Skip to content

Preserve API-key first delivery in the exact validated Web172 tree - #164

Merged
chen21019 merged 1 commit into
mainfrom
fix/web172-signed-delivery
Oct 3, 2026
Merged

chen21019 merged 1 commit into
mainfrom
fix/web172-signed-delivery

Conversation

@chen21019

Copy link
Copy Markdown

This signed single-commit branch replaces #163 without changing one source-tree byte. Tested source daab6e8 and tree 8f6c8eb930fe77d6983a37e9b30912a384af5e7e passed formal Validate 37109872791: 808/808, zero failure/skip/todo; 14 actual Store cases and 2 save-owner cases, personal/project first-delivery barriers 100 each. Both production archives are identical, SHA256 9a21c5e6ff9fbb274dbc7c45ec1ccffdbff33a945544b64d5976b14ee9752bfa. The component tag will point to that exact signed tested source, and assets will be the exact CI outputs without rebuilding.

The new branch resolves unsigned-ancestor protection, not a bypass. It has one verified signed commit based on current main and the identical tested tree. API-key editor alone opts into schema-bound one-time fields delivered to its detached clone; cache identity/store/generation/base/account/save-owner cleanup and other consumers remain unchanged. Protected branch CodeQL checks are still required before merge. Original failed/cancelled CI evidence stays retained.

Server packaged native delivery and the full permission/resource/locale matrix remain separate and incomplete. No company deployment, zero-CVE assertion, or historical HOLD promotion.

@chen21019
chen21019 requested a review from a team as a code owner October 3, 2026 08:37
@chen21019
chen21019 merged commit 5df701d into main Oct 3, 2026
3 checks passed
@chen21019
chen21019 deleted the fix/web172-signed-delivery branch October 3, 2026 08:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant