aboutsummaryrefslogtreecommitdiff
path: root/docs
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-10-06 06:24:37 -0600
committerCraig Jennings <c@cjennings.net>2026-10-06 06:24:37 -0600
commit4a2f811c73f7bceb1e10a565e46fb1b8536fed28 (patch)
tree1b6233cc188c10188fde030f369e70a3f6d812b2 /docs
parent40a8190729683342948c28e3ea1d13d1c6d4eb7e (diff)
downloadarchsetup-4a2f811c73f7bceb1e10a565e46fb1b8536fed28.tar.gz
archsetup-4a2f811c73f7bceb1e10a565e46fb1b8536fed28.zip
chore(security): record the history rewrite and remap its SHAs
The Signal pager number is rewritten out of every commit. 59 of 951 changed SHA, every descendant of the 08-17 post-rebuild-check commit, and tag v0.5 is untouched. The filter-repo map lands under assets/ so old citations can be translated. The cgit audit task carries the dated record and the release task notes that a full pre-release secrets scan is still owed. Sixteen citations of renamed SHAs across the task list, the task archive and the topgrade spec now point at the new ones.
Diffstat (limited to 'docs')
-rw-r--r--docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org10
1 files changed, 5 insertions, 5 deletions
diff --git a/docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org b/docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org
index e19ea6c..ae456a5 100644
--- a/docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org
+++ b/docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org
@@ -520,7 +520,7 @@ Spec text:
- L193: "The =--only system= scope … shrink this to near zero".
Git history:
-- =git show 77447d0:…spec.org= L64 has the identical ExecStart sentence, so it was never revised.
+- =git show a50fb3b:…spec.org= L64 has the identical ExecStart sentence, so it was never revised.
- The uncommitted diff touches only the script name and the containers flag, not L69.
Live system:
@@ -1195,7 +1195,7 @@ Disposition: modified, folded into Design, Alternatives. Confirmed. Its proposed
- L155 (Phase 1): =scripts/upgrade-guarded=, with "=--complete= (... stamp when the deferred set is empty)".
- L161 (Phase 3): "=ExecStart= runs the script's =--complete= form as the user".
- L173 (AC): "via the Phase-1 path".
-- Draft provenance: =git show 77447d0:docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org= has the L71 text verbatim at its line 66 and the L93 text at its line 88. That draft's Phase 1 (its line 119) reads "A single =maint= entry point (=maint apply-upgrade=, ...)". Commit e777ddc rewrote the phases around the script but left these lines in place.
+- Draft provenance: =git show a50fb3b:docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org= has the L71 text verbatim at its line 66 and the L93 text at its line 88. That draft's Phase 1 (its line 119) reads "A single =maint= entry point (=maint apply-upgrade=, ...)". Commit 068306e rewrote the phases around the script but left these lines in place.
- No implementation exists: =grep -rn "apply.upgrade" ~/.dotfiles/maint/src= finds nothing, and the only archsetup hits are in this spec.
- Adjacent stale text: L69's ExecStart still lists "=topgrade --only system= ... then =maint stamp topgrade= on success". That conflicts with L142 and L161.
:END:
@@ -1280,7 +1280,7 @@ Spec docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org:
- L193: "verified in Phase 2".
- L200: "Phase-1 and Phase-3 logic under the maint fake harness; Phase-2 install under =tests/installer-steps/=".
-The stale lines come from the first draft. In git show 77447d0, the phases are: Phase 1 "Stamp the safe-completion path", Phase 2 "The armed boot-time unit (archsetup)", Phase 3 "The arming affordance (dotfiles maint)". Its lines 148, 154 and 159 match the current L187, L193 and L200 word for word.
+The stale lines come from the first draft. In git show a50fb3b, the phases are: Phase 1 "Stamp the safe-completion path", Phase 2 "The armed boot-time unit (archsetup)", Phase 3 "The arming affordance (dotfiles maint)". Its lines 148, 154 and 159 match the current L187, L193 and L200 word for word.
Test conventions:
- tests/hypr-live-update-guard/test_hypr_live_update_guard.py:1-21 is unittest with HYPR_GUARD_* env-var seams, and its docstring says "python3 -m unittest tests.hypr-live-update-guard...".
@@ -1605,7 +1605,7 @@ Spec docs/specs/2026-08-25-topgrade-guarded-upgrade-spec.org:
- L57: "vNext: none open — the kernel deferral that was vNext is now part of v1's held set."
- L136: "the kernel deferral is now standing, so the dedicated session has to happen on a cadence (security fixes ride the kernel), and the panel's deferred count carries a kernel most days"
- L197: "The panel's deferred row is the reminder; a stale-kernel age in maint is a possible follow-up."
-- git show 77447d0 L54, the original vNext: "fold the same arm-and-reboot pattern into a live-kernel-upgrade prompt (log to todo.org)". e777ddc, the decision-closing commit, added L57's "none open" and L197 together.
+- git show a50fb3b L54, the original vNext: "fold the same arm-and-reboot pattern into a live-kernel-upgrade prompt (log to todo.org)". 068306e, the decision-closing commit, added L57's "none open" and L197 together.
todo.org:
- :739-740: "...file the vNext =[#D]= kernel-reboot item, and commit the spec."
@@ -1858,7 +1858,7 @@ Disposition: modified, folded into Summary, Goals and Non-Goals, Design, Alterna
- Spec L61: "...while the ordinary full sweep stays a normal live =topgrade= run."
- Spec L158 (Phase 2): "UPDATE and TOPGRADE levers change their =argv= to the script".
- Spec L65: the script runs pacman -Syu --ignore=..., then yay -Sua, then topgrade --disable system,git_repos,containers -y.
-- git show 77447d0 has the identical Summary at draft L25, Goals at draft L40-43, and the L61 sentence at draft L58. Draft L60 is "Three pieces, at two altitudes." with nothing after it, but current L63 appends "— but the everyday gesture is not a reboot. It is a normal live update that simply leaves the dangerous few behind." So L63 has been edited and is not verbatim.
+- git show a50fb3b has the identical Summary at draft L25, Goals at draft L40-43, and the L61 sentence at draft L58. Draft L60 is "Three pieces, at two altitudes." with nothing after it, but current L63 appends "— but the everyday gesture is not a reboot. It is a normal live update that simply leaves the dangerous few behind." So L63 has been edited and is not verbatim.
- Current L65/L67/L69 are three bold-labelled paragraphs (split script, user, implementer).
- Mitigations already in the spec: L13 (history line naming the live split upgrade as the everyday path), L51 and L55 (the split script named as v1), L167 (acceptance criterion for the live UPDATE).
- Labels: L90 "D. ... (this spec)" vs L95 "E. ... (this spec's everyday path)".