Skip to content

Payload gate: compare documentation by path, not basename - #21

Merged
itcmsgr merged 1 commit into
mainfrom
sync/payload-gate
Sep 29, 2026
Merged

itcmsgr merged 1 commit into
mainfrom
sync/payload-gate

Conversation

@itcmsgr

@itcmsgr itcmsgr commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Payload gate: compare documentation by path, not basename

The first attested release run for 0.1.0 (workflow_dispatch on public main
c16c46b, run 36557987409) stopped at the package payload gate, before any
attestation: "deb and rpm ship DIFFERENT documentation". Both packages ship
the same nine files. The gate compared basenames, and 0.1.0 installs its
guides in docs/: tar lists that directory as "docs/" (an empty basename),
rpm as "docs". A basename comparison also could never see a guide installed
in the wrong directory.

The gate now compares paths relative to /usr/share/doc/isedraf, regular files
only (tar directory entries end in "/", rpm reports modes). On the GA
packages: "deb and rpm ship the same 9 documentation files".

Falsification: "D-86 the rpm and the deb ship different documentation" did
not commit its mutation, so build.sh refused the dirty tree and the gate's
"no packages" failure matched its loose evidence - detection for the wrong
reason. It now commits first, like the other packaging injections, and
requires the real evidence. New: "D-86 the rpm installs a guide outside
docs/", which the basename comparison could not detect. Both were shown to
pass on real builds and fail on the mutation in harness-style sandboxes.

Assisted-by: Claude (implementation agent, Claude Code)

The first attested release run for 0.1.0 (workflow_dispatch on public main
c16c46b, run 36557987409) stopped at the package payload gate, before any
attestation: "deb and rpm ship DIFFERENT documentation". Both packages ship
the same nine files. The gate compared basenames, and 0.1.0 installs its
guides in docs/: tar lists that directory as "docs/" (an empty basename),
rpm as "docs". A basename comparison also could never see a guide installed
in the wrong directory.

The gate now compares paths relative to /usr/share/doc/isedraf, regular files
only (tar directory entries end in "/", rpm reports modes). On the GA
packages: "deb and rpm ship the same 9 documentation files".

Falsification: "D-86 the rpm and the deb ship different documentation" did
not commit its mutation, so build.sh refused the dirty tree and the gate's
"no packages" failure matched its loose evidence - detection for the wrong
reason. It now commits first, like the other packaging injections, and
requires the real evidence. New: "D-86 the rpm installs a guide outside
docs/", which the basename comparison could not detect. Both were shown to
pass on real builds and fail on the mutation in harness-style sandboxes.

Assisted-by: Claude (implementation agent, Claude Code)
Signed-off-by: Antonios Voulvoulis <contact@itcms.gr>
@itcmsgr
itcmsgr merged commit 07d0c55 into main Sep 29, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant