@@ -17,6 +17,7 @@ Track 3.
1717chromium/
1818 config/
1919 version.json # pinned chromium + ungoogled versions, targets, tor
20+ cromite-candidate.json # attested downstream snapshot + adoption policy
2021 gn-args/ # common.gni + android.gni (privacy + branding)
2122 branding/ # product strings + APK icon assets
2223 patches/ # required TronBrowser Android overlay (after ungoogled)
@@ -29,6 +30,8 @@ chromium/
2930node scripts/preflight.mjs --mode scaffold
3031node scripts/preflight.mjs --mode checkout
3132node scripts/preflight.mjs --mode release
33+ node scripts/audit-candidate.mjs --mode record
34+ node scripts/audit-candidate.mjs --mode adopt
3235```
3336
3437Scaffold mode validates configuration and reports unresolved release inputs.
@@ -37,6 +40,27 @@ requiring release approval, so maintainers can develop patches against a real
3740checkout. Release mode refuses to continue while the Chromium pin, required
3841patches, branding assets, or pinned Tor integration are unapproved or missing.
3942
43+ Candidate ` record ` mode validates the pinned downstream snapshot and reports
44+ licensing, release-lag, freshness, security-SLA, and extension-support blockers
45+ without failing CI merely because a product decision remains open. ` adopt ` mode
46+ fails closed until every blocker is resolved. Both modes are offline: repository
47+ tags, commits, releases, and patch metadata are recorded attestations, not live
48+ network verification, and must be refreshed from primary upstream sources before
49+ an adoption decision. A stale or malformed attestation fails both modes.
50+ Refresh the record at least every ` policy.maximumRecordAgeDays ` (currently 30):
51+ re-check the candidate tag, commit, version, and release date; the recorded stable
52+ version and source; and the extension patch URL, blob SHA, reviewer, and date.
53+
54+ Use ` --json ` for machine-readable output. ` --as-of YYYY-MM-DD ` is available only
55+ in ` record ` mode for reproducing a historical snapshot; ` adopt ` always evaluates
56+ against the current UTC date. The audit exits with status 0 for a valid record
57+ (including unresolved product blockers in ` record ` mode), 1 for invalid evidence
58+ or a blocked adoption, and 2 for invalid command-line usage.
59+
60+ Cromite release tags contain a 40-character build identifier after the Chromium
61+ version. That identifier is not assumed to be a Git commit: ` commitSha `
62+ independently pins the tag's resolved Git target.
63+
4064## Build (100GB+ free disk, 16GB+ RAM recommended, hours, Linux x64)
4165
4266Scripts are ** guarded** : they dry-run unless ` TB_RUN=1 ` . Source lands outside the
0 commit comments