Skip to content

release: 2.1.226 - #3100

Merged
wphillipmoore merged 14 commits into
mainfrom
release/2.1.226
Oct 6, 2026
Merged

wphillipmoore merged 14 commits into
mainfrom
release/2.1.226

Conversation

@wphillipmoore

Copy link
Copy Markdown
Collaborator

Summary

Release 2.1.226

Ref #3099

Generated with vrg-release

wphillipmoore and others added 14 commits October 3, 2026 09:09
chore(release): back-merge 2.1.225 and bump to 2.1.226
…ix (#3074) (#3087)

Add the binary-packaging foundation for epic vergil-project/.github#356 (Task T1): the target registry (lib/package/targets.py), the [package] vergil.toml section with its spec 5.4 hard validation and nFPM overlay shape check, matrix resolution into build/test cells plus the release artifact manifest, package-name resolution, PackageError, and the vrg-package CLI with its matrix subcommand. The ubuntu/26.04 glibc is 2.43, verified with ldd in the image.
…-line retention (#3079) (#3089)

Add lib/package/index/{config,collect,retention}. packages.toml is parsed strictly; collect lists stable vX.Y.Z releases, skips releases without packages-manifest.json with a note, and fails on a missing or unlisted package; verify pins gh attestation verify to the vergil-actions cd-release.yml workflow on refs/heads/main and requires an org signature on every rpm; retention keeps the newest lines and releases per product plus the transitive dependency closure, and fails when one package identity has different bytes in two releases.
… at release (#3081) (#3090)

Require the package / evidence status check in the CI-gates ruleset exactly when vergil.toml has a [package] section, classify it as the package evidence gate so vrg-ci-evidence harvest downloads ci-evidence-package, and register ci-package.yml's evidence context as producible.
… audit (#3091)

Adds "Public Domain" to the pip-licenses allowlist so public-domain dependencies (e.g. pyelftools, needed by #3075) pass vrg-validate's audit stage. Fleet-wide policy change approved by the human on 2026-10-05. Ref #3088.
…ge build (#3075) (#3092)

Add the builder registry and build orchestration (lib/package/build.py), the staged builder, nFPM config rendering with overlay validation and merge plus the raw-systemctl maintainer-script check, the pyelftools-based glibc floor guard, and the vrg-package build subcommand. pyelftools>=0.31 becomes a runtime dependency.
…ootstrap (#3076) (#3093)

Add lib/package/orgs.py (OrgRepo, ORGS with the vergil entry pinned to the OP1-attested primary fingerprint, for_vendor) and lib/package/repo_setup.py (Run, local_run, parse_primary_fingerprint, bootstrap for apt and dnf). The published key is verified to hold exactly one primary key matching the pin before any source is written; the bootstrap source and key are always removed after the keyring install. index/collect.py now takes Run/local_run from repo_setup.
…package index (#3094)

* feat(package): index: apt and dnf metadata, signing, size guard, vrg-package index (#3080)

Adds index/apt.py (Python-generated Packages/Packages.gz/Release), index/rpm.py (createrepo_c per EL and arch over a shared rpm/pool with --baseurl), index/sign.py (env-held key and passphrase via 0600 temp files, InRelease, Release.gpg, repomd.xml.asc), index/site.py (size guard and end-to-end build_site) and the vrg-package index subcommand. collect.verify gains an optional private rpm DB so the publish-index runner never writes the system rpm database.

* fix(package): emit SHA256-only apt metadata (#3080)

Semgrep (python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1) flagged the SHA1 field in Packages. apt verifies with SHA256, and MD5/SHA1 are not collision resistant, so Packages and Release now carry SHA256 only. The tests assert MD5 and SHA1 are absent.

Ref #3080
#3077) (#3095)

Add lib/package/python_builder.py, registered as builder "python": trust the vergil repo, install vergil-python<runtime> (apt in shared/native Ubuntu cells, dnf in native RHEL cells), read its PBS version, build the venv at /opt/<vendor>/<name>/venv from the runtime interpreter, uv sync --frozen --no-dev --no-editable --compile-bytecode, stage it, add /usr/bin shims and the vergil-python runtime dependency. A missing uv.lock is a hard config error (spec 5.4). vrg-package imports the builder so it registers.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… removal (#3078) (#3096)

Adds lib/package/install_test.py (select_artifact, run_install_test) and the vrg-package install-test subcommand. Smoke and shim checks run under a sanitized env -i environment with a system-only PATH; each /usr/bin shim must resolve to itself; removal must leave no residue under /opt/<vendor>/<name> or in the shims.
…or the index (#3097)

* feat(release): deferred package-index stage; consumer refresh waits for the index (#3082)

* test(release): write uv.lock in package-index test fixtures (#3082)

Once #3077 lands, builder = "python" requires a uv.lock next to vergil.toml (spec §5.4). These fixtures write a python [package] config, so they now write a lock too. On its own the extra file is harmless.

Ref #3082
…licit dev installs (#3083) (#3098)

A release version (vX.Y line or vX.Y.Z exact) now installs vergil-tooling on Lima and cloud VMs from the vergil apt repository: trust bootstrap via repo_setup, an apt preferences pin, a candidate check that fails naming the ref and repository URL when nothing matches, then apt install. Any uv-installed copy and the dev-ref marker are removed only after the apt install succeeds. A non-release ref is an explicit uv dev install that records its ref, and vrg-vm prints a DEV banner on create, rebuild, start, update and session while it is in place. get_tooling_version falls back to the installed deb version.
@wphillipmoore wphillipmoore mentioned this pull request Oct 6, 2026
10 of 12 tasks
@wphillipmoore
wphillipmoore merged commit 6247c03 into main Oct 6, 2026
30 checks passed
@wphillipmoore
wphillipmoore deleted the release/2.1.226 branch October 6, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant