Source-Sha: 194a59adfd6c901635da7a9c18253bb2210e2426 Policy-Sha: b9b0be0ee74e55f561a803b8aef6be3c2134f5a83b46816a069a372f2eb04f4d Tree-Digest: 4697f2e281c1c6ecafff17cf6eeb391a0a1ac0fa6e5fc429f5b473f4579c252c
4.1 KiB
Publication provenance
This branch is a constructed public projection. Its commit trailers identify the internal source commit and the policy used to admit the projected tree. Admission means the tree is eligible for disclosure; it neither authorizes nor implies external publication.
.publication/paths.txt is the exact path authority. Every file in a candidate
must be listed, and every listed file must exist. Parent directories grant no
recursive authority. .publication/surface_gate.py can also write the exact
mode, blob ID, size, and path inventory for one immutable candidate with
--inventory-out.
Path authority covers every reachable commit, including files deleted before the tip. Removing a path from disclosure therefore requires history that does not contain it; a deletion commit alone is insufficient. Shallow history fails closed. Internal development history is preserved separately.
Candidate preparation now runs separately from public ref movement. Its internal receipt binds the source commit, both policy files, previous public head, constructor and gate hashes, exact tree inventory, omitted source paths and retained object pack. The source check requires the exact successful run and every required job, including all cross-compile jobs; the candidate also requires a separate secret scan. These unsigned receipts are evidence for the trusted publisher to verify, not permission for a builder to publish.
Preparation records disclosure holds without failing otherwise successful product CI. The pack and receipt enter internal package custody under the source SHA and source run ID. Custody does not make a held candidate ready.
The shared contract now defines a fixed-command trusted publisher with READY, BLOCKED and PUBLISHED receipts. It independently reconstructs this same projection under protected tool/policy/workflow identities, rechecks source CI and the public parent, then accepts only an authenticated human request naming the exact READY receipt. A one-parent fast-forward compare-and-swap and fresh anonymous commit/tree readback are required before it reports PUBLISHED. The implementation and negative tests are not a claim that production publisher credentials, branch protections or human authentication are enrolled. The source workflow no longer contains public or mirror push jobs.
Private network addresses and house hostnames are advisory findings. Private identities, unadmitted paths, unsafe links and credential findings still block. Credential rules cannot be waived by a path exception. The gate scans reachable historical blobs as well as the current tree and commit metadata, and withholds matched content from reports. Policy-marked review paths require a new decision only when their mode or bytes differ from the previous public head.
Reproduce the tree digest from a checked-out public commit with:
LC_ALL=C git ls-tree -r --full-tree HEAD^{tree} | LC_ALL=C sort | sha256sum
The result must equal the commit's Tree-Digest trailer.
Why public history begins at the epoch
Public history starts at a single constructed commit because the history before it was not admissible. Twenty-six commits carried an internal author identity and one body quoted an internal registry address, and no force push removes what a mirror has already copied.
Replaying eleven hundred commit messages through a filter would have produced a different object graph wearing the old words, and would still have required a person to read every one of them. The honest alternative is this one: the development history is preserved in full inside the private forge, where it is useful, and the public repository carries what was deliberately sent out.
The reviewed history allowlist is empty for the first time. It held forty-four commits, and every one of them was excused for exactly the thing the epoch removes.
Everything after the epoch commit is an ordinary publication carrying the same three trailers, so a force push stops being routine and starts meaning that something deliberate happened. The trailers bind a projection to its source without pretending the public commit is the private one: same lineage, different tree, and the record says so.