release: cut v0.5.10 - #1020
Merged
Merged
release: cut v0.5.10#1020
Conversation
Bump 0.5.9 -> 0.5.10 across the version surfaces RELEASE.md step 1 names (Cargo.toml [workspace.package].version, Cargo.lock workspace crate entries, npm/*/package.json version, npm/maxplayer/package.json optionalDependencies) and add the v0.5.10 RELEASE_NOTES.md section covering MakePrisms#1006. Gates: verify-release-version.sh 0.5.10 = 0 verify-release-surface.sh --no-artifacts 0.5.10 = 0 verify-release-workflow.sh .github/workflows/release.yml = 0
|
Someone is attempting to deploy a commit to the MakePrisms Team on Vercel. A member of the Team first needs to authorize it. |
web/app/test/muse-buyer-skill.test.mjs asserts every version literal in web/app/.well-known/skills/muse-buyer/ equals this tree's Cargo.toml version unless the line labels itself a field report, so the bundle is a CI-enforced version surface that RELEASE.md step 1 does not name. Precedent: 0485f99. Version literals only; no other prose changed. The Tier 2 field-report line (verification.md:44, maxplayer 0.5.7) is exempt by the test and left alone. The source-checked claims still hold at 0.5.10: MakePrisms#1006 is the only PR in this release and it touches the seller delivery path plus one internal, unadvertised __delivery-push CLI arm -- nothing in the buyer, wallet or settlement path.
jbojcic1
approved these changes
Sep 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
v0.5.10
A seller's delivery lock is now bounded by the lifetime of the push work, not by the patience of
whatever async arm started it. A caller that times out no longer hands the seat to the next delivery
while bytes from the old one are still on the wire, and a revoked push stops at the next boundary
instead of doing its local work when the slot comes free. Nothing about relay policy, token expiry
or the per-leg authorization from v0.5.9 changes.
The delivery turn is bounded by the work, not by its caller (#1006)
The seat's delivery lock was released when the future that started the push finished. Three things
followed from that. A push revoked while parked on a blocking thread still occupied the turn, and
still performed its local work once the thread woke. Queued and pre-HTTP work honoured neither
cancellation nor a deadline. And an async supervisor cancelled at an await took the lock guard with
it while its own blocking thread was still mid-upload, which let the next delivery open a second
git-receive-packagainst the same remote.The turn is now handed back only when both sides are done with it: the work has actually stopped
(or provably never started), and the supervising arm has left the excluded section. Either
condition alone has been a bug — supervisor-alone was the original defect, and work-alone is its
mirror. A caller's timeout does not free the seat for live work: it revokes, declares its own side
finished, and returns
TimedOut.New
crates/maxplayer-core/src/delivery_turn.rscarries the exclusion token itself — the lock'sowned guard, moved in, so a dying supervisor cannot take exclusion with it — plus an absolute
deadline fixed when the turn is created.
begin()is queue admission on the blocking thread, andRunningWorkis dropped on the thread that did the work.seller_gitcomposes one gate for thetransport: the delivery's authority first, the turn's lifetime second.
That gate is asked at queue admission, before the push-config rewrite, before pack generation, at
pack negotiation, before the mint so a dead delivery never joins the signer queue, again after the
mint because the queue wait is exactly where a turn dies unnoticed, on every buffered pack chunk,
and before every wire request.
The drain bound is stated as a constant rather than inferred:
DELIVERY_DRAIN_BOUND = DELIVERY_PUSH_TIMEOUT + DEFAULT_HTTP_LEG_TIMEOUT= 150s + 120s = 270s, witha build-time assertion on the sum and a test pinning the literal. It is not an HTTP timeout — it is
the work's absolute deadline, checked at every boundary above, plus the one in-flight leg whose
bytes cannot be recalled.
One span stays outside that guarantee and is documented rather than hidden: libgit2's delta search
discards its cancellation answer, so it is bounded by the delivery's object list rather than by a
clock. It is measured from its true start and an overrun is reported with the number;
UNINTERRUPTIBLE_DELTA_BUDGET = 5sis what that span is expected to fit in, held finite andstrictly inside the work deadline by a second compile-time assertion. A hard bound there needs a
killable executor — the local phase in a child process, the deadline enforced by a signal — which is
an architectural change, written down instead of smuggled in.
The tests run the real signer actor, the real transport and a real HTTPS git fixture, with no sleep
used as scheduling proof: the fixture parks a chosen request and announces it, and ordering is read
off one journal. They cover cancellation before dispatch (
.git/configbyte-identical, no mint, nodial), cancellation during the signer queue wait with the mint parked inside the round trip,
cancellation mid-flight with the advertisement held at the server, and a real GET and POST across a
caller timeout — the POST held open at the relay while the arm that started it times out, a second
real delivery launched into that window and proved pending on acquisition, landing its ref only
after the abandoned upload stops. Peak concurrency stays 1 throughout.
Gates (all exit 0 on
d1e4c110a57a15b237c9be6623fc0191127d1bca):Version bump covers the surfaces
RELEASE.mdstep 1 names:[workspace.package].versioninCargo.toml, the workspace crate entries inCargo.lock(regenerated by a cleancargo build,--locked-clean),versionin everynpm/*/package.json, and theoptionalDependenciespins innpm/maxplayer/package.json. The only remaining0.5.9strings in the tree are the deliberate"checked against source at 0.5.9" prose pins in
web/app/.well-known/skills/muse-buyer/, which arenot release surfaces, plus release-notes history.
No tag, no merge, no push to a protected branch.