Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/ISSUE_TEMPLATE/release-qualification.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,14 @@ body:
placeholder: "v1.2.3"
validations:
required: true
- type: textarea
id: self-update-published-e2e
attributes:
label: Published-release self-update E2E
description: Record the previous release, exact published candidate tag, source commit, signed GitHub CLI version/publisher, command, and complete sanitized JSON result from scripts/qualify-self-update-published.ps1.
render: text
validations:
required: true
- type: textarea
id: cell-powershell51-current
attributes:
Expand Down
44 changes: 43 additions & 1 deletion docs/release-matrix.md
Original file line number Diff line number Diff line change
Expand Up @@ -193,7 +193,49 @@ So CI validates compilation and pure/unit logic on a GitHub-hosted Windows
runner. The matrix is what validates the `docs/shell-contract.md` semantics on a
real Windows 11 + Docker Desktop host before a release.

### Live self-update attestation verifier check
### Live published-release self-update qualification

The repository includes a Windows/amd64 harness that builds the current source
with an injected earlier version, installs isolated hardlink and byte-identical
managed shims, and updates that private installation to an exact canonical
published release.

For a release candidate, set the source version to the previous supported
release and the target to the exact already-published candidate tag, then retain
the emitted JSON in the release-qualification issue:

```powershell
$previousVersion = 'v1.1.0'
$candidateVersion = 'v2.0.0-rc.1'
$env:GH_TOKEN = gh auth token --hostname github.com
pwsh -NoProfile -File .\scripts\qualify-self-update-published.ps1 `
-FromVersion $previousVersion `
-TargetVersion $candidateVersion `
-GitHubCLI (Get-Command gh.exe).Source
```

Run it from the repository root. `go` may be a native executable or a
ContainerBin shim; the harness sets the intended repository working directory
and explicit Windows/amd64 build target in the same child process. The selected
GitHub CLI must be the official Authenticode-valid executable, and an explicit
`GH_TOKEN` or `GITHUB_TOKEN` is required. The harness never prints the token.

This exercises release selection, canonical bounded downloads, checksum and
GitHub build-provenance verification, the private helper handoff, repeated
verification after the parent exits, transactional replacement, bootstrap
version smoke testing, hardlink reconciliation for both originally hardlinked
and byte-identical shims, bounded child-process execution, and an exact
post-transaction survivor allowlist that catches staging/helper/rollback
directories, replacement temporary files and mutation-lock residue. It uses a
unique system-temp installation and removes only that validated path.

Qualification evidence on 2026-10-04: current `main` at `e625ab6` was built as
`v1.0.0` and updated to the canonical published `v1.1.0` release on native
Windows/amd64. The exact published asset (`cb.exe`, 3,383,808 bytes), checksum
manifest and GitHub Actions provenance passed; both managed shims were
reconciled as hardlinks and no private update artifact remained.

### Lower-level live attestation verifier check

`internal/selfupdate` includes an opt-in native-Windows integration test for the
external verifier boundary. It must be run with an Authenticode-valid GitHub CLI
Expand Down
10 changes: 7 additions & 3 deletions docs/roadmap-decisions.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ items from being repeatedly rediscovered as if they were immediately actionable.
| Image trust | **Policy-driven Sigstore/cosign at lock time** | Ready after signed-registry policy. Digest locking remains default where policy permits. Required trust never silently falls back to digest-only. |
| Per-project overlays | **Explicit digest-bound, add-only trust model** | Implementation-ready on the merged policy foundation. Initial overlays exclude host mounts, env prefixes and shared cross-project volumes. |
| Plugin/provider architecture | **Intentionally deferred** | Reopen only after at least two concrete integrations cannot be expressed safely by the declarative model. |
| RM-31 self-update | **Explicit transactional, attestation-verifying update** | Selection/check, staging, verification, ARM64 artifact selection, the private wait helper and explicit apply wiring are implemented. Real published-release E2E remains. |
| RM-31 self-update | **Explicit transactional, attestation-verifying update** | Selection/check, staging, verification, ARM64 artifact selection, the private wait helper and explicit apply wiring are implemented. A repeatable Windows/amd64 published-release E2E harness now qualifies the complete current-source-to-v1.1.0 transaction; future release candidates must rerun it against their exact published target. |
| RM-30 Authenticode | **Design accepted; externally blocked** | Implement only after a real code-signing certificate and protected signing mechanism exist. Stable and prerelease release artifacts are both signed. |
| RM-29 Windows ARM64 | **Lowest priority** | Native GitHub Windows ARM64 CI shipped in PR #78, reproducible release packaging in PR #86 and ARM64 self-update selection in PR #91. Real Windows-on-Arm + Docker Desktop qualification remains. Do not delay other roadmap work. |
| Standalone Linux/macOS | **Demand-gated** | No support claim yet. WSL should create reusable narrow Linux host abstractions, but standalone hosts require their own contract and real Docker qualification. |
Expand Down Expand Up @@ -330,14 +330,18 @@ is not completion.
inputs;
- explicit private-registry credential bridging remains.

2. **Remaining RM-31 self-update qualification**
2. **RM-31 self-update qualification**
- selection/check, bounded staging and `gh attestation verify` are merged in
PRs #76, #81 and #82;
- ARM64 archive selection, verification and exact extraction are merged in
PR #91;
- rollback-safe Windows transaction, managed-shim reconciliation, the
temporary wait helper and user-facing apply wiring are implemented;
- real published-release/self-test E2E remains.
- the repeatable Windows/amd64 qualification harness covers a complete
current-source-to-canonical-published-release transaction, including
provenance, helper handoff, replacement, shim reconciliation and cleanup;
- it passed against canonical v1.1.0 assets on 2026-10-04; each future
release candidate must rerun it against that exact published target.

3. **Remaining WSL2**
- narrow reusable Linux host interfaces, fail-closed boundary and native
Expand Down
10 changes: 6 additions & 4 deletions docs/roadmap-implementation-requirements.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ The minimum delivery gate for a code change is:
| RM-26 Python global CLI exposure | **Completed in PR #74** | Stateful pipx + `cb expose pipx` shipped; plain pip `/venv/bin` remains intentionally unexposed |
| RM-29 Windows ARM64 | **Native CI, release packaging and update selection shipped / hardware work remains** | PR #78 added native hosted ARM64 CI, PR #86 added reproducible release packaging and PR #91 added ARM64 self-update selection; real Windows-on-Arm + Docker Desktop E2E remains |
| RM-30 Authenticode | **Design complete / externally blocked** | Provision real code-signing certificate and protected signing mechanism |
| RM-31 self-update | **Core pipeline shipped / explicit apply implemented** | PRs #76, #81, #82 and #91 shipped the read-only plan, fail-closed staging, provenance verification and ARM64 artifact selection; this tree adds the rollback-safe replacement transaction, protected wait helper and explicit user-facing apply wiring. Real published-release E2E remains |
| RM-31 self-update | **Core pipeline and repeatable published-release E2E implemented** | PRs #76, #81, #82 and #91 shipped the read-only plan, fail-closed staging, provenance verification and ARM64 artifact selection; this tree adds the rollback-safe replacement transaction, protected wait helper and explicit user-facing apply wiring. The Windows/amd64 harness qualifies the complete transaction against a canonical published release and must be rerun for each release candidate |
| RM-34 Cargo expose enhancement | **Intentionally deferred** | Existing expose-all/explicit selection are sufficient; reopen only for concrete unmet use case |
| Linux/macOS hosts | **Demand-gated** | WSL may factor reusable Linux host code; standalone support needs its own demand and qualification |
| Enterprise policy | **Foundation and signed registry shipped / image trust remains** | PRs #75 and #84 shipped the machine-owned constraint layer and authenticated registry; image trust remains |
Expand Down Expand Up @@ -404,7 +404,8 @@ also selects, stages and verifies the Windows/arm64 archive from native
`GOARCH`; unsupported architectures still fail closed. This tree also
implements the rollback-safe Windows replacement transaction, complete
proven-shim reconciliation, protected wait helper and explicit user-facing
apply wiring. Real published-release E2E remains incomplete.
apply wiring. A repeatable native-Windows/amd64 qualification harness now
exercises the complete transaction against a canonical published release.

### Command and selection requirements

Expand Down Expand Up @@ -467,8 +468,9 @@ ABSOLUTE_GH_EXE` is now wired through private same-volume staging and a
protected copy of the proven installed binary. The helper waits for the parent,
re-verifies the staged artifact and bound identities, then enters the serialized
rollback-safe transaction. Unit/native-Windows CI covers the process boundary;
the remaining acceptance gate is real published-release E2E across the manual
release matrix.
the complete Windows/amd64 path passed against canonical v1.1.0 assets on
2026-10-04. Release candidates must rerun the harness against their exact
published target and retain the result with the manual release-matrix evidence.
Comment thread
AviBackToBlack marked this conversation as resolved.

## Linux and macOS hosts

Expand Down
Loading
Loading