Enforce source and native package provenance for WP00.03 - #50
Conversation
|
Full self-review of Reviewed all source and workflow changes, source inventories, legal bytes, generated declarations, all native records/profiles and their immutable predecessors, toolchain overlays, packaging/inspection paths, negative tests and documentation. The 36 upstream component identities, package catalogue and owned C ABI remain unchanged. All 42 initial records are retained byte-for-byte; revised records explicitly supersede them. The review found and fixed two concrete issues: the existing native-artifact rejection diagnostic was lost, and a metadata-prefix exemption admitted unrecorded NuGet resources. The final metadata allowlist names exact producer files; tests reject both an extra script in metadata and an extra nested nuspec. Another collection finding was that development builds used different local generators/compiler selection; those artifacts were not used for acceptance. The entire dependency closure and owned CMake outputs were rebuilt with the reviewed pins after the narrow Design repair was merged. Final source audit: 316 files, ten reused source files, 79 immutable records, 42 active records, clean source No remaining actionable findings in this scope. PR CI and post-merge publication are still required; this review does not replace them or claim product readiness. |
|
Reviewed the complete added change through CI failure All 41 provenance tests pass. The final clean source inventory has 353 files, 10 reused targets, 115 historical records and 42 active records. Both actual Meson receipts pass. Existing immutable source/legal evidence, source history, actionlint and gitleaks pass. Candidate No actionable finding remains in the complete local change. All applicable hosted CI must pass on this new head before merge; main publication and exact public package verification remain pending. GitHub refused its combined diff endpoint at the 20,000-line limit. The complete paginated PR file list and every remote file blob SHA were therefore independently matched to the reviewed base/head Git objects; all 147 files match. No file was omitted from review. |
|
Post-merge verification complete for
Detailed local evidence: |
The current source tree and native NuGet producers could accept reused material without a complete, immutable provenance record. WP00.03 now checks every source file and records the actual native artifact closure: 36 upstream components, full applicable notices and corresponding sources, 174 port recipes, four toolchain definitions, and the separately reviewed Microsoft runtime binaries. Candidate inspection rejects changed or unrecorded members, including files disguised as NuGet metadata.
The producer verifies actual CMake caches, installed vcpkg ABI records, compiler paths and runtime signatures. Minimal overlays of the existing standard triplets pin MSVC 14.51.36231; dependency builds use CMake 4.4.0 and owned wrappers retain CMake 4.3.3/Ninja 1.13.1. This follows merged Design PRs #23 and #24 (authority
5322d698a1b650a52a5a139d986dd85b00b48581). Existing records remain immutable through superseding revisions. The exact Meson helper recipe has two verified SPDX forms: an empty resource list when the patched tool already exists, or the single reviewed Meson source archive on a cold build. Profile revision 3 admits only those forms and preserves strict URL/hash and runtime-resource validation. The Apache provenance checker and original tests retain their exact Contracts source record and licence.win.slnx Release|x64with zero warnings/errors; both actual CMake profiles, four CTest cases and managed P/Invoke; actionlint and gitleaks.1.0.0-wp00.3.b0a09a7, sourceb0a09a7990860a54e3b1dcbeddcd18cc24265daa: ten NuGet archives passed twelve package guard tests, isolated Build.Policy smoke, five JIT and five Native AOT cases, and one independent C17 executable covering all four native ABIs. Wrong RID, missing owned/transitive DLLs and changed DLLs are rejected. The full evidence and candidate archives remain in the retained worktree.visualCppRuntime.versionsemantics are retained alongside explicit directory and actual file versions.