T0-E1.2 Preflight — Runtime Evidence Truth and Residual Security Closure
| Item |
Value |
| Mode |
Server development /home/scola/odoo |
| Docs read |
workspace-governance, T0-E1.1-result, T0-E1.1-independent-*, DEC-014 / DEC-002 context |
| Prior E1.1 label |
IMPLEMENTED_BUT_INDEPENDENTLY_FAILED (E11-C) |
| This tranche |
Corrective — evidence truth + residual security; must not write T0 CLOSED |
| Do not start |
T0-E2, T1 |
Do not rewrite:
docs/release-readiness/audit/T0-final-*.md / original T0 independent audit
docs/release-readiness/audit/T0-E1-independent-*.md
docs/release-readiness/execution/T0-E1-* (implementation + evidence)
docs/release-readiness/audit/T0-E1.1-independent-*.md
docs/release-readiness/execution/T0-E1.1-* (PASS matrices are not E1.2 certification evidence)
E1.1 implementation status for this tranche baseline:
IMPLEMENTED_BUT_INDEPENDENTLY_FAILED
Source identity (E1.2 start)
| Repo |
Branch |
HEAD |
origin |
| FE |
develop |
7ca45c6c66766f761ad83d0259e69f62f616dc25 |
synced |
| BE |
main |
d947ed9d5a1ef1541620123561590f19af188438 |
synced |
| FE working tree |
untracked: recon XLSX; E1.1 independent audit docs (preserve, do not rewrite) |
|
|
| BE working tree |
clean |
|
|
Served / Golden baseline (start)
| Item |
Value |
| Golden HTTP |
http://127.0.0.1:8090 (/web/login 200) |
| Process |
pid 1494146 — odoo-bin -c config/odoo-golden.conf -d scola_golden |
| BE env SHA |
start identity d947ed9d… via SCOLA_BACKEND_GIT_COMMIT_SHA |
| DB |
scola_golden |
| DB UUID (live) |
2bf5fd27-9390-11f1-9617-28e8d4be73f5 |
| Live fixture ICP |
gt-core-b1.1 (E1.1 manifest falsely claimed gt-core-e11) |
| Live Scola modules |
attendance, bundle_core, core, hr, identity_admin, leadership_hub, lesson_hours, news, observability, parent, platform, platform_support, portal, timetable |
| Live entitlements (sample) |
optional packages largely False on GT-T1 |
Keep CLOSED (regression only)
Entering E1.2 (independent)
| Finding |
Status entering E1.2 |
Primary gap |
| T0F-003 |
NOT_FIXED |
Manifest false-green (modules=[], entitlements {}, null fixture checksum, env SHA trust) |
| T0F-006 |
NOT_FIXED |
provision_clean_tenant.sh default ADMIN_PASSWORD=admin |
| T0F-001,004,005,007,008,009,014,015 |
Not independently closed / PARTIALLY_FIXED |
Re-prove on truthful runtime; do not rewrite controls unless exploit still succeeds |
Architectural goals
- Truthful live runtime identity (DB/fixture/modules/entitlements/source tree)
- Fail-closed validator vs live observed state
- Eliminate production-capable predictable credential defaults
- Re-reproduce auditor exploits only against frozen truthful runtime