Add a signed openSUSE Tumbleweed repository - #47
Merged
dskvr merged 5 commits intoSep 29, 2026
Merged
Conversation
The openSUSE path now publishes the exact project-authenticated release RPM through a project-owned signed RPM-md repository, with target-isolated promotion, retention, recovery, and rollback. A fingerprint-pinned Zypper bootstrap, protected workflow, public activation gate, clean-guest proof harness, and operator/user guidance keep production activation reviewable. Constraint: Initial support is openSUSE Tumbleweed x86_64 only Constraint: Production hosting, credentials, signing custody, and activation remain human operations Rejected: Open Build Service | provider rebuild identity and controls require separate provisioned proof Confidence: high Scope-risk: moderate Reversibility: clean Directive: Keep the channel pending until a protected public run and clean production guest proof are reviewed Tested: pnpm check; Fedora and openSUSE repository gates; workflow/actionlint; pending and verified Chromium fixtures; visual verdict 96 Not-tested: Production origin, credentials, key custody, or public activation
Tumbleweed's enforcing SELinux policy denies RPM database locks in user-home and temporary labels. Create a root-owned disposable database under /var/lib, copy the system RPM database label, use it only for fixture signature checks, and remove it before repository cleanup. Constraint: RPM database writes require rpm_var_lib_t under the tested Tumbleweed policy Confidence: high Scope-risk: narrow Reversibility: clean Directive: Keep fixture trust isolated from the guest system RPM database and remove it after lifecycle proof Tested: Live Tumbleweed KVM reproduction of init/import/Kv/removal; Bash syntax; ShellCheck; 38 raw-proof mutation cases Not-tested: Full KVM lifecycle reruns from the amended commit
Tumbleweed reports the configured repository display name in XML search output, while `loopwire` remains the command alias. Preserve and verify that exact native origin value across install, reinstall, upgrade, and rollback evidence. Constraint: Zypper XML exposes repository name rather than repository alias for installed results Confidence: high Scope-risk: narrow Reversibility: clean Directive: Keep CLI alias assertions separate from installed-origin display-name assertions Tested: Live Tumbleweed signed repository install; Bash/Node syntax; ShellCheck; 38 raw-proof mutation cases Not-tested: Full KVM lifecycle reruns from this commit
Zypper may render a freshly installed build as `(System Packages)` even while the active repository still advertises that exact NEVRA. Prove origin from the retrieval transaction, verify the matching active repository candidate, and record the native installed-system view without rewriting it as an alias. Constraint: Zypper's installed search view can differ from its transaction source and active candidate view Confidence: high Scope-risk: narrow Reversibility: clean Directive: Preserve all three evidence surfaces when changing openSUSE origin checks Tested: Live Tumbleweed install and upgrade observations; Bash/Node syntax; ShellCheck; 39 raw-proof mutation cases Not-tested: Full KVM lifecycle reruns from this commit
Map every development requirement to signed-package, publication, workflow, clean-guest, compatibility, documentation, and UI evidence. Keep the five production operations explicitly human-owned before public activation. Constraint: Public v0.1.0 is baseline proof; the fixture upgrade and signer are not production material Confidence: high Scope-risk: narrow Reversibility: clean Directive: Do not activate the channel from development fixture evidence Tested: Final pnpm check; Tumbleweed 20260829 KVM lifecycle and independent replay at 08a18e4 Not-tested: Production origin, credentials, signing custody, and public activation remain human tasks
9 of 14 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
openSUSE Tumbleweed users currently authenticate and install a downloaded RPM manually, so Zypper cannot manage normal updates. This adds a pending-by-default, project-owned signed RPM-md channel for Tumbleweed x86_64 with strict package and metadata verification, recoverable publication, protected automation, and clean-guest lifecycle proof.
This PR intentionally targets
feature/36-signed-fedora-repo/ #46 because it extends that exact-release RPM signing and SSH/POSIX publication foundation. After #46 lands, this branch can be retargeted tomasterwithout changing the #37 diff.resolves #37
What changed
opensuse-tumbleweed-x86_64generator/publisher target,/opensuse/tumbleweed/x86_64public namespace, isolated locks/CAS/journals/snapshots, immutable retention, signature-first metadata promotion, interruption recovery, rollback, actual SSH proof, and Nginx cache rules.gpgcheck=1,repo_gpgcheck=1, andpkg_gpgcheck=1; no repository path uses--no-gpg-checksor--allow-unsigned-rpm.OPENSUSE_REPOSITORY_ENABLEDandpackages-production, followed by exact public HTTPS verification and activation-record output.Architecture layers
Validation
pnpm check— passed after the final runtime changes, including requirements/docs, automation/workflows, runtime/install/packaging, types, 295 workspace tests, 22 Rust tests, production builds, static-site proof, and APT/Fedora/openSUSE suites.pnpm verify:opensuse-repository— passed: 7 generator, 27 publisher, 7 bootstrap, 6 public HTTPS, 3 preflight, workflow contract, 39 raw-proof mutations, and 5 channel cases. Real Zypper rejected signed-metadata transition mismatch and accepted recovery/rollback; actual SSH and Nginx checks passed.20260829KVM — passed at08a18e4484627e36233ab068891bc468e9613f84; independent replay verified 159 evidence files. Image SHA-256:e80d2d1f9cfb328c79a5031d6a30f9744ec83824f6ba44c41ce831ff829a5dad.f6bc10589e6308fdc405faa104835cd6bcc486c4bc3fba95b5808b94267f1d05; release commit:dfdecf30d681c553a906ceebb13c859bb1b46ef3. Only0.1.0+zypperfixture1is synthetic.Docs and support boundary
Updated the homepage, install guide, openSUSE user/maintainer guides, support matrix, release guide, packaging guide, navigation, and unreleased notes. The repository is identified as third-party; Leap and non-x86_64 targets remain unsupported.
Production provider ownership, HTTPS/storage, signing custody, GitHub variables/secrets, first public publication, and activation remain the five unchecked Human operational tasks. No production account, host, credential, key, repository, or website activation was changed by this PR.