• v1.1.0-rc2 8aafe65153

    Activity-Relay Directory 1.1.0-rc2
    All checks were successful
    Build / Container (push) Successful in 1m41s
    Test / Go 1.27rc2 (forward) (push) Successful in 3m22s
    Test / Go 1.26.5 (push) Successful in 3m23s
    Test / Go 1.26.0 (push) Successful in 3m31s
    Debian Package / Debian package validation (push) Successful in 5m6s
    Pre-release

    alan released this 2026-09-17 01:21:05 +00:00 | 47 commits to master since this release

    Signed by alan
    SSH key fingerprint: SHA256:yvtkLe2vkdG0Y1CCxra56JR6gjOJFURf52LUTVpWqPw

    Activity-Relay Directory 1.1.0-rc2

    Status: release-candidate source draft. Canonical artifacts, tag, publication,
    deployment, and feature activation remain separate gates.

    1.1.0-rc1 was prepared as a source candidate but was not tagged or published.
    This RC2 draft supersedes that unpublished candidate after the human-directory
    and Debian lifecycle corrections merged to master.

    Version identity

    • Git tag: v1.1.0-rc2
    • Application version: 1.1.0-rc2
    • Debian package version: 1.1.0~rc2-1
    • Stable baseline: v1.0.0
    • RC2 pre-freeze baseline merge: b181f599d0d48720dcaacd385f68a48b46c4de80
    • Prior 1.1.0-rc1 tag/publication: none

    Candidate scope

    Activity-Relay Directory 1.1 continues to add operator-controlled discovery and
    independent relay reachability without changing the authenticated version 1
    lifecycle or reinterpreting heartbeat recency. Schema version 8 records
    discovery state, actor/inbox observations, and positive RFC 9421 evidence while
    preserving private provenance and audit boundaries.

    RC2 carries the RC1 1.1 feature set and adds the following post-RC1 corrections:

    • scale the human directory into compact responsive relay rows with clearer
      heartbeat and reachability presentation while intentionally leaving detailed
      inbox/RFC 9421 evidence in the JSON projection;
    • add signed previous/next navigation to the human directory using the existing
      bounded v2 cursor format, while keeping /v2/relays itself forward-only;
    • make Debian package removal non-destructive for retained SQLite state and the
      dedicated service account, with explicit package purge as the destructive
      boundary;
    • keep operator-owned /etc/activity-relay-directory/config.yml outside the
      package conffile set and outside maintainer-script deletion; and
    • validate built maintainer scripts and package ownership boundaries under a
      Debian Trixie / debhelper >= 13.25 release-build contract.

    These changes do not introduce a new database migration, lifecycle protocol
    version, or public JSON schema version beyond the RC1 1.1 candidate.

    Compatibility and schemas

    • Database schema: 8.
    • /v1/status schema: 3.
    • /v1/relays schema: 1, frozen for 1.0 compatibility.
    • /v2/relays schema: 2.
    • Lifecycle protocol: version 1.
    • Go module floor: 1.26.0; release toolchain: 1.26.5.

    Migrations 0001 through 0007 remain byte-identical to the v1.0.0 release;
    0008_discovery_reachability.sql remains the only 1.1 migration. Existing
    retained lifecycle/audit state upgrades in place to schema 8. In-place database
    downgrade is unsupported: take and verify a standalone SQLite backup before
    upgrade, and restore the matching older backup when downgrading.

    Human directory and public contract

    /v1/relays retains the 1.0 wire and semantic contract. The v2 projection keeps
    lifecycle heartbeat, actor reachability, inbox diagnostics, and RFC 9421
    evidence independent. Discovered-only relays never receive fabricated
    registration or heartbeat timestamps. Administrative suspension overrides both
    registration and discovery eligibility.

    The human / view remains a presentation over the same bounded v2 projection.
    It now supports signed reverse traversal with before in addition to normal
    forward cursor navigation. Reverse traversal does not extend the original
    five-minute walk lifetime. /v2/relays remains forward-only and rejects the
    human-only reverse parameter.

    Discovery source/provenance, operator and reason values, private probe errors,
    audit events, database identifiers, request signatures, client addresses,
    resolver details, and internal participation flags remain non-public.

    Debian lifecycle contract

    Ordinary package removal and upgrade preserve
    /var/lib/activity-relay-directory and the dedicated
    activity-relay-directory system account so the package can be reinstalled or
    upgraded without discarding retained directory state.

    Package purge is explicitly destructive: it removes the state directory and the
    dedicated system user/group. The optional
    /etc/activity-relay-directory/config.yml is operator-owned, is not a package
    conffile, and is not deleted by the custom maintainer scripts. The package-created
    parent directory is removed only when otherwise empty. Purge under DPKG_ROOT
    is rejected rather than attempting destructive account/state cleanup against an
    alternate root.

    The release builder inspects the generated .deb, requires generated postinst,
    prerm, and postrm scripts, checks their shell syntax, proves the custom
    destructive operations occur only behind the purge guard, verifies the exact
    package conffile set, and confirms operator config.yml is absent from the
    payload.

    Default safety posture

    Fresh installations remain deliberately inert until configured. In particular:

    • lifecycle routes remain disabled by default and enrollment remains closed;
    • public directory presentation remains disabled by default;
    • background reachability remains disabled by default;
    • automatic soft pruning remains disabled by default;
    • inactive-record retention remains 0 (indefinite); and
    • administrator email remains disabled.

    Enabling the public listing does not activate lifecycle, reachability, pruning,
    retention, or any public mutation route.

    Source and release-build gates

    The accepted 1.1 source gate continues to cover exact 1.0.0/schema-7 upgrade
    identity, registered and discovered-only participation paths, candidate URL
    convergence, fail-closed resolver/network behavior, inbox method rejection, a
    real RFC 9421 signed lifecycle request persisted through SQLite, independent
    registration/discovery transitions, suspension, pruning races, and schema-8
    inactive retention.

    The RC2 pre-freeze master baseline additionally passed Forgejo container,
    Debian package, and Go test workflows after the human-directory and Debian
    lifecycle corrections were merged. Canonical package construction now runs on
    the shared forgejo-workstation execution profile, requires Debian Trixie,
    installs debhelper from Trixie backports, and fails closed below version
    13.25.

    This source-preparation commit must still pass the normal branch/PR checks before
    it becomes the exact reviewed source identity for a canonical RC2 dispatch.

    Candidate artifact and operator gates

    Forgejo is authoritative. After this candidate-preparation source state is
    reviewed and merged, the manual exact-commit workflow must build one new
    canonical 1.1.0-rc2 artifact set. The Debian package and Docker archive from
    that exact set must then be independently install-tested using separate SQLite
    state and bind ports before tagging or publication.

    Do not relabel RC1 or 1.0.0 artifacts. Tagging, release publication, deployment,
    activation of the default-off 1.1 surfaces, production verification/soak, and
    stable 1.1 promotion remain separate explicit approvals.

    Downloads