Enforce ArcScope source and portable release provenance - #4
Conversation
|
Full review of Reviewed all 21 changed files, all nine records and twelve target bindings, exact legal bytes, source lineage, current-owner C# tool/test transformations, CI comparison history, real archive inspection and documentation. The four imported files match the merged reviewed source after only ArcNotes/arcnotes to ArcScope/arcscope substitutions; prior tool/test files were also compared before replacement. The original Apache adaptation and full terms remain accounted for, within this AGPL owner. Source inputs exclude the retired initialization repository. No dependency, lock, application UI, protocol or signing change is present. The independent provenance checker agrees with the C# inventory/NOTICE. All 89 deterministic tests and required local checks pass, including complete records, immutable history and actual ZIP/tar failures with matching outer hashes. The actual Windows Native AOT window, live Cloud receipt and packaged archive were reviewed and passed. No actionable finding remains in this owner contribution. Final-head hosted CI and post-merge public release verification remain required and are not claimed here. Branch and worktree are retained. |
|
Post-merge closure verified for All eleven public release assets were independently downloaded and their actual sizes/digests verified. All five archives and fifteen verification members match the tested CI bytes. Independent C# archive verification passes for exact legal text and clean matching source receipts. Each host's source and licence evidence identifies the merge commit. Runtime evidence is the five actual main CI native/UI/live tests on those byte-identical public candidates, plus the completed local pre-merge Windows test; no separate post-download local execution is claimed. The retained worktree contains |
Change
ArcScope now enforces WP00.03 provenance in its existing C# repository and release tooling. All 76 files are classified; twelve reused targets have nine complete immutable records covering the root/upstream legal text and the reviewed current C# checker, release validation and tests. The four tool/test files come from merged ArcNotes
e40423a1b14ce8341de35748cc2a093c7c9b77a7with only explicit product identity substitutions. The previous ArcScope tool/test baseline was independently compared before the import, and full AGPL/Apache attribution and terms remain present.CI checks trusted-base history, target bytes, complete records, closed licence decisions and notices. Native staging requires clean reviewed source. Packing and independent release verification inspect the real ZIP/tar contents, exact full legal texts and source receipt, rejecting missing/changed notices, wrong/dirty source identity, case collisions, duplicate paths, traversal and links.
Validation
0.1.0-ci.0.1from20ef3920a32602a1fad8bbc622c3fcef29b9dff2passed the button-triggered greeting, Unicode/whitespace/size boundary and both InvalidArgument/ResourceExhausted cases against deployed Cloud2cf5a58633a7e09db05ebc1741f1cab83547a832. The native screenshot was inspected.335f1dc3f4b3b9a84b9651b8e18159de5b8c61d199c3a3e3dbbda1ce9b4ecae2. Receipts and candidate bytes remain in the retained worktree.Release impact
Authority is Design
5322d698a1b650a52a5a139d986dd85b00b48581. Current owner source and exact published packages remain the build inputs; no retired initialization repository or sibling-source build dependency is used. Native Avalonia/Skia UI, dependency versions/locks, protocol, product identity and signing behavior are unchanged. These bootstrap checks do not establish later product or commercial completion.