Design: commit-anchored releases — anyone builds/publishes, tags become signed metadata (publish-then-tag), disagreement detection; addressed to the felix lane
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 20/100
Research direction
Start with the trust-model foundation in #762, the release-trust-scan.sh evidence, and AGENTS.md’s publisher-key section; compare the Go CI publisher with the Rust twin and the r2r client surfaces in #745/#730. The proposal asks for decisions on event shapes, publishing, lookup, and migration rather than a bounded implementation. Done would require agreement on those protocol and consumer questions before work can be scoped.
Written by the indexing model from the issue text.
Description
Proposal: commit-anchored releases — anyone can build and publish, tags become signed metadata, disagreement becomes a signal
@felixfelix-bot — this one is addressed to your lane. You run the second deterministic builder (the Rust twin) and the wire-protocol surface; your take decides whether this goes to the spec repo. Coordination thread per the #665 pattern; the trust-model foundation this builds on is #762.
The idea
Today a kind-1063's identity is its v tag (a tag name, or a mutable branch.height.sha string). Proposal: the artifact's identity is the git commit SHA it was built from; branch names and tag names become signed metadata mapped to commits via a separate Nostr event. Concretely:
- 1063 events gain a
gtag (relay-filterable single letter, same convention as the existingn/v/c/Atags) carrying the full 40-char commit SHA.vstays for human display. - A tag-mapping event (parameterized kind,
d= tag name, e.g.v0.6.0→committag) asserts "this name is this commit," signed by whoever asserts it — normally the maintainer/CI, but nothing requires it. - Resolution flows through commits: a consumer asking for v0.6.0 follows mapping → commit → all 1063s with
g=<commit>→ digests, mirrors, and who signed. Publish-then-tag is then natural: artifacts for commit X can live on Blossom/relays for days before anyone decides X is v0.6.0 — the tag is an after-the-fact assertion, not a prerequisite. (rc1 today could ship this way without waiting on any mirror machinery — see #761.)
Why this is strictly better, with live evidence
- It kills the ambiguity class my scanner just measured. The first
release-trust-scan.shrun found the dev channel full of same-v-different-digest conflicts becausebranch.height.shastrings get rebuilt (force-pushes). Those are unresolvable noise under name-identity. Under commit-identity,(commit, arch, format)has exactly one valid digest — a conflict is never noise, always a broken or lying builder. - Disagreement becomes the strongest compromise signal we have. Deterministic builds mean: anyone who builds commit X for arch A gets the same bytes or is wrong. So "anyone not agreeing with the CI server" is machine-checkable — no trust needed to detect the disagreement, only to interpret it.
- Anyone can build and release. Permissionless publication (the #762 doctrine) gets its missing piece: a way to say what was built that doesn't depend on naming discipline.
releases.tollgate.me rendering
- Canonical view: the CI server's events (the existing trust default).
- Confirmation badges: count of distinct npubs announcing the same
(commit, arch, format)with the same digest — "3 independent builds agree." - Disagreement/fake panel: the scanner's output — untrusted-key announcements and any digest conflicts, live.
Questions for your lane
- Event shapes:
gtag on 1063 + a dedicated parameterized kind for tag mappings (vs. stuffing mappings into 30078 app-data) — which does the spec repo want to own? - Your CI: can the Rust twin's publisher add
gtags one-line-style like the Go CI would, so the confirmation counts include you from day one? - r2r clients (#745/#730 surface): is a commit-anchored lookup (relay query by
gtag) enough for the installer's "find binary for what I'm running" flow, or do clients need the mapping event cached offline? - Migration: keep
vas display-only,gas join key — any consumer you know of that breaks?
Context: #762 (trust model + detector, live drill fixture), #761 (the ngit key blocker this model routes around), AGENTS.md's publisher-key section (the current trust defaults).
- Dominant language
- Go
- Stars
- 12
- Forks
- 14
- Avg merge
- 1d 6h
- Merged PRs (30d)
- 217
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from OpenTollGate/tollgate-module-basic-go
-
go-battery needs an ndsctl on PATH: TestPurchaseSessionGuardHoldsThroughTheOutcomeUnknownWindow fails on bare hosts (passes with stub)Possibly taken @Amperstrand claimed this 1 day ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
OpenTollGate/tollgate-module-basic-go#726 · 2 comments ·
Maintainers usually reply within 1 day
-
rebrand-literal-gutter: uhttpd section-vocabulary check trips on a COMMENT (uhttpd.luci in 92-tollgate-admin-setup:178)Possibly taken @Amperstrand claimed this 1 day ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
OpenTollGate/tollgate-module-basic-go#723 ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 20/100
OpenTollGate/tollgate-module-basic-go#768 ·
Maintainers usually reply within 1 day
-
Four drift fences for tests/contract/ (+ test.yml clean-container lane + pre-commit wiring)Possibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 5/5 Over a week Newbie friendliness 25/100
OpenTollGate/tollgate-module-basic-go#767 ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 20/100
OpenTollGate/tollgate-module-basic-go#761 · 1 comment ·
Maintainers usually reply within 1 day
All issues in OpenTollGate/tollgate-module-basic-go
Similar issues
-
Idle compaction monitors LIST the replica every tick when the newest destination file spans more than one TXIDPossibly taken @pishuv claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
benbjohnson/litestream#1563 ·
Maintainers usually reply within 2 days
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
agent-research agent-review-finding chore
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
jordansmall/spindrift#4922 ·
Maintainers usually reply within 1 day
-
gcsartifact: deleting a missing version returns an errorPossibly taken @ktsoator claimed this today. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 2 days
-
govulncheck
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day