Skip to content

Latest commit

 

History

History
124 lines (92 loc) · 22.3 KB

File metadata and controls

124 lines (92 loc) · 22.3 KB

P6: Acceptance-sized platform, native library and distribution tasks

English | 简体中文 | Back to roadmap

This list preserves the existing P6 scope. Every leaf is ⏳ Planned; named directories, profiles, runners, command interfaces and reports are planned deliverables, not existing implementation or execution evidence. Each parent requires all its leaves. P6-GATE aggregates P6-01 through P6-08 and all four gate leaves. P6-08 belongs to the 1.0 exit set and depends on applicable P4/P5 gates plus P6-02 through P6-07; it must not depend back on P6-GATE. Ordinary leaves inherit prerequisites through the listed edges and do not require their own phase gate before work starts.

A parent ID means all its leaves; phase nodes such as P2-GATE mean the complete phase aggregate. Listed files/directories define edit ownership; shared release, ABI or CI interface changes must integrate serially. Scope decisions freeze API/ABI, RID/OS/toolchain and numeric thresholds before manifests and runners are implemented. Later extensions create new versions; closure cannot shrink denominators, temporarily exclude failed platforms or relax budgets.

An evidence key suite-v1#group identifies the planned tests/roadmap/suite-v1.json and named group. Manifests fix individual case IDs, input hashes, expected outcomes, positive/negative/boundary/budget classification and exact denominators. tools/RustSharp.Conformance is to gain --manifest <path> --group <group>; this future interface is not a currently executable command. Runner implementation belongs to the corresponding table unit and is dispatched by that conformance entry point. Local reports are planned at artifacts/p6/local/<suite>/<group>.json; CI uploads equivalent reports with stable run/artifact links. Reports in ignored directories need not be force-committed.

Every report records final SHA, tool/profile/ABI/dependency versions, lock hash, native host architecture and RID, command, denominator, failure reasons, timeout, maximum attempts/backoff, PID/parent PID/start time and cleanup result. Processes, polls, samples and retries are finite and cancellable; only confirmed owned resources are cleaned. Local and CI evidence are separate, and actual native execution cannot be replaced by cross-compilation, emulation or another architecture's result. Missing runners, signing services or service credentials are explicit blockers, not passes or skips. Every functional leaf requires corresponding positive, negative, boundary and budget cases.

P6-01: Three independent compatibility contracts

ID Status Deliverable / ownership Depends on Done when Evidence
P6-01.01 ⏳ Planned Freeze version axes and change classifications; own docs/adr/release-contract-versions.md. P2-GATE, P3-05 ADR distinguishes Rust# metadata, public .NET and C ABI compatibility, enumerates supported producer/consumer version pairs, and fixes finite baseline/fixture limits; no single version number implies all three are compatible. p6-api-v1#policy
P6-01.02 ⏳ Planned Metadata schema evolution; own src/RustSharp.CodeGen.IL/MetadataCompatibility.cs and tests/compatibility/metadata/. P6-01.01 Old/new producer-consumer fixtures accept documented optional additions and reject required-field removal, incompatible MIR/profile changes, corruption and oversized metadata with stable diagnostics. p6-api-v1#metadata
P6-01.03 ⏳ Planned Public .NET API baselines; own tests/compatibility/dotnet/ and eng/api/DotNetBaseline.cs. P6-01.01 Real consumers accept declared additive members and reject signature, accessibility, layout and calling-contract breaks; baseline output is deterministic and bounded by fixed member/assembly counts. p6-api-v1#dotnet
P6-01.04 ⏳ Planned C ABI baselines; own tests/compatibility/c-abi/ and eng/api/CAbiBaseline.cs. P6-01.01 Header/export/layout/calling-convention fixtures distinguish each supported ABI; compatible additions pass while removed symbols, changed offsets, widths or ownership fail before consumers execute. p6-api-v1#c-abi
P6-01.05 ⏳ Planned Reconcile independent compatibility decisions; own tests/compatibility/contracts/. P6-01.02, P6-01.03, P6-01.04 An intentionally breaking fixture for each axis fails only the appropriate baseline, valid extensions pass all affected consumers, and missing/duplicate baseline/version-pair entries cannot be ignored. p6-api-v1#reconcile

P6-02: Native libraries and C ABI ownership

ID Status Deliverable / ownership Depends on Done when Evidence
P6-02.01 ⏳ Planned Freeze exported ABI profile; own docs/profiles/native-library-v1.json. P6-01 Exact exports, scalar/layout types, calling conventions, RIDs, buffer ownership, error codes, callback/thread rules and numeric resource limits are fixed; Rust ABI and unlisted exports remain rejected. p6-native-library-v1#profile
P6-02.02 ⏳ Planned Emit native exports and headers; own src/RustSharp.CodeGen.IL/NativeExports.cs and src/RustSharp.Compiler/NativeLibraryPublisher.cs. P6-02.01 Generated header, PE/ELF/Mach-O export table and lowered parameter/return layouts agree; duplicate exports, invalid visibility/layout and unsupported signatures fail before native linking. p6-native-library-v1#exports
P6-02.03 ⏳ Planned Buffer allocation and ownership; own src/RustSharp.Runtime/Interop/ExportBuffers.cs. P6-02.02 Caller/callee allocation and release, null/empty buffers, length/capacity bounds and alignment follow one explicit contract; invalid handle, double release and integer overflow are contained without memory corruption. p6-native-library-v1#buffers
P6-02.04 ⏳ Planned Error and panic boundary; own src/RustSharp.Runtime/Interop/ExportErrors.cs. P6-02.02 Success/error payload ownership and cleanup are explicit; no managed exception unwinds across C; panic/invalid-input paths produce the frozen status or documented abort in a bounded child process. p6-native-library-v1#errors
P6-02.05 ⏳ Planned Callbacks and lifetime registration; own src/RustSharp.Runtime/Interop/ExportCallbacks.cs. P6-02.03, P6-02.04 Register/call/unregister, null callbacks, reentrancy and unregister-during-call obey the profile; delegates remain rooted exactly as required and late callbacks fail safely without leaked registrations. p6-native-library-v1#callbacks
P6-02.06 ⏳ Planned Thread and concurrency contracts; own src/RustSharp.Runtime/Interop/ExportThreads.cs. P6-02.05 Foreign-thread entry, thread-affine handles, concurrent calls and shutdown races obey frozen rules; bounded stress proves no use-after-release, deadlock or thread-local error cross-talk. p6-native-library-v1#threads
P6-02.07 ⏳ Planned Real C and C# consumers; own samples/c-abi/, tests/native-consumers/c/ and csharp/. P6-02.03, P6-02.04, P6-02.05, P6-02.06 Both consumers compile separately, load the produced native library, exchange scalars/structs/buffers/errors and invoke callbacks on each declared RID; generated-header mismatch is detected. p6-native-library-v1#consumers
P6-02.08 ⏳ Planned Leak and failed-publish recovery; own tests/native-consumers/lifecycle/. P6-02.07 Repeated load/use/unload and cancelled/failed publish stay within handle/allocation/process budgets; reports prove exactly-once cleanup and leave caller-owned files/processes intact. p6-native-library-v1#lifecycle

P6-03: Windows and Linux ARM64 runners

ID Status Deliverable / ownership Depends on Done when Evidence
P6-03.01 ⏳ Planned Freeze ARM64 native runner matrix; own docs/profiles/arm64-runners-v1.json. P0-17, P6-01 Pin native win-arm64/linux-arm64 OS, SDK, linker, ABI/native dependency versions, profile manifests and numeric build/run budgets; emulator or x64-host output cannot satisfy native evidence. p6-arm64-v1#matrix
P6-03.02 ⏳ Planned Windows ARM64 runner and artifact execution; own .github/workflows/native-win-arm64.yml. P6-03.01 Native Windows ARM64 builds Release with zero warnings/errors, verifies architecture/IL and executes all declared CoreCLR/AOT cases; wrong-architecture artifacts and missing native assets fail explicitly. p6-arm64-v1#win-arm64
P6-03.03 ⏳ Planned Linux ARM64 runner and artifact execution; own .github/workflows/native-linux-arm64.yml. P6-03.01 Native Linux ARM64 builds and executes the frozen CoreCLR/AOT corpus; ELF architecture, loader/native dependencies and libc baseline are checked, including missing-library and timeout cleanup negatives. p6-arm64-v1#linux-arm64
P6-03.04 ⏳ Planned ARM64 parity and reproducibility; own tests/platforms/arm64/ and eng/platforms/Arm64Gate.cs. P6-03.02, P6-03.03 Fixed IDs compare runtime effects, diagnostics, layout, Drop and resource limits to the declared x64 baseline; independent clean native reruns archive matching source/lock/SHA provenance with zero missing cases. p6-arm64-v1#parity

P6-04: macOS x64 and ARM64 runners

ID Status Deliverable / ownership Depends on Done when Evidence
P6-04.01 ⏳ Planned Freeze macOS native runner matrix; own docs/profiles/macos-runners-v1.json. P6-01 Pin native osx-x64/osx-arm64 OS/deployment targets, SDK/linker, ABI, native dependencies and budgets; functional test artifacts do not depend on release signing/notarization credentials. p6-macos-v1#matrix
P6-04.02 ⏳ Planned macOS x64 runner; own .github/workflows/native-osx-x64.yml. P6-04.01 Native x64 builds zero-warning Release, verifies Mach-O architecture and runs the declared CoreCLR/AOT corpus; loader-path and unsupported-deployment errors produce bounded diagnostics and cleanup. p6-macos-v1#osx-x64
P6-04.03 ⏳ Planned macOS ARM64 runner; own .github/workflows/native-osx-arm64.yml. P6-04.01 Native ARM64 executes the fixed corpus without translation; architecture/native assets, CoreCLR/AOT behavior and cancelled/failed build cleanup are evidenced independently of x64 results. p6-macos-v1#osx-arm64
P6-04.04 ⏳ Planned macOS parity and rerun evidence; own tests/platforms/macos/ and eng/platforms/MacOsGate.cs. P6-04.02, P6-04.03 Each frozen case reconciles path/IO/network/TLS/layout/Drop behavior with documented platform differences; clean native reruns retain identical denominators and no translated or cross-compiled pass substitutes. p6-macos-v1#parity

P6-05: Supply chain, AOT analysis and signed packages

ID Status Deliverable / ownership Depends on Done when Evidence
P6-05.01 ⏳ Planned Freeze dependency/signing policy; own docs/profiles/release-supply-chain-v1.json. P2-05, P6-01 Exact direct/transitive/native dependency allowlist, source identities, license policy, signing identities/algorithms, trust roots and package count/size limits are fixed; unknown inputs fail closed. p6-supply-chain-v1#policy
P6-05.02 ⏳ Planned Enforce trimming and AOT reachability analysis; own eng/release/AnalyzeAot.cs. P6-05.01 Every declared publish closure builds with zero analysis warnings and no blanket suppression; fixtures introducing dynamic code, unsupported reflection or unapproved dependency fail with attributable diagnostics. p6-supply-chain-v1#analysis
P6-05.03 ⏳ Planned Deterministic unsigned packaging; own eng/release/Package.cs. P6-05.01 Two clean builds with identical locked inputs produce identical unsigned package bytes and canonical contents; path/timestamp/order variation, duplicate assets and size-limit violations are tested. p6-supply-chain-v1#deterministic-package
P6-05.04 ⏳ Planned Signing and signature verification; own eng/release/SignPackage.cs. P6-05.02, P6-05.03 Trusted signatures bind exact package digests/profile/RID; tampering, wrong signer, expired/revoked/untrusted credentials and unavailable signing service follow frozen failure policy; secrets never enter logs. p6-supply-chain-v1#signatures
P6-05.05 ⏳ Planned SBOM and build provenance; own eng/release/Provenance.cs. P6-05.04 Signed attestations reconcile source SHA, locks, build identity, tools, native runner, all dependency hashes and output digests; missing components or mismatched claims fail independently of signature validity. p6-supply-chain-v1#provenance
P6-05.06 ⏳ Planned Consumer package verification and adversarial corpus; own src/RustSharp.Cli/PackageVerification.cs and tests/release/packages/. P6-05.05 A fresh consumer verifies valid packages offline under the frozen trust policy; malformed archives, traversal, zip expansion, unknown profiles and hash/signature/provenance mismatches fail within resource bounds. p6-supply-chain-v1#verification

P6-06: Separate workload and compiler budgets

ID Status Deliverable / ownership Depends on Done when Evidence
P6-06.01 ⏳ Planned Freeze workloads and numeric thresholds; own benchmarks/profiles/release-gates-v1.json. P2-GATE List finite workloads/RIDs/runtime modes, hardware class, warmups/repetitions, statistic/noise rules and explicit latency, throughput, memory, startup, size and compiler time/work budgets; no TBD thresholds or rustc parity claim. p6-budgets-v1#thresholds
P6-06.02 ⏳ Planned Latency and throughput measurements; own benchmarks/RustSharp.Benchmarks/LatencyThroughput.cs. P6-06.01 Frozen workloads report required percentiles and operations/time under specified concurrency; idle/overload controls and injected slowdowns validate units, bounded run duration and regression detection. p6-budgets-v1#latency-throughput
P6-06.03 ⏳ Planned Memory and allocation budgets; own benchmarks/RustSharp.Benchmarks/Memory.cs. P6-06.01 Peak/steady managed/native memory and allocation metrics use declared measurement intervals; injected retention/leak and near-limit workloads fail the correct budget without relying on eventual GC cleanup. p6-budgets-v1#memory
P6-06.04 ⏳ Planned Cold/warm startup budgets; own benchmarks/RustSharp.Benchmarks/Startup.cs. P6-06.01 Measure process-start-to-ready with frozen cache conditions for CoreCLR/AOT; missing readiness, startup failure and near-deadline fixtures produce bounded failed samples rather than disappearing from the denominator. p6-budgets-v1#startup
P6-06.05 ⏳ Planned Code and package size budgets; own benchmarks/RustSharp.Benchmarks/CodeSize.cs. P6-06.01 Measure IL/native text, total binary and distributable size using declared inclusion rules; injected generic expansion and duplicate assets exceed the appropriate threshold and reveal contributing artifacts. p6-budgets-v1#code-size
P6-06.06 ⏳ Planned Compiler time/work/resource budgets; own benchmarks/RustSharp.Benchmarks/CompilerResources.cs. P6-06.01 Frozen source families cover parsing, traits, monomorphization, MIR and emission; depth/work/output/heap/time limit-minus-one, limit and limit-plus-one cases terminate deterministically with owned cleanup. p6-budgets-v1#compiler
P6-06.07 ⏳ Planned Historical comparison and benchmark gate; own benchmarks/RustSharp.Benchmarks/BudgetGate.cs. P6-06.02, P6-06.03, P6-06.04, P6-06.05, P6-06.06 Same-hardware/profile baselines and frozen absolute budgets are both checked; incompatible hardware, missing samples, excessive noise or exceeded retry count block evidence, and historical improvements cannot mask absolute failures. p6-budgets-v1#history-gate

P6-07: Upgrade, rollback and release operations

ID Status Deliverable / ownership Depends on Done when Evidence
P6-07.01 ⏳ Planned Freeze and implement supported upgrade paths; own docs/profiles/upgrade-v1.json and tests/release/upgrade/. P6-01, P6-05 Finite from/to toolchain, package, metadata and lock-format pairs upgrade a working application; unsupported pairs fail before mutation; interrupted upgrade preserves a recoverable prior installation. p6-release-ops-v1#upgrade
P6-07.02 ⏳ Planned Rollback and migration recovery; own tests/release/rollback/ and docs/release-rollback.md. P6-07.01 Every declared reversible path restores the prior executable/configuration/lock state after failed upgrade; irreversible format/data transitions are diagnosed before execution with tested recovery instructions. p6-release-ops-v1#rollback
P6-07.03 ⏳ Planned Cache invalidation; own tests/release/cache/ and src/RustSharp.Compiler/ArtifactCacheVersioning.cs. P6-07.01 Compiler/profile/source/lock/RID/ABI changes invalidate exactly the affected cache entries; stale/tampered/concurrently written artifacts never execute, and eviction/cancellation respects byte/count limits and owned paths. p6-release-ops-v1#cache
P6-07.04 ⏳ Planned Diagnostic compatibility; own tests/release/diagnostics/. P6-07.01 Versioned golden cases retain code/severity/span/arguments across supported upgrades; intentional breaking changes have migration records, while locale/path variation and oversized messages cannot destabilize machine-readable output. p6-release-ops-v1#diagnostics
P6-07.05 ⏳ Planned Atomic release staging and promotion; own eng/release/Promote.cs. P6-07.02, P6-07.03, P6-07.04 Only verified artifacts move through the frozen staging/promote/withdraw state machine; duplicate submission, digest mismatch and interrupted promotion leave a documented retriable state without overwriting unrelated releases. p6-release-ops-v1#promotion
P6-07.06 ⏳ Planned Release operations drill and runbook; own tests/release/recovery/, docs/release-operations.md and docs/release-operations_zh.md. P6-07.05 An isolated release drill executes install/upgrade/failure/rollback/withdraw using bounded retries; bilingual commands reproduce outcomes and record cleanup, credentials boundaries and recovery ownership. p6-release-ops-v1#drill

P6-08: 1.0 release-candidate evidence

ID Status Deliverable / ownership Depends on Done when Evidence
P6-08.01 ⏳ Planned Freeze the 1.0 release inventory; own docs/profiles/release-1.0-v1.json. P4-GATE, P5-GATE, P6-02, P6-03, P6-04, P6-05, P6-06, P6-07 Enumerate every declared language/library/ecosystem/output/RID/version combination, prerequisite report and denominator; applicable P4/P5 gates are named, exclusions are frozen and no required parent scope disappears. p6-release-1.0-v1#inventory
P6-08.02 ⏳ Planned Language/ownership/Drop differential reconciliation; own tests/release/conformance/language/. P6-08.01 All release-profile compile-pass/fail/run-pass/borrow/Drop case IDs run against the pinned Rust oracle; every difference has the pre-approved profile disposition, with zero skips or unexplained differences. p6-release-1.0-v1#language
P6-08.03 ⏳ Planned Library/ecosystem/application reconciliation; own tests/release/conformance/applications/. P6-08.01 Every declared API/feature/profile cell maps to a passing executable case and representative application, including Web/database profiles; unavailable services or missing inventories block the candidate. p6-release-1.0-v1#applications
P6-08.04 ⏳ Planned Output and native platform reconciliation; own tests/release/conformance/outputs/. P6-08.01 Managed executables/libraries and declared AOT executables/C ABI libraries pass IL/metadata/PDB and real consumer gates on each declared native RID; architecture/runtime/SHA mismatches fail aggregation. p6-release-1.0-v1#outputs
P6-08.05 ⏳ Planned Independent clean candidate reproduction; own eng/release/ReproduceCandidate.cs. P6-08.02, P6-08.03, P6-08.04 A second clean native run replays pinned inputs and manifests with equal unsigned outputs/denominators and passing budgets; signed-envelope variability is checked under P6-05 rather than falsely requiring identical signatures. p6-release-1.0-v1#reproduction
P6-08.06 ⏳ Planned Signed candidate report and denial tests; own tools/RustSharp.Conformance/Release/CandidateGate.cs. P6-08.05 Signed report binds final SHA, every denominator/version/RID, all exclusions and immutable CI provenance; missing/duplicate/tampered evidence, any failure/skip or unapproved difference rejects the candidate. p6-release-1.0-v1#signed-gate

P6-GATE: Finite exit gate

ID Status Deliverable / ownership Depends on Done when Evidence
P6-GATE.01 ⏳ Planned Reconcile prerequisite and candidate evidence; own tests/roadmap/p6-exit-v1.json. P2-GATE, P4-GATE, P5-GATE, P6-01, P6-02, P6-03, P6-04, P6-05, P6-06, P6-07, P6-08 Fixed manifest references every required leaf and applicable phase gate, same-SHA release candidate, native RID evidence and explicit exclusions; no candidate leaf depends on P6-GATE. p6-exit-v1#inventory
P6-GATE.02 ⏳ Planned Verify complete native evidence and cleanup; own eng/release/Collect-P6Evidence.cs. P6-GATE.01 All declared runs pass zero-warning/error Release, zero-failure/skip conformance and resource budgets; reports prove process/service/temp ownership cleanup and never substitute cross-compilation for execution. p6-exit-v1#native-evidence
P6-GATE.03 ⏳ Planned Validate signed reproducible release bundle; own tests/release/final-bundle/. P6-GATE.02 Fresh install and verification consume exactly the candidate digests, signatures and provenance; rerun instructions reconstruct evidence, and missing artifacts, expired links or inconsistent versions block closure. p6-exit-v1#bundle
P6-GATE.04 ⏳ Planned Publish 1.0 gate record and synchronized status; own the P6 sections of paired roadmap/front-page documents. P6-GATE.03 Reviewable release record names immutable CI runs/artifacts, final remote SHA, denominators, all RID results and cleanup; P6 status changes in both languages only after every required leaf and gate passes. p6-exit-v1#publication