Files
chanora/docs/release/release-readiness-go-nogo-record.md
T

103 lines
6.3 KiB
Markdown

# Chanora Release Readiness Go/No-Go Record
**Document status:** DV meeting baseline candidate
**Date:** 2026-05-29
**Candidate:** `v1.0.0-rc.1` evidence over workspace version `0.2.0-beta.1`
**Decision:** No-Go for public/store release; Conditional Go only for documentation review and continued internal DV validation
## 1. Decision Summary
Chanora has enough documented structure for DV review and continued internal release-candidate validation. It is not ready for public, store, or broad external release because legal/trademark/OSS sign-off, platform release artifacts, signing/notarization, and several verification evidence items remain open.
The phrase `Conditional Go` in this record is restricted to document-baseline review and internal validation planning. It is not a product release approval, not a public beta approval, and not a store-distribution approval.
| Decision scope | Result | Rationale |
|---|---|---|
| Documentation baseline for DV meeting | Conditional Go | SysRS, SysDes, SRS, verification plans, traceability summary, and waiver register are available |
| Internal candidate validation | Conditional Go | Core product paths are implemented enough to continue targeted validation with recorded limitations |
| Public release | No-Go | DEC-012 and platform release gates remain open |
| Store release | No-Go | Signing, app-store build, legal/privacy/security evidence, and artifact records are incomplete |
## 2. Candidate Metadata
| Field | Value |
|---|---|
| Workspace version | `0.2.0-beta.1` |
| CHANGELOG latest candidate | `v1.0.0-rc.1` |
| Build number | `76` from `apps/chanora_flutter/pubspec.yaml` |
| Commit SHA | To be recorded from the candidate build job before release approval |
| Git tag | To be recorded if `v1.0.0-rc.1` is tagged for release validation |
| Artifact hashes | Not recorded in current workspace; required before release approval |
| Release owner | Product / Release Operations |
| Verification owner | Software QA with System Engineering support |
## 3. Current Implementation Readiness
Current implementation status is summarized in `docs/implementation-status-2026-05-28.md`.
| Area | Readiness statement |
|---|---|
| Core product path | Connect, channel/voice/chat/bookmark/storage/diagnostics paths are substantially implemented |
| CI baseline | Rust and Flutter automated checks are defined in `.github/workflows/ci.yml` |
| Audio benchmarks | Advisory workflow exists in `.github/workflows/bench-advisory.yml` |
| Platform coverage | Android and iOS platform work exists; desktop/iOS release artifacts are not ready for public distribution |
| Documentation | Verification plan set and DV gate summaries now exist for review |
## 4. Release Gates
| Gate | Status | Decision impact |
|---|---|---|
| Requirements/design baseline | Passed for DV | SysRS/SysDes/SRS available |
| Verification plan baseline | Passed for DV | `docs/verification/` plan set available |
| Traceability summary | Passed for DV | `docs/governance/traceability-matrix.md` available |
| Legal/trademark/OSS review DEC-012 | Blocked / open | Blocks public/store release |
| Privacy policy baseline | Baseline candidate | Requires owner/legal review before public/store release |
| Security/privacy evidence | Partial | Blocks strong secure-storage and diagnostic claims until audits attach evidence |
| Android secure-storage DEK | Deferred to v1.1 | Requires waiver for internal testing; limits release claim |
| iOS release build/signing | Unsigned verification only | Blocks TestFlight/App Store release |
| macOS signing/notarization | Not complete | Blocks macOS public binary release |
| Windows/Linux packaging | Source-buildable only for candidate | Blocks packaged public desktop release claims |
| Artifact hashes | Not recorded | Blocks final release approval |
## 5. Verification Evidence Status
| Evidence | Current status | Required action before public/store release |
|---|---|---|
| Rust workspace check/test | CI defined | Attach latest passing candidate run |
| Flutter analyze/test | CI defined | Attach latest passing candidate run |
| Cargo deny and cargo-about | CI defined | Attach latest passing candidate run and inventory records |
| Flutter license inventory | CI defined | Attach latest passing candidate run and inventory records |
| iOS unsigned build | CI defined | Attach latest passing candidate run; add signing evidence before release |
| Compatible-server demo | Evidence not attached in this record | Run and attach demo notes/logs |
| Audio send/receive and processing demo | Evidence not attached in this record | Run and attach platform evidence |
| Diagnostics redaction/export demo | Evidence not attached in this record | Run and attach export review |
| Platform secure-storage audit | Partial | Attach per-platform audit or waiver |
| PTT capability evidence | Partial | Attach per-platform `PttCapabilityLevel` and backend record |
## 6. Platform Readiness
| Platform | Current readiness | Release decision |
|---|---|---|
| Android | Core platform implementation present; Android Keystore-backed DEK deferred | Conditional internal validation only |
| iOS | Unsigned build path present; signing and store pipeline incomplete | No-Go for store release |
| Windows | Source-buildable; smoke procedure exists | No-Go for packaged release until smoke/signing evidence exists |
| macOS | Source-buildable; public artifact not in candidate | No-Go for packaged release until signing/notarization evidence exists |
| Linux | Source-buildable; packaging not confirmed | No-Go for packaged release until artifact evidence exists |
## 7. Waivers and Deferrals
All current waivers and deferrals are controlled by `docs/release/dv-waiver-register.md`. A release approver may accept a waiver for internal validation, but public/store release waivers require explicit product, legal/security, and release-owner approval where applicable.
## 8. Final DV Recommendation
Recommended DV meeting outcome:
| Question | Recommendation |
|---|---|
| Can the document baseline pass DV review? | Yes, with recorded limitations |
| Can internal release-candidate validation continue? | Yes, with the waiver register attached |
| Can Chanora be publicly released now? | No |
| Can store release proceed now? | No |
The release decision remains **No-Go** until current candidate run evidence, legal/trademark/OSS approval, privacy/security approval, platform signing, and artifact records are complete.