igneum/packaging
igneum-labs 272b542120 ui-ota: the publisher (tools/ui-ota/publish.mjs), publish-manifest.sh --ui and --no-ui, the plan with the security notes
publish.mjs packs the fifteen served files with one fixed mtime (reproducible; the self-test checks it), hashes, signs
the entry through igneum-ota-sign sign-ui with the key in ~/.config/igneum (never read or printed here), copies the
bundle into the folder's ui/ and hands ui.json to publish-manifest.sh --ui, the one writer of the signed manifest,
which verifies the entry and the bundle's hash before signing; --dry-run writes nothing, --verify reads the live
manifest back against dl/<token>/ui and dl/public/ui; --no-ui withdraws the channel. Both self-tests sit on the one
gate. docs/plans/ui-ota.md: the shape, the engine, the security notes, the operator recipe, the tests, per tier.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit e02f5e14d0)
2026-10-07 10:44:51 +00:00
..
hive hive package: no AppleDouble entries in the tar (COPYFILE_DISABLE, no mac metadata) 2026-10-07 02:43:07 +00:00
mac 0.3.20: this feature tree renumbered (0.3.19 is the app-only miner-ui-5 cut); plan moved to release-0.3.20.md 2026-10-07 09:35:42 +00:00
ota ui-ota: the publisher (tools/ui-ota/publish.mjs), publish-manifest.sh --ui and --no-ui, the plan with the security notes 2026-10-07 10:44:51 +00:00
windows 0.3.20: this feature tree renumbered (0.3.19 is the app-only miner-ui-5 cut); plan moved to release-0.3.20.md 2026-10-07 09:35:42 +00:00
README-ship.md CI: run jobs test their fetched kit before use (the wiped-jobs-folder class) 2026-10-05 22:37:29 +00:00