Release

Komms 0.4.2 Unsigned Test Release

This page is the durable repository record for the public Komms 0.4.2 Beta test release. It records what was published, how it was validated, the explicit exception used for this version, and every assurance boundary that remained open.

1. Immutable release identity

Field Value
Public release v0.4.2
Release title Komms 0.4.2 Beta — UNSIGNED TEST RELEASE
Published 2026-08-04 as a GitHub prerelease
Source tag annotated tag v0.4.2
Source commit 5a09190cfef9cfef92703672517bc008b6e8cc1f
Validation workflow release candidates run 30938415216
Release channel in evidence validation
Production signed false
Qualified for stable false
Independently reproduced false

All validation jobs passed: immutable-source checks, primary and controlled Linux builds, macOS universal packaging, Windows x86-64 packaging, both Android flavors, the iOS Simulator build, and evidence assembly. A green validation run proves only the recorded build/test statements for that revision and environment.

The hosted validation-candidate-assets artifact had SHA-256 c25aa8f6f3ac0723c3edd4a1b6c37e36c7feb70fbc1a883efab841ce8a38cb50. The hosted release-evidence-bundle artifact had SHA-256 3ab0f46f99892bfb1eb76fe2abab3ec298c69de533485a4b4e8064e7d2bea87c. Those workflow artifacts expire on 2026-11-02. The public release retains the selected platform files, checksum manifests, and packed validation archive.

2. Explicit one-version exception

The maintainer explicitly authorized publication of the green validation set as an unsigned, pre-production test release for version 0.4.2 only. The release page leads with that warning and excludes emergency, safety-critical, and production use.

This exception did not:

  • enroll or exercise the offline release-manifest role;
  • enroll Android Play, Android Google-free, Apple, Windows, or store signing;
  • promote the validation evidence to a production beta evidence channel;
  • complete authenticated install/upgrade/rollback qualification;
  • establish independent reproduction, interoperability, or security review;
  • qualify a platform, operator, background lifecycle, real network, or radio environment;
  • authorize a stable-beta or stable claim; or
  • change the required signing and protected-publication path for a later release.

The normal production boundary remains Release Security and Recovery, Release Evidence Bundles, and the Release Runbook.

3. Public assets and checksums

UNSIGNED-TEST-SHA256SUMS is the checksum authority for the public 0.4.2 test asset set. Its own SHA-256 is 48ba6a499bdfcb03d10fb79e7ef1000996658b916a722ff4775cfbaf3705c1f4.

SHA-256 Public asset
fee9f0e7d91418d8c50c6196db7e5232214aab3dfb30cd9e1ecdbeaa3da46e4a Komms-0.4.2-android-google-free-arm64-app-googleFree-release-unsigned.apk
deb2acbef27abb2e316b1cbe2e39e1854e1dc05078cf74a5b1bf35d1674a1273 Komms-0.4.2-android-google-free-test-signed.apk
d03db699e692aa631823ee6e5ca21ccc5fb2bc352ff90fcbb2d408ed62c2fbda Komms-0.4.2-android-play-arm64-app-play-release-unsigned.apk
fded241c72fca6b1db8f0d42b7f4a79beae328ca63452f0fc30445296f6065df Komms-0.4.2-android-play-arm64-app-play-release.aab
4ffb9f6b084157a361bc5f8c3892062d28d7b585c1d2acc8239ebb1464b3c56f Komms-0.4.2-ios-simulator-validation.zip
ce5aaae1ff030fa4ad73b8fb7811782779d58430d51dddd9bc106abb3d61744b Komms-0.4.2-linux-x86_64-Komms-0.4.2-1.x86_64.rpm
7df473a629f52901b23230dbc9a8bbe8cdc5d4b62eba72db1280a4c370585ad5 Komms-0.4.2-linux-x86_64-Komms_0.4.2_amd64.AppImage
51f63d59c5b205e6e272d90c6148cbd4480985098ce0234cf5e05226a5320888 Komms-0.4.2-linux-x86_64-Komms_0.4.2_amd64.deb
d100217919634ba74dd456e25db21622d5484fb95a9704b913a2fdb59dcd615c Komms-0.4.2-macos-universal-Komms_0.4.2_universal.dmg
b639a1ad81210a17f4dc8bc5d47d981ab0011aa45357b99638350e4d9d99e58f Komms-0.4.2-validation-evidence.tar.gz
cac0b121d622c3519359dda645a30ac17aefec7811e1f29548c422f3df214ada Komms-0.4.2-windows-x86_64-Komms_0.4.2_x64-setup.exe
aea06e7ebd6ba5e4f484eb11d60502156ef4c7d6d172f7aa9aec2e9c8477fd61 Komms-0.4.2-windows-x86_64-Komms_0.4.2_x64_en-US.msi
8a90276c0e2da125ad0fdba2165b356f7711b89f7cfe68c65c4a8398d6f6d2ca VALIDATION-SHA256SUMS

The public checksum manifest was downloaded without an authenticated project session and compared byte-for-byte with the staged manifest after publication. Every public asset name, byte size, and SHA-256 matched its staged source.

4. Android test certificate

The hosted Google-free APK is unsigned and cannot serve as an ordinary Android install package. For physical-device testing, a copy of that exact hosted APK was signed with the existing Android test/debug certificate and published as Komms-0.4.2-android-google-free-test-signed.apk.

Field Value
Package id is.andri.komms
Version name 0.4.2
Version code 6
APK signing schemes v2 and v3
Test certificate SHA-256 ec07a2d6a873d4b921c03c63a4c38888db582ee8b9e00517c124b4e395083cb7
Normalized unsigned payload SHA-256 9c789a92b5fe9bc233a60ee27e17809ee1f0c2c42290c0fc7ed8bd46197c3251

The normalized unsigned payload digest matched the hosted Google-free APK exactly. The Google-free inspection also passed: no Firebase, FCM, Play Services, or ML Kit dependency was present.

This certificate is not the future Google-free production identity. Android will reject an in-place update signed by an unrelated key, so testers must preserve any needed encrypted export and uninstall this test build before a future production-signed installation.

5. Physical development evidence

On the same source tree, a fresh macOS profile and a physical Galaxy S23 Ultra completed pairing, Message Request acceptance, trust comparison, and bidirectional delivered messaging on one local Wi-Fi network. This is useful development evidence, but it used debug/ad-hoc binaries and does not satisfy the canonical named-platform, distinct-NAT, background-lifecycle, upgrade/rollback, accessibility, operator, or independent field matrix.

The public platform files therefore remain test artifacts even where the corresponding workflow job or development walk-through passed.

6. Gates that remain open

At publication time, all P0 gates remained open. In particular:

  • every production signing role and store credential remained unenrolled;
  • no offline release-manifest signature or authenticated update path existed;
  • no independently administered reproduction or conformance execution existed;
  • no independent protocol/security review had occurred;
  • no platform had completed the full signed install, upgrade, failure, rollback, compatibility, lifecycle, and accessibility matrix;
  • no qualified default bootstrap, mailbox, rendezvous, wake, or OHTTP operator shipped;
  • the two-stock-radio physical HIL matrix remained open; and
  • no consent-based pilot, support commitment, final P0 audit, or stable go/no-go record had passed.

Testing instructions and exact platform limitations are in Install and Test Komms 0.4 Beta. The canonical gate status remains the Release Evidence Ledger.

Edit this page on GitHub ↗