From bcf6625d7b9d108fa83dc6af5a7e345fe728af89 Mon Sep 17 00:00:00 2001 From: Julian Noble Date: Tue, 28 Jul 2026 23:03:10 +1000 Subject: [PATCH] G-135 activated: asset provenance records User-directed proposed->active flip. Activation freshness survey (goals_xref score G-135) found no relationships beyond those already recorded in the detail file (G-136, G-057, G-128, G-133 all referenced; higher-scoring unlinked pairs are lexical coincidence). goals_lint clean. Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com --- GOALS.md | 2 +- goals/G-135-asset-provenance-records.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/GOALS.md b/GOALS.md index 4098c8f4..544ddec4 100644 --- a/GOALS.md +++ b/GOALS.md @@ -411,7 +411,7 @@ Detail: goals/G-132-tcl-windows-errno-catchall-report.md Scope: src/make.tcl (post-assembly offset-style probe at the G-133 advisory-check seam, recapped reporting); src/modules/punkboot/utils-999999.0a1.0.tm (probe predicate beside the G-133 scan helpers, guarded require; bootsupport copies via established sync channels); src/tests/modules/punkboot/utils/ + src/tests/shell/testsuites/punkexe/ (characterization); src/AGENTS.md (what the pin does and does not guarantee) Detail: goals/G-134-baked-kits-pinned-archive-relative.md -### G-135 [proposed] Asset provenance records: a verifiable master-to-derived icon chain with a platform-neutral generator +### G-135 [active] Asset provenance records: a verifiable master-to-derived icon chain with a platform-neutral generator Scope: src/assets/logo/ (per-asset *.assetorigin.toml sidecars, masters and generated icons); src/assets/logo/make-ico.ps1 (replaced in place by a Tcl generator, then removed); scriptlib/developer/ (provenance checker, sibling to goals_lint and architecture_lint); checker home revisited if it becomes a bake step (a punk:: module rather than scriptlib, which make.tcl must not depend on); src/runtime/punkshell.ico and src/vfs/_vfscommon.vfs/punkshell.ico (recorded as derived copies, not relocated) Detail: goals/G-135-asset-provenance-records.md diff --git a/goals/G-135-asset-provenance-records.md b/goals/G-135-asset-provenance-records.md index 2eea74f7..4175dcf3 100644 --- a/goals/G-135-asset-provenance-records.md +++ b/goals/G-135-asset-provenance-records.md @@ -1,6 +1,6 @@ # G-135 Asset provenance records: a verifiable master-to-derived icon chain with a platform-neutral generator -Status: proposed +Status: active Scope: src/assets/logo/ (per-asset *.assetorigin.toml sidecars, masters and generated icons); src/assets/logo/make-ico.ps1 (replaced in place by a Tcl generator, then removed); scriptlib/developer/ (provenance checker, sibling to goals_lint and architecture_lint); checker home revisited if it becomes a bake step (a punk:: module rather than scriptlib, which make.tcl must not depend on); src/runtime/punkshell.ico and src/vfs/_vfscommon.vfs/punkshell.ico (recorded as derived copies, not relocated) Goal: Any committed icon in the tree can state what it was derived from and be checked against that claim on any platform, and regenerating one from its master needs no Windows-only tooling - while an icon carrying no record stays a fully supported and silent case. Acceptance: the `.assetorigin.toml` sidecar format is documented with a `schema` key, the recorded asset bound by the sidecar's own filename (suffix stripped, same directory) and the source reference relative to that directory, files ending in the suffix being records, never assets; a reader tolerates a missing sidecar, unknown keys and an unrecognised schema version without erroring; a checker written in plain Tcl - no rasterizer, no external binary, runnable under any punkshell runtime - classifies each asset it examines as exactly one of `unrecorded` (no sidecar), `verified`, `artifact-absent` (a sidecar whose paired asset is gone), `source-absent`, `replaced` or `stale` per the state table in this file, where `verified` requires every hash the sidecar records to match, so a sidecar carrying only the artifact hash is verified on that alone, demonstrably distinguishing `stale` (source changed since the artifact was generated) from `replaced` (artifact changed since recording) and from `artifact-absent` on constructed fixtures, and is advisory only, never failing a build, in the manner of the G-133 payload checks; the icon generator is reimplemented with no Windows-only component (`System.Drawing` in particular), regenerating every generated `.ico` under `src/assets/logo/` byte-identically to the current `make-ico.ps1` under the invocation profile that produced it before that script is removed, and (re)writing the sidecar of each artifact it produces - artifact and source hashes plus the invocation options - so regeneration cannot leave a stale record; and sidecars exist and verify for every generated artifact under `src/assets/logo/`, `alternative/`, `web/` and `project-default/`.