Add reproducible unprivileged Linux build and mount checks

This commit is contained in:
2026-10-09 18:32:37 -04:00
parent 8b177e21a0
commit 988aad9951
11 changed files with 212 additions and 10 deletions
+25
View File
@@ -2,6 +2,31 @@
This document defines the process for versioning and distributing the `sized` project independently of the Git hosting provider (GitHub, GitLab, Gitea).
## Source review before a release
Use a named branch from `main` and keep a pull request focused on one outcome.
The `sizequeen-scan-hardening` branch corrects accounting/error handling and
adds the scan controls needed by SizeQueen; shared-crate extraction follows
in a separate PR so reviewers can distinguish behaviour changes from packaging.
1. Run local locked tests and strict Clippy as an unprivileged user. Run
`./scripts/check-linux.sh linux/arm64` and
`./scripts/check-linux.sh linux/amd64` for the repeatable Linux checks,
including actual mount boundaries and an optimized-binary smoke test.
2. Push the review branch. Open a PR against `main` when its scope is ready,
explaining changed behaviour, test evidence and remaining limits. For this
branch, call out nonzero status on partial scans, added JSON status fields,
and library API changes. Record current work and evidence in `TODO.md`.
3. Review and merge independently of distribution. A branch push or PR merge
does not publish a package, change repository visibility or create a tag.
4. Choose the release version after reviewing library/API compatibility, then
use the release steps below when explicitly authorized. Reconcile legacy
GitLab download/package links before announcing a Gitea release.
Use the same Linux check script in Gitea CI when a Docker-capable runner is
configured. The current branch provides the local entry point; it does not
configure a runner or enable automatic publishing.
## 1. Versioning and Tagging
The project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).