Validate SHA256SUMS with GNU sha256sum before publishing and advance the immutable correction release to alpha.13.
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
Use a deterministic v1 release fixture, prepare alpha.12 version sources, and document release ownership and burned tags.
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
alpha.10 tag produced a failed release pipeline (test-release-contract.sh
still asserted alpha.9, and run-negative-tests.sh test 5 failed on
cross-version verify-release). Per release-policy.md, published tags are
immutable — errors are fixed in the next tag.
The update guard compared the archive version with PROGRAM_VERSION using shell
string ordering. Both halves were wrong.
PROGRAM_VERSION is a constant describing the bootstrap source tree ("0.2.0-dev"),
never the deployed component, so it could not represent what is installed. The
cross-role compatibility check compared it with a manifest field such as
"v0.1.0-alpha.9"; those can never be equal, so update-control on a host that also
runs the agent always failed. The downgrade guard compared the same mismatched
pair and passed only by accident, because "v" sorts above "0" in ASCII.
String ordering is also wrong for the version scheme in use: "0.1.0-alpha.10"
sorts below "0.1.0-alpha.9", so the next release after the ninth would have been
rejected as a downgrade.
- record the installed version per role at install and update time, and compare
against that instead of PROGRAM_VERSION;
- order versions with sort -V after stripping the leading "v", so prerelease
numbering and tag prefixes compare correctly;
- treat an unknown peer version as a warning rather than a failure, because
installations predating version recording have nothing to compare against;
- guard all of the above in the bootstrap contract test, including the six
ordering cases and a check that the lexicographic comparison is not restored.
Verified by deliberately reintroducing each defect: lexicographic comparison,
sort without -V, and a missing version record are all caught by the contract test.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- UpdateService: manifest version must match release tag_name (prevents cross-version attacks)
- UpdateService: corrupted MSIX deleted immediately on hash mismatch
- UpdateService: TraceSource logging for all verification steps
- UpdateService: Trust anchor constants with docs/release-policy.md reference
- Bootstrap: docs/release-policy.md reference next to identity constants
- Test csproj: add UpdateService.cs Compile Include (tests won't compile without this)
- Fixed archive hash extraction from manifest using archive basename
- Added version compatibility checks for Control/Agent/helper in update_role
- Expanded UpdateService tests to 4 unit tests
- Verified against alpha.8 manifest