Workflow status is tracked in GitHub. This local document is retained as an engineering spec/evidence record.
RUST-FEAT-033 - First usable release rust-v0.1.0-beta.1¶
Summary¶
Ship the first usable emulebb-rust release: an unsigned Windows x64 zip built
by a GitHub Actions release workflow, tagged rust-v0.1.0-beta.1, with the
supported, permanent-drop, deferred, and beta-backlog surface documented
unambiguously. Release publication is workflow-only by operator direction
(2026-07-05). The workflow-owned packaging helper requires explicit absolute
target and archive directories outside the source workspace.
Locked Decisions¶
- Version
0.1.0-beta.1([workspace.package], own semver line decoupled from MFC0.7.x/0.8.xand from the RESTx-contract-version). - Tag scheme
rust-vX.Y.Z[-pre.N], distinct from MFCemulebb-v*. - Artifact
emulebb-rust-v<version>-windows-x64.zip+SHA256SUMS, always unsigned. - Embedded SPA WebUI proof is required for beta acceptance. TrackMuleBB is parked future controller work and is not tagged, packaged, or required for this first Rust prerelease.
- The annotated tag is created only after stock-parity, safety, REST-contract, WebUI, and soak evidence review plus an explicit operator go.
Intended Shape¶
- Scope doc
docs/RELEASE-SCOPE.md- the human-facing authority: supported surface; SX1 as the only pre-approved permanent drop; explicit deferred backlog; beta-allowed parity backlog; platform tier (Windows x64 release-supported; Linux runtime-proven unpackaged; macOS compile-only). - Version bump
0.0.3->0.1.0-beta.1+ regeneratedCargo.lock. - Release workflow
.github/workflows/release.ymlonrust-v*tags: windows runner,cargo build --release --locked -p emulebb-daemonwith default features (assert theegress-audittest feature is absent from the resolved feature set), stage exe +emulebb-rust.example.toml(fail-closed VPN defaults verified) +RELEASE-SCOPE.md+LICENSE, zip +SHA256SUMS, attach to the GitHub release. Cargo output and staged release artifacts use runner-temporary directories rather thantarget/ordist/in the source checkout. - Release documentation: version-specific changelog (compact one-line-per-item, operational focus) + source-run WebUI instructions.
Release Gate (all must hold before the tag)¶
- [ ] RUST-FEAT-005 fail-closed VPN leak gate passes in CI and candidate evidence.
- [ ] RUST-REF-004 re-audits every non-SX1 registry entry with no undispositioned P0 or stock-wire-critical findings.
- [ ] RUST-CI-003 OpenAPI conformance/drift gate passes against the Rust-forward OpenAPI artifact.
- [ ] The packaged embedded SPA WebUI is green against the candidate daemon: status, transfers, uploads, search/download, shared files, servers/Kad, settings, logs, and diagnostics.
- [ ] Stock-parity soak evidence covers UDP reask, buddy callback, firewall-check, HighID + LowID, finished-file delivery, and sustained REST responsiveness. emulebb-mfc may be a frozen witness but is not the product parity target.
- [ ]
RELEASE-SCOPE.mdmatches the re-audit dispositions and does not imply full stock parity where beta backlog remains. - [ ] Operator gives the explicit tagging go.
Current Beta Gate Status (2026-07-22)¶
This is the working gate map for turning the broad beta goal into executable
evidence. It is not release sign-off; unchecked items remain blockers for the
rust-v0.1.0-beta.1 tag.
| Gate | Current status | Evidence / next proof |
|---|---|---|
| Regular headless persisted launch | PASS for current soak profile | repos/emulebb-build-tests/scripts/start-rust-soak-profile.py --describe and the staged launch-client-here.py resolve to the regular emulebb-rust.exe with the persisted profile. The tracked --install-launchers path now refreshes launch-client-here.py from emule_test_harness.rust_profile_client_launcher and writes a disabled launch-UI-here.py stub. On 2026-07-22 the installed launcher refused a second daemon, requested ED2K/Kad startup on the running regular daemon, and reported 44085 upload-capable shared files with the hash backlog still draining. The native Slint UI is not a beta launch path. |
| Early network connection | PASS for current persisted profile | The repeatable repos/emulebb-build-tests/scripts/rust-soak-control.py early-connect-proof gate now requests normal P2P startup, polls immediately, writes a sanitized retained report, and exits nonzero unless ED2K is connected with HighID and Kad is connected before the bounded timeout. On 2026-07-22 it passed against the regular persisted daemon in 3.148 s and wrote reports/rust-early-connect-proof/rust-early-connect-proof.latest.json. |
| Shared library persistence | PARTIAL | The 2026-07-22 persisted profile recovery restored 2534 accessible shared roots from the persisted shareddir.dat, and conformance no longer clears them. The retained shared-reload-settled-proof gate now waits for stable root/item/shared-file counts with no active hashing or reload before clean restart proof. A short live run on 2026-07-22 wrote reports/rust-shared-reload-settled-proof/rust-shared-reload-settled-proof.latest.json and correctly failed while hashing was still active: 2534 roots, 2617 items, 51083 shared files, plannedHashCount=16980, hashedCount=3011, hashingCount=13969, failedHashCount=0, reload still running/pending. The release gate still needs this proof to pass and then a clean restart/reload proof with hashing already settled. |
| Public upload path | PASS for current live/profile proof; keep monitoring | The regular persisted daemon showed fresh public upload throughput after the 2026-07-22 shared-root recovery: knownUploadedBytes rose from 507176960 to 508575907 between 16:24:23Z and 16:32:29Z, upload requests/accepts rose from 2777 to 2782, and a sample showed 13.13 KiB/s while ED2K/Kad stayed connected. After the 2026-07-22 orchestrated regular rebuild/restart, a direct persisted-profile sample showed uploadSpeedKiBps=498.44 with ED2K HighID and Kad connected while republish was still maturing. Deterministic regular-exe Rust-Rust upload proof also passed at rust-local-upload/20260722T181737Z with 4 MiB completed/delivered, max active uploads 1, max upload speed 573.857 KiB/s, and delivered-path verification. After the regular-log hardening rebuild, deterministic regular-exe proof passed again at rust-local-upload/20260722T192636Z with 4 MiB completed/delivered, max active uploads 1, max upload speed 481.283 KiB/s, 60 observed upload rows, and delivered-path verification. The retained profile watcher now runs Rust-only by default, survives transient REST sample failures, and on 2026-07-22 wrote a fresh sample with ED2K HighID, Kad connected, visibility at 22.44%, and no stale parity-monitor repair recommendation. |
| Download and finished-file delivery | PASS for current live/profile proof | Fresh deterministic regular-exe Rust-Rust proof passed at rust-local-upload/20260722T164553Z: the leecher added the ED2K link paused, resumed through REST, completed 4 MiB, and verified the delivered path/bytes. A bounded public persisted-profile proof at reports/rust-public-search-download-proof.latest.json found a sanitized safe public candidate, added it paused, resumed it, and observed source acquisition. The 2026-07-22 hardened public proof now fails on source count alone and tries bounded safe candidates until byte movement or completion. After Rust network search rows were fixed to expose decoded complete-source counts, the rebuilt regular daemon passed the strict retained proof at reports/rust-public-search-download-proof/rust-public-search-download-proof.strict-complete.latest.json: the sanitized candidate had sources=2 and completeSources=2, completion was required, final completedBytes=sizeBytes=6738525, progress=1.0, state=completed, deliveredPathPresent=true, and deliveredFileExists=true. |
| Search and publish | PARTIAL | Current soak samples show ED2K visibility and Kad publish counters progressing. The retained publish-visibility-proof gate now waits for ED2K connected/HighID, mature ED2K visibility, Kad connected, Kad publish gate allowed, and observed Kad keyword/source publish totals. A short live run on 2026-07-22 wrote reports/rust-publish-visibility-proof/rust-publish-visibility-proof.latest.json and correctly failed only on ed2kVisibilityMature: ED2K was connected with HighID, Kad was connected/gate-allowed/publishing, Kad keyword/source published totals were 1603/41, but ED2K visibility was still 6.26% with 47924 pending entries. The public persisted-profile probes found safe candidates from ignored operator-local terms without retaining names, hashes, paths, or terms in tracked output; the strict complete-source proof completed with delivered-file verification. The release gate still needs publish visibility to mature and a clean restart/reload proof after hashing settles. |
| REST/OpenAPI conformance | PASS for current candidate | check-rust-rest-openapi-responses.py --rest-coverage-budget contract passed against the live persisted daemon on 2026-07-22 after the Rust OpenAPI contract and conformance harness were aligned with current response shapes. The harness now skips live-disruptive network, shared-root replacement, server mutation, Kad mutation, log clear, and search-delete routes during contract smoke. |
| Embedded SPA WebUI | PASS for current live/profile proof | Mocked WebUI unit/e2e/build gates are green after the polling reduction. On 2026-07-22 python -m emule_workspace build clients --client emulebb-rust --config Release --platform x64 --build-output-mode ErrorsOnly staged the current packaged WebUI beside the regular daemon (index-Bcfp4OWs.js). The reusable scripts/rust-webui-live-proof.py proof passed against the persisted regular daemon and wrote reports/rust-webui-live-proof/rust-webui-live-proof.latest.json: the default-tab steady window made only 6 snapshot?limit=500 API polls over 18 s, the stale secondary-endpoint polling check passed, browser diagnostics were clean, and the proof visited Overview, Transfers, Search, Sharing, Shared Files, Uploads, Network, Servers, Kad, Categories, Friends, Settings, Diagnostics, and Logs. The retained transferWorkflow check now verifies public download progress without retaining names or hashes; the current run showed 2 transfer rows, 1 active nonzero-progress row, and no empty table. The same retained proof now includes a steady browser main-thread budget: Chrome reported 0.130454 s TaskDuration over 18.004 s, a 0.0072 busy ratio against the 0.25 beta limit. |
| Regular logs and diagnostics | PASS for current candidate | The repeatable repos/emulebb-build-tests/scripts/rust-soak-control.py regular-log-proof gate writes a sanitized retained report and exits nonzero when beta diagnostic categories are missing. The regular daemon now keeps a 2000-entry REST log ring and emits a 10 s regular summary with VPN Guard HTTP public IPv4/STUN probe state, ED2K/Kad, publish, upload, download, transfer, and shared-hashing counters, without diagnostics-only binaries. After the 2026-07-22 regular rebuild/restart, early-connect-proof passed in 47.332 s and regular-log-proof passed at reports/rust-regular-log-proof/rust-regular-log-proof.latest.json: the recent regular log window contained startup, VPN Guard HTTP public IPv4, STUN, ED2K, Kad, publish, upload, and download categories; /status plus persisted metadata proved ED2K HighID, Kad connected, 589932079 uploaded bytes, 2951 upload accepts, 47142 completed known files, and 47154 transfers. |
| VPN leak gate | BLOCKER | RUST-FEAT-005 remains release-blocking: CI/socket-truth plus operator wire-truth tunnel-down proof must show zero off-tunnel eD2K/Kad traffic. |
| Stock-wire parity re-audit | BLOCKER | RUST-REF-004/RUST-CI-002 must leave no undispositioned P0 or stock-wire-critical finding before tag. |
| Packaging workflow | PARTIAL | Versioning and release-scope decisions are in place. The orchestrated Rust client build stages the regular exe and packaged WebUI together under the canonical tools path, and python -m emule_workspace package-emulebb-rust --skip-build --config Release --platform x64 --build-output-mode ErrorsOnly now creates the unsigned local candidate under %EMULEBB_WORKSPACE_OUTPUT_ROOT%\release\rust-v0.1.0-beta.1\. On 2026-07-22 the local candidate wrote emulebb-rust-v0.1.0-beta.1-windows-x64.zip, .manifest.json, .sbom.spdx.json, and SHA256SUMS; the package content gate reported 9 entries: regular emulebb-rust.exe, packaged WebUI assets, example settings, LICENSE, generated package README.md, RELEASE-SCOPE.md, and SBOM.spdx.json. The package excludes emulebb-rust-ui.exe and diagnostics binaries. The local orchestrated zip SHA256 was c0a47eda35734d6f016db35642149c135aba121d46a2942df8ca8e0f8113ad74. The repo-local rust-v* release workflow now packages from the canonical staged regular runtime, checks out the release-scope doc, uploads the zip/manifest/SBOM/SHA256SUMS assets, and prunes stale Slint UI staging artifacts. A post-commit probe from Rust commit 77a803f wrote the same 9-entry shape under %EMULEBB_WORKSPACE_OUTPUT_ROOT%\release\rust-v0.1.0-beta.1-workflow-packager-probe-20260722-current\; its zip SHA256 was 9ce12cc136308371f8b0be836d12690a7e6782c1410e9669a7862531bb256fff, manifest SHA256 2cca97ecc95948f58381e3d9c3dab00913183120ebbd808e4f8a35d105544b8b, and SBOM SHA256 79407251ecefb0c1e78fabcc7b79dab8ae71995e865d42dcf9ea4ce54fed7336. The release tag/GitHub release run still needs operator approval and final release evidence. |
Next Core Feature Focus¶
The next coding/testing priority is turning the persisted shared-library state into a clean restart/reload proof after hashing settles, while continuing public download/search monitoring on the regular daemon. Work this as small slices:
- Keep the sanitized
public-search-download-proof,publish-visibility-proof,rust-webui-live-proof, andshared-reload-settled-proofharnesses on the regular daemon path as the current download/search, publish, embedded WebUI, and shared-library gates. - Preserve the privacy boundary: operator-owned terms and public result names, hashes, and paths stay out of tracked docs, tests, and retained reports.
- Treat
sources>0without transfer bytes orsourcesTransferringas weak evidence only; fix the first reproducible Rust core or harness failure with focused tests before another live run.
Notes¶
- Release-output hygiene landed in emulebb-rust commit
0d12f91; the policy checker and packaging-helper tests guard the external-output requirement. - The INDEX scope note "emulebb-rust is out of RC2 ship scope" remains true for the MFC RC2 train; this item creates the rust client's own release gate.
- Docker/GHCR (RUST-FEAT-006) intentionally stays out of this release.