Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260915-2154-ecs0lib-claims-audit-SEC-20260830-01-closed

rdmsm4x-changelog-20260915-2154-ecs0lib-claims-audit-SEC-20260830-01-closed

2026-09-15 21:54:21 EDT · rdmsm4x · session_012cXdr2uPhnPS1cQfbt9pPQ

Closed SEC-20260830-01, the ecs0lib and app-integration completion-claims audit, open since 2026-08-30. Every checklist item re-measured from canonical paths. ecs0lib's own claims hold and are stronger than when made; what fails is the evidence chain past the source tree.

Scope

Result: 2 PASS · 1 PARTIAL · 1 FAIL · 1 N/A

PASS — canonical state. lib/ecs0lib HEAD bf17115e, branch main, 0 dirty paths, last commit 2026-09-11. git ls-remote fleet main == HEAD, so the ecs0.net remote is current too.

PASS, claim exceeded — tests reproduce.

Command XCTest swift-testing Total Failures
swift test 397 78 475 0
swift test --sanitize=thread 397 78 475 0 (and 0 TSAN warnings)

The 2026-08-30 comment claimed "133 TSAN tests". The suite is now 475 and still clean — the claim is superseded upward, not contradicted.

PARTIAL — dependency confirmation. Source side: 4 of 5 consumers (dataROO/macos, Xentropy/app, Xentropy-additive-reconciliation-v2/app) use .package(path:) and cannot go stale. SubnetCalculator uses .package(url: ssh://git.ecs0.net/…, branch: "main") and is pinned 11 commits behind at 34efcde7 (an ancestor of HEAD, not a fork). The remote already carries HEAD, so nothing blocks a refresh. → ISSUE-20260915-14. Signed-artifact side: not verifiable by any available means → ISSUE-20260915-15.

FAIL — published documentation. Nothing exists to match a hash against:

/projects/definitely-not-a-project.html -> 404   # negative control: 404s are real
/projects/ecs0lib.html                  -> 404
/standards/ecs0lib.html                 -> 404
/projects/index.html                    -> 200, 27,095 bytes, contains no "ecs0lib"

The index renders, so this is genuine absence, not a broken fetch. Already owned by the open DOC-20260830-02 — linked, not duplicated.

N/A — lifecycle labels. None needed correcting. The 2026-08-30 HOLD concerned 32923c28 with fixes on 158fcc2; both are ancestors of current HEAD, tree clean, full suite green under TSAN. No claim was found overstated.

The one finding worth acting on

You cannot prove which ecs0lib a shipped, signed app contains.

So every "app X adopted ecs0lib" claim is unfalsifiable from the artifact. This is the documented "a consistency check is not a freshness check" trap: libraryVersion agreeing with itself proves the copies agree, not that the value tracks the code. Filed as ISSUE-20260915-15, related to the in-progress FEAT-20260830-41 version contract.

Method note — recorded on the ticket for whoever re-runs this

Piping swift test through tail truncates the XCTest half of the report. The swift-testing summary prints last, so a tail-captured log ends with "Test run with 78 tests in 11 suites passed" and reads as though 397 XCTest tests never ran. I hit exactly that and was one step from filing a false "400 XCTest tests never execute" defect; the probe that killed it was swift test --filter <a known XCTestCase>, which ran 13 tests and proved XCTest was fine. Capture the whole log.

Verification evidence

Every negative claim carries a negative control: the 404s are quoted against a bogus-path 404 and a working 200; the "0 revision markers" is a grep whose pattern matches the real revisions. All four published pages verified live through the gateway (200, with a 404 control). Commits are path-scoped: issues 9fbecb4, sites/dev.ecs0.net ab43422, both pushed; other agents' uncommitted paths in both repos were left untouched.

Outstanding owner actions

No secrets, credentials, tokens, or signed URLs appear in this record.