Skip to content

chore(release): prepare v0.36.0 beta-48 - #1739

Merged
jeremi merged 9 commits into
mainfrom
release/v0.36.0
Sep 29, 2026
Merged

jeremi merged 9 commits into
mainfrom
release/v0.36.0

Conversation

@jeremi

@jeremi jeremi commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Prepare Registry Stack v0.36.0 / beta-48. This commit carries:

  • versioned manifests;
  • workspace and excluded lockfiles;
  • native client metadata;
  • generated contracts;
  • reviewed release notes and changelogs;
  • the canonical documentation archive lock;
  • renewed image advisory baselines.

v0.36.0 is the first breaking beta of the 1.0 push. It carries 19 BREAKING entries: BReg 9, Casework 7, Evidence 1, Scheduling 2. The notes give the migration step for each. Main points:

Security review notes (advisory baselines, deployment defaults, release provenance):

  • Unchanged images. The runtime bases and every image's OCI process configuration are unchanged. renew-advisory-baselines would have refused either change, and it refused nothing.

  • What the renewal moved. The subcommand moved, for all six images:

    • the application layers;
    • the executable digests;
    • the reference image digests;
    • the source revision;
    • the review dates;
    • the live pins in release/scripts/test_check_advisory_baselines.py.

    A second dry run reports no changes, the strict check passes for every image, and test_check_advisory_baselines passes.

  • The 18 exceptions are re-reviewed and kept. They cover CVE-2026-5435 and CVE-2026-19499 on libc6, and CVE-2026-85091 on zlib1g.

    • Loader, libc, libm and libpthread digests are unchanged, as are libc6 2.41-12+deb13u4 and zlib1g 1:1.3.dfsg+really1.3.1-1+b1.
    • There are no new findings: each image has 22, and the 3 High ones are covered by those exceptions.
    • expires_at stays 2026-10-06.
  • The operator tools are reviewed too. They are new in these images this release, so the rehearsal records an exposure report for each (exposure/<name>.<name>ctl.json).

    • None of bregctl, caseworkctl or schedulingctl imports or contains the resolver-printing, strfmon, libz or gzip-write symbols the rationales name. I checked both the exposure reports and the exported bytes.
    • bregctl's one review_required entry is the same Wasmtime ittapi dlsym probe as breg: it reaches the tool through registry-breg, registry-platform-script, wasmtime and ittapi.
    • caseworkctl and schedulingctl have none.
    • I did not add the tools to the assertions' files. The whole_image_fingerprint_equals assertion already binds every ordered rootfs DiffID, including the application layer that holds the tool.
    • Each BReg, Casework and Scheduling rationale now has one sentence covering its tool. Otherwise only the version, run, source and review date moved.
  • Other review_required entries are unchanged: SQLite's nonconstant extension dlsym in evidence and relay, where load_extension is denied. Casework, discovery and scheduling have none.

  • Documentation date. The documentation set is dated 2026-09-29, the intended publication date.

  • Review fixes. The upgrade steps name --runtime-config FILE on every BReg, Casework and Scheduling plan, apply, verify and status call. The Evidence migration, in the notes and the docs changelog, keeps the documented --project on source import, source diff, source update and target new. Because the changelog is archived, the v0.36.0 archive-lock entry was regenerated from the fixed tree. The upgrade order, in the notes and in upgrade-and-retire.mdx, now includes a Scheduling backup and activation step, and every BReg and Casework command in the runbook carries its required --runtime-config (and --package). A read-only review of the runbook against the code then completed it: the BReg rebuild names bregctl test and --test-receipt, Casework adds identity.databaseId, repins its BReg sources, and repoints package.root, the earlier casework and evidence processes are stopped before the new ones start, evidence check takes --runtime-config, and "Roll back" covers returning BReg, Casework, and Scheduling to the previous release, and the Scheduling changelog names the schedulingctl sibling of audit.path instead of a literal file name. A further round names BUILD/package as the package bregctl package --output BUILD writes, repoints BReg package.expectedDigest when set, has a BReg rollback restore into a fresh database and adopt its instance claim with the v0.35.0 bregctl instance-claim adopt before starting the previous breg, and adds "Retire Scheduling" to "Retire a deployment".

Validation:

  • Local:
    • registry-release validate on beta-48;
    • registry-release prepare (ready);
    • test_registry_release;
    • the monorepo release source model check and its tests;
    • test_check_advisory_baselines;
    • cargo fmt --check;
    • cargo check --locked --workspace --all-targets.
  • Rehearsals:
    • The advisory-evidence rehearsal (run 36494611865) passed.
    • The strict rehearsal on the final head (run 36512885121) is running.
    • The upgrade rehearsal runs on this pull request.

Known follow-ups, not blockers:

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T02:34:47.887989Z 301902a New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b1f0f04a62

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread release/security/breg-advisory-baseline.json Outdated
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6f0f332b72

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread release/notes/v0.36.0.md Outdated
Comment thread release/notes/v0.36.0.md Outdated
…ject in v0.36.0 notes

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f418ec67f1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread release/notes/v0.36.0.md Outdated
Comment thread products/scheduling/CHANGELOG.md
… the schedulingctl audit file

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 457b7aff33

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread release/notes/v0.36.0.md
…Scheduling to the upgrade order

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 71672a99e7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx Outdated
Comment thread docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx Outdated
Comment thread docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx Outdated
Comment thread release/notes/v0.36.0.md Outdated
…g upgrade and rollback steps

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 40caf7754e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx Outdated
Comment thread docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx Outdated
Comment thread docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx Outdated
Comment thread docs/site/src/content/docs/operate/advanced/upgrade-and-retire.mdx
…the restored claim on rollback, and retire Scheduling

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@jeremi
jeremi added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 0b9b6a7 Sep 29, 2026
66 checks passed
@jeremi
jeremi deleted the release/v0.36.0 branch September 29, 2026 03:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant