mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
The kas configuration takes the pinned-remote meta-openglow block, with its commit in the lock file (d655e1e, the read-only rootfs), so a fresh clone builds the release without a sibling checkout. The lock keeps the upstream layers where they were. releases/v0.0.1 carries the acceptance artifact the bench exported for this image: campaign c-20260909160235-7649 on 20260909150456, 83 tests, 83 satisfied, none inherited, release authorized. The release gate recomputes every test's fingerprint from the manifest inside the release rootfs and signs only when the recorded results agree.
Release acceptance artifacts
One directory per release, v<version>/, holding the acceptance.json and
acceptance.md that forgetest exported on the bench for that release.
scripts/release.sh refuses to sign a release whose artifact does not
authorize the built rootfs; see https://docs.forgefirm.org/developers/acceptance/.