608 B
608 B
ADR-0007: Artifact provenance is machine-readable and fail-closed
- Status: accepted
- Date: 2026-07-17
Decision
Every review or hardware candidate uses artifact-manifest schema version 1. The manifest binds filename, size, SHA-256, target, clean source commit, toolchain pins, optional SDL commit, firmware gate, and explicit non-execution state. Generation and verification are separate tested tools.
An artifact with firmware identifier NONE is never allowlisted. Any rebuild,
including a firmware-specific rebuild, creates a new digest and therefore
requires a new artifact-specific approval.