Record final candidate readiness evidence

This commit is contained in:
SimpleTest 2026-08-13 13:39:47 +03:00
parent 02ccebb5b9
commit dbfb019598

View File

@ -5,14 +5,14 @@ results from product limits and unknown production properties.
## Current local candidate and operations recheck on 2026-08-13
- Application source candidate `df6396df8adbac982c145d5e0629feaacedcd304` passed the
- Application source candidate `02ccebb5b9b0720bf7c40b5be736d4c1a1e9e656` passed the
complete isolated `scripts/quality.sh` pipeline in user-systemd unit
`codex-heavy-wnh-final-quality-df6396d-20260813-074825-2662087.service`.
ExUnit reported 470 passing tests with seed `358182`; the fourteen browser
map tests passed; every configured quality and security gate passed; and the
`codex-heavy-wnh-final-quality-02ccebb-20260813-132155-4023930.service`.
ExUnit reported 470 passing tests; the fourteen browser map tests passed;
every configured quality and security gate passed; and the
final Debian 13.6 runtime-image scan reported zero detected
vulnerabilities. The unit exited successfully after 2 minutes 24.548
seconds with a measured 212.7 MiB systemd-unit memory peak. Exact-name
vulnerabilities. The unit exited successfully after 3 minutes 8.923
seconds with a measured 327.5 MiB systemd-unit memory peak. Exact-name
inspection after the run found no remaining run-scoped container, network,
volume, or temporary quality/security image.
- The same candidate passed the complete isolated browser E2E suite in
@ -32,11 +32,17 @@ results from product limits and unknown production properties.
`output/e2e/20260813033312-437829/results.json`.
- A fresh read-only production release plan compared this candidate with
production revision `dafcdb36cbe221af0c880fd05da3321e181ddd2c`. It observed
thirty-one pending
thirty-four pending
commits, one reviewed `application_safe` migration
(`20260812120611_allow_inbox_only_nearby_subscriptions.exs`), external
PostgreSQL 18.4, unchanged shared-edge routing, and all twelve environment
capability groups `READY`. The plan completed without changing production.
- The clean release-artifact workflow prepared a complete-history Git bundle
and a compressed `linux/amd64` application-image archive under
`output/releases/02ccebb5b9b0720bf7c40b5be736d4c1a1e9e656/`. The retained
artifact set occupies 65 MiB; its manifests and adjacent SHA-256 files
validated successfully. Preparing and validating these local files did
not upload or apply them.
- Production's configured rate-limit map contains all twelve required
authentication and anonymous-intake policies with positive limits and
windows. The implementation has a retained local one-CPU benchmark, but the
@ -91,12 +97,17 @@ results from product limits and unknown production properties.
14 continuous days before production access can be requested; Internal
testing does not satisfy that gate.
- Public DNS returned no MX record for `whoneedhelp.com` or
`contact.whoneedhelp.com`. Production uses `contact@whoneedhelp.com` as a
`email.whoneedhelp.com`. Production uses `contact@whoneedhelp.com` as a
Brevo outbound sender and routes internal support alerts to the monitored
operator mailbox, but neither fact establishes inbound delivery to
`contact@whoneedhelp.com`. The address must not be saved as the public Play
support contact until an inbound route is configured and tested, or the
operator deliberately selects another monitored public address.
- Read-only account inspection did not establish an existing netcup mail
product: the authenticated customer-control-panel login stopped at the
account's required TAN challenge. The ImprovMX page was still an unauthenticated
login page. No account, alias, MX record, forwarding destination, or DNS
setting was created or changed during these checks.
- The connected physical phone again passed the strict Play-delivered build
check for `org.whoneedhelp.mobile` version `0.1.2 (3)`: installer Google
Play, signing identity from the protected Play App Signing set, verified