You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/GATE_EVIDENCE.md
+2-1Lines changed: 2 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -56,7 +56,8 @@ Gate statuses used here:
56
56
| npm `0.1.17` model-broker request-replay repair candidate | Broker nonce edge inventory; canonical source scout; GPT-5.5 patch plan; DeepSeek security and constitution reviews; required/malformed/duplicate/concurrent/cross-capability nonce regressions; unfiltered local suite; release verifier; two deterministic builds; source → installed generation 1 → repacked generation 2 package verification | Reviews PASS/converge; focused broker suite `10 passed`; unfiltered `1147 passed, 15 expected host/PostgreSQL skips`; source and both installed npm generations each `1068 passed, 15 expected skips`; package check, release verifier, recursive package gate, and byte-identical Python builds PASS on 2026-07-20 | H/L candidate evidence only. The capability remains reusable within exact worker/grant/model/expiry/request/token budgets, while every inference requires a persistent per-capability one-use request nonce before transport. Duplicate and concurrent replay fails closed without a second transport call or extra budget spend. No live semantic worker, mutation-authorized PostgreSQL, real-host cross-platform `0.1.17`, publication, enrollment, company data, production, A2A cutover, or gate promotion is claimed. |
57
57
| npm `0.1.18` Core→Approval signed-broker replay repair candidate | Broker edge inventory; Core/Approval wire-contract reconciliation; Codex implementation plan; DeepSeek security critic; constitution review; exact proof binding/tamper/time/canonicalization/duplicate-header/query and sequential/concurrent/reopen replay regressions; focused approval suite; unfiltered local suite; `agentnet verify`; release verifier; two deterministic builds; source → installed generation 1 → repacked generation 2 package verification | Reviews PASS/converge with no blocker; focused approval suite `46 passed`; unfiltered `1166 passed, 15 expected host/PostgreSQL skips`; `agentnet verify`, source, and both installed npm generations each `1087 passed, 15 expected skips`; package check, release verifier, recursive package gate, and byte-identical Python builds PASS on 2026-07-20 | H/L candidate evidence only. Every Core→Approval create/status/retrieve request retains Bearer authentication and adds an exact method/path/body/audience/purpose/key/time/nonce HMAC proof; Approval schema v3 persistently and atomically consumes the verified nonce hash before business action, while response-loss retries use fresh broker nonces and preserve separate business idempotency. No mutation-authorized PostgreSQL v3 run, atomic live Core/Approval deployment, live enrollment/passkey, C0 round trip, company data, publication, production, A2A cutover, or gate promotion is claimed. |
58
58
| Published npm `0.1.19` zero-state C0 release and blocked deployment preflight | Exact public registry identity/integrity; clean install/launcher/package/Pi-skill checks; source → generation 1 → generation 2 verification; peer-reported remote public-artifact preflight against reportedly live Core schema v3 | Public package checks passed; the remote deployment peer reported that pre-migration `require_exact_postgres_catalog` failed deterministically with `psycopg.ProgrammingError` because PostgreSQL `format('%I.%I', ...)` appeared in a parameterized psycopg query, and reported stopping before mutation on 2026-07-22 | H/L package evidence plus peer-reported negative deployment evidence only. The peer reported no migration, restart, runtime switch, enrollment, authority, message, company-data action, live C0, or A2A mutation and reported live Core/Approval still on `0.1.18`, schema v3; this candidate's retained local evidence does not independently verify that remote runtime report. `0.1.19` is immutable and must not be deployed. |
59
-
| Current uncommitted `0.1.20` PostgreSQL catalog-verifier correction candidate | Exact psycopg failure regression; server-side `quote_ident()` composition; full PostgreSQL production-test file; full source suite; release/package conformance; `agentnet verify`; recursive installed-package proof; deterministic builds; package/lock/import/diff checks | Failing regression reproduced exact `%I` error before repair; fixed PostgreSQL lane `47 passed, 7 expected dedicated-database skips`; full source `1346 passed, 15 expected host/PostgreSQL skips`; release/package conformance `32 passed`; `agentnet verify` and both recursive npm generations each `1267 passed, 15 expected skips`; release verifier, recursive package gate, and package/lock/import/diff checks PASS; byte-identical wheel/sdist on 2026-07-22 | Minimal verifier-only correction. Migration SQL/checksums, exact catalog comparisons, identity, authority, C0, messaging, cleanup, and A2A semantics remain unchanged. Final review/commit/tag/push/CI/publication/public verification/deployment remain pending. |
59
+
| Published npm `0.1.20` PostgreSQL placeholder correction and blocked read-only preflight | Public package verification plus independent private-staging, transaction-read-only PostgreSQL 18.4 preflight against preserved live schema v3 | Public package checks passed; `%I` defect was corrected; preflight then exposed exact-catalog gaps for PostgreSQL 18 `contype='n'` rows and server-rendered CHECK/index predicates before mutation | Negative deployment evidence only. The peer reported no migration, restart, runtime switch, enrollment, authority, message, company-data action, or A2A mutation. `0.1.20` remains immutable and undeployable. |
| OIDC validated-address transport repair |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py`| 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. |
61
62
| Independent WebAuthn-UV approval component |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. |
62
63
| Prior `0.1.8` candidate, unfiltered local run |`UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q`|`1087 passed, 2 failed, 7 expected PostgreSQL skips` on 2026-07-16 | Both failures were preserved environmental G01 gates. This was not a passing unfiltered release run and is not current `0.1.9` evidence. |
0 commit comments