diff --git a/docs/verification.md b/docs/verification.md index 24e2a4b..7dacdc9 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -31,6 +31,46 @@ results from product limits and unknown production properties. creation and the monitored mailbox receipt check remain explicit external operations. +## Current pilot release-boundary audit on 2026-08-09 + +- The read-only production release plan compared local candidate `f672e9c` + with production revision `f0cb936854343be12ce58284d872c68c701ad7f3` and + observed eleven pending commits. Shared edge routing is unchanged, the + migration policy is `application_safe` with zero migrations, external + PostgreSQL reported version 18.4, and all twelve environment-readiness + capability groups reported `READY` with zero local-only warnings. +- The same plan stopped before any mutation because the production checkout is + not clean. Its exact differences are a tracked modification to + `scripts/production-play-physical-fixture.exs` and the untracked companion + `scripts/production-play-physical-fixture.sh`. Both remote SHA-256 values + match the current local files exactly. The running production application + remains healthy with zero restarts on immutable image + `who-need-help:production-f0cb93685434`. +- Read-only isolation inspection observed the frozen hackathon-test checkout + clean at `cf7bacdf61ffb171ebac85e32dfcf12bc6972d59`. Its application, + PostGIS, and Mailpit containers remain healthy, and its public readiness + endpoint returned the exact ready payload. No test file, container, database, + Git reference, or public remote was changed. +- The connected physical device is authorised over USB and still has Google + Play-delivered `org.whoneedhelp.mobile` version `0.1.1 (2)`, installed by + `com.android.vending`. Candidate `0.1.2 (3)` remains local-only; its AAB + SHA-256 is + `5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`, + and a fresh Android source fingerprint still matches the recorded candidate + fingerprint. +- The daily encrypted backup timer is loaded, enabled, and active; its latest + completed service exited successfully. The independent off-host monitor + timer is likewise loaded, enabled, and active. Its latest observed checks + reported production readiness HTTP 200 with the expected payload and an + authenticated aggregate-metrics scrape. +- Advancing from this boundary still requires deliberate external mutations: + archive the two exact fixture files outside the production checkout and + restore that checkout to its observed revision, repeat the read-only plan, + approve an application-only release, publish the exact v3 AAB only to Google + Play Internal testing, and create/rotate independently scoped application + and monitor SMTP credentials with delivery checks before revocation. None of + those mutations was performed by this audit. + ## Current pilot-candidate recheck on 2026-08-09 - Local revision `beb5de5eda5e7490cf8b757810bf55787cce211f` passed the