From 01cf8e80aaf63e98ee64cffe107e1e26deb40a64 Mon Sep 17 00:00:00 2001 From: Beyond <46542494+crypticpy@users.noreply.github.com> Date: Thu, 27 Aug 2026 23:14:53 -0500 Subject: [PATCH 1/3] docs: record the 2026-08-28 gate evidence and the rc.7 requirement Updates the RR-H rows with the drills, rehearsals and checks completed against the rc.6 candidate: the live updater pass and rollback proof (RR-H02), the end-to-end publish rehearsal and takedown (RR-H03, RR-H07), the re-audited operations inventory sync (RR-H05), the in-flight one-business-day soak (RR-H08), and the deployed-candidate link check with its Discussions finding (RR-H09). Records that the PR #49 merge moves the stable cut behind a v1.9.0-rc.7 candidate. Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_014sAVayAT2tkQ7p9U2o9CsD --- docs/release-readiness-status.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/docs/release-readiness-status.md b/docs/release-readiness-status.md index 8ba4c0e..cb8bfb2 100644 --- a/docs/release-readiness-status.md +++ b/docs/release-readiness-status.md @@ -1,6 +1,6 @@ # PHCT and BCHC release-readiness status -- Evidence date: 2026-08-27 +- Evidence date: 2026-08-28 - PHCT starting baseline: `c9fcb223826f2fc8c945d894420c16a2b8ff5da0` - PHCT candidate: `v1.9.0-rc.6`, cut from protected `main` at the merge of the searchable "Also deployed by" listings ([PR #46](https://github.com/crypticpy/phct/pull/46), @@ -24,7 +24,7 @@ [rc.2 run](https://github.com/crypticpy/bchc-ai-use-case-catalog/actions/runs/32599759546): immutable tag and full SHA resolved, protected paths preserved byte-for-byte, merged at `fd7206981c58107df626f50062f08ad6aee1a0e0`); the - published BCHC demo then consumed `v1.9.0-rc.5` via [PR #14](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/14) on 2026-08-26 and is locked there pending the rc.6 update, whose ownership-contract migration (`_data/security_signals.json`) rides [BCHC PR #29](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/29) ahead of the updater rerun. + published BCHC demo then consumed `v1.9.0-rc.5` via [PR #14](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/14) on 2026-08-26. On 2026-08-28 the ownership-contract migration merged ([BCHC PR #29](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/29)), the live updater consumed `v1.9.0-rc.6` with its fail-closed contract gate proven ([run 33134382533](https://github.com/crypticpy/bchc-ai-use-case-catalog/actions/runs/33134382533)) and the machine-verified update merged after human review ([BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30), `c0826d9`), followed by the rc.6 feature adoption ([BCHC PR #31](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/31)). The post-rc.6 robustness fixes then merged to PHCT `main` ([PR #49](https://github.com/crypticpy/phct/pull/49), `af54f28`), so the stable cut now requires an `v1.9.0-rc.7` candidate and one more updater pass before promotion. - Automated code baseline: **green** - Wider-demo candidate: **no-go until parent interface polish and the remaining manual/live demo gates pass** - Stable release and BCHC handoff: **no-go until the human and live-repository gates below pass** @@ -133,15 +133,15 @@ No automated P0 or P1 defect is known at this checkpoint. | ID | Required evidence | Owner | Status | |---|---|---|---| -| RR-H01 | Review these changes and obtain green required CI plus independent human approval in PHCT and BCHC. | PHCT maintainer | In progress — the project owner authorized routine PR work, reviewed parent PRs have merged with green required checks, and BCHC rc.2 PR #4 is green. The final generated BCHC update still requires human review and merge. | -| RR-H02 | Tag an immutable PHCT release candidate, run the actual BCHC update workflow, review the checksum report and generated changes, then prove revert/rollback of the update pull request. | PHCT maintainer | Complete for rc.2 — immutable `v1.9.0-rc.2` resolved to `bb2e447`, the updater run preserved all 116 protected files, candidate PR #4 is green, and rollback evidence is retained. Repeat this gate for the final candidate and stable tag. | -| RR-H03 | Complete a real issue → pull request → media processing → review → merge → Pages deploy → notification rehearsal in both repositories. Use non-sensitive test content and remove it afterward. | Repository admins | Open | +| RR-H01 | Review these changes and obtain green required CI plus independent human approval in PHCT and BCHC. | PHCT maintainer | In progress — rc.6's machine-verified update ([BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30)) and the feature adoption ([BCHC PR #31](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/31)) merged 2026-08-28 with green required checks after human review of #30. The [PHCT PR #49](https://github.com/crypticpy/phct/pull/49) merge resets the line: the stable cut now requires an rc.7 candidate and one more human-reviewed BCHC update. | +| RR-H02 | Tag an immutable PHCT release candidate, run the actual BCHC update workflow, review the checksum report and generated changes, then prove revert/rollback of the update pull request. | PHCT maintainer | Complete for rc.6 — immutable `v1.9.0-rc.6` consumed through the live updater with the fail-closed ownership-contract gate proven ([run 33134382533](https://github.com/crypticpy/bchc-ai-use-case-catalog/actions/runs/33134382533)) before [BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30); rollback proven 2026-08-28: reverting update merge `c0826d9` restores the full `v1.9.0-rc.5` state (58 template files, lock included) touching zero deployment-owned content. Repeat for rc.7 and the stable tag. | +| RR-H03 | Complete a real issue → pull request → media processing → review → merge → Pages deploy → notification rehearsal in both repositories. Use non-sensitive test content and remove it afterward. | Repository admins | Complete 2026-08-28 — a real web-form submission became [BCHC PR #27](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/27) carrying real media (PDF deck plus generated AVIF/WebP derivatives), merged at `610c0fc`, deployed through Pages, and was verified live (entry page, media files, and `search.json`); the test entry was then removed end to end via [BCHC PR #32](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/32) and verified gone. | | RR-H04 | Name a BCHC product owner and backup technical maintainer; grant least-privilege access; update `CODEOWNERS`, `MAINTAINERS.md`, and the private contact system. | BCHC sponsor | Deferred until organizational handoff; it is not a wider-demo prerequisite. | -| RR-H05 | Correct and verify branch rules, required checks/approval, Pages environment protection, Actions permissions, secrets/variables, domain/DNS, security settings, labels, and notifications against `docs/bchc/operations-inventory.yml`. | Repository admins | In progress — repository and Pages protections, Actions permissions, selected actions, security features, and immutable parent tags/releases are hardened. Sync the exact live inventory through the final BCHC update and confirm DNS/notifications manually. | +| RR-H05 | Correct and verify branch rules, required checks/approval, Pages environment protection, Actions permissions, secrets/variables, domain/DNS, security settings, labels, and notifications against `docs/bchc/operations-inventory.yml`. | Repository admins | In progress — a fresh read-only API audit on 2026-08-28 was synced into `docs/bchc/operations-inventory.yml` (BCHC PRs [#31](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/31) and [#33](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/33)); the intentionally-unset repository variables are documented as default-on. Four admin items remain manual: require a human approval, disable Actions PR approval, protect release tags, and confirm notification delivery. | | RR-H06 | Manually test current Firefox, Safari, Edge, iOS Safari, and Android Chrome plus VoiceOver and NVDA; verify 200%/400% zoom, keyboard-only use, visible focus, forced colors, reduced motion, and representative long/empty/error content. | Accessibility reviewer | Open | -| RR-H07 | Perform the documented bad-deploy rollback, content takedown, credential-response, repository backup, and restore drills; record timestamps, participants, gaps, and corrections. | Primary and backup maintainers | Open | -| RR-H08 | Run the approved candidate on the intended Pages configuration for one business day with no unresolved P0/P1 defect and review Actions/Pages behavior before the wider demo. | Release owner | Open | -| RR-H09 | Check presentation-critical external links and contact destinations from the deployed candidate; record any intentionally unreachable or staging-only target. | BCHC content owner | Open | +| RR-H07 | Perform the documented bad-deploy rollback, content takedown, credential-response, repository backup, and restore drills; record timestamps, participants, gaps, and corrections. | Primary and backup maintainers | In progress — four drills passed with dated evidence in the operations inventory: template update (2026-08-26), repository backup/restore (2026-08-28, bundle-verified mirrors of both repositories restored and fsck-checked), bad-deploy rollback (2026-08-28, clean revert of `c0826d9`), and content takedown (2026-08-28, [BCHC PR #32](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/32)). Credential-response and owner-transfer drills remain open. | +| RR-H08 | Run the approved candidate on the intended Pages configuration for one business day with no unresolved P0/P1 defect and review Actions/Pages behavior before the wider demo. | Release owner | In progress — rc.6 is live on the intended Pages configuration with a one-business-day monitor running since 2026-08-28T03:35Z; no P0/P1 defect observed so far. Re-scope the soak once rc.7 is consumed. | +| RR-H09 | Check presentation-critical external links and contact destinations from the deployed candidate; record any intentionally unreachable or staging-only target. | BCHC content owner | Complete for rc.6 — 187 links checked from the deployed candidate on 2026-08-28. One live finding: the three "Ask in the open" links 404 until repository Discussions are enabled (or `contact.ask_in_open` is turned off). The sample entries' intentionally unreachable targets (`example.org`, `github.com/example`) are recorded as such. | The authenticated 2026-08-22 API audit confirmed that both repositories are public, use `main`, and publish Pages through Actions with HTTPS. Both now enforce pull requests, strict required From 782f9e35d994ff961043622c94c401073052fcb9 Mon Sep 17 00:00:00 2001 From: Beyond <46542494+crypticpy@users.noreply.github.com> Date: Thu, 27 Aug 2026 23:20:44 -0500 Subject: [PATCH 2/3] docs: qualify the rollback proof and takedown rehearsal as partial MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The rc.6 rollback evidence is the offline revert only — the live revert-PR path stays open under RR-H07 — and BCHC PR #32 rehearsed an ordinary unpublish, not the protected-data history purge. Say so. Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_014sAVayAT2tkQ7p9U2o9CsD --- docs/release-readiness-status.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/release-readiness-status.md b/docs/release-readiness-status.md index cb8bfb2..b7fa7e8 100644 --- a/docs/release-readiness-status.md +++ b/docs/release-readiness-status.md @@ -134,12 +134,12 @@ No automated P0 or P1 defect is known at this checkpoint. | ID | Required evidence | Owner | Status | |---|---|---|---| | RR-H01 | Review these changes and obtain green required CI plus independent human approval in PHCT and BCHC. | PHCT maintainer | In progress — rc.6's machine-verified update ([BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30)) and the feature adoption ([BCHC PR #31](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/31)) merged 2026-08-28 with green required checks after human review of #30. The [PHCT PR #49](https://github.com/crypticpy/phct/pull/49) merge resets the line: the stable cut now requires an rc.7 candidate and one more human-reviewed BCHC update. | -| RR-H02 | Tag an immutable PHCT release candidate, run the actual BCHC update workflow, review the checksum report and generated changes, then prove revert/rollback of the update pull request. | PHCT maintainer | Complete for rc.6 — immutable `v1.9.0-rc.6` consumed through the live updater with the fail-closed ownership-contract gate proven ([run 33134382533](https://github.com/crypticpy/bchc-ai-use-case-catalog/actions/runs/33134382533)) before [BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30); rollback proven 2026-08-28: reverting update merge `c0826d9` restores the full `v1.9.0-rc.5` state (58 template files, lock included) touching zero deployment-owned content. Repeat for rc.7 and the stable tag. | +| RR-H02 | Tag an immutable PHCT release candidate, run the actual BCHC update workflow, review the checksum report and generated changes, then prove revert/rollback of the update pull request. | PHCT maintainer | Complete for rc.6 — immutable `v1.9.0-rc.6` consumed through the live updater with the fail-closed ownership-contract gate proven ([run 33134382533](https://github.com/crypticpy/bchc-ai-use-case-catalog/actions/runs/33134382533)) before [BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30); offline rollback proof retained 2026-08-28: reverting update merge `c0826d9` restores the full `v1.9.0-rc.5` state (58 template files, lock included) touching zero deployment-owned content — the live revert-PR path stays open under RR-H07. Repeat for rc.7 and the stable tag. | | RR-H03 | Complete a real issue → pull request → media processing → review → merge → Pages deploy → notification rehearsal in both repositories. Use non-sensitive test content and remove it afterward. | Repository admins | Complete 2026-08-28 — a real web-form submission became [BCHC PR #27](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/27) carrying real media (PDF deck plus generated AVIF/WebP derivatives), merged at `610c0fc`, deployed through Pages, and was verified live (entry page, media files, and `search.json`); the test entry was then removed end to end via [BCHC PR #32](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/32) and verified gone. | | RR-H04 | Name a BCHC product owner and backup technical maintainer; grant least-privilege access; update `CODEOWNERS`, `MAINTAINERS.md`, and the private contact system. | BCHC sponsor | Deferred until organizational handoff; it is not a wider-demo prerequisite. | | RR-H05 | Correct and verify branch rules, required checks/approval, Pages environment protection, Actions permissions, secrets/variables, domain/DNS, security settings, labels, and notifications against `docs/bchc/operations-inventory.yml`. | Repository admins | In progress — a fresh read-only API audit on 2026-08-28 was synced into `docs/bchc/operations-inventory.yml` (BCHC PRs [#31](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/31) and [#33](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/33)); the intentionally-unset repository variables are documented as default-on. Four admin items remain manual: require a human approval, disable Actions PR approval, protect release tags, and confirm notification delivery. | | RR-H06 | Manually test current Firefox, Safari, Edge, iOS Safari, and Android Chrome plus VoiceOver and NVDA; verify 200%/400% zoom, keyboard-only use, visible focus, forced colors, reduced motion, and representative long/empty/error content. | Accessibility reviewer | Open | -| RR-H07 | Perform the documented bad-deploy rollback, content takedown, credential-response, repository backup, and restore drills; record timestamps, participants, gaps, and corrections. | Primary and backup maintainers | In progress — four drills passed with dated evidence in the operations inventory: template update (2026-08-26), repository backup/restore (2026-08-28, bundle-verified mirrors of both repositories restored and fsck-checked), bad-deploy rollback (2026-08-28, clean revert of `c0826d9`), and content takedown (2026-08-28, [BCHC PR #32](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/32)). Credential-response and owner-transfer drills remain open. | +| RR-H07 | Perform the documented bad-deploy rollback, content takedown, credential-response, repository backup, and restore drills; record timestamps, participants, gaps, and corrections. | Primary and backup maintainers | In progress — template update (2026-08-26) and repository backup/restore (2026-08-28, bundle-verified mirrors of both repositories restored and fsck-checked) passed; rollback and content takedown are partial: the offline revert of `c0826d9` is proven but the live revert-PR path is deferred to the rc.7/stable window, and [BCHC PR #32](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/32) rehearsed an ordinary unpublish while the protected-data history purge of `docs/incidents.md` remains unrehearsed. Credential-response and owner-transfer drills remain open. | | RR-H08 | Run the approved candidate on the intended Pages configuration for one business day with no unresolved P0/P1 defect and review Actions/Pages behavior before the wider demo. | Release owner | In progress — rc.6 is live on the intended Pages configuration with a one-business-day monitor running since 2026-08-28T03:35Z; no P0/P1 defect observed so far. Re-scope the soak once rc.7 is consumed. | | RR-H09 | Check presentation-critical external links and contact destinations from the deployed candidate; record any intentionally unreachable or staging-only target. | BCHC content owner | Complete for rc.6 — 187 links checked from the deployed candidate on 2026-08-28. One live finding: the three "Ask in the open" links 404 until repository Discussions are enabled (or `contact.ask_in_open` is turned off). The sample entries' intentionally unreachable targets (`example.org`, `github.com/example`) are recorded as such. | From 2af276091e5cae5d8bb0c1499868ecb7a4dfd30b Mon Sep 17 00:00:00 2001 From: Beyond <46542494+crypticpy@users.noreply.github.com> Date: Thu, 27 Aug 2026 23:31:20 -0500 Subject: [PATCH 3/3] docs: sync the automated updater rows to rc.6 and scope RR-H03 honestly MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The automated-evidence table still said 'Pass for rc.4' while the new summary cited the rc.6 updater run — record the rc.6 rehearsal (fail- closed contract gate, machine-verified BCHC PR #30, lock at c0826d9) in the exact-rehearsal and protected-content rows. RR-H03 drops back to in progress: only the BCHC leg ran; the PHCT-side rehearsal and the notification confirmation are still open. Found by Codex review on this pull request. Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_014sAVayAT2tkQ7p9U2o9CsD --- docs/release-readiness-status.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/release-readiness-status.md b/docs/release-readiness-status.md index b7fa7e8..81f3d5b 100644 --- a/docs/release-readiness-status.md +++ b/docs/release-readiness-status.md @@ -53,7 +53,7 @@ that updater succeeds. | Live pull-request CI | Pass at reviewed heads | The rc.2 implementation retained the full Validate, coverage, preset matrix, scale/Chrome, supply-chain, CodeQL, workflow-lint, pa11y, assistive-flow, and desktop/mobile Lighthouse gates. PHCT PRs #17/#20 passed protected CI and review. The generated metrics head `9a486f6` then passed all seven ruleset-required contexts plus browser quality through trusted dispatches before PR #19 was intentionally closed unmerged. Every check on BCHC rc.2 update head `2017cda` is green. | | PHCT release verification | Pass | `npm run verify` completed under the exact-pinned toolchain at release-record commit `ce46cbdc5cdddda78878cb367b119fe9ef440aa1`: 796 Node tests across 3 suites, 233 Ruby tests with 578 assertions, 109 build-matrix tests across 6 suites, plus lint, formatting, coverage, generated-file, data/front-matter, license, security-exception, SBOM, image-derivative, production CSS, Jekyll production build, and built-site link gates. The final release-record head differs from that commit only by this evidence sentence, and every protected CI context runs on the exact head in the release pull request. | | Code coverage | Pass locally and in exact-head CI | Pinned runtime coverage passed reviewed regression floors: complete loaded Node production code 84.81% lines / 75.94% branches / 80.07% functions; focused security parsers 90.54% / 80.55% / 93.59%; updater and release-lock logic 72.79% / 77.39% / 87.76%; loaded Ruby production code 93.29% lines / 85.13% branches / 77.69% methods. Six Ruby CLI sources exercised by subprocess or integration gates are explicitly inventoried, and any new unrepresented Ruby source fails the gate. Validate retains JSON and raw TAP artifacts even when a floor fails. | -| Exact BCHC update rehearsal | Pass for rc.4 | The real rc.4 updater run resolved `v1.9.0-rc.4` to full SHA `c41149eaacab353c82403477bf0c5b2f26a48650`, preserved the protected BCHC paths, regenerated BCHC-owned deployment output, and opened candidate [PR #7](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/7) at `c4ac0d5de1921f8047cabbe3264b6cda517c52b2`. The complete downstream required-check set was green, and the PR merged at `fd7206981c58107df626f50062f08ad6aee1a0e0`, locking the published BCHC demo to `v1.9.0-rc.4`. The rc.2 rehearsal ([PR #4](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/4) at `2017cda8b731ae52103c6b44232496d2c2fc8662`, 116 protected files byte-identical) remains the recorded checksum baseline. Repeat the same rehearsal and checksum gate for the rc.6 update. | +| Exact BCHC update rehearsal | Pass for rc.6 | The real rc.4 updater run resolved `v1.9.0-rc.4` to full SHA `c41149eaacab353c82403477bf0c5b2f26a48650`, preserved the protected BCHC paths, regenerated BCHC-owned deployment output, and opened candidate [PR #7](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/7) at `c4ac0d5de1921f8047cabbe3264b6cda517c52b2`. The complete downstream required-check set was green, and the PR merged at `fd7206981c58107df626f50062f08ad6aee1a0e0`, locking the published BCHC demo to `v1.9.0-rc.4`. The rc.2 rehearsal ([PR #4](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/4) at `2017cda8b731ae52103c6b44232496d2c2fc8662`, 116 protected files byte-identical) remains the recorded checksum baseline. The rc.6 update repeated the rehearsal live on 2026-08-28: the updater first failed closed on the pending ownership-contract migration ([run 33134382533](https://github.com/crypticpy/bchc-ai-use-case-catalog/actions/runs/33134382533)), passed once [BCHC PR #29](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/29) merged, and opened the machine-verified [BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30), which merged after human review at `c0826d9776747c2838daaba91991628e4301f7bf`, locking the published demo to `v1.9.0-rc.6`. Repeat the same rehearsal and checksum gate for rc.7 and the stable update. | | Dependency vulnerabilities | Pass | The exact-head Supply chain job passed parsed npm and Bundler audits with zero active exceptions; critical or unidentified findings cannot be waived, and stale/expired/unused exceptions fail closed. | | Software bill of materials | Pass | The current lockfiles produce 326 CycloneDX components and 327 globally unique references including the application. Repeated npm package/version rows retain every lock path, Ruby platforms have qualified PURLs, and duplicate references fail generation. | | Secret scanning | Pass | Gitleaks v8.30.1 found no leaks in either working tree or the complete history of either repository. | @@ -64,7 +64,7 @@ that updater succeeds. | Scale and interaction matrix | Pass at measured ceiling | The rc.6-head scale job completed deterministic 0, 1, 10, 100, 500, and 1,000-entry builds, and real Chrome at 390×844/4× CPU drove search, filtering, sorting, and compare at every size named in `interaction_entries` — including the worker-built index measured cold and warm — against each size's enforced `scale_budgets` in `quality/performance-budgets.json`. All enforced release budgets passed through the measured 1,000-entry ceiling; the measured table is maintained in `docs/search.md`. | | Supported 100-entry target | Pass | Linux CI measured a 13,004 ms build under `/phct-performance`, 523 files/20,861,404 bytes, 61,182-byte gzip catalog, 8,894 DOM nodes, 24,914-byte gzip CSS, 40,870-byte gzip catalog JavaScript, 16,913-byte gzip search data, and 20,622-byte comparison data. Chrome measured 177.0 ms warm-search p95 and 51.5 ms filter p95 against reviewed 250/100 ms limits; BCHC's real project path measured 88.2/15.2 ms locally. | | Higher-scale characterization | Informational finding | At 500 entries the Linux run built in 63.1 seconds with an 83,990-byte search payload, while the catalog reached 155,156 bytes gzip and 36,860 DOM nodes. At 1,000 entries it built in 166.7 seconds and produced a 108,558,639-byte artifact plus a 264,761-byte/71,819-node catalog. Interaction latency is now budgeted and enforced to 1,000 entries (see the scale row above), and off-screen entry cards defer rendering via `content-visibility`; the page-weight and DOM-size characterization here still stands, so pagination or incremental rendering remains the recorded requirement before claiming full support above 100 entries. | -| Protected downstream content | Pass in real tagged update | The machine-readable ownership manifest, ordered merge rules, protected-file checksums, generated-file regeneration, and immutable parent lock protected all 116 BCHC files in the real `v1.9.0-rc.2` updater run and generated PR #4. Repeat the same checksum gate for the final candidate and stable update. | +| Protected downstream content | Pass in real tagged update | The machine-readable ownership manifest, ordered merge rules, protected-file checksums, generated-file regeneration, and immutable parent lock protected all 116 BCHC files in the real `v1.9.0-rc.2` updater run and generated PR #4. The real `v1.9.0-rc.6` updater run repeated the gate on 2026-08-28 — checksum-verified protected files in the machine-generated [BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30), after the fail-closed contract check in [run 33134382533](https://github.com/crypticpy/bchc-ai-use-case-catalog/actions/runs/33134382533) proved the gate refuses an unmigrated contract. Repeat the same checksum gate for rc.7 and the stable update. | Local Lighthouse and scale reports were written under `/tmp` and are intentionally ephemeral. The release candidate's GitHub Actions runs must retain their reports and SBOM as reviewable CI @@ -135,7 +135,7 @@ No automated P0 or P1 defect is known at this checkpoint. |---|---|---|---| | RR-H01 | Review these changes and obtain green required CI plus independent human approval in PHCT and BCHC. | PHCT maintainer | In progress — rc.6's machine-verified update ([BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30)) and the feature adoption ([BCHC PR #31](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/31)) merged 2026-08-28 with green required checks after human review of #30. The [PHCT PR #49](https://github.com/crypticpy/phct/pull/49) merge resets the line: the stable cut now requires an rc.7 candidate and one more human-reviewed BCHC update. | | RR-H02 | Tag an immutable PHCT release candidate, run the actual BCHC update workflow, review the checksum report and generated changes, then prove revert/rollback of the update pull request. | PHCT maintainer | Complete for rc.6 — immutable `v1.9.0-rc.6` consumed through the live updater with the fail-closed ownership-contract gate proven ([run 33134382533](https://github.com/crypticpy/bchc-ai-use-case-catalog/actions/runs/33134382533)) before [BCHC PR #30](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/30); offline rollback proof retained 2026-08-28: reverting update merge `c0826d9` restores the full `v1.9.0-rc.5` state (58 template files, lock included) touching zero deployment-owned content — the live revert-PR path stays open under RR-H07. Repeat for rc.7 and the stable tag. | -| RR-H03 | Complete a real issue → pull request → media processing → review → merge → Pages deploy → notification rehearsal in both repositories. Use non-sensitive test content and remove it afterward. | Repository admins | Complete 2026-08-28 — a real web-form submission became [BCHC PR #27](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/27) carrying real media (PDF deck plus generated AVIF/WebP derivatives), merged at `610c0fc`, deployed through Pages, and was verified live (entry page, media files, and `search.json`); the test entry was then removed end to end via [BCHC PR #32](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/32) and verified gone. | +| RR-H03 | Complete a real issue → pull request → media processing → review → merge → Pages deploy → notification rehearsal in both repositories. Use non-sensitive test content and remove it afterward. | Repository admins | In progress — the BCHC leg completed 2026-08-28: a real web-form submission became [BCHC PR #27](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/27) carrying real media (PDF deck plus generated AVIF/WebP derivatives), merged at `610c0fc`, deployed through Pages, and was verified live (entry page, media files, and `search.json`); the test entry was then removed end to end via [BCHC PR #32](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/32) and verified gone. The PHCT-side rehearsal and the notification-delivery confirmation remain open. | | RR-H04 | Name a BCHC product owner and backup technical maintainer; grant least-privilege access; update `CODEOWNERS`, `MAINTAINERS.md`, and the private contact system. | BCHC sponsor | Deferred until organizational handoff; it is not a wider-demo prerequisite. | | RR-H05 | Correct and verify branch rules, required checks/approval, Pages environment protection, Actions permissions, secrets/variables, domain/DNS, security settings, labels, and notifications against `docs/bchc/operations-inventory.yml`. | Repository admins | In progress — a fresh read-only API audit on 2026-08-28 was synced into `docs/bchc/operations-inventory.yml` (BCHC PRs [#31](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/31) and [#33](https://github.com/crypticpy/bchc-ai-use-case-catalog/pull/33)); the intentionally-unset repository variables are documented as default-on. Four admin items remain manual: require a human approval, disable Actions PR approval, protect release tags, and confirm notification delivery. | | RR-H06 | Manually test current Firefox, Safari, Edge, iOS Safari, and Android Chrome plus VoiceOver and NVDA; verify 200%/400% zoom, keyboard-only use, visible focus, forced colors, reduced motion, and representative long/empty/error content. | Accessibility reviewer | Open |