EDGE-05: pinned downstream artifacts, migration inventory and release/promotion contract #6

Open
opened 2026-09-23 05:58:34 +00:00 by lost-rob0t · 0 comments
lost-rob0t commented 2026-09-23 05:58:34 +00:00 (Migrated from github.com)

User decision: lost-rob0t/starintel-edge is where later canonical downstream distributions pull reusable edge implementation from. ADR 0001 and downstream/README.md define the boundary. Related implementation: #2 #3 #4 #5.

Scope

Inventory current edge code in actual server, infrastructure, Biz, Android/Wear OS, Zara and distribution source authorities. Record exact source paths/revisions, license, consumers and coverage. Do not infer that similarly named GitHub/Forgejo repositories are interchangeable or import private deployment material into public source.

Establish versioned upstream Lisp libraries, Android/watch libraries and device/image artifacts as each becomes real. Downstream products keep UI, branding, private policies and deployments, but depend on this runtime. starintel-universe and ROM overlays pin it; no parallel runtime copy. Keep canonical StarIntel schema, STAR URI and StarLang libraries as dependencies in their existing authorities.

Acceptance

  • Migration manifest records provenance and every affected consumer.
  • Reusable implementation/tests moved upstream with forwarding dependencies downstream.
  • Exact source commits and artifact digests; no floating branch production deployments.
  • Signed provenance/trust verification, artifact compatibility metadata and target-specific evidence.
  • Consumer conformance tests gate updates; old source removed only after equivalence passes.
  • Previous verified version and compatible-state rollback tested.
  • Source mirroring has one lineage; deployment authority remains downstream.
  • Secrets only from environment, OS wallet/keyring or Emacs auth-source; never store values in Nix/generated/checked-in config or CLI history.

No downstream repositories were migrated by the initial bootstrap; this issue tracks that remaining work. Publishing a scaffold target does not count as releasing a working device artifact.

User decision: `lost-rob0t/starintel-edge` is where later canonical downstream distributions pull reusable edge implementation from. ADR 0001 and `downstream/README.md` define the boundary. Related implementation: #2 #3 #4 #5. ## Scope Inventory current edge code in actual server, infrastructure, Biz, Android/Wear OS, Zara and distribution source authorities. Record exact source paths/revisions, license, consumers and coverage. Do not infer that similarly named GitHub/Forgejo repositories are interchangeable or import private deployment material into public source. Establish versioned upstream Lisp libraries, Android/watch libraries and device/image artifacts as each becomes real. Downstream products keep UI, branding, private policies and deployments, but depend on this runtime. `starintel-universe` and ROM overlays pin it; no parallel runtime copy. Keep canonical StarIntel schema, STAR URI and StarLang libraries as dependencies in their existing authorities. ## Acceptance - [ ] Migration manifest records provenance and every affected consumer. - [ ] Reusable implementation/tests moved upstream with forwarding dependencies downstream. - [ ] Exact source commits and artifact digests; no floating branch production deployments. - [ ] Signed provenance/trust verification, artifact compatibility metadata and target-specific evidence. - [ ] Consumer conformance tests gate updates; old source removed only after equivalence passes. - [ ] Previous verified version and compatible-state rollback tested. - [ ] Source mirroring has one lineage; deployment authority remains downstream. - [ ] Secrets only from environment, OS wallet/keyring or Emacs auth-source; never store values in Nix/generated/checked-in config or CLI history. No downstream repositories were migrated by the initial bootstrap; this issue tracks that remaining work. Publishing a scaffold target does not count as releasing a working device artifact.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
nsaspy/starintel-edge#6
No description provided.