Fresh independent exact-candidate review passed

Exact Alpha 6 candidate · zero open findings · human release decision executed

CECP Alpha 6 Assurance & Verification

What was tested, what passed, and what the evidence does not prove.

The exact CECP Community Edition 0.2.0-alpha.6 candidate authenticated, completed the full independent review with no failed gate or open finding, preserved its bytes through review, and passed to Thomas Prislac’s exact-hash decision. Thomas then authorized publication of the listed exact artifacts as a public open-source research preview.

  • 168 passed
  • 0 failed
  • 0 errors
  • 0 skipped
  • First failed gate: none
  • Open findings: 0
  • Candidate nonmutation: pass
  • Production release: not authorized

A matching hash establishes byte identity—not truth. Neither the software, its receipt, its tests, nor this review establishes authorship, consent, legality, safety, external factual correctness, scientific validity, production fitness, or authority to act.

Independent disposition

The reviewer’s PASS closed the exact-candidate review gate. It did not publish the software or convert technical evidence into truth, legal clearance, or production approval.

TechnicalPASS_EXACT_CANDIDATE

Exact identities, testing, clean installs, receipts, boundaries, browser evidence, and nonmutation passed.

Editorial / governancePASS_FOR_BOUNDED_PUBLIC_RELEASE_CANDIDATE_DECISION

The reviewed claims and boundaries supported a bounded human release decision.

RecommendationPASS_TO_THOMAS_PRISLAC_EXACT_HASH_DECISION_GATE

The review passed the unchanged candidate to the named human authority.

Human decisionAUTHORIZE_EXACT_HASH_PUBLIC_RELEASE_CANDIDATE

Publication is authorized only for the exact listed filenames and hashes.

Review the thirteen ordered independent gates
  1. GATE-00: Handoff ZIP, sidecar, supplied SHA-256, CRC, and path safety — PASS.
  2. GATE-01: Commission discovery and mandated replay used only as noncontrolling evidence — PASS.
  3. GATE-02: Exact Alpha 6 candidate identity and closed-set authentication — PASS.
  4. GATE-03: Alpha 5 IR-BLOCK-001 canonical MPL-2.0 parity across nine distributed surfaces — PASS.
  5. GATE-04: Truthful provenance, rights/origin, and claim-ceiling review — PASS.
  6. GATE-05: Exact Git commit, tree, tag, bundle identity, and clean checkout posture — PASS.
  7. GATE-06: Complete 168-test suite with zero failures, errors, and skips — PASS.
  8. GATE-07: Fresh wheel and source-distribution clean-install replay — PASS.
  9. GATE-08: Real PASS, HOLD, and REJECT receipts; process exits; authority effect NONE — PASS.
  10. GATE-09: Public-boundary and secret, host, and private-material scanning — PASS.
  11. GATE-10: Browser evidence replay and bounded Windows-evidence interpretation — PASS.
  12. GATE-11: Source pre-seal status treated as historical process evidence, not release authority — PASS.
  13. GATE-12: Final exact-candidate nonmutation — PASS.

Alpha 5 license finding closed

Alpha 5 remained held because its distributed license bytes did not support its absolute “exact, verbatim, unmodified” claim. Alpha 6 replaced that unsupported claim with dated, hash-bound provenance and one canonical vendored MPL-2.0 source.

Prior finding

IR-BLOCK-001

Distributed MPL text and the public exactness claim did not agree at the byte level. Alpha 5 was not released.

Alpha 6 closure

Nine distributed surfaces matched

The source, built distributions, package metadata, Windows packages, and related public surfaces agree with the authenticated canonical MPL-2.0 posture.

3f3d9e0024b1921b067d6f7f88deb4a60cbe7a78e76c64e3f1d7fc3b779b9d04

Provenance boundary. The record binds the license text retrieved from Mozilla on 2026-08-21 to a URL, byte count of 16,726, and SHA-256. It is not a legal opinion, chain-of-title ruling, or release authority by itself.

Executed review evidence

The reviewer separately replayed the complete candidate rather than treating builder evidence or the limited mandated replay as controlling.

168

Source tests passed

Zero failures, errors, or skips.

3

Real dispositions replayed

Fresh PASS, HOLD, and REJECT receipts preserved the process-exit contract and authority_effect: NONE.

2

Clean Python installs

Wheel and source distribution installed and ran in isolated environments.

0

Public-boundary findings

No release-blocking secret or prohibited private-material exposure was found.

Browser lane

Commissioned controls passed

Browser evidence, keyboard operation, reflow, exact-byte behavior, and bounded local-interface controls were reviewed within the commissioned scope.

Windows lane

Authenticated evidence, bounded interpretation

The Linux review host authenticated and reviewed the Windows evidence. It did not misrepresent that evidence as a fresh Windows execution performed by the review host.

Public assurance records

These records support independent inspection of the review, build evidence, public Git identity, exact human decision, approved artifact ledger, and release continuity.

Independent review

Fresh exact-candidate review ZIP

Sealed decision, ordered gates, claim ceiling, findings register, evidence records, and candidate nonmutation.

8abc53c36a0133f32955c45d314ce6cae6293816085930a3dfdcf15102a9af9c
Builder evidence

Public-safe Builder Evidence

Named Windows, browser, test, clean-install, packaging, licensing, and public-boundary evidence from the builder workstream.

180693e3688cf7a98bdc435577199fac0633965c894751c59bda09f396e94dde
Git provenance

Clean source bundle

Exact candidate Git history for advanced provenance replay and clean-checkout inspection.

644e50d0a2542a6eef1a81e982cc1b4c68cfa54a743542253685ff21a0db8391
Repository export

GitHub-ready public repository

Clean public repository export with no configured public remote.

967c9f75db4e300c074097f8ea10ac2c89f678d7dda81237b492673e276db384
Human authority

Human release authorization

Thomas Prislac’s exact-hash authorization for publication of the named candidate bytes only.

MD: e1dce26793b6347da44a2da524d3062b81fef6bafeb03f3b5d4028fdf2ec8124
JSON: d1ec235acd9befcb0e81b53c2171f13eb2d7771f7a063794c6cac1f914a45a6f
Exact release identities

Approved artifact ledger

Machine-readable filenames, byte sizes, SHA-256 values, decision state, and immutable-byte boundary.

37be3a4e6e265aa8db115c003cf089b5a242601f6a93e4b8c42fad4e0e53caea
Continuity

Release continuity receipt

Executed human decision, release authorization, next publication gate, and nonproduction boundary.

1e26bcdfbcb2b1c50609a75a8cbb1505bc2e3cb190f0f0102e777e0e68b0ae73
Master verification

Exact-candidate SHA256SUMS

One compact checksum ledger for the reviewed candidate’s exact file identities.

ee705ae6349b53372c6311fceb5827074f6be980dfb7c8c4efbf075e51ad2a06

Exact approved artifact ledger

Any changed byte creates a new candidate and requires a new identity and review treatment. Squarespace may simplify a public URL; the expected bytes and SHA-256 remain the controlling identity.

Public source ZIP UVLM_CECP_Community_Edition_0.2.0-alpha.6_Public_Source_Release_Candidate.zip 305,777 bytes
053210fd38739b7e0a67b071932457bf2be70522187419066de55114c039414e
GitHub repository export UVLM_CECP_Community_Edition_0.2.0-alpha.6_GitHub_Repository_Export.zip 306,897 bytes
967c9f75db4e300c074097f8ea10ac2c89f678d7dda81237b492673e276db384
Clean Git source bundle UVLM_CECP_Community_Edition_0.2.0-alpha.6_Source.bundle 279,969 bytes
644e50d0a2542a6eef1a81e982cc1b4c68cfa54a743542253685ff21a0db8391
Python wheel uvlm_cecp_community-0.2.0a6-py3-none-any.whl 62,002 bytes
c05602e8726c135ba06145eb5ea4516f933d9fee5d673be32b143d3accbd47ec
Python source distribution uvlm_cecp_community-0.2.0a6.tar.gz 101,705 bytes
32dac80de5decbbc64907ac3a93fae7606a08185117d4b078d29811bd51b29aa
Windows x64 portable UVLM_CECP_Community_Edition_0.2.0-alpha.6_Windows_x64_Portable.zip 7,918,821 bytes
506ce438870ed9e615a69993a25da4062eb53e442586d3662344b49b253581ab
Windows installer candidate UVLM_CECP_Community_Edition_0.2.0-alpha.6_Windows_x64_Installer_Candidate.zip 7,953,311 bytes
d71b1c2efc150cbbfcbd8adc6135880564ecab32f7ec5d0785b329671645d923
Public-safe Builder Evidence UVLM_CECP_Community_Edition_0.2.0-alpha.6_Builder_Evidence_v1.0.0.zip 106,677 bytes
180693e3688cf7a98bdc435577199fac0633965c894751c59bda09f396e94dde
Squarespace Publication Kit UVLM_CECP_Community_Edition_0.2.0-alpha.6_Squarespace_Publication_Kit_v1.0.0.zip 66,980 bytes
82b49868ab9bf8b905aee0e36973bfea7de576928d9a59d9e096b3677393a097
Master checksum ledger SHA256SUMS.txt 3,550 bytes
ee705ae6349b53372c6311fceb5827074f6be980dfb7c8c4efbf075e51ad2a06

Verify a downloaded file

Do not rely on a filename, button label, browser address, or page appearance. Download the file, calculate its SHA-256 locally, and compare the full 64-character digest.

Windows PowerShell

Get-FileHash -Algorithm SHA256 ".\DOWNLOADED_FILE"

Compare the returned Hash with the exact ledger on this page or the downloaded sidecar. A mismatch means the bytes are not the approved artifact.

Python

python -c "import hashlib, pathlib; p=pathlib.Path(r'DOWNLOADED_FILE'); print(hashlib.sha256(p.read_bytes()).hexdigest())"

The full digest must match exactly. Do not trim, normalize, recompress, or edit an approved artifact.

Hash limitation. A correct digest proves that the downloaded bytes match the declared bytes. It does not prove the content is true, safe, lawful, ethical, authored by a named person, or fit for a particular use.

Scope, limitations, and nonclaims

Assurance is strongest when its boundaries remain visible. These limitations are part of the release, not fine print to be hidden after a favorable result.

Evidence scope

What the review supports

  • Exact candidate identity and closed-set integrity.
  • Complete 168-test execution on the review host.
  • Clean wheel and source-distribution installation.
  • Real PASS, HOLD, and REJECT receipt generation.
  • Canonical MPL-2.0 parity and truthful provenance.
  • Public-boundary scanning with no release-blocking finding.
  • Browser evidence and bounded interpretation of authenticated Windows evidence.
  • Final candidate nonmutation.
Nonclaims

What the review does not establish

  • Production readiness, certification, or universal compatibility.
  • External factual truth, document authenticity, consent, or authority.
  • Legal advice, regulatory compliance, human-rights certification, or policy approval.
  • Malware absence, external penetration testing, or FIPS validation.
  • Formal affected-user accessibility certification.
  • That a PASS authorizes an action or decides a person’s worth, credibility, diagnosis, dangerousness, benefits, employment, punishment, detention, or access to essential services.

Windows boundary. The Windows portable and installer are unsigned research-preview artifacts. The independent Linux review host authenticated and evaluated the supplied Windows evidence but did not claim a fresh Windows execution from that Linux environment.

Corrections, defects, and security reports

Report a reproducible defect with the exact artifact name and SHA-256, operating system, interface or command, minimal synthetic reproduction, expected behavior, observed behavior, and logs with personal data and secrets removed.

Do not email private keys, credentials, customer records, sensitive source material, or personal data. Use synthetic reproduction material whenever possible.

Support public-interest protocol engineering

Ultra Verba Lux Mentis is a nonprofit research organization. Voluntary donations help fund accessibility work, independent review, documentation, maintenance, education, and grant-sponsored access. Access to CECP, software behavior, review findings, support decisions, and governance outcomes never depend on whether someone donates.

The sitewide donation options below are separate from this release’s license, downloads, assurance, and human decision.