Read posture
Start from status, non-claims, and the validation source records before running commands.
Install Evidence and Package Guards
Latticra validation records show what can be inspected locally, what has user-local install evidence, and which package lanes remain static, gated, or disposable-VM-only.
Validation Rule
The current validation surface is deliberately narrow. It includes user-local Panel install evidence, static package checks, dry-run contracts, and gated VM lanes. It does not claim root installation, distribution approval, daily-driver safety, runtime enforcement, or production security.
Start from status, non-claims, and the validation source records before running commands.
Use the workbench path to generate a local plan and inspect receipts before guarded writes.
Confirm wrappers, prefix, payload tree, desktop entry, icon, receipts, and Seal report-only output.
Use Fedora, Ubuntu, Debian, FreeBSD, and OpenBSD package validation scripts without creating distribution artifacts.
Disposable VM lanes require snapshot, recovery, consent, and exact target evidence.
Panel Evidence
The current Panel evidence records a Fedora Workstation user-local install with local wrappers, local prefix, receipts, desktop entry, desktop icon, Panel launcher, and a Latticra Seal report-only local report.
Evidence Snapshot
These are the public-facing fields a reader should keep in mind when interpreting local install evidence.
Validation Lanes
The package and platform records are useful only when their scope is kept visible.
Fedora Workstation transcript evidence exists for local wrappers, prefix, payload, receipts, desktop entry, icon, launcher, and Seal report-only output.
Panel evidence statusStatic local RPM validation does not create artifacts. VM RPM validation is gated to disposable Fedora targets with snapshot, recovery, and consent evidence.
RPM validation planChecks local package shape for the no-effect CLI payload without running dpkg-buildpackage, debuild, lintian, sbuild, or pbuilder.
Deb static validationChecks local Debian package shape for the no-effect CLI payload without claiming archive readiness, sponsorship, or ftp-master acceptance.
Debian static validationChecks local ports metadata without running make package, poudriere, portlint, or claiming ports-tree submission.
FreeBSD port validationChecks local ports metadata with package redistribution disabled until license, checksum, portcheck, and bulk-build evidence exist.
OpenBSD port validationDefines future managed-target removal order while deletion, receipt writes, absence verification, and host mutation remain disabled.
macOS dry-run contractGate Matrix
A local command is not automatically an install claim. The gate has to state which target may be touched and what remains forbidden.
Read status, run no-effect guards, inspect Panel dry-runs, verify user-local evidence, and run static package checks.
Panel local-prefix writes require explicit local mode, receipts, visible prefix, and no root or network authority.
Fedora RPM install/removal validation requires disposable VM target evidence, clean snapshot, recovery path, and operator consent.
Production installer readiness, distro approval, daily-driver eligibility, immutable host readiness, runtime enforcement, and security-product claims.
Local Commands
These commands are intentionally narrow. Run them from the repository root unless a command names a subdirectory.
make -C installer dry-run
make -C installer verify-local
sh scripts/test-fedora-local-rpm-validation-plan.sh
sh scripts/test-ubuntu-local-deb-static-validation.sh
sh scripts/test-latticra-panel-local-install-evidence-status.sh
sh scripts/test-macos-reset-uninstall-dry-run-contract.sh
Source Records
These records define the validation boundaries more precisely than a summary page can.