mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
Release acceptance gate: release.sh refuses to sign without a matching artifact
scripts/acceptance-gate.py recomputes every catalog test's domain fingerprint from /etc/forgefirm-manifest.json inside the release rootfs and requires the committed releases/v<version>/acceptance.json to carry a matching PASS (inherited results not core and newer than the invalidate epoch; the artifact self-hashed; the catalog identical to the tree). release.sh runs it after the build and stages the artifact as a release asset; FORGEFIRM_ACCEPTANCE_SKIP=1 bypasses loudly. scripts/manifest-from-tree.py builds the same manifest from the recipe pins with git for CI and the workstation; forgetest-ci.yml runs the unit tests and enforces the coverage lint (every manifest path covered by some test). docs/ACCEPTANCE.md is the contract; the coverage currency rule and the status live in BRINGUP.
This commit is contained in:
@@ -148,8 +148,13 @@ demonstrably untouched.*
|
||||
command (`--publish` runs it where gh is authenticated). Gates:
|
||||
clean tree, version single-source, rootfs-vs-slot size
|
||||
(warn ≥ 170 MiB / fail ≥ 195 MiB, under bitbake's own hard cap),
|
||||
**installer-embedded pubkey must match the signing key**, and
|
||||
factory-era fwup (0.14.2) verification of the packed archive.
|
||||
**installer-embedded pubkey must match the signing key**,
|
||||
factory-era fwup (0.14.2) verification of the packed archive, and the
|
||||
**release acceptance gate**: `releases/v<version>/acceptance.json`
|
||||
(exported by forgetest on the bench) must authorize the built rootfs
|
||||
per `docs/ACCEPTANCE.md` - the gate recomputes every catalog test's
|
||||
domain fingerprint from `/etc/forgefirm-manifest.json` inside the
|
||||
release ext4. The artifact is attached to the GitHub release.
|
||||
- One version source: `FORGEFIRM_RELEASE` = git tag =
|
||||
`/etc/forgefirm-version` = `.fw` meta-version; the script enforces
|
||||
agreement.
|
||||
|
||||
Reference in New Issue
Block a user