Conversation
871c6d9 to
8b28842
Compare
Current hosted ARM gateThe stacked source and shell matrices pass at This is the strict policy working as designed. Do not relax it or merge this PR ahead of #435. Merge and publish the rc4 trust bootstrap first, verify the key on the canary, merge omarchy-mac/omarchy-pkgs-aarch64#26 and publish the complete signed 52-package/database baseline, then rerun this ARM job. A green rerun will be evidence that the same stacked rc5 source can perform a fresh strict install from the signed lane. |
8b28842 to
226f2ee
Compare
Problem
This is the second half of the fork signing transition. The rc4 parent branch delivers and populates
omarchy-mac-keyringunder the final disclosed unsigned transaction. This stacked change makes 4.0.3rc5 the signed candidate and refuses unsigned or untrusted fork packages and databases.Changes
4.0.3rc4to4.0.3rc5; the signed candidate must be rebuilt and cannot reuse rc4 archives.PackageRequired DatabaseRequired TrustedOnlyforomarchy-aarch64only.Optional TrustAllstanza. Other repositories and the active configuration remain unchanged during preflight.pacman-conf.Validation
Stack and release order
Base:
codex/release-4.0.3-rc-20260913/ PR #435.Do not merge or publish this ahead of the rc4 trust bootstrap. After rc4 is installed on the canary, seal and publish the complete signed 52-package repository/database, then build rc5 from this exact source and run fresh, rc4-to-rc5, skipped-bootstrap, reboot, desktop and rollback checks. Publish only to
rc; stable promotion requires the canary result and separately rebuilt final bytes.No package, lane or stable release is published by this PR.