GURDN

Documentation / Operating it

Release status

Engineering complete is not the same as released.

GURDN version 0.2.0 is in release qualification. There is no public download, and this site will not offer one until that changes.

Four states, not one

Engineering complete
The product is built and its behaviour is covered by automated tests. GURDN is here. There are no known product defects.
Qualification complete
The product has been exercised in the environments a release requires: a clean build, an elevated machine for the live service, firewall and resolver tests, and a machine that has never had GURDN on it. Not yet.
Signed release
Every artefact signed by a certificate that a stranger's machine will trust, with the signatures verified and the digests regenerated afterwards. Not yet.
Production release
A signed, qualified build published for general use. Not yet.

Why qualification is not complete

Not because of anything found in the product. The remaining requirements are environments and credentials rather than engineering:

  • A build host where a clean release build can run. On the development machine, Windows Smart App Control refuses the unsigned build scripts of some dependencies, which is correct behaviour on its part and not something to be worked around.
  • A code-signing certificate that chains to a trusted root.
  • A toolchain for building the installer package.
  • A disposable Windows machine with administrative rights, for the live service, firewall and resolver validation.
  • A clean Windows machine that has never had GURDN installed.

What has been verified

  • The full test suite passes, with no failures.
  • Lints are clean across the workspace.
  • The update path is exercised against real packages on disk, including a genuinely signed package being accepted and the full set of refusals: revoked key, unknown key, not-yet-valid key, downgrade, tampered payload and hostile staging paths.
  • Executable version metadata is verified by reading it out of the built binary rather than trusting the build.
  • The release gate is tested in both directions, so it can fail as well as pass.

Why this page exists

A product that hides its release state asks you to find out the hard way. The release verdict is computed by the product itself from recorded evidence, and it currently reads not ready. When that changes, the download page will say so, and not before.