Repository navigation
Ship signed cross-platform compiler distributions #102
Description
Activity
- addeddocumentationImprovements or additions to documentationImprovements or additions to documentationenhancementNew feature or requestNew feature or request
on Aug 29, 2026 Toolchain update automation is implemented in #113. It moves workflow-owned locks to
toolchains/, adds weekly activity-gated stable upstream discovery, and suppresses native production for already-selected fingerprints. PR CI passed with unit/race/native jobs correctly skipped for this infrastructure-only change.Toolchain run 33316758497 produced all six immutable assets successfully; only lock fan-in failed because same-name record artifacts were merged into one path. PR #113 recovers those real records without rebuilding, fixes artifact fan-in, and passed CI in run 33326029222.
Published first public release: https://github.com/PeeperLanguage/compiler/releases/tag/v0.1.0
Verified release run: https://github.com/PeeperLanguage/compiler/actions/runs/33327852177
Completed in this release:
- six compiler components and six target runtime components
- six independently pinned immutable toolchains in release manifest
- all six fresh-install doctor and source-fixture verification jobs
- six SPDX SBOMs
- Ed25519-signed release manifest
- SHA256SUMS verified against every listed release asset
- GitHub provenance attestation verified
- 27 uploaded assets
Release remains non-draft, non-prerelease, and latest. Keeping issue open because its stated scope still includes Apple notarization and Windows Authenticode signing, which were not claimed by this pipeline.
Simplified release architecture merged in #117: release manifest schema 2 (compiler + toolchain per host, runtime bundled in compiler pack), six host-local release pipelines with fresh-install verification, protected finalization job (sign + SHA256SUMS + draft), and one-command bootstrap installers (install.sh / install.ps1) with SHA-256 verification and idempotent PATH persistence. Remaining for this issue: publish next release candidate and validate draft assets on all six hosts.
Final architecture shipped (supersedes earlier comment): the Go-based native installer was removed in #120. Installation is now pure-script:
install.sh/install.ps1download the release manifest, verify it against SHA256SUMS, read pack URLs and SHA-256 digests for the detected host, download compiler and toolchain packs, verify every digest, extract into staging, and activate atomically. Release assets dropped from 27 (v0.1.0 original) to 11: six host packs, two bootstrap scripts, manifest, signature, SHA256SUMS. Manifest Ed25519 signature is still generated and published for out-of-band audit. v0.1.0 is published and verified end-to-end on Linux amd64 via the README one-liner. Remaining: Windows install.ps1 end-to-end validation (see follow-up issue), and macOS verification when a host is available.Closing as superseded by #122 for the remaining validation work.
Final disposition of scope:
Delivered and live in v0.1.0:
- Six-host native CI with fresh-install verification (doctor + x_test fixtures) per host
- Managed LLVM profiles and peeper_rt_v1 runtime ABI, bundled into compiler packs
- Deterministic compiler + toolchain packs, release manifest schema 2
- Ed25519-signed manifest (signature published for out-of-band audit), SHA256SUMS, draft-only promotion
- Pinned LLVM/musl/llvm-mingw inputs via content-addressed immutable toolchain prereleases
- Pure-script installers (install.sh / install.ps1) with SHA-256 verification and atomic activation; verified end-to-end on Linux amd64 via the README one-liner
Consciously removed during architecture simplification (#117, #120):
- Go-based native installer (replaced by bootstrap scripts)
- Separate target/runtime packs (merged into compiler packs)
- SPDX SBOMs, GitHub provenance attestations
- Apple code signing/notarization and Windows Authenticode expectations
Remaining validation tracked by #122 (Windows install.ps1 end-to-end); macOS verification to follow.
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsDone
Goal
Publish self-contained native Peeper compiler distributions for Linux, macOS, and Windows on amd64 and arm64.
Scope
Security boundaries
Validation
Status
Implementation merged through #103 as
acb405a. Push and pull-request CI both passed race detection and all six native host jobs.Keep issue open until first signed draft release validates signing, notarization, packaging, installer downloads, checksums, SBOMs, attestations, and native installation smoke tests.