Skip to content

Phoenix Key: prove update and rollback lifecycle - #148

Draft
Bboy9090 wants to merge 2 commits into
mainfrom
convergence/phoenix-key-update-rollback-proof
Draft

Phoenix Key: prove update and rollback lifecycle#148
Bboy9090 wants to merge 2 commits into
mainfrom
convergence/phoenix-key-update-rollback-proof

Conversation

@Bboy9090

@Bboy9090 Bboy9090 commented Aug 31, 2026

Copy link
Copy Markdown
Owner

Purpose

Provide a real two-version Phoenix Key update/rollback proof without weakening the downstream artifact contract.

Baseline: Phoenix Key 3.1.0 source f68c2cb917ec1d800956232de7ea99e60cdb94f7
Candidate: Phoenix Key 3.2.0 exact PR head d2afb2cf18db2aa68899809035711291128150c5

Exact-head evidence

Workflow: Phoenix Key Update Rollback
Run ID: 33424190304
Result: SUCCESS

Successful jobs:

  • build-version-pair
  • update-rollback (msi)
  • update-rollback (nsis)

The workflow built both source versions and independently proved MSI and NSIS lifecycle:

  • clean runner
  • baseline 3.1.0 install + source-bound smoke PASS
  • candidate 3.2.0 update/install + source-bound smoke PASS
  • candidate removal
  • known-good 3.1.0 reinstall + source-bound smoke PASS
  • final uninstall and clean removal

Retained evidence:

  • version pair artifact 9770336654, archive SHA-256 8f64b5ddf4b96e893431c7d3d7a6feed545948de7824c6ece65087dafb09bddc
  • MSI update/rollback artifact 9770364551, archive SHA-256 e31efefea835f340f01cf3e6c9b9f4a96a49ef12c89dd9ca4f8fcf4e3b3f6e12
  • NSIS update/rollback artifact 9770357378, archive SHA-256 129043b2f6b07f956ff8a69fe27453bb93545582d5738016aa33747ceeb4a193
  • MSI proof receipt SHA-256 36a7c41534ca34aaac148afd09cefffa41c47a15de8793f3180842b55b292d3f
  • NSIS proof receipt SHA-256 4790a6c3abd1d8706250bb42d6fb06614e7b2273faaf1d3dcd5c70cadd57aac4

Truth boundary

The host update/rollback lifecycle is now validated. Signing, ARCWYRE-native compatibility, physical hardware validation, and release-candidate status remain separate gates.

Downstream bluephoenix-native already retains an observed receipt bound to this run; package-byte import/revalidation remains the mechanical step before its registry can be promoted.

Keep draft until downstream evidence reconciliation is complete.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant