Establish public verified release boundary
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
# Requirements
|
||||
|
||||
## distribution
|
||||
|
||||
001 The repository must remain public and contain only installers, manifests, checksums, and built release artifacts derived from private source repositories.
|
||||
002 The stable `channels/main/ink` path must contain the latest verified Ink core asset and checksum published from the private Ink main branch.
|
||||
003 The stable toolset channel must contain verified individual assets, a set manifest, and checksums from the private main branch.
|
||||
004 A source release tag must publish the same source-owned files under `releases/TAG/ink` or `releases/TAG/toolset` without modifying the other source subtree.
|
||||
005 Every executable artifact must be a static x86_64 Linux-musl executable and must pass `--help` inside Void Linux musl before publication.
|
||||
006 Every published manifest must identify its source repository, source commit, target, executable, set, byte count, digest, and asset path.
|
||||
007 Publication must fail closed before changing this repository when build, test, static-artifact inspection, checksum, or Void Linux runtime proof fails.
|
||||
008 This repository must never contain source-repository credentials, deploy keys, private source, Ink policy, shell configuration, or user credentials.
|
||||
|
||||
## installer
|
||||
|
||||
001 The root `install.sh` must install Ink and only explicitly selected tool assets from public repository paths after SHA-256 verification.
|
||||
002 Without a terminal or selection flags the installer must install Ink only; with a terminal it may present a compact native text menu.
|
||||
003 The installer must support exact tool and named set selection without downloading unselected executable assets.
|
||||
004 The installer must write only selected-prefix executables and must not edit PATH, shell configuration, policy, or credentials.
|
||||
005 Installer help must completely document options, environment, effects, defaults, examples, and platform support.
|
||||
006 The installer must support the stable main channel and immutable matching source-release tags.
|
||||
|
||||
## governance
|
||||
|
||||
001 `REQUIREMENTS.md` must remain authoritative; code, workflows, tests, runtime, and source repositories are evidence.
|
||||
002 Durable behavior changes must update requirements before implementation and proof.
|
||||
003 `req:` references must provide traceability; only accepted local executable `test` edges satisfy proof coverage.
|
||||
004 Work is tracked in Gitea Issues for `tmk241/ink-releases`; agents must not mirror issues locally or mutate tracker state without explicit authority.
|
||||
Reference in New Issue
Block a user