test(release): strengthen repository verification

This commit is contained in:
tmk241
2026-08-17 07:54:05 +02:00
parent 6f3969f071
commit 1ee3b97f3b
5 changed files with 73 additions and 43 deletions
+26
View File
@@ -0,0 +1,26 @@
# Ink releases current-state specification
# Flat records use component/id<TAB>summary. Git history carries prior states.
distribution/001 The repository must remain public and contain only installers, manifests, checksums, and built release artifacts derived from private source repositories.
distribution/002 The stable `channels/main/ink` path must contain the latest verified Ink core asset and checksum published from the private Ink main branch.
distribution/003 The stable toolset channel must contain verified individual assets, a set manifest, and checksums from the private main branch.
distribution/004 A source release tag must publish the same source-owned files under `releases/TAG/ink` or `releases/TAG/toolset` without modifying the other source subtree.
distribution/005 Every executable artifact must be a static x86_64 Linux-musl executable and must pass `--help` inside Void Linux musl before publication.
distribution/006 Every published manifest must identify its source repository, source commit, target, executable, set, byte count, digest, and asset path.
distribution/007 Publication must fail closed before changing this repository when build, test, static-artifact inspection, checksum, or Void Linux runtime proof fails.
distribution/008 This repository must never contain source-repository credentials, deploy keys, private source, Ink policy, shell configuration, or user credentials.
installer/001 The root `install.sh` must install Ink and only explicitly selected tool assets from public repository paths after SHA-256 verification.
installer/002 Without a terminal or selection flags the installer must install Ink only; with a terminal it may present a compact native text menu.
installer/003 The installer must support exact tool and named set selection without downloading unselected executable assets.
installer/004 The installer must write only selected-prefix executables and must not edit PATH, shell configuration, policy, or credentials.
installer/005 Installer help must completely document options, environment, effects, defaults, examples, and platform support.
installer/006 The installer must support the stable main channel and immutable matching source-release tags.
governance/001 `SPEC.md` must remain the sole authority; code, workflows, tests, runtime, and source repositories are evidence.
governance/002 Durable behavior changes must update the specification before implementation and proof.
governance/003 `req:` references must provide traceability; only accepted local executable `test` edges satisfy strict coverage.
governance/004 Work is tracked in Gitea Issues for `tmk241/ink-releases`; agents must not mirror issues locally or mutate tracker state without explicit authority.