Skip to content

Enforce signed read-only driver policy and public feedback flow#614

Merged
frahlg merged 1 commit into
masterfrom
codex/driver-source-cutover
Jul 20, 2026
Merged

Enforce signed read-only driver policy and public feedback flow#614
frahlg merged 1 commit into
masterfrom
codex/driver-source-cutover

Conversation

@frahlg

@frahlg frahlg commented Jul 20, 2026

Copy link
Copy Markdown
Member

Summary

  • Bind verified signed read-only package permissions to the Lua host and deny writes during every lifecycle phase.
  • Report exact managed package provenance while keeping local unsigned overlays first and leaving the managed cache unchanged.
  • Point shared driver work to srcfl/device-drivers, document the local offline flow and add the gated Sungrow observe-only pilot checklist.
  • Add review-first driver issue diagnostics and separate FTW bug and feature links.

Release boundary

  • No control driver is enabled.
  • No driver package is signed or published by this PR.
  • Public source lock: srcfl/device-drivers 61157e670e1acea568c90090f3cd13e47510d8c9, tree 9a447d54cb48083f0ff32a099a6097c26b921af6.
  • Private lock update merged in srcfl/srcful-device-support#18 as d4d58b928e9ae5c47009a75d3fd2fb02ac3a86a3.

Verification

  • make verify
  • focused Go tests for config, driver inventory, repository and Lua host policy
  • npm test: 60 passed
  • git diff --check and changed documentation link audit
  • browser render at 1280 px and 390 px: five destinations, History ledger and decision timeline, boost start/stop, feedback review, no horizontal overflow, no console errors after final startup

@frahlg
frahlg merged commit b5b3ae5 into master Jul 20, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant