1865a979
10 changed files with 43 additions and 31 deletions
+11 -7
View File
@@ -1,13 +1,13 @@
[CmdletBinding()]
param(
[string]$EvidenceDirectory = 'output\aug1-rc\0.1.12-112-b9e08789-frozen',
[string]$EvidenceDirectory = 'output\aug1-rc\0.1.13-113-af8af2f6-frozen',
[Parameter(Mandatory = $true)]
[string]$BackendJar,
[string]$ContentCandidate = 'docs\content-candidates\aug1-life-advisor-content-candidates-v0.1.json',
[string]$RuntimeCommit = 'b9e08789265b73524e3ce2646abe2f2fc4565906',
[string]$RuntimeCommit = 'af8af2f6dd169e4616a4ca0ca724e8b809502ab3',
[string]$OperationsCommit = 'HEAD',
@@ -189,7 +189,7 @@ try {
"- Runtime commit: $runtimeCommitSha (unchanged APK/JAR)",
"- Operations commit: $operationsCommitSha (deploy, rollback, API and Android evidence tools)",
'- Automated candidate: `releaseEligible=true`',
'- Current decision: **No-Go**; manual privacy/permission, authenticated business, content and authorization gates remain.',
'- Current decision: **No-Go**; Android device permission/write/media, formal content/handler, production authorization and enterprise sign-off gates remain.',
'',
'## Core artifacts',
'',
@@ -205,7 +205,7 @@ try {
'',
'Run the versioned release script from a clean checkout of the operations commit. The ZIP operations folder is an audit snapshot and must not be executed outside repository context. Run read-only plan first; deploy only after separate explicit authorization. Do not manually overwrite the JAR.',
'',
'Run the GET-only API probe before and after release, and capture read-only Android evidence after each manual step. Neither replaces the user privacy choice or authenticated business acceptance.',
'Run the GET-only API probe before and after release, and capture read-only Android evidence after each manual step. Neither replaces Android device acceptance or formal business sign-off.',
'',
'This package does not authorize production deployment, service restart, database change, Git push or public distribution.'
) -join [Environment]::NewLine
@@ -215,13 +215,14 @@ try {
'# August 1 production preflight summary',
'',
"- Generated from operations commit: $operationsCommitSha",
'- Check type: read-only; no deployment, restart, database mutation, SMS request, login, upload or static sync.',
'- Check type: read-only deploy plan; no deployment, restart, database mutation, SMS request, login, upload or static sync.',
'- Backend deploy plan: passed for the frozen JAR.',
"- Candidate JAR SHA-256: $backendSha256",
'- Current production JAR SHA-256: `46c99cff75d21f8536a71c3c058b6437e99dbf9ff4bae3542b44471f3f34ad84`',
'- Production service: `wygj-aihr.service` active and starts the fixed JAR path.',
'- Production schema: 64/64 and runtime schema bootstrap disabled/default.',
'- Production GET-only route probe: 20/20 (`1x200`, `6x401`, `13x405`).',
'- Separate fixed-code authenticated smoke passed request/login, read-only business routes, logout, old-token rejection and re-login; application logs confirmed that no real SMS was sent.',
'- Backend normalized AIHR module remains mismatched until an authorized deploy.',
'- Overall result: **No-Go** pending the manual and authorization gates in `operations/go-no-go.md`.'
) -join [Environment]::NewLine
@@ -259,7 +260,8 @@ try {
sha256 = $apkSha256
signerSha256 = ([string]$evidence.app.signerSha256).ToLowerInvariant()
internalTestOnly = $true
manualPrivacyChoicePending = $true
androidDeviceAcceptancePending = $true
loginLegalInteractionOnAndroidPending = $true
}
backend = [ordered]@{
artifact = $backendName
@@ -275,7 +277,9 @@ try {
schema = '64/64'
runtimeSchemaBootstrap = 'false/default'
routeProbe = '20/20: 1 public 200, 6 auth 401, 13 method 405'
smsOrLoginTriggered = $false
deployPlanSmsOrLoginTriggered = $false
authenticatedFixedCodeSmokePassed = $true
fixedCodeNoRealSmsConfirmed = $true
}
contentCandidates = [ordered]@{
artifact = 'aug1-life-advisor-content-candidates-v0.1.json'
+9 -3
View File
@@ -5,8 +5,8 @@ $devSetupPath = Join-Path $projectRoot 'docs\DEV_SETUP.md'
$source = Get-Content -Raw -Encoding UTF8 -LiteralPath $scriptPath
$requiredFragments = @(
"output\aug1-rc\0.1.12-112-b9e08789-frozen",
'b9e08789265b73524e3ce2646abe2f2fc4565906',
"output\aug1-rc\0.1.13-113-af8af2f6-frozen",
'af8af2f6dd169e4616a4ca0ca724e8b809502ab3',
'Runtime commit must be an ancestor of the operations commit',
'Frozen evidence is not release eligible',
'Frozen APK hash mismatch',
@@ -20,7 +20,10 @@ $requiredFragments = @(
'Release package already exists and will not be overwritten',
'Release package expected 14 files',
'ZIP entry hash mismatch',
'package_verified=true'
'package_verified=true',
'authenticatedFixedCodeSmokePassed = $true',
'fixedCodeNoRealSmsConfirmed = $true',
'deployPlanSmsOrLoginTriggered = $false'
)
foreach ($fragment in $requiredFragments) {
if (-not $source.Contains($fragment)) {
@@ -34,6 +37,9 @@ if ($source -match 'Compress-Archive') {
if ($source -match '\[switch\]\$Force') {
throw 'August 1 packager must not expose an overwrite switch.'
}
if ($source.Contains('manualPrivacyChoicePending') -or $source.Contains('authenticated business, content')) {
throw 'August 1 packager still describes completed fixed-code authentication as a pending gate.'
}
$devSetup = Get-Content -Raw -Encoding UTF8 -LiteralPath $devSetupPath
if (-not $devSetup.Contains('.\scripts\package-aug1-release.ps1')) {