← Git: team decisions and recovery
12 / 12 · 60 MIN

Release artifacts and traceability

Inspect archives by identity, membership, attributes, modes and links before accepting them as distribution artifacts.

Select source and observe content

The second runner section prepares a synthetic release containing docs/internal.txt, VERSION and a current link to deploy.sh. The index records shell executable mode through update-index --chmod=+x. After commit R, the working tree receives a local deploy.sh edit that will not be distributed. The archive created from ID R is inspected in memory without extracting members to the filesystem. Its script matches versioned content rather than the local draft. untracked.txt is also absent. These controls make the question of which snapshot is distributed concrete. A branch name can advance, so the exercise records the selected ID before creating the package. There is still no application build or installation in a destination environment.

Distinguish distribution, history and identity

Versioned policy excludes docs/** from distribution and allows a VERSION placeholder to be replaced by the selected commit. The runner confirms the internal note is absent from tar while it can still read it using git show R:path. This difference is central to the Dune case: export-ignore neither deletes history nor revokes copies. An archive created with commit R expands the placeholder; an archive created with R^{tree} retains it. The second object describes the tree but does not supply the same commit identity for substitution. get-tar-commit-id reads R from the first tar metadata. This reading verifies neither a signature, trust in a producer nor functional release approval. Record identity as one piece of evidence and connect it to the remaining acceptance criteria.

Include policy and types in the package contract

The Bridge case compares two exports of R. Local policy was edited to stop excluding docs. By default, archive still uses the versioned exclusion; with --worktree-attributes, the internal file is included. deploy.sh content still comes from R even in that variant. Attribute source can therefore change membership without replacing the file snapshot with local edits. The runner also checks executable bits and the symlink member with its target. In the Beacon case, the installer requires another contract; reproducing an incompatible package exactly does not make it acceptable. Record members, modes, links, exclusions and the creation command. In-memory inspection avoids extracting the fixture but does not establish that the real installation mechanism handles these members as intended.

Work through the guided review

The guide below allocates forty minutes across Quay, Mill, Dune, Bridge and Beacon. It has expected answers but has not yet been performed with participants. Produce a table containing source, policy, membership, identity and consumer validation. Two executions of the R tar produced identical bytes in the pinned environment; that result is limited to the experiment command, version and inputs. No claim is made about reproducibility of every future build, Windows execution, signing or production installation. A digest identifies bytes; acceptance also needs trust in the process and appropriate behavior. Connect the package to its commit and producing transformations, including local attributes when used. Before closing review, identify who should validate destination execution and which criteria remain outstanding. Cases are fictional and do not represent internal BNP Paribas procedures.

ARTIFACT GUIDE, 40 minutes, fictional data
0–10 Quay/Mill: a large eol diff includes a new timeout; CI uses LF and a laptop uses CRLF with a local override. Deliver a review sequence.
Answer: separate intents, inspect index and effective/cached attributes, compare bytes and sources, test consumers. Do not copy personal overrides into CI without a decision.
10–20 Dune: docs/internal.txt is in commit R and has export-ignore; it is absent from tar. VERSION expands with R but not R^{tree}.
Answer: distribution exclusion does not erase history; tree does not supply commit context for export-subst. R metadata is neither a signature nor a functional test.
20–30 Bridge: two exports of R differ; one uses --worktree-attributes with exclusion removed. List inputs to retain.
Answer: ID R, command, version, effective attributes, members, modes, links and each package digest. The option changes attributes, not copying local drafts into tar.
30–40 Beacon: installer requires regular files and executable script; package has a symlink and incorrect mode. Write the decision.
Answer: correct the contract and validate again at destination; repeatable bytes do not compensate for incompatibility. Identify the owner and outstanding tests.
Deliver: source/policy/membership/identity/consumer table and decision with gaps.
Status: editorial guide, not performed with participants.
IN PRACTICE

The same commit R excludes docs by default and includes docs with edited local attributes; source identity alone does not identify the package.

Common pitfalls

Treating exclusion as deletion; confusing digest with signature; omitting local attributes; assuming repeatable bytes guarantee compatibility.

Related topics: States and index · Diagnosis and releases · Integration and review

Take this idea with you

Traceability connects source, transformation and observed artifact; the consumer still needs to validate installation and behavior.

Create account

Reference: Git archive · Git 2.56; workflow concepts compatible with modern Git 2.x