Skip to content

Bind installer artifacts to platform identity - #8

Merged
oratis merged 5 commits into
codex/hardware-coveragefrom
codex/platform-identity
Aug 1, 2026
Merged

Bind installer artifacts to platform identity#8
oratis merged 5 commits into
codex/hardware-coveragefrom
codex/platform-identity

Conversation

@oratis

@oratis oratis commented Jul 30, 2026

Copy link
Copy Markdown
Owner

Summary

  • bind each payload and ISO to a machine-readable platform variant, architecture, boot provider, HEP ID, digest, and checksum
  • reject Apple hardware, architecture mismatches, boot-provider mismatches, and payload identity mismatches before installation
  • require virtualization before the destructive CI installer can partition a disk
  • run the same platform preflight for interactive installs and cover the guard with 11 fixtures

Validation

Scope

This PR creates the safety and artifact identity boundary for separate PC, Intel Mac, T2, and Apple Silicon release lines. It does not claim Mac support.

@oratis

oratis commented Jul 30, 2026

Copy link
Copy Markdown
Owner Author

Final E2E evidence: https://github.com/oratis/Andromeda/actions/runs/30536367639 completed successfully. The exact head SHA passed payload/ISO build, platform identity manifest and OCI-label cross-checks, guarded installation to a blank 64 GiB UEFI disk, first boot, desktop checks, v2 update, v1 rollback, three virtual hardware profiles, evidence upload, and installer upload.

@oratis
oratis marked this pull request as ready for review July 30, 2026 11:57
@oratis
oratis merged commit 46642e4 into codex/hardware-coverage Aug 1, 2026
5 checks passed
@oratis
oratis deleted the codex/platform-identity branch August 2, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant