Skip to content

Enforce source provenance and portable archive notices - #4

Merged
deku2026 merged 1 commit into
mainfrom
codex/wp00-03-provenance
Sep 19, 2026
Merged

deku2026 merged 1 commit into
mainfrom
codex/wp00-03-provenance

Conversation

@deku2026

Copy link
Copy Markdown
Contributor

Change

Reused source and legal text now require a complete immutable provenance record before they can pass the existing repository check. WP00.03 accounts for all 77 files, binds nine reused files to nine active records, retains the superseded checker revision, and checks all ten required fields, exact bytes, attribution, history and the closed licence decision table. The existing C# tool implements the reviewed Apache Contracts checker with a recorded rewrite and full original terms. CI fetches the required comparison history and retains the source receipt.

Portable staging requires clean reviewed source and includes the package source summary and receipt alongside the existing full notices. Packing and independent release verification read the actual ZIP/tar entries, require exact recorded legal text and the correct source identity, and reject missing/changed notices, duplicate/case-colliding paths, traversal and links.

Validation

  • .NET SDK 10.0.401 locked restore, formatting, Release build with zero warnings/errors, 89 deterministic tests, all four project licence declarations, naming scan, actionlint and gitleaks pass. The independent Apache checker confirms the same inventory and deterministic NOTICE.
  • The actual Windows x64 Native AOT candidate 0.1.0-ci.0.1 at d6f88d881aa0e0503e136012dfc9a9e8581f0330 passed the native window/button action, live Cloud greeting, Unicode/whitespace/size boundary, InvalidArgument and ResourceExhausted scenarios against deployed Cloud 2cf5a58633a7e09db05ebc1741f1cab83547a832. The rendered native window was inspected. This is programmatic native UI validation, not browser testing.
  • Actual portable ZIP and full legal/source checks passed. Archive SHA-256: d6a0903de99fa901f10da3d43f697de68b05e51896d0b77aca36503adbbb882e. The candidate, screenshots and receipts remain in the retained worktree.
  • Pending: all five hosted native RID gates, review of the final PR head, merge, main publication and exact public release asset verification. These gates remain required.

Release impact

Design authority is merged 5322d698a1b650a52a5a139d986dd85b00b48581. The current ArcNotes repository and exact published dependencies remain the inputs; no retired initialization repository is consumed. Dependency versions/locks, protocol, native Avalonia/Skia UI, application identity and signing behavior are unchanged. No Python/Node runtime or browser UI is added. Hello checks establish this bootstrap's current behavior, not completion of future product or commercial-release requirements.

@deku2026

Copy link
Copy Markdown
Contributor Author

Full review of ce797cd18d368b57dc4c9bc29112a9467172ac6d..d6f88d881aa0e0503e136012dfc9a9e8581f0330 completed against WP00.03 and Design 5322d698a1b650a52a5a139d986dd85b00b48581.

Reviewed all 22 changed files: C# validation and packaging paths, event-derived history, all records and exact upstream legal evidence, source/inventory classification, Apache-to-AGPL source adaptation and preserved terms, generated NOTICE, CI integration, documentation and failure tests. No dependency/lock, application UI, protocol or signing change is present. Current first-party code and dated internal lineage remain separate from actual retained external material; the retired initialization repository was not fetched or used.

The independent renderer exposed a different summary heading in the first C# adaptation; revision 2 corrects it while keeping revision 1 unchanged. Review also found a portable-archive collision risk: a differently cased duplicate could replace a required notice when extracted. Archive member checks now reject duplicate/case-colliding names, traversal and links; tests exercise real ZIP/tar archives with matching outer hashes and deliberately missing, changed, duplicated or wrongly sourced legal evidence.

All 89 deterministic tests, required local checks and the real Windows Native AOT/UI/live Cloud candidate pass. The actual screenshot and source-bound receipt were inspected. No remaining actionable finding in this contribution. All applicable final-head CI and post-merge release verification remain mandatory; this review does not claim those pending gates or later commercial readiness.

@deku2026
deku2026 merged commit e40423a into main Sep 19, 2026
13 checks passed
@deku2026

Copy link
Copy Markdown
Contributor Author

Post-merge verification completed for e40423a1b14ce8341de35748cc2a093c7c9b77a7, version 0.1.0-ci.8.1. Main CI 35425608146, security, five native hosts, publication and publication confirmation passed. The clean primary checkout is pulled to the merge commit; the retained branch tree exactly matches it.

All eleven public release assets were independently downloaded and their actual sizes/SHA-256 digests checked. The five portable archives and all fifteen public verification members exactly match CI candidates/evidence. Independent C# archive checks pass for all five public packages, including full legal bytes and clean source-bound receipts. Main provenance/licence receipts match the merge commit on every native host. All five native UI/live Cloud runs passed against Cloud 2cf5a58633a7e09db05ebc1741f1cab83547a832.

The extra local rerun of the downloaded Windows executable was not performed: automatic approval review rejected the launch with blocked by policy and no specific reason. No alternate launch was attempted. Runtime evidence is the actual five-host main CI execution of the byte-identical candidates and the previously completed local pre-merge Windows test, not a claimed post-download local run.

Evidence is retained under the worktree's artifacts/evidence/post-merge-closure.json, public downloads and main artifacts. Branch/worktree remain. This closes this owner's current provenance contribution, not later product workflows, trusted signing or commercial readiness.

@deku2026
deku2026 deleted the codex/wp00-03-provenance branch September 19, 2026 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant