
============================================================
Sentinel Linux Final Release Validation
============================================================
PASS: shell syntax: sentinelos-public-convert
PASS: shell syntax: lib/common.sh
PASS: shell syntax: phases/80_login_boot_branding.sh
PASS: shell syntax: phases/90_cleanup_and_drift_lock.sh
PASS: shell syntax: tests/test_phase80_login_boot_release_contract.sh
PASS: shell syntax: tests/test_phase90_cleanup_drift_contract.sh
PASS: shell syntax: tests/test_phase90_fixture.sh
Phase 80 static contract: PASS
PASS: Phase 6 identity contract regression
{
    "schema": "sentinelos.public_conversion.cleanup_drift_contract.v1",
    "master_version": "1.0.18-final",
    "release": "Sentinel Linux 1.0 AMBROSO",
    "packages": {
        "drift_control": "sentinelos-drift-control=1.0.0-3",
        "release_baseline": "sentinelos-release-baseline=1.0.0-3"
    },
    "locked_package_count": 37,
    "required_previous_phases": [
        "00",
        "10",
        "12",
        "15",
        "20",
        "30",
        "40",
        "50",
        "60",
        "65",
        "66",
        "70",
        "80"
    ],
    "safe_cleanup": {
        "apt_cache_clean": true,
        "apt_partial_age_days": 7,
        "conversion_temp_age_days": 7,
        "apt_autoremove": false,
        "home_cleanup": false,
        "application_data_cleanup": false
    },
    "drift_audit": {
        "automatic_remediation": false,
        "weekly_timer": true,
        "exact_sentinel_package_versions": true,
        "debian_base_updates_allowed": true,
        "repository_signed_by_required": true,
        "private_boundary_required": true
    },
    "rollback": {
        "removes_policy_metapackage": true,
        "removes_drift_control": true,
        "component_packages_removed": false
    },
    "plymouth_ownership_transition": {
        "package": "sentinelos-login-boot-branding=1.0.1-2",
        "legacy_owner": "sentinelos-plymouth-theme=0.2.0c-1"
    },
    "final_release_gate": "sentinelos-release-gate=1.0.0-1",
    "name_transition_package": "sentinel-linux-name-transition=1.0.2-1"
}
PASS: Phase 90 JSON contract
Phase 90 static contract: PASS
PASS: Phase 90 static contract

============================================================
Phase 90 — Cleanup and Drift Controls
============================================================
PASS: installed: sentinelos-drift-control=1.0.0-3
PASS: installed: sentinelos-release-baseline=1.0.0-3
PASS: safe cleanup complete
apt_partial_files_removed=0
conversion_temp_directories_removed=0
apt_autoremove_performed=false
user_files_removed=false
application_data_removed=false
PASS: Phase 90 safe cleanup, release lock and drift controls complete
Phase 90 isolated fixture: PASS
PASS: Phase 90 isolated fixture

============================================================
Sentinel Linux Public Conversion Plan
============================================================
PHASE   STATUS      AEGIS      DESCRIPTION
-----   ----------- ---------- -----------
00      ready       no         Host, architecture, disk and target-user preflight
10      ready       no         Embedded archive key and signed public APT source
12      ready       no         Rotate retired archive trust and verify current InRelease signing subkey
15      ready       no         Repository trust and exact-version contract
20      ready       no         Debian Trixie/MATE and LightDM foundation
30      ready       no         Package-owned Sentinel Base audit, apply and verification
40      ready       no         Package-owned Sentinel Linux Light/Dark GTK and Marco baseline
50      ready       no         Package-owned official icons and desktop branding
60      ready       no         Package-owned MATE menu, panel and pinned launchers
65      ready       no         Official cursor family and integration
66      ready       no         Verify base Sentinel Linux desktop identity
70      ready       no         Complete exact-version public Sentinel Desktop Suite
80      ready       no         Package-owned LightDM, GRUB, Plymouth, release identity and official wallpapers
85      ready       no         Correct GRUB parser/title, quiet Plymouth splash and persistent user-selected icon colours
90      ready       no         Package-owned safe cleanup, coherent release lock and read-only drift audit
99      ready       no         Read-only final release evidence and ISO input gate

AEGIS included: no
Final execution policy: Phases 00, 10, 12, 15, 20, 30, 40, 50, 60, 65, 66, 70, 80, 85, 90 and 99 are executable.
PASS: Phase 7 plan
PASS: public conversion defaults to without AEGIS
PASS: no remote payload retrieval in Phase 90
PASS: Phase 90 does not use apt autoremove

Phase 7 validation: PASS
PASS: Phase 7 regression validation
PASS: shell syntax: sentinelos-public-convert
PASS: shell syntax: lib/common.sh
PASS: shell syntax: phases/90_cleanup_and_drift_lock.sh
PASS: shell syntax: phases/99_final_release_verification.sh
PASS: shell syntax: tests/test_phase99_final_release_contract.sh
PASS: shell syntax: tests/test_phase99_fixture.sh
{
    "schema": "org.sentinellinux.final_release_contract.v1",
    "master_version": "1.0.18-final",
    "release": "Sentinel Linux v1.0 AMBROSO",
    "channel": "public",
    "architecture": "amd64",
    "packages": {
        "drift_control": "sentinelos-drift-control=1.0.0-3",
        "release_baseline": "sentinelos-release-baseline=1.0.0-3",
        "release_gate": "sentinelos-release-gate=1.0.0-1"
    },
    "required_phase_markers": [
        "00",
        "10",
        "12",
        "15",
        "20",
        "30",
        "40",
        "50",
        "60",
        "65",
        "66",
        "70",
        "80",
        "85",
        "90"
    ],
    "evidence": {
        "final_report": "/var/lib/sentinelos-conversion/reports/phase-99/final-release-report.json",
        "iso_build_inputs": "/var/lib/sentinelos-conversion/reports/phase-99/iso-build-inputs.json",
        "evidence_directory": "/var/lib/sentinelos-conversion/reports/phase-99/evidence",
        "release_certificate": "/var/lib/sentinelos-conversion/reports/phase-99/RELEASE_CERTIFICATE.txt",
        "sha256_manifest": "/var/lib/sentinelos-conversion/reports/phase-99/SHA256SUMS"
    },
    "gate_policy": {
        "read_only_verification": true,
        "automatic_remediation": false,
        "apt_autoremove": false,
        "user_file_deletion": false,
        "application_data_deletion": false,
        "display_manager_restart": false
    },
    "iso_readiness": {
        "conversion_release_inputs_required": true,
        "iso_toolchain_required_on_target": false,
        "toolchain_status_reported": true,
        "iso_not_built_by_phase_99": true
    },
    "name_transition_package": "sentinel-linux-name-transition=1.0.2-1",
    "legacy_internal_id": "sentinelos",
    "desktop_boot_hotfix_package": "sentinel-linux-desktop-boot-hotfix=1.0.1-1",
    "report_schema": "org.sentinellinux.final_release_report.v1",
    "iso_input_schema": "org.sentinellinux.iso_build_inputs.v1",
    "legacy_release_gate": {
        "package": "sentinelos-release-gate=1.0.0-1",
        "role": "read-only evidence source",
        "compatibility": "Sentinel Linux report normalization performed by Phase 99",
        "automatic_remediation": false
    }
}
PASS: Phase 99 JSON contract
Phase 99 static contract: PASS
PASS: Phase 99 static contract

============================================================
Phase 99 — Final Release Gate
============================================================
PASS: installed final release package: sentinelos-drift-control=1.0.0-3
PASS: installed final release package: sentinelos-release-baseline=1.0.0-3
PASS: installed final release package: sentinelos-release-gate=1.0.0-1
PASS: legacy SentinelOS release-gate result normalized against current Sentinel Linux contracts
PASS: Phase 99 final release gate complete
PASS: release: Sentinel Linux v1.0 AMBROSO
PASS: report schema: org.sentinellinux.final_release_report.v1
PASS: release evidence: /tmp/tmp.qqEf3XfXxI/root/var/lib/sentinelos-conversion/reports/phase-99
PASS: ISO build inputs: /tmp/tmp.qqEf3XfXxI/root/var/lib/sentinelos-conversion/reports/phase-99/iso-build-inputs.json
Phase 99 Sentinel Linux compatibility fixture: PASS
Phase 99 substantive-failure diagnostics fixture: PASS
PASS: Phase 99 isolated fixture
INFO: running phase: pass.sh
legacy phase verified
INFO: phase 65 marked complete
INFO: resume: phase 65 already complete
INFO: running phase: pass.sh
INFO: dry-run: /tmp/tmp.MnP7EtEQ0Q/pass.sh
Phase marker autocommit regression: PASS
PASS: Phase marker autocommit regression
INFO: running phase: child.sh
Master-version export regression: PASS
PASS: Master-version export regression

============================================================
Sentinel Linux Public Conversion Plan
============================================================
PHASE   STATUS      AEGIS      DESCRIPTION
-----   ----------- ---------- -----------
00      ready       no         Host, architecture, disk and target-user preflight
10      ready       no         Embedded archive key and signed public APT source
12      ready       no         Rotate retired archive trust and verify current InRelease signing subkey
15      ready       no         Repository trust and exact-version contract
20      ready       no         Debian Trixie/MATE and LightDM foundation
30      ready       no         Package-owned Sentinel Base audit, apply and verification
40      ready       no         Package-owned Sentinel Linux Light/Dark GTK and Marco baseline
50      ready       no         Package-owned official icons and desktop branding
60      ready       no         Package-owned MATE menu, panel and pinned launchers
65      ready       no         Official cursor family and integration
66      ready       no         Verify base Sentinel Linux desktop identity
70      ready       no         Complete exact-version public Sentinel Desktop Suite
80      ready       no         Package-owned LightDM, GRUB, Plymouth, release identity and official wallpapers
85      ready       no         Correct GRUB parser/title, quiet Plymouth splash and persistent user-selected icon colours
90      ready       no         Package-owned safe cleanup, coherent release lock and read-only drift audit
99      ready       no         Read-only final release evidence and ISO input gate

AEGIS included: no
Final execution policy: Phases 00, 10, 12, 15, 20, 30, 40, 50, 60, 65, 66, 70, 80, 85, 90 and 99 are executable.
PASS: Final conversion plan
PASS: public conversion defaults to without AEGIS
PASS: no remote payload retrieval in Phase 99
PASS: Phase 99 does not use apt autoremove

Final release validation: PASS
