Skip to content

release: add v1.0 acceptance gates - #30

Merged
zuudevs merged 10 commits into
mainfrom
release/v1.0-hardening
Sep 16, 2026
Merged

zuudevs merged 10 commits into
mainfrom
release/v1.0-hardening

Conversation

@zuudevs

@zuudevs zuudevs commented Sep 16, 2026 •

Copy link
Copy Markdown
Owner

Summary

Starts the v1.0 release-hardening milestone without adding feature scope. This PR turns the frozen requirements into explicit release gates and strengthens the installed/public surface checks.

New v1 Release Gate workflow

Adds two Linux release-gate jobs:

  • ASan + UBSan (Clang, C++17)

    • Debug build
    • warnings as errors
    • AddressSanitizer + UndefinedBehaviorSanitizer
    • leak detection enabled
    • unit and loopback integration tests under sanitizers
    • install-consumer script excluded from the sanitizer run because its independent link step would need matching sanitizer flags
  • C++20 Compatibility + Installed Consumer

    • full C++20 Release build and tests
    • warnings as errors
    • installs to a staging prefix
    • separately configures/builds/runs the installed consumer in C++20 mode

The C++20 gate has already completed successfully on an earlier hardening head, including full tests, install, separately configured installed consumer, and consumer tests.

The existing cross-platform Debug/Release CI and benchmark smoke workflows remain authoritative for Windows/Linux/macOS and benchmark coverage.

Public-header isolation gate

Every installed public header is compiled as its own translation unit using only the public include directory:

  • client.hpp
  • error.hpp
  • headers.hpp
  • request.hpp
  • response.hpp
  • response_limits.hpp
  • result.hpp
  • url.hpp

This catches missing direct includes and accidental dependencies on src/ or platform implementation headers.

Installed consumer hardening

The package consumer now includes and exercises the full public header surface rather than only the common Client/Request path.

Warning hygiene found by the gate

Clang warnings-as-errors exposed implicit signed char to unsigned-byte conversions in byte-oriented validation code. The hardening branch now makes those conversions explicit in:

  • URL forbidden-byte validation
  • request percent encoding and header validation
  • response header/reason-phrase validation

These changes preserve existing byte semantics while making signedness handling explicit and portable.

Acceptance matrix

Adds docs/release/v1.0-acceptance.md, mapping frozen functional/non-functional requirement groups to concrete test, CI, benchmark, package, and documentation evidence.

Roadmap

Marks v0.9 complete and v1.0 release hardening as in progress. The project version intentionally remains 0.9.0; the 1.0.0 bump is deferred until all automated gates and manual acceptance checks are green.

Scope

No new HTTP behavior, networking feature, public API semantic, or product-scope change is introduced by this PR. Source edits discovered by warnings-as-errors are release-hardening portability fixes only.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6c03c9c6ab

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

-DCMAKE_BUILD_TYPE=Debug \
-DCMAKE_CXX_COMPILER=clang++ \
-DCPP_REQUEST_ENABLE_SANITIZERS=ON \
-DCPP_REQUEST_WARNINGS_AS_ERRORS=ON \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Make the Clang warnings-as-errors gate buildable

With the Ubuntu/Clang configuration used by this job, enabling CPP_REQUEST_WARNINGS_AS_ERRORS makes the new gate fail during compilation before any sanitizer tests run: Clang reports -Wsign-conversion for the character loops in src/core/url.cpp:42 and src/http/request_serializer.cpp:93,134,143. I reproduced this using the workflow's configuration with Clang 17; fix these warnings or avoid promoting them to errors here so the required release gate can become green.

Useful? React with 👍 / 👎.

@zuudevs
zuudevs merged commit 03848be into main Sep 16, 2026
11 checks passed
@zuudevs
zuudevs deleted the release/v1.0-hardening branch September 16, 2026 03:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant