Enforce ArcSlate source and portable release provenance - #4
Conversation
|
Complete review of Reviewed all 21 changed files, every record and target binding, file-level terms/attribution, policy/template/inventory, history selection, actual archive inspection and implementation documentation. The four imported C# files were independently compared to their exact current-owner source and differ only by ArcNotes/arcnotes to ArcSlate/arcslate substitutions. The previous tools were compared before replacement, protecting owner-specific behavior. Full Apache terms and original attribution remain. No application, lock, package, protocol or signing change is present. All required local checks and 89 tests pass. Independent Apache and C# provenance checks agree on all 76 files, twelve reused targets, nine records and NOTICE digest. The actual Windows native window, live Cloud evidence and portable ZIP were inspected and passed. Security/workflow checks are clean. Five-host final-head CI and post-merge public distribution verification remain mandatory and are not claimed by this local review. |
|
Post-merge closure verified for All eleven public release assets were independently downloaded and their actual sizes/digests verified. All five archives and fifteen verification members match the tested CI bytes. Independent C# archive verification passes for exact legal text and clean matching source receipts. Each host's source and licence evidence identifies the merge commit. Runtime evidence is the five actual main CI native/UI/live tests on those byte-identical public candidates, plus the completed local pre-merge Windows test; no separate post-download local execution is claimed. The retained worktree contains |
ArcSlate now checks source reuse and portable release provenance under WP00.03. All 76 files are classified; nine complete immutable records bind twelve reused targets. The C# provenance/release tooling and tests come from reviewed merged ArcNotes
e40423a1b14ce8341de35748cc2a093c7c9b77a7with exact product-identity substitutions, recorded before introduction. Original Apache attribution and full legal terms remain present alongside AGPL licensing.CI validates trusted-base record history, complete fields, file hashes and deterministic notices. Native staging requires clean reviewed source. Pack and release verification inspect real ZIP/tar members, full legal bytes and clean source receipts, rejecting missing/changed notices, source mismatches, duplicate/case-colliding paths, traversal and links even with matching outer hashes.
cb261cb5c2924b998b8e2dcd7310432d170e36fe: button-triggered greeting, Unicode/size boundaries and InvalidArgument/ResourceExhausted, against deployed Cloud2cf5a58633a7e09db05ebc1741f1cab83547a832. The native screenshot was inspected.0.1.0-ci.0.1ZIP passes legal/source verification, SHA-256429f90c144664efeb52c83e9b380c488b9fd797c05d09c449810398140bb720a.Design authority is
5322d698a1b650a52a5a139d986dd85b00b48581. Native Avalonia/Skia UI, package/lock versions, transport, application identity and signing behavior are preserved. No retired initialization source or sibling-source build dependency is used. This is the current provenance contribution, not completion of later media workflows or commercial activation. Branch, worktree and evidence are retained.