Engineering journal
Repository Trust Is Desired State, Not a Compliance Claim
The Yocto and QEMU lab separates a versioned policy, a collected observation and a deterministic evaluator. A matching snapshot does not establish continuous enforcement.
Source: https://louijiecompo.com/writing/repository-trust-is-desired-state-not-a-compliance-claim/
About 2 min read

A repository can describe its intended protections without proving that a hosting service currently enforces them. The Yocto and QEMU lab makes that distinction part of its implementation. M9 / PR #17 adds a versioned repository-trust contract and a deterministic evaluator, alongside the lab's existing virtual-device and Linux-driver work.
Three artifacts, three responsibilities
The tracked policy (opens in a new tab) describes the desired state: selected repository settings, Actions permissions, required checks and a named protection ruleset. Its SHA-256 identifies the exact policy bytes. Changing a policy changes what an observation is being compared with.
An observation is collected separately. The observation contract (opens in a new tab) accepts a normalized point-in-time input at a fixed ignored path. Raw API responses, actor identities, tokens and unrelated settings do not belong in that projection. Collecting it requires its own authorized settings read.
The evaluator compares those inputs. It has no network, subprocess or settings-mutation interface. This separation makes its decision reproducible without pretending that an offline command is a live GitHub monitor.
Unknown is a result
The implementation (opens in a new tab) preserves distinct outcomes:
| Exit | Meaning |
|---|---|
| 0 | Every required observed fact matches the policy. |
| 1 | At least one observed fact conflicts with the policy. |
| 2 | Usage, policy, local contract or observation input is invalid. |
| 3 | An observation or required fact is unavailable, with no known conflict. |
A known conflict takes priority over missing information. Missing information takes priority over a pass. That prevents an incomplete observation from becoming a reassuring green result simply because the collector could not read a setting.
Input handling is also part of the boundary. The fixed observation is limited to 64 KiB, rejects duplicate or unknown keys, and bounds nested values. The tests (opens in a new tab) exercise malformed inputs, unavailable facts and policy conflicts, alongside deterministic evidence behavior.
What a match cannot establish
A passing projection does not authenticate its collector or timestamp. It does not cover every organization, enterprise or legacy protection rule. It is not proof of account security, independent review, continuous compliance or a supply-chain certification.
The engineering decision is to make desired state inspectable and evaluation bounded before treating operational enforcement as established. This portfolio reviews the merged implementation; it has not collected a live settings observation or run a new Yocto image. The case study keeps those limits beside the implemented contract.