Skip to content

Add a signed openSUSE Tumbleweed repository - #47

Merged
dskvr merged 5 commits into
feature/36-signed-fedora-repofrom
feature/37-signed-opensuse-repo
Sep 29, 2026
Merged

dskvr merged 5 commits into
feature/36-signed-fedora-repofrom
feature/37-signed-opensuse-repo

Conversation

@dskvr

@dskvr dskvr commented Sep 5, 2026

Copy link
Copy Markdown
Member

openSUSE Tumbleweed users currently authenticate and install a downloaded RPM manually, so Zypper cannot manage normal updates. This adds a pending-by-default, project-owned signed RPM-md channel for Tumbleweed x86_64 with strict package and metadata verification, recoverable publication, protected automation, and clean-guest lifecycle proof.

This PR intentionally targets feature/36-signed-fedora-repo / #46 because it extends that exact-release RPM signing and SSH/POSIX publication foundation. After #46 lands, this branch can be retargeted to master without changing the #37 diff.

resolves #37

What changed

  • Selected project-owned hosting over OBS for the initial channel and documented the tradeoff. The generator authenticates the published release manifest, exact openSUSE RPM, signed checksums, x86_64 archive, source commit and hashes before signing only a staged RPM copy.
  • Added the opensuse-tumbleweed-x86_64 generator/publisher target, /opensuse/tumbleweed/x86_64 public namespace, isolated locks/CAS/journals/snapshots, immutable retention, signature-first metadata promotion, interruption recovery, rollback, actual SSH proof, and Nginx cache rules.
  • Added a fingerprint-pinned Tumbleweed bootstrap with gpgcheck=1, repo_gpgcheck=1, and pkg_gpgcheck=1; no repository path uses --no-gpg-checks or --allow-unsigned-rpm.
  • Added a protected publish/refresh/rollback workflow gated by OPENSUSE_REPOSITORY_ENABLED and packages-production, followed by exact public HTTPS verification and activation-record output.
  • Added a clean KVM lifecycle harness and strict raw verifier for install, reinstall, synthetic upgrade, rollback, removal, provider/backend checks, exact installed bytes, package origin/vendor, and a real GUI window.
  • Added pending/verified website behavior, user/operator guides, support matrix, release guidance, rolling-snapshot compatibility policy, release notes, workflow/docs gates, and browser proof.

Architecture layers

  • Audio backend adapters: unchanged; installed provider/backend surfaces are smoke-tested only.
  • Platform integration: signed RPM-md generation, publication, workflow, Zypper bootstrap, and KVM lifecycle proof.
  • UI and interaction shell: pending/verified openSUSE install option on the homepage.
  • Documentation/release: user setup/update/rollback guidance and maintainer operations/compatibility policy.

Validation

  • pnpm check — passed after the final runtime changes, including requirements/docs, automation/workflows, runtime/install/packaging, types, 295 workspace tests, 22 Rust tests, production builds, static-site proof, and APT/Fedora/openSUSE suites.
  • pnpm verify:opensuse-repository — passed: 7 generator, 27 publisher, 7 bootstrap, 6 public HTTPS, 3 preflight, workflow contract, 39 raw-proof mutations, and 5 channel cases. Real Zypper rejected signed-metadata transition mismatch and accepted recovery/rollback; actual SSH and Nginx checks passed.
  • Fedora regression gate — passed: 13 generator and 27 publisher cases plus bootstrap/public/workflow/proof/UI checks with real DNF behavior.
  • Clean Tumbleweed 20260829 KVM — passed at 08a18e4484627e36233ab068891bc468e9613f84; independent replay verified 159 evidence files. Image SHA-256: e80d2d1f9cfb328c79a5031d6a30f9744ec83824f6ba44c41ce831ff829a5dad.
  • Public baseline source RPM SHA-256: f6bc10589e6308fdc405faa104835cd6bcc486c4bc3fba95b5808b94267f1d05; release commit: dfdecf30d681c553a906ceebb13c859bb1b46ef3. Only 0.1.0+zypperfixture1 is synthetic.
  • Pending and verified Chromium fixtures passed desktop/mobile, keyboard/copy, no-JavaScript, responsive, motion/reduced-motion, guide, and setup-link checks. Visual verdict: 96/100. Checked-in channel and final build are pending.
  • Comprehensive review approved after read-only-container, later-snapshot manifest, workflow path coverage, SELinux RPM database, and native Zypper origin findings were fixed.

Docs and support boundary

Updated the homepage, install guide, openSUSE user/maintainer guides, support matrix, release guide, packaging guide, navigation, and unreleased notes. The repository is identified as third-party; Leap and non-x86_64 targets remain unsupported.

Production provider ownership, HTTPS/storage, signing custody, GitHub variables/secrets, first public publication, and activation remain the five unchecked Human operational tasks. No production account, host, credential, key, repository, or website activation was changed by this PR.

The openSUSE path now publishes the exact project-authenticated release RPM
through a project-owned signed RPM-md repository, with target-isolated
promotion, retention, recovery, and rollback. A fingerprint-pinned Zypper
bootstrap, protected workflow, public activation gate, clean-guest proof
harness, and operator/user guidance keep production activation reviewable.

Constraint: Initial support is openSUSE Tumbleweed x86_64 only
Constraint: Production hosting, credentials, signing custody, and activation remain human operations
Rejected: Open Build Service | provider rebuild identity and controls require separate provisioned proof
Confidence: high
Scope-risk: moderate
Reversibility: clean
Directive: Keep the channel pending until a protected public run and clean production guest proof are reviewed
Tested: pnpm check; Fedora and openSUSE repository gates; workflow/actionlint; pending and verified Chromium fixtures; visual verdict 96
Not-tested: Production origin, credentials, key custody, or public activation
Tumbleweed's enforcing SELinux policy denies RPM database locks in user-home
and temporary labels. Create a root-owned disposable database under /var/lib,
copy the system RPM database label, use it only for fixture signature checks,
and remove it before repository cleanup.

Constraint: RPM database writes require rpm_var_lib_t under the tested Tumbleweed policy
Confidence: high
Scope-risk: narrow
Reversibility: clean
Directive: Keep fixture trust isolated from the guest system RPM database and remove it after lifecycle proof
Tested: Live Tumbleweed KVM reproduction of init/import/Kv/removal; Bash syntax; ShellCheck; 38 raw-proof mutation cases
Not-tested: Full KVM lifecycle reruns from the amended commit
Tumbleweed reports the configured repository display name in XML search output,
while `loopwire` remains the command alias. Preserve and verify that exact native
origin value across install, reinstall, upgrade, and rollback evidence.

Constraint: Zypper XML exposes repository name rather than repository alias for installed results
Confidence: high
Scope-risk: narrow
Reversibility: clean
Directive: Keep CLI alias assertions separate from installed-origin display-name assertions
Tested: Live Tumbleweed signed repository install; Bash/Node syntax; ShellCheck; 38 raw-proof mutation cases
Not-tested: Full KVM lifecycle reruns from this commit
Zypper may render a freshly installed build as `(System Packages)` even while
the active repository still advertises that exact NEVRA. Prove origin from the
retrieval transaction, verify the matching active repository candidate, and
record the native installed-system view without rewriting it as an alias.

Constraint: Zypper's installed search view can differ from its transaction source and active candidate view
Confidence: high
Scope-risk: narrow
Reversibility: clean
Directive: Preserve all three evidence surfaces when changing openSUSE origin checks
Tested: Live Tumbleweed install and upgrade observations; Bash/Node syntax; ShellCheck; 39 raw-proof mutation cases
Not-tested: Full KVM lifecycle reruns from this commit
Map every development requirement to signed-package, publication, workflow,
clean-guest, compatibility, documentation, and UI evidence. Keep the five
production operations explicitly human-owned before public activation.

Constraint: Public v0.1.0 is baseline proof; the fixture upgrade and signer are not production material
Confidence: high
Scope-risk: narrow
Reversibility: clean
Directive: Do not activate the channel from development fixture evidence
Tested: Final pnpm check; Tumbleweed 20260829 KVM lifecycle and independent replay at 08a18e4
Not-tested: Production origin, credentials, signing custody, and public activation remain human tasks
@dskvr
dskvr merged commit 694585d into feature/36-signed-fedora-repo Sep 29, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant