generated from erix/meta
[FEATURE] Close final security, documentation, CI and self-hosting acceptance #10
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/integration#10
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem and motivation
Phase completion requires one coherent final graph with full regression and authority evidence. A predecessor’s green run, warnings inside successful jobs or incomplete cross-repository checks cannot certify the delivered system.
Proposed behavior and scope
Run final warning-free Rust/documentation checks, the complete old-plus-new VM suite, exact-head repository CI, independent whole-codebase audits and final performance gates. Reconcile AC1–AC24, supplementary requirements, public tracking and the two-generation proof, then prepare the alpha manual-review dossier.
This issue records planned work; its unchecked criteria are not implementation proof. The normative basis is Phase 6 and AC1–AC24.
Authority, security and reliability
Verify zero unresolved in-scope ambient/residual/unwanted explicit authority and exact cleanup under enforced workload deadlines. Preserve source hashes, clean/extended separation and signed provenance. Readiness and phase completion do not authorize merges, tags, firmware changes or artifact promotion.
Apply the priority order: security, reliability, then performance. Keep suspected vulnerabilities in the repository’s restricted SECURITY.md reporting channel.
Acceptance criteria
target/profile builds and rustdoc for every altered repository at its exact final signed
revision, with no warnings and no unexplained skipped tests.
interruption/cleanup and bounded VM integration coverage.
authored scenario counts, source/worker ownership, expected exits, images and retained
failures. Preserve the existing catalog as a baseline, not a fixed future denominator that
permits dropping tests.
test stalled guests/helpers fail and release their worker. Report progress throughout long
full-build jobs without fabricating liveness.
unit/VM regressions; classify pending/cancelled/stale/missing evidence separately. Fix
failures and warning-bearing green jobs before acceptance.
ci.yml, includingIntegration's library job; remove unsupported Forgejo workflow permissions fields and use
authorized integrations only for needed capabilities.
over-limit authored code files, missing inline docs and unresolved ambient/residual/unwanted
explicit authority findings.
signed source/artifact provenance, reproducibility and rollback/ upgrade behavior for changed
persistent or ABI contracts.
graph; an earlier candidate's speedup or predecessor CI cannot certify a later graph.
docs/phases/6.md, manual/API references and operator self-hosting runbook with observedbehavior, supported limits and exact final evidence.
feature/posix-compattrees and coherent Integration pins;verify remote heads/signatures and their own terminal CIs. Do not silently merge, retag,
rewrite history or replace main images.
later-phase non-goals, and request explicit promotion direction for accepted images. Do not
declare Phase 6 complete before integration#9/integration#10 actually pass.
downloadable boot artifacts, all-file authority verification, real-input CLI coverage, native
tools, manuals and human-legible documentation/code.
and this tracker; remove "WIP: " only from genuinely accomplished PR goals and leave
unresolved/dependent work visibly open.
v1.0.0-alpha.1manual-review dossier: complete source graph,self-host proof, security/CI/performance results, licenses, custom-key enrollment/recovery
instructions and known non-goals. Wait for explicit manual approval before merges, version
promotion, release tags or artifact promotion.
For each implementation slice, retain actual formatting, strict Clippy, unit/doctest and warning-denied build results for all altered Rust repositories and valid configurations. Add relevant runtime VM coverage, monitor older unit/VM regressions in exact-head CI, and update canonical component documents and affected technical-manual/API material. Every authored code file must remain below 1,000 physical lines, with meaningful inline documentation and missing_docs enforcement in Rust crates.
Alternatives and tradeoffs
Repeated partial passes or a reduced scenario denominator conceal regressions. Retain true exit status and failures, validate final signed revisions, and request explicit manual release direction only after the complete reviewable dossier exists.
Tracking and rollout
Dependencies: integration#6, integration#1, integration#2, docs#1, integration#3, lib-posixabi#1, posixd#1, posixd#2, kernel#1, posixd#3, lib-cstd#1, dynlinkd#1, exsh#1, integration#4, integration#7, integration#8, integration#9, meta#2, integration#5, bootloader#1, ttyd#1
Dependencies identify required contracts and closure gates; preparatory inventory/design can proceed in parallel under one owner per edited file. Link bounded implementation issues and their PRs here before claiming acceptance. Use
feature/posix-compat, regular signed commits in the canonical contribution format, and WIP PRs linked to the exact coherent component graph. All cross-repository Cargo/catalog selections and CI helpers use full 40-character lowercase commit hashes, including transitive dependencies; do not substitute branch, tag or implicit HEAD selection.Close criteria only with their own reviewed deliverables and validation evidence. Pending, skipped, cancelled, failed or predecessor-only results remain distinct. Keep main images unchanged until explicit promotion direction; technical completion does not authorize merges, release tags or publication.
[FEATURE] [P17] Close final security, documentation, CI and self-hosting acceptanceto [FEATURE] Close final security, documentation, CI and self-hosting acceptance