Release evidence · alpha.6

Technical pass · Exact-hash public alpha authorized

Assurance & verification

What was actually tested, what the exact hashes identify, and what remains outside the claim.

This page reports the sealed candidate, separate-pass review, human authorization, fresh publication replay, known limitations, and direct evidence routes. It does not turn technical evidence into truth or production certification.

Controlling release state

Technical disposition

PASS_FOR_OPEN_ALPHA_RIGHTS_AND_EXACT_HASH_DECISION

Zero known technical blockers in the commissioned exact-package scope.

Human decision

Authorized for exact-hash public open-source alpha

Authority is limited to public distribution of the exact named bytes under the recorded MPL-2.0 posture.

Release class. Experimental public open alpha. No production, security, accessibility, legal, clinical, scientific, provider, training, memory, mapped-product, or core-merge authority is claimed.

Exact controlling hashes

Source candidate

UVLM_CoherenceLattice_Product_Module_Contract_v0.1.0-alpha.6_Release_Safety_Successor_v1.0.2.zip

adc29787223610c1fd1b5f3188aebe8096c7d7816e5d954906c0bab93208fe0e

Passing review bundle

UVLM_CoherenceLattice_Product_Module_Contract_v0.1.0-alpha.6_Fresh_Separate_Pass_Open_Alpha_Review_v1.0.1.zip

ca2cb8f6d1958c9ac9247095a3b641b40278d948e4cfaba230658590cda90a6f

Human authorization receipt

UVLM_CoherenceLattice_Product_Module_Contract_v0.1.0-alpha.6_Thomas_Exact_Hash_Open_Alpha_Release_Authorization_v1.0.1.md

c36238f2f512cd34312fc76622884216da34075a3e36aab9e703b7d060199320

Rights ledger inside source

115 exact rows

6e6d319681349eb123fb6b3ed57e78ede68b71de83a0e22fa74932eed71739a7

Executed review results

GateExecuted result
Source archive115 unique members, one safe root, CRC PASS, no unsafe paths, encryption, symlinks, special members, or Unicode/case collisions.
Manifest and checksums113 manifest entries and 114 checksum entries close exactly; no digest or size failures.
Rights ledger115 rows close over all source members; external exact-hash human authorization executed.
Schemas10 Draft 2020-12 schemas valid with unique IDs; 33 routed instances valid.
Reference replay16 generated output files reproduced byte-for-byte; zero Python socket network attempts.
Unit tests54 passed, 0 failed, 0 skipped.
Adversarial matrix39 of 39 mutations rejected; baseline accepted; zero harness errors.
Release-safety matrix11 attacks rejected and one valid owned-refresh control passed.
Reference lineageAll 15 governed alpha.3 artifacts remain byte-identical.
Deterministic rebuildTwo rebuilds reproduced the exact source ZIP bytes and SHA-256.
Public sanitizationNo configured credentials, email addresses, private keys, or machine-local absolute paths in the final public source or review bundle.
Candidate nonmutationExact candidate and detached sidecar unchanged throughout review.

Release-safety findings closed

Recursive deletion removed

Caller-selected output directories are no longer recursively removed or treated as disposable.

Ownership closure required

Existing nonempty output must carry the exact marker and match every known artifact digest.

Linked and protected paths reject

Symlinks, reparse branches, roots, source ancestors, VCS metadata, altered content, and unexpected entries fail closed.

Review and release limitations

  • Native Windows junction/reparse execution was not available; this is disclosed rather than labeled as a native pass.
  • The passing review is a fresh separate technical pass from the same conversation as the builder, not organizational or personnel independence.
  • Portable path operations do not eliminate all local concurrent filesystem races.
  • Dependency installation may require a configured package index or local wheelhouse even though the runtime made no network attempts.
  • The reference route is one deterministic fixture; it does not prove every portfolio mapping or live-model adapter.

Download release evidence

The eight publisher-supplied public URLs are integrated below. Calculate each local SHA-256 after download; this build could not independently retrieve and rehash the hosted copies.

Transmission-evidence boundary. URL syntax and local exact-file identity were validated. Live logged-out retrieval remains a post-publication check and must not be inferred from URL insertion alone.

What a matching checksum proves

A matching SHA-256 establishes that a downloaded file is byte-for-byte identical to the released file. It can detect alteration and support lineage. It does not prove the contents are correct, safe for every purpose, authored by a particular person, legally sufficient, scientifically valid, or free of every defect.