publication: gate the public candidate
This commit is contained in:
parent
f8c9df352b
commit
f01a2fcb2b
3 changed files with 14 additions and 12 deletions
|
|
@ -3,10 +3,11 @@ name: ci
|
|||
# the package: on primary, two archdev jobs build the x86_64 and AArch64
|
||||
# release binaries, assemble signed pacman packages and publish them into the
|
||||
# shared edge archive (Fimeg/souveraine). Green on primary means both declared
|
||||
# package paths built, passed their ownership gates and published.
|
||||
# package paths built, passed their ownership gates and published. The public
|
||||
# candidate ref runs the source gates only; it never republishes edge packages.
|
||||
on:
|
||||
push:
|
||||
branches: [primary]
|
||||
branches: [primary, public]
|
||||
pull_request:
|
||||
branches: [primary]
|
||||
|
||||
|
|
|
|||
13
DESIGN.md
13
DESIGN.md
|
|
@ -227,9 +227,10 @@ The vault stays the one thing with no other readers.
|
|||
|
||||
A recipe establishes a path. Delivery crosses source, package, archive,
|
||||
install, then exercised behavior — each proved separately.
|
||||
As observed on 2026-08-24, r18 is a signed package in the internal x86_64 edge
|
||||
repository and owns the installed laptop binary. The current source head is
|
||||
r19 (`216faea`), which has not replaced that package.
|
||||
As observed on 2026-08-24, r20 (`f8c9df3`) is signed in the internal x86_64
|
||||
edge repository and owns the installed laptop binary. Later source commits are
|
||||
new package versions only after their own CI run publishes them; source HEAD
|
||||
must not be used as installation proof.
|
||||
|
||||
- **Source of truth**: the `primary` branch; green CI (test + clippy + the
|
||||
attribution and action-pin gates) is the bar, on the same Gitea the
|
||||
|
|
@ -245,10 +246,10 @@ r19 (`216faea`), which has not replaced that package.
|
|||
declares the `LENS_PKGVER` version `0.1.r<commits>.g<sha12>`. The package
|
||||
owns `/usr/bin/souveraine-lens`, the desktop entry and the icon; the
|
||||
binary is the durable result, never a home-directory symlink.
|
||||
- **x86_64 proof**: r18 (`0.1.r18.g1eb2840df769-1`) is present by name in
|
||||
- **x86_64 proof**: r20 (`0.1.r20.gf8c9df352be3-1`) is present by name in
|
||||
`souveraine-x86_64`, has a validated signature, and is package-owned on the
|
||||
laptop. That proves r18 packaging and installation; it says nothing about
|
||||
the unshipped r19 changes.
|
||||
laptop. That proves r20 packaging and installation; it says nothing about a
|
||||
later commit until its own package is indexed and installed.
|
||||
- **AArch64 boundary**: the second job cross-compiles against an AArch64
|
||||
sysroot and assembles the same package name for `souveraine-aarch64`. Until a
|
||||
run, archive artifact, package-owned install and device exercise are checked,
|
||||
|
|
|
|||
|
|
@ -69,7 +69,7 @@ The package owns `/usr/bin/souveraine-lens`, the desktop entry and the icon;
|
|||
the vault remains a home-directory git tree pacman never touches. The design
|
||||
argument lives in `DESIGN.md`.
|
||||
|
||||
Current proof, 2026-08-24: x86_64 r18 is signed, indexed and installed as
|
||||
`0.1.r18.g1eb2840df769-1`. Source `primary` is r19 (`216faea`) and has not yet
|
||||
replaced that package. The AArch64 workflow is a build path, not evidence of a
|
||||
published, installed or running AArch64 Lens.
|
||||
Current proof, 2026-08-24: x86_64 r20 is signed, indexed and installed as
|
||||
`0.1.r20.gf8c9df352be3-1`; AArch64 r20 is signed and indexed. A later source
|
||||
commit is not installed merely because it exists. AArch64 package proof is
|
||||
also not evidence of an installed or running AArch64 Lens.
|
||||
|
|
|
|||
Loading…
Reference in a new issue