v0.2.0 release notes — draft, not published
The public release remains v0.1.1. These notes describe development-source
behavior and must be checked against the exact final release source, archives
and native pilot receipts before publication.
Intended bounded capability
- Select exact keeper and candidate paths in a new execution plan. The
read-only review plan's suggested
keep_pathis never write authority. A separate local fingerprint-bound approval enables a bounded dry run or live quarantine; it is an audit record, not a cryptographic signature. - On supported Linux filesystems, revalidate complete hashes, direct bytes, path identities, properties, scope and reserves before each sequential action. Same-filesystem no-replace rename is atomic where supported; cross-filesystem copy, verification and source unlink is not atomic.
- Durable journals support read-only status, bounded resume of untouched actions, explicit restore and empty owned-namespace cleanup. Ambiguous pending steps require inspection. Cross-filesystem restore retains the quarantine copy.
- An irreversible finalization has its own preview and separate authorization. It can remove only a selected retained quarantine copy after a completed cross-filesystem restore, while re-proving the surviving source and keeper. An unlink pending without a completion event is never reported committed.
Storage evidence
Logical selected bytes, quarantined bytes, observed allocated blocks and per-volume free-space changes have different meanings. Quarantine retains content; cross-volume movement may increase available space on the source volume while consuming it on the quarantine volume. Restoring a source before finalizing its retained copy returns that source volume to its previous logical occupancy. Shared extent bytes and causally proven physical savings remain unknown; no aggregate reclaimed-space promise is made.
Exclusions and release gates
There is no direct deletion at an original source path, automatic expiry,
media encoding, PNG replacement, universal removable-filesystem support, or
cryptographic operator approval. Development mutation refuses on macOS. An
APFS disposable-volume pilot, a portability-relevant external-format pilot,
failure/interruption/disconnect proof, clean installation and upgrade from
v0.1.x on all three supported binary targets, and independent signed-bundle
verification are still required. The release workflow rejects new sources and
versions until a separate native mutation qualification contract is implemented.
Back up the complete state directory and disposable source before an upgrade. Stop the process before rollback; restore the pre-upgrade state at its original absolute path and run the previously verified binary. Do not open a newly migrated state with that older binary. A published release is immutable; a correction uses a new reviewed patch version. See the mutation operator guide.