Repository navigation
Conversation
zoeyrose
added a commit
to atrinik/protocol
that referenced
this pull request
Oct 4, 2026
## Summary Prepare the unpublished Rust 0.2.0 crate for a separately reviewed registry activation, and fix the release download layout exposed by v2.6.0. The published v2.6.0 assets remain unchanged. Its 33 downloaded assets match their GitHub digests and all 32 flat checksum entries pass, but its checksum manifest also names 30 nested fixtures absent from the GitHub asset list. Those fixtures are present in the source archive. ## Implementation / behavior - Produce a deterministic contract bundle containing the full contract layout, nested fixtures and internal checksums. Keep the outer release directory flat, with every downloadable asset covered by the outer checksum manifest. - Prepare Cargo source for crates.io while keeping the candidate explicitly unpublished. Preserve the immutable published 0.1.0 release coordinates and checksum. - Add a manual preparation-only workflow. It has no OIDC permission, registry credentials or upload job. The pending artifact policy contains no predicted source revision or digest. - Validate an actual published tag and exact source revision against local/public Git identity and release provenance; package twice with Rust 1.97.1; check identical bytes, package inventory, clean VCS metadata and registry-only dependencies. - Emit the actual crate and artifact pins for the next review. The verifier also provides credential-free checks for later pinned release assets and public API/sparse-index checksums; it never uploads. ## Validation At `fec06675d996c41e2802a3c8e71d6239733773b2`: - Full `tools/validate.sh` passed in the pinned Atrinik Linux build image `sha256:7904a1802054662b0ede5b55de72e4c92b0112a3c211125f994ed6c62e9ec9d8`, with Go 1.26.6 and Rust 1.97.1. - Workflow actionlint, shell lint and full-base whitespace checks passed. The full aggregate also passed with the pull-request CI environment variables set. - Tests cover flat publish-glob discovery, complete outer/internal checksum inventories, omitted/tampered files, redirected fixture roots, disabled activation, malformed artifact pins, source-tag drift, crate provenance/dependency boundaries and registry checksum conflicts. - Independent review approved the implementation and the final test-only CI-environment correction. Required GitHub checks `Protocol validation` and `Conventional PR title` passed on this exact head and accepted base. ## Limitations / follow-up This is the preparation source change, not registry activation. v2.6.0 still has Cargo publication disabled and cannot supply publishable bytes without changing them. Actual released-tag preparation therefore follows a separately approved source merge/release and manual preparation dispatch. The next activation PR must use the real prepared source release, revision, asset and checksum, and add the reviewed Trusted Publishing upload job. Exact release-asset attachment, environment/Trusted Publisher setup and publication dispatch each retain their authorization boundary. Governance preparation is tracked in [atrinik/github-settings#86](atrinik/github-settings#86); access-token consumer coordination remains in #43. No release asset, environment, registry configuration or package was changed. No merge, dispatch or publication is authorized by this PR. Consumers still need the actual registry release and normal dependency-lock validation.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Record the pending Trusted Publishing contract for the
atrinik-protocolcrate so its future manual release workflow has an exact action allowance and reviewable environment policy.Implementation / behavior
rust-lang/crates-io-auth-action@c6f97d42243bad5fab37ca0427f495c86d5b1a18, verified as upstreamv1.0.5.atrinik/protocol(repository ID1327106950),publish-crate.yml,workflow_dispatchonrefs/heads/main, andcrates-io-release.zoeyrose(User ID3865595) as environment reviewer, permit the existing solo-maintainer review flow, disable administrator bypass, and require no environment secrets or variables.PENDING; the publisher only reports the manual follow-up.Validation
d819290f3183d050c599dcbc2d1216aede6aeaea; the reviewer independently reran the schema mutants, full manual-verifier fixture and repository validator.Limitations / follow-up
This draft applies no policy and creates no environment or Trusted Publisher. It performs no workflow dispatch, crate publication or merge. The protocol workflow and actual published source-release proof remain separate activation prerequisites.
The unmodified proposal's live publisher plan and audit correctly stop because
atrinik/service-updateris live but absent frommain's inventory; #85 supplies that dependency. The combined plan used temporary copies of #85's inventory files and is not evidence that this proposal alone can currently apply. The complete live manual-settings verifier stops earlier on pre-existing Classic Pages source drift; its overall live result is not passing. New crate identity checks were verified separately, and fixture coverage passes.