Status: WITHHELD — tagged verification failed before publication on 2026-09-07. Issue #103 tracks delivery. The corrected capability continues as 1.12.1. This record preserves the failed candidate; no 1.12.0 package was published or installed.
This candidate was intended to publish the automatic backups from
PR #102, merged at e27fe04
with all 14 checks passing. Configured owner stores check their default 12-hour
interval at writable startup and before an outer write. Complete, verified
SQLite snapshots retain vectors, provenance and task history. Managed retention
keeps seven recent days and four older weekly recovery points. Ordinary writes
continue with typed warnings if a backup fails.
Current-schema store opens also stop rewriting the schema-version header. The release retains schema 7, 21 MCP tools and existing dependencies. Release preparation changes metadata and documentation; the accepted runtime stays unchanged except for its version string. No reindex, migration, background scheduler or production data repair is required.
The frozen release contract separates candidate, publication and installation evidence. Historical backup acceptance remains immutable: 29 new cases and 39 mandatory store regressions passed on official round 0 with no repairs. Three independent failure cases also passed. Feature validation passed 1,142 regression cases and seven model evaluations; the release below records its own fresh verification.
Automated acceptance:
scripts/check_release_tags.py)The full local suite passed 1,150 tests, with no skips or deselections, at 83.47% coverage, including all slow acceptance and seven model evaluations. Ruff lint/format, strict types, exceptions, 164 commitments, 12 seams, docs links, strict MkDocs, release tags and all 134 locked dependency advisory checks passed. The production doctor gate passed at 1,419 drawers; vault drift was explicitly skipped because no vault is configured.
Independent candidate evidence verifies aligned metadata, unchanged runtime/dependencies/frozen artifacts and all 74 wheel/sdist package files. A separate installed-wheel probe passed 13 CLI commands, redirected Windows help, bundled recipes, all 21 MCP object schemas, owner CLI/MCP startup backups and a real overdue 12-hour outer write whose snapshot exactly matched the prior committed tables and vectors. It loaded no model and made no production changes. Independent diff review found no blocking defect, credential or local-data artifact. All 12 workflow action references use immutable commit SHAs.
Operational acceptance:
cairntir-mcp --host claudeMigration and live reindex are not applicable: schema and embeddings are unchanged, and the completed production audit found no repair necessary.
Release operations:
PR #104 passed all 14 checks.
Accepted head e5d4f6ee56ae7382ce913a0bc70d37011772aba0 and protected merge
73cc04249010411fa3d2cb198d6c20d6654c68d0 have identical trees. The annotated
v1.12.0 tag remains on that merge and will not be moved or reused.
Release run 34152318223 failed the original frozen crash-replacement acceptance case: a helper surviving its coordinator could remove another active helper’s staging directory. Results: one failed, 1,147 passed, one Windows-only skip, one self-referential publication test deselected, 83.40% coverage. Build, attestation, PyPI publication and GitHub Release jobs were all skipped. The passing candidate checks above remain historical evidence and do not override this failure.
The failure was reproduced deterministically before the corrective runtime change. A new independently frozen ownership test and release generation govern 1.12.1; all original frozen artifacts remain unchanged. Production stays 1.11.0 until that corrected public package is verified and installed. Its saved policy and verified recovery snapshot remain intact.
Budget: one release preparation pass, at most two repair rounds, with at least 25% reserved for verification. Final disposition is COMPLETE, BLOCKED or EXHAUSTED. A failed protected publication attempt retains its evidence and follows the documented recovery policy; published tags are never moved.