Harden Mesh public beta and prepare exact-source gates - #35
Draft
dhawal-ss wants to merge 18 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Why
The Phase 1 through Phase 6 work existed only in a dirty tree, so nine R0 release gates could not bind protected evidence to an exact source. The same tranche also contained three concrete runtime defects: expired tokens were classified too narrowly, typing status polled every two seconds, and early failures could disappear before the toast surface mounted. These commits bind the reviewed branch source and fix those causes without silently selecting an account provider, weakening message or media protection, or overstating voice readiness.
User and developer impact
Mesh presents calmer consumer language, familiar messaging controls, a discoverable beta support path, safer saved-account recovery, less idle work, and stronger Windows accessibility behavior. Account hosting stays independent from community hosting, public and custom providers remain explicit choices, automatic updates remain disabled, and Matrix voice remains fail closed.
Verification
ec83c942483f8d1645689bdf076a77dce27752ffand tree44c9c7177535961b31277ad108b904549262f90dProtected review evidence
aeabf76419bcdf4257c84b951bce65edb45289fc3572bb6e0952c68b96d94066cc7d70ec0adca81a; the release verifier intentionally accepts only successful protectedpushruns onmain, so PR evidence cannot be ingested as release evidence for the ledger source snapshotRelease boundary
This remains a draft. The committed readiness ledger is current and structurally valid, and is intentionally bound to reviewed source snapshot
ec83c942483f8d1645689bdf076a77dce27752ffbeneath the ledger-only head. All 25 release gates remain blocked: a branch PR run cannot satisfy the protected-main evidence contract, and the current Security run emitted no passing manifest. Track A has not met its nine-gate exit criterion, Track B has not started, the physical private-calling campaign remains 0/23, and no signing, tag, deployment, publication, provider configuration, or release is authorized by this PR.Follow-up container remediation evidence
A fresh local-only campaign on 2026-08-09 used policy-pinned Syft 1.50.0, Grype 0.116.1, and database build 2026-08-09T06:23:06Z. The reproducible Caddy
2.11.4-patched.2and lk-jwt-service0.5.0-patched.2prototypes passed smoke, containment, payload, SBOM, provenance, repeated-image-ID, and zero-fixable-finding checks. They remain unsigned local evidence and cannot replace an owner-approved registry, protected multi-architecture build, signing, or regression contract.Official-image comparison remains blocked: Caddy
2.11.4-alpineis still the latest release and has 8 fixable High matches; official lk-jwt-service0.5.0improves from 6 to 3 High matches but still fails on Go stdlib,x/net, andx/text; Synapsev1.158.0anddevelopeach retain 62 fixable findings, including 32 High/Critical. No production image pin was changed and no policy exception was added.Upstream remediation watchpoints
v2.11.5contains the merged dependency updates in #7872 and #7876, but still has five open items and no due date. Re-scan only after an official image is published with a new exact digest.x/netto 0.57.0, andx/textto 0.40.0, which covers the remaining official-image findings. The upstream PR is currently blocked with failing integration checks and has no published release image.developremains equivalent to the refreshed blocked scan. Wait for a supported official release/develop image whose Python, curl, Pillow, cryptography, pyasn1, and Twisted stack clears the policy; do not construct an unsupported local Synapse image.