You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/GATE_EVIDENCE.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -47,6 +47,7 @@ Gate statuses used here:
47
47
| npm `0.1.11` recursive-generation repair candidate | Deterministic one-second conversation retry reproducer; exact relay and internal-invitation repeated-run reproductions; explicit-deadline negative test; coherent relay/invitation test clocks; stable approval-purpose config serialization; model-diverse critic and constitution review plus bounded `claude -p` clock analysis; broad and repeated regression runs; release verifier; two independent `SOURCE_DATE_EPOCH=1580601600` builds; explicit source → pack/install generation 1 → repack/install generation 2 verification | Conversation/relay/assignment focused suites `56 passed`; relay target `100/100` repeats; activation serialization `100/100` repeats; internal-invitation HTTP target `100/100` repeats; code-regression corpus `1079 passed, 7 expected PostgreSQL skips`; unfiltered local run `1106 passed, 2 preserved G01 failures, 7 expected PostgreSQL skips`; complete `npm run check` PASS with source and both installed npm generations each reporting `1030 passed, 7 expected PostgreSQL skips`; package check, release verifier, compile, and reproducible-build comparisons PASS on 2026-07-17 | Minimal production change reuses the stored encrypted canonical conversation deadline only for exact omitted-deadline proposal retries; explicit caller deadline changes still conflict. Relay and invitation production freshness remain unchanged at 300 seconds; only test fixtures now use coherent clocks. Config change only sorts an unordered approval-purpose set during serialization. No current mutation-authorized PostgreSQL, live enrollment, real passkey, first signed message/reply, activation, company data, publication, or cutover evidence is promoted. |
48
48
| `0.1.12` cross-platform implementation, pre-version real-host gate | GitHub Actions run `29610467753` at commit `6d7834e`; pinned Node `24.18.0`, uv `0.11.28`, CPython `3.13.13`; platform contracts; package check; npm pack/install; direct launcher execution from unrelated cwd | Ubuntu `13 passed, 8 skipped`; macOS `15 passed, 6 skipped`; Windows `17 passed, 4 skipped`; package check and packed install/launch passed on all three hosts on 2026-07-17 | P-shaped exact-host evidence for package launch, canonical state, portable SQLite, macOS peer/read-only-pipe/link denial, Windows SID/DACL/reparse/named-pipe/replay/capability-theft/Job cleanup, and host-gated imports. This is not signed installer/update/uninstall/rollback, privileged hostile same-account/path replacement, semantic harness, clean-worker, production, enrollment, activation, company-data, first-message, or cutover evidence. Package metadata at this pre-version commit still read `0.1.11`; final `0.1.12` evidence binds the frozen release source separately below. |
49
49
| npm `0.1.12` cross-platform candidate | Real-host gate above; DeepSeek security and GLM constitution review with repairs; local unfiltered suite; exact installed-harness probe; release verifier; two independent `SOURCE_DATE_EPOCH=1580601600` builds; explicit source → pack/install generation 1 → repack/install generation 2 verification | Unfiltered local `1122 passed, 15 expected host/PostgreSQL skips`; installed deterministic harness `8 passed`; source, generation 1, and generation 2 each `1043 passed, 15 expected skips`; package check, release verifier, recursive package gate, and reproducible Python builds PASS on 2026-07-17 | H/L and bounded ordinary-runner P-shaped evidence only. Cross-platform installation creates no identity or authority. No current mutation-authorized PostgreSQL, signed native installer/update/uninstall, privileged hostile-host campaign, semantic clean-worker inference, live enrollment/passkey, independent production host, first signed message/reply, activation, company data, publication, or cutover evidence is promoted. |
50
+
| npm `0.1.13` canonical onboarding prompt candidate | Canonical-template commit `2dc177c`; pre-release critic and constitution review; focused npm/release conformance; release verifier; two independent `SOURCE_DATE_EPOCH=1580601600` builds; complete `npm run check` source → pack/install generation 1 → repack/install generation 2 verification | Reviews PASS; focused release/package conformance `30 passed`; source, generation 1, and generation 2 each `1043 passed, 15 expected host/PostgreSQL skips`; package check, release verifier, recursive package gate, canonical prompt markers, and byte-identical Python builds PASS on 2026-07-18 | Documentation/skill and regression correction only: one canonical public fresh-laptop prompt is required and unresolved public metadata blocks issuance. The template itself grants no enrollment, approval, authority, messaging, activation, deployment, restart, production, or cutover permission. No mutation-authorized PostgreSQL, live blank-laptop ceremony, passkey, first signed message/reply, company data, npm publication, or production evidence is promoted. |
50
51
| OIDC validated-address transport repair |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py`| 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. |
51
52
| Independent WebAuthn-UV approval component |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. |
52
53
| Prior `0.1.8` candidate, unfiltered local run |`UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q`|`1087 passed, 2 failed, 7 expected PostgreSQL skips` on 2026-07-16 | Both failures were preserved environmental G01 gates. This was not a passing unfiltered release run and is not current `0.1.9` evidence. |
"change_boundary": "Documentation/skill-only canonical fresh-laptop onboarding prompt and regression checks. Runtime authority, enrollment implementation, A2A, activation, company data, first-message, production readiness, and cutover remain unchanged and not authorized.",
10
+
"commands": [
11
+
{
12
+
"command": "pre-release critic and constitution-watcher review",
13
+
"result": "PASS; release remains owner-controlled and unrelated worktree edits are excluded"
14
+
},
15
+
{
16
+
"command": "UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q tests/conformance/test_npm_package.py tests/conformance/test_release_manifest.py",
0 commit comments