From 4efa52921579affbbdfee695ed4f1ff838d632bd Mon Sep 17 00:00:00 2001 From: "pulse-triage[bot]" <249995291+pulse-triage[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 05:51:28 +0100 Subject: [PATCH] Close release-note qualification input and fixture gaps Bind the new compiled notes helper and authored fixture in the rootful source manifest. Repair the visual rollback fixture's missing version and align the internal control-plane page with the active release-reliability target, without changing source routing or published packets. Change-source: pulse-maintainer --- .../release-control/internal/CONTROL_PLANE.md | 20 ++++++++++--------- .../HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md | 1 + .../subsystems/deployment-installability.md | 4 ++++ .../release_note_visuals_test.py | 1 + ...ure_runtime_rootful_attestation_v1_test.py | 2 ++ ...re_runtime_rootful_source_manifest_v1.json | 2 ++ 6 files changed, 21 insertions(+), 9 deletions(-) diff --git a/docs/release-control/internal/CONTROL_PLANE.md b/docs/release-control/internal/CONTROL_PLANE.md index 129ba0d39..167bb7c07 100644 --- a/docs/release-control/internal/CONTROL_PLANE.md +++ b/docs/release-control/internal/CONTROL_PLANE.md @@ -242,16 +242,16 @@ user language should update the control plane. ## Current State 1. v6 is the current active release profile. -2. `v6-product-lane-expansion` is the current active engineering target. - Pulse v6 GA and the initial 6.0.x patch line have shipped; active - development and stable release preparation now run on `main`. +2. `v6-release-reliability` is the current active engineering target. + Pulse v6 has shipped. Active development runs on `main`; release preparation + uses the exact source line resolved by `control_plane.json`. 3. `v6-ga-promotion` is complete. Its release records remain historical evidence and must not keep pre-GA branch, checkout, or readiness posture active in current lane state. -4. Candidate lanes and coverage gaps now route post-GA product expansion. - Release-blocking correctness work may still override that default queue - when a shipped customer contract can drift across billing, entitlements, - runtime behavior, or public copy. +4. Reported defects, dependable delivery and release qualification take + priority over new product expansion. Candidate lanes and coverage gaps + support that work; billing, entitlements, runtime behavior and public copy + remain customer contracts that must not drift. 5. `v6-rc-stabilization` is completed after the shipped RCs established the current monitored-first floor and the active objective moved to stable promotion. @@ -259,8 +259,10 @@ user language should update the control plane. 7. The existing v6 control surfaces are still live, but they now sit underneath an evergreen Pulse control plane rather than pretending to be the whole long-term system. -8. Both prerelease and stable v6 promotions resolve to `main` via - `control_plane.json`. +8. The v6 profile defaults to `main`; explicit version overrides in + `control_plane.json` bind existing releases to `release/v6.4` and + `release/v6.5`. A new checkpoint's mapping is verified during governed + preparation, not inferred from the profile default or this page. 9. Legacy maintenance releases that still feed governed automation outside the active v6 line must also resolve through `control_plane.json`. Right now the remaining `5.1.x` stable maintenance line resolves to `main` diff --git a/docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md b/docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md index 31dd05748..502c99bf6 100644 --- a/docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md +++ b/docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md @@ -1023,6 +1023,7 @@ Companion drill: - Automated proof: `go test ./scripts/installtests -run 'TestStablePatchReleaseNotes' -count=1` `cd scripts/release_control && python3 -m unittest render_release_body_test` + `cd scripts/release_control && python3 -m unittest secure_runtime_rootful_attestation_v1_test release_note_visuals_test documentation_currentness_test` `cd scripts/release_control && python3 -m unittest resolve_release_promotion_test release_promotion_policy_test` `go test ./scripts/installtests -run 'Test(Demo|DeployDemo|UpdateDemo|Release)' -count=1` - Manual scenario: diff --git a/docs/release-control/v6/internal/subsystems/deployment-installability.md b/docs/release-control/v6/internal/subsystems/deployment-installability.md index 5be7fa997..3d3d41935 100644 --- a/docs/release-control/v6/internal/subsystems/deployment-installability.md +++ b/docs/release-control/v6/internal/subsystems/deployment-installability.md @@ -1935,6 +1935,10 @@ artifact-selection behaviour. the changelog and release metadata, not a mandatory public boilerplate sentence. Historical published notes are not edited or re-rendered to fit a later authoring template. + The rootful qualification source manifest retains the complete compiled + install-test package, including the release-notes helper and its exact + authored-copy fixture. Accepting grouped notes must not silently narrow + that attested source boundary. Qualification counts, readiness assertions, release gates, workflow narration, artifact identity, and promotion metadata stay in governed workflow summaries and evidence records rather than the public changelog. diff --git a/scripts/release_control/release_note_visuals_test.py b/scripts/release_control/release_note_visuals_test.py index cb169a99a..f3f93abf1 100644 --- a/scripts/release_control/release_note_visuals_test.py +++ b/scripts/release_control/release_note_visuals_test.py @@ -176,6 +176,7 @@ class ReleaseNoteVisualPlanTest(unittest.TestCase): "Args", (), { + "version": "6.4.0", "rollback_target": "v6.3.2", "rollback_command": "sudo /bin/update --version v6.3.2", }, diff --git a/scripts/release_control/secure_runtime_rootful_attestation_v1_test.py b/scripts/release_control/secure_runtime_rootful_attestation_v1_test.py index beb40af50..2d058d1e2 100644 --- a/scripts/release_control/secure_runtime_rootful_attestation_v1_test.py +++ b/scripts/release_control/secure_runtime_rootful_attestation_v1_test.py @@ -489,6 +489,8 @@ if module.MAX_RECEIPT_BYTES <= 0: def test_manifest_contract_binds_transitive_harness_and_production_boundary(self) -> None: manifest = json.loads((Path(__file__).with_name("secure_runtime_rootful_source_manifest_v1.json")).read_text(encoding="utf-8")) required = { + "scripts/installtests/release_notes_contract_test.go", + "scripts/installtests/testdata/release-notes-v6.4.5-authored.md", "scripts/installtests/secure_runtime_rootful_qualification_test.go", "scripts/installtests/secure_runtime_rootless_qualification_test.go", "scripts/installtests/secure_runtime_systemd_lab_test.go", diff --git a/scripts/release_control/secure_runtime_rootful_source_manifest_v1.json b/scripts/release_control/secure_runtime_rootful_source_manifest_v1.json index 45fee927c..758b48ce0 100644 --- a/scripts/release_control/secure_runtime_rootful_source_manifest_v1.json +++ b/scripts/release_control/secure_runtime_rootful_source_manifest_v1.json @@ -28,12 +28,14 @@ "scripts/installtests/provider_msp_deploy_test.go", "scripts/installtests/pulse_auto_update_test.go", "scripts/installtests/release_ldflags_test.go", + "scripts/installtests/release_notes_contract_test.go", "scripts/installtests/root_install_sh_test.go", "scripts/installtests/safe_profile_migration_test.go", "scripts/installtests/secure_runtime_platform_matrix_test.go", "scripts/installtests/secure_runtime_rootful_qualification_test.go", "scripts/installtests/secure_runtime_rootless_qualification_test.go", "scripts/installtests/secure_runtime_systemd_lab_test.go", + "scripts/installtests/testdata/release-notes-v6.4.5-authored.md", "scripts/installtests/testdata/secure_runtime_docker_fixture.go", "scripts/installtests/umask_unix_test.go", "scripts/installtests/uninstall_sensor_proxy_test.go",