docs(packaging): clarify Linux source release gate

This commit is contained in:
4gray committed 2026-07-17 22:42:37 +02:00
1 parent 99e5731beb
commit 99cb0a4dd6
5 files changed
+47 -18

No files matched your search

+6 -2
View File
@@ -248,8 +248,12 @@ Key files:
`pnp.ids` input. Each bundled package carries
`embedded-mpv-notices.json`, `THIRD_PARTY_NOTICES.txt`, and the exact
`licenses/**` files. CI may cache immutable source inputs, but regenerates
notices and `linux-frame-copy-runtime-sources.tar.xz` for the current
checkout on every run. Canonical maintenance docs:
notices and a VCS-metadata-free
`linux-frame-copy-runtime-sources.tar.xz` for the current checkout on every
run while retaining exact commit/submodule records. Automated Snap Store
publication is allowed only after a public `v*` GitHub release contains
both the Snap assets and exactly one matching source archive. Canonical
maintenance docs:
`docs/architecture/embedded-mpv-native.md` and
`tools/embedded-mpv/README.md`.
+6 -3
View File
@@ -642,9 +642,12 @@ engine` (restart required) or
`embedded-mpv-notices.json`, `THIRD_PARTY_NOTICES.txt`, and `licenses/**`.
CI caches the staged runtime plus immutable source inputs, never finished
notices or the compliance tarball; it regenerates those notices and the
deterministic `linux-frame-copy-runtime-sources.tar.xz` for the current
checkout. On Windows, package validation requires the exact MPV DLL named by
the helper's PE import table beside the executable.
VCS-metadata-free `linux-frame-copy-runtime-sources.tar.xz` for the current
checkout while preserving exact commit/submodule records. Snap Store
publication runs only from a public `v*` GitHub release that already
contains the Snap assets and exactly one source archive. On Windows, package
validation requires the exact MPV DLL named by the helper's PE import table
beside the executable.
Backend adapter:
`apps/electron-backend/src/app/services/embedded-mpv-frame-copy.adapter.ts`;
shared-controls adapter:
+14 -6
View File
@@ -675,9 +675,11 @@ the finished source-compliance archive. Runtime cache entries are saved only
from trusted repository refs. The Linux cache key covers the builder/stager,
notice generator, pinned sources, and toolchain. On every run, including a
cache hit, CI validates the cached hashes and clean checkout, regenerates the
notices for the current runtime manifest, and creates the deterministic
notices for the current runtime manifest, converts libplacebo into a
VCS-metadata-free working-tree snapshot while retaining the validated
commit/submodule record, and creates
`linux-frame-copy-runtime-sources.tar.xz` for the current repository revision
and binary diff.
and binary diff with normalized tar metadata.
Windows CI uses a checksum-pinned `win32-x64` runtime archive configured
through `IPTVNATOR_WINDOWS_EMBEDDED_MPV_RUNTIME_URL` and
@@ -768,10 +770,16 @@ verified, and the x64 helper probe runs in the intended runtime environment.
Bundled package layouts must include the generated notices and exact license
tree. The separately uploaded
`linux-frame-copy-runtime-sources.tar.xz` contains the exact archive set,
clean recursive libplacebo checkout, notice/license inputs, runtime metadata,
current revision/diff, and build tooling. Its tar metadata is normalized for
deterministic output. ARM artifacts are independently verified as marker-only
and never run the x64 helper.
the VCS-metadata-free libplacebo working tree plus exact commit/submodule
records, notice/license inputs, runtime metadata, current revision/diff, and
build tooling. Its tar metadata is normalized. ARM artifacts are independently
verified as marker-only and never run the x64 helper.
The build workflow creates a draft GitHub release but never publishes Snap in
parallel with that draft. The separate Snap workflow runs only for a public
`release.published` event whose tag starts with `v`; before any Store upload it
requires at least one exact `.snap` asset and exactly one non-empty
`linux-frame-copy-runtime-sources.tar.xz` in that public release.
During temporary artifact tests, CI may also set `IPTVNATOR_REQUIRE_EMBEDDED_MPV=1` for PR and `master` push jobs where a runtime is known to exist. After the artifacts are manually validated, remove temporary conditions so ordinary development builds leave `IPTVNATOR_REQUIRE_EMBEDDED_MPV` unset or `0`. This keeps the native feature in-tree without making every non-release build depend on runtime artifacts.
@@ -213,4 +213,8 @@ status.
Release artifacts must publish the generated runtime manifest and exact source
archives/metadata required by the recorded LGPL source-distribution statement.
No publication, push, pull request, or merge is part of this task.
The libplacebo payload is a VCS-metadata-free working-tree snapshot with exact
commit/submodule records, so clone-local `.git` state cannot perturb the
compliance tar. Automated Snap publication must wait for a public `v*` release
that already contains both the Snap assets and the exact source archive. No
publication, push, pull request, or merge is part of this task.
+16 -6
View File
@@ -193,13 +193,23 @@ finished notices or the compliance tarball. After either a build or cache hit,
CI revalidates those inputs, regenerates `vendor/embedded-mpv/linux-x64/notices`
for the current runtime manifest, and creates
`linux-frame-copy-runtime-sources.tar.xz` for the current repository
revision/diff.
revision/diff. Before archiving, the clean cached libplacebo checkout is
converted into a non-dereferenced working-tree snapshot with every `.git`
entry removed; the validated main/submodule commits remain in the source
index.
That deterministic source-compliance archive contains the exact unique archive
hash set, clean libplacebo checkout and recursive submodules, license inputs,
generated notices, runtime/source index metadata, and the builder, stager,
manifest, and notice-generator code. The notice generator rejects missing,
undeclared, symlinked, size-mismatched, or hash-mismatched license files.
That source-compliance archive uses normalized tar metadata and contains the
exact unique archive hash set, VCS-free libplacebo sources and recursive
submodules, license inputs, generated notices, runtime/source index metadata,
and the builder, stager, manifest, notice-generator, and source-snapshot code.
The notice generator rejects missing, undeclared, symlinked, size-mismatched,
or hash-mismatched license files.
Snap publication is a separate `release.published` workflow for public `v*`
GitHub releases. It verifies that the public release already contains at least
one Snap and exactly one non-empty
`linux-frame-copy-runtime-sources.tar.xz` before uploading any Snap to the
Store's edge channel.
Windows CI stages a checksum-pinned x64 LGPL archive. The DLL basename encoded
in its import library is preserved and must be present beside