Skip to content

[WP02 · SubStep 02.04] Expose ArcNotes compiled build identity and independent versions - #7

Merged
deku2026 merged 2 commits into
mainfrom
codex/wp02-04-version-identity
Sep 21, 2026
Merged

deku2026 merged 2 commits into
mainfrom
codex/wp02-04-version-identity

Conversation

@deku2026

Copy link
Copy Markdown
Contributor

ArcNotes now exposes --build-info --evidence PATH before UI or host startup. Its compiled source/run/timestamp identity and embedded inputs report all nine independent version axes, with explicit future-owner absences. Portable preparation executes the actual candidate, and archive verification rejects missing or changed metadata even if outer hashes are recomputed.

Consumes the already published and verified Build.Policy 1.0.0-ci.20.1; Contracts remains 1.0.0-ci.36.1. All four owned assemblies receive identity metadata and CI verifies their actual PE attributes. Existing application IDs, transport behavior and five-platform native UI/live gates remain in place.

Validation: locked restore, formatting, Release build, provenance/licence checks, 109 tests, actual four-assembly PE inspection, runtime environment-independence check and wrong-source build rejection passed. The clean committed Windows x64 Native AOT candidate passed offline identity retrieval, native UI/live Cloud success/error checks and archive packaging locally. Five native CI hosts, security gates and merged-main public release verification remain required before closure.

Authority: ArcForges-Design PR #52, WP02.04 version identity profile. This is foundation support metadata, not commercial product acceptance.

Signed-off-by: sammiller <dekueon@gmail.com>

@deku2026 deku2026 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the complete 21-file change at 2df6de8 against the accepted WP02.04 profile. No remaining actionable finding in this revision.

Verified independent source resolution for all nine axes, honest future-producer states, compiled metadata on all four owned assemblies, no runtime environment reconstruction, offline entry before host/UI initialization, exact Build.Policy-only version upgrade, preserved Contracts pin and application/protocol identities, closed source inventory, and portable archive validation including rehashed internal metadata tampering. The repository tool reuses the owner-local core resolver; no sibling source reference was added. Expected source/run/release values are obtained independently of the executable under test.

Local evidence: locked restore/format/build and provenance/licence gates passed; 109 tests passed; actual PE metadata of all four assemblies passed; runtime environment override did not alter the report; a wrong declared Git source was rejected by AFB001. Clean Windows x64 Native AOT candidate 0.1.0-ci.0.1 passed offline identity, actual native UI/live Cloud greeting/boundary/error checks and archive packaging against Cloud revision 8942437a5e42c01ae7595b64a220efd60f33b4f0.

Merge remains gated on all applicable checks of this exact PR head. Merged-main public archive and runtime verification remain a separate required step.

Signed-off-by: sammiller <dekueon@gmail.com>

@deku2026 deku2026 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up review: found and fixed a false-positive risk in the invalid-catalog test fixture. Reads for non-target inputs now succeed, so rejection must come from the intended validation rule. The complete final diff was reviewed again; the follow-up changes tests only. All 109 tests, formatting and Release build passed after the repair. No remaining actionable finding; merge only after the latest-head CI is green.

@deku2026
deku2026 merged commit 0c797e3 into main Sep 21, 2026
13 checks passed
@deku2026
deku2026 deleted the codex/wp02-04-version-identity branch September 21, 2026 22:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant