Record pilot candidate verification

This commit is contained in:
SimpleTest 2026-08-09 22:09:02 +03:00
parent d2cba218f7
commit 360c7a567e

View File

@ -3,6 +3,51 @@
Observed through 2026-08-09 in the local workspace. This report separates observed Observed through 2026-08-09 in the local workspace. This report separates observed
results from product limits and unknown production properties. results from product limits and unknown production properties.
## Current pilot-candidate recheck on 2026-08-09
- Local revision `beb5de5eda5e7490cf8b757810bf55787cce211f` passed the
complete isolated `scripts/quality.sh` pipeline in user-systemd unit
`codex-heavy-wnh-quality-current-head-20260809-20260809-214131-211016.service`.
The unit completed successfully in 4 minutes 40.738 seconds with a measured
384.7 MiB memory peak. It passed all configured quality and security gates,
456 ExUnit tests, and the final Debian 13.6 image scan with zero detected
vulnerabilities. The later local change through `d2cba21` modifies only the
Play location-video runbook; application and Android source are unchanged.
- Android release candidate `0.1.2 (3)` remains source-bound: the current source
fingerprint and the recorded artifact fingerprint are both
`70529d3befcb0818f0b79f7869389b4fad432eb2911be08d52342529b7f22614`.
The AAB SHA-256 is
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`,
and the location/foreground-service policy contract passes. The connected
physical phone still has Play-delivered `0.1.1 (2)` installed by
`com.android.vending`; candidate v3 has not been uploaded or delivered and is
therefore not yet Play-verified.
- Read-only production inspection observed checkout
`f0cb936854343be12ce58284d872c68c701ad7f3`, image
`who-need-help:production-f0cb93685434`, a healthy application container, and
the exact public readiness response. The checkout contains two fixture-script
paths prepared for the Play location recording. Their SHA-256 values exactly
match the current local files, and no fixture state file or fixture process
exists. They still make the checkout dirty, so the release preflight must not
proceed until those exact files are archived outside the checkout and the
tracked path is restored to the observed production revision.
- The frozen hackathon-test checkout remains clean at
`cf7bacdf61ffb171ebac85e32dfcf12bc6972d59`, its application, PostGIS, and
Mailpit containers remain healthy, and public readiness returns the exact
ready payload. This recheck did not write to either server checkout, restart a
container, or push Git.
- The daily encrypted off-site backup timer is loaded, enabled, and active. Its
latest service run on 2026-08-09 completed successfully with status 0. The
independent BuyVM monitor timer is also loaded, enabled, and active; its
latest observed run completed successfully and reported production readiness
HTTP 200 with the expected payload plus a successful aggregate-metrics scrape.
These observations leave three deliberate external changes outstanding: the
application-only production release, upload/publication of the exact v3 AAB to
Google Play Internal testing followed by Play-delivered physical-device checks,
and rotation of the exposed production Brevo SMTP credential. None was
performed by this recheck.
## Current production E2E and isolation proof on 2026-08-09 ## Current production E2E and isolation proof on 2026-08-09
- Read-only inspection observed the independent production checkout at - Read-only inspection observed the independent production checkout at