Conversation
A competing listener reproduced AddrInUse after the original preflight pause. Allocate the server port at bind time and retain a listener on the old address while preserving all lease assertions. Record the immutable production build and functional Git checks separately from incomplete candidate recovery and performance qualification.
Keep the read-only v0 no-haves transfer probe separate from the bound live campaign. Count actual pack-channel bytes, reject malformed and failed responses, retain incomplete receipts, and require strict stock-Git indexing and full graph verification. Record serial transfer scope without claiming clone throughput or cold recovery. All 52 harness tests pass on Python 3.12 and 3.14.
Keep the immutable running fleet and campaign unchanged. Read Darwin rusage v2 with its Mach timebase and Linux proc stat ticks; preserve raw counters and process identities and reject discontinuities. Verify native CPU-clock calibration and delayed child rollup, while explicitly excluding live-tree totals and Git-only attribution. All 59 harness tests pass on Python 3.12 and 3.14.
The SHA-256 test helper dropped its listener before Canopy rebound the advertised address. Preserve ownership across startup, reject address mismatch before writes, and keep the existing supervisor, cancellation and drain semantics. Retain the deterministic pre-fix failure and separate new artifact verification from historical performance measurements.
Original-corpus remote verification passedThe admitted original RustFS corpus now passed remote verification through three fresh qualified
Verification closed October 2 at 03:02:09 UTC (October 1 Pacific). The full-corpus stage took 756.929 seconds, including all client clones and validation; this is verification wall time, not scheduled throughput or a latency benchmark.
Receipts remain at Full load campaign is running, not qualifiedThe unchanged 108-window / 114,960-arrival / 8,640-second plan is now launched on the same bound fleet. Its mandatory full preflight is running. Twenty scheduled critical workflows (300 seconds, 15-second interval, cap four) will overlap the first admitted load windows. Outputs are retained at A separate clean checkout at Both Rust and both Python CI jobs at PR head |
First six full-campaign windows are audited and preservedThis is a failed diagnostic baseline so far, not a capacity or speedup pass. The unchanged 108-window campaign continues on qualified Cellule All six closed windows offered 20 requests/s for 120 seconds with concurrency 32 over 100 active identities:
The 300-second concurrent critical schedule is closed and independently audited: 19/20 successful workflows, one busy drop, 323 successful critical steps, 38 acknowledged repository identities. One workflow completed after its schedule window; delivered workflow throughput was 0.060000/s in-window and 0.060223/s including drain, with attempted-workflow p50/p95/p99 37.089/60.551/60.551 seconds. Times include stock-Git work and validation. The dropped workflow has no receipt or writes; all nineteen attempted workflows have complete successful receipts. Their owner-loss recovery is still required.
The read-only watcher audits each sealed window's exact arrival sequences, deterministic selection, outcomes, percentiles, throughput and resource bindings before copying its report/ledger/resource files to another local filesystem. Every finished workflow attempt is retained too, including failures and its local Git data when present. In-progress outputs are not copied or qualified. Copies and manifests are at Diagnosis remains open. In the first two windows, dispatch p99 was only 12.760/20.340 ms versus service p99 3,190.791/1,550.308 ms. Proxy connection deltas were balanced (85/85/84 and 106/106/105), with zero rejections/errors. Those facts weaken timer scheduling and connection-count imbalance as dominant explanations; they do not prove a Directory or RustFS bottleneck. No fix is claimed. The previous independent lease-fencing failure also remains unexplained. The full matrix is now proceeding to its 500-identity active sets. All running-fleet source bindings remain unchanged. Full scheduled completion, every newly acknowledged write after owner loss, explicit concurrent fault coverage, higher admission profiles, matched comparisons, large transfers and isolated Linux capacity remain open. The newer |
Read-only failure diagnosis: first thirteen sealed windowsThe unchanged full baseline is still running; this is not a passing capacity result. An offline analysis reread all 52 copied report/ledger/resource files for exactly the first thirteen windows and revalidated the immutable live-run bindings.
The next separately bound replay will use the qualified binary's existing bounded request/stage tracing to distinguish repository transition time from Directory lookup/authentication time. That follows full-baseline completion and mandatory original-corpus/every-ACK recovery; no logging, source, resource budget, rate, timeout, cap or assertion was changed on the running baseline. No bottleneck fix or matched speedup is claimed. Analysis: SHA-256: The analysis, exact analyzer and three captured log prefixes were copied and independently reread on a different local filesystem at The full 108-window / 114,960-arrival plan, concurrent faults, every-ACK recovery, newer Cellule release/RustFS qualification, higher admission profiles, matched comparisons, large non-sparse transfers and isolated Linux capacity remain open. |
Repository creation windows and terminal evidence gateThe full baseline remains active and unchanged. 22 windows are now sealed, audited and copied: all eighteen metadata windows and the first four creation windows. Results below are creation-only observations on the shared Mac/Colima RustFS diagnostic, not isolated capacity or matched improvement.
Each window retained its declared 120-second schedule, 30-second HTTP timeout and unchanged runtime/node budgets. Busy drops remain failed arrivals with no fabricated latency; completed-attempt percentiles include HTTP errors. Drain completions count toward ACKs, not in-window RPS. The stock closed-ledger validator reconciled all 754 positive creation ACKs across these four windows: canonical UUIDs, exact run/sequence-derived names, global uniqueness and no collisions with the original 10,000 identities or the nineteen critical workflows' 38 UUIDs. All copied finalized report/sample/resource files were independently reread. This is ACK-input integrity, not remote verification after owner loss. HTTP failures are not asserted to mean rollback or absence of persisted state. The new read-only terminal evidence helper is live at PID 96486, waiting for the existing supervisor, matrix, critical child and copy watcher to be absent with complete terminal receipts. Its four pure tests (18 cases including subtests) passed, and it correctly refused terminal admission against the actual live campaign. It makes no provider requests and sends no server signals. Only after all 108 windows close will it run the independent full-ledger/resource audit, reconcile the complete creation/write/critical ACK inventory and preserve finalized inputs. Incomplete or changed ledgers refuse admission; failed performance does not excuse missing correctness recovery. Helper qualification receipt: All four fresh Linux PR/push Rust and harness CI jobs at 085a278 passed; the PR description now reflects that. The full campaign, original-corpus and every-ACK recovery after owner loss, concurrent faults, independent qualification of newer Cellule, higher admission profiles, matched comparisons, large non-sparse transfers and isolated Linux capacity remain open. No rate, cap, timeout or correctness assertion was relaxed. |
Creation and HTTP discovery phases closed; targeted observer preparedThe unchanged full campaign remains live. Its six creation windows and eight HTTP Git-v2 capability/discovery windows are now completely sealed, independently ledger-audited and copied. Stock-Git
All 1,464 positive creation ACKs were reconciled across the complete six-window ledgers: exact run/sequence names, canonical globally distinct UUIDs and no collisions with the original 10,000 identities, original critical-2 fixtures or nineteen concurrent workflows' 38 UUIDs. All 24 finalized creation report/sample/resource copy files were reread. This is input integrity, not post-owner-loss remote verification. Failed HTTP writes are not assumed to have rolled back. Fast refusals are not a latency improvement. In the first 100-RPS uniform discovery window, all-completed p50 was 7.824 ms, while successful-only p50/p95/p99 was 1,406.853 / 4,472.563 / 6,349.508 ms. That window had 1,343 OK, 8,857 HTTP 503s and 1,800 busy drops out of 12,000 arrivals; delivered success throughput was 10.992/s. Failed attempts remain in the primary completed-attempt timing population, with successful-only timing shown separately. Busy arrivals have no fabricated latency. The first discovery window's HTTP 503s have no corresponding routing-error logs. The transfer-admission path can refuse without such a log, so the current logs do not prove an inner SQL/storage cause. A later separately bound read-only observer now classifies exact known 503 responses into transfer admission, node readiness, repository availability, Cell availability and changing-ref snapshots; unknown bodies retain only byte count and SHA-256. It records canonical request UUIDs and static route categories, never paths, credentials, response text or exception messages. Writes/unsupported routes refuse before the client runs; it performs no retries and preserves original client outcomes. The diagnostic observer passed seven synthetic safety/privacy/classification tests. A regression then exposed its initial 10,000-record limit as insufficient for the full 100-RPS × 120-second = 12,000-arrival declared window. The separately bound full-window adapter now passes all eight tests with every sequence retained; the workload was not shortened. The failing pre-fix source/output and passing source/output were preserved and reread on a different local filesystem. This changes diagnostic collection only—not any server, benchmark admission limit or runtime budget—and it has not been installed in the running baseline.
All 638 immutable launch bindings remain unchanged. The terminal evidence auditor remains live and read-only. Full 108-window completion/audit, original-corpus/every-ACK recovery, concurrent faults, newer Cellule release/RustFS qualification, higher admission profiles, matched improvements, large non-sparse transfers and isolated Linux capacity remain open. No bottleneck fix or capacity pass is claimed. |
|
Progress after the 40-window documentation snapshot: the clone and cold-fetch phases are now closed, audited and retained (56 completed windows through these phases; the full 108-window campaign continues unchanged).
All 64 finalized source/copy file pairs from these two phases were independently reread. Both phases vary rate (1 or 4/s) independently of concurrency (1 or 16), with two repetitions each. At concurrency 16 / 4/s, clone returned 239/240 and 240/240 OK, delivering 3.850 and 3.950 successful operations/s; cold fetch returned 240/240 in both repetitions, delivering 3.950 and 3.917/s. Busy arrivals remain failed, and successful drain completions do not count toward in-window RPS. Cold fetch means a fresh empty bare client, not a proven cold server cache. Clone checks the expected tip and README digest; full fsck remains part of separate original-corpus/recovery verification. No matched speedup or reference capacity is claimed. The isolated latest-Cellule candidate (63c93b0, Cellule 191409685b001a82bd02780def45102b4fc2f164) was pushed to codex/cellule-main-1914096 and is running standard Linux CI: https://github.com/crabbuild/canopy/actions/runs/36965371936 . Its Python harness passed; Rust testing is in progress. Only five manifest pins and six lockfile source entries differ from its base, and 262 non-pin source files match the frozen qualified source. A six-file CI/source observation has a verified cross-filesystem copy (manifest SHA-256 182c3ce2e01874bfd5e03b504da62faac90c3f2c09fb1553ff1f73356f149675). This is debug CI, not native/release qualification or performance proof. The PR and live benchmark still use the independently qualified 0dc04a6 revision. A separate read-only recovery preflight now guards complete terminal evidence and reconciles every future creation/Git/LFS/critical ACK inventory against its closed ledgers. A missing-owned-handle regression failed before the guard correction; all ten pure guard/identity tests now pass, and the actual live-campaign inspection correctly refuses readiness. Existing closed creation/critical ledgers reconcile 11,504 distinct UUIDs and names (10,000 originals + two original critical fixtures + 1,464 positive creation ACKs + 38 current critical UUIDs). No owner was stopped and no provider request was sent. The full post-terminal path and remote every-ACK recovery remain unverified. Failed and passing preflight evidence is retained outside the repository; verified manifests are d119704bffc96c0168a8c11bc71ae489403f6befc1f146038cbd6765271678f5 and 77abcc0216593448752be30987af9feeca58b0ecc17d88bf0e76324f5abe753a. All 638 frozen live input bindings remain unchanged. Incremental fetch is now running; push/pull/LFS phases, complete terminal audit, original-corpus/every-ACK recovery, concurrent fault coverage, higher caps, matched comparisons, large transfers and isolated Linux reference capacity remain open. |
|
Latest Cellule candidate Linux CI is now closed and passed: https://github.com/crabbuild/canopy/actions/runs/36965371936 . Exact head 63c93b0 pins Cellule 191409685b001a82bd02780def45102b4fc2f164. Log reconciliation confirms 244 top-level Rust tests passed, zero failed, nine ignored; two nested child results are not double-counted. All 84 Python harness tests and all eight exact fresh RustFS compatibility gates passed, as did formatting, all-target Clippy and the debug server build. Native/release qualification, retained-store upgrade/recovery and performance do not follow from these debug CI results. The live fleet and PR pin remain on the separately qualified 0dc04a6 revision. Both PR and push CI at documentation-only head ec81650 also passed all four Rust/harness jobs, including RustFS compatibility. The PR description now records those closed scopes. Closed candidate CI/source/log evidence has nine copied and independently reread files; manifest SHA-256 880d2100bf28801b80aeaa0cd6b38bfd50abe0b263b19189b273cf03531de1c1. The independent log-accounting copy has manifest 7683fcea17f284d593cbfdea6f5975aa5e5a51c653e151c16b41a832e0f475f1. These are local cross-filesystem evidence copies, not off-machine/provider-data backups. The original full campaign has now closed 64 windows and moved to incremental pull. The eight incremental-fetch windows finished at 771 OK / 1,200 scheduled, 418 busy drops and 11 Git errors; all 32 finalized source/copy file pairs were reread. At concurrency 16 / 4/s, the first repetition returned 211/240 OK (18 busy, 11 Git errors), delivering 3.333 successful operations/s with completed-attempt p95/p99 7,245.835/8,568.187 ms; the second returned 240/240 OK, delivering 3.883/s with p95/p99 3,847.302/4,845.643 ms. Variability and failed arrivals remain recorded, with no matched speedup claimed. A separate complete-recovery verifier is prepared outside the repository. It gates on the full terminal audit/ACK inventory, the exact three old owners being absent for at least 32 recorded monotonic seconds, unchanged provider/deployment/budgets, distinct new owners, the same executable and fresh local-state provenance. It invokes full original 10K/100 content checks plus every creation, ref/fresh-object Git push, LFS and complete critical-workflow ACK verifier, retaining a request ledger. Eleven pure guard/accounting tests passed; ledger reconciliation also matched the actual earlier complete pre-load record (10,002 identities, 100 full LFS downloads, 824 Git commands). The real live-campaign invocation refused before reading nonexistent owner/fresh-launch inputs or creating any verifier output. No owner signal or provider request was sent. The real post-terminal/fresh-fleet path and every-ACK remote recovery have not run; this is preparation, not a correctness pass. Its four-file verified qualification copy has manifest febe3e79bc3a3be77274084b79b0d0dd5bce07224ecc6abea13a2e7092eca231. The existing large-transfer workflow requires a dedicated self-hosted Linux runner. The repository runner inventory currently returns zero registered runners, so no unserviceable job was queued. Full schedule/audit and owner-loss recovery continue to be required before reference capacity or any improvement claim; all 638 frozen live input bindings remain unchanged. |
|
Closed verification update (no changes to the live benchmark):
Immutable receipts: release artifact audit |
|
New negative correctness evidence and closed push accounting:
Immutable receipts: CI contradiction audit |
|
Updated this PR to The unchanged-source release diagnostic passed 100 isolated runs and both full-target runs (104 passed, zero failed, nine ignored each). The GitHub archive, all 264 source inputs, retained ELF and every result/log binding were independently verified; 115 evidence files were copied and reread. This does not clear the original release failure, establish a fix, or qualify recovery/performance. The update is documentation-only. No production code, assertions, dependencies, workflows, workload budgets or provider state changed. Fresh PR-head CI is separate. |
|
The complete unchanged baseline is now closed and independently audited: 108 windows / 114,960 arrivals / 59,554 OK / 55,406 failed arrivals. Every positive ACK is preserved: 1,464 creations, 1,490 Git writes, 242 LFS uploads and 19 critical workflows. This is not a performance or capacity pass. After the closed-evidence preflight passed, only the exact three owned gateways were removed. 32.008191 seconds of confirmed owner absence was recorded, with RustFS unchanged. A first fresh-start observer race was preserved and all its nodes drained normally; a separately qualified, bounded same-child metrics wait allowed a new attempt to reach readiness. Full original-corpus and every-ACK read-only verification is running; recovery is not yet proven. Fresh PR-head checks are green, but the earlier residency 503 remains unresolved. The seven-case stage-context diagnostic did not reproduce it: the target passed all seven cases. A different SSH SHA-256 bind test failed |
Summary
Correctness status: release CI at production-equivalent head
5581d5cfailedresidency::faults::disconnected_admission_finishes_release_and_allows_a_later_restorewith HTTP 503. Both debug workflows passed, but they do not clear this failure. The unchanged-source release diagnostic completed: 100/100 isolated runs and 2/2 full-target runs passed. Its archive, 264 source inputs, retained executable and all 102 result/log bindings were independently audited and copied to a second local filesystem. This is nonreproduction, not a fix. No root cause or resolution is claimed. Fresh CI for the documentation-only update is separate.Follow-up to merged #17. This PR contains bounded authentication, cold-residency admission, retained-catalog startup fixes, the latest Cellule pin and three-node verification tools, with qualification status separated below. An owned old-binary RustFS upgrade and twenty scheduled critical workflows passed complete fresh-owner recovery. The affected CI test's HTTP port reservation gap is now reproduced and corrected, with separately bound release/RustFS checks. The original 10,003-Cell corpus also completed supported same-code maintenance recovery: all 301 unsettled Cells drained, all published roots and catalog identities unchanged; it subsequently passed full new-release admission and controlled activation to Ready revision 9 without changing any canonical Control or published root. Three upgraded gateways passed full remote verification: all 10,000 original identities, 100 full LFS bodies, 200 stock-Git v0/v2 clones and both critical fixtures. An independent offline audit passed, and 7,061 closed files were copied and reread. The unchanged full load campaign is running: its first ten metadata windows recorded 23,779/24,000 OK, 206 busy drops and 15 HTTP 503s; concurrent critical load closed at 19/20 OK with one busy drop. These are failed arrival gates, not capacity passes. The original 10,000-repository campaign and reference capacity remain open. Both Linux PR and push CI at documentation head
2c897c7eae1afa36049685dd35f2214082e03e23passed formatting, lints, tests, real RustFS Git compatibility, the server build and the Python harness. All four fresh CI jobs at documentation head085a278passed; those historical documentation updates changed no production, test, script, Cargo or live benchmark-plan inputs.mainat publication. Its Linux debug CI and independently audited Linux release correctness run passed; latest-head debug CI passed, but release CI failed the disconnected-admission test described above. The original-corpus campaign remains frozen on the separately qualified0dc04a6executable, so its recovery/performance evidence does not transfer to this pin. Only five manifest pins and six lockfile source revisions change; other dependency versions and runtime budgets are unchanged.Historical verification of the frozen 0dc04a6 build
At the previous PR head
ec81650, all 264 production, test, script and Cargo files matched frozen tested source3dda2b47b1cba105642a62b4ad27d7c84d0940d5. The current PR changes only two of those files: the Cellule manifest pins and lockfile sources. The results in this historical section remain bound to the frozen source, not to the current dependency pin. The executable and workspace test artifacts are retained outside Cargo targets. Publication checks verify source equivalence, all eight listener-checkpoint artifact digests, formatting, diff cleanliness, documentation links and the same-source Python harness. The earlier measured build remains bound tobbd784a40c3867646044a8c716b7ee517f9aca49; its performance results do not transfer to the new executable.a61ef0f2cb977348e4e4fc45330334a1f8fd68bf8c44146cd9343b0e6676a6c8bbd784a4, 20 cold-activation repetitions, 20 three-case retained-startup repetitions and all 15 residency tests passed; those historical artifacts are separately retained240203a7, one Rust job failedAddrInUseand the parallel job passed. Both later Rust jobs and both harness jobs at0498e22passed before the correction. The original failure is retained. Fresh Linux PR CI ateaebfc4passed both Rust and harness jobs, including real RustFS compatibility; the separate push workflow also passed both jobsThe native retained-catalog regression uses an owned in-memory store written by the current test runtime; the eight provider compatibility gates use a disposable fresh fixture. The separate actual-old-binary run below is an upgrade/recovery proof, not a non-sparse five-GiB test. The existing 10,000-repository provider was unchanged before and after qualification; neither its corpus nor the UI preview was upgraded during that qualification. The subsequent original-corpus activation is reported separately below.
The listener reservation regression failed with
AddrInUsein all three pre-fix runs. An injected competing binder reproduces the helper's gap; the exact competing binder in the original CI job was not captured. The corrected tests keep the listener bound into supervised startup and verify advertised clone URLs, refusal before writes, rebind after shutdown and cleanup after cancelled startup. Other tests still use the legacy address helper; this does not claim every test-suite port race is eliminated.Actual old-binary upgrade and scheduled critical workflows
The initial remote LFS byte mismatch was missing clone-side LFS filter setup, proven by a failing stock-Git regression and corrected without weakening the full-byte check. The earlier reserved-ref rejection remains a negative result, with its partial main/tag ACKs preserved.
Original full-corpus maintenance recovery
See the original corpus recovery checkpoint for the sequence, counts, CLI boundaries and artifact digests.
Original full-corpus release activation
a61ef0f2cb977348e4e4fc45330334a1f8fd68bf8c44146cd9343b0e6676a6c8and 100 active repositories per node. Readiness is not full remote-content or performance proof.See the activation checkpoint for the sequence, write boundary, counts and immutable artifact bindings. This activation and the live load use Cellule 0dc04a6. The PR now pins
1914096, with separate CI below. These activation and performance results do not transfer to that revision.Original-corpus remote verification and current load snapshot
Remote verification closed October 2 at 03:02:09 UTC, independently audited at 03:02:40 UTC. The four completed phases / 40-window snapshot was checked at 04:33 UTC (October 1 Pacific). Later clone windows are excluded from this completed-phase summary. Full load remains running on the qualified
0dc04a6executable; no rate, cap, timeout or assertion was relaxed. Completed-attempt percentiles include HTTP errors; busy drops have no completed-request latency. Delivered RPS excludes successful requests finishing during drain. Direct full LFS object downloads are verified, not clone-side hydration of uncommitted LFS pointer files.Verification receipt SHA-256:
1447486483a253c3fad18000a73eaa449dbaa26a1223903c074497d2b431bd4a; independent audit:2b1a256a40cec3bcf24359a21559da8b35927d697ec0e25ba5a42982cdb030d0; verified backup manifest:783902ec100a41e7882c73478a98b912b06b6ec0293907146a60a7dd7d8b8078.The updated full-corpus checkpoint contains the completed-phase outcome table, six creation throughput/latency windows, stock-Git ref-listing results, the historical ten-window metadata table, closed critical artifact bindings and remaining gates. The first two windows' service tails dominate dispatch delay, and proxy connection counts were balanced; these observations do not prove a Directory or RustFS bottleneck. No performance fix or matched speedup is claimed.
Open correctness and performance gates
The target remains 10,000 identities / 100 populated Git-LFS fixtures / three nodes and a proxy / 108 windows / 114,960 arrivals / 8,640 scheduled seconds. No matched speedup or isolated Linux reference capacity is claimed.
eaebfc4both passed. Both Rust jobs and both Python harness jobs at4ddc742passed. All four Rust/harness jobs at2c897c7passed. All four fresh Rust/harness jobs at documentation-only head085a278also passed, including Linux PR and push RustFS compatibility. Production, test, script, Cargo and live benchmark inputs are unchanged. The affected SHA-256 gap is reproduced and corrected, but a later passing job does not erase the original failure.1914096PR pin. Its pin-only candidate passed Linux debug CI: 244 top-level Rust tests (nine ignored), 84 Python tests, all eight fresh RustFS compatibility gates, formatting, all-target lints and the debug server build. The Linux release candidate passed 244 top-level Rust tests (nine ignored), 84 Python tests, all eight fresh RustFS gates, release lints and the executable build. Its retained archive, source hashes, metadata and binary checksum were independently verified and copied to a second local filesystem. Latest-head debug CI passed, but release CI failed the disconnected-admission test described above. Native qualification, retained-store recovery and matched performance remain open. Do not relabel the tested0dc04a6results.Historical failed performance and missing raw ledgers remain documented. New tests cannot certify missing historical full-corpus/every-ACK recovery. Retention and read-only catalog admission are not an upgrade controller.
See the listener handoff verification, actual old-binary upgrade and recovery checkpoint, latest Cellule checkpoint, retained-catalog checkpoint and full performance plan.
Latest PR update
Head
5581d5cbrings the latest Cellule pin and the release-correctness workflow into this PR, without changing the running campaign's checkout, workload, binary or provider.191409685b001a82bd02780def45102b4fc2f164; all six lockfile packages resolve to it. Only five direct pins and six lockfile sources change; no other dependency versions or runtime budgets change.5ff3a4daf2c2012357b4643b896e4f89b8402f7cad9c29679ea20c12becc880d. All 267 bound source/workflow files match the tested commit; the current PR has identical production, test, script and Cargo inputs. The archive digest was verified against GitHub, and 17 files were copied and independently reread on another local filesystem. The first setup failure remains retained; native/recovery/performance proof is not inferred.0dc04a6release, activation and benchmark evidence. Historical failed arrivals remain unchanged.Remaining gates: native latest-pin verification, retained-store/every-ACK recovery, the complete performance campaign, matched comparisons, non-sparse five-GiB transfers and isolated Linux reference capacity are not yet closed.
Documentation evidence refresh
Head
0ba7775updates the three qualification/performance documents with the closed release-candidate results, the retained PR-head failure and the audited diagnostic. Production, tests, Cargo, scripts and workflows are unchanged from5581d5c; the diagnostic-only workflow is not added to this PR.ccd848c30d08b75e0958ff3b973e9416df027d1ebb81cd2fa685eca7f6ce018f. All 115 evidence files were copied and independently reread on a second local filesystem, not an off-machine backup.Complete baseline campaign and owner-loss verification
The unchanged 108-window / 114,960-arrival / 8,640-scheduled-second baseline has closed on the separately qualified
0dc04a6binary and original RustFS provider. Every report, arrival ledger and resource boundary was independently audited. It recorded 59,554 OK / 55,406 failed arrivals; this is a failed arrival gate, not capacity or a matched speedup. The separately scheduled critical work remains 19/20 OK.Full campaign audit SHA-256:
23836f6a437826a58e5157b534a17346b939e9c4e7213168b1c872c19f387f59; complete ACK inventory:9853c5f32551980165d62e06281e163a26d435fde070984883fe8c388758a0de; owner-loss receipt:40cb5aa9068b8f32cffb51433682af6c8fa4ce36b4a2a856543c753018f0addb.Fresh PR checks at
0ba7775passed, including release correctness; the exact release attempt was preserved. This does not erase the earlier disconnected-admission 503. The separate stage-context diagnostic preserved all seven declared cases: the disconnected-admission test passed in all seven; one serial full-target case instead failedssh::sha256_ssh_push_and_clonewithAddrInUse(OS error 98). Its independent audit SHA-256 isba4d93864f31e4e507c8b04130e460cfa0c88df3c30907eefdd98b5364ffad75. This is a distinct unresolved bind failure, not reproduction or resolution of the residency 503. Diagnostic test context remains outside this PR.The current
1914096pin is not the baseline runtime. Its native retained-store recovery, matched performance, concurrent faults, higher admission profiles, non-sparse five-GiB transfers and isolated Linux capacity remain open. Failed arrivals, failed startup attempts and CI failures remain retained.