Skip to content

Ship signed cross-platform compiler distributions #102

Description

@itsfuad

Goal

Publish self-contained native Peeper compiler distributions for Linux, macOS, and Windows on amd64 and arm64.

Scope

  • six-host native CI using scripts/build.sh
  • managed LLVM profiles and private peeper_rt_v1 runtime ABI
  • deterministic compiler, target, and toolchain packs
  • signed release manifest and atomic native installer
  • pinned LLVM, musl, and llvm-mingw inputs
  • Apple code signing and notarization
  • Windows Authenticode signing
  • SPDX SBOMs, checksums, and GitHub provenance attestations
  • draft-only release promotion

Security boundaries

  • build jobs receive no signing secrets
  • release components execute only after Ed25519, size, and SHA-256 verification
  • Apple SDK is discovered through xcrun and is never redistributed
  • v1 supports native compilation only; cross-compilation remains out of scope

Validation

  • focused distribution, installer, toolchain, target, and CLI tests
  • compiler bundle built only through scripts/build.sh
  • full source fixture suite with bundled compiler
  • six native GitHub runner gates in CI and release workflows
  • actionlint and packaging smoke validation

Status

Implementation merged through #103 as acb405a. Push and pull-request CI both passed race detection and all six native host jobs.

Keep issue open until first signed draft release validates signing, notarization, packaging, installer downloads, checksums, SBOMs, attestations, and native installation smoke tests.

Activity

  1. moved this from Todo to In Progress in Peeper Roadmapon Aug 29, 2026
  2. itsfuad commented on Aug 30, 2026

    @itsfuad
    MemberAuthor

    Toolchain update automation is implemented in #113. It moves workflow-owned locks to toolchains/, adds weekly activity-gated stable upstream discovery, and suppresses native production for already-selected fingerprints. PR CI passed with unit/race/native jobs correctly skipped for this infrastructure-only change.

  3. itsfuad commented on Aug 30, 2026

    @itsfuad
    MemberAuthor

    Toolchain run 33316758497 produced all six immutable assets successfully; only lock fan-in failed because same-name record artifacts were merged into one path. PR #113 recovers those real records without rebuilding, fixes artifact fan-in, and passed CI in run 33326029222.

  4. itsfuad commented on Aug 30, 2026

    @itsfuad
    MemberAuthor

    PR #113 merged as cf107a6. Main CI run 33326243041 passed. Toolchain planner run 33326243188 passed and skipped all six producers plus lock update because recovered immutable IDs already match the finished lock; no toolchain rebuild occurred.

  5. itsfuad commented on Aug 30, 2026

    @itsfuad
    MemberAuthor

    Published first public release: https://github.com/PeeperLanguage/compiler/releases/tag/v0.1.0

    Verified release run: https://github.com/PeeperLanguage/compiler/actions/runs/33327852177

    Completed in this release:

    • six compiler components and six target runtime components
    • six independently pinned immutable toolchains in release manifest
    • all six fresh-install doctor and source-fixture verification jobs
    • six SPDX SBOMs
    • Ed25519-signed release manifest
    • SHA256SUMS verified against every listed release asset
    • GitHub provenance attestation verified
    • 27 uploaded assets

    Release remains non-draft, non-prerelease, and latest. Keeping issue open because its stated scope still includes Apple notarization and Windows Authenticode signing, which were not claimed by this pipeline.

  6. itsfuad commented on Aug 30, 2026

    @itsfuad
    MemberAuthor

    Simplified release architecture merged in #117: release manifest schema 2 (compiler + toolchain per host, runtime bundled in compiler pack), six host-local release pipelines with fresh-install verification, protected finalization job (sign + SHA256SUMS + draft), and one-command bootstrap installers (install.sh / install.ps1) with SHA-256 verification and idempotent PATH persistence. Remaining for this issue: publish next release candidate and validate draft assets on all six hosts.

  7. itsfuad commented on Aug 30, 2026

    @itsfuad
    MemberAuthor

    Final architecture shipped (supersedes earlier comment): the Go-based native installer was removed in #120. Installation is now pure-script: install.sh / install.ps1 download the release manifest, verify it against SHA256SUMS, read pack URLs and SHA-256 digests for the detected host, download compiler and toolchain packs, verify every digest, extract into staging, and activate atomically. Release assets dropped from 27 (v0.1.0 original) to 11: six host packs, two bootstrap scripts, manifest, signature, SHA256SUMS. Manifest Ed25519 signature is still generated and published for out-of-band audit. v0.1.0 is published and verified end-to-end on Linux amd64 via the README one-liner. Remaining: Windows install.ps1 end-to-end validation (see follow-up issue), and macOS verification when a host is available.

  8. itsfuad commented on Aug 30, 2026

    @itsfuad
    MemberAuthor

    Closing as superseded by #122 for the remaining validation work.

    Final disposition of scope:

    Delivered and live in v0.1.0:

    • Six-host native CI with fresh-install verification (doctor + x_test fixtures) per host
    • Managed LLVM profiles and peeper_rt_v1 runtime ABI, bundled into compiler packs
    • Deterministic compiler + toolchain packs, release manifest schema 2
    • Ed25519-signed manifest (signature published for out-of-band audit), SHA256SUMS, draft-only promotion
    • Pinned LLVM/musl/llvm-mingw inputs via content-addressed immutable toolchain prereleases
    • Pure-script installers (install.sh / install.ps1) with SHA-256 verification and atomic activation; verified end-to-end on Linux amd64 via the README one-liner

    Consciously removed during architecture simplification (#117, #120):

    • Go-based native installer (replaced by bootstrap scripts)
    • Separate target/runtime packs (merged into compiler packs)
    • SPDX SBOMs, GitHub provenance attestations
    • Apple code signing/notarization and Windows Authenticode expectations

    Remaining validation tracked by #122 (Windows install.ps1 end-to-end); macOS verification to follow.

  9. moved this from In Progress to Done in Peeper Roadmapon Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationenhancementNew feature or request

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions