You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/GATE_EVIDENCE.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -84,7 +84,7 @@ Gate statuses used here:
84
84
| Candidate npm `0.1.48` canonical post-C0 credential correction | Completed-C0 terminal credentials now resolve through the exact domain/principal-bound harness plus credential epoch; unknown or mismatched identity state remains fail-closed. Adds only the exact forward-only `0.1.47→0.1.48` five-unit marker edge and no database migration. | Focused lane: `547 passed, 5 skipped`; broad releasable-source lane: `2155 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-006`, `ID-009`, `SEC-007`, `OPS-003`. |
85
85
| Candidate npm `0.1.49` completed-C0 communication recovery | Permanent communication activation resolves the exact completed C0 pair; only the authenticated ordinary server harness may advance to its current active credential, while the C0 peer remains pinned to its enrolled credential absent separately verified succession. Terminal pre-commit retries converge without replacing committed authority. Signed message send, inbox, and acknowledgement requests bind the exact collaboration scope. Adds only the forward-only `0.1.48→0.1.49` five-unit marker edge and no database migration. | Focused lane: `645 passed, 5 skipped`; broad releasable-source lane: `2166 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-004`, `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-007`, `AUTH-009`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `COM-011`, `AVL-003`, `AVL-005`, `AVL-006`, `SEC-003`, `SEC-005`. |
86
86
| Candidate npm `0.1.50` setup-usability, direct-upgrade, and communication-scope approval path | One guided server command over the strict request/plan/apply protocol; one server-origin-only guided laptop command with authenticated discovery defaults; content-free named phases; ten-minute server and five-minute laptop bounds; resumable blocker output; exact direct allowlist from v0.1.45–v0.1.49 schema-v7 five-unit markers; installed separate-process local communication/obligation roundtrip added to packed verification; explicit one-hour Approval request ceiling limited to `authorization.communication_scope.approve`, with all other approvals retaining the five-minute ceiling and short-lived WebAuthn challenges | Focused release lane: `681 passed, 5 skipped`; broad releasable-source lane: `2180 passed, 21 skipped`; source and two recursive packed generations: `2207 passed, 21 skipped` each; two byte-identical release builds; release manifest verifier passed; installed tarball journey passed from an unrelated prefix; installed-host, fresh-machine, and same-commit CI evidence pending | H/L-shaped local candidate evidence only. No production, owner-policy, external, privileged-host, or gate promotion. Affected IDs: `ID-006`, `AUTH-004`, `AUTH-007`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `AVL-003`, `AVL-005`, `AVL-006`, `UX-001`, `UX-002`, `SEC-003`, `SEC-005`, `OPS-003`, `OPS-006`. |
87
-
| Corrective v0.1.51 canonical-owner, schema-v7 projection, retained-TTL, and expired-member replacement recovery | Exact enrolled-Core plus pinned-Approval-OIDC owner selection; transactional Approval owner/passkey adoption; current receipt-signer replacement; strict resumable signer/config journal; journaled Core OIDC/approver cutover; exact published v0.1.50 300-second Approval policy preservation plus retained one-hour generic Approval hotfix normalization to separate 600-second ordinary and 3600-second communication-scope ceilings under compare-and-swap, resume, and rollback; single-scope schema-v7 projection shared by atomic activation and idempotent legacy repair; separately approved same-principal expired-member replacement requires the exact scope owner, preserves role, tombstones the former harness, activates the enrolled replacement, increments membership and scope revisions once, recomputes canonical digests, cuts authorization over to current schema-v7 membership, and permits exact committed replay after request expiry; ambiguity, cross-principal/domain, replay, tamper, drift, partial-row, conflicting-row, and already-shortened TTL rejection | Recovery-focused lane: `238 passed`; replacement-focused SQLite lane: `62 passed`; PostgreSQL contract collection: `82 passed, 8 dedicated-database skips`; broad releasable-source lane: `2226 passed, 22 skipped`; `npm run check` source plus two recursively packed generations: `2253 passed, 22 skipped` each; release manifest, installed-byte local communication, exact-endpoint routing, and packaged v0.1.45 journey passed | Current source/package H/L-shaped evidence only. Dedicated PostgreSQL replacement execution, same-commit CI, installed-host setup/upgrade, and live server/laptop reliability evidence remain pending. No requirement or gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-005`, `ID-006`, `ID-009`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-005`, `COM-001`, `COM-002`, `COM-009`, `AVL-003`, `AVL-005`, `AVL-006`, `SEC-003`, `SEC-005`, `SEC-007`, `OPS-003`, `OPS-006`. |
87
+
| Corrective v0.1.51 canonical-owner, schema-v7 projection, retained-TTL, and expired-member replacement recovery | Exact enrolled-Core plus pinned-Approval-OIDC owner selection; transactional Approval owner/passkey adoption; current receipt-signer replacement; strict resumable signer/config journal; journaled Core OIDC/approver cutover; exact published v0.1.50 300-second Approval policy preservation plus marker-relative proof and normalization of the retained one-hour generic Approval hotfix to separate 600-second ordinary and 3600-second communication-scope ceilings under compare-and-swap, resume, and rollback; single-scope schema-v7 projection shared by atomic activation and idempotent legacy repair; separately approved same-principal expired-member replacement requires the exact scope owner, preserves role, tombstones the former harness, activates the enrolled replacement, increments membership and scope revisions once, recomputes canonical digests, cuts authorization over to current schema-v7 membership, and permits exact committed replay after request expiry; ambiguity, cross-principal/domain, replay, tamper, drift, partial-row, conflicting-row, and already-shortened TTL rejection | Recovery-focused lane: `240 passed`; replacement-focused SQLite lane: `62 passed`; PostgreSQL contract collection: `82 passed, 8 dedicated-database skips`; broad releasable-source lane: `2228 passed, 22 skipped`; `npm run check` source plus two recursively packed generations: `2255 passed, 22 skipped` each; release manifest, installed-byte local communication, exact-endpoint routing, and packaged v0.1.45 journey passed | Current source/package H/L-shaped evidence only. Dedicated PostgreSQL replacement execution, same-commit CI, installed-host setup/upgrade, and live server/laptop reliability evidence remain pending. No requirement or gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-005`, `ID-006`, `ID-009`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-005`, `COM-001`, `COM-002`, `COM-009`, `AVL-003`, `AVL-005`, `AVL-006`, `SEC-003`, `SEC-005`, `SEC-007`, `OPS-003`, `OPS-006`. |
88
88
89
89
| OIDC validated-address transport repair |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py`| 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. |
90
90
| Independent WebAuthn-UV approval component |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. |
0 commit comments