Evidence consumer acceptance — 2026-09-12
This record covers the EVD-5 caller and native-route cutover. Source was verified against consumer implementation f94c39995d079b9a5553821d57090017c5911d75, Platform tenant correction de40dad49cb951a5cf818e0cd865c6043264f232, and Policy report publication 240882ea04402bae9fbb23744f4d15975fc02bd2. All seven consumer containers were healthy with zero restarts at final readback. The final native archive content and cold-start trust gates passed against Evidence source 81d78a68f5a9cf0c31f636148ed51addd1b486e7. The frozen final acceptance receipt records the completed caller criteria; the sprint record owns final program closure.
Caller outcomes
| Census IDs | Measured outcome | Acceptance boundary |
|---|---|---|
| 00, 05 | Policy evaluated the existing scn-id-acceptance revision 1 and created an attested verdict; owner readback returned 200. | The fixed internal controller route remains native. No pack was activated. |
| 01 | Platform’s owner erasure check returned 200 after preserving the authenticated tenant claim and validating its canonical UUID. | The actor was verified absent before the request; no real identity was erased. |
| 02 | Scanner assembled a blocked report from a controlled Low finding and anchored its ES256 scan-result attestation at local index 14. | Real report assembly, not a new scanner analysis job. |
| 03, 04 | Excititor callers are withdrawn from current source and deployed Vulnerabilities successors. | Successor source, DI, dependency manifests and deployed DLL census were checked; predecessor container absence alone was insufficient. |
| 06 | The deployed RO verifier returned Verified for the actual Scanner report and Missing for an absent digest. Owner query and Scanner JWKS both returned 200. | Production client invoked in an isolated probe; no promotion was executed. |
| 07 | Creating a controlled RO draft/component issued canonical provenance queries returning 200. | No provenance entry existed for that local image; the stored reference stayed null. |
| 08 | Deployed RO deployment writer reached the canonical owner and propagated 400 payload_type_missing. | Intentionally invalid input plus positive typed-client specs; no successful synthetic deployment attestation. |
| 09 | Deployed RO seal writer reached the canonical snapshot owner and propagated 400 for oversized releaseName metadata. | No approval, promotion, deployment or release-decision bundle was created. |
| 10 | Findings created a signed controlled VEX override and local transparency receipt at index 13; owner readback returned 200. | Retained test decision, without customer artifact delivery. |
| 11 | Export completed a bounded audit bundle and published an Evidence snapshot. Invalid TLPT input propagated the owner’s 400 validation response. | No white-team approval or TLPT exercise is claimed. |
| 12 | The built production CLI client verified local Merkle inclusion bound to the actual bundle digest. | CheckpointSignatureValid=false: inclusion is not checkpoint signature verification. |
| 13 | CLI export/status and native five-file content passed; the existing crypto verify command accepted the original signature and rejected tampered payload and wrong trust. An unsealed controlled draft returned 404/nonzero without a file; the verdict-metadata helper reached the owner with 200. | A native signed-reference archive is verified. The tested verdict lacks frozen replay inputs, and the top-level replay engine is unavailable; no replay ran. |
| 14 | After the cold public key matched independently retained trust, Tester created exactly one new signed snapshot and completed native export/status/download. Its hash equals API, CLI, repeated download and cached package bytes. | Native five-file signed-reference package, with updated verification instructions. Referenced material bytes are not claimed as embedded. |
| 15 | The final 42-running-container census contains zero predecessor Evidence host bindings. Native Doctor API and Platform registration agree on 25 checks. | Twelve TimestampAssurance checks are unhealthy or conditional; this is API/registration parity, not a claim that all checks pass. |
| 16 | BuildX keeps its optional operator-supplied exact URI. | No service binding exists to repoint; no automatic Rekor-v2 retarget. |
| 17 | Timeline’s retired provider returns an empty result without calling its old helper. | No current HTTP caller. |
| 18–20 | Findings FixChain, JobEngine bundle rotation and generic Provcache have no active production HTTP binding. | Source/DI and runtime successor census support exclusion. |
Retained controlled records
- Policy verdict:
verdict-184aa9408f27f0da69d7c7c029deaa9216acbd460fdf0db0ecec3de342c82bc6. - The initial Platform probe retained actor reference
63c5234d-c51e-4917-9da1-47308e937d29and audit eventeafb7e48-fce7-44fe-85da-95c45fe96b53after its owner call failed; the actor had been verified absent. - Platform successful absent-actor probe:
2b7a2d5f-188f-4f80-8755-5bb5ae1febf1. - Scanner report:
report-4474f9b17bd67f3fb7fe; attestationcf212de2-74c1-0354-b446-120f46a57ce8, index 14. - Findings decision:
2ace4436-ab51-4e8d-85b5-4ad3da1b6586; transparency6901806c-780b-9558-a189-82a30120985f, index 13. - RO draft
rel-0cb88d5, componentcomp-6d5a457; no deployment requested. - Export job
bndl-493a3a90be5a42869aa0805554aeb97f; Evidence snapshotefb8b818-31d9-4920-8952-d7d1718f8189. - Tester snapshots
17f789a5-62db-4d54-a29a-5b4c48b27d0d(initial failed export) and27f7d5f2-d21a-4da3-8ce8-5c27f377687d(transport retry). - Report-policy snapshot
387384b3-dd22-46f9-95f3-ac8839d64f7f, revision 1. - Final cold-start snapshot
593d1a49-f6d3-43fb-92ef-4b729f6511cb; native exportsexp-20260912152447-77f8b9a2andexp-20260912152626-d6382b11.
The first portable export was 349 bytes and contained an empty artifact manifest. Tester/CLI byte hashes agreed, but that result is retained as transport-only proof and is not accepted as a complete portable evidence archive.
Final cold-start and native archive proof
Evidence Web image sha256:d3b726bfa304d6c1122026ff5a7291cf79e10247a41b62ac1b1d4c71485c0b2a started at 15:21:11 UTC. Its public JWKS returned 200 before any new seal, and its Ed25519 public identity matched the independent trust retained at 11:58:35 UTC. The runtime receipt records 118 unchanged environment settings, nine unchanged mounts, ready 200, healthy with zero restarts, and the unchanged healthy Evidence Worker.
One Tester snapshot increased the signed-bundle census from 12 to 13. Its native archive is 5,280 bytes, SHA-256 fd19068a25675e7ff8d34342e4ba66faee699905847f8b561f831fdd12b5fb12. All paths returned identical bytes: direct API, CLI export, Tester download, repeated download and the cached package. The five members are manifest.json, signature.json, bundle.json, checksums.txt and instructions.txt. The signed manifest retains the exact 90-byte controlled material reference; the exported payload and signature match the owner record.
The real CLI command uses the existing Stella Ops bouncycastle.ed25519 provider. It returned 0 for the decoded original payload/signature, and 1 for both a changed material hash and a different trusted public point:
stella crypto verify --input payload.bin --signature signature.raw --key-id evidence-locker-capsule-key --trust-policy trust-policy.yaml --format raw
The new package includes these corrected instructions. Verification uses independently retained public trust, not a key asserted by the archive. It does not validate the RFC3161 token, a transparency checkpoint signature, or the bytes behind external material references. See the native verification workflow.
The earlier 349-byte manifest-only failure and the 5,072-byte signed native package remain historical evidence. The latter’s local and live cached bytes retain SHA-256 2417e526dbabf84bb893ebd389d838f8c9fb2ef172d42bdc1a87088970b559c7; its cached instructions were not rewritten.
Governed report-policy prerequisite
Policy had zero report snapshots. The new owner API requires both policy:edit and policy:activate, an authenticated tenant/subject, and an expected revision. Anonymous publication returned 401; each single-scope request returned 403. The reviewed initial policy blocks every severity, including Unknown. Publication created exactly revision 1 with digest 1bc049bf3c19f83023c666aa35d6d1ba7a2e8e0e42d69229e4eef0ad1a3518d2; replaying expected revision 0 returned 409. Complete pack/version state hashes before and after were identical. No existing pack, approval or release gate was modified. See Policy publication.
Runtime and persistence boundaries
The durable forward/recovery profiles are under devops/compose/evd5/. Scanner/Platform chains are recorded in local-runtime-chains.json; Policy/RO chains and pins are recorded in local-scn-runtime.json. Every swap used an immutable image, exact environment comparison and unchanged mounts/networks, with its prior image retained. The Platform tenant correction and Policy publisher refresh each had zero effective environment changes.
| Consumer | Current image digest |
|---|---|
| platform | sha256:ca24e4a0f82e8c0423ee196d7bbe0af4693106d0317c72991acdda80aacc88b8 |
| policy-engine | sha256:49f335ee8aa94af7a18a3cfb1fee951a1329335074aa014de7b8ef876088545d |
| scanner-web | sha256:6f0ba26483fd87db83a391c82838e39f802662d1f682fd531c5ac229393fe220 |
| release-orchestrator | sha256:8fc26d8d65494e1e94d6281b1ff0e922e5372455bb2547450ad17dc50ddd00a1 |
| findings-web | sha256:aa42099b7efbd04c50d55b01b6b73b7dc97b3bbdbc022c2e1df8098bc8131573 |
| export-web | sha256:47abc6b7e9ac1d4eb9e31defc6b1be32e9e920d80165e3aa7beb1f88f0739359 |
| stellaops-tester | sha256:d122887de9cec3ff41686b2ad3f68734f87de144c8c68d91c9ee179cc203cccd |
No caller migration introduced destructive SQL. Export’s newly activated retention was explicitly reviewed against empty existing data. The shared Catalog metadata migration materialized only in RO, as an empty catalog_replica.empty_observations table owned by release_orchestrator. Scanner, Findings and Export had no such table after their restart. Platform’s refresh removed central Scheduler/PacksRegistry migration registrations; it did not move or delete their data. Export’s newly reachable audit-job retention was admitted only after a fresh zero-job census; the existing 24-hour/200-job defaults were retained. The new report policy is request-driven, not startup fixture data.
Reverification
Run the adjacent client suites and the current runtime source guards: node tools/scripts/validate/check-local-scn-runtime-sources.cjs --self-test and node tools/scripts/validate/check-local-scn-runtime-sources.cjs. The guard passed 79 positive and 275 negative controls; source review covered 22 canonical Compose inputs. The generic replay guard passed 42 positive and 167 negative controls. Its unrelated historical Gateway selection was preserved.
Latest focused suites passed: RO 39, CLI 28, Scanner 15, Findings 10, Export 5, Tester 21, Platform tenant checks 9, Policy publisher checks 6, architecture 64 and consolidated route checks 5. The new actual-startup Ed25519 command cases passed 3/3 (original, tampered and wrong trust). The knowledge verifier was clean. These are separate scoped runs, not a claim that a full repository suite ran.
Use the existing operator/service identities for the API rows above. Doctor’s registered self endpoint is http://evidence.stella-ops.local:8080/doctor/evidence/checks; all 25 Platform registrations were fresh. Existing TimestampAssurance trust/qualification/ revocation/time/TSA configuration limitations remain outside this cutover.
