1.0.0-alpha.1.toml (19376B)
1 schema_version = 1 2 3 [release] 4 version = "1.0.0-alpha.1" 5 previous_version = "0.1.0-alpha.2" 6 contract_base_version = "1.0.0" 7 status = "unreleased" 8 9 [artifacts] 10 changelog = "CHANGELOG.md" 11 manifest = "contracts/manifest.toml" 12 operations = "contracts/operations.toml" 13 replica = "contracts/replica.toml" 14 conformance = "contracts/conformance" 15 publish_policy = "contracts/releases/publish_policy.toml" 16 sqlite_runtime = "contracts/releases/sqlite_runtime.toml" 17 18 [[changes]] 19 id = "registry-sqlite-provenance" 20 classification = "fix" 21 semver_impacts = ["fix_packaging_metadata"] 22 summary = "Replace the local SQLite source patch with the checksummed crates.io bundled runtime and record its registry provenance." 23 24 [[changes]] 25 id = "standalone-release-authority" 26 classification = "fix" 27 semver_impacts = ["fix_packaging_metadata"] 28 summary = "Make the versioned capsule release contract authoritative for crate classification and publication order." 29 30 [[changes]] 31 id = "calendar-nip52-typestate" 32 classification = "breaking" 33 semver_impacts = [ 34 "remove_exported_type", 35 "remove_exported_field", 36 "remove_exported_function", 37 "change_exported_field_type", 38 "change_exported_algorithm_behavior", 39 ] 40 summary = "Replace legacy calendar authoring models with authored, parsed, and admitted NIP-52 states." 41 42 [[changes]] 43 id = "authored-blossom-media-proof" 44 classification = "breaking" 45 semver_impacts = ["remove_exported_type", "change_exported_field_type"] 46 summary = "Require byte-verified Blossom image proofs at strict profile and calendar authoring boundaries." 47 48 [[changes]] 49 id = "legacy-profile-authoring-removal" 50 classification = "breaking" 51 semver_impacts = [ 52 "remove_exported_type", 53 "remove_exported_field", 54 "remove_exported_function", 55 "remove_exported_module", 56 "remove_exported_trait_impl", 57 "remove_public_cargo_feature", 58 "change_exported_enum_variant", 59 "change_exported_algorithm_behavior", 60 ] 61 summary = "Remove direct profile draft encoding, the radroots_identity profile Cargo feature, and identity publishing paths that bypass authored validation; reject identity files containing the retired embedded profile projection." 62 63 [[changes]] 64 id = "nostr-client-boundary" 65 classification = "breaking" 66 semver_impacts = ["remove_exported_trait_impl"] 67 summary = "Remove implicit Deref access to the upstream Nostr SDK client while retaining narrow operations and an explicit ownership bridge." 68 69 [[changes]] 70 id = "replica-profile-compatibility" 71 classification = "breaking" 72 semver_impacts = [ 73 "remove_exported_field", 74 "remove_exported_function", 75 "change_exported_constant_value", 76 "change_exported_algorithm_behavior", 77 ] 78 summary = "Stop synthesizing lossy Profile events from replica projections, remove the include_profiles sync option, reject obsolete request fields, and advance the transfer contract to version 2." 79 80 [[changes]] 81 id = "replica-backup-schema-version" 82 classification = "breaking" 83 semver_impacts = [ 84 "remove_exported_constant", 85 "change_exported_algorithm_behavior", 86 ] 87 summary = "Decouple replica backup compatibility from package SemVer and retain restore support for schema-compatible 0.1.0-alpha.2 backups." 88 89 [[changes]] 90 id = "library-crate-version-authority" 91 classification = "fix" 92 semver_impacts = ["fix_packaging_metadata"] 93 summary = "Pin every library workspace crate and internal requirement to the authoritative 0.1.0-alpha Cargo cohort independently of protocol contract versions." 94 95 [[changes]] 96 id = "general-verified-event-boundary" 97 classification = "breaking" 98 semver_impacts = [ 99 "add_exported_type", 100 "add_enum_variant", 101 "add_conformance_vector", 102 "change_exported_algorithm_behavior", 103 ] 104 summary = "Expose knowledge-independent NIP-01 verification and verified Profile admission while rejecting out-of-range Nostr kinds and malformed secp256k1 author keys." 105 106 [[changes]] 107 id = "strict-kind-one-product-profiles" 108 classification = "breaking" 109 semver_impacts = [ 110 "add_exported_type", 111 "add_exported_constant", 112 "add_exported_field", 113 "add_enum_variant", 114 "add_conformance_vector", 115 "remove_exported_type", 116 "remove_exported_function", 117 "remove_exported_module", 118 "remove_exported_trait_impl", 119 "change_exported_function_signature", 120 "change_exported_enum_variant", 121 "change_exported_constant_value", 122 "change_exported_algorithm_behavior", 123 ] 124 summary = "Replace permissive kind-1 post authoring with strict Update, PhotoUpdate, and Ask states plus signature-gated tolerant product admission." 125 126 [[changes]] 127 id = "operational-listing-decoder-authority" 128 classification = "breaking" 129 semver_impacts = [ 130 "add_conformance_vector", 131 "change_exported_function_signature", 132 "change_exported_algorithm_behavior", 133 ] 134 summary = "Consolidate operational listing decoding in radroots_event_codec, return the typed operational-listing error contract, and make canonical tags authoritative over JSON content." 135 136 [[changes]] 137 id = "classified-operational-listing-taxonomy" 138 classification = "breaking" 139 semver_impacts = [ 140 "add_exported_type", 141 "add_exported_constant", 142 "add_enum_variant", 143 "add_conformance_vector", 144 "remove_exported_type", 145 "remove_exported_function", 146 "remove_exported_module", 147 "change_exported_function_signature", 148 "change_exported_enum_variant", 149 "change_exported_constant_value", 150 "change_exported_algorithm_behavior", 151 ] 152 summary = "Separate the standard NIP-99 Classified Listing kind and coordinate authority from the richer Radroots Operational Listing profile, operations, codecs, and conformance namespace." 153 154 [[changes]] 155 id = "blossom-raw-authority-validation" 156 classification = "breaking" 157 semver_impacts = [ 158 "add_conformance_vector", 159 "change_exported_algorithm_behavior", 160 ] 161 summary = "Reject raw Unicode normalization, implicit IDNA, and invalid ASCII DNS labels before constructing Blossom blob URL, approval, or byte-verification typestates." 162 163 [[changes]] 164 id = "food-availability-domain-foundation" 165 classification = "feature" 166 semver_impacts = [ 167 "add_exported_type", 168 "add_exported_constant", 169 "add_enum_variant", 170 ] 171 summary = "Add raw kind-30402 profile partitioning and validated FoodAvailability domain and media-input primitives without claiming a codec, authored draft, admission, signing, or publication boundary." 172 173 [[changes]] 174 id = "food-availability-codec-contract" 175 classification = "breaking" 176 semver_impacts = [ 177 "add_exported_type", 178 "add_exported_constant", 179 "add_enum_variant", 180 "add_conformance_vector", 181 "change_exported_constant_value", 182 "change_exported_algorithm_behavior", 183 ] 184 summary = "Add typed FoodAvailability encoding, signature-gated tolerant admission, strict signed-revision comparison, and partition-aware kind-30402 contract identification while advancing the event registry to version 4." 185 186 [[changes]] 187 id = "food-availability-publication-replica-boundary" 188 classification = "breaking" 189 semver_impacts = [ 190 "add_exported_type", 191 "add_exported_function", 192 "add_exported_field", 193 "add_enum_variant", 194 "add_conformance_vector", 195 "change_exported_function_signature", 196 "change_exported_algorithm_behavior", 197 ] 198 summary = "Reserve focused FoodAvailability signing and publication behind a sealed typed Nostr builder, require verified Operational Listing validation input, route replica kind-30402 heads before profile projection, and reject head-only kind-30402 ingestion." 199 200 [[changes]] 201 id = "strict-nip10-reply-contract" 202 classification = "breaking" 203 semver_impacts = [ 204 "add_exported_type", 205 "add_exported_function", 206 "add_enum_variant", 207 "add_conformance_vector", 208 "remove_exported_function", 209 "change_exported_function_signature", 210 "change_exported_constant_value", 211 "change_exported_algorithm_behavior", 212 ] 213 summary = "Replace permissive unmarked reply authoring with strict marked direct and nested NIP-10 Reply types, signature-gated tolerant inbound projection with supplemental citations and advisory diagnostics, typed publication, and a registry-version-5 admission-only event contract." 214 215 [[changes]] 216 id = "canonical-nip10-relay-hints" 217 classification = "breaking" 218 semver_impacts = [ 219 "add_exported_type", 220 "add_exported_function", 221 "add_conformance_vector", 222 "change_exported_function_signature", 223 "change_exported_algorithm_behavior", 224 ] 225 summary = "Replace generic URL normalization for NIP-10 relay hints with one portable canonical profile, reject noncanonical hints during strict authoring, and preserve rejected inbound hints verbatim in ordered diagnostics." 226 227 [[changes]] 228 id = "strict-nip22-comment-contract" 229 classification = "breaking" 230 semver_impacts = [ 231 "add_exported_type", 232 "add_exported_function", 233 "add_exported_constant", 234 "add_enum_variant", 235 "add_conformance_vector", 236 "remove_exported_type", 237 "remove_exported_function", 238 "remove_exported_module", 239 "remove_exported_trait_impl", 240 "change_exported_function_signature", 241 "change_exported_constant_value", 242 "change_exported_algorithm_behavior", 243 ] 244 summary = "Replace the permissive Comment model and codecs with a strict kind-1111 NIP-22 authored contract, signature-gated tolerant projection and admission, sealed publication, exact operation authority, and a fixed self-contained conformance corpus while advancing the event registry to version 6." 245 246 [[changes]] 247 id = "shared-canonical-nostr-relay-hint" 248 classification = "breaking" 249 semver_impacts = [ 250 "add_exported_type", 251 "remove_exported_type", 252 "change_exported_function_signature", 253 "change_exported_algorithm_behavior", 254 ] 255 summary = "Replace the Reply-owned RadrootsNip10RelayHint with the shared NostrRelayHint protocol primitive and migrate NIP-10 Reply and NIP-22 Comment references to that canonical byte-stable profile." 256 257 [[changes]] 258 id = "strict-nip09-deletion-request-contract" 259 classification = "breaking" 260 semver_impacts = [ 261 "add_exported_type", 262 "add_exported_function", 263 "add_exported_constant", 264 "add_enum_variant", 265 "add_conformance_vector", 266 "change_exported_constant_value", 267 "change_exported_algorithm_behavior", 268 ] 269 summary = "Add strict effect-free NIP-09 deletion-request authoring, verified tolerant projection and admission, sealed publication, exact operation authority, and a fixed self-contained conformance corpus while advancing the event registry to version 7 and reserving generic kind-5 authoring." 270 271 [[changes]] 272 id = "pure-nip09-suppression-evaluator" 273 classification = "feature" 274 semver_impacts = [ 275 "add_exported_type", 276 "add_exported_function", 277 "add_enum_variant", 278 "add_conformance_vector", 279 ] 280 summary = "Add a pure deterministic NIP-09 evaluator that returns canonical suppression decisions and evidence for same-author event and inclusive address targets while preserving immutable events, kind-5 immunity, advisory-kind irrelevance, and storage ownership boundaries." 281 282 [[changes]] 283 id = "central-verified-event-admission" 284 classification = "feature" 285 semver_impacts = [ 286 "add_exported_type", 287 "add_exported_function", 288 "add_enum_variant", 289 "add_conformance_vector", 290 ] 291 summary = "Add one signature-verified event admission operation that preserves typed product admissions, applies complete registry validation to generic contracts, and distinguishes unsupported matching, invalid shapes, Post-to-Reply routing, and kind-30402 profile exclusions." 292 293 [[changes]] 294 id = "event-store-validity-visibility-split" 295 classification = "breaking" 296 semver_impacts = [ 297 "add_exported_type", 298 "add_exported_function", 299 "add_exported_field", 300 "add_enum_variant", 301 "remove_exported_type", 302 "remove_exported_field", 303 "remove_exported_function", 304 "change_exported_field_type", 305 "change_exported_function_signature", 306 "change_exported_algorithm_behavior", 307 ] 308 summary = "Replace projection-eligible event-store APIs with signature-verified durable raw storage, typed ephemeral non-persistence, stable valid-stream eligibility, registry-independent NIP-01 heads keyed by protocol-opaque address identifiers, exact visible heads without stale fallback, and versioned monotonic cursor compare-and-swap." 309 310 [[changes]] 311 id = "nostr-fetch-admission-receipts" 312 classification = "breaking" 313 semver_impacts = [ 314 "add_exported_field", 315 "remove_exported_field", 316 "change_exported_algorithm_behavior", 317 ] 318 summary = "Replace serialized fetch-receipt verification/projection fields with admission status, stable admission code, valid-stream eligibility, and distinct invalid and ephemeral non-persistence outcomes and counts; propagate local event-store failures instead of classifying them as malformed relay events." 319 320 [[changes]] 321 id = "outbox-ephemeral-event-policy" 322 classification = "breaking" 323 semver_impacts = ["add_enum_variant", "change_exported_algorithm_behavior"] 324 summary = "Reject every NIP-16 ephemeral event from all generic durable-outbox entry points, keep transient events inside their owning live transport exchanges, and validate and configure every externally supplied SQLite pool connection before migration or writes." 325 326 [[changes]] 327 id = "shared-read-only-owner-boundaries" 328 classification = "feature" 329 semver_impacts = ["add_exported_function"] 330 summary = "Expose one Operational Listing model-semantic validator shared by unsigned authoring tools and verified event validation, plus one non-migrating event-store status inspector shared by runtime and offline consumers." 331 332 [[changes]] 333 id = "operational-listing-authoring-validation" 334 classification = "breaking" 335 semver_impacts = ["add_enum_variant", "change_exported_algorithm_behavior"] 336 summary = "Require every canonical Operational Listing edit to pass the shared model-semantic validator, reject duplicate IDs and invalid quantity or price semantics across every bin, and return the typed validation cause before draft construction, signing, or durable workflow mutation." 337 338 [[changes]] 339 id = "textual-geonames-administrative-identifiers" 340 classification = "breaking" 341 semver_impacts = [ 342 "change_exported_field_type", 343 "change_exported_algorithm_behavior", 344 ] 345 summary = "Represent GeoNames administrative subdivision identifiers as opaque strings, normalize SQLite integer and text values at query boundaries, and make locality and reverse tie ordering deterministic." 346 347 [[changes]] 348 id = "event-store-versioned-migration-authority" 349 classification = "breaking" 350 semver_impacts = [ 351 "add_exported_type", 352 "add_exported_function", 353 "add_exported_constant", 354 "add_exported_field", 355 "add_enum_variant", 356 "remove_exported_function", 357 "remove_exported_constant", 358 "change_exported_algorithm_behavior", 359 ] 360 summary = "Replace raw event-store migration SQL and unrestricted destructive rollback with a transactional, checksummed schema authority, exact legacy adoption, descriptor-owned catalog validation and deltas, tamper-evident fail-closed history, a no-write current-schema fast path, SQLite and FTS5 integrity checks, read-only schema inspection, and terminal pool-closing rollback with a governed version floor." 361 362 [[changes]] 363 id = "event-store-nip09-reconciliation-contract" 364 classification = "breaking" 365 semver_impacts = [ 366 "add_exported_type", 367 "add_exported_function", 368 "add_conformance_vector", 369 "remove_exported_field", 370 "change_exported_constant_value", 371 "change_exported_function_signature", 372 "change_exported_algorithm_behavior", 373 ] 374 summary = "Advance the event store to schema version 2 with byte-pinned registry-v7 NIP-09 reconciliation, generation-partitioned facts and addressable state transitions, generation-bound projection cursors and rebuild tickets, immutable raw authority, and an executable reconciliation result vector." 375 376 [[changes]] 377 id = "geonames-asset-download-boundary" 378 classification = "breaking" 379 semver_impacts = [ 380 "add_exported_type", 381 "add_exported_function", 382 "change_exported_field_type", 383 "change_exported_enum_variant", 384 "change_exported_algorithm_behavior", 385 ] 386 summary = "Replace dependency-specific GeoNames download errors and whole-body default installation with stable typed failure phases, cancellable DNS and bounded deadlines, and incrementally verified atomic streaming installation." 387 388 [[changes]] 389 id = "canonical-transport-target-identity" 390 classification = "breaking" 391 semver_impacts = [ 392 "add_exported_type", 393 "add_exported_function", 394 "add_exported_constant", 395 "add_enum_variant", 396 "remove_exported_field", 397 "remove_exported_function", 398 "remove_exported_trait_impl", 399 "change_exported_field_type", 400 "change_exported_function_signature", 401 "change_exported_algorithm_behavior", 402 ] 403 summary = "Seal and revalidate transport identity, remove policy-free relay deserialization, require typed nonempty fetch targets, reject forged adapter provenance, bind fetch observations to request time, bound caller-redacted diagnostics, constrain relay policies to trusted public configuration or exact loopback hosts, and require canonical reset and reseeding of unreleased-alpha state." 404 405 [[changes]] 406 id = "event-store-current-visibility-and-food-projection" 407 classification = "breaking" 408 semver_impacts = [ 409 "add_exported_type", 410 "add_exported_function", 411 "add_exported_constant", 412 "add_enum_variant", 413 "add_conformance_vector", 414 "change_exported_constant_value", 415 "change_exported_field_type", 416 "change_exported_algorithm_behavior", 417 ] 418 summary = "Advance the event store to schema version 3 with central current visibility, a generation-bound addressable transition feed, an atomic registry-v7 FoodAvailability projection and bounded search authority, typed Blossom digests, and an executable successor contract that preserves the frozen NIP-09 predecessor." 419 420 [[changes]] 421 id = "event-store-source-maintenance-authority" 422 classification = "breaking" 423 semver_impacts = [ 424 "add_exported_type", 425 "add_exported_function", 426 "add_exported_constant", 427 "add_enum_variant", 428 "add_conformance_vector", 429 "remove_exported_type", 430 "change_exported_enum_variant", 431 "change_exported_constant_value", 432 "change_exported_algorithm_behavior", 433 ] 434 summary = "Advance the event store to schema version 4 with prospective retained-source capacity enforcement across independent file pools, UTF-8 preflight before schema or journal mutation, bounded reopen recounts, rollback-protected finite generation history, coherent NIP-09 and FoodAvailability rebuild seals, typed capacity and recovery failures, and an authenticated executable SourceMaintenance successor contract that replaces exactly radroots_event_store_food_availability_image_delete_guard, radroots_event_store_food_availability_projection_delete_guard, and radroots_event_store_source_rebuild_marker_insert_guard; rejects drifted v3 upgrades atomically; restores the exact predecessor trigger SQL on rollback; and reserves future derived-state repair for an exact managed-v4 catalog, ledger, migration history, immutable raw/source lineage, and capacity without requiring derived hook health as a precondition." 435 436 [[changes]] 437 id = "transport-event-outcomes-and-replica-quarantine" 438 classification = "breaking" 439 semver_impacts = [ 440 "add_exported_type", 441 "add_exported_function", 442 "add_exported_constant", 443 "add_exported_field", 444 "add_enum_variant", 445 "remove_exported_field", 446 "remove_exported_module", 447 "remove_exported_function", 448 "change_exported_field_type", 449 "change_exported_algorithm_behavior", 450 ] 451 summary = "Represent relay-event verification, contract admission, valid-stream eligibility, and current visibility as independent exhaustive outcomes; enforce hard raw-event, aggregate raw-JSON, and pre-parse per-event fetch bounds; and remove bare-envelope legacy replica ingestion from the default public feature surface."