P343 · Workflow control

Promote the Exact Verified Artifact

Keep the identity of the tested artifact unchanged through staging, publication and promotion, and read it back.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

A release tests archive A but rebuilds B under the same version before publishing. Dependencies/environment may alter bytes even without source changes. Preserve tested artifact identity through promotion, separately from release authorization.

Mechanism

Pack once from intended revision, record digest/environment and test that archive. Stage identical bytes, read actual served content/integrity, then promote and read back. B is a new candidate if rebuilt, not covered automatically by A. Report mismatches/unverified states rather than using a version label as identity.

Bad example

A passed, so publish rebuilt B with the same version and claim verified delivery without readback.

Good example

Carry A through source/digest/test/stage/readback. Match served bytes before authorized promotion and verify the promoted identity. A mismatch or rebuilt B stops that promotion as an unverified candidate. Evidence identifies the actual delivered artifact, not version text alone.

Why the change matters

Rebuilds sever tested/delivered identity. Digest/readback preserve continuity and expose wrong archives/sources or same-version byte drift.

Observable expectation

An illustrative chain records revision→A digest→test→stage read→promotion read. B/wrong-source substitution fails identity checks.

Equal bytes do not replace required tests/permission; no package is published here.

Limits

Deterministic builds reduce variation without eliminating identity/signature/supply-chain checks. Frozen registry/version/platform commands are instances, not current procedures to execute.

Sources and evidence

Read the editorial criteria