5f8273222c
Release notes now carry one row per product — the bytes actually published, with their VirusTotal verdict — instead of a column per candidate. Several candidates are scanned so the selector has an alternative when an opaque classifier flags one, but a reader installing cbm cares about what they receive, not about what we discarded. The rejected candidates' verdicts remain in the published evidence TSVs for anyone auditing the selection, and they stay useful to US as a development signal; in a changelog they are noise, and listing a "microsoft-ml" verdict next to a binary nobody can download invites exactly the wrong conclusion. Also removes a claim that had become FALSE: the section asserted that every scan had a minimum of 50 decisive engines. That floor was removed deliberately (it is VirusTotal fleet availability, not a property of our binary) and the last release observed 31. Published notes would have stated something untrue. The observed range is still reported, now over the shipped binaries. The disclosure of a tolerated Microsoft `!ml` is preserved and narrowed to the binaries that ship. The contract test now pins both directions: a flagged binary that SHIPS must be disclosed, and flagged candidates that were rejected must not appear at all. Its fixture gained a target that draws the tolerated verdict on all three candidates, so the disclosure branch is actually exercised — previously every flagged candidate was rejected in favour of a clean sibling, leaving that path untested. README and SECURITY.md updated: they promised notes "link every candidate result". All five release/VT contract tests pass. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com>
scripts/ci/ — venue plumbing (single implementations)
Support scripts that keep the venues in the SAME shape. Each exists because
the logic used to live inline in workflow YAML or was hand-duplicated between
CI and the local infrastructure — both of which the venue-parity contract
(tests/test_venue_parity_contract.sh) now forbids. Everything here answers
--help (PowerShell: comment-based help, Get-Help <script>).
| script | job | called by |
|---|---|---|
new-protected-temp-root.ps1 |
Create the owner-stamped, inheritance-protected per-user TEMP root the daemon/install suites require (shared /tmp and default runner TEMP grant Authenticated-Users mutation rights, which the trust policy correctly refuses — running there produces security refusals, not signal). -ProtectDir stamps build dirs the same way. |
_test.yml, _soak.yml, vm-run-tests.sh |
clean-test-residue.ps1 |
Sweep cbm-* residue from the Windows VM and assert runner-like free disk (default 14 GB — the GitHub runner's SSD). Long-path \\?\ fallback for the guard suites' adversarial trees; every removal VERIFIED (an earlier version counted attempts and reported 86 swept while 11 GB remained). BLOCKS below the floor: a disk that fills mid-run reads as a product bug. |
win.sh before every build/run |
preflight-docker.sh |
Same idea for Colima/docker: prune runner-unlike residue, assert free space on the filesystem backing the docker data root (not the VM's /). Build cache + named volumes KEPT (the local analogue of actions/cache); --deep drops them. |
test-infrastructure/run.sh |
check-glibc-compat.sh |
Run a linux binary in debian:bullseye (glibc 2.31) — the portable binary must start on old glibc. | _smoke.yml portable legs |
generate-sbom.py |
The release SPDX SBOM (vendored versions reviewable here, diffable by vendoring PRs — was inline YAML). | release.yml |
require-all-green.sh |
The aggregate gate: fail unless every needed job succeeded or legitimately skipped (was inline YAML). | pr.yml ci-ok |
verify-shard-union.sh |
Prove sharded test legs lost nothing: shard count agreement, indices 1..n, identical suite lists, union of slices == full list (was inline YAML). | _test.yml shard-completeness |
prepare-release-candidates.sh |
Copy one linker output into stripped/unstripped candidates, finalize signatures, composition-check them without execution, and record their hashes. | _build.yml, local artifact smoke |
stage-release-candidates.py |
Admit exactly eight candidate artifacts / sixteen byte-distinct binaries into the content-addressed VirusTotal scan set. | _build.yml |
select-release-candidates.py |
Apply the reviewed tuple-local VT truth table, or the explicit dry-run stripped default, and atomically copy one content-bound binary per target. | _build.yml |
verify-release-selection.py |
Recompute the selection policy and prove every executable member in all 14 public containers equals its selected SHA-256. | _build.yml, release.yml final draft verification |
check-virustotal.sh |
Poll and validate the exact candidate scan set, enforce engine coverage and the narrow documented Microsoft !ml policy, and emit content-bound results evidence. |
_build.yml |