Skip to content

0.2.0 promotion gate

The native Linux implementation is promoted to 0.2.0 only after every required runtime, package, session, accessibility, soak, and protected-provider claim has explicit evidence. A missing or unavailable check remains a blocker; it is not converted into a positive compatibility statement.

  • docs/reviews/0.2.0-promotion-matrix.yml — machine-readable state of every gate.
  • docs/releases/0.2.0.yml — candidate scope, required commands, and publish boundary.
  • scripts/validate-020-readiness.py — summary, pre-tag, and post-tag publication validator.
Terminal window
make release-020-readiness
make test
make desktop-test
make linux-ci
make desktop-session-audit
make desktop-sleep-monitor-smoke
PROPERPCLOUD_SOAK_SECONDS=120 make desktop-resilience-soak
make arch-package-gate
make docs-build

desktop-session-audit uses a disposable random Secret Service record, externally invokes all supported MPRIS controls, and verifies the packaged logind sleep-signal subscription. desktop-locked-keyring-smoke uses a separate ephemeral keyring and never touches the real user collection. desktop-accessibility-audit retains 200% high-contrast base/help captures at 1280×820. Evidence contains neither credential material nor the user D-Bus address. arch-package-gate builds only an immutable release-tag archive and records the installed package digest. The credential-free soak can run between ten seconds and four hours, but it cannot substitute for a protected-provider capability-expiry run.

Before the tag is allowed, record:

  1. EU and US pCloud browse, playback, capability expiry, disconnect, cleanup, and restart;
  2. one four-hour provider run with genuine link expiry and a controlled suspend/resume;
  3. one physical media-key observation and one real suspend/resume cycle;
  4. GNOME and KDE Plasma session checks beyond the current i3 session;
  5. a real AT-SPI screen-reader traversal/action review.

The documented regional direct-sign-in fallback remains the selected boundary while pCloud desktop redirect registration is unconfirmed; the release does not claim browser OAuth.

Evidence must never contain passwords, tokens, signed URLs, provider response bodies, private media, or the session bus address.

Before creating the signed tag:

Terminal window
python3 scripts/validate-020-readiness.py --pre-tag

This permits only a gate explicitly marked pending_post_tag. After the tag exists and the exact tag archive has passed the Arch rebuild, use the publication gate:

Terminal window
python3 scripts/validate-020-readiness.py --strict

A nonzero result blocks the corresponding transition. The maintainer may accept a narrow exception only by changing its matrix status to an explicit accepted_* state and documenting the scope; silently deleting or relaxing a gate is not permitted.