Verify and promote
Promotion applies to a candidate that has been uploaded to its final location and verified after re-download, not to a local file on the build machine. Manifest publication follows successful verification of every required platform.
Verify a candidate
For each target:
- Download the actual bytes from the candidate channel's final URL.
- Verify HTTP result, filename, size, platform, and channel.
- Recompute SHA-256 and verify Ed25519 or the platform signature.
- Run an install or startup smoke check on the target platform.
- Record URL, digest, signature result, time, and operator as release evidence.
Promotion order
text
build and sign
upload immutable artifacts
re-download and verify every target
publish candidate manifest
observe candidate channel
approve Stable
publish Stable manifest last
If the product uses other channel names, the rule is unchanged: verify immutable artifacts before moving a user-visible pointer.
Blocking conditions
- Downloaded bytes differ from the local candidate.
- Platform, architecture, filename, or channel fields do not match.
- A required platform is missing, fails signature checks, or cannot start.
- A manifest points to a missing, mutable, or incorrectly cached object.
- Verification evidence contains unredacted secrets or personal data.
Roll back
Stop further promotion and restore the previous verified channel manifest. Do not overwrite immutable files for the failed version. Build and verify a new version after repair and retain the failure record for incident review.
Related pages
EvoX Docs · Administration · Release management