You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/GATE_EVIDENCE.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -76,6 +76,7 @@ Gate statuses used here:
76
76
| Corrective npm `0.1.39` request-identity plus packaged local-communication candidate | Explicit GET `urllib.request.Request`; `User-Agent: AgentNet/0.1.39`; JSON Accept; unchanged TLS/proxy/redirect/timeout/identity boundaries; local-policy-only deterministic lab revision, recipient-resolution, and custody-ACK composition; second recursive npm generation runs a real Core plus separate fresh-proof client processes over loopback from installed bytes; fresh clean-state setup only with no migration edge | Health regression passed (`2 passed`); setup/recovery (`224 passed`) and prior focused release (`645 passed, 7 expected PostgreSQL skips`) remain green. New focused synthetic-lane/HTTP/obligation regressions report `7 passed`. A fresh manually packed npm tarball installed into an unrelated prefix passed `accepted_local`, exact proof-derived request/reply attribution, offline recipient recovery after Core restart, stable request event/obligation and ACK receipt idempotency, `recipient_committed`, typed obligation `completed`, requester response custody after another restart, fresh authentication refusal after an explicitly non-approved lab credential fixture, closed listener, and removed state. Final metadata-bound recursive verification passed in both clean npm generations with `1642 passed, 16 expected skips` each; generation 2 additionally passed the installed-byte multiprocess lifecycle, package-tree equality, empty-workspace, listener-release, and no-residue checks. Peer-reported 403→502 comparison remains corroboration only. | `BLOCKED`; H/L-shaped synthetic local evidence only. The production policy engine still rejects deterministic lab harnesses. This is not bounded `COMPLETED_C0_ROUND_TRIP`, approved revocation or five-power cleanup, real enrollment, ordinary server-agent `COM-002`/`COM-003`, PostgreSQL durability, Hub installation, production, ship, requirement, or gate promotion. Exact same-commit cross-platform, clean-setup, public-0.1.38-marker rejection, packaged communication, tag, stage, public-byte, and fresh-setup evidence remain pending. |
77
77
| Unpublished npm `0.1.42` narrow real C0 candidate | Explicit owner-approved reset of only disposable AgentNet state; fresh ordinary server setup; real workforce Google OIDC and owner-controlled WebAuthn UV for exact server and laptop harness enrollment; strict remote-browser challenge evidence; fixed one-hour `BootstrapGrantPlan`; package-owned systemd responder credential custody; native request/reply/ACK journey; authoritative PostgreSQL postcondition query | Narrow live path PASS: both harnesses ended identity-only before the fixed plan; plan commit returned `prepared_unusable`; `c0-pilot` progressed `waiting_owner` → `waiting_fresh` → `COMPLETED_C0_ROUND_TRIP`; retained parent-scoped postconditions are exactly one committed plan, its one revoked guard, its one `communication_revoked` attempt, 7 rows/7 distinct fact kinds for that attempt, 5/5 communication entitlements for that plan revoked, and 5 exact-revoke items for that plan. Broad run remains non-green: `1747 passed, 16 skipped, 3 failed`; `agentnet verify` reported `1665 passed, 16 skipped, 1 failed`; release verifier reported 15 manifest/source/package drift findings. | Narrow L/E-shaped real IdP/authenticator plus disposable single-node service evidence is retained at `evidence/local/2026-08-04-v0.1.42-c0-live/manifest.json`; its sanitized parent-scoped postcondition query/result is hash-bound as `postconditions.json` SHA-256 `518f030c0503f93bcc6e119581c1c4d88c16f6ec06b69addc2768a5c7be2681a`. Both artifacts remain historical evidence for deployed source `d8884b6c03a0dd38baab03386982aae8ad11dd58`; they do not prove the post-run nonblocking credential-open correction at `52b6941`. The run does not pass a gate, certify a release, prove independent approval hosting, production key custody, PostgreSQL HA/PITR, real four-harness semantics, cross-platform packaging, or owner decisions. Candidate is unpublished and release posture remains BLOCKED. |
78
78
| Post-live `0.1.42` credential-open correction |`O_NONBLOCK` before descriptor metadata validation; dedicated regression; retained parent-scoped C0 SQL/result evidence | Regression failed before the correction; responder file passed `23 tests`; independent corrective review ended `NO_BLOCKING_FINDINGS`| H-shaped source-only evidence at `evidence/local/2026-08-04-v0.1.42-post-live-corrective/manifest.json`. Revision `52b6941` was not deployed for the historical live run. No package, live rerun, release, requirement, or gate promotion is claimed. |
79
+
| Candidate npm `0.1.43` corrected first-C0 release path | Strict remote-browser bootstrap evidence; byte-preserving P-256 responder credential handling; package-owned systemd credential custody; `O_NONBLOCK` before regular-file validation; retained historical real OIDC/WebAuthn two-harness C0 and exact-revocation evidence | Focused affected lane `757 passed, 7 expected dedicated-PostgreSQL skips`; broad source lane and both fresh recursive npm generations each `1640 passed, 16 expected skips`; the retained-content generation completed the real loopback Core/separate-client local communication journey and left an empty workspace. The candidate manifest records final release-manifest/direct-verifier and byte-identical archive outcomes. Same-commit CI/stage and corrected-source remote evidence remain external actions. Historical narrow deployment passed only at source `d8884b6c03a0dd38baab03386982aae8ad11dd58`. | H/L-shaped candidate source, recursive-package, installed-byte, and retained-archive evidence at `evidence/local/2026-08-04-v0.1.43/manifest.json`. The historical live run predates the descriptor-open correction. No requirement, release, production, or gate promotion is claimed. |
79
80
| OIDC validated-address transport repair |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py`| 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. |
80
81
| Independent WebAuthn-UV approval component |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. |
81
82
| Prior `0.1.8` candidate, unfiltered local run |`UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q`|`1087 passed, 2 failed, 7 expected PostgreSQL skips` on 2026-07-16 | Both failures were preserved environmental G01 gates. This was not a passing unfiltered release run and is not current `0.1.9` evidence. |
0 commit comments