#88·aos-ce

Certify the AOS release-to-Station adapter

Author: joshuajbouwCreated Aug 26, 2026Updated Aug 26, 2026
Labelscampaign/station

Outcome

AOS releases can be transformed into fail-closed Station publication inputs using an immutable, fetchable Station-tools pin, without granting the adapter publication or runtime authority.

Parent

astrid-runtime/astrid#1563

Scope and ownership

Repository: unicity-aos/aos-ce. Release-to-Station adapter, immutable Git-object verification, hosted contract matrix, and Station v1 product terminology.

Dependencies

  • The accepted Station publication interface in astrid-runtime/station-tools.
  • AOS release evidence assets (SHA256SUMS.txt and matching Capsules).
  • PR #87 review and required CI.

Exit gate

  • PR #87 is merged to the intended protected branch.
  • Hosted and local adapter matrices verify the immutable Station-tools object and reject replacement refs, dirt, ignored extras, mode drift, or unavailable pins before manifest generation.
  • A real release evidence bundle produces deterministic unsigned Station inputs; publication remains a separate protected operation.

Claim boundary

This lands a release adapter. It does not publish an AOS Station generation, sign TUF metadata, or activate a Station source.

Verification

Adapter matrix, exact-head independent review, GitHub CI, and a release-asset dry run bound to the signed Station interface.