Skip to content

release(windows): enforce Store and direct-EXE delivery contract - #186

Merged
Qiyuanqiii merged 2 commits into
mainfrom
codex/issue-123-dual-windows-release
Aug 27, 2026
Merged

Qiyuanqiii merged 2 commits into
mainfrom
codex/issue-123-dual-windows-release

Conversation

@Qiyuanqiii

@Qiyuanqiii Qiyuanqiii commented Aug 27, 2026 •

Copy link
Copy Markdown
Member

Summary

Implements the repository-owned portion of #123's Windows two-deliverable contract:

  • the sole direct user entry is zero-argument TraverseBoard.exe;
  • the Store route produces an identity-bound MSIX/MSIXUPLOAD for Partner Center;
  • the old Start-Prayu-Operator-Preview.cmd is removed with no renamed Start wrapper;
  • internal ZIP/development MSIX/Store upload/evidence sidecars remain validation material, not extra products.

Part of #37. Refs #123. This PR stays Draft and intentionally does not close #123 until a real stable candidate passes the external gates below.

Repository-owned implementation

  • Added a two-phase protected direct-EXE signing contract:
    • prepare emits an exact payload-bound signing request;
    • finalize consumes the unchanged request, signed EXE, and retained handoff;
    • every stable verifier requires the repository-configured signer Subject/thumbprint and never self-anchors from evidence;
    • PE normalization proves signing changed only permitted Authenticode regions;
    • PKCS#7 parsing independently requires SHA-256 Authenticode file/signature digests, exactly one RFC 3161 timestamp, SHA-256 timestamp imprint, matching message imprint, and the token's real genTime;
    • stable request/handoff/evidence are published as hash-bound sidecars, while intake-only TraverseBoard-signed.exe is removed.
  • Added permission-scoped GitHub provenance/SBOM attestations for the public EXE and Store upload, with downloadable bundles, exact subject/predicate checks, and offline gh attestation verify.
  • Reworked Store packaging/verification around msix_manifest.v2: exact Partner Center identity/version/architecture, deterministic one-entry .msixupload, immutable release-evidence inventory, and pre-sign Store payload to post-sign public-EXE binding.
  • Added finalize-windows-release.ps1. It emits immutable windows_release_completion.v1 only after live verification of:
    • an installed package with exact identity/version/architecture/payload and SignatureKind=Store;
    • Partner Center/listing/privacy/age readbacks;
    • the published GitHub tag, body, exact asset allowlist, hashes, and attestation bundles;
    • four hash-resolved Windows 10/11 × 100%/200% DPI × zh-CN IME lifecycle rows, including upgrade, downgrade rejection, repair, uninstall/reinstall, and data-sentinel preservation.
  • Explicitly labels Partner Center exports, screenshots, and operator lifecycle reports as reviewer-attested/hash-bound evidence rather than cryptographic proof.
  • Added canonical bilingual release notes and exact public asset inventory. New releases contain neither the old CMD nor a renamed Start helper.
  • Registered all new durable protocols and added release/workflow contract tests.

Validation performed

  • Real clean reproducible Windows build: two TraverseBoard.exe builds matched byte-for-byte.
  • Web: 73 test files / 351 tests passed; production bundle built.
  • Internal ZIP: deterministic double-pack and exact-entry verification passed.
  • Real MakeAppx development MSIX and synthetic non-submittable Store MSIX/MSIXUPLOAD: pack, unpack, identity/architecture/payload/evidence inspection passed.
  • Prerelease direct-EXE and portable verification passed in PowerShell 7 and Windows PowerShell 5.1.
  • The stable cryptographic profile was exercised against valid embedded Authenticode/RFC 3161 files in both PowerShell versions, including SHA-256 file digest and timestamp message-imprint parsing.
  • go test -count=1 ./cmd/releasegate ./internal/releasegate ./internal/protocolregistry ./internal/producte2e ./internal/packagede2e passed.
  • actionlint v1.7.12, both PowerShell parsers, protocol-registry synchronization, and git diff --check passed.

A repository-wide local go test ./... run also exposed an unrelated existing Windows deadline assertion in internal/application; the concurrent internal/store timeout passed when rerun alone. No implementation file in either failing path is changed here; GitHub CI remains authoritative for the new revision.

External completion gates (not claimed by this PR)

Until those facts exist, final completion fails closed and #123 remains open.

@Qiyuanqiii
Qiyuanqiii marked this pull request as ready for review August 27, 2026 12:56
@Qiyuanqiii
Qiyuanqiii merged commit 2306416 into main Aug 27, 2026
13 checks passed
@Qiyuanqiii
Qiyuanqiii deleted the codex/issue-123-dual-windows-release branch August 27, 2026 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

release(windows): 交付 Microsoft Store 包与开箱即用单 EXE

1 participant