docs: record verified Linux packages and startup limits
This commit is contained in:
@@ -18,6 +18,9 @@
|
||||
- [ ] Cold install / repair / update / game exit на чистых Windows/Linux/macOS.
|
||||
Unit tests и web preview не заменяют эти прогоны.
|
||||
- [x] Native самообновление, русский UX, pinned updater key и защищённый release pipeline.
|
||||
- [x] Локальные AppImage/deb собраны на Ubuntu 26.04 с CI test key; подписи и
|
||||
форматы проверены. Настоящий AppImage прошёл изолированный startup/lock/marker
|
||||
smoke. Это не проверка установки, самообновления или совместимости Ubuntu 22.04.
|
||||
- [ ] Настроить защищённое GitHub environment/production secrets, опубликовать первый
|
||||
updater-релиз и проверить реальную замену приложения на каждой ОС. Подпись ОС и
|
||||
Apple notarization — отдельные настройки; CI test keys не предназначены игрокам.
|
||||
|
||||
@@ -281,3 +281,27 @@ Linux draft/publish verifier rechecks their container headers and signatures.
|
||||
Header/metadata inspection is not a runtime, architecture-emulation or installer
|
||||
migration test. Synthetic header fixtures exercise these checks; they are never
|
||||
installed or executed.
|
||||
|
||||
|
||||
## Local package verification, 2026-09-09
|
||||
|
||||
Application source `696c6b0` was built on Ubuntu 26.04 x86_64 using a disposable
|
||||
CI updater key and the visible test-build flag. Actual AppImage and deb packages
|
||||
passed the same collection checks used by the workflow: expected container,
|
||||
architecture/version where represented, and cryptographic updater signatures.
|
||||
The manual-package collector explicitly signs deb/DMG even when a CLI version
|
||||
also emits their signatures. No production package or release was signed.
|
||||
|
||||
The actual AppImage was started with `--appimage-extract-and-run`, isolated XDG
|
||||
roots and a pending update targeting a different version. The native executable
|
||||
ran inside its own `APPDIR/usr/bin/shacraft-launcher`, referenced the expected
|
||||
`APPIMAGE`, held the instance OS lock and preserved the pending marker during
|
||||
startup and after termination. This checks native startup and the runtime binding;
|
||||
it does not establish visual/IPC behavior, installation, self-replacement or a
|
||||
successful updater restart. The deb was inspected, not installed.
|
||||
|
||||
This local Ubuntu 26.04 build is not a compatibility result for Ubuntu 22.04 or
|
||||
other distributions. The four-platform GitHub matrix, real Windows/macOS
|
||||
installations, old-version migration and end-to-end update acceptance remain
|
||||
pending. Production signing credentials and release environments are not
|
||||
configured on GitHub, and no release has been published.
|
||||
|
||||
+1
-1
@@ -250,7 +250,7 @@ def collect(root, bundle, destination, platform, version):
|
||||
)
|
||||
shutil.copyfile(source_signature, signature)
|
||||
else:
|
||||
signer(root, target) # Tauri does not produce deb/DMG updater signatures.
|
||||
signer(root, target) # Sign manual packages explicitly, independent of bundler output.
|
||||
verify_signature(root, target, signature)
|
||||
if os.environ.get("SHACRAFT_UPDATER_TEST_BUILD") == "1":
|
||||
(destination / "CI_NOT_FOR_RELEASE.txt").write_text(
|
||||
|
||||
Reference in New Issue
Block a user