<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>OpenVMX releases</title>
  <subtitle>Shipped releases of OpenVMX — the DCL and RMS operating environment on the Linux and NetBSD kernels.</subtitle>
  <link href="https://openvmx.3dl.dev/atom.xml" rel="self"/>
  <link href="https://openvmx.3dl.dev/" rel="alternate"/>
  <id>tag:openvmx.3dl.dev,2026:releases</id>
  <updated>2026-09-17T16:28:27-04:00</updated>
  <author><name>OpenVMX</name></author>
  <entry>
    <title>V0.7</title>
    <id>tag:openvmx.3dl.dev,2026:release/V0.7</id>
    <updated>2026-09-17T16:28:27-04:00</updated>
    <link href="https://openvmx.3dl.dev/roadmap/" rel="alternate"/>
    <summary>Cluster wire fidelity — a booted OpenVMX node joins a real VMS VAXcluster on a single circuit. A fresh-booted OVMX node opens its SCS virtual circuit to a live two-node VAXcluster, completes the connection-manager dialogue, and is admitted through the membership transition to STATUS=MEMBER at sustained CN=3 — on ONE NISCA circuit formation, no reformation. This is the first admission that is genuinely OpenVMX's own: the V0.6-11 CN=3 was real as a counted-member state but completed only on a circuit the VAX reformed in response to an OpenVMX defect (an unaddressed op-5 REJECT_RESPONSE that also crash-looped later builds); that defect is fixed, and the join FSM now re-arms across the VAX's transition-abort and completes admission cleanly on the first circuit. Proven on the lab's real VAXes (group 257) by a five-leg gate: OVMX SHOW CLUSTER lists the member, VAX1's SDA CSB shows OVMXJ1 admitted MEMBER, VAX1's F$GETSYI("CLUSTER_NODES") reads 3, the join pcap carries OVMXJ1 in the 0x6007 SCA traffic, and CAP_NET_RAW is DENIED to the booted node — so the OVMX executive itself, not an ambient Linux capability, served the Ethernet L2 I/O. CN=3 held ~225s+ (a floor, not a ceiling — the lab poll ended on a harness race, not a membership drop), both real VAXes zero bugchecks, the release-gating never-crash-a-peer invariant. Honest scope: OVMX's RECOVERY from a VAX transition-abort is host-proven but was not exercised on the wire in the passing run (the abort is intermittent, tracked vms-c10); quorum votes are computed and displayed but not enforced; and this JOINS an existing cluster — it does not yet form a cluster from nothing to a real VAX or MSCP-serve storage to one.</summary>
  </entry>
  <entry>
    <title>V0.6-16</title>
    <id>tag:openvmx.3dl.dev,2026:release/V0.6-16</id>
    <updated>2026-09-12T21:04:43-04:00</updated>
    <link href="https://openvmx.3dl.dev/roadmap/" rel="alternate"/>
    <summary>Point release.</summary>
  </entry>
  <entry>
    <title>V0.6-15</title>
    <id>tag:openvmx.3dl.dev,2026:release/V0.6-15</id>
    <updated>2026-09-11T20:03:30-04:00</updated>
    <link href="https://openvmx.3dl.dev/roadmap/" rel="alternate"/>
    <summary>Point release.</summary>
  </entry>
  <entry>
    <title>V0.6-14</title>
    <id>tag:openvmx.3dl.dev,2026:release/V0.6-14</id>
    <updated>2026-09-10T13:49:58-04:00</updated>
    <link href="https://openvmx.3dl.dev/roadmap/" rel="alternate"/>
    <summary>Cluster genesis and networking hardening. OpenVMX becomes a first-class founding cluster member: the executive can now FORM a VMScluster from nothing (authentic VMS formation, quorum-grounded) — a genesis, not only a join of an existing cluster — running on the real executive-resident membership machinery. A cluster crash-fix closes a host-kernel panic on a clustered node's shared network buffer and a founder self-demotion. Networking: a valid SYSUAF user now lands at a DCL prompt over the wrapped OpenSSH sshd end to end (real ACP SYSUAF authentication, the earlier pubkey-root overclaim dropped from the register), the DECnet routing receive path gains ASan/UBSan fuzzing and bound proofs with CI-enforced sanitizer teeth, and the libdatalink DECnet datalink is wire-proven on live NetBSD/VAX. Honest scope: interoperation with a REAL VAX cluster — a genuine VAX joining and mounting OpenVMX-served storage — remains in progress and unproven.</summary>
  </entry>
  <entry>
    <title>V0.6-13</title>
    <id>tag:openvmx.3dl.dev,2026:release/V0.6-13</id>
    <updated>2026-09-10T05:02:39Z</updated>
    <link href="https://openvmx.3dl.dev/roadmap/" rel="alternate"/>
    <summary>DECnet Phase IV file COPY, and a substrate-agnostic login frontier. Authenticated inbound SET HOST -&gt; LOGINOUT is now a hard release gate on all three rails (x86_64, Alpha, and VAX) — the interactive-login frontier no longer depends on the substrate. DECnet Phase IV file COPY (FAL/DAP) lands: an object-17 FAL server, a DAP codec, and a COPY client, authenticated against the real SYSUAF/Purdy, transferring over RMS-on-the-executive-ACP and byte-verified in both directions, with a Phase IV configuration and usage guide. And a compatibility-register honesty pass: four cluster distributed-lock-manager rows whose multi-node proof harness had been retired were downgraded from verified to implemented (re-establishment tracked as a follow-on), so the surface states only what a live test currently proves.</summary>
  </entry>
  <entry>
    <title>V0.6-12</title>
    <id>tag:openvmx.3dl.dev,2026:release/V0.6-12</id>
    <updated>2026-09-09T18:01:55-04:00</updated>
    <link href="https://openvmx.3dl.dev/roadmap/" rel="alternate"/>
    <summary>DECnet Phase IV SET HOST reaches an authenticated interactive login. An inbound SET HOST session now runs the full connect-through-LOGINOUT dialogue (P0-P5) bidirectionally against the real binary SYSUAF, so a remote terminal lands at a genuine DCL prompt with full SYSUAF login-flag authenticity. Alpha activates its symbol-vector shareables on the live executive; the VAX rail builds them, with runtime activation isolated to a cross-image cross-call marshalling bug (tracked RED). Plus CI-backlog optimization across the release gates.</summary>
  </entry>
  <entry>
    <title>V0.6-11</title>
    <id>tag:openvmx.3dl.dev,2026:release/V0.6-11</id>
    <updated>2026-09-05T19:27:26-04:00</updated>
    <link href="https://openvmx.3dl.dev/roadmap/" rel="alternate"/>
    <summary>The cluster claim, made good: a booted OpenVMX node joins a real, running VMS Cluster and is counted as a member. On the lab's two-node VAXcluster, a fresh-booted OVMX node — with CAP_NET_RAW dropped, so the executive itself, not an ambient Linux capability, drove the Ethernet — brought up its cluster port, opened an SCS virtual circuit to a live VAX, connected the VMS$VAXcluster connection manager, and was admitted through the membership transition. The existing members' own accounting counted it: VAX1's F$GETSYI("CLUSTER_NODES") reported 3, sustained for the full ten-minute run; SHOW CLUSTER listed the node with STATUS=MEMBER; SDA showed a genuine, sequential Cluster System Block (CSID 00010003, following the VAXes' 00010001/00010002) with the member flag. The whole join runs inside the executive (vms.ko) — SCS, the connection manager, the PE/virtual-circuit transport, the DLM rebuild, and the state-transition barrier — not a userspace daemon. And it is crash-safe: both real VAXes stayed up the entire run with zero bugchecks, the release-gating invariant that OpenVMX must never emit a frame that can crash a peer. That safety is enforced two ways — a runtime emit-guard that drops any frame violating the measured crash-safe envelope, and a post-hoc wire-safety audit calibrated against 234k real cluster frames — after a hunt (E55–E85) that found and closed every crash-vector in the lab, never in production, the last being a transaction-close frame whose mandatory field VMS asserts nonzero. Honest scope: this edition JOINS an existing cluster (it does not boot satellites or form a cluster from nothing); quorum votes are computed and displayed but not yet enforced; and the member committed the transition without an on-wire barrier-release frame, a tracked follow-on. Configure it the VMS way: @SYS$MANAGER:CLUSTER_CONFIG_LAN.COM (docs/cluster-configuration.md). (V0.7 correction: this counted CN=3 — F$GETSYI=3, SDA CSID 00010003 — was a real observation, but the admission completed only on a circuit the VAX REFORMED in response to an OpenVMX defect, not a clean single-circuit join; the wire also still carried one latent unaddressed frame that survived by luck here and crash-looped later builds. A clean single-circuit admission, crash-safe, is V0.7's milestone.)</summary>
  </entry>
  <entry>
    <title>V0.6-10</title>
    <id>tag:openvmx.3dl.dev,2026:release/V0.6-10</id>
    <updated>2026-08-31T18:03:24-04:00</updated>
    <link href="https://openvmx.3dl.dev/roadmap/" rel="alternate"/>
    <summary>Three more rungs up the self-hosting and networking long poles, no cluster-participation claim. DECnet Phase IV gains a real transport: an NSP logical-link connection service — establish (Connect Initiate/Confirm), carry data segments with acknowledgement and in-order sequencing, tear down (Disconnect Initiate/Confirm), and give up honestly (retransmit then abandon as unreachable) — proven on the wire between two nodes, byte-identical, the layer SET HOST and file transfer will ride. VMS condition handling gains its third authentic rung: the real Alpha invocation-context primitives (LIB$GET_INVO_*) walk the genuine procedure-descriptor and register-save-area chain, so an unwind can transfer into an ancestor frame that armed no explicit anchor — the mechanism a bare 'return to main' and compiler exception handling need — replacing the last piece of emulation on the software path. And the compiler runtime's file layer gains a real RMS veneer: a C-RTL stdio surface that routes fopen/fwrite/fread/fclose to genuine RMS create/put/get/close over the executive ACP, proven un-fakeably — a file written through the veneer is then seen on the real Files-11 ODS-2 volume by an independent reader, with a genuine File ID and version a POSIX bootstrap cannot forge; wiring it into the alpha port image is scoped as tracked follow-on work.</summary>
  </entry>
</feed>
