Watch
1
0
Fork
You've already forked souveraine-lens
0

publication: gate the public candidate

This commit is contained in:
Fimeg 2026-08-24 23:22:34 -04:00
commit f01a2fcb2b
3 changed files with 14 additions and 12 deletions

View file

@ -3,10 +3,11 @@ name: ci
# the package: on primary, two archdev jobs build the x86_64 and AArch64
# release binaries, assemble signed pacman packages and publish them into the
# shared edge archive (Fimeg/souveraine). Green on primary means both declared
# package paths built, passed their ownership gates and published.
# package paths built, passed their ownership gates and published. The public
# candidate ref runs the source gates only; it never republishes edge packages.
on:
push:
branches: [primary]
branches: [primary, public]
pull_request:
branches: [primary]

View file

@ -227,9 +227,10 @@ The vault stays the one thing with no other readers.
A recipe establishes a path. Delivery crosses source, package, archive,
install, then exercised behavior — each proved separately.
As observed on 2026-08-24, r18 is a signed package in the internal x86_64 edge
repository and owns the installed laptop binary. The current source head is
r19 (`216faea`), which has not replaced that package.
As observed on 2026-08-24, r20 (`f8c9df3`) is signed in the internal x86_64
edge repository and owns the installed laptop binary. Later source commits are
new package versions only after their own CI run publishes them; source HEAD
must not be used as installation proof.
- **Source of truth**: the `primary` branch; green CI (test + clippy + the
attribution and action-pin gates) is the bar, on the same Gitea the
@ -245,10 +246,10 @@ r19 (`216faea`), which has not replaced that package.
declares the `LENS_PKGVER` version `0.1.r<commits>.g<sha12>`. The package
owns `/usr/bin/souveraine-lens`, the desktop entry and the icon; the
binary is the durable result, never a home-directory symlink.
- **x86_64 proof**: r18 (`0.1.r18.g1eb2840df769-1`) is present by name in
- **x86_64 proof**: r20 (`0.1.r20.gf8c9df352be3-1`) is present by name in
`souveraine-x86_64`, has a validated signature, and is package-owned on the
laptop. That proves r18 packaging and installation; it says nothing about
the unshipped r19 changes.
laptop. That proves r20 packaging and installation; it says nothing about a
later commit until its own package is indexed and installed.
- **AArch64 boundary**: the second job cross-compiles against an AArch64
sysroot and assembles the same package name for `souveraine-aarch64`. Until a
run, archive artifact, package-owned install and device exercise are checked,

View file

@ -69,7 +69,7 @@ The package owns `/usr/bin/souveraine-lens`, the desktop entry and the icon;
the vault remains a home-directory git tree pacman never touches. The design
argument lives in `DESIGN.md`.
Current proof, 2026-08-24: x86_64 r18 is signed, indexed and installed as
`0.1.r18.g1eb2840df769-1`. Source `primary` is r19 (`216faea`) and has not yet
replaced that package. The AArch64 workflow is a build path, not evidence of a
published, installed or running AArch64 Lens.
Current proof, 2026-08-24: x86_64 r20 is signed, indexed and installed as
`0.1.r20.gf8c9df352be3-1`; AArch64 r20 is signed and indexed. A later source
commit is not installed merely because it exists. AArch64 package proof is
also not evidence of an installed or running AArch64 Lens.