Repair campaign recovery and native client progress across platforms - #23
Draft
oliverdougherC wants to merge 20 commits into
Draft
oliverdougherC wants to merge 20 commits into
oliverdougherC wants to merge 20 commits into
Conversation
added 20 commits
September 24, 2026 01:23
The quick clip can be acquired and resumed independently with exact hash and license verification. A staged flat asset inventory keeps the full-pack fallback explicit until the per-clip files are published. Constraint: Protocol 7.1 and frozen canonical bytes cannot change Constraint: Per-clip assets remain unpublished pending the release gate Confidence: high Scope-risk: moderate Directive: Publish and rehash every flat asset before setting published=true Tested: 14 acquisition tests; 40 frozen-suite/cancellation checks; suite drift check Not-tested: Public hosted URLs and native packaged first-launch acquisition
Bound create, authorization and upload phases, and let Stop return promptly while the durable spool keeps the same local hash for ambiguous outcomes. Public errors carry safe status and Retry-After information without tokens. Constraint: Requests transport and protocol 7.1 remain in place Rejected: Global socket monkey-patching | process-wide side effects Confidence: medium Scope-risk: moderate Directive: A cancelled daemon socket may linger until its phase timeout; do not claim strict no-orphan acceptance Tested: 22 independent transport-focused tests; 11 artifact cancellation cases Not-tested: Physical Windows Stop/Close during a stalled upload
Durable journals can rebuild complete unsubmitted groups, while unfinished groups remain unfinished. A host phase lock excludes measurement and upload across queue directories. The terminal menu and Windows GUI expose saved work, safe publication, due retries and truthful pending outcomes. Constraint: Preserve frozen protocol 7.1 recipes, attempts and receipt IDs Constraint: Explicit local-only choice and publication consent remain authoritative Confidence: medium Scope-risk: broad Directive: Legacy journals without clientVersion cannot prove upgrade-stable reconstruction; keep that limitation visible Directive: A storage-limited Publish pass may return deferred with unadmitted envelopes; do not label it published Tested: 547 full client tests with frozen canonical media; 145 focused recovery/GUI/transport checks; 43 publication/durability checks after final truthfulness fix Not-tested: Native packaged Windows/macOS/Linux G01 failure-path acceptance or multi-user host locking
One manifest gate now checks all four native asset hashes, wrapper receipts, source revision, client/protocol/suite identity and runtime fingerprints. The contribution page places platform eligibility before download and points Windows CLI users to the verified current console asset. Constraint: Current rc.5 packages remain published until a new validated candidate exists Confidence: high Scope-risk: narrow Directive: Run the assembler on actual downloaded native assets before promotion; it is not a substitute for G01 Tested: 11 manifest/release tests; 78 frontend tests; ESLint and TypeScript checks Not-tested: Final candidate native builds, public download byte matches and ordinary-user launch flows
…ears The reviewed BtbN release tag now returns 404 before client tests or native builds start. Existing public candidate archives embed the exact locked Linux and Windows FFmpeg/FFprobe bytes, so CI extracts only those binaries after verifying archive and runtime-lock hashes. Runtime identity is unchanged. Constraint: The checked-in FFmpeg runtime lock and protocol identity cannot change Rejected: Runner FFmpeg packages | required xpsnr/libvmaf capabilities vary Confidence: high Scope-risk: moderate Directive: Do not replace the locked binaries without native model execution and a new reviewed lock Tested: Local extraction and SHA-256 match for Linux/Windows; anonymous archive HEAD 200; 9 tests; workflow YAML parse Not-tested: Rerun of all GitHub Actions native jobs and physical packaged-client acceptance
The guided Windows client moved retry and batch controls into Advanced settings, leaving the mode selector in a three-child row. The native harness still required seven children and blocked before it could exercise the packaged GUI. Match the observed three-child mode row with a short label followed by a wider combobox, while retaining owned-window, popup-alignment and unique-row guards. Constraint: Tk controls have no accessible names in the hosted Windows UIA tree. Rejected: Hard-coded screen coordinates | cannot establish owned control identity across layouts. Confidence: medium Scope-risk: narrow Directive: Recheck native Win32 control evidence whenever the guided configuration row changes. Tested: Captured CI Windows screenshot and Win32 tree match the new structural predicate; git diff --check. Not-tested: Packaged Windows GUI rerun pending CI.
The native selector now recognizes the current three-control guided row, but its pure operator fixtures still supplied the removed retry and batch controls. Refresh the hosted geometry and negative cases so the guard tests exercise the same structural contract before a native build. Constraint: PowerShell is unavailable on the local macOS host; Windows CI executes the guard suite. Confidence: medium Scope-risk: narrow Tested: Reviewed captured Win32 bounds against fixture; git diff --check. Not-tested: Windows harness guard rerun pending CI.
The packaged GUI now shows a transfer and storage estimate before source preparation. The Windows harness clicked Start but never answered that dialog, so it timed out waiting for the preparation probe. Verify the owned native dialog, visible cost disclosure and exact Yes/No controls before a bounded Yes click; preserve a path for runs with no transfer prompt. Add operator fixtures for accepted and rejected dialog identities. Constraint: Native Windows UIA exposes the message box as #32770 with direct Button and Static children. Rejected: Suppress the estimate prompt in test mode | would skip the contributor decision being certified. Confidence: medium Scope-risk: narrow Directive: Keep consent prompt automation tied to captured native title, text and control IDs. Tested: Captured Windows screenshot, UIA and Win32 evidence matched the guarded predicate; git diff --check. Not-tested: Native GUI rerun pending Windows CI.
The native Windows GUI showed the cost dialog, but Tk exposed Stop as Win32-enabled even while its visual state was disabled. The harness treated that flag as proof Start had advanced and never answered the prompt. Prefer the exact owned dialog; only a source preparation probe or owned encode can establish that no prompt was needed. Constraint: ttk widget state does not reliably map to IsWindowEnabled on hosted Windows. Rejected: Treat the Stop handle as readiness | the captured modal case disproves that signal. Confidence: medium Scope-risk: narrow Tested: Captured failing receipt showed download-estimate-not-shown with the dialog visible; git diff --check. Not-tested: Native rerun pending Windows CI.
Record the original package identities, retained campaign state, backend reconciliation and uncertainty. Add an independent conservation oracle with seeded transitions to test durable state projections. Confidence: high Scope-risk: narrow Tested: 4 oracle tests and read-only original campaign audits Not-tested: Original Windows and Linux campaigns have no completed Medium group to recover
Bound runtime preparation and publication I/O, retain worker ownership through shutdown, project saved campaign state from durable evidence, interleave upload staging with replay, persist consented continuation, and drive Windows progress from real producer events. Preserve original client provenance during saved-work publication. Constraint: Frozen protocol and suite identities must remain intact Rejected: Re-encode completed measurements for delivery | changes evidence and identity Confidence: medium Scope-risk: broad Tested: Full client run 616 passed, 1 skipped, 1 stale version assertion failed; focused 46 passed after fixing that assertion Not-tested: Native four-package Medium and fault acceptance remains pending
Assign client 0.3.4 and rc.6 to the repaired source, require four native receipts from one clean revision with explicit build and publication states, and make release metadata checks fail on incoherent identity. Constraint: Public downloads still refer to rc.5 until promotion Confidence: high Scope-risk: moderate Tested: 46 package/release tests, frontend lint and build, server tests, metadata preflight gate Not-tested: Four native build receipts and physical hardware acceptance pending
A global pending entry from a different campaign previously made a fully receipted selected campaign return pending. Gate selected publication status and GUI count on its own logical pending identities. Confidence: high Scope-risk: narrow Tested: Red regression then 62 passed, 1 skipped in recovery, progress and GUI suites
The first packaged macOS Medium run left a source-contract heartbeat with no stage budget. Wrap that full-decode validation in a finite named stage, and bound version, encoder, filter and optional device probes with owned cancellation. Preserve optional-device timeout as an unavailable encoder rather than changing the plan to an unverified fallback. Constraint: Frozen runtime and source checks remain mandatory Confidence: medium Scope-risk: moderate Tested: 41 focused preparation, source and encoder tests passed; native macOS trace identified the missing budget Not-tested: New package builds and full native Medium acceptance pending
The first native macOS CLI attempt treated --no-submit and --queue-dir as a direct single recipe, performed frozen media acquisition, then failed for lack of --codec. Route policy/storage flags through the guided menu and keep explicit --submit/default-recipe direct behavior. Clarify preparation timeout text. Confidence: high Scope-risk: narrow Tested: Reproduced packaged exit 4; 18 focused routing and preparation tests passed Not-tested: Rebuilt package and final Medium acceptance pending
A physical Windows 11 console run downloaded and validated the frozen media, froze its 126-group plan, then exited 1 before attempt one because CP1252 could not encode a storage-estimate glyph. Use plain wording and configure CLI output for safe escaping of arbitrary Unicode. Bump the unpublished implementation identity so earlier candidate campaigns cannot silently resume under these changed bytes. Constraint: Preserve original queue and unaltered frozen protocol evidence Confidence: high Scope-risk: moderate Tested: Physical packaged failure captured; red CP1252 regression then 51 focused tests passed Not-tested: Rebuilt native package and complete Medium outcome pending
The packaged GUI showed both bars at zero while its third encode was underway because only publication confirmation moved them. Count journaled warmups and measured attempts as they happen, preserve the Overall baseline across resumes, restart Batch for each segment, and keep upload/analysis state in separate counters. The planned maximum shrinks only when unused optional repetitions are resolved. Constraint: Frozen protocol and validity rules are unchanged Rejected: Advance bars from encode-start callbacks | would count unsaved/interrupted work Confidence: high Scope-risk: moderate Tested: Failing-before producer-to-GUI regression then 130 focused tests passed, 1 skipped; 42 release/progress tests passed after version bump Not-tested: Rebuilt physical Medium GUI run and exact-package overnight acceptance pending
A held PUT response in the physical macOS package exposed an unhandled KeyboardInterrupt in the CLI Publish path. The server had retained the bytes and the queue survived, but the client printed a traceback and exited 1. A scoped SIGINT handler now sets the same cancellation event used by owned network work, allowing that work to quiesce before the host phase ends and returning 130 with a saved-work message. Both Publish and Retry use it. Advance the unpublished candidate identity because packaged behavior changed. Constraint: Preserve saved artifact and run identities across ambiguous upload outcomes Rejected: Catch KeyboardInterrupt only at the outer CLI boundary | it would unwind the phase lock while the network worker could still be active Confidence: high Scope-risk: narrow Tested: Red-to-green CLI signal tests; 94 focused unittest checks; physical Mac held-response source test exited 130 in 1.086 seconds and replayed with one server run ID and no second PUT Not-tested: Rebuilt rc.7 native package and full CI suite are pending
The new CLI signal scope intentionally passes a cancellation event and finite deadline to spool admission. The previous exact-call assertion described the old unsafe shape and failed CI despite the actual campaign and receipt checks passing. Assert the preserved payload/budget plus the owned cancellation inputs without freezing a monotonic deadline value. Constraint: Publication admission must be cancellable under the host phase lock Confidence: high Scope-risk: narrow Tested: Corrected case and three interrupt regressions, 4 passed locally; previous CI reported 623 passed, 5 skipped, one stale assertion Not-tested: Full rerun is pending CI
The exact rc.7 Mac DMG reproduced an upload-response SIGINT gap that source execution could not: signalling its PyInstaller onefile process group left the child waiting for 60 seconds, while signalling only the child returned 130 and preserved/replayed the same upload ID. Build the console onefile assets with PyInstaller's bootloader signal forwarding disabled so the group signal already delivered to the child is not sent twice. The Windows GUI continues to use its owned Stop/Close event. Advance the unpublished package identity because the executable bytes and interrupt behavior change. Constraint: PyInstaller 6.19 documents --bootloader-ignore-signals for supervisors that signal both the bootloader and child process group Rejected: Change only the Python SIGINT handler | the exact package still hung while the corrected source exited 130 Confidence: medium Scope-risk: moderate Directive: Verify both process-group SIGINT and parent-only termination on each rebuilt console package before certifying cancellation Tested: Red-to-green build-contract regression; 95 focused tests; Mac rc.7 group/child contrast with one stable server run ID and no second PUT Not-tested: rc.8 exact-package signal and full native/CI acceptance are pending
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Integrates PR #22 as the base for September 28 reliability repairs (R01–R11), including both Windows GUI progress bars, bounded runtime preparation, owned upload cancellation, saved-work discovery/publication, durable continuation, typed errors, and a four-asset candidate manifest gate. This is an unpublished rc.6 candidate; public downloads remain rc.5.
Original incident evidence
docs/collection-readiness/reliability-20260928/ORIGINAL-INCIDENTS.md.Executed checks
Native and release gates still open
The four new assets, three independent physical Medium runs per OS, original-state zero-encode recovery, overnight observations, full fault matrix, receipt→backend reconciliation, and public independent redownload are not certified. CI native build artifacts and physical-machine acceptance must be reviewed before promotion. This PR must stay draft and must not be merged or released based only on source tests.
No production writes, release publication, service installation or retained-state deletion were performed.
Native diagnostic while validating the first package
The first rc.6 macOS DMG built from PR merge tree
62fc095launched from a read-only mount and completed cold frozen-pack acquisition. Its heartbeat exposed an unboundedsource-contractpreparation stage and separate encoder discovery probes. Commit3d7f62dadds finite stages and owned probe deadlines with focused 41-test coverage. A new exact-source four-platform build is running; the earlier package and its in-progress local-only Medium sweep are diagnostic evidence, not final certification.Superseded four-asset diagnostic receipt (PR merge tree
b7b04084f4daaebf91586ca1474029050288c5f3)The source tree equals branch commit
df9dfa1(tree73d425eca23ba8e2f388eda34fb5b7aa46929b1c). These superseded native receipts identify client0.3.4, protocol7.1, the frozen suite, and their pinned platform runtime. The checked aggregate manifest is retained locally at.test-reports/reliability-20260928/final-native/four-asset-manifest.json.28ca8d0ccf12f9af26babed5cfcd89abb0bec16f57769b45bd80217929d20634c622b7053fcfcf91faa3a9f1a6429a44210e268bf51935a578c531a33def96b5dff9241456bef9a2714fb0ac02ee4070f28518cc7baf0df9ddfb9bfa8a71696a6d2abec6775ead938a358be541def4b0643fc838077e622aa62a455ef35ebd4eThese bytes are retained diagnostic candidates. The physical Windows console Medium run exited before its first encode because CP1252 could not print a Unicode storage-estimate glyph. Commit
878eb23fixes this, adds a red-to-green regression and bumps the unpublished client identity to0.3.5. A new four-asset build is pending; no asset above is eligible for promotion. Physical Medium, recovery, fault and public redownload gates remain open. The final CI client, server, frontend, migration, stack smoke, clean-deployment, Linux build, macOS build, release preflight and dependency audit jobs have passed; Windows native GUI/console CI is still running.Superseded four-asset diagnostic candidate (
2f9bb5686b4eb5a5ecc8f2c4c07340a85545acca)Branch commit
878eb23and the CI merge revision above have the same source tree. The aggregate receipt is.test-reports/reliability-20260928/candidate-035/four-asset-manifest.jsonand reports client0.3.5, protocol7.1, frozen suite, and per-platform pinned runtime. Lifecycle remains built / native acceptance not certified / unpublished / no public redownload.750978f126a1de80d070faf0e3eac176948023089209c4bf9c61c2f738336f2d8f93f9734baa2ebe793466be09974b3fbfd578501649a15943b19874bb95913ef03d3068919ae813ffa25e0fd3cc28d8765f9dacb63776242d1dfac611ae87eb579c32e435f41c7c59e6e0c1a7e4d827516af5d229e22b26b341109836cd2cb1Local-only Medium runs from these bytes began on the physical macOS, Windows console and Linux machines. The packaged Windows GUI screenshot exposed stationary Overall and Batch bars during active encoding. Commit
7394f22makes the bars advance from durably journaled warmups and measured attempts (red-to-green producer-to-GUI regression; 130 focused tests passed, one skipped) and bumps the unpublished identity toclient/0.3.6. These hashes are diagnostic only; new exact-source native assets are building. No Medium or production acceptance is claimed yet.R01–R11 review state
0.3.5assets assembled from one clean merge tree with hash/OS/runtime/suite receipts (2d99ea4,878eb23); manifest verifier tests pass.2d8a343,3d7f62d); focused timeout tests pass; new Linux/Windows source-contract heartbeats show finite 600 s budgets.2d8a343); live-upload cancellation regressions pass.2d8a343); drip/endless/oversized/rejection regressions pass.2d8a343); worker race tests pass; physical Linux SIGINT during encode exited 130 without owned survivors.2d8a343); source and original-run conservation checks pass.2d8a343,7394f22); packaged0.3.5screenshot exposed stationary bars before the fix, and the new red-to-green integration case passes.0.3.6guided Medium GUI bar and physical end-state proof.2d8a343,714e99f); >5/old-receipt focused cases pass.2d8a343); corrupt-sibling/upgraded-runtime tests pass.2d8a343); one-artifact-headroom and reopen tests pass.2d8a343); blocked/rejected/terminal consumer tests pass.The complete
0.3.5client, server, frontend, migration, stack-smoke, clean-deployment, preflight and audit CI jobs have passed. Windows native GUI/console CI is still running. The physical Medium runs are in progress; no item above is marked Done solely from source tests.Current source revision
Branch
7394f22identifies unpublished client0.3.6. Its four native assets and CI checks are rebuilding; all hash tables above refer to preserved, superseded diagnostic builds.Current four-asset candidate (
a98af4adaa0ca32cf43f7e32eef6e4ff7b9e4b5c)Branch
7394f22and this clean PR merge build have the same source tree. The hash-checked aggregate manifest is.test-reports/reliability-20260928/candidate-036/four-asset-manifest.json. Each receipt names client0.3.6, protocol7.1, the frozen suite and its pinned platform runtime. Lifecycle is built=true, nativeAcceptance=not_certified, published=false, independentRedownloadVerified=false.20d1c7fa8738ef02d799884a4b2d4d69a71b51916257f0335587a8ecfea2518f2118a40607c647907373b2fe4828f435461564eb30a0d333f16e2e3339c9b9e05a3027d4ab726c0e522f50c30c6169f2ae54cbd36b2ee3864fabdb03aaa23c054175a262186ce729d58b3ae16dc91da9e6dba159c422be3cbf755c470cd21aa1Fresh physical local-only Medium campaigns from these exact bytes are in progress on macOS, Windows console and Linux. The actual packaged Windows GUI CI phase is in progress. The three prior diagnostic candidates and their retained interrupted state are separate from this current build.
Native Windows GUI progress evidence on
client/0.3.6CI run 36522960727 uploaded exact-package GUI screenshots. In the real windowed executable,
stop/before-click-Stop.pngshows both Overall and Batch at 2/5 while encode 3/5 is underway, withRecorded 2/5 attempts (1 warmups, 1 measured)in the status line.stop/cancelled.pngkeeps both bars at 2/5 and the stage is Cancelled.complete/locally-complete.pngshows both bars full for a completed local-only single recipe, with four measured attempts saved, zero uploaded and Stage Complete. This is direct proof that the bars advance during work and do not fill on Stop. It is not a guided Medium GUI certification; that remains open.Final CI result for
client/0.3.6Run 36522960727 completed successfully: client 621 passed / 5 skipped; server 242 passed / 0 skipped; frontend 78 passed, lint and build; migration, stack smoke, clean deployment and Mac/Linux native builds passed. Windows candidate build plus four real packaged GUI automated phases passed (
PASSED_AUTOMATED_GUI_CHECKS_VISUAL_REVIEW_PENDING), and its separate packaged seven-clip console phase passed on a virtualized software-only runner. I inspected the running, cancelled and locally completed progress screenshots for R07; full GUI visual/accessibility and physical Medium acceptance remain separate open gates.Physical Medium checkpoint evidence, exact
client/0.3.6packagesOn macOS, the first 60-minute measurement segment saved a budget marker for in-flight order 159; the same process and campaign
campaign-db3147ef35d99bacsubsequently journaled order 159 and advanced beyond 162, with no false completion envelope. On Windows 11, the 60-minute marker for campaigncampaign-c74b167a5af00b65named in-flight order 177; the same physical console run has since journaled 182 attempts. Linux checkpointed campaigncampaign-6999072148bd9679at in-flight warmup 27 after 3,605 seconds; 26 earlier warmups are durable and the process remains active. These are checkpoint/continuation observations, not complete Medium sweeps or uploaded scientific outcomes.Physical macOS interrupted journal recovery
A controlled SIGINT to the exact
client/0.3.6macOS process returned 130 with 218 durable attempts (98 warmups, 120 measured), 19 finished groups and 38 eligible measured records, yet zero pre-existing submission envelopes. The independent oracle reported zero accounting issues. From the read-only mounted DMG,--recovery-statusshowed all 98 frozen groups, 19 complete, 79 unfinished, 38 logical pending uploads, and bothpublish_saved(zero encodes) andresumeactions before runtime/source preparation. A SHA-256 snapshot of 340 attempt, artifact, manifest and budget files was taken. Packaged--resume-campaignreopened the same campaign and recorded attempt 219; all 340 snapshotted file hashes remained unchanged. This proves discoverability and no re-encoding of completed pre-interruption evidence for this boundary. Actual upload of those journal-only groups to an isolated candidate server is deferred while Linux is timing on that server host; no delivery/analysis claim is made.First complete physical Medium, macOS
client/0.3.6Campaign
campaign-db3147ef35d99baccompleted local-only after a controlled SIGINT/reopen. From initial launch 2026-09-29 04:56:28 UTC to completion marker 07:03:59 UTC, observed wall time was 2h 7m 31s, including an 80s pause; active wall time was about 2h 6m 11s. The independent oracle reports 98/98 frozen groups finished, 98 warmups, 230 measured attempts (required floor 196 plus 34 optional adaptive), 230 unstaged local envelopes, zero accounting issues, zero server receipts. Validity among 328 attempts: 316 valid and 12 suspect, no invalid. A separate byte audit verified all 98 warmup-release markers, all 230 retained measured artifacts (1,708,885,152 bytes, SHA-256 vs attempt records), and all 230 envelope hashes, sizes, campaign IDs and client identities with zero mismatches. The 340-file pre-resume hash snapshot remained unchanged after resume. A second independent warm-cache Medium run is now active.The existing
scripts/native-e2e-ledger.py capturecannot process hash-verified released warmup artifacts because it callsresolve(strict=True)on their intentionally absent paths; it failed on warmup 1. The independent conservation oracle and task-local byte audit above provide the stated checks, while that older ledger harness limitation remains open. This local-only campaign is not server-confirmed or analysis-complete.Windows physical Medium second-checkpoint salvage
Campaign
campaign-c74b167a5af00b65continued through a second 60-minute measurement checkpoint on the exact Windows console asset. At the observed checkpoint it had 375 durable attempts (126 warmups, 249 measured), all with valid client validity; independent oracle: 110/126 groups finished, 16 unfinished, 220 eligible measured records, 208 immutable local envelopes and 12 journal-only candidates, zero accounting issues. This shows completed work became locally publishable while later groups were still unfinished, without falsely marking the campaign complete. No upload/server receipt or analysis disposition is claimed. The process remains active.First complete physical Medium, Windows console
client/0.3.6Campaign
campaign-c74b167a5af00b65completed local-only after a recoverable retention-budget failure. Initial attempt: 2026-09-29 05:06:20–07:17:23 UTC, exit 6 when the saved 2,048 MiB local-only allowance filled during encode. The frozen 126-group journal then held 397 attempts, 119 finished groups, 250 eligible measured records, 208 immutable envelopes and 42 journal-only candidates, with zero oracle issues. Packaged recovery offered Publish and Resume. An explicit 4,096 MiB allowance was applied on resume 07:19:55–07:30:13 UTC; it changedbudget.jsononly, not the frozen plan. Completion: exit 0, 126/126 groups finished, 126 released warmups, 278 measured attempts (required floor 252 plus 26 adaptive), 278 local envelopes, all 404 attempts valid, zero uploads. Byte audit verified all 278 measured artifacts (2,183,473,526 bytes), envelopes and release markers with zero issues; all 1,003 snapshotted pre-resume attempt/artifact/envelope/manifest files retained identical SHA-256. Total observed wall 2h 23m 53s including 2m 31s between runs; active wall about 2h 21m 22s. A second independent warm-cache Windows Medium campaign is now running. No server/analysis acceptance is claimed.Second complete physical Medium, macOS
client/0.3.6Independent warm-cache campaign
campaign-b03a13be085a6ca9completed with exit 0, 98/98 groups finished, 98 warmups and 222 measured attempts (196 required floor plus 26 adaptive). It retained 222 local envelopes and zero server receipts. Independent conservation oracle: zero issues; byte audit matched all 98 warmup-release markers, 222 measured artifacts totaling 1,646,342,322 bytes, all 222 envelope hashes/sizes andclient/0.3.6identities, zero mismatches. Validity across 320 attempts: 312 valid and 8 suspect, no invalid. Wall from package launch 07:07:28 to completion 09:03:34 UTC: 1h 56m 6s, including one automatic 60-minute measurement checkpoint. A third independent warm-cache Mac Medium is now active; Mac native three-run acceptance is still open, and no local-only run is server-confirmed.Second complete physical Medium, Windows console
client/0.3.6Independent warm-cache campaign
campaign-000573c58e3beb83also finished local-only after recoverable 2,048 MiB retention cap, with the same exact console asset and a new queue/seed. First segment 07:33:02–09:42:14 UTC exited 6 at 395 attempts: 117/126 groups finished, 242 eligible records, 218 local envelopes and 24 journal-only candidates, zero oracle issues. Packaged recovery offered Publish/Resume. An explicit 4,096 MiB allowance resumed the same campaign 09:46:26–09:58:17 UTC; exit 0, 126/126 groups, 126 warmups, 278 measured attempts (252 required + 26 adaptive), 278 local envelopes, all 404 attempts valid. Byte audit matched all 278 artifacts (2,181,161,442 bytes), 278 envelopes and 126 warmup-release markers, zero mismatches. All 1,009 snapshotted pre-resume files retained identical SHA-256. Active wall ~2h 21m 3s, total wall ~2h 25m 14s including the pause. A third independent Windows Medium was launched with 4,096 MiB at start. Neither completed run is uploaded or analysis-complete.Third complete physical Medium and three-run Mac aggregate
Independent warm-cache campaign
campaign-e5f4a1a34ea897eecompleted from the exactclient/0.3.6DMG: exit 0, 98/98 groups, 98 warmups, 210 measured attempts (196 required + 14 adaptive), 210 local envelopes, no server receipts. Independent oracle zero issues; byte audit matched all 98 warmup-release markers and 210 measured artifacts totaling 1,526,644,590 bytes, plus 210 envelope hash/size/client/campaign identities, zero mismatches. Validity: 297 valid, 11 suspect, none invalid among 308 attempts. Wall from 2026-09-29 09:05:00 to 10:59:20 UTC: 1h 54m 21s, with one automatic measurement checkpoint.Across three distinct complete macOS Medium campaigns: 294/294 frozen groups finished; 294 warmups, 662 measured attempts and 662 local envelopes; 4,881,872,064 retained artifact bytes hash-verified; 925 valid and 31 suspect attempts, zero invalid; oracle and byte-audit issues zero. This closes a local measurement/saved-artifact three-run gate for the tested DMG on the physical M4 Pro. It does not close publication, authoritative analysis, public redownload, unattended no-contention quality, native Large/Full, or the analogous Windows/Linux gates.
Packaged read-only recovery of the owner's original macOS state
From the mounted
client/0.3.6DMG,--recovery-statusinspected the byte-preserved original Mac queue copy without runtime preparation or mutation (5,244 queue files before and after). It projected original Mediumcampaign-7e6d70761d73929eas 98/98 finished groups, 198 accepted uploads, zero logical pending and no Publish action. Its older manifest lacksclientVersion, so the new client explicitly blocks measurement Resume rather than relabeling those old attempts. Other retained Mac campaigns remained listed, including an incomplete Large campaign with already accepted work. This is read-only recovery projection, not a new server transaction or proof of old-client measurement compatibility.Third complete physical Medium and three-run Windows aggregate
Independent warm-cache campaign
campaign-887af0c757c8cc84used the exactclient/0.3.6Windows console with 4,096 MiB local retention from its start. It completed with exit0 in 8,026 seconds (2h13m46s), two automatic measurement checkpoints, 126/126 groups, 126 warmups, 284 measured attempts (252 required + 32 adaptive) and 284 local envelopes. All 410 attempts were valid. Independent oracle zero issues; byte audit verified all 126 warmup-release markers, 284 retained artifacts totaling 2,159,967,882 bytes and matching 284 envelope hashes/sizes/campaign/client identities with zero issues. No storage failure occurred in this run.Across three distinct complete Windows Medium console campaigns: 378/378 frozen groups finished; 378 warmups, 840 measured attempts and 840 local envelopes; 6,524,602,850 artifact bytes hash-verified; 1,218 valid attempts, zero suspect/invalid; oracle and byte-audit issues zero. The first two needed explicit 4,096 MiB recovery after local-only default-cap failure, with 1,003 and 1,009 pre-resume file hashes unchanged respectively. This closes a local measurement/saved-artifact three-run gate for the tested physical Ryzen/RTX 5090 console bytes. It does not close actual physical Windows GUI Medium, publication/analysis, independent public redownload, native Large/Full, or the Linux three-run gate.
Owner's original Windows Medium recovered locally with original package
Read-only
client/0.3.6recovery first projectedcampaign-c820031ccf718637as 126 planned groups, zero finished/accepted; two adjacent original Small campaigns each had 14 accepted receipt identities. The original Windows queue was freshly SHA-256 snapshotted (763 files, 1,609,025,638 bytes). Exact public rc.5 Windows console SHA-25605189da160c876f812cd16ae228b76df50bac8925d5763bb3d49ea9f0e42a60ewas downloaded and run on the original physical Windows host with the original queue/installation identity and--no-submit. First invocation with default max-attempts 100 exited4 before measurement because the saved Medium can require630; all 763 queue hashes remained unchanged. The same binary with explicit--max-attempts 630/4,096 MiB recorded attempts167–346, then exited11 at its 60-minute checkpoint. A third compatible invocation used a 240-minute measurement allowance (no recipe/repetition change) and finished the saved campaign with exit0. Recovery invocations: 2026-09-29 12:21:51–15:57:46 UTC, about 3h35m55s total wall including two short gaps and repeated rc.5 source validation.Independent final oracle: 126/126 groups, 126 warmups, 304 measured attempts (252 required + 52 adaptive), 304 local immutable envelopes, 430/430 client-valid attempts, zero accounting issues and zero upload receipts. Byte audit of the old format, which retains warmup files instead of release markers: 126 warmups (987,347,020 bytes) and 304 measured artifacts (2,306,373,664 bytes) all match saved SHA-256; every envelope matches artifact hash/size/campaign and consistently identifies
client/0.3.3, zero issues. Compared with the pre-resume inventory, 759 of 763 original files retained identical SHA-256; only the never-durable in-flight attempt167 output/environment,in-flight.jsonand the measurement lock changed. No original completed attempt or artifact changed. The original queue is now locally complete and eligible for later consented candidate-server publication. No production write or scientific acceptance is claimed. The currentclient/0.3.6correctly refuses measurement Resume of this no-clientVersion manifest and can publish intact old envelopes without relabeling once an isolated endpoint is available.After the original Windows campaign completed, the exact
client/0.3.6packaged console inspected its original queue read-only. It projectedcampaign-c820031ccf718637as 126/126 finished groups, zero accepted, 304 logical pending uploads and an actionablepublish_savedroute, while measurement Resume remained blocked for missing old manifest client identity. Both adjacent original Small campaigns still showed 14 accepted each. The original queue file count remained 2,124 before/after this status command. This proves discovery of the owner's newly finalized old envelopes without relabeling or re-encoding; actual upload/analysis awaits an isolated endpoint and explicit consent.Packaged TLS fault and near-full publication, isolated endpoints only
On the idle Mac, a task-local HTTPS fault server used a trusted test certificate and checked artifact byte size/SHA-256. A metadata-only queue copy of a real 171,544-byte macOS envelope published through the mounted
client/0.3.6DMG: one create, one authorization, one hash-matched PUT, one durable receipt/accepted marker, zero attempt/encode files, original artifact unchanged; repeat Publish returned0 with no extra create/PUT. A second real 6,823,054-byte artifact was accepted by the local server but its first PUT response deliberately dropped. Packaged Publish returned10 with a durable pending entry and no receipt; after the saved retry time, replay used the same run ID, made no second PUT, wrote one receipt/marker, returned0, and left original bytes unchanged. These server decisions are synthetic transport acknowledgments, not authoritative analysis acceptance.On the physical Windows 11 host, the same verified
client/0.3.6console used an isolated local HTTPS server and a metadata-only copy of its first complete Medium campaign. One normal--publish-savedcall, with a 64 MiB copied-queue budget versus 2,183,473,526 bytes of original artifacts, finished in 3m01s: 278 distinct run creates/authorizations/hash-matched PUTs, 278 unique server IDs, 278 durable receipts and accepted markers, zero pending entries or test attempt files, zero changed source artifact hashes. This proves repeated admission→drain→retire→restage in one call for a >2 GiB saved campaign without another click or encode. Repeating Publish took20s, returned0, and made zero additional creates/PUTs; packaged recovery showed 278 accepted / 0 pending in the copied queue. Both local servers were stopped after evidence capture. All local-server analysis responses were synthetic; no production/candidate-server corpus or scientific acceptance is inferred. Windows validation receipt and event trace are retained locally at.test-reports/reliability-20260928/candidate-036/windows-nearfull-verify.jsonandwindows-nearfull-events.jsonl.Owner Windows old-envelope publication, isolated HTTPS endpoint
The recovered original Windows Medium campaign's old
client/0.3.3envelopesubmission-000127.jsonand manifest were copied as metadata into a fresh test queue; its 8,377,414-byte artifact stayed in the original queue and was SHA-256 checked before publication. The exactclient/0.3.6Windows console package published that intact envelope to a local TLS-verified synthetic transport server with exit 0. The server trace shows one run create, one authorization and one hash-matched PUT; the copied queue has one durable receipt and accepted marker, zero pending entries and zero attempt files. Repeating the same packaged Publish exited 0 without any additional create/auth/PUT. Independent post-check matched the receipt's server ID to the upload, confirmed the original artifact hash unchanged, and confirmed the envelope still declaresclient/0.3.3. Receipt:.test-reports/reliability-20260928/candidate-036/windows-old-envelope-local-verify.json; trace:windows-old-envelope-local-events.jsonl. The task-local server was stopped. This proves a representative original old envelope can be delivered without measurement or identity relabeling through the current client; the remaining 303 original Windows Medium envelopes and all authoritative scientific analysis remain untested/unpublished.Interrupted Mac journal-only groups published without encoding
A task-local test fixture recreated the exact 218-attempt stop boundary of physical Mac
campaign-db3147ef35d99bac: 98 warmups, 120 measured attempts, 19/98 finished groups, 38 eligible measured records and zero initial envelopes. It copied the real attempt records and APFS-cloned their 120 measured artifacts (934,230,719 bytes); onlymetadata.info.artifactPathwas rewritten to the cloned owned path, so this is a transparent derived fixture rather than an untouched original queue. The independent oracle found zero issues before/after. The exact mountedclient/0.3.6DMG first projected Publish with zero encoding and 38 logical pending. One packaged Publish to a local TLS-verified synthetic server exited0 and produced 38 unique creates, authorizations, hash-matched PUTs, durable receipts and accepted markers; 318,320,370 upload bytes and zero pending entries. A repeat Publish exited0 with no additional create/auth/PUT. The fixture still had 218 attempts and zero new encode process logs. Exactly the 38 acknowledged cloned artifacts were retired; the 82 unfinished-group clones and all 120 original source artifacts retained their SHA-256 hashes. Local server stopped. Retained evidence:mac-interrupted-publish-fixture.json,mac-interrupted-publish-conservation.json,mac-interrupted-publish-verify.json, andmac-interrupted-publish-events.jsonlin the ignoredcandidate-036evidence folder. This covers one physical-origin controlled interruption and local transport only; no authoritative analysis or original queue publication is implied.Native packaged 429 oversized drip body and recovery
From the exact
client/0.3.6mounted Mac DMG, a copied immutable real 171,544-byte envelope was published to an isolated trusted-TLS server that returned HTTP 429 withRetry-After: 3, advertised a 1,000,000-byte error body and dripped 1 KiB every 50 ms. The server observed the client close after 66,560 bytes sent (approximately the 65,536-byte hard cap plus one in-flight chunk), rather than consuming the declared body. Packaged Publish exited10 with one durable due retry entry, no accepted marker/receipt and no test attempt files. After the saved retry time, a normal isolated HTTPS server accepted the same queue in one packaged Publish (exit0): one create, one authorization, one hash-matched PUT, one receipt/accepted marker, pending0. The original source artifact SHA-256 stayed unchanged and the managed spool copy was retired. Both task-local servers were stopped. Receipt:.test-reports/reliability-20260928/candidate-036/mac-error-body-recovery-verify.json; error/recovery event traces adjacent. This is one executed native 429/body-cap/offline→online path, not the complete 429/5xx/permanent/TLS fault matrix or authoritative analysis.Native packaged 503 and permanent 400 error dispositions
Two more isolated TLS Mac package tests reused a copied immutable 171,544-byte real envelope. For each, the server advertised a 1,000,000-byte error body and dripped 1 KiB/50 ms; the exact
client/0.3.6DMG closed after 66,560 bytes sent. HTTP 503 left one durable retryable queue entry, no terminal/dead-letter or false receipt. HTTP 400 returned a visible terminal action, preserved one terminal record, one dead-letter record and a hash-matched dead-letter artifact copy; replay did not send a second create and again reported the terminal state. Neither case altered the original artifact or created test attempts. Both test servers were stopped. Receipt:.test-reports/reliability-20260928/candidate-036/mac-error-503-400-verify.json; event traces adjacent. This extends native error-body/disposition coverage; DNS/TLS/write/read/stalled connection and Stop/Close permutations remain open.Native packaged TLS verification and saved-envelope recovery
A copied real Mac envelope against a task-local HTTPS server with an untrusted self-signed certificate made the exact mounted
client/0.3.6DMG exit10 with a certificate verification error before any HTTP request reached the server. The immutable envelope and original artifact remained intact; no receipt or accepted marker was invented. With the test CA explicitly added to the process trust bundle, the same saved envelope published once (one compatibility, create, authorization and hash-matched PUT), wrote one durable receipt/marker, and left zero pending/attempt entries and the original source SHA unchanged. The test server was stopped. Receipt:.test-reports/reliability-20260928/candidate-036/mac-tls-recovery-verify.json; trusted replay trace adjacent. This demonstrates TLS was enforced and normal recovery worked for one native fixture; broader TLS failure/permanent endpoint matrix remains open.Current rc.7 source correction after native held-response fault
The exact rc.6 mounted Mac DMG was SIGINT-interrupted while its first PUT response was deliberately held after the isolated server had accepted 171,544 hash-matched bytes. It exited1 with an unhandled
KeyboardInterrupttraceback in the CLI Publish path, although its queue entry/artifact stayed durable and the client process ended. A subsequent packaged Publish queried the same server run ID, made no second PUT, wrote one receipt/accepted marker and preserved the original artifact SHA. This is a real rc.6 cancellation presentation/ownership gap, not a lost measurement or duplicate upload. Retained receipt/event trace:candidate-036/mac-held-response-package-gap-verify.jsonand adjacent events.Commit
d1f3574adds scoped SIGINT→cancel-event ownership for terminal Publish and Retry, restores the prior signal handler, returns130 with a saved-work message, and advances the current unpublished identity to1.3.0-rc.7/client/0.3.7. Two CLI signal regressions failed before the change and pass after; 94 focused routing/release/preparation checks pass. Repeating the held-response fault against the corrected source exited130 in1.086s without an orphan client, then replayed the same server run ID with one total PUT and one receipt; source-level verification iscandidate-036/mac-held-response-source-fix-verify.json. The broader local unittest discovery ran 340 tests but could not be a release gate in this checkout because pytest and frozen media were absent; one patch-specific mock assertion was corrected and the 94 focused tests reran green. Exact rc.7 four-asset CI/native packaging and the packaged interrupt rerun are pending; all rc.6 asset hashes and Medium runs above are retained as diagnostic, not current final-package certification. PR remains draft; no release or production write.Normal collection upload SIGINT fault on corrected rc.7 source
On the physical M4 Pro, current
d1f3574source (client/0.3.7) ran a real frozen animation clip with libx264 fast under the normal collection→publication path against an isolated TLS server. One warmup and two measured attempts (both honestly marked suspect for battery power) were durably journaled; the server accepted the first 6,823,054-byte PUT and held its response. SIGINT to the isolated client process group returned130 in1.089s with no traceback or surviving client. The independent oracle at the stop boundary found 1/1 finished group, two eligible records, one queued and one journal-only, zero accounting issues. Normal saved Publish then confirmed both: three create calls over two stable server run IDs, two authorizations, exactly two PUTs (no repeat of the first accepted PUT), two durable receipts and accepted markers, pending0. Attempt count stayed3; all pre-replay journal/manifest hashes stayed fixed; exactly the two acknowledged measured artifact files were retired. Final independent oracle: two confirmed, zero issues. Source-level receiptcandidate-036/mac-normal-upload-cancel-source-verify.json, event trace adjacent. This directly tests R03's active collection path, while exact rc.7 native package and GUI Stop/Close paths are still open. The local server was stopped.Superseded rc.7 four-asset receipt and packaged signal contrast
The exact rc.7 merge build
2b705c5cbca2643adb5ae9d88597c24246ccab7f(same source tree asfe1312e) produced a hash-checked unpublished diagnostic four-asset manifest at.test-reports/reliability-20260928/candidate-038/four-asset-manifest.json: Mac DMG 129,846,263 bytes SHA-2568ad8d7192826c58d556ff09d6d5cab2bcc2f31ca0a6e65fbf4c93ec7cfa30bc1; Windows GUI 182,676,075 bytes9aac6dbdaad0cffe5ac1387ec6f19fa32d5fbcc63112c836038f42aecec38672; Windows console 182,679,692 bytes96e39ef04023ea8f09a8ca97f9808607f5f41f1e28ace7092d2372888695a5b8; Linux archive 201,017,249 bytes4aa25fd6b9d3d2e95004292f1f9843c86ce9d6e5dfa734ab9abafaa033e7ba20. The Mac DMG was mounted read-only; its embedded CLI matched the CI hash. No rc.7 promotion is implied.The packaged Mac CLI was tested with a held response after a 171,544-byte PUT. Process-group SIGINT left the PyInstaller child active for the full 60-second test window; the harness then sent SIGTERM, so the exit was
-15, not the promised controlled 130. In a separate fresh queue/server, SIGINT directed only to the onefile child exited130 promptly. Each stopped queue replayed one original server run ID without a second PUT and wrote one receipt/marker. Exact contrast and event traces:candidate-038/mac-pyinstaller-signal-contrast.jsonand adjacent JSONL. PyInstaller 6.19 documents--bootloader-ignore-signalsfor a process-group signal delivered to both bootloader and child. Commit73ede39applies that console-only build option for macOS/Linux/Windows console, retains the Windows GUI's own Stop/Close path, adds a red-to-green build regression and advances the current unpublished candidate to1.3.0-rc.8/client/0.3.8. Ninety-five focused tests passed locally. Exact rc.8 CI assets and native group/parent-only cancellation checks are pending; this PR remains draft and readiness remains not certified.rc.8 packaged Mac terminal SIGINT proof and boundary
The exact rc.8 CI Mac DMG from merge tree
f805c177d8eba1c98c91ac83e2fb4967ee0303e3is 129,845,771 bytes, SHA-2562b2d41ae8d6e331b28d060439cf67c193a3df98843e563dc43d54e20fec9b7ac; mounted read-only as an ordinary user. Its embedded CLI SHA-256556c2391b64d5c5db06fc66c1e72341132c833dab069b0eedfb6034c4a4d3129matches CI package-info. With the isolated TLS server holding the first PUT response after accepting 171,544 hash-matched bytes, SIGINT to the packaged onefile process group exited130 in 1.148 seconds, where rc.7 hung beyond60s. A normal replay queried the same server run ID, made no second PUT, wrote one durable receipt/accepted marker, left pending0 and did not change the original artifact. Receipt:.test-reports/reliability-20260928/candidate-039/mac-packaged-group-sigint-verify.json; event trace adjacent. The server was stopped.The bootloader option has a separate observed limit: SIGINT sent only to the onefile launcher PID left both launcher and Python child active after2s; signalling the child then exited130 and replay again used one PUT/run ID/receipt. Receipt:
candidate-039/mac-parent-only-sigint-limitation.json. A task-local PyInstaller 6.19 probe reproduced this parent-only tradeoff. Terminal Ctrl+C/group cancellation is proven for this Mac fixture, while parent-PID-only signalling and the remaining Stop/Close/network phase matrix are not certified. This is local synthetic transport acknowledgment, not authoritative analysis or publication promotion.Current rc.8 four-asset manifest and active native checks
The exact unpublished rc.8 merge build
f805c177d8eba1c98c91ac83e2fb4967ee0303e3has the same source tree as commit73ede39.scripts/assemble_client_release.pyindependently checked all CI sidecars and asset bytes in.test-reports/reliability-20260928/candidate-039/four-asset-manifest.json. Each identifies1.3.0-rc.8,client/0.3.8, protocol 7.1 and the frozen suite. Lifecycle: built from reviewed source=true; native acceptance=not certified; published=false; independent public redownload=false.2b2d41ae8d6e331b28d060439cf67c193a3df98843e563dc43d54e20fec9b7ace8c3997a13c4be85130f786de84f129bab8fbec2fef5d79d285a53121fed9ecc435d6987c50617a0a88fa561b0a435054efc972e85196893cba945ac8d42d6159fa70f852bac88a1830e4803e6a579f81050e7ba7b7b06c0a56afc57050c8183The physical Windows host rehashed both executable copies against those sidecars. First new rc.8 cold-cache Medium sweeps on Mac DMG and Windows console are in preparation, with finite source heartbeats; neither is yet a completed or published scientific result. A second physical Linux Medium from superseded rc.6 remains active as diagnostic evidence; rc.8 Linux timing starts only after it finishes and is independently audited. The exact rc.8 Windows packaged GUI CI phase is still running. No production writes or promotion.
Current rc.8 packaged Windows GUI progress evidence
The exact rc.8 Windows GUI CI phase
Exercise actual packaged Windows GUIpassed, and its diagnostic artifactwindows-gui-diagnostics-f805c177d8eba1c98c91ac83e2fb4967ee0303e3was visually inspected. Instop/before-click-Stop.png, while encode 3/5 is underway, both Overall and Batch bars show 2/5 and the status readsRecorded 2/5 attempts (1 warmups, 1 measured). Instop/cancelled.png, both remain at 2/5 and Stage is Cancelled. Incomplete/locally-complete.png, both fill at local completion, with two measured records saved and zero uploads. Files are retained at.test-reports/reliability-20260928/candidate-039/windows-gui-diagnostics/. This directly closes the reported progress-bar behavior for the tested packaged single-recipe flow. Physical guided Medium GUI and full visual/accessibility acceptance remain unexecuted; the separate Windows CI seven-clip software-only console phase is still running.Final rc.8 CI and Mac disk-stop recovery in progress
CI run 36615229951 is fully green: client 625 passed / 5 skipped; server, frontend, migration, stack smoke, clean deployment, release preflight and dependency audits passed; all native builds passed. The exact packaged Windows GUI passed prepare-stop, complete, stop and close phases (
PASSED_AUTOMATED_GUI_CHECKS_VISUAL_REVIEW_PENDING), and its separate seven-clip console phase passed on a virtualized software-only runner (PASSED_VIRTUALIZED_WINDOWS_SOFTWARE_ONLY). I inspected the active/cancelled/complete rc.8 GUI screenshots above; this is not physical guided Medium GUI or GPU proof.On physical Mac, the first exact rc.8 cold-cache Medium campaign
campaign-e5d684ca48e69284downloaded and verified the full frozen pack, then exited6 when free disk fell below the 1 GiB system safety floor after 24 retained warmups. It marked zero groups complete and the independent oracle reported zero issues. The new cold cache's 29 files / 4,520,317,708 logical bytes matched the preserved prior frozen cache by SHA-256, every file. Only the new task-created duplicate cache blocks were replaced at the same paths with APFS clones; an independent post-clone hash pass found zero mismatches and available space rose from about1.1GiB to9GiB. No owner original state or campaign evidence was deleted. A 74-file SHA-256 snapshot of the saved manifest, budget, warmup attempts, release markers and process records is unchanged after the same rc.8 campaign resumed and journaled attempts 25–27. The run remains active; this is executed storage recovery evidence, not a complete Medium result yet. Physical Windows rc.8 cold-cache Medium and Linux rc.6 diagnostic Medium are also active locally without production upload.Second complete physical Linux rc.6 Medium diagnostic
The second independent physical Ubuntu/p910
client/0.3.6archive campaigncampaign-3c96b9e8347785caran local-only from 2026-09-29 12:55:33 to20:31:26 UTC, 7h35m53s observed wall, with seven automatic measurement checkpoints and exit0. Independent oracle: 112/112 frozen groups finished;112 warmups,270 measured attempts (224 required floor+46 optional adaptive),270 local immutable envelopes, all382 attempts client-valid, zero accounting issues and zero server receipts. Separate byte audit verified all112 warmup release markers, all270 measured artifacts totaling 1,986,169,744 bytes, and every envelope artifact hash/size/campaign/client identity with zero mismatches. Evidence: ignoredcandidate-036/linux-medium-2-conservation.jsonandlinux-medium-2-byte-audit.json, plus retained physical queue/logs. Across two distinct complete rc.6 Linux Medium runs: 224/224 groups,224 warmups,562 measured/envelopes,4,101,127,226 artifact bytes hash verified,786 valid attempts and zero audit issues; all remain local-only. The third rc.6 script is intentionally not launched because rc.8 superseded that candidate. The Linux host is now idle and will receive the exact rc.8 package outside any active timing window. These diagnostics do not certify rc.8 Linux three-run, server analysis, or native Large/Full.