[WP02 · SubStep 02.04] Add ArcSlate independent version and build identity - #7
Conversation
|
Full review at 5cd02cd: reviewed the complete 24-file patch, actual source catalog, independent source/run checks, embedded resource paths, runtime offline entry, PE metadata checks, archive member validation, tests and workflow. No remaining actionable finding. Independently reconstructed all 16 adapted inputs from ArcNotes 0c797e30690a10d8798ddca19ca7f37b16cecf01, including ArcSlate media/storage declarations and the preserved checkout option ordering; compared every r2 hash. The immutable predecessor, full AGPL terms and original Apache tooling attribution remain intact. Portable README retains corresponding-source attribution. All existing resolved versions and package hashes remain unchanged except the required Build.Policy 1.0.0-ci.20.1. The tool's local Core reference introduces only the already pinned client dependencies. Contracts remains 1.0.0-ci.36.1 and its wire schema major remains distinct. No sibling source, transport, startup, retry or signing behavior changed. Local checks passed: 109 tests, locked restore, format/build, four actual PE identities, provenance/licence inventory, mismatched-source rejection and runtime environment independence. Native AOT candidate and all PR CI gates must pass before merge; merged-main public-byte/runtime verification is separate. Clean Windows x64 Native AOT staging, offline identity, actual native UI/live Cloud success/error checks and archive packaging subsequently passed for this exact reviewed commit. |
ArcSlate now exposes an offline build-info command from compiled assembly metadata and embedded version sources. Portable candidates retain that report and reject source/run, version-axis or internal archive tampering; every owned assembly is checked from its actual PE metadata.
The nine version axes have independent sources and explicitly identify unimplemented future producers. This consumes verified Build.Policy 1.0.0-ci.20.1, preserves all other package versions and app/transport identities, and records the reviewed ArcNotes adaptation in immutable provenance r2 while retaining r1.
Validation: 109 tests, locked restore, formatting/build, provenance/licence checks, four compiled assembly identities, wrong-source rejection and runtime environment independence passed. A clean Windows x64 Native AOT candidate passed offline identity, actual native UI/live Cloud success/error scenarios, and archive packaging. Five native CI hosts and security checks must pass before merge; merged-main public-byte and downloaded runtime verification follows separately.