From 0f30947b75f4e68c50aa25caaf962e38924ed83f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?D=C3=A1vid=20Balatoni?= Date: Mon, 21 Sep 2026 22:38:44 +0200 Subject: [PATCH] docs(tizen): record the rc2 device evidence and executed CI Co-Authored-By: Claude Opus 5 --- docs/tizen/ACCEPTANCE.md | 25 +++++++++++++++++++++++-- docs/tizen/BUILD.md | 26 ++++++++++++++++---------- 2 files changed, 39 insertions(+), 12 deletions(-) diff --git a/docs/tizen/ACCEPTANCE.md b/docs/tizen/ACCEPTANCE.md index a02659705..898cc7c4a 100644 --- a/docs/tizen/ACCEPTANCE.md +++ b/docs/tizen/ACCEPTANCE.md @@ -143,6 +143,23 @@ channels for device evidence. - Signing now uses a preserved author key held outside the repository, so upgrades install in place. Losing it would again force a reinstall; it is the operator's to back up. The per-session disposable authors are no longer used for the TV. +- The first CI-built signed package was installed from the published + pre-release `tizen-v2.20.1-rc2`, rather than from a local build. Release + asset TPK SHA-256 + `a76d6153c85c5c82b1d8997a91c8841c3af39df79fd8eca6a25130a89ff8c61e`, + source-input SHA-256 + `5f2d240394068e19ce13d94b9c29969d3cb1df79bd2e14047af91aa80e2dff82`, + source revision `16b0ae89c604648b566a4345b3baace35b402d17`, clean tree. + The hash was checked against `SHA256SUMS` at every hop, including inside the + deploy container immediately before installation. SDK SDB 4.2.36 reported + `install completed` as an in-place signed upgrade over the previous build: + no uninstall, no app data cleared. Launch was accepted. +- With that build the operator confirmed both that the sidebar no longer offers + a fullscreen toggle and that playback works. Retail `sdbd` refuses arbitrary + shell verbs, so process liveness was not confirmed from the CLI; only + `applist` and `was_execute` are available, and the observation is the + operator's. This is functional confirmation by observation, not a measured + benchmark, and it does not close the device-matrix rows. - `inspection.json` remains the build-time report; its installation flag is not retroactively changed. Independent cryptographic verification is pending. @@ -174,7 +191,12 @@ channels for device evidence. - CI now separates Ubuntu 22.04 host checks from the pinned Focal API-6 package build. Actionlint passes. The four guarded upstream workflows have no added yamllint findings relative to the baseline; inherited formatting is preserved. - No GitHub workflow execution is claimed. +- The workflow has since run on GitHub. Run + (tag + `tizen-v2.20.1-rc2`) completed both `tv-arm-release` and + `tv-arm-signed-release` successfully and attached the package to a + pre-release. For a pull-request event `tv-arm-signed-release` is skipped, as + the fork-safety guard intends. ## Verification tiers @@ -274,6 +296,5 @@ extract. Only the explicitly allowlisted build artifacts belong in ordinary PR C subtitle burn-in/conversion, not just fake channel responses. - Execute the isolated device suite and process-restart/upgrade checks. - Establish independent cryptographic verification and Samsung entitlement. -- Run the checked-in GitHub workflow and record its actual run URL. Do not call the port production-ready while these acceptance gates remain open. diff --git a/docs/tizen/BUILD.md b/docs/tizen/BUILD.md index 64d994768..1086ec92a 100644 --- a/docs/tizen/BUILD.md +++ b/docs/tizen/BUILD.md @@ -10,16 +10,22 @@ See [PORT.md](PORT.md) and `tizen/toolchain.json` for provenance and exact pins. configured `tizen60` project. This does not prove every runtime API on the TV. - The pure .NET geometry tests have passed. Dart channel tests use fake native channels; they are not playback or physical-remote tests. -- A 28 MB release-mode, disposable-test-signed TPK passed structural inspection - and direct SDK installation on the target TV, but closed immediately. - An isolated diagnostic app captured a missing integration-test registration - entry point. After the dependency correction, the same inspected release - payload reached a stable login page in a separate diagnostic app on the TV, - with native player/window initialization and initial database startup verified. - See [ACCEPTANCE.md](ACCEPTANCE.md) for hashes and current evidence. -- The corrected production-identity package is not installed. Independent - cryptographic verification, playback and storage/remote acceptance remain open. -- CI is defined but has not been run on GitHub. No release has been published. +- Early release-mode, disposable-test-signed TPKs installed but closed + immediately; the cause was a missing integration-test registration entry + point, since corrected. That history is superseded by the entries below and + is retained only in [ACCEPTANCE.md](ACCEPTANCE.md), with hashes. +- A production-identity package signed by the preserved author is installed on + the target TV as an in-place upgrade. The operator has confirmed Jellyfin + playback with picture, audio, seek and the Flutter controls together. See + [ACCEPTANCE.md](ACCEPTANCE.md) for the current status line and evidence. +- Independent cryptographic verification and Samsung entitlement remain open, + as do storage/remote acceptance and the device-matrix rows. `inspection.json` + still reports `cryptographic_signature_verified` and `tv_installation_verified` + as false: it is a build-time structural report and is not retroactively + changed by a later successful installation. +- CI has been run on GitHub and pre-releases are published from `tizen-v*` tags. + A green workflow and an attached package are build evidence, not device + acceptance. ## Reproducible Linux environment