diff --git a/docs/verification.md b/docs/verification.md index e4b508e..fb57d69 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -3,6 +3,83 @@ Observed through 2026-07-24 in the local workspace. This report separates observed results from product limits and unknown production properties. +## Final local development audit on 2026-07-24 + +These observations apply to the local checkout, its isolated test projects, and +`https://whoneedhelp.imalto.site`. No push, test/production deployment, Devpost +edit, branch, or tag was made. + +- The separate Firebase project `who-need-help-dev-firebase` uses the free Spark + plan, has Gemini and Analytics disabled, and contains the development Android + app `org.whoneedhelp.mobile.development`. Its public Android configuration and + a dedicated FCM service-account credential are present only in the ignored + mode-`0600` development `.env`. The service account has the exact Firebase + Cloud Messaging API Admin role. `check-environment-readiness.sh .env + --require-release` reports zero blocking items and zero local-only warnings. +- The current development workers were recreated with that FCM configuration + only after a mode-`0600` custom-format database backup was written to + `output/backups/dev-before-fcm-workers-20260724-114450.dump` and its checksum + and archive catalog passed. Web replicas, proxy, database, test, production, + public Git, and Devpost were not changed. +- The complete Android/browser development replay passed on the stable Android + 37.1 Google APIs image with Google Play Services `262031038`. It completed a + magic-link login, Android-to-browser chat, browser-to-Android chat, FCM device + registration, a real FCM system notification, foreground live-location + sharing, and stop-sharing cleanup. The exact fixture retained two messages + and six tracking samples during verification, then cleanup restored the + original database counts with zero current tracking positions. Evidence is + `output/android-browser-development-e2e/20260724121700-2530398`; the + run-scoped container, AVD volume, image, and database fixture were absent + afterward. +- A separate signed development smoke passed on Android 37.1. Android verified + the exact App Link host, the implicit same-origin deep link opened the app, + the home and `/safety` DOM assertions passed, an unrelated HTTPS origin was + not claimed, and no WebView load or TLS error was recorded. Evidence is + `output/android-development-smoke/20260724124143-3282044`; its exact + container, volume, and image were absent afterward. +- `./scripts/test.sh` passed all 356 ExUnit tests. The final isolated browser + suite passed all 42 scenarios in Chromium, Firefox, and WebKit after updating + one stale assertion to the product's already-covered double-blind review + reveal behavior. Evidence is `output/e2e/20260724122808-2848321`; all + run-scoped containers, networks, database volume, and images were absent + afterward. +- `./scripts/quality.sh` passed ShellCheck, Hadolint at the configured threshold, + actionlint, every Compose render, Prometheus and Alertmanager validation, + Helm lint, tracked-source and image scans, formatting, warnings-as-errors + compilation, xref, strict Credo, Sobelow, Dialyzer, Hex/npm audits, all 356 + ExUnit tests, and the isolated release/rollback/migration drills. The quality + project's exact temporary resources were absent afterward. +- The final isolated 30-second load run used 3 web and 2 worker replicas with 40 + public HTTP, 40 WebSocket, and 8 authenticated mutual-aid virtual users. It + completed 38,364 HTTP requests and 34,890 checks with zero failures, including + 1,729 authenticated chat/tracking iterations. HTTP p95 was 6.776 ms and the + authenticated HTTP p95 was 9.88 ms. These are workstation measurements, not + production limits or minimum resource requirements. +- During that load, PostgreSQL peaked at 21 client backends with at least 76 + connection slots of observed headroom. It recorded zero rollbacks, deadlocks, + conflicts, temporary files, or lock-waiting backends. Ecto telemetry across + the three web replicas observed 186,908 queries with a 0.250 ms average total + duration; the largest individual statement maximum in `pg_stat_statements` + was 8.300 ms. The exact application-table cleanup diff was empty. Evidence is + `output/performance/final-local-audit-load`. +- Observed load peaks were 335.7 MiB for one web replica, 239.5 MiB for one + worker, 141.6 MiB for PostgreSQL, and 307.2 MiB for the isolated proxy. + CPU peaks occurred under the deliberately concurrent workstation replay and + are retained in `resource-summary.json`; no arbitrary production threshold is + inferred from them. +- The follow-up resilience drill restarted and sequentially replaced all 3 web + and 2 worker replicas. It recorded 1,244 readiness samples with zero failures, + observed all replacement web nodes, and passed the cross-node PubSub probe. + Application logs contained no error, fatal, panic, timeout, deadlock, or + out-of-memory marker. Evidence is + `output/resilience/final-local-audit-resilience`; the exact isolated load + project and resources were absent afterward. +- A visible Chrome session on the development origin rendered the real MapLibre + landing-page demo with its three synthetic markers and zoom controls. The + unauthenticated Requests navigation correctly redirected to login and showed + the access guard. The isolated browser suite covers the authenticated request + map, viewport discovery, clustering, and request lifecycle. + ## Local dev hardening audit on 2026-07-23 These observations apply only to the local checkout, its Compose project, and @@ -32,18 +109,13 @@ edit, branch, or tag was made during this audit. port 2525. A real application-generated Google ownership-verification message was accepted in 853 ms and observed in the Gmail inbox from `dev@whoneedhelp.com`. -- `./scripts/check-environment-readiness.sh .env` now reports external SMTP, - the support inbox, application secrets, Google sign-in, browser VAPID, - Android App Links, and Android signing inputs as ready. Its two remaining - development blockers are the four public Firebase Android values and the FCM - service-account credential. No release-readiness claim is made until those - credentials are imported and provider/device behavior is exercised. -- The existing Google Cloud project `who-need-help-development` was selected in - the Firebase console through the user's already authenticated dev-port Chrome - session. Firebase requires the account holder to accept its Terms before it - can add Firebase services to that existing project. That legal acceptance - remains pending explicit user confirmation; no Firebase project, app, - service account, credential, or environment value was created or changed. +- At this point in the audit, `./scripts/check-environment-readiness.sh .env` + still reported the four Firebase Android values and the FCM service-account + credential as blockers. They were subsequently configured and externally + exercised as recorded in the final 2026-07-24 audit above. +- The user subsequently accepted Firebase's separate terms in the authenticated + dev-port Chrome session. A separate Spark-plan development Firebase project + was then created and configured as recorded in the final audit above. - Real browser Web Push was exercised on the development origin through the user's existing dev-port Chrome profile. The exact origin permission was changed from `Ask (default)` to `Allow`; the application registered a second, @@ -1479,10 +1551,10 @@ None of the observations below describe the current delivery path. Compose project, containers, PostgreSQL volume, and images were absent after cleanup. Evidence is retained at `output/external-boundaries/local-boundaries-fix-20260723`. -- Firebase Android and server FCM credentials are intentionally still absent. - Adding Firebase to the existing Google Cloud development project is pending - explicit acceptance of the separate Firebase terms. No test or production - provider configuration was changed. +- Firebase Android and server FCM credentials were subsequently configured in a + separate development-only Spark project and exercised as recorded in the + final 2026-07-24 audit above. No test or production provider configuration was + changed. ## Known work before a public production launch @@ -1512,14 +1584,11 @@ None of the observations below describe the current delivery path. Google OAuth client on its exact HTTPS callback origin after the tested release is explicitly promoted. The test client and callback have already completed real registration and returning-user login. -- Development VAPID is configured, and a real development browser subscription - plus one external adapter delivery completed successfully. Configure isolated - Firebase/FCM credentials, then verify a physical Android development device - before repeating browser and Android delivery against each promoted origin. - Direct Web Push/FCM adapters, registration lifecycle, private payload shape, - retries, invalid-device cleanup, and Android deep-link handling are - implemented and locally tested. Browser provider delivery is now observed on - development; Android FCM delivery is not. APNs and iOS are outside the current +- Development VAPID and isolated Firebase/FCM are configured. Real development + browser Web Push and Android-emulator FCM delivery both completed + successfully. Before a public mobile release, repeat FCM and background + tracking on a physical Android device and repeat browser/Android delivery + against each explicitly promoted origin. APNs and iOS are outside the current scope. - Load-test representative data and traffic, then set measured pool, resource, autoscaling, and action-limit policies.