Skip to content

[v0.17 REL-MAN] Bind native release manifests and recover catalog delivery #1671

Description

@TheGreenCedar

Package REL-MAN in the v0.17.0 consolidated remediation program.

Contract

Deliver W8.4, W8.6b, and W8.11 as the publication unit: candidate-pinned marketplace proof and previous catalog SHA, catalog recovery semantics in machine policy, a release-generated manifest carrying target/archive length/SHA-256 and release identity, launcher consumption before extraction, and optional Ed25519 arming with rotation/revocation and no unsigned fallback once armed.

Discharge W8.6a's intentionally provisional source-pin assertion by lane:

  • plugin-source provision proof continues to require the pinned archive digest already carried by the source pin;
  • native frozen-head/pre-publish provision proof consumes the staged release manifest that owns the native archive digest, or defers that digest assertion to the post-release manifest proof;
  • the native lane must never run the current unconditional source-pin archive assertion, because a lawful native pin has no archive digest.

Dependencies

REL-CI and W8-A. Key ceremony is not a v0.17 blocker; current release_gate:false semantics must change before automatic rollback/recovery can be claimed.

Program boundaries

  • The implementation PR uses a codex/* branch, targets dev/codestory-next, and carries this issue as Closes #N.
  • Keep source, package, protected-host, installed-runtime, and publication proof distinct.
  • Preserve atomic old-or-new publication, pinned readers, crash recovery, content-verified freshness, fail-closed evidence, observational status/doctor, accelerated embedding without CPU fallback, proof-owned cleanup, and serial Cargo execution.
  • Do not touch product version surfaces. The release lane owns the single synchronized version change after implementation is integrated.
  • Run focused proof while iterating and the owning path gate on the accepted candidate; broad source proof remains once on the frozen release candidate.

Done when

The frozen source contains no circular native digest; release-built bytes are manifest-bound; plugin and native provision proof each assert the digest source their lane actually owns; the frozen native head cannot fail solely because its lawful source pin lacks archive digests; digest-only containment is stated until signatures arm; catalog published/deferred/recovered identities remain distinguishable and rollback behavior is executable before docs claim it.

Refs #1233
Refs #1179

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:p1Release blocker or high-risk reliability/security issuetype:contractRuntime, CLI, API, or evidence contract work

    Projects

    Status
    Todo

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions