The publish-snap verifier had never run against a real release and
encoded three stale expectations that the tag build's own validators do
not share:
- it required the app under usr/lib/iptvnator inside the snap, while
Electron Builder's snap target ships the app at the snap root
(/iptvnator.bin, /resources/**) — the layout the packaged smoke tests
exercise;
- it validated the source archive's runtime manifest with the raw
source-build validator, but the archive carries the STAGED manifest
(origin "vendored-lgpl" + sourceBuildOrigin) written by
stage-runtime.mjs; the staged envelope is now checked explicitly and
the remaining fields still go through the shared validator via an
origin projection;
- it deep-equaled the snap's bundled sourceRuntime against the archive
manifest, but the snap bundles the builder view (no staging
envelope); the binding now projects the envelope away first.
Verified end-to-end in a Linux container against the real v0.23.0
release assets: release-snap-assets.cjs verify now passes and emits the
sealed snapshot receipt. Regression tests cover the legacy usr/lib
layout and staged-envelope mismatches.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>