Lewati ke isi

T0-E1.2 independent re-audit runtime

Validator reproduction

Command:

python3 scripts/golden/e12_evidence_identity_validator.py \
  --manifest T0-E1.2-runtime-manifest.json \
  --results T0-E1.2-20260809T221606Z-security-matrix.json \
  --allow-docs-tip

Result:

FAIL: backend tree mismatch: manifest=005258351f... workspace=8e0990ff...
FAIL: backend runtime tree must equal live runtime tree, manifest runtime tree, and certified workspace BE tree
FAIL: BE: docs-tip refused because application tree changed
E12 VALIDATOR FAIL (3 issues)

This is an expected fail for the current stale manifest, and proves that the evidence cannot currently certify the served tip.

Provisioning regression

Running provision_clean_tenant.sh without a password exits 1:

ADMIN_PASSWORD / --admin-password is required (no default).

The script also rejects predictable values and does not print the supplied secret. This closes the previously observed default-password path.

Runtime identity

POST /api/public/certification-identity reports the live DB/module/entitlement payload, but the runtime tree is different from the frozen E1.2 manifest because the BE application tip advanced to 5232370.