Files
chanora/docs/release/platform-release-policy.md
T
EdisonJwa 02ffadfa52 docs(ptt): land Baseline Candidate v0.9.3 — capability-based desktop PTT
Applies the gen2 desktop-PTT review summary
(`gen2/chanora-desktop-ptt-review-summary-v0.9.2.md`) to our doc set
with the owner rulings PTT-OPEN-001 through PTT-OPEN-006 resolved as
accepted decisions DEC-023 through DEC-028:

  * DEC-023 Windows Global PTT P0 / MVP
  * DEC-024 macOS Global PTT P0 / MVP with permission UX
  * DEC-025 Linux officially-tested env: GNOME on Wayland only
  * DEC-026 Mouse side buttons supported (Win + macOS; Linux portal)
  * DEC-027 PTT diagnostics: capability + availability only, no
            raw key codes ever
  * DEC-028 Missed-key-up watchdog: P0

Requirements (SysRS / SRS) and architecture (SysDes / SAD / SDD)
gain the desktop-PTT ID set the gen2 summary describes:

  SysRS-296..302  -> SysDes-142..148
                  -> SRS-195..203
                  -> SAD-071..079
                  -> SDD-081..092

ID totals advance from 295 / 141 / 194 / 70 / 80 to 302 / 148 / 203
/ 79 / 92. The strict layered sourcing rule (`SRS -> SysDes` only,
`SAD -> SRS` only, `SDD -> SAD` only) is preserved; the
`tools/validate_docs.py` validator reports zero undefined refs and
zero direct-layer-rule violations.

New document:

  * `docs/architecture/desktop-ptt-architecture.md` — capability
    ladder (L0Focused, L1GlobalShortcut, L2GlobalHoldToTalk,
    L3GlobalWithMouseButtons, L4DeviceAware reserved), Windows /
    macOS / Linux strategies, privacy rule, audio-gate rule,
    missed-key-up watchdog, release-readiness evidence requirement,
    traceability summary.

Doc addenda (Baseline Candidate 0.9.3):

  * `privacy/privacy-policy.md` — no raw key history, capability-
    dependent Global PTT, UI reflects actual runtime capability
  * `security/threat-model.md` — THREAT-PTT-001..006
  * `security/diagnostic-redaction-audit-report.md` —
    REDACT-PTT-001..006 banned field list enforced by `PttSanitizer`
  * `release/platform-release-policy.md` — per-platform evidence
    fields, no over-claim on untested Linux compositors
  * `release/release-readiness-go-nogo-record.md` — RR-PTT-001..008
    release-readiness items
  * `verification/swe4-unit-verification-plan.md` —
    SWE4-UV-035..039
  * `verification/swe5-software-integration-verification-plan.md` —
    SWE5-IV-015
  * `verification/swe6-software-verification-plan.md` — SWE6-SV-017
  * `verification/sys4-system-integration-verification-plan.md` —
    SYS4-SIV-016
  * `governance/traceability-matrix.md` — full PTT trace rows +
    verification map
  * `governance/decision-impact-assessment.md` — DEC-023..028
    impact matrix
  * `governance/product-decision-register.md` v0.9.9 entry
    recording DEC-023..028 in the decision table and the status
    table at §7
  * `governance/document-index.md` — adds
    `desktop-ptt-architecture.md` to the controlled set
  * `architecture/proof-of-concept-plan.md` —
    PoC-PTT-001..005 platform items
  * `references/external-references.md` — Windows Raw Input,
    macOS event-tap, Linux GlobalShortcuts portal references
  * Both validation reports
    (`baseline-candidate-validation-report.md`,
    `repo-format-validation-report.md`) bumped to v0.9.3 with the
    new ID totals (302 / 148 / 203 / 79 / 92).

README §"Desktop Push-to-Talk" added between Architecture Overview
and Repository Layout: capability levels, per-platform strategy,
privacy posture, missed-key-up watchdog.

Tooling:

  * `tools/validate_docs.py` copied from the gen2 zip into the
    repo tree (was previously available only inside the zip).
    Reports zero undefined refs, zero direct-layer-rule violations,
    English-only CJK check passes. The 35 "old package-style
    filename" hits are pre-existing and identical to the gen2
    baseline (they live in `path-migration-map.md` and config-ID
    headers of governance docs and are intentional per the path
    migration policy).
  * `.gitignore` adds `/gen2/` so the externally-provided review
    package does not enter the repo.

No code changes in this commit; B (the implementation split into
`transmit_active` / `capture_active`, `PttCapabilityLevel`
reporting, `PttSanitizer` diagnostics rule, and the UI capability
badge) follows in a separate commit.
2026-05-15 14:51:22 +08:00

4.2 KiB

Rel Platform Release Policy

Document type: Release / Platform Release Policy
Version: 0.9.2
Status: Baseline Candidate
Language: English
Product: Chanora
Repo path: docs/release/platform-release-policy.md ---

1. Purpose

This document separates runtime deployment targets from app-store upload build-SDK gates.

2. iOS / iPadOS Policy

Policy item Decision
Runtime deployment target iOS 13 or later unless Flutter, plugin, audio, or product constraints require raising it.
App Store Connect upload build-SDK gate For upload on or after 2026-04-28, use Xcode 26 or later and the iOS 26 / iPadOS 26 SDK or later, unless Apple publishes a newer applicable requirement before upload.
Internal Alpha / local development May use development toolchains suitable for internal testing if no App Store Connect upload is performed.
TestFlight / App Store upload Must satisfy the active Apple App Store Connect upload requirement.

3. Android Policy

Policy item Decision
Runtime minimum Android API 24 or later unless Flutter, plugin, audio, or product constraints require raising it.
Store upload target API Target the Google Play-required API level on the upload date.
Internal Alpha / sideload testing May use internal build configuration suitable for internal testing, but release readiness must state whether Google Play rules apply.

4. Release Readiness Rule

The Go/No-Go record shall record:

  • runtime minimum versions;
  • store upload build/toolchain gates;
  • build number;
  • commit SHA;
  • tag;
  • artifact hashes;
  • platform-specific release status;
  • whether the release is internal-only or store-uploaded.

5. Traceability

Policy Traceability
iOS runtime minimum SysRS-286 -> SysDes-133 -> SRS-185 -> SAD-061 -> SDD-071
Apple App Store Connect upload SDK gate SysRS-287 -> SysDes-134 -> SRS-186 -> SAD-062 -> SDD-072
Android runtime and target API policy SysRS-288/289 -> SysDes-135 -> SRS-187/188 -> SAD-063 -> SDD-073

6. Change History

Version Date Description
0.9.2 2026-05-14 Initial platform release policy separating runtime targets from store upload build-SDK gates.

Baseline Candidate 0.9.2 Update

Version Date Description
0.9.2 2026-05-14 Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage.

Desktop Push-to-Talk Release Policy Addendum (Baseline Candidate 0.9.3)

Per SysDes-148 the release readiness record shall carry, for every desktop release artefact, the following per-platform evidence:

Field Source Acceptance
Detected PttCapabilityLevel Live runtime measurement on the verification host. Must equal the level the release notes claim.
Active backend identifier DesktopPttBackend::backend_id() reported by the live measurement. Must equal the backend the release notes claim.
Focused fallback exercised Manual verification step. Must record "yes" with a re-measurement of the same backend identifier after the user revokes the relevant permission / blocks the relevant input path.
Capability badge UI Screenshot or platform-test trace. Must match the runtime capability.

Release notes shall not claim Global PTT support on a platform when the live measurement returned L0Focused. Release notes shall not claim mouse-side-button support on a platform when the live measurement did not include a side-button binding (per DEC-026 the Linux portal may not expose side-button bindings on every session).

Per DEC-025 the only officially-tested Linux environment for the first public release is GNOME on Wayland. Other Linux environments are supported at the L0Focused capability only; the release notes shall not claim Global PTT support outside the tested compositor.

Version Date Description
0.9.3 2026-05-15 Added desktop PTT release-policy evidence requirements: per-platform capability level + backend identifier + fallback-exercised + capability badge UI screenshot must be recorded before release notes may claim Global PTT support.