T0-E2 Independent Audit Handoff
| Item |
Value |
| Mode |
Server /home/scola/odoo |
| Purpose |
Exact-tip binding for independent audit of T0-E2 (+ E1.2 security regression) |
| Engineering label |
T0-E2 current-tip reconciliation — E1.2 rebind verified |
| Not claimed |
Optional business-workflow certification; historical audit inputs remain immutable |
Exact tips under audit
| Repo |
Branch |
Tip SHA |
Notes |
BE gcgscola |
main |
95468e5e5bd46157adff044c6004e343bb9c5c5c |
current attendance tip; topology fix is an ancestor |
FE scola-fe-v2 |
develop |
295fad05ceed19515c02b4be3864f002333a1260 |
current merged FE tip; served build bound |
E1.2 security baseline (must stay green)
| Field |
Value |
| Current rebind run |
T0-E1.2-REBIND-CURRENT-20260810T0853Z |
| Matrix |
29/29 PASS, 0 skip |
| Validator |
PASS with --allow-docs-tip after evidence commit |
| Golden DB |
scola_golden / 2bf5fd27-9390-11f1-9617-28e8d4be73f5 |
| Fixture |
gt-core-b1.1 |
| Independent VERIFIED_CURRENT_TIP (pre-remediation) |
preserved in audit/T0-E2-independent-* |
| Prior FE81 rebind |
T0-E1.2-REBIND-FE81-20260810T025733Z (preserved) |
| Security/current-tip changes |
Attendance role allowlist and LMS service changes were included in the rebind; no silent exclusion |
Validator command
python3 custom_addons_scola/gcgscola/scripts/golden/e12_evidence_identity_validator.py \
--manifest scola-fe-v2/docs/release-readiness/execution/T0-E1.2-runtime-manifest.json \
--results scola-fe-v2/docs/release-readiness/execution/T0-E1.2-evidence/T0-E1.2-REBIND-CURRENT-20260810T0853Z-security-matrix.json \
--fe-root scola-fe-v2 \
--be-root custom_addons_scola/gcgscola \
--dist scola-fe-v2/dist \
--allow-docs-tip
T0-E2 package / topology gates
python3 custom_addons_scola/gcgscola/scripts/modular/package_topology_ci_check.py \
--gcgscola custom_addons_scola/gcgscola \
--dispositions scola-fe-v2/docs/release-readiness/execution/T0-E2-package-topology-dispositions.json \
--fe-root scola-fe-v2
python3 custom_addons_scola/gcgscola/scripts/modular/package_contract_consistency_check.py \
--gcgscola custom_addons_scola/gcgscola \
--fe-root scola-fe-v2 \
--dispositions scola-fe-v2/docs/release-readiness/execution/T0-E2-package-topology-dispositions.json
python3 custom_addons_scola/gcgscola/scripts/modular/tests/test_package_topology_ci_mutations.py
python3 scola-fe-v2/scripts/modular/check_package_catalog.py
Expected: all PASS (mutations deliberately fail intermediate cases then restore).
Finding claims for auditor
| Finding |
Engineering status |
Auditor focus |
| T0F-010 |
CLOSED_BY_INDEPENDENT_AUDIT |
Preserve; regression only |
| T0F-011 |
CLOSED_BY_INDEPENDENT_AUDIT |
Catalog SC-UNKNOWN fails package_contract_consistency_check.py; mutation suite includes test_05_unknown_catalog_sku_fails_consistency |
| T0F-012 |
APPROVED_BY_REQUESTING_USER_CONVERSATION |
DEC-001 bounded catalog + DEC-014 V1 credential policy approved in current conversation; FOUND installer record remains |
Primary evidence paths
- Independent audit (preserved):
audit/T0-E2-independent-*.md
execution/T0-E2-result.md
execution/T0-E2-preflight.md
execution/T0-E2-package-matrix.md
execution/T0-E2-decision-inventory.md
execution/T0-E2-DEC-FOUND-INSTALLER.md
execution/T0-E2-package-topology-dispositions.json
execution/T0-C-evidence/baselines/*
execution/T0-C-suite-manifests/*
audit/T0-E1.2-final-reaudit-* (prior security VERIFIED — preserve, do not rewrite)
Disposition snapshot
- baseline: CORE, ADM, FEES, LIB, FIN, OPS, STUDENT, PEOPLE, ATTEND+, FOUND
- blocked_engineering: REPORT, LEARN, ASSESS, DAP, BOS
- composite: SC-ADM+SC-FEES →
scola_admission_fees_bridge
- enterprise: umbrella profile only (
scola_bundle_enterprise), not SC-FOUND SKU
Explicit non-goals for this audit
- T1 entry is approved only for bounded Core after the current rebind PASS; optional workflows remain gated.
- Do not certify optional business workflows
- Do not require FOUND→enterprise conversion
- Do not invent Product signatures for DEC-001 / DEC-014 tables