CENTL v0.14.0

Manual · hosted from the CENTL repository

Documentation · Manual

Manual

CENTL v0.14.0 is a deliberate consolidation release. The v0.13.0 development line reached a release-candidate state but was never formally published as a stable CENTL release. Rather than preserve that intermediate boundary as an…

Source in the repository

Version: 0.14.0

Platform: GNU/Linux x86_64

Release posture: consolidated and hardened stable baseline

Oasis status: CENTL v0.14.0 is an Oasis release.

CENTL v0.14.0 is a deliberate consolidation release. The v0.13.0 development line reached a release-candidate state but was never formally published as a stable CENTL release. Rather than preserve that intermediate boundary as an artificial public release, v0.14.0 incorporates the validated work from that line together with bounded CARAVAN and MIRAGE work and establishes one reviewed stable baseline.

Oasis declaration

CENTL v0.14.0 is an Oasis release.

Oasis is a repeatable release classification, not a version codename. The declaration belongs only to the exact source commit that passes the complete local and hosted Oasis gate, is promoted unchanged to the authoritative oasis branch, receives the exact v0.14.0 tag, and publishes the already-qualified release bytes.

This release branch intentionally carries the final declaration before qualification so the exact text and exact source tree are tested together. If the branch changes after qualification, it becomes a new candidate and the gate must run again.

The v0.14.0 Oasis gate covers repository reconciliation, stable-boundary review, source and release metadata coherence, executing toolchain identity, F* verification and fresh extraction identity, deterministic/native/Python testing, mandatory sanitizer-backed hardening, fuzz/metamorphic/performance coverage, Julia/Nemo differential validation, SCi validation, CARAVAN Phase 1 validation, hostile archive validation, staged installer smoke tests, release-blocking GitHub security state, exact hosted check provenance, exact source/tag identity, and post-publication byte revalidation.

Native release boundary

The standard v0.14.0 native archive is deliberately GNU/Linux x86_64 only and installs exactly these public command surfaces:

  • centl;
  • centl-physics;
  • centl-sci.

The release archive does not install centl-mirage or CARAVAN as public commands. Their admitted v0.14.0 work is present in the source baseline under the explicit source/laboratory boundaries below. Repository presence does not silently expand the supported installed product.

Historical macOS and Windows implementation material may remain available in source history, but it is outside the active v0.14.0 Oasis release promise.

Included systems

CENTL core

v0.14.0 retains CENTL's exact-first numerical contract: exact input remains exact where the admitted mathematics permits, approximations carry explicit evidence, unsupported work remains visible, and machine-facing assurance classes cannot be promoted by untrusted semantic tooling.

CENTL-SCi v0.0.2-Caramels

Caramels is the current scientific interaction generation, including deterministic mathematics and physics interpretation, evidence-backed presentation, persistent user workspaces, and controlled BUILD/self-extension workflows.

A configured local semantic model remains an interpreter of intent rather than mathematical authority. Model-produced semantics must cross CENTL's typed and deterministic boundaries before a result can inherit mathematical meaning.

CENTL-MIRAGE

v0.14.0 includes the bounded local MIRAGE bootstrap in the source baseline: Mathematical Introspective Recursive Autonomous Growth Engine.

The admitted boundary includes:

  • bounded local design-document ingestion;
  • SHA-256 source identity;
  • provenance-preserving Specification IR;
  • typed goal and capability graphs;
  • deterministic hard-requirement conflict detection;
  • capability-gap analysis and existing-capability reuse;
  • transaction-bound deterministic candidate materialization where supported;
  • authoritative parser evidence for exact staged source;
  • machine-readable evidence obligations and evidence-execution plans;
  • readiness, admission, evidence, and review artifacts that retain explicit authority boundaries;
  • non-mutating candidate transactions;
  • explicit blocking of ambiguous, conflicting, unsupported, or policy-prohibited requests.

v0.14.0 does not claim autonomous source mutation or autonomous promotion into verified core. Candidate material remains staged and must cross the appropriate engineering and assurance gates before activation. centl-mirage is not one of the public commands shipped in the v0.14.0 native archive.

CENTL CARAVAN Phase 1

v0.14.0 includes the completed CARAVAN Phase 1 local laboratory in the source baseline for content-addressed, authenticated artifact preservation and availability.

The laboratory includes:

  • immutable content-addressed storage with whole-file and deterministic chunk SHA-256 identities;
  • Ed25519 pseudonymous carrier identity and proof of possession;
  • signed policy-acceptance receipts;
  • TUF-authenticated artifact catalog consumption;
  • outbound-only laboratory carrier/coordinator transport;
  • bounded transfer, session, challenge, polling, request, and storage behavior;
  • pre-transfer capacity enforcement and authenticated chunk-size validation;
  • serialized local store admission so concurrent transfers cannot race the configured storage ceiling;
  • verified multi-carrier retrieval with automatic bad-carrier quarantine/fallback;
  • hostile-transfer handling for corruption, reordering, truncation, appended data, and malformed authenticated manifests;
  • local join/status/leave lifecycle;
  • a reproducible local laboratory.

CARAVAN's governing invariant remains:

A carrier may provide bytes, but a carrier may never define which bytes are trusted.

v0.14.0 does not enable arbitrary public volunteer enrollment. Production relay deployment, public enrollment, abuse operations, final telemetry/privacy policy, and other public-network rollout gates remain later work. CARAVAN is not installed as a public command in the standard v0.14.0 native archive.

Consolidation and repository hygiene

Oasis qualification treats repository state as part of release quality. Obsolete v0.13.0 one-shot tag/gate-observer automation and obsolete fixed-version publication machinery are removed from the active release path. Stale release references are reconciled, repository structure is documented, the branch model is explicit, and active pull-request state must be clear before publication.

Historical branches may remain as preservation refs when unique history has not been proven redundant. A historical branch name is not part of the supported runtime surface and does not by itself prevent an Oasis declaration.

Security posture

Oasis qualification is gated on source remediation rather than alert suppression. Security work includes:

  • immutable GitHub Action pins with accurate version annotations;
  • least-privilege workflow permissions;
  • dependency and hosted security review;
  • release and installer supply-chain boundaries;
  • filesystem, path, symlink, archive-member, and atomic-write boundaries;
  • native/process/protocol resource limits;
  • CARAVAN trust, identity, metadata, transfer, storage, session, and quarantine boundaries;
  • MIRAGE provenance, materialization, workspace, evidence, and candidate-authority boundaries;
  • fail-closed verification that mandatory hosted Oasis checks actually exist, come from GitHub Actions, and succeed on the exact final SHA.

Security review establishes evidence for the declared release boundary; it is not a claim that any nontrivial software is free of every possible vulnerability.

Exact qualification and publication integrity

The final v0.14.0 path deliberately keeps one source identity from hosted qualification through publication.

The final release branch is checked out by its literal head SHA. The build is stamped with that same SHA. The mandatory hosted jobs are:

  • Adversarial engine self-test;
  • Full stable-product convergence;
  • Release security state.

The full convergence job builds and validates the release package and preserves the exact archive and checksum as an artifact named for that commit.

The final release latch may run only after that same green SHA has been promoted unchanged to origin/oasis and its qualification pull request is closed. It then requires zero remaining open Oasis pull requests, confirms the mandatory check provenance and success, locates exactly one qualified artifact, revalidates the archive checksum and embedded build identity, creates v0.14.0 at the exact Oasis SHA, publishes only those already-qualified bytes, downloads them again, and compares the published archive to the qualified archive.

A tag never authorizes a substitute release build.

Version history note

0.13.0 remains visible in development history and documentation where historically useful, but it is not a formally published stable release. v0.14.0 is the stable successor to v0.12.0.

Release identity

Canonical Git tag:

v0.14.0

Human release title:

CENTL v0.14.0

Quality declaration:

CENTL v0.14.0 is an Oasis release.

Semantic Versioning and the repeatable Oasis classification remain independent.