cairntir

v1.12.1 release acceptance

Status: COMPLETE — published, installed and verified on 2026-09-07. Issue #103 tracks delivery.

Scope and failed candidate

This release delivers the automatic backups from PR #102, with a correction for the worker-ownership race exposed by the withheld 1.12.0 candidate. A helper left behind by a killed coordinator must never delete another active helper’s unfinished snapshot. Each helper holds a native operating-system claim through staging and publication; cleanup skips claims still held by live workers.

The failed v1.12.0 tag remains at 73cc042; no 1.12.0 package reached PyPI. Its failed verification and all frozen artifacts remain available. No release guard exception, moved tag or weakened acceptance is used for this correction. The necessary patch version was stated to the user under the existing approval to publish and install the backup capability.

The configured policy checks every 12 hours at writable owner startup or the next outer write. Snapshots retain the complete database, vectors, provenance and task history. Retention keeps seven recent days and four older weekly points; manual recovery copies remain unmanaged. Failures warn while memory writes continue. Schema 7, all 21 MCP tools, existing dependencies and model files remain unchanged. No migration, reindex, background scheduler or other feature is included.

Independent acceptance

The original 29 backup cases, 39 mandatory store regressions and three supporting failure cases remain frozen. The new ownership supplement reproduced the race using real processes and scheduling barriers before repair; snapshot and cleanup operations were not mocked.

The 1.12.1 release generation binds the other 57 Python source files, exact version-only module change, unchanged dependencies, historical frozen artifacts and all 74 package files. The repaired backup module requires an independent passing behavioral receipt with stable before/after hashes. Candidate, publication, installation and activation are separate gates; unexecuted checks remain pending.

Official repair round 1 passed all 72 cases in 76.22 seconds. All 59 source files and 25 frozen inputs matched their before/after hashes. The repaired module is bound by SHA-256 e5d2412f64559d7295e37013084761ee39b6a6beae6a2df36e24abd9b52fc273. The new source verifier also passed, including the required independent repair receipt, unchanged dependencies and historical acceptance artifacts.

The full local suite passed 1,151 tests in 333.56 seconds, including all slow acceptance and model evaluations, with 83.17% coverage. Static checks, 165 executable commitments, 12 seams, strict documentation and locked dependency advisories passed. Independent candidate smoke verified all 74 wheel files, 13 CLI commands, all 21 MCP object schemas, owner startup backups and a real overdue outer-write backup preserving the prior committed state.

The accepted candidate wheel SHA-256 is 9b92b6a03353e66ca25526b665d6dfde9a020ddea39b2eed865f4860ea403307. These candidate results remain historical evidence; completed public distribution and production installation are recorded below.

Release gates

Publication

PR #105 passed all 14 checks, including Linux, macOS and Windows on Python 3.11–3.13. Reviewed head 8e966c2cbd100e83677445a677391f4f6ab290c4 and protected merge 5584ff7be4494d72d0776b3c2948d9b227cdfe26 have the identical tree 95b747e64c40ad8974d3cb57fa31eee84c0e977d. New annotated tag v1.12.1 identifies that merge; its tag object is 532910815354c176b3eaf97532a02d9ef210d6e5.

All five jobs in Release workflow 34155498484 passed on attempt 1. Tagged tests passed 1,149 cases in 275.33 seconds with 83.11% coverage. Linux skipped one Windows-only encoding case and deselected the self-referential publication check; the subsequent PyPI verification job passed that check. The withheld 1.12.0 tag remains unchanged.

Version 1.12.1 is available on PyPI and GitHub. Independent verification matched both distributions across workflow artifacts, GitHub Release and PyPI, with signed provenance pinned to the exact source, release workflow, tag, hosted runner and run attempt.

Distribution SHA-256
cairntir-1.12.1-py3-none-any.whl 6ac9d4bcec90144b986e5bd826d2f4a2bd6f1d6a215b8acacf2cc2e040072314
cairntir-1.12.1.tar.gz 6cbbb37f8a090d0285d0846d9238c2154d9a8573ead058055a859596f1e80f9a

All 79 wheel member payloads equal the tested candidate. Only ZIP creator-platform metadata differs between the Windows candidate and Linux build. A fresh isolated PyPI installation passed dependency checks, matched all 74 package files, and passed real CLI/MCP startup and overdue-write backups, standalone snapshot fidelity, all 21 schemas, exact Unicode cross-host checkpoint/resume, typed invalid input and CLI/MCP parity while the server held the store. No model prompts ran.

Production installation and activation

The authorized package-only upgrade installed the independently verified public wheel, changing 1.11.0 to 1.12.1 without dependency updates. Only the 20 verified Cairntir backend processes holding the global executables were stopped. User applications and the Codex app server remained open.

Under a memory-write hold, independent before/after audits matched every row, column and schema object in all 22 tables: 1,433 drawers, vectors and portable records, plus task history and provenance. Schema remains 7. Every model-cache file, non-Cairntir distribution version, six runtime requirements, five host entries, backup configuration and existing recovery file remained unchanged. All 74 installed package files match the public wheel. No migration or reindex ran.

A fresh installed MCP executable reported 1.12.1 and all 21 object-root schemas. An observer delegated the actual owner startup backup.run(force=False) call: the saved 12-hour policy was enabled and correctly returned not_due, with no clock or configuration manipulation. The installed CLI then created a new 14,974,976-byte managed snapshot. Independent immutable inspection passed integrity and foreign-key checks and matched all 22 tables against both the live source and pre-install baseline. Every earlier manual and managed backup remained intact.

The fresh snapshot SHA-256 is 06fd2e06e4b05d40af9a77ea8ca1cfb5d1ee458c5a824f2beef18ec3c2245bd7. Its successful timestamp is 2026-09-07T19:41:16.393385Z; the next due time is 2026-09-08T07:41:16.393385Z, checked on the next writable startup or outer write. Private destination paths and store contents remain outside public evidence.

After all preservation and activation checks passed, the write hold was released. Subsequent release checkpoints are intentional new memories. Production doctor passed at 1,434 drawers; vault drift was explicitly skipped because no vault is configured. Actual Claude MCP health reports Connected, and project Claude, Codex, Cursor and Qwen configuration is ready. Existing app sessions require an MCP reconnect: the old transport closed, and fresh probes do not establish reload. The same checkpoint was successfully saved through a fresh 1.12.1 connection.

The sanitized publication receipt binds independent public, installation, preservation, activation and host-health evidence without rewriting frozen candidate results.

Finalization

Completed on the first product repair round after the failed protected candidate. At most two repair rounds are allowed, with at least 25% of work reserved for verification. Final disposition is COMPLETE, BLOCKED or EXHAUSTED. Original failures and acceptance generations are retained; no test is weakened to obtain a passing release.