Phase 12 remains incomplete until its operational prerequisites and review boundaries are closed with the exact evidence required by their existing authorities.
| Item | Current boundary | Future owner / closure requirement |
|---|---|---|
| PR-296 app-subject projection | PR-300 adds the Java signed-artifact declaration exporter, separately attested complete tool archive, protected cohort producer and authenticated v2 matrix admission. First-party inventory and external submission bindings are recomputed; selected federation projection remains unsupported. Original broad v1 summaries remain insufficient. No protected projection has been executed for this change. | Provision and approve the exact first-party/external cohort and original artifact authorities; execute and verify the producer. PR-303 must verify the exact matrix and original attestation, including explicit experimental Mail scope. |
| PR-297 migration producer | PR-300 adds the fixed converter/installed Site Publisher observer, dedicated protected producer and authenticated v2 consumer. A separate root-sealed operator-private source API is implemented; no operator source or live migration was executed. Synthetic execution, authorized private observation, independent real-user confirmation and CHK publication remain separate. | Complete missing browser literal-preview, bundle-rollback and cleanup adapters, then observe every required case on approved disposable resources. Root-sealed private-source selection and publication each require explicit authority; no such authority or observation was supplied. |
| Exact-source CI | PR-299's inspected CI-safe redaction failure was privately reproduced on its exact tree: 15 source-expression findings in packaged SDK copies. The merged SDK fix passes the same pipeline and its regression test. On the merged commit cde5319829274b7df6517e37ab73ce72f8f71a18, Java CI 34446210986 and CodeQL 34446209123 succeeded. Supply-chain 34446209720 was rejected before jobs: its run-page annotation identifies an expression exceeding 21,000 characters at workflow line 2362. PR-301 extracts that Python body into a checked-in helper; local validation is not a successful hosted rerun. A separate SonarCloud check reports 79.2% new-code coverage and failing reliability/security ratings. Local PR-301 changes have no published-head checks. | Retain all existing checks; diagnose supply-chain from actual available details and verify CI on the exact subsequently authorized published head. Earlier local, predecessor and merge-commit results cannot substitute. |
| Profile runtime interoperability | PR-300 locally executed 76 synthetic JS cases using immutable predecessor/current sources, including generated Feed documents in both directions. This is a source comparison with local DOM/data ports. Original historical binaries, historical signed producers, the missing production JS Trust reader, current Java-to-JS generated documents and an independent external implementation remain distinct gaps. | Execute supported directions using the authenticated selected implementations and record unsupported directions without treating them as signature failures. PR-303 verifies exact code/runtime/corpus identity and required coverage. |
| Profile redesign | Trust typed normalization and repeated-issuer weighting; Social own-app admission; unsigned aggregate freshness/completeness | Separate versioned proposals where legitimate v1 semantics change. Preserve Feed stable status and valid signed bytes; PR-303 verifies dispositions rather than automatically promoting labels. |
| Mail prototype | PR-300 reuses the real demo through owned packaged processes, normal AppHost installation, independent stores and own-app sessions. Actual two-node delivery was not executed. HTTP sibling-origin/invalid-session and owned log checks are partial; complete origin and audit/support/queue canary coverage and independent security review remain open. | Observe the full exact-target matrix on an approved topology. Preserve finite account/inbox/outbox/replay limits, original sealed retry identity and authenticated vault storage. See Mail design. |
| Mail lifecycle | Restore remains paused for sending and receiving; retained authenticated messages remain readable, and missing keys remain unavailable. PR-301 adds an explicit same-key contact renewal slice; recipient/storage key rotation, signing-account replacement and recovery-resume remain unimplemented. Contact renewal does not renew or regrant key material. | PR-301 owns reviewed account/key expiry, renewal, rotation and recovery-resume design/drills. Neither bundle rollback nor daemon downgrade can bypass revocations or writer authentication. |
| Remaining runtime implementation | Catalog registration/signature cases are a finite subset. Source-switch consent remains unobserved: staged installs have no catalog origin, and the runner lacks the federation-scoped installation/update prerequisites, so it does not attempt the alternate update. Complete channel/mirror-fallback/update-consent/conflict/rollback coverage and the full budget/resource baseline matrix remain open. Mail restore/unsafe-daemon-downgrade drills, full origin/process-token denial and complete canary surfaces are not implemented or observed as a complete cohort. | Finish the missing actual adapters without relaxing quotas, sandboxing, authenticated storage or exact subject policy. Explicit missing cases continue to block readiness and operational closeout. |
| Cross-version long run | PR-300 supplies an owned local packaged runner, measured journal/verifier and tokenless persistent service. No live topology was authorized or executed: observed live coverage is zero. The fixed protected authorize/start/checkpoint/finish workflow and root activation admission are implemented but unexecuted. Several full workload/recovery scenarios and release-consumer projections remain implementation gaps. Existing RC app-product freeze does not by itself freeze a portable daemon package. | Complete the required adapters and exact product/freeze binding, then run the approved 72-hour profile with original runner/checkpoint authority. PR-303 separately verifies duration, scenarios, safe recovery/cleanup, maintenance, transparency and release-consumer requirements. |
No local receipt, checked-in placeholder, fixture, source-presence check or reupload closes a protected producer or independent runtime requirement. Frozen RC/GA history stays immutable.
The maintenance operations drill records the exact starting commit/tree, reusable authorities, executable isolated cases and a per-boundary residual matrix. Its local summary is not original protected runtime evidence. The prospective maintenance portable admission path does not repair historical RC freezes or close the app-bearing maintenance roster and complete measured-consumer gaps. New protected report v2 derives maintenance measurements from the original journal/product bindings, but every maintenance row retains its concrete adapter blockers and no protected finish has been observed. Full catalog-origin, scheduler pressure, migration browser/rollback, historical binary, Mail recovery/rotation and privacy canary directions above remain open.
Experimental Mail contact renewal uses explicit current-worker preparation/confirmation and current vault/CAS authority; it does not establish a host minimum-reader lifecycle barrier or safe recovery resume. Independent security review and actual two-node delivery remain unobserved.
The public ecosystem transparency site presents selected public evidence through separate provenance, signature/semantic, disclosure, rehearsal, publication, activation and freshness dimensions. Empty production snapshots do not invent releases. The reviewed repository-status projection is a repository statement; a local drill remains partial and blocked on original protected authority even if every implemented synthetic case passes.
Static rendering, local verification, browser conformance and a prepared Pages workflow do not establish production publication, external security review, independent binary reproduction or public byte observation. Source-owned safe exports rerun the existing release, maintenance and advisory verifiers without copying their internal receipts; eligible original public input and offline original-proof coverage remain separate prerequisites. Host configuration, approval and actual deployment/observation remain unperformed. PR-303 owns Phase 12 closeout and must retain every unresolved item above; site readiness does not waive those requirements.