P3-11: Private beta — internal gate, NOT the release #40
Labels
No labels
data-integrity
engine
platform
procurement
remote
scaffold
ui
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: Cordy/cairn-desktop#40
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Depends on P3-10. Closes phase 3.
Nothing is published here. v1.0 means "it ships", and nothing ships until phase 4 is
complete — see #50. This milestone proves the sync engine is trustworthy so that placeholders
can be built on top of it. Tag
v0.9.0-rc; do not announce, do not publish.Why an internal gate is worth the effort
If the engine were unproven when placeholders arrive, every subsequent bug report would be
ambiguous: engine fault, or hydration fault? Two clean gates is the only thing that keeps
phase 4 debuggable.
The gate
Not 72 hours of the app being open. 72 hours of real work: editing documents, renaming
folders, deleting things, going offline, closing laptops mid-sync, working on the same files
from two machines.
Beta protocol
already in closed beta, so the audience exists.
explicitly and confirm it before they start.
user syncing the same folder from two machines simultaneously — that is where conflicts
actually arise.
Adversarial checklist — run these deliberately
conflict copy appears and both versions survive.
than a crash loop.
skip with a legible reason.
Report.pdfandreport.pdfserver-side, then sync to macOS. Verify both areskipped rather than one clobbering the other.
Exit criteria — all must hold
data-integrity.TestConvergencegreen at 500 seeds.Then
v0.9.0-rc. Internal only.phase-3-desktop-appmilestone.Do not publish the website clients page, announce anything, or tag
v1.0.0. Those belongto #50, once files-on-demand has passed its own gate.
If the gate is not met
Do not proceed to phase 4. Extend the beta. Layering placeholders onto an engine that still
loses data would make both problems harder to find.
Amendment — 2026-09-10: this is not the release
Decision: v1.0 means "it ships", and nothing ships until phase 4 is done too. There is no
v1.0-then-v1.1 split. Files-on-demand is part of the product, not a follow-up.
So this issue is now an internal milestone gate, not a public release. Everything about the
testing bar stays exactly as written — 72 hours, three machines, zero data loss, the full
adversarial checklist. What changes is what happens afterwards.
Remove from the "Then" section:
Tag→ tagv1.0.0v0.9.0-rcor similar. The version number is not the point; notcalling it 1.0 is.
Publish the "Clients" page on swisscairn.ch→ moves to #50, since the page shoulddescribe the product as it actually ships, files-on-demand included.
Update the handbook with the §8.3 network-behaviour statement→ also moves to #50.Keep: every exit criterion, and the instruction not to proceed if the gate is not met.
Why the gate still matters even though nothing ships here
Passing this gate is what proves the sync engine is correct before placeholders are layered
on top. If you skip it and go straight to phase 4, every subsequent bug report is ambiguous —
engine fault or hydration fault? Keeping two clean gates is the only way phase 4 stays
debuggable.
Closing this milestone means: the engine is trustworthy, and phase 4 can start.
P3-11: Private beta and v1.0 release gateto P3-11: Private beta — internal gate, NOT the release