From 1e9d16db8cce1c8e0e4220efcf7cdf367c1a02f1 Mon Sep 17 00:00:00 2001 From: cjharriskc-ai Date: Tue, 4 Aug 2026 16:55:36 -0500 Subject: [PATCH] Publish recovery 4 evidence --- README.md | 6 ++++-- docs/RELEASE_EVIDENCE_0.3.1.md | 28 ++++++++++++++++++---------- docs/RELEASE_NOTES_0.3.1.md | 11 +++++++++++ docs/SHA256SUMS-0.3.1.txt | 12 ++++++------ docs/download/index.html | 8 ++++---- 5 files changed, 43 insertions(+), 22 deletions(-) diff --git a/README.md b/README.md index 10f785c..3dbbe32 100644 --- a/README.md +++ b/README.md @@ -70,7 +70,9 @@ place, return a worker to pairing, revoke a stale enrolled identity from the own the local Rampage runtime without uninstalling external model stores. A failed native status bridge now produces an actionable recovery state instead of an infinite loading surface. Nearby pairing fans out over every active LAN interface and uses local bounded lifetimes, so a VPN adapter or a -wrong device clock cannot silently strand a laptop on “Looking for your main PC.” +wrong device clock cannot silently strand a laptop on “Looking for your main PC.” Pair again now +waits for the retiring worker process tree before rotating identity, and setup mode can remove only +its bounded stale worker credentials before accepting a new encrypted invitation. | Proof surface | Validated result | | --- | --- | @@ -85,7 +87,7 @@ wrong device clock cannot silently strand a laptop on “Looking for your main P | Autonomous self-scan | Stable evidence digests cover routes, links, failures, denials, thermal/battery pressure, capability gaps, idle capacity, and protected-artifact replication | | Compute Strategy | Outcome-first Automatic, Biggest AI, Fastest AI, More Work, and Protect This PC placement previews with exact capacity and qualification blockers | | Nearby pairing | Zero-copy X25519 pairing over multicast, global broadcast, and every active directed LAN broadcast; owner-local expiry removes cross-device clock dependence | -| Lifecycle recovery | One-screen Fix Rampage, Pair again, enrolled-device Forget, redacted receipt, and typed local factory reset; restart replay keeps revoked nodes and offers gone | +| Lifecycle recovery | One-screen Fix Rampage, race-proof Pair again, setup-only stale-credential healing, enrolled-device Forget, redacted receipt, and typed local factory reset; restart replay keeps revoked nodes and offers gone | | Remote Assist | Worker opt-in; paired-owner view/control; dedicated authenticated QUIC protocol; request-, node-, controller-, epoch-, size-, frame-rate-, and input-sequence bounds; visible active state; STOP/revoke | | Packaged product | Native Tauri shell, role-aware system tray, close-to-tray, start-at-login, governed sidecars, cold-start tolerance, controller-restart recovery, clean explicit shutdown, installer, and automatic desktop launcher | | Verification | Rust, desktop, TypeScript SDK, Python intelligence, Python SDK, deterministic universal-gateway, forced-relay mesh, packaging, and lifecycle gates | diff --git a/docs/RELEASE_EVIDENCE_0.3.1.md b/docs/RELEASE_EVIDENCE_0.3.1.md index 6fe28b7..737f338 100644 --- a/docs/RELEASE_EVIDENCE_0.3.1.md +++ b/docs/RELEASE_EVIDENCE_0.3.1.md @@ -10,7 +10,7 @@ packages, public artifacts, and physical two-machine behavior are separate claim | Nine release versions | `scripts/Assert-RampageVersion.ps1 -Tag v0.3.1` | PASS — nine surfaces report 0.3.1 | | Rust workspace compile | `cargo check --workspace --all-targets` | PASS | | Controller lifecycle | `cargo test -p rampage-controller --bin rampage-controller` | PASS — 20 tests, including restart-safe node revocation | -| Native desktop recovery and pairing | `cargo test --workspace`; `cargo test -p rampage-desktop` | PASS — 22 desktop tests, including clock-independent loopback enrollment and multi-interface directed-broadcast coverage | +| Native desktop recovery and pairing | `cargo test --workspace`; `cargo test -p rampage-desktop` | PASS — 24 desktop tests, including clock-independent loopback enrollment, multi-interface directed-broadcast coverage, setup-only stale-credential healing, and active-worker credential protection | | Desktop UI and recovery | `pnpm --dir apps/desktop test -- --run` | PASS — 18 tests | | TypeScript SDK | `pnpm --dir packages/sdk-ts test -- --run` | PASS — 12 tests | | Python SDK | `uv run --project packages/sdk-python --with pytest --with httpx python -m pytest packages/sdk-python/tests -q` | PASS — 11 tests | @@ -18,7 +18,7 @@ packages, public artifacts, and physical two-machine behavior are separate claim | Desktop, edge, and TypeScript builds | `pnpm check` | PASS — desktop 18, edge 2, SDK 12 tests plus all production builds | | Proposal-only intelligence | Ruff, mypy, and pytest | PASS — Ruff clean, mypy clean across 9 files, 17 tests | | NSIS installer and desktop shortcut | `scripts/Smoke-RampageInstaller.ps1` | PASS — install 0, uninstall 0, six payloads, controller/intelligence ready, one signed node and offer, shortcut created then removed, no leaked sidecars | -| Public release assets | [`v0.3.1-recovery.3`](https://github.com/ObtuseAI/rampage/releases/tag/v0.3.1-recovery.3) | PASS — 12 assets, three source-bound manifests, three checksum files, and verified Sigstore/SLSA provenance | +| Public release assets | [`v0.3.1-recovery.4`](https://github.com/ObtuseAI/rampage/releases/tag/v0.3.1-recovery.4) | PASS — 12 assets, three source-bound manifests, three checksum files, and verified Sigstore/SLSA provenance | | Physical owner upgrade and recovery | Public candidate 2 on Windows | PASS — exact public hash, install exit 0, runtime preserved, desktop shortcut present, lifecycle consistent, non-destructive repair restart, controller ready, one resident agent, and one fresh signed offer | | Physical owner/laptop re-pair | Fresh 0.3.1 installs | PENDING physical laptop action | | Physical owner-to-laptop view | `scripts/Qualify-RampageRemoteAssist.ps1 -ExpectedVersion 0.3.1` | PENDING live opted-in worker | @@ -40,19 +40,19 @@ The source-current Recovery Center capture is ## Public candidate artifacts -The candidate-3 tag-bound GitHub Actions run `30940450467` rebuilt every package from merged commit -`41a091dd02232a92238515996fee9387f40223c8`. Every manifest reports that exact source commit and +The candidate-4 tag-bound GitHub Actions run `30952445731` rebuilt every package from merged commit +`1e230bcd2a2480007f335333fda8c099f202a008`. Every manifest reports that exact source commit and version 0.3.1. `gh attestation verify` bound all 12 subjects to the public repository, release tag, distribution workflow, GitHub-hosted runner, and merged commit. | Package | Bytes | SHA-256 | | --- | ---: | --- | -| `Rampage_0.3.1_x64-setup.exe` | 69,125,163 | `793cab7cd16e3c40d8ffe7e91e48729548c8f0b40fe124bf73c4ff0591ccf115` | -| `Rampage_0.3.1_x64_en-US.msi` | 79,003,648 | `8c1510ee0b857e7140a2f90e43120d400c4623e262124f4a6cd0ec552c54db4b` | -| `Rampage_0.3.1_amd64.AppImage` | 168,917,496 | `33bafb0c548ff8f3c538844a47b41aae72e311f0bdb274b92fd1fbcdde8b3add` | -| `Rampage_0.3.1_amd64.deb` | 98,061,312 | `b6c3f4521ad9058d092fb4c386226a73cc5b5126f0090b0a71dd92db89ef5786` | -| `Rampage_0.3.1_aarch64.dmg` | 86,264,888 | `48685fe630b23ea451dc035d46ff83c729e01c0a6855eee35c74acb6a7fdccad` | -| `Rampage.app.zip` | 84,303,262 | `8b1f0a5ea7f7c1de2ea6cb3846e3184e0a8274ec7609e8ef08308adf17d7ef77` | +| `Rampage_0.3.1_x64-setup.exe` | 69,130,089 | `f7863556c21828048f34725800db6cc3b9abac3aea449f35220f38086e6245c8` | +| `Rampage_0.3.1_x64_en-US.msi` | 79,011,840 | `63ad5083ded101ca7a262d0063eda6934ca0bdbfc7a5d89ae6c641a424a96544` | +| `Rampage_0.3.1_amd64.AppImage` | 168,909,304 | `bd55d53e5519a5ff64ed92c7d075b075634ebd918a2b81d18317452b0f41c654` | +| `Rampage_0.3.1_amd64.deb` | 98,052,650 | `c0bde5ecacbe94bb0a6dfa4054e4cf28461db6170f2fdf7e7059fe906bffa2f3` | +| `Rampage_0.3.1_aarch64.dmg` | 86,262,227 | `9122b470a9430a27a83b5228627b479546544439f8b84ef2a8bd87e22b783198` | +| `Rampage.app.zip` | 84,305,433 | `5a1909d0acd22937ecaca3234dcee10aa45efde5912a7496d2337164ae1f25b6` | Candidate Windows and macOS packages are intentionally identified as unsigned/not notarized; the workflow keeps production-signing gates reserved for a future stable channel. @@ -70,6 +70,14 @@ every active LAN address, and neither side trusts the other device's wall clock owner's local three-minute window, laptop's local five-minute window, bounded requests, rate limits, ephemeral X25519 transcript, matching four-digit code, and encrypted invitation remain intact. +Candidate 4 was required after physical discovery and four-digit approval succeeded but the laptop +reported that it was already enrolled. Pair again previously signalled the worker process to stop and +immediately reset the runtime; the retiring process could recreate its pin after reset. Rampage now +waits for the complete managed process tree to exit before identity rotation. Setup-only invitation +persistence may remove only the fixed stale worker-credential allowlist, while active owner and +worker identities remain protected. The Windows firewall readiness marker also records the current +installation directory so an upgrade cannot silently trust rules for obsolete binaries. + ## Honest boundary The Recovery Center screenshot is a browser-rendered view of the real React component using labeled diff --git a/docs/RELEASE_NOTES_0.3.1.md b/docs/RELEASE_NOTES_0.3.1.md index 84543ad..be9d846 100644 --- a/docs/RELEASE_NOTES_0.3.1.md +++ b/docs/RELEASE_NOTES_0.3.1.md @@ -13,11 +13,20 @@ LAN interface instead of trusting Windows to choose one path for global broadcas lifetimes are bounded independently on each device instead of requiring synchronized wall clocks. The normal flow remains one **Find my fabric** action on the laptop and **Add machine** on the owner. +Candidate 4 closes a worker-lifecycle race found during the physical re-pair. Pair again now waits +for every managed sidecar process to exit before rotating the runtime. While the authoritative setup +marker is present, accepting a new invitation can remove only a fixed allowlist of stale worker +credentials left by an older retiring process; active owner and worker identities are never +self-deleted. The Windows firewall marker is also bound to the current installation directory, so +an upgrade cannot silently retain private-network rules for obsolete binaries. + ## What changed - **Fix Rampage** safely restarts a consistent native installation without erasing identity or work. - **Pair again** stops the worker sidecars, removes its old fabric runtime, and returns the device to the two-button nearby-pairing screen. +- Sidecar shutdown has a bounded exit barrier, and setup-only invitation persistence clears a fixed + stale-worker allowlist so an older process cannot trap the next attempt in “already enrolled.” - Owner **Forget** revokes one exact enrolled identity and removes its offer, outstanding assignments, reservations, shard sets, Remote Assist sessions, artifact locations, and possession evidence. - Revocation is appended to the hash-chained ledger and replayed after controller restart, so a stale @@ -31,6 +40,8 @@ The normal flow remains one **Find my fabric** action on the laptop and **Add ma while excluding loopback, link-local, and point-to-point tunnel interfaces. - The owner derives request expiry from its own open window and the laptop displays its own bounded countdown. Remote clocks cannot extend the window or silently prevent discovery. +- Private-network firewall readiness records the exact installation directory and regenerates the + three scoped Windows rules when that directory changes. ## Simpler compute outcomes diff --git a/docs/SHA256SUMS-0.3.1.txt b/docs/SHA256SUMS-0.3.1.txt index 2b56282..284b842 100644 --- a/docs/SHA256SUMS-0.3.1.txt +++ b/docs/SHA256SUMS-0.3.1.txt @@ -1,7 +1,7 @@ -793cab7cd16e3c40d8ffe7e91e48729548c8f0b40fe124bf73c4ff0591ccf115 Rampage_0.3.1_x64-setup.exe -8c1510ee0b857e7140a2f90e43120d400c4623e262124f4a6cd0ec552c54db4b Rampage_0.3.1_x64_en-US.msi -33bafb0c548ff8f3c538844a47b41aae72e311f0bdb274b92fd1fbcdde8b3add Rampage_0.3.1_amd64.AppImage -b6c3f4521ad9058d092fb4c386226a73cc5b5126f0090b0a71dd92db89ef5786 Rampage_0.3.1_amd64.deb -48685fe630b23ea451dc035d46ff83c729e01c0a6855eee35c74acb6a7fdccad Rampage_0.3.1_aarch64.dmg -8b1f0a5ea7f7c1de2ea6cb3846e3184e0a8274ec7609e8ef08308adf17d7ef77 Rampage.app.zip +f7863556c21828048f34725800db6cc3b9abac3aea449f35220f38086e6245c8 Rampage_0.3.1_x64-setup.exe +63ad5083ded101ca7a262d0063eda6934ca0bdbfc7a5d89ae6c641a424a96544 Rampage_0.3.1_x64_en-US.msi +bd55d53e5519a5ff64ed92c7d075b075634ebd918a2b81d18317452b0f41c654 Rampage_0.3.1_amd64.AppImage +c0bde5ecacbe94bb0a6dfa4054e4cf28461db6170f2fdf7e7059fe906bffa2f3 Rampage_0.3.1_amd64.deb +9122b470a9430a27a83b5228627b479546544439f8b84ef2a8bd87e22b783198 Rampage_0.3.1_aarch64.dmg +5a1909d0acd22937ecaca3234dcee10aa45efde5912a7496d2337164ae1f25b6 Rampage.app.zip f5503739ce0f1a069ea067a9bb807639d541872f7f6487a12efcb46fa414366d rampage-recovery-center.png diff --git a/docs/download/index.html b/docs/download/index.html index 6e67012..49a9f5f 100644 --- a/docs/download/index.html +++ b/docs/download/index.html @@ -3,16 +3,16 @@ - - + + Download Rampage for Windows

Rampage for Windows

Your download should begin automatically.

-

Download Rampage 0.3.1 for Windows x64

-

Release notes and SHA-256

+

Download Rampage 0.3.1 for Windows x64

+

Release notes and SHA-256