cairntir

v1.12.3 release acceptance

This patch publishes the independently investigated integration repairs from PR #111. The maintainer explicitly authorized publication, installation and the subsequent Cairntir MCP reconnect: “go ahead and publish, afterwards, reset cairntirs mcp”.

Verified starting point

Reviewed head e3b237ffbc14133bfffd44c103e370f5dbcb34ca and merge 7ee239f have identical trees. Council CI passed all nine supported OS/Python combinations, three native behavioral jobs, three built/installed CLI/MCP jobs and retrieval evaluation. CodeQL passed. The council audit retains findings, failing baselines, repairs and limitations; final CI artifacts supersede its earlier pending-run observations.

Thirty-seven frozen acceptance cases, fifteen deliberate mutation pairs and five actual historical broken/fixed pairs demonstrate detection of incorrect behavior. An independent verifier checked native artifacts and corresponding wheel hashes. Fresh local source tests passed 1,742 cases with 92.236728% combined statement-and-branch coverage. The gate is combined coverage, not 92% branches separately. Existing frozen inputs and exclusions remain intact.

Release contract

Release preparation changes package metadata, the changelog and documentation; the only runtime change from the verified merge is __version__. Dependencies, all tests, frozen manifests and CI/release workflows remain unchanged. Schema 7 and the existing MCP tools require no migration or reindex.

The candidate must pass the protected release PR’s full matrix and freshly installed wheel checks before merge. Publication uses a new immutable v1.12.3 tag and the trusted Release workflow. Public PyPI and GitHub distributions must match workflow artifacts and signed source provenance. A fresh installation from public PyPI must pass the real CLI/MCP package verifier before the configured production interpreter is upgraded.

The approved reconnect targets Cairntir MCP sessions and preserves existing store paths, grants and backup configuration. Verify loaded version 1.12.3, known exact evidence and successful task recovery after reconnect. Do not reset, replace or reindex the live store. Graphical applications are not themselves restarted as a substitute for reconnecting MCP.

Final evidence

Publication status and final machine-readable receipts are recorded with the versioned GitHub release and PyPI artifacts. These links identify the intended publication; their presence in source is not proof of completion. The release task checkpoint records the exact release PR, tag, run, public hashes, installed package identity and actual reconnect result after verification.

At most two release repair rounds are available; publication has one protected attempt. A partially published version and its tag are preserved. No product expansion, weakened assertion or coverage exclusion belongs in release preparation.