release: add v1.0 acceptance gates - #30
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6c03c9c6ab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| -DCMAKE_BUILD_TYPE=Debug \ | ||
| -DCMAKE_CXX_COMPILER=clang++ \ | ||
| -DCPP_REQUEST_ENABLE_SANITIZERS=ON \ | ||
| -DCPP_REQUEST_WARNINGS_AS_ERRORS=ON \ |
There was a problem hiding this comment.
Make the Clang warnings-as-errors gate buildable
With the Ubuntu/Clang configuration used by this job, enabling CPP_REQUEST_WARNINGS_AS_ERRORS makes the new gate fail during compilation before any sanitizer tests run: Clang reports -Wsign-conversion for the character loops in src/core/url.cpp:42 and src/http/request_serializer.cpp:93,134,143. I reproduced this using the workflow's configuration with Clang 17; fix these warnings or avoid promoting them to errors here so the required release gate can become green.
Useful? React with 👍 / 👎.
Summary
Starts the v1.0 release-hardening milestone without adding feature scope. This PR turns the frozen requirements into explicit release gates and strengthens the installed/public surface checks.
New v1 Release Gate workflow
Adds two Linux release-gate jobs:
ASan + UBSan (Clang, C++17)
C++20 Compatibility + Installed Consumer
The C++20 gate has already completed successfully on an earlier hardening head, including full tests, install, separately configured installed consumer, and consumer tests.
The existing cross-platform Debug/Release CI and benchmark smoke workflows remain authoritative for Windows/Linux/macOS and benchmark coverage.
Public-header isolation gate
Every installed public header is compiled as its own translation unit using only the public include directory:
client.hpperror.hppheaders.hpprequest.hppresponse.hppresponse_limits.hppresult.hppurl.hppThis catches missing direct includes and accidental dependencies on
src/or platform implementation headers.Installed consumer hardening
The package consumer now includes and exercises the full public header surface rather than only the common Client/Request path.
Warning hygiene found by the gate
Clang warnings-as-errors exposed implicit signed
charto unsigned-byte conversions in byte-oriented validation code. The hardening branch now makes those conversions explicit in:These changes preserve existing byte semantics while making signedness handling explicit and portable.
Acceptance matrix
Adds
docs/release/v1.0-acceptance.md, mapping frozen functional/non-functional requirement groups to concrete test, CI, benchmark, package, and documentation evidence.Roadmap
Marks v0.9 complete and v1.0 release hardening as in progress. The project version intentionally remains
0.9.0; the1.0.0bump is deferred until all automated gates and manual acceptance checks are green.Scope
No new HTTP behavior, networking feature, public API semantic, or product-scope change is introduced by this PR. Source edits discovered by warnings-as-errors are release-hardening portability fixes only.