Skip to content

docs(release): v0.6.0 plan — 'Reach and Rigor' (breadth × depth) - #227

Open
avrabe wants to merge 1 commit into
mainfrom
docs/v0.6.0-plan
Open

docs(release): v0.6.0 plan — 'Reach and Rigor' (breadth × depth)#227
avrabe wants to merge 1 commit into
mainfrom
docs/v0.6.0-plan

Conversation

@avrabe

@avrabe avrabe commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Plans v0.6.0 along both north-star axes, grounded on measured state rather than assumption.

What the survey found

Track Requirement V Reality
T1 tri-track implemented verified V closed, status lags
T2 object-code verification proposed proposed untouched
T3 schedulability proposed proposed untouched
T4 static WCET implemented proposed V open
I-ISO keystone implemented verified V closed, status lags

Plus a machinery gap: 12 requirements whose VER-* is verified but whose own status still reads implemented/proposed — the whole verified driver suite, gpio, timer, and the syscall seam. The release-completeness gate reads them as not done. It errs safe, but it misreports, and nothing prevents recurrence.

Scope (all seven committed)

Depth — D1 close T4's WCET V · D2 object-code verification first light (T2) · D3 traceability promotion + a CI gate so the drift can't recur · D4 compositional schedulability bridge (T3).
Breadth — B1 fused gale-nano component exporting gust:os (gale#224, the real multi-consumer deliverable) · B2 a third target family through the AADL model (today: two families, one vendor) · B3 a new capability class.

The discipline

Scope is committed; claims are not. Anything that can't close honestly ships with its gap stated — never dropped silently, never inflated. Kill-criteria are retained for the two overclaimable items: T2 "first light" that is only a re-assertion of the differential test is not first light, and a fused component that leaks a scheduler/heap import is not the consumable unit (publish nothing, report the leak).

Sequenced D3 first — until the gate tells the truth, "is v0.6.0 cuttable?" isn't a question rivet can answer.

🤖 Generated with Claude Code

… scope)

Plans the next release along both north-star axes. Grounded on measured state:
T2 (object-code verification) and T3 (schedulability) are UNTOUCHED (req+V both
proposed); T4's V was never closed; and 12 requirements have a closed V but a
lagging status, so the release-completeness gate currently misreports them.

Scope committed in full: D1 close T4's V, D2 object-code first light, D3
traceability promotion + a CI gate so the drift cannot recur, D4 schedulability
bridge; B1 fused gale-nano gust:os component (gale#224), B2 a third target family
through the AADL model, B3 a new capability class. Sequenced D3 first (until the
gate tells the truth, cuttability is unanswerable) with the two research-shaped
tracks late.

Claims are not committed with the scope: any workstream that cannot close honestly
ships WITH ITS GAP STATED rather than inflated. Kill-criteria retained for the two
overclaimable items (T2 first light, the component's gust:hal-only residual).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@codecov

codecov Bot commented Jul 28, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant