diff --git a/CHANGELOG.md b/CHANGELOG.md index 4b47db0..1094fc9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,11 +1,15 @@ -## UNRELEASED — v0.130.0 candidate: the agent was the one leaking connections onto the off-site box (2026-08-20, R-344) +## v0.130.0 — the agent was the one leaking connections onto the off-site box (2026-08-20, R-344) -> **Deliberately not a release heading yet, and the `release-complete` gate is doing its job by -> requiring that.** This build is **hand-installed on `demo-hp` only** so the fix can be proved -> against `demo-felhom` as an untouched control. Publishing it — tag + Gitea package — would put it -> on the control box through the self-update path and destroy the experiment. **When the operator -> authorises the publish, this heading becomes `## v0.130.0` in the same commit as the tag and the -> package**, and the gate then checks it for real. See R-347. +> **RELEASED 2026-08-20**, on the operator's word, after the fix was proved on both boxes. +> `sha256 a56a92a7bd68f5b46736eaec4806c3d26c16ccb35118c4ac0e3d8094eaefabc3`, 14,141,158 bytes, +> tag `v0.130.0` at `7569f34`. Reproducible: a rebuild with `-trimpath -buildvcs=false` matches the +> published artifact byte for byte (R-186's property, checked rather than assumed). +> +> The heading read `## UNRELEASED — v0.130.0 candidate` until this point, deliberately: while the fix +> was hand-installed on `demo-hp` only, publishing would have pushed it onto `demo-felhom` through +> self-update and destroyed the control the proof rested on. **`release-complete` convicted on the +> release heading and was right to** — the answer was to stop claiming a release, not to bypass the +> gate. See R-347. **What was measured, before anything was changed.** Between 2026-08-18 09:51:22Z and 2026-08-20 08:02:13Z, ep0's PBS proxy accumulated **388 established connections** — 194 from each demo box, on a