Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 23 additions & 7 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,14 +1,30 @@
# Changelog

## Unreleased
## 1.1.0 — 2026-09-01

Minor release: first-class macOS, SP1 **6.5.0**, gRPC stack 0.14, and Dependabot aimed at `development`.

### Platforms

- First-class Linux + macOS: `sealed_worker` cfg-splits Linux `prctl` / macOS `PT_DENY_ATTACH`; SP1 scripts use portable mem/`PROTOC` helpers (`scripts/lib/platform.sh`)
- SP1 `sp1-execute` CI: disable PR/push/schedule; keep `workflow_dispatch` only (GH runners lack SP1 compute) — run `scripts/sp1_execute_ci.sh` locally
- Coordinated Dependabot upgrades: tonic/tonic-prost/prost 0.14, sha2 0.11, Actions checkout/upload-artifact v7; ignore bincode majors (3.0.0 is an unmaintained stub)
- Pin lean-grpc dependency to **v1.1.0** (was v1.0.0)
- Mid-tier Lean SP1 guest + `sp1_lean_mid_smoke --prove` (Init-free mix/rounds; laptop-oriented)
- Spike smoke: optional `--prove` for CPU prove+verify

### SP1 / integrity

- Coordinated SP1 **6.5.0** (`sp1-sdk` / `sp1-build` / `sp1-zkvm`); fix `ProveRequest`/`ProvingKey` imports for SP1 6.3+ builds
- Refresh ELF/vk pin in `artifacts/sp1_guest_digests.json` for the 6.5.0 guest rebuild (Linux)
- Mid-tier Lean SP1 guest + `sp1_lean_mid_smoke --prove`; spike smoke optional `--prove`
- SP1 `sp1-execute` CI: PR/push/schedule off (GH runners lack compute); `workflow_dispatch` + local `scripts/sp1_execute_ci.sh`

### Dependencies / CI

- tonic / tonic-prost / prost **0.14**; sha2 **0.11**; blake3 1.8.7; cc 1.4.4; Actions checkout/upload-artifact **v7**
- Ignore bincode majors (3.0.0 is an unmaintained compile-error stub)
- Dependabot: `target-branch: development`, group `sp1-*` and tonic/prost
- Pin lean-grpc dependency to **v1.1.0**

### Packages

- Lake **1.1.0**, host workspace **1.1.0**, Rust client **1.1.0**

## 1.0.1 — 2026-08-05

Expand Down Expand Up @@ -75,4 +91,4 @@ First stable release: Lean-measured SP1 guest, integrity-hardened Accept path, a
- Initial product spine: Lean Tee/Prove/Verify/AnchorSink, mock proofs, teeServer/teeClient
- Host compliance lib + SP1-ready prove_server
- Product docs, `lean_tee_receipt`, standalone demo, CI, clients, policy/registry, SP1 host verify path
- Profiles: `lean-tee-v1` (mock), `lean-tee-v2` (SP1)
- Lake package metadata for Reservoir
12 changes: 6 additions & 6 deletions artifacts/sp1_guest_digests.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,10 +3,10 @@
"profile": "lean-tee-v2",
"code_id_example": "lean-tee/compliance_operator/lean-sp1/v1",
"code_hash": "bec5a1b6fd790b3332da9ebdd744dbe4d58612fa9de64321298ddea05a40784f",
"elf_sha256": "cfaef020528620feed5e970d4828137f443a53328539b3a64483a84ad3ef3554",
"elf_bytes": 2128064,
"vk_hash_bytes": "49223f521ef81309217bbfb46f9820ed68a26bf52a5911801b90df8a025bd915",
"vk_bytes32": "0x0092447ea47be04c250bddfda6f9820edd144d7eaa9644600dc86fc5025bd915",
"sp1_version": "6.3.1",
"note": "Wire Measurement remains codeHash+configHash (logical code_id). elf_sha256 / vk_* pin the SP1 executable for counterparties and host verify."
"elf_sha256": "a56164482d7bf6056d5ac0cc1fe7bf9904701cc45c8e552ec284176f2caeedc3",
"elf_bytes": 2128104,
"vk_hash_bytes": "35b959ae48d96d621cfb9a833931f68e216ccc35776148274f12e1b8257787ed",
"vk_bytes32": "0x006b72b35d2365b588e7dcd41b931f68e42d9986bdd85209e78970dc257787ed",
"sp1_version": "6.5.0",
"note": "Wire Measurement remains codeHash+configHash (logical code_id). elf_sha256 / vk_* pin the SP1 executable for counterparties and host verify. Hashes from Linux sp1-execute on 2026-09-01 (SP1 6.5.0)."
}
4 changes: 2 additions & 2 deletions clients/rust/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion clients/rust/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "lean_tee_client"
version = "1.0.1"
version = "1.1.0"
edition = "2021"
license = "Apache-2.0"
description = "Thin tonic client for lean_tee.v1 Tee + Prove"
Expand Down
4 changes: 2 additions & 2 deletions docs/RELEASE_REVIEW.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ Gate checklist before flipping [RileyBetts/lean-tee](https://github.com/RileyBet
| Issue / PR templates | **Fix applied** | `.github/ISSUE_TEMPLATE/`, PR template |
| CODEOWNERS / Dependabot | **Fix applied** | Optional polish landed |
| Secret scrub | **Pass** | No private keys/tokens found; `.env` gitignored |
| `main` / `v1.0.1` | **Pass** | Default branch `main`; CI green; package versions and tag `v1.0.1` aligned. |
| `main` / `v1.1.0` | **Pass** | Default branch `main`; package versions and tag `v1.1.0` aligned; Dependabot targets `development`. |

## Gate 4 — Supply chain / licenses

Expand All @@ -51,7 +51,7 @@ Gate checklist before flipping [RileyBetts/lean-tee](https://github.com/RileyBet
| Enable vulnerability alerts / secret scanning | **Done** |
| Set visibility public | **Done** — https://github.com/RileyBetts/lean-tee |
| Fresh-clone verify | **Done** — `git clone` + `lake update` (lean-grpc v1.1.0) |
| Release note / Reservoir watch | **Done** — `v1.0.1` is latest; watch Reservoir over coming days |
| Release note / Reservoir watch | **Done** — `v1.1.0` is latest |

## Deferred (honest roadmap)

Expand Down
Loading
Loading