Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,11 @@ jobs:
python3 scripts/test-verify-release-attempt-v090.py
python3 scripts/test-release-runtime-inventory-v090.py
python3 scripts/test-probe-warm-observability-v090.py
python3 scripts/test-probe-python-modeling-load-bearing-v090.py
python3 scripts/test-probe-opentaint-product-v090.py
python3 scripts/test-release-control-attempt-v090.py
python3 scripts/test-run-release-control-v090.py
python3 scripts/test-execute-release-controls-v090.py
python3 scripts/test-swift-common-v2.py
- run: cargo fmt --check
- run: cargo test
Expand Down
32 changes: 26 additions & 6 deletions docs/v0.9.0-control-inventory.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,9 +7,29 @@ runtime environment and deadlines derived from the retained run durations.
These controls are not included in the 84 correctness groups or the 92 normalized
report partitions.

Control execution remains disabled. The next prospective plan must finish
non-report capture integration and resolve the Python modeling supplemental
command inventory before final parent review. The warm-observability script
records advertised help surfaces only; it does not establish performance or
infer unsupported behavior from an absent option. Existing Swift query/control
compatibility is independently bound by the common-population plans.
Three supplementary controls retain the prior release's Python modeling,
warm-observability and shipped OpenTaint product scopes. The full OpenTaint
0.4.6 Darwin arm64 archive and every one of its 329 files have been restored
against the historical hashes. The restoration receipt records the 2 GiB
acquisition/extraction budget; the actual archive and extracted files total
approximately 327 MiB. Restoration is not an analyzer result.

Each control receives an isolated checkout because the historical Java and
FlowDroid probes share an output path. The prospective storage budget includes
33 control checkouts (23.68 GiB of tracked files) plus the original 12 GiB of
matrix and staging space, rounded to 36 GiB. The launch floor is therefore
124 GiB: 40 GiB protected reserve, 24 GiB scratch, 24 GiB retained output,
and 36 GiB checkout/staging allowance. All operations share the analyzer lock.

Warm commands perform two measurement repeats internally, and overhead
commands perform three. These are method repetitions, not retries; the outer
runner must invoke each command once and retain every repeat. Infrastructure
attempts remain separately bounded at two and are never selected automatically.

Control execution remains disabled pending integration validation, the final
merged harness identity, an exclusive resource reservation and parent plan
review. Capturing a successful command does not establish that a model engaged
or that a tool is equivalent to another invocation surface. The help audit
does not establish performance or infer unsupported behavior from an absent
option. Existing Swift query/control compatibility remains independently bound
by the common-population plans. Historical runners and evidence are unchanged.
177 changes: 165 additions & 12 deletions reports/releases/v0.9.0/execution-v1/contract.json

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,142 @@
{
"base_commit": "1e8b871cc207af7995d9ad13c77a1e0d58d0c4df",
"captured_utc": "2026-09-29T15:35:38.468781+00:00",
"execution_authorized": false,
"live_read_only_checks": [
"Exact OpenTaint archive hash and329-file membership verified",
"Python probe held tool digests and full CodeQL CLI and pack inventory verified",
"Current execution_authorized=false rejects both new probes before output creation"
],
"schema": "release-control-integration-validation/v1",
"scope": "Synthetic and mocked control/recorder tests only; no analyzer control or matrix result.",
"test_count": 78,
"test_scripts": 14,
"tests": [
{
"command": [
"/usr/bin/python3",
"scripts/test-execute-release-controls-v090.py"
],
"exit_code": 0,
"output": "....\n----------------------------------------------------------------------\nRan 4 tests in 0.002s\n\nOK\n",
"seconds": 0.076
},
{
"command": [
"/usr/bin/python3",
"scripts/test-execute-release-v090.py"
],
"exit_code": 0,
"output": "....\n----------------------------------------------------------------------\nRan 4 tests in 0.006s\n\nOK\n",
"seconds": 0.054
},
{
"command": [
"/usr/bin/python3",
"scripts/test-prepare-release-root-v090.py"
],
"exit_code": 0,
"output": ".Cloning into '/private/var/folders/t1/k_27wjcd4095w9w121dm92_w0000gn/T/tmpzfrvjhcb/controls/java-modeling'...\ndone.\nHEAD is now at a3900db exact control harness\n...Cloning into '/private/var/folders/t1/k_27wjcd4095w9w121dm92_w0000gn/T/tmpw2tfxq49/execution'...\ndone.\nHEAD is now at da7efc5 harness\n..\n----------------------------------------------------------------------\nRan 6 tests in 1.155s\n\nOK\n",
"seconds": 1.201
},
{
"command": [
"/usr/bin/python3",
"scripts/test-probe-opentaint-product-v090.py"
],
"exit_code": 0,
"output": ".....\n----------------------------------------------------------------------\nRan 5 tests in 0.480s\n\nOK\n",
"seconds": 0.546
},
{
"command": [
"/usr/bin/python3",
"scripts/test-probe-python-modeling-load-bearing-v090.py"
],
"exit_code": 0,
"output": ".....\n----------------------------------------------------------------------\nRan 5 tests in 0.065s\n\nOK\n",
"seconds": 0.119
},
{
"command": [
"/usr/bin/python3",
"scripts/test-probe-warm-observability-v090.py"
],
"exit_code": 0,
"output": ".....\n----------------------------------------------------------------------\nRan 5 tests in 0.008s\n\nOK\n",
"seconds": 0.063
},
{
"command": [
"/usr/bin/python3",
"scripts/test-release-attempt-v090.py"
],
"exit_code": 0,
"output": "..........\n----------------------------------------------------------------------\nRan 10 tests in 0.891s\n\nOK\n",
"seconds": 0.934
},
{
"command": [
"/usr/bin/python3",
"scripts/test-release-control-attempt-v090.py"
],
"exit_code": 0,
"output": "........\n----------------------------------------------------------------------\nRan 8 tests in 1.828s\n\nOK\n",
"seconds": 2.678
},
{
"command": [
"/usr/bin/python3",
"scripts/test-release-environment-v090.py"
],
"exit_code": 0,
"output": "..\n----------------------------------------------------------------------\nRan 2 tests in 0.004s\n\nOK\n",
"seconds": 0.046
},
{
"command": [
"/usr/bin/python3",
"scripts/test-release-runtime-inventory-v090.py"
],
"exit_code": 0,
"output": "..\n----------------------------------------------------------------------\nRan 2 tests in 0.004s\n\nOK\n",
"seconds": 0.042
},
{
"command": [
"/usr/bin/python3",
"scripts/test-run-release-control-v090.py"
],
"exit_code": 0,
"output": "..\n----------------------------------------------------------------------\nRan 2 tests in 0.001s\n\nOK\n",
"seconds": 0.064
},
{
"command": [
"/usr/bin/python3",
"scripts/test-run-release-group-v090.py"
],
"exit_code": 0,
"output": ".........\n----------------------------------------------------------------------\nRan 9 tests in 0.014s\n\nOK\n",
"seconds": 0.076
},
{
"command": [
"/usr/bin/python3",
"scripts/test-v090-execution-contract.py"
],
"exit_code": 0,
"output": "...........\n----------------------------------------------------------------------\nRan 11 tests in 0.123s\n\nOK\n",
"seconds": 0.165
},
{
"command": [
"/usr/bin/python3",
"scripts/test-verify-release-attempt-v090.py"
],
"exit_code": 0,
"output": ".....\n----------------------------------------------------------------------\nRan 5 tests in 0.502s\n\nOK\n",
"seconds": 0.55
}
]
}
Loading
Loading