5.2 KiB
Rollout result — 2026-09-09
Architecture/planning/resolutions: GPT-6 Astra. Three additional Astra architecture/review executions supported the lead. Bounded implementation/verifier workers used GPT-5.6 Terra; final Windows operations used GPT-5.5. No source-repository commit, push or deployment of a new game shim was performed. The Windows housekeeping changes were explicitly authorized.
Delivered
- Versioned role prompts/model routing, AGENTS entry points, 40-step worker quanta, auto-compaction, regular durable checkpoints, no silent fallback and no nested worker delegation.
- Canonical RE contracts, guarded lifecycle, independent source-bound evidence/verdicts, surprise/Astra decision records, atomic leases and source-isolated launch controls.
- Replaced old board/coverage/Forgejo/displacement workflow and removed global Claude re-* agents. Current projections come from contracts and explicit content-addressed evidence selection.
- Fresh snapshot gate with actual source/input/binary hashes, expected test inventory, positive corpus execution, explicit skips and full output capture; no reused remote overlay/build.
- Separate file/inflated/state comparisons, retained output saves, measured-only reporter and optional equality requirement. Campaign acceptance is not inferred from equal hashes alone.
- Fixed RNG draw accounting across twists/rejections, duplicate nested-player accounting, lost replay writes, empty/malformed corpus false-skips, and snapshot clean-room scanning.
- Concrete proposed research write-set replacement pilot with archived workload, prerequisites, complete effect boundary, controls and remaining implementation dependencies.
Validation
- Python: 71 unique tests passed (37 campaign controls, 19 tooling, 8 publishing, 7 config/scanner).
- Actual OpenCode loader/model availability checks passed. Real normal launcher runs completed for Astra architecture-review and Terra verifier roles, with actual session IDs, successful stop events, fresh canonical checkpoints and source identity records. Model request is explicit; emitted provider model metadata is unavailable and is not fabricated.
- Fresh engine host build and MinGW shim cross-build passed. 59 CTest identities: 52 passed, 7 explicit permitted asset/trace skips, 0 failed. Four corpus suites each exercised 43 saves.
- Independent Astra review rehashed 524 engine + 10 RE execution-tool files, both binaries, all corpus inputs and the saved replay; all matched retained manifests.
- Canonical turn remains 62 state differences from the oracle. It is measured, not accepted.
controls-bootstrapreached accepted through independent verification and integrated source-bound verdict after R4/R6/R8 and handoff issues were resolved by Astra. Acceptance scope is the declared control-plane criterion, not engine/game fidelity.
Current selected gate: campaign/evidence/8e14e00ee3ce7478ddfdef8de12183451e858c52d78dc28cffbdee47f5d087d8-gate.json.
Current selected replay: campaign/evidence/87f92c2b54625ecbca1f3c0a37e57c43d03a4aff488edf4ea8a09a842cd6279d-replay.json.
Build/source/tool snapshots retained at /home/alex/.local/share/sots-runs/rollout-host-20260909-c.
Actual replay output retained at /home/alex/.local/share/sots-runs/rollout-replay-20260909.
Final independent controls verdict: campaign/runtime/verdicts/controls-bootstrap.json.
Final integrated verifier run: campaign/runtime/runs/run-97066391080a3d06dce27a80.json.
Five Windows guests
| VM | Verified IP | Cleanup/profile | Login evidence |
|---|---|---|---|
| 140 | 192.168.10.139 | compliant | existing console preserved; autologon config + key SSH verified |
| 141 | 192.168.10.143 | compliant | reboot → automatic re console; key SSH recovered |
| 144 | 192.168.10.144 | compliant | reboot → automatic re console; key SSH recovered |
| 145 | 192.168.10.145 | compliant | reboot → automatic re console; key SSH recovered |
| 146 | 192.168.10.146 | compliant | reboot → automatic re console; key SSH recovered |
Lead independently queried all five after completion: re console active; sshd Running/Automatic.
Policy/task/consumer cleanup and per-VM result JSON are under verify/results/housekeeping/.
The existing provisioned credential was located in the documented installation ISO and streamed
privately into protected LSA autologon storage. No password reset or plaintext-registry password.
Temporary ISO mount absent after cleanup; all VM/credential leases released.
Windows re-enabled a scheduled scan/OneDrive after login during verification. The repeatable
Apply/Verify profile is therefore a required preflight after reboot and before each new oracle
capture; old compliant JSON is not proof of current guest state. See the housekeeping guide.
Next action
Review uncommitted rollout changes; prepare the research replacement pilot from the reviewed integration snapshot. Use source-identical verifier handoffs (baseline HEAD alone omits these uncommitted changes). Full asset/trace gate and live completion-bearing research replacement remain separate, unclaimed milestones. Restart OpenCode to load project configuration/agents; existing sessions retain their previously loaded configuration.