Skip to content

Release Litter 1.7.0 - #219

Merged
0xSero merged 10 commits into
mainfrom
codex/release-1.7.0
Aug 4, 2026
Merged

Release Litter 1.7.0#219
0xSero merged 10 commits into
mainfrom
codex/release-1.7.0

Conversation

@0xSero

@0xSero 0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner

Purpose

Prepare and validate Litter 1.7.0 for the Apple App Store and Google Play, including the Local Studio mobile-pairing repair.

Key changes

  • Stabilize Local Studio cold-start discovery so Codex, Pi, and every registered agent are available before selection.
  • Preserve immediate discovery for generic KittyLitter hosts.
  • Repair persisted Android TLS roots and reject header-only or truncated CA bundles.
  • Restore full iOS unit-test execution and make rendered SSH-template checks hermetic.
  • Add a bounded iOS device-signing fallback that requires an exact phone bundle id, iOS device profile, development entitlement, and matching identity.
  • Retry canonical iOS signing on every build; do not persist reduced local-signing state.
  • Scope the 1.7.0 merge to Android and iOS release lanes with the [skip mac-release] merge marker.
  • Set iOS and Android marketing versions to 1.7.0, build/version code 200000254, and refresh release notes.

Verification

Completed locally on the current branch:

  • UniFFI Swift/Kotlin binding generation and project regeneration.
  • Rust: 788 tests total; 783 passed and 5 explicitly ignored live-environment tests.
  • iOS: 211 unit tests passed; 6 UI tests passed; 1 discovery-screenshot UI test skipped by its environment gate.
  • Android JVM unit suite passed.
  • iOS simulator build, install, and launch at 1.7.0 / 200000254.
  • Android emulator build, install, and launch at 1.7.0 / 200000254.
  • Canonical iOS device build passed strict signature validation and preserved the Live Activity and Watch bundles.
  • Explicit iOS local-signing fallback passed strict signature validation for the exact phone app.
  • Android release APK and store AAB built through the optimized release lane; APK v2 signature and AAB JAR signature verified.
  • Android persisted-CA corruption tests cover empty, tiny, header-only, and truncated-root inputs.
  • Live Pop!OS Local Studio pairing on Android discovered Codex, Pi, OpenCode, Claude, Droid, Hermes, and Shell; all seven attached successfully.
  • A real Codex turn completed and rendered CODEX_RUNTIME_OK. A real Pi turn completed through the runtime; the selected live Pi backend echoed the prompt instead of a distinct assistant body.
  • Mobile web over Tailnet showed streamed output, reasoning, and a successful shell tool call.
  • Bash syntax, ShellCheck warning gate, release routing simulation, diff whitespace, and secret scan passed.

Current-head GitHub Actions must be green before the draft is marked ready or merged.

Acceptance limitations

No physical iPhone was available to install and launch this build. The canonical signed iPhone bundle and its embedded extensions were built and validated locally, while simulator acceptance covered app launch. The Pi transport/session/turn path completed, but its live model output was an echo; that is recorded rather than treated as a rendered-response pass.

Release execution

After merge, wait for the main-branch Mobile Release workflow to upload Android internal/alpha/beta and iOS TestFlight while skipping both Mac external lanes. Then explicitly dispatch Android production with completed status and submit iOS 1.7.0 for App Review, verifying the authoritative workflow and store states.

@0xSero 0xSero added enhancement New feature or request priority: critical Must land in the current stabilization window labels Aug 4, 2026
@0xSero

0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

GitHub-ops audit: this is correctly draft and based on current main (f5a34f48). The Local Studio scan commit is content-identical to dedicated draft #209, so #209 can be closed as superseded and its validation carried here rather than maintaining two PRs for the same tree. Static checks here pass git diff --check, bash -n for both device scripts, and ShellCheck for the new build-device.sh; the existing run-device.sh still reports its pre-existing SC2024/SC2034 warnings. iOS and Android versions agree at 1.7.0 / build 200000254. Before this becomes ready, require the full stated matrix, a canonical-signing non-regression, and install/launch proof for the locally re-signed app on an actual device (including the resolved bundle id/profile). Store publication or review submission is a separate external action and is not authorized by this audit.

@0xSero

0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Focused release review found three blockers before this draft can become ready:

  1. [P1] Profile selection can sign the phone app with an extension or Mac profile. apps/ios/scripts/build-device.sh:114-154 accepts any development profile whose application identifier merely contains .litter, then selects the latest expiry. apps/ios/project.yml defines matching main, Live Activity, Watch, and Watch-complication identifiers (and the Mac target reuses the main id). The script can therefore rewrite Litter.app at line 213 to the wrong bundle id and still pass codesign. Require the exact requested phone bundle id plus iOS/development-platform validation (or an explicit local bundle id), with a candidate-set regression covering app/extension/watch/Mac profiles.

  2. [P1] Merging this mobile release also triggers unmentioned Mac external release lanes. The changed Makefile, apps/ios/project.yml, apps/ios/Sources/**, shared Rust, and TestFlight notes match both Mac filters in .github/workflows/mobile-release.yml:90-126. That workflow uploads Mac TestFlight at 1128-1144 and may publish or clobber GitHub release v1.7.0 at 1305-1353. Either explicitly include Mac 1.7.0 with its build/sign/notarization evidence and release authorization, or prevent those jobs from running for this mobile-only release.

  3. [P2] The fallback is sticky rather than fallback-only. build-device.sh:37-42 skips canonical signing whenever the global marker exists, and line 239 persists it after one local success. Future device builds then keep stripping Watch/Live Activity at 209-211 even after canonical credentials recover. Retry canonical signing on each invocation, require explicit local opt-in, or narrowly scope/expire the marker so later device acceptance cannot silently validate a reduced app.

I reviewed all 19 live changed files at head 7c60054d. These findings are in addition to the full matrix and physical-device gates already recorded.

@0xSero

0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Mobile CI was intentionally canceled while this draft has the two P1 release blockers recorded above, so the next runner slot can prove merge-blocking #221 on a clean environment. Rerun the complete release matrix only after the profile-selection and unintended Mac-release scope are resolved. The cancellation is scheduling/risk control, not a test result.

@0xSero

0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Review-blocker resolution at a443001:

  • Profile selection now requires the exact requested phone bundle identifier, iOS platform, device provisioning, development entitlement, and an installed matching signing identity. It no longer accepts extension, Watch, or Mac profiles by substring.
  • The canonical signing path is retried on every invocation. Local signing is an explicit request or a one-invocation fallback after a qualifying canonical signing failure; no marker is persisted.
  • Mobile-only merge commits can carry [skip mac-release], which leaves Android and iOS release jobs enabled while forcing both Mac external-release outputs false.

Validation on this head: Bash syntax, ShellCheck warning gate, diff whitespace, local-signing build, and an unforced canonical-signing build all pass. The canonical result is com.sigkitten.litter 1.7.0 (200000254), team TZ447KHNZL, with strict signature verification plus the Live Activity and Watch bundles preserved. The final merge commit will include [skip mac-release].

@0xSero

0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Additional current-head blocker after the Android TLS commits (head a8f5d904):

[P1] The CA-bundle repair accepts realistic truncated and invalid bundles as usable.

tls_roots::is_usable_pem_bundle only finds the first BEGIN/END marker pair and requires any non-whitespace body. The bundled file is 270,954 bytes / 136 certificates, but an interrupted-write prefix ending after certificate 1 is only 2,455 bytes and passes this predicate, leaving 135 roots missing. The new test also treats Zm9v (foo), not DER X.509, as a usable certificate. That means the repair can preserve exactly the partial file it is intended to replace and leave Android HTTPS failures unresolved.

Please:

  • for the app-managed CODEX_HOME/cacert.pem, validate against the bundled bytes/hash and replace through a temp file plus atomic rename;
  • for an externally supplied SSL_CERT_FILE, parse every PEM certificate and reject malformed content or a trailing partial block;
  • add regressions for a first-certificate-only prefix and invalid base64/DER.

Changed-file rustfmt and git diff --check pass. The prior profile-selection, sticky fallback-marker, and unintended Mac release-trigger blockers remain unchanged.

@0xSero

0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Follow-up review of a443001:

  • Fixed: profile selection now requires the exact requested phone-app bundle ID, iOS platform, a provisioned device, and an installed matching identity.
  • Fixed: the sticky global signing marker is gone; normal invocations retry canonical signing, while explicit force modes fail/opt in as expected.

Two blockers remain:

  1. [P1] Mac release suppression is implemented but not active for this PR. The workflow checks [skip mac-release] only in the pushed head commit message. The PR title/body and current last commit contain no such marker, so default merge/rebase/squash commit messages still run the Mac TestFlight/direct channels. Put the token in the actual merge commit subject and document that required merge action, or encode mobile-only scope in a deterministic release input/file rather than an operator-edited message.
  2. [P1] The Android TLS validator still accepts a one-certificate prefix or fake Zm9v body as a usable 136-certificate bundle and still rewrites the managed bundle non-atomically. The earlier exact-hash/parse-all/atomic-write remediation and regression cases remain required.

bash -n and git diff --check pass for the follow-up delta. Store publication/review submission remains outside this audit's authorization and must stay separately user-controlled.

@0xSero 0xSero left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Self-review completed at synchronized head 0b34a84 against origin/main 891c48d.

I re-reviewed the full 23-file release diff, with extra attention to Local Studio inventory timing and dedupe, Android CA repair, rendered SSH templates, iOS fallback profile selection/signing, release metadata, and mobile workflow routing. The three previously recorded findings are resolved, the merge from current main made no tree changes, and I found no additional unresolved code findings.

The release remains gated on current-head Mobile CI and Release checks. Physical iPhone install/launch and the Pi backend echo limitation remain explicitly disclosed in the PR acceptance section.

@0xSero

0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

CI follow-up at f8647bc7:

  • Current-head Mobile CI run 30906675513 compiled successfully and passed shared Rust plus Android, but exposed a timing race in two Watch snapshot XCTest cases. Both asserted after a fixed 250 ms sleep; under the CI runner the scheduled main-actor context update had not executed yet.
  • Replaced those sleeps with event-driven XCTest expectations in WatchCompanionBridgeTests.
  • Focused verification: both affected tests passed 10 iterations each (20/20).
  • Full iOS unit verification after the repair: 211/211 passed.
  • The change is test-only; production behavior is unchanged.

A clean current-head CI run is now required before merge.

@0xSero 0xSero left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final self-review at f8647bc7: no unresolved correctness, security, release-scoping, or maintainability findings.

The last CI-only XCTest race was fixed by awaiting the actual Watch context event rather than elapsed wall time. The repair passed 20/20 focused iterations and the full 211-test local suite. Current-head GitHub checks are all green: shared Rust, Android JNI/build/unit tests, iOS simulator build/XCTest, and the independent release-plan check. origin/main is an ancestor of this exact head and GitHub reports the PR CLEAN/MERGEABLE.

@0xSero

0xSero commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Final current-head verification:

No unresolved review findings remain.

@0xSero
0xSero marked this pull request as ready for review August 4, 2026 13:51
@0xSero
0xSero merged commit 4621e33 into main Aug 4, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: critical Must land in the current stabilization window

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant