docs: record verified Linux packages and startup limits

This commit is contained in:
Emil
2026-09-09 20:16:49 +03:00
parent 696c6b0e52
commit cbc727829c
3 changed files with 28 additions and 1 deletions
+3
View File
@@ -18,6 +18,9 @@
- [ ] Cold install / repair / update / game exit на чистых Windows/Linux/macOS.
Unit tests и web preview не заменяют эти прогоны.
- [x] Native самообновление, русский UX, pinned updater key и защищённый release pipeline.
- [x] Локальные AppImage/deb собраны на Ubuntu 26.04 с CI test key; подписи и
форматы проверены. Настоящий AppImage прошёл изолированный startup/lock/marker
smoke. Это не проверка установки, самообновления или совместимости Ubuntu 22.04.
- [ ] Настроить защищённое GitHub environment/production secrets, опубликовать первый
updater-релиз и проверить реальную замену приложения на каждой ОС. Подпись ОС и
Apple notarization — отдельные настройки; CI test keys не предназначены игрокам.
+24
View File
@@ -281,3 +281,27 @@ Linux draft/publish verifier rechecks their container headers and signatures.
Header/metadata inspection is not a runtime, architecture-emulation or installer
migration test. Synthetic header fixtures exercise these checks; they are never
installed or executed.
## Local package verification, 2026-09-09
Application source `696c6b0` was built on Ubuntu 26.04 x86_64 using a disposable
CI updater key and the visible test-build flag. Actual AppImage and deb packages
passed the same collection checks used by the workflow: expected container,
architecture/version where represented, and cryptographic updater signatures.
The manual-package collector explicitly signs deb/DMG even when a CLI version
also emits their signatures. No production package or release was signed.
The actual AppImage was started with `--appimage-extract-and-run`, isolated XDG
roots and a pending update targeting a different version. The native executable
ran inside its own `APPDIR/usr/bin/shacraft-launcher`, referenced the expected
`APPIMAGE`, held the instance OS lock and preserved the pending marker during
startup and after termination. This checks native startup and the runtime binding;
it does not establish visual/IPC behavior, installation, self-replacement or a
successful updater restart. The deb was inspected, not installed.
This local Ubuntu 26.04 build is not a compatibility result for Ubuntu 22.04 or
other distributions. The four-platform GitHub matrix, real Windows/macOS
installations, old-version migration and end-to-end update acceptance remain
pending. Production signing credentials and release environments are not
configured on GitHub, and no release has been published.
+1 -1
View File
@@ -250,7 +250,7 @@ def collect(root, bundle, destination, platform, version):
)
shutil.copyfile(source_signature, signature)
else:
signer(root, target) # Tauri does not produce deb/DMG updater signatures.
signer(root, target) # Sign manual packages explicitly, independent of bundler output.
verify_signature(root, target, signature)
if os.environ.get("SHACRAFT_UPDATER_TEST_BUILD") == "1":
(destination / "CI_NOT_FOR_RELEASE.txt").write_text(