|
1 | 1 | # Must-Not-Ship Gate Evidence Ledger |
2 | 2 |
|
3 | | -Current ledger update: 2026-08-07. Overall release posture: **blocked**. Older |
| 3 | +Current ledger update: 2026-08-09. Overall release posture: **blocked**. Older |
4 | 4 | rows retain their exact run dates and remain historical evidence. This ledger |
5 | 5 | separates checked-in historical release evidence from an explicitly labeled |
6 | 6 | uncommitted worktree candidate, records only commands actually run for the stated |
@@ -84,6 +84,8 @@ Gate statuses used here: |
84 | 84 | | Candidate npm `0.1.48` canonical post-C0 credential correction | Completed-C0 terminal credentials now resolve through the exact domain/principal-bound harness plus credential epoch; unknown or mismatched identity state remains fail-closed. Adds only the exact forward-only `0.1.47→0.1.48` five-unit marker edge and no database migration. | Focused lane: `547 passed, 5 skipped`; broad releasable-source lane: `2155 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-006`, `ID-009`, `SEC-007`, `OPS-003`. | |
85 | 85 | | Candidate npm `0.1.49` completed-C0 communication recovery | Permanent communication activation resolves the exact completed C0 pair; only the authenticated ordinary server harness may advance to its current active credential, while the C0 peer remains pinned to its enrolled credential absent separately verified succession. Terminal pre-commit retries converge without replacing committed authority. Signed message send, inbox, and acknowledgement requests bind the exact collaboration scope. Adds only the forward-only `0.1.48→0.1.49` five-unit marker edge and no database migration. | Focused lane: `645 passed, 5 skipped`; broad releasable-source lane: `2166 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-004`, `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-007`, `AUTH-009`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `COM-011`, `AVL-003`, `AVL-005`, `AVL-006`, `SEC-003`, `SEC-005`. | |
86 | 86 | | Candidate npm `0.1.50` setup-usability, direct-upgrade, and communication-scope approval path | One guided server command over the strict request/plan/apply protocol; one server-origin-only guided laptop command with authenticated discovery defaults; content-free named phases; ten-minute server and five-minute laptop bounds; resumable blocker output; exact direct allowlist from v0.1.45–v0.1.49 schema-v7 five-unit markers; installed separate-process local communication/obligation roundtrip added to packed verification; explicit one-hour Approval request ceiling limited to `authorization.communication_scope.approve`, with all other approvals retaining the five-minute ceiling and short-lived WebAuthn challenges | Focused release lane: `681 passed, 5 skipped`; broad releasable-source lane: `2180 passed, 21 skipped`; source and two recursive packed generations: `2207 passed, 21 skipped` each; two byte-identical release builds; release manifest verifier passed; installed tarball journey passed from an unrelated prefix; installed-host, fresh-machine, and same-commit CI evidence pending | H/L-shaped local candidate evidence only. No production, owner-policy, external, privileged-host, or gate promotion. Affected IDs: `ID-006`, `AUTH-004`, `AUTH-007`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `AVL-003`, `AVL-005`, `AVL-006`, `UX-001`, `UX-002`, `SEC-003`, `SEC-005`, `OPS-003`, `OPS-006`. | |
| 87 | +| Corrective v0.1.51 canonical-owner and schema-v7 scope-projection recovery | Exact enrolled-Core plus pinned-Approval-OIDC owner selection; transactional Approval owner/passkey adoption; current receipt-signer replacement; strict resumable signer/config journal; journaled Core OIDC/approver cutover; single-scope schema-v7 projection shared by atomic activation and idempotent legacy repair; ambiguity, tamper, drift, partial-row, and conflicting-row rejection | Focused recovery lane: `347 passed`; broad releasable-source lane: `2204 passed, 22 skipped`; source plus two recursively packed generations: `2231 passed, 22 skipped` each; two byte-identical builds; installed-byte local communication reached `recipient_committed`; fresh installed npm exact-endpoint routing proved zero sibling reactions and no process/capability residue | Current source/package H/L-shaped evidence only. Dedicated PostgreSQL, installed-host setup/upgrade, same-commit CI, and live server/laptop reliability evidence remain pending. No requirement or gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-005`, `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-005`, `COM-001`, `COM-002`, `COM-009`, `AVL-003`, `AVL-005`, `SEC-003`, `SEC-005`, `SEC-007`, `OPS-003`, `OPS-006`. | |
| 88 | + |
87 | 89 | | OIDC validated-address transport repair | `UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py` | 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. | |
88 | 90 | | Independent WebAuthn-UV approval component | `UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. | |
89 | 91 | | Prior `0.1.8` candidate, unfiltered local run | `UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q` | `1087 passed, 2 failed, 7 expected PostgreSQL skips` on 2026-07-16 | Both failures were preserved environmental G01 gates. This was not a passing unfiltered release run and is not current `0.1.9` evidence. | |
|
0 commit comments