cairntir

v1.10.0 release acceptance

Status: COMPLETE — published and verified on 2026-09-06. The additive release preserves the public root exports and 21-tool MCP surface under the release policy.

Independent acceptance

Milestone Evidence Disposition
Task-aware context and isolated demo Foundation result PASS
CLI with concurrent WAL clients Concurrency result 210 PASS, zero repairs
Portable evidence Independent result 71 PASS, including 100,003 records
Evaluated procedures Independent result 161 PASS
Bulk transaction boundaries Independent result 8 PASS
Scoped sharing Original result, repair result 193 PASS after an infrastructure retry; unchanged 193 PASS after composition repair

The support change record separates historical frozen configuration from schema 7 and version 1.10.0. Original freezes, failing evidence and the explicit portable harness amendment remain unchanged. The 14 independently authored postimplementation composition probes supplement the frozen suite; they are not a new preimplementation freeze.

Release gates

Native acceptance and merged source

PR #89 merged reviewed head ddffede03d87c4fb3c67550d25223ec7a430cff0 as be9fdc408a040674d012dad60e2d0c4bd988ce05; their trees are identical. The immutable annotated tag v1.10.0 points to that merged commit.

Final native CI passed all nine jobs across Linux, macOS and Windows on Python 3.11–3.13, plus Build Package and LongMemEval R@5 Gate. Each POSIX job passed 984 tests, skipped 2 and deselected 8, with 83.31% coverage. Each Windows job passed 985, skipped 1 and deselected 8, with 83.35% coverage. POSIX skips the Windows encoding regression; every matrix job skips the release-tag test because its checkout contains no release tags. The matrix selects not slow; the unchanged 100,003-record case passed separately in independent portable acceptance. The separate model gate passed all 7 evaluations in 11.86 seconds. Sanitized native evidence records each job and its actual skips, counts and coverage.

The first CodeQL result flagged skipped base initialization in the scoped facade. Repair 1 uses composition, explicit context cleanup and two adapter typing casts. It opens no second database and changes no frozen assertions. Final CodeQL and its separate result check 101424916493 passed on the final reviewed head; no alert was suppressed or dismissed.

Publication and public-package verification

All five jobs in Release workflow 34010797495 succeeded: verification, build, Trusted Publishing to PyPI, PyPI verification and GitHub Release. Version 1.10.0 is available on GitHub and PyPI.

The tagged release test gate passed 992 tests, including slow and evaluation cases, with 84.44% coverage. It skipped the Windows encoding case on Linux and explicitly deselected the self-referential publication-tag test; the subsequent PyPI verification job passed that release-tag gate after publication.

Independent publication verification matched both distributions byte for byte across the workflow artifact, GitHub Release and PyPI. Cryptographic verification pinned the certificate, release workflow, tag, source commit and release run attempt 1.

Distribution SHA-256
cairntir-1.10.0-py3-none-any.whl 321a6275c52e09d3c7af44c0d4be878b4e176e0f3247621fb7bf653aa1f7b7e5
cairntir-1.10.0.tar.gz cc915da3afff5405cd9d4be23516327ed565a194bc6094223017663e6d41f2d5

Fresh public-package smoke passed in an isolated Windows Python 3.11.9 environment. All 72 installed package files matched the public wheel. Version, redirected help, recipes, v2 export/import/retry, abstention, recovery incompatibility and the demo passed. Actual stdio MCP exposed 21 tools and agreed with CLI handoff; its complete response used 1,851 characters under an 8,192-character ceiling. Doctor found 4 drawers and 4 vectors at dimension 512, SQLite integrity ok and no foreign-key errors. The initial sandbox denied read-only host-configuration inspection; the same package and harness passed with those reads allowed, without a runtime change. The synthetic demo measured 7,720 versus 2,899 characters, a 62.45% payload reduction, with no billing-savings claim.

Migration and local package evidence

The independent migration rehearsal preserved all 1,280 drawers and vectors, every original row across 19 tables, and the original table schemas. Schema 7 adds portable identities and procedure registries; the automatic backup matches the input snapshot. No embedding calls or source migration occurred.

The isolated candidate wheel reported 1.10.0 and exposed 21 MCP tools. CLI and actual stdio MCP handoff agreed; the complete MCP response used 1,851 characters under an 8,192-character ceiling. Abstention, recovery incompatibility, v2 export/import/retry, store integrity, redirected Windows help, recipes and the synthetic demo passed. A legacy fixture was first migrated by normal status; read-only task mode correctly refused to migrate it itself. These are candidate checks; fresh published-package results are recorded separately above.

Local gate evidence retains the full regression run, report-encoding correction and affected-file rerun, 83.37% coverage, seven offline model evaluations and quality checks. Source review records the candidate archive and credential-pattern inventories.

Operational and packaging boundaries

Production launchers still resolve to installed 1.9.0. Publication does not replace that installation or reindex the live store. The migration rehearsal used a private online backup; package checks use fresh isolated environments. No new dependency, production configuration or license change occurred.

The installed production Claude launcher connected but its health command reported tools-fetch failure. A separately configured candidate launcher remains pending Claude’s project approval. Neither is counted as a passing candidate host test; actual isolated stdio MCP tests provide automated transport evidence. Project Claude/Codex/Cursor configuration and policy checks are ready. Production host restarts remain outside scope until an installation upgrade is authorized; Qwen is unavailable on this workstation’s command path.

Hosted preflight has no production store or configured vault, so it makes no production integrity or vault-comparison claim. Plugin metadata remains in the versioned repository; wheel/sdist inventories do not claim to contain it. Synthetic payload reduction is a measured local comparison, not a commercial host, billed-token or general task-success result.