Skip to content

feat: add verified official package catalog - #16

Merged
tifycloud merged 1 commit into
mainfrom
codex/expand-component-catalog
Jul 21, 2026
Merged

tifycloud merged 1 commit into
mainfrom
codex/expand-component-catalog

Conversation

@tifycloud

Copy link
Copy Markdown
Owner

Summary

  • add locked OpenWrt 25.12.5 official package catalogs for x86_64, Xiaomi AX9000 official, and AX9000 NSS
  • expose 10k+ searchable packages per supported official target while blocking unsafe/base-pinned entries
  • verify every lazy-loaded shard with SHA-256, strict schema, architecture, feed, risk, and selectable policy
  • make browser and Python resolver produce the same normalized build request and request hash
  • add verified in-memory shard caching, target/flavor race protection, 120ms search debounce, and a 100-result DOM cap
  • validate and safely stage exactly three package shards in the Pages workflow

Catalog sizes

  • x86_64 official: 10,947 packages / 10,722 selectable
  • Xiaomi AX9000 official: 11,154 packages / 10,857 selectable
  • Xiaomi AX9000 NSS: 3,903 packages / 3,902 selectable

Verification

  • ./tests/test_static.sh
  • focused component/package/staging/UI/Pages/custom-build policy suites
  • real frontend ↔ Python resolver hash contract across defaults, bundles, package-only, mixed, AX9000 official, and NSS selections
  • real browser loading/search/select/target/flavor switching against the generated catalogs
  • independent production/security review: APPROVE after fixing Pages path triggers for resolver and shared package policy

Scope

This intentionally aggregates locked official OpenWrt feeds only. Arbitrary third-party package feeds are excluded from the production-safe catalog.

@tifycloud
tifycloud merged commit afaaeec into main Jul 21, 2026
4 checks passed
@tifycloud
tifycloud deleted the codex/expand-component-catalog branch July 21, 2026 05:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant