# Findings and retests

Version 1.3 — evidence status checked September 7, 2026 through 14:48:48 UTC

This record keeps a failed check visible beside its correction. “Closed” means the named retest passed within its stated scope. It does not mean an outside assessor or customer approved the product. A later release must identify the exact superseding version and evidence before changing an open item.

| ID | Finding | Current state and evidence | What remains outside that result |
| --- | --- | --- | --- |
| F-01 | A browser could treat a missing, malformed, interrupted or digest-mismatched evidence download as successful. | **Closed in R02.** Controlled negative tests and dated public verifier checks reject these cases before download. | The caller's digest is not an independently trusted statement or timestamp. |
| F-02 | The KAIDAN handoff could open a fictional queue without giving a real signed-out user a usable sign-in path. | **Closed in I02.** The desktop and phone retest retained the requested KAIDAN destination through sign-in and reload. | It did not complete a customer's MFA or source setup. |
| F-03 | KAIDAN G05 passed pull-request checks, then merged run [34085621962](https://github.com/wildzealot/Kaidan1/actions/runs/34085621962) failed a dialog color-contrast assertion and skipped deployment. | **Partly closed.** The correction is included in deployed KAIDAN revision `6b71b4d`, and Briard production has the two exact G05 migrations plus route fix `e25bccc`. The old failure remains retained. | The signed-in production incident-to-policy workflow still requires a final live retest. |
| F-04 | The first D02/D03 controlled production detector run was denied because the local event omitted the region required by active metadata policy. | **Partly closed.** PR 90 corrected the event region; the correction is included in deployed revision `6b71b4d`; its latest CI, Security and deployment runs passed. The failed run remains retained. | D02-D04 still require signed-in production retests for local, multi-step, cross-session, delayed, priority, grouped and quiet outcomes. |
| F-05 | Historical Briard object recovery did not cover the full database, identity, configuration and KAIDAN boundary, and KAIDAN O02 previously lacked deployed receipt-bound recovery proof. | **KAIDAN O02 closed; broader boundary partly open.** Revision `6b71b4d` passed CI, Security and production deployment. Snapshot `c76e7184…` then passed the 8-second isolated release/schema/object/OpenBao restore and continuity audit; the guarded no-confirmation action stayed stopped; controlled restart, alert and health recovery passed in 19 seconds. The earlier 7-second/64-schema restore remains retained as historical evidence. July test-account recovery also retained fresh Entra MFA and a protected HTTP 200 from an operator-transcribed Entra observation; it did not establish an Owner role. | Briard managed-database, identity and full-boundary recovery remain separate. One KAIDAN rehearsal does not establish contractual objective attainment, independent second-person succession or external assurance. |
| F-06 | No executable DPA, universal contractual breach-notification deadline, residency commitment, independent penetration test, SOC 2 report or ISO certificate is available. | **Open external or legal work.** The questionnaire and order worksheet say “not available” instead of treating the gap as complete. | Customer trials, independent assessments and counsel approval remain in a separate future plan and are not engineering acceptance gates. |
| F-07 | Invitation requests lacked a durable delivery record and clear retry/provider states. | **Partly closed.** Release `9339994`, exact migration `20260907051658`, successful deployment [6304018049](https://github.com/wildzealot/Briard-AI/deployments/6304018049), four authenticated cron 200s and a private zero-queue snapshot prove the production database/application/drain boundary. | A fictional signed-in invitation and its provider-acceptance receipt remain open. An accepted provider reply will not prove inbox arrival or reading. |
| F-08 | Alert timing and doubled-load behavior lacked one bounded repeatable qualification. | **Capacity and scoped release retests passed.** Exact source `86152045f6280625265cf6f552c5c019fb4ed8fa` passed the local 2x profile. Hosted runs `34101805472`, `34105020712`, `34107510589`, `34110802725` and `34113906052` remain retained failures. In `34113906052`, exact head `155f4b663ef72cfc5358dc7faeba7f82f89962ce` / tree `523473ab16715ac90e437ea386ee25a4aa280874` completed schedule and cleanup in both cells but recorded three and two observation-serialization exhaustion events; report SHA-256 values are `7512507db6c5963db18bc7c2ca7d3e41d3cc55c903417d2edff2140c61ea806d` and `4648dfe96db4a7bd8a7ddf4262abc91740f8cf86f7b875de2e213996db404ecc`. Head `c7b53f37307a2f4b01042a8ac3d422487c63a9fe` then passed Security `34116719253`, but CI `34116719250` and capacity `34116723124` were automatically canceled as superseded when the repaired replacement was pushed; review had found an unbounded rollback-cleanup defect, and capacity produced startup-only artifacts with no qualification report. Repaired exact head `06e98f063bc605985d82b80feccc921df0250e68` / tree `d7a6f060458e70441387b6a30ef2564809461653` passed CI `34118427589`, Security `34118427617` and both cells in capacity run `34118429419`: each recorded 7,500 originals, 360 replays, 72 alerts, five handoffs, alert p95 0.5 seconds and no admission, server, read, dispatch, receipt, backlog, duplicate-effect or worker failure. Exact cell report SHA-256 values are `340d6c094e7a3f857bca61ab01504d1042a4ffa32fbff25ab1a6c1379d87a5e1` and `eb7d9214e5a34f192765dd16d7d956bab6dbe0744d44f5584593c0cf348a2765`. PR 93 merged as signed and verified `142418191a3722d268ea0b0caf5e55c5206bd01a` with the same tree. Post-main Security `34120188991` attempt 1 failed only its container build/scan on transient `proxy.golang.org` HTTP/2 `INTERNAL_ERROR` responses for locked `github.com/minio/minio-go/v7@v7.0.91` and `aead.dev/mtls@v0.2.1`; every other applicable source and security job passed, and unchanged-SHA attempt 2 reran only that job and failed at 12:27:22 UTC: the relay image built, but the pinned MinIO image again stopped when `proxy.golang.org` returned HTTP/2 `INTERNAL_ERROR` for locked `github.com/minio/mux@v1.9.2`. Both failed container attempts are retained as recurring external infrastructure fetch failures; they do not show a source defect. KAIDAN production remained on `6b71b4dede46543a030a26f2024a12150c1e057b` and was untouched. PR 95 first candidate exact head `364fd359e41f7dc255b16ffc5e5fbbb6c5f14344` / tree `baeaa1bf216334ff053384cc59dd3278666190eb` / parent `142418191a3722d268ea0b0caf5e55c5206bd01a` adds fixed four-attempt, 240-second-per-attempt HTTP/1 full-module-graph prefetch, then `GOPROXY=off` compilation and `go mod verify`, while retaining the pinned versions and image digests; Security `34122497940` failed its container job at 12:40:18 UTC after HTTP/1 prefetch and `go mod download all` completed because `GOPROXY=off` compilation found locked `github.com/pborman/getopt@v0.0.0-20170112200414-7148bc3a4c30` absent from cache. This incomplete offline-prefetch hardening defect means the candidate is not qualified or deployed. Security finished failed at 12:40:58 UTC with all seven other jobs passing. CI `34122497949` passed its format/build and SDK jobs, then its integration, accessibility and race jobs were automatically canceled as superseded when the corrected replacement was pushed; the run finished canceled at 12:43:01 UTC. Corrected final head `b48801011a3b3580a2bf67b9f3503a5212ad2444` / tree `53321ac7451232bccf3d7c578fa5210a7dbc8c23` / parent `142418191a3722d268ea0b0caf5e55c5206bd01a` retained the bounded HTTP/1 graph/overlay prefetch and added exact Linux, non-CGO, `kqueue` build-dependency resolution under the same bounds. Generation, compilation and `go mod verify` then ran with `GOPROXY=off`; pins and image digests remained unchanged. CI `34123352820` passed all five jobs and Security `34123352826` passed all eight, including object-store build and image scans. PR 95 squash-merged as signed and verified `786a81d2f4da27a41cec72323524cad12ea622c3` with unchanged tree at 13:02:17 UTC. | Post-main CI `34120188869` passed all five jobs, while Security `34120188991` retained the two infrastructure-fetch failures. Final object-store hardening gates and verified merge passed, as did exact-merge CI `34125139565` and Security `34125139467`. Deployment `34126531698` activated exact `786a81d2f4da27a41cec72323524cad12ea622c3`, applied the 64-migration schema and passed nginx, health and maintenance, then failed its post-activation helper probe because the restricted account could not run arbitrary `sudo test -x`; the invalid-token proof was skipped. Read-only administration confirmed the exact live revision/symlink/schema, three executable helpers, active service and passing health audit. PR 96 first head `94123876d021cb22523cd0b2f811d167ff378178` / tree `5880b714b764f10aa6ed678fcfeca5573d5a22a3` replaced the sudo probe with direct non-root checks; Security `34127623989` passed, while CI `34127624025` retained two superseded runner-fixture failures in jobs `101759925556` and `101764438338` with log SHA-256 values `3de4cb7a52db694dcfa18936c10eb97a13f61ed50d7764b7197a599406b11c5f` and `846d81667b027b8cfdd7571ce1df6132b328aa6a74e18df53297b470362f4040`. Final head `47dbbe896ec356ebad7553d7042c8a4feaff5ff6` / tree `2b7c1d2377046f4a4e7e0efd613bc3d2b89e9412` passed CI `34130124723` and Security `34130124750`, then merged as signed and verified `e0a9b5b3031b79ab77bd5d540370f3eea5d20b4c`. Exact-main CI `34131955343` passed all five jobs, with console accessibility completing at 14:35:07 UTC, and Security `34131955590` passed all seven applicable jobs. Corrected automatic deployment `34133754984`, job `101779780952`, passed at exact `e0a9b5b3031b79ab77bd5d540370f3eea5d20b4c`; all steps were green, including direct non-root helper assertions and invalid-token ingress throttling/version suppression, with authoritative raw GitHub run-log byte SHA-256 `65c9dfc16f942673a7c7002c1da3ce2747a01cbcfc4b8a61d9b024aa92bb51a7` and local CRLF-normalized PowerShell text-export SHA-256 `272419c42ebee32c57734713b12a4306a18a563a458c07145855d8d0a333bcaf`. Direct administration passed with log SHA-256 `abcdc5c254353a18c579adbf0e5e0c3ee1b731add45d11e605e7bdc9167f6144`. Snapshot `b5aec0f3112034bccf02456577218d25fde999e51be7763ca3e09c7fc5540d8e` then passed a 7-second isolated exact-release/schema/OpenBao restore and continuity check; controlled recovery passed in 18 seconds with an accepted alert, and final health passed. Combined recovery-log SHA-256 is `e97b383483d6ae6b4bbc5cc23bb0f1dac8ede84fd869372b8e4150ccc4ff6425`. [Production Health `34134980871`](https://github.com/wildzealot/Kaidan1/actions/runs/34134980871), job `101783702570`, passed at exact `e0a9b5b3031b79ab77bd5d540370f3eea5d20b4c` from 14:48:41 through 14:48:48 UTC. API, console, object-store, notary and KAIDAN-console HTTPS passed; provisioning without platform authority failed closed with 401; and all four certificate windows passed. Production Health log SHA-256 is `bbc6d817b6dc8cff4cf78ffa0ca144e64f16bac6987c10da256ab040a8af0c03`. O01 release is closed within the stated engineering scope. The capacity pass shows aggregate software behavior on the recorded runners, not one host's 80 events/second or production/customer capacity. |
| F-09 | R01 hosted tests and deployed source could be mistaken for a signed-in production provider-action result. | **Open production retest.** R01 is included in current deployed revision `6b71b4d`; hosted PostgreSQL/Elasticsearch effects remain valid within their controlled scope. | The three signed-in production response-plan checks and provider-effect review remain open. |

See [evidence and open findings](./evidence-status.md) for the compact release snapshot. Keep prior failed evidence when a later retest passes; add the new result rather than rewriting history.
