Changelog0.10.0

Decisions

Decisions in fragcap 0.10.0.

2026-09-15: S150 explicitly authorized runtime remediation extension. After retained Windows campaigns exposed hard QUIC observation queue loss, the operator authorized scoped diagnosis and correction without changing workload, queue capacity, budgets, sensitive-execution restrictions, or the two-review-round limit. Source inspection established unnecessary writer write/allocation amplification, not the exact historical platform stall. A deterministic regression initially required 373 writes for 4,096 metadata records; the finite 64 KiB buffer targets 64 writes while preserving every serialized record and the existing 64-event pending bound. Owned JSON maps move instead of being deep-cloned. Preserve original failed evidence and require two fresh fixed-code Windows campaigns before clearing release verification. This release branch updates the already assembled v0.10.0 record directly because rerunning the current assembler would create a duplicate version section; no general changelog or release-tool policy is changed.

S139 deliberately splits guided calibration issue #380 at the pure policy boundary. The stable facade owns proposal semantics now so later CLI and library workflows cannot diverge; target resolution, process enumeration, execution, persistence, and ordinary eligibility remain outside this child slice. Conflicting current exact facts conservatively require a retest instead of allowing row order to choose an answer.

S140 keeps guided execution narrower than parent issue #380: one query-only process snapshot feeds the S139 proposal, and only the first exact reachability case may reach the existing plan-bound executor. Current evidence and warm or invalid state remain effect-free by default. Every generated durable identifier remains bound to its effective local store through a PowerShell-quoted path. TLS and protocol guidance, automatic registration, multi-attempt execution, and workflow persistence remain deferred.

Automatic protocol candidates now require concrete terminal observations with matched final-client correlation, while operator candidates remain requests rather than evidence. Protocol fact derivation applies the same final-client boundary to protocol behavior, inspectability, and local-CA trust, and retains only the strongest directly observed same-session inspectability value per protocol. Post-session planning also refreshes process inventory and marks warm continuations with --restart-warm, preventing launcher traffic, unresolved correlation, stale cold-state assumptions, and expected handshake metadata from creating false target facts or unusable guidance.

  • Stored target resolution remains authoritative: resolved and ambiguous stored selectors never fall through to discovery, and --id remains stored-only.

  • Discovery accepts only an exact Steam application identifier or Unicode-aware case-insensitive display-name match. Ambiguity, partial names, executable hints, and path inference never select a target.

  • Registration uses a complete, domain-separated plan that binds the candidate, conserved discovery account and warnings, and effective store before default-no or exact structured confirmation. Fresh discovery must reproduce the plan before the existing shared registration operation runs.

  • Registration authorization is separate from any later Deep Capture session authorization. Discovery hints are not promoted into launch topology, so a newly registered target can truthfully stop at the existing missing-declaration limitation without starting a session.

  • Post-confirmation rediscovery preserves exact ambiguity diagnostics, and every downstream resolver replaces the discovery token with the recovered durable stable identifier so a numeric Steam application id cannot be reinterpreted as a listing row.

  • Treat Steam appinfo executables only as proposals: an operator must explicitly identify the socket-holding client, fresh discovery must reproduce the complete plan, and an immediate complete-row conditional update must preserve every present declaration and concurrent change. Ineligible discovery authority is reported by exact condition, executable proposals containing whitespace are conservatively refused as command-ambiguous, and every emitted plan receives a terminal outcome across target re-read, persistence, and post-update verification failures.

S144 deliberately replaces S141's process-exit boundary with finite in-process orchestration while retaining separate authorization and fresh authority per session. One reachability plus thirteen concrete protocol cases is the closed bound; decline, drift, interruption, failure, partial evidence, warm state, limitations, repetition, and bundle collision stop before later effects. Workflow persistence, resume, non-Steam topology authoring, and parent issue #380 completion remain later work.

Guided calibration progress now lives in additive local-store schema version 11 as a revision-checked checkpoint distinct from compatibility facts and recovery journals. Its bounded canonical exact-case history carries S144's no-repeat rule across process exit without treating an authorization refusal as an effectful attempt. It stores no authorization, secret, trust state, endpoint, or effect authority. A crash-shaped in-flight row first becomes an interruption pause, and every resumed attempt still requires a fresh complete plan and response.

Candidate choices are ephemeral candidate-v1 digests of complete canonical authority, never positions or authorization. Launch-case input is an assertion against current inferred topology, unsupported routing remains a refusal, and schema version 12 preserves prior workflows as inferred launch, child-environment, and IPv4.

S147 closes guided-calibration issue #380 from controlled automated evidence without changing network, trust, or artifact behavior. Real-game compatibility was not demonstrated; optional live validation is operator-owned and restricted to an already published release, while general Deep Capture completion remains issue #334.

S148 closes issue #379 without launching a target or changing network, trust, artifact, schema, dependency, or structured-output behavior. Embedded help states exact-case compatibility, certificate-pinning, and sensitive-artifact limits; runtime session failures retain their existing terminal evidence, and general Deep Capture completion remains issue #334.

Calibration error decoration is confined to the target front door inside the calibration command. Runtime terminal failures retain their existing evidence and intentionally receive no generic retry. Durable --id input remains durable in generated commands, and ambiguous stored selectors preserve every listed identifier as a finite choice instead of redirecting to discovery.

2026-09-15 (S149): The PR dependency audit discovered newly published RUSTSEC-2026-0285 in the existing Rustls 0.23.43 pin. Extend the dependency-free presentation plan only to exact-pinned Rustls 0.23.45, the upstream-patched version. Ignoring the advisory or weakening the audit is rejected. Retain ring-only provider selection, features, MSRV, and all trust/consent boundaries; refresh the threat-model review record and run the existing controlled protocol/security gates. No workflow or pinned process artifact is modified.

Synchronize the current isolated performance harness pin and performance/fuzz lockfiles with the patched product graph. Historical spike lockfiles remain historical evidence. No benchmark workload, budget, reference, approved soak evidence, or fuzz surface is changed.

2026-09-15: S150 reviewable native release preparation. The aggregate Cargo release dry run emits a Publishing banner despite disabled publication. Local preparation therefore previews and executes only the structurally version-only subcommand with explicit release.toml, then commits separately. No aggregate release execution, tag or publication is performed. Root and isolated Cargo locks change only first-party versions; fresh closed-graph digests retain the same package/edge counts (187/448 Linux, 186/424 Windows, 148/317 official release), with no third-party dependency or policy-ceiling change. The existing unsafe inventory is rebound only to the version-renamed windows-all graph, without changing source-review scope, expiry or exceptions; it is not independent #333 acceptance. Browser route coverage is compared to the complete content inventory instead of a stale fixed count, and current internal links/search destinations are checked.

2026-09-15: S150 second-round review remediation. Text-only test references could admit disabled enclosing configuration or tracked-looking specimens outside Cargo targets. Readiness now binds evidence to Git-tracked Cargo ownership and exact declared package features, builds test targets, and discovers matching tests through harness listing without executing them. The not-started candidate version follows the workspace manifest instead of another release constant. Actual feature-gated and enclosing-configuration regression checks protect zero-test refusal. Complete discovery runs in the standalone CI command, avoiding recursive relinking of a running Windows test harness. No third review round, dependency change, independent-audit approval, tag or publication is authorized by these fixes.

2026-09-15: S150 retained performance finding. Final Windows verification recorded one hard QUIC observation-queue loss window under #413. Original failed campaign identities and exact conserved loss counters remain retained; an unchanged-job diagnostic rerun does not convert the hard breach into acceptance. The existing two-fresh-campaign agreement, workload, budgets, queue bound, and retry rules remain unchanged. Candidate tagging/publication and final S150 verification remain pending disposition. Production QUIC or writer changes are not silently added to the approved documentation/readiness/version-preparation slice. Correct performance prose to distinguish oldest failure-detail eviction from refusal of a new application observation when full.

S150 prepares v0.10.0 for accumulated native workflow and presentation improvements while keeping independent security review #333 and final completion #334 open. Current documentation is aligned through parser-only examples, actual artifact readers, and a twelve-area static review handoff. An empty explicitly not-started review record does not assert zero findings or approval. Installed-build testing and Doctor #372 reproduction remain independently authorized against operator-published bytes. Release preflight found S130/S131/S132 fragments using unsupported .feature.md suffixes; they are renamed to .added.md without changing their historical contents or weakening the assembler's unknown-section refusal.

The release preparation uses release/0.10.0 instead of the normal codex prefix because release.toml permits its version-only operation only on release branches. Existing New-Release orchestration assumes clean synchronized main and directly dispatches console tools; S150 does not run that launcher or weaken its preflight. Its existing lower-level version, golden, changelog, and check operations run through the verified hidden non-interactive path with targeted staging. No tag, release publication, registry approval, workflow, runtime budget, crypto provider, or physical historical measurement is changed. Version-bound portable evidence is regenerated or rerun rather than relabeled as installed-build proof. Release documentation is updated under this dated pinned-artifact decision.

  • 2026-09-05: Replace changelog-derived GitHub release bodies with separately authored AI summaries. Require a versioned summary before tagging, reject copied text including selected or reordered changelog entries, enforce a 1,400-character and 12-non-empty-line screen budget, append explicit guidance to the complete tagged changelog, and remove every fallback that republishes changelog sections. Normalize the complete CHANGELOG.md to one source line per paragraph or list item during release assembly without editing that shared release record on feature branches.

  • 2026-09-05: Pin cargo-deny-action v2.1.1 to commit 3c6349835b2b7b196a839186cb8b78e02f7b5f25, cargo-deny to 0.20.2, cargo-cyclonedx to 0.5.9, and cargo-about to 0.9.2. Keep mutable advisory intelligence in blocking GitHub automation, keep normalized graph and exception governance offline in xtask, and preserve the existing three-download release contract by embedding evidence in ZIP and MSI rather than publishing loose files. Accept the official cargo-cyclonedx lock's yanked, non-advisory xml-rs 0.8.19 only as finite exception S130-TOOL-001 through 2026-12-04; it is a generator-only package and must leave with the first suitable upstream tool release.

  • 2026-09-05: Give the unlaunchable direct-target CLI fixture a unique nonexistent executable identity. The former generic client.exe identity collided with an unrelated running desktop application and made the refusal test depend on workstation process state; product launch behavior is unchanged.

  • 2026-09-05: Build Windows packages once and publish only the transferred bytes that passed certification. Pin cargo-wix 0.3.9, WiX 3.14.1.20250415, Npcap SDK 1.16 at SHA-256 f0a8be7778ee3ae1b99bbbecb27a3ff0f6c111a4093f1c78c5c5a099607184db, and the official v0.8.0 predecessor MSI at SHA-256 eaf2554b1da3721400c1b00f5ea0a298455f59454b0084e617ed2efcdcf83901. Preserve the documented unsigned release policy and validate it rather than adding a signing claim. Make Defender cleanup conditional on an exact installer-created ownership marker so a pre-existing administrator exclusion survives uninstall. Do not add a transform-based rollback fault injector; issue #329's required real lifecycle remains the release blocker, while failed transactions retain bounded cleanup and residue checks.

  • 2026-09-05: Deviate from T009's planned executable malformed-package fixtures. Exercise every malformed report and package-state failure class as a pure Rust contract mutation, then reserve machine-changing PowerShell execution for the genuine hosted install lifecycle. This preserves the required refusal coverage without deliberately installing corrupt or adversarial packages on the certification host.

  • 2026-09-05: Stabilize fragcap::deep_capture::api as the sole explicit version-one integration contract while preserving existing top-level exports for pre-1.0 compatibility. Keep coordinators and injected adapters serial and thread-confined instead of imposing new Send or Sync bounds; make only the cloneable cancellation token thread-safe. Observe cancellation before effects and between bounded adapter calls, then preserve exact cleanup and terminal reporting. Expose the facade-owned native adapter but exclude proxy protocol engines, leases, journals, and artifact writers from the stable inventory. Add no semantic-version dependency checker because the repository-owned compile contract and sorted reviewed inventory enforce this boundary without expanding the toolchain.

  • 2026-09-05: Deviate from S132's API-only file list after the full offline gate exposed authentication and conformance tests that depended on the workstation native certificate loader. Supply those controlled listener tests with an isolated generated root store, matching the existing protocol-lab pattern, so authentication, capability, and protocol behavior cannot fail or create an async-runtime drop panic because host certificate enumeration is temporarily unavailable. This changes no product path, dependency, or trust state.

  • 2026-09-05: Close first-round review findings by including TrafficFamily in the exact stable inventory and observing cancellation after event delivery, artifact preparation, immediately before external effects, immediately after Capture returns, during stop, and before terminal freeze. Artifact preparation is tracked as an acquired obligation so cancellation still reaches finalization, and Capture completion retains observations before the ordinary stop path runs.

  • 2026-09-05: Close second-round review findings without expanding implementation ownership. Export every target-store, classification, recovery, and trust type transitively required by the stable signatures, using StoredCompatibilityFact to distinguish persisted calibration evidence from the facade-owned runtime fact. When cancellation wins after a durable pending entry but before an effect invocation, settle that entry as NotApplied before stopping. Recheck cancellation after fact persistence, cleanup, artifact finalization, artifact reconciliation, and terminal-transition boundaries before freezing the terminal report.

2026-09-09 Reassigned S133 from final documentation issue #331 to target-discovery integrity issue #375 because the prior known-root location claim produced false platform targets. Issue #331 remains open for later work; S133 adds no dependency or store-schema change.

S134 replaces Deep Capture's generic --trust-ca and --yes authorization with a versioned canonical plan digest. The exact session CA is generated only in memory before review and is handed unchanged to the native runtime; concrete loopback listener reservation moves after authorization; plan and prompt writes, complete-line input, certificate validity, exact millisecond deadlines, and both stored and fully resolved launch-authority boundaries fail closed. Pending prior-session recovery is inspected read-only and delegated to Doctor rather than being replayed under a new plan, while complete owner-registry records are published atomically for concurrent readers. This bounded inspection deliberately supersedes the initial no-filesystem-scan assumption because recovery effects belong to the older plan. Hidden legacy flags return migration errors for one tagged release without retaining their former authority.

2026-09-09: S135 keeps Doctor's existing dynamic machine check identity but separates a short human residue label and diagnosis, so automation remains compatible while terminal columns stay stable. The shared S124 inventory and recovery planner remain the only cleanup authorities; presentation cannot create an action. Extracting the shared display-width helper also corrects U+2764 emoji presentation from one cell to two, because the prior base-plus-selector accounting could visibly misalign both CLI surfaces.

2026-09-09: S136 selects one human layout for the complete Steam title result. A four-column table is used only when every complete row fits the shared 40-through-80 display-column width; otherwise every row uses labeled vertical fields. No value is truncated. Tab, carriage return, and line feed are represented visibly in human fields so observed controls cannot become layout syntax, while JSON preserves the original values. Discovery, identity resolution, ordering, diagnostics, exits, and storage remain outside the presentation change.

2026-09-09: S137 keeps WiX responsible only for unchecked consent, explicit removal conditions, and initiating-user root transfer. One Rust command owns canonical inventory, digest binding, Doctor recovery, contained deletion, and bounded reporting. The static MSI deliberately does not offer all-users deletion because it cannot display a verified dynamic profile inventory; administrators use a separate elevated preview whose identifier must match unchanged execution. Tests operate only on synthetic AppData roots, and package certification validates MSI wiring statically rather than risking the runner account's real shell folders.

2026-09-09: Elevated all-users cleanup does not replay another user's Deep Capture recovery because the recorded Windows CurrentUser trust store belongs to that profile identity. It retains those sessions under a truthful partial result for current-user recovery in the named profile, while independently owned ordinary state may still be removed. This prevents an administrator token from being mistaken for cross-profile trust authority.

2026-09-09: The package-certification report advances from schema version 1 to 2 because S137 adds the closed fresh_start result object. The release package contract and build-identity schemas remain version 1; only the certification evidence envelope changed.

2026-09-09: Initial external review tightened the destructive boundary before merge. Every execution, including the MSI adapter, now requires the exact current inventory identifier; the adapter also proves its supplied roots equal the impersonated initiating user's canonical roots. Fresh start treats a live session-generation lease as blocking, keeps recovery progress out of JSON stdout, rechecks initially absent roots, and revalidates every ordinary ancestor immediately before lookup and deletion so a post-preview redirection cannot broaden authority.