Skip to content

ci: build exact v30.1.5 canary candidate - #51

Draft
Blackcoin-Dev wants to merge 16 commits into
mainfrom
build/v30.1.4-hotfix-candidate-linux
Draft

ci: build exact v30.1.5 canary candidate#51
Blackcoin-Dev wants to merge 16 commits into
mainfrom
build/v30.1.4-hotfix-candidate-linux

Conversation

@Blackcoin-Dev

@Blackcoin-Dev Blackcoin-Dev commented Aug 8, 2026

Copy link
Copy Markdown
Owner

Purpose

This draft provides a fail-closed v30.1.5 candidate pipeline and a separately gated OCI publication/handoff path. Neither path can build, publish, or deploy until the final signed Core source and its exact successful safety-gate evidence are atomically pinned.

Signed stages on this branch

  1. bad55a3a321d33ac5294cfcbc230b9ae7e5b1594 — identity-generic candidate adapter.
  2. f2ef7c4e0490ba098de125a5754a78c8f2ed8032 — initial OCI publication adapter (superseded history).
  3. 50a1b1a4c4484fd2d8ed6d601a82105f7ed243b2 — exact Core-CI/check-run/zero-report TSan receipt.
  4. db8812b603744fee7615979f87899b4dd48b154d — live-main protection binding: exact 16 contexts and Actions app ID 15368.
  5. 6c34b97122b46505b8360841be5014ba06b61f1a — exact integer-type closure for Core receipt schemas and GitHub IDs.
  6. 97ae128d0a7b3924474c487556d6c37813c3fcff — schema-2 publication intent, sealed OCI-manifest equality, and digest-preserving registry copy (superseded by schema 3).
  7. f539049beaa98d4d1a2cfb2b94e40eb56669d533 — repository-required executable modes for the Core receipt tools.
  8. f6042df3cf14c9c3f2a53d341affc070c96303f1 — schema-3 complete publication authority and hardened live wrapper.
  9. f0b93f583f7bc4e81c1236d4bcba9977cf71b204 — portable Bash entrypoint and resealed publication package.
  10. 1419cf02c6c007bd06abb1e176c25f2da7873589 — blocked/ready publication-fixture isolation for the eventual checked-in authorization transition.

Every stage is signed by Blackcoin-Dev with ED25519 fingerprint SHA256:jAkpBudDw+ntWHSUx3e1KY+czAFjnlaPxQtRFtptL70 and pushed before the next stage. The Core-CI receipt stage has completed independent hostile review with no remaining P0/P1/P2 defect. The exact schema-3 publication head is undergoing an independent read-only hostile audit; no live publication is authorized from this draft.

Current authority state

The checked-in policy remains deliberately blocked:

{
  "state": "blocked_pending_final_signed_source_and_green_ci",
  "dispatch_enabled": false,
  "temporary_source_pin": true,
  "core_ci_run_id": null,
  "core_ci_run_attempt": null,
  "thread_sanitizer_artifact": null
}

The workflow sentinel remains EXPECTED_CORE_CI_RUN_ID: 0. Build, assembly, OCI import, registry publication, and fleet deployment are impossible from this state.

Implemented gates

  • signed source commit/tree, base commit/tree, PR, workflow, run, attempt, actor, and triggering-actor binding;
  • unique exact-head pull_request run, current strict-main freshness, open/non-draft/clean PR, and exact live protected-context set;
  • exact 16-job inventory paired with check-run IDs, suite, head, conclusion, and Actions app ID 15368;
  • exact attempt-scoped TSan artifact ID/name/API digest/downloaded ZIP digest and strict zero-report receipt;
  • two isolated builds with all six executable hashes required byte-identical;
  • exact 14-file bundle, provenance, manifest, OCI descriptor graph, source labels, and six binary labels;
  • schema-3 canonical publication authority bound to complete Core, packaging, publication-tooling, artifact, OCI, registry, executable, exclusive-writer, and nonce/time identities;
  • signed exact-six-file publication snapshot and full prepare-state revalidation;
  • durable crash-safe one-use nonce ledger and root-owned mode-0600 Skopeo authfile contract;
  • fixed safe PATH, absolute trusted tools, curl --disable, compressed ZIP cap, stopped-container host-side executable hashing, and no candidate execution;
  • skopeo copy --preserve-digests, exact source/remote manifest bytes, same-response digest verification, digest-refetch equality, and fail-closed ambiguous-copy handling; and
  • complete schema-2 result/handoff cross-binding, including immutable durability image reference qqblackcoin/blackcoin-v4-gui@sha256:<manifest>.

Validation at current head

  • Publication schema-3 authority/hostile fixtures: pass.
  • Disabled publication wrapper no-live-tools sentinel: pass.
  • Publication static/package seal: pass.
  • Candidate metadata hostile suite: 34/34 pass.
  • Core-CI receipt hostile suite: 14/14 pass.
  • Candidate package fixture/static/seal suite: pass.
  • Standard repository file lint, actionlint, ShellCheck, Bash syntax, Python compilation, JSON/YAML parsing, checksum seals, and git diff --check: pass.

Remaining stages

The exact Core candidate remains 0e62ec0af3daefba30f87382d9b3cc8b00224e62, tree d460eee11b7c8c6d5fffe6935f2e9a5d58e18aac, run 31710198720, attempt 1. Its TSan job is green with a verified zero-report artifact, but the overall run remains 15/16 while ASan/UBSan is still running. Only after that last protected job succeeds and the publication audit is green may a later signed commit atomically pin H/T, terminal run/attempt, exact TSan artifact, and the distinct base/source workflow digests and enable dispatch. This draft authorizes no build, registry push, canary, or fleet deployment.

@Blackcoin-Dev Blackcoin-Dev changed the title ci: build exact Gold Rush hotfix candidate ci: build exact v30.1.5 canary candidate Aug 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant