Skip to content

release: prepare ARSAS 1.6.40 stable - #348

Merged
masarray merged 4 commits into
mainfrom
release/1.6.40
Sep 20, 2026
Merged

masarray merged 4 commits into
mainfrom
release/1.6.40

Conversation

@masarray

Copy link
Copy Markdown
Owner

Release authority

Base is exact hotfixed main:
35060737a87657643a3279a9a2e4b4ea0beefcb9

Engine remains:
648124097621046f5f127ceb1cf853fea54db730

This main contains PR #347, which removes workflow-dependent discovery compilation and tracks the physical-proven Smart Discovery route directly in production source.

Allowed diff

Exactly four metadata files:

  • VERSION
  • Directory.Build.props
  • ArIED61850Tester.csproj
  • .release/windows.json

No discovery, engine, MMS, report, RCB, SCL, UI, installer implementation, release workflow, or build-route source changes are allowed in this PR.

Why 1.6.40

v1.6.39 is physically rejected and preserved as rejection evidence.

The corrected production contract is:

  • R7, Field Capture, normal Build, Installer, Release Windows, and local production build compile the same tracked Smart Discovery route;
  • build-time mutation based on GITHUB_WORKFLOW is forbidden;
  • release/installer fail closed if the physical-proven route is missing;
  • engine remains the accepted 648124097... revision.

Publication

Merge only after every current-head PR check is green.

Merging this metadata-only PR intentionally triggers the existing Windows release pipeline. That pipeline must verify the tracked Smart Discovery route before compiling and must complete full tests, portable smoke, installer smoke, checksums, SBOM, provenance and publication before v1.6.40 is accepted.

@masarray
masarray merged commit 1b26dc1 into main Sep 20, 2026
10 checks passed

Copy link
Copy Markdown
Owner Author

v1.6.40 release publication complete

This release is the first stable package after removing workflow-dependent discovery compilation.

Release source:

Critical release gate that did not exist for the physically rejected v1.6.39:

  • Verify physical-proven Smart Discovery route before release build: success
  • release build therefore compiled the tracked Smart Discovery route, not the legacy workflow-dependent entrypoint.

Published assets:

  • Portable SHA-256: 1c6c521a236edbc91f0e990b92fa573fffa36b06224b66c55d762e10a667e073
  • Installer SHA-256: 39e6f32f4ac653bf6529b0b6c7fd054c88ef09b064de1a56b342480428855c8e
  • SBOM SHA-256: 7c98f7e09d6786d0ef71e34ca0781d4e2f284ea27ada5d4b555ea2542b20099b
  • Provenance SHA-256: 45ecd927c06fa8837be0d714b5b04ce7ae1e4a671089635ccaf4af9d268a567b

Exact release source anchor:
release-baseline/v1.6.40-source-1b26dc12

Post-release main advances only through publication/landing evidence:

  • .release/published.json
  • landing/latest.json
  • landing/release-notes.json

No runtime source changed after the tag.

v1.6.39 remains explicitly recorded as physically rejected in evidence/v1.6.39-physical-rejection.json.

Physical relay validation of the published v1.6.40 binaries is still the final field authority. CI/package success must not be represented as physical acceptance until AA1E1F06R4 proves 58/58, 22/22 Analog, 36/36 Digital, 58/58 report-backed, cyclic polling 0 and no BIT STRING-as-Boolean rejection burst.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant