Skip to content

[G18] Package signed releases and reproducible distribution #18

Description

@jjangg96

Goal

Produce verifiable macOS ARM64 release artifacts with install/upgrade/rollback instructions and accurate preview/stability labeling.

Create one active Codex goal from the statement above when this issue is dispatched. The Project Goal field is a work specification; it does not start an agent. Do not invent a token budget.

Execution contract

Field Value
Goal key G18
Stage M4 - Pilot and release
Initial status Backlog
Primary agent gpt-5.6-luna / max
Priority / risk P1 / Medium
Test profiles offline, trusted-runtime

Use one issue branch/worktree and one focused PR. Independent Luna max review is required for authentication, protocol, concurrency, resource ownership, cleanup or service identity boundaries; other changes need independent contract review. Model fields are routing instructions, not GitHub user assignments.

Dependencies

Dependencies must be Done before implementation begins. A new issue is not blocked simply because its future evidence has not been collected.

Scope

Build packaging/checksums/provenance/SBOM/license notices/Homebrew formula plan; signing/notarization only with user-owned credentials when available.

TDD and failure evidence

  1. Red: corrupted artifact/signature and incompatible state version fail before replacement.
  2. Test clean install and upgrade rollback without deleting user state/keys or interrupting busy jobs.
  3. Verify PR builds require no signing secrets; release evidence records unsigned/notarized status truthfully.

Capture a meaningful failing case before the implementation, then green evidence and relevant refactor checks. Tooling/prose-only work uses appropriate negative checks without artificial application tests. Live/runtime profiles require reviewed commits, a dedicated trusted test environment and explicit authorization for the concrete experiment. Public PR CI uses hosted environments without credentials. Planned or skipped tests never count as passed.

Acceptance criteria

  • No downloaded macOS image, restricted virtualization binary or embedded App private key.
  • No auto-publish/signing purchase implied; repository owner controls release channel.
  • Bootstrap build remains independent of gh-runnerd.
  • Luna max reviews supply-chain, update and rollback effects.
  • Record exact validation commands, actual results, skipped/live-test gaps and applicable rollback notes in the PR.
  • Independent review is resolved and the focused PR is merged under the repository execution policy.
  • Update issue/Project accurately; mark the active goal complete only after all required evidence and work are complete.

Safety invariants

Preserve existing manual runners; no global Docker prune/context switching, broad process kill, implicit App enrollment, busy-job cancellation during ordinary scale-down or transparent workflow replay. Use only verifiably owned resources. Keep management credentials and raw secret-bearing SDK errors out of worker environments, logs, fixtures and commits; per-worker JIT transport follows G01. Native pools remain trusted-only.

Design references

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:luna-maxPrimary implementer: gpt-5.6-luna, max reasoningpriority:P1Required delivery workrelease:distributionApproved delivery sequencing; does not change acceptance or dependency gatesrisk:mediumBounded contract and validation reviewtype:implementationBounded implementation goal with TDD evidence

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions