Current Release Milestone — Operator-ready Path
This is the compact execution view from OptiFlow's shipped read-only product to
safe external-drive space reclamation.
ROADMAP.md
remains the long-horizon product roadmap; live issue acceptance criteria and
merged evidence remain authoritative.
Verified read-only release
v0.1.1 was
published on 2026-09-26 from b82599a2231e997d42fd9f26f4b59587f4ae14cf.
Release run 36264382086
passed all eight jobs, including native qualification on Linux, Intel macOS,
and Apple silicon macOS. The downloaded signature, checksums, source/SBOM
bindings, and all 39 pilot scenario results passed independent verification;
the published Linux executable also passed a fresh scan/plan installation check.
See the release record.
Historical reconciliation pins
The starting evidence snapshot was captured on 2026-09-25 before this change.
| Evidence | Exact pin |
|---|---|
| Starting default branch | 7de8483b64387542a05214004c19a9cd05628908 |
| Public release | v0.1.0, published 2026-09-12 |
| Released source | f04c82a0b0c677a2939ea351c4219602cd7181af |
| Annotated tag object | 1e0381cb9e92616fabda2828f201ef1c1f2d4688 |
| Release workflow | Run 34698618575 |
The release bundle contains checksums, an SPDX SBOM, SLSA provenance, and a keyless signature for its release-subject manifest. The annotated Git tag object reports as unsigned, so this documentation claims signed and verified release evidence, not a cryptographically signed Git tag.
At the starting main revision, the latest push runs for
CI,
adversarial tests,
documentation,
site publication,
security,
and Identity validation
all succeeded.
Capability truth
| State | What it means now |
|---|---|
Released in v0.1.0 |
Read-only inventory, exact-duplicate proof, conservative reclaimable-byte evidence, and immutable review planning from the released source pin. |
Released in v0.1.1 |
Extension, media-profile, bounded PNG library-validation, documentation, performance, filesystem-corpus, and native pilot work from the immutable released source. Each feature retains its documented CLI/library boundary. |
Development main after #96 |
Explicit execution plans and approvals, dry-run validation, Linux-only bounded quarantine, status/resume/restore, and separately authorized finalization of restored retained copies. Not in v0.1.1. |
| Planned | #93 disposable real-volume/native release qualification; #94 candidate production and #95 validated replacement remain separate. |
| Unsupported | Mutation on macOS, PNG candidate production/replacement, direct original-path deletion, and causal physical-space reclamation claims. |
Version 0.1.1 is read-only with respect to source media. A review plan is
evidence for an operator; it is never write authorization. Development main
can mutate on Linux only after explicit execution approval and retains the
documented irreversible boundary. The existing signed release workflow refuses
any new source/version pair until distinct qualification is ready.
Completed evidence chain
| Issue | Delivered evidence |
|---|---|
| #21 — NativePath v4 | Lossless native path identity across state and artifact boundaries |
| #23 — bounded subprocess runner | Direct argv execution with time, output, concurrency, cancellation, and typed failure bounds |
| #22 — handle-bound observations | One stable read handle binds identity, allocation, content, and optional probe evidence |
| #24 — artifact-set commit protocol | Staged, digest-verified publication with incomplete/incompatible refusal and recovery |
| #26 — adversarial matrix | Property, filesystem-fault, parser, and artifact-reader evidence |
| #27 — release policy | Dependency policy plus the published and verified v0.1.0 release path |
| #51 — safe extension SDK | Explicit declarations and locks, typed read-only roles, deterministic resolution, and bounded providers |
| #29 — CLI and performance | Focused command coordination, stable remediation guidance, and enforced synthetic performance budgets |
| #66 — lossless PNG review profile | Deterministic, provider-bound review evidence with explicit limitations and no savings estimate |
| #28 — production site | Canonical production publication, live validation, and rollback evidence |
| #75 / PR #76 | Bounded batching, perceptual-validation, and metadata-policy planning; no mutation authority |
| #78 / PR #79 | Static PNG candidate preparation contract; no encoder or candidate output |
| #80 / PR #82 | Read-only validation of actual PNG source/candidate bytes within a documented subset |
| #83 / PR #84 | Media capability matrix and optimizer-strategy documentation |
| #85 / PR #86 | Deterministic cold-discovery performance evidence on the pinned starting main |
The live GitHub records remain authoritative for the full acceptance evidence. Closed planning, contract, validation, documentation, or CI work is not evidence of an optimizer or transaction engine.
Operator-ready execution chain
Work proceeds by dependency. Rows 1–7 are the primary operator chain; #94 is a
parallel candidate-production lane, and #95 is their v0.3.0 join. Each row
has exactly one capability owner.
| Gate | Owning issue | Bounded outcome |
|---|---|---|
| 1 | #88 | Filesystem, path, state, and removable-volume corpus foundations |
| 2 | #89 | External-drive read-only pilot and signed v0.1.1 |
| 3 | #90 | Execution/approval contracts and non-mutating dry-run preflight |
| 4 | #91 | Bounded exact-duplicate quarantine apply |
| 5 | #92 | Status, resume, restore, cleanup, and fault recovery |
| 6 | #96 | Separately authorized quarantine finalization |
| 7 | #93 | Removable-volume qualification and signed exact-deduplication v0.2.0 |
| Parallel after relevant #65 fixtures | #94 | Bounded, source-preserving OxiPNG candidate production |
| Join after #93 and #94 | #95 | Transactional validated lossless PNG replacement and signed v0.3.0 |
The strict dependency shape is:
-
88 → #89 qualifies real read-only use before mutation.
-
88 → #90 → #91 → #92 → #96, with #89 also complete, enables #93.
- The relevant provider/media/candidate fixtures under #65 enable #94.
-
93 and #94 together enable #95.
The first honest space-reclamation release is #93's v0.2.0, not the #89
read-only pilot. #94 may produce validated candidate artifacts only in
OptiFlow-owned storage; it grants no replacement authority. #95 is the first
lossless-PNG replacement release.
Separately gated work
- #60 remains blocked on the shared ADR system. It is not a prerequisite for starting #88.
- #61 remains the deferred post-roadmap repository, backlog, and Identity audit. It does not replace an active implementation issue.
-
65 remains the corpus umbrella after #88 for media, provider,
candidate-comparison, perceptual, compatibility, and resource-stress fixture families. Those later families do not block the exact-duplicatev0.2chain unless a consuming issue explicitly depends on them. - Later image and audio/video profiles remain long-horizon roadmap work. Once #61's Flow-suite completion gate is satisfied, that audit owns turning confirmed gaps into bounded issues; no later format is supported merely because it appears in the roadmap.
Next checkpoint
#88 is complete through
PR #101, merged at
ddc4b010caf5ad51c3d3f4b04e6b967a87ff8eea. #89
now has the pilot guide, completed native
qualification, and the independently verified signed v0.1.1 release above.
#90 is next: execution/approval
contracts and a non-mutating apply --dry-run path. It grants no source-change
authority; that remains owned by later transaction checkpoints.
The Flow-suite coordinator is
flow#11.