Skip to content

Execute 3-OS immutable Registry consumer proof and rollback outcome #173

Description

@StatPan

Goal

Produce the CLI-owned, independently reviewable public consumer-proof matrix for one exact immutable published StatPan/datapan-registry Hugging Face revision: public installer install, datapan doctor, Registry journey on Linux, macOS, and Windows; plus an actual incompatible-result rollback or manual_hold outcome.

Parent: #165. Supersedes neither the historical single-host compatible receipt in #168 nor the offline receipt contract in #166.

Scope

  • Start only after Registry #592 records an explicit publication and anonymous pointer/payload verification for the exact immutable Dataset revision, Registry digest, manifest digest, and safe prior-pointer candidate.
  • On all three public installer platforms, bind the same immutable CLI revision and exact published Dataset revision; retain redacted observed install, doctor, and journey outcomes for each platform.
  • Execute one real incompatible-result path against that admitted public release boundary. Record either an observed prior-pointer rollback followed by observed CLI install/doctor result, or manual_hold with no_safe_target; never call either state successful without its actual observed result.
  • Schema/admission-validate each observed receipt using caller-owned time. Preserve only allowed redacted receipt fields.

Boundaries

  • Do not publish or release Registry, mutate Registry branches/manifests, issue/rotate/store credentials, call public-data providers, or treat fixtures, source CI, Registry Journey regression CI, or Execute an admitted post-publication Registry consumer smoke #168 as evidence for this matrix.
  • CLI does not make Registry pre-publication admission depend on CLI execution. Registry never checks out, builds, or executes CLI.
  • Do not remove checkout guards or progress Registry #593 from this task; #593 remains separately blocked until it can consume the real cross-repository rollback/manual-hold evidence.

Dependencies

  • Registry #592: exact immutable producer receipts admitted, explicit public release recorded, and anonymous pointer/payload verification complete.
  • Registry #593: consumes this task's actual rollback/manual-hold evidence; it is not unblocked by a compatible smoke alone.
  • A prior public immutable pointer that is safe to attempt for the required failure path, or an explicit no-safe-target decision that permits manual_hold.

Acceptance Criteria

  • Three retained evidence_class:"observed" receipts bind one immutable CLI revision and one exact published Dataset revision, Registry/manifest digests, public installer outcome, doctor outcome, journey outcome, platform, and observation time for Linux, macOS, and Windows.
  • The receipts are schema-valid, redacted, fresh at their caller-owned admission time, and independently reviewable; no fixture or CI-only vector is counted as an observed platform result.
  • A real incompatible result produces either observed prior-pointer rollback plus observed post-rollback CLI install/doctor proof, or manual_hold with rollback.state:"no_safe_target" and the actual reason.
  • Registry #592 publication/anonymous-verification receipt and Registry #593 dependency are linked in the execution evidence; no Registry pre-publication gate, publish action, or checkout-control change is made here.
  • Completion note distinguishes compatible matrix proof, rollback success, and manual_hold; it does not claim a new Registry publication without its exact observed Registry receipt.

Doctor Impact

No doctor semantic change is in scope. This task observes the existing CLI installer and doctor contract only.

Stop Conditions

  • Stop before any public install or failure-path execution when the exact published revision, public pointer/payload/manifest/Registry digests, or rollback/manual-hold authority is absent.
  • Stop and record the concrete missing upstream receipt rather than infer it from a fixture, source CI, or a stale public payload.

Metadata

Metadata

Assignees

No one assigned

    Labels

    status:blockedBlocked by an external dependency or decision.type:taskConcrete implementation task.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions