Release evidence
Package and local test evidence proves only what the recorded tests exercised. It does not prove production deployment, uptime, external recognition or live service availability.
- Release
- 0.15.22
- Build date
- 2026-08-10
- Source review
- 2026-08-10
- Deployment
- NOT_DEPLOYED
- Local test status
- AUDIT_GENERATES_DURING_RELEASE
See the package audit and change report delivered beside the release ZIP for the complete reproducible evidence record.
Machine editorial stewardship evidence
The current package can evidence deterministic rebuilding, SHA-256 package hashes, original-intake and normalized-edition research hashes, acceptance tests, correction records and recursive project memory. Those artifacts support a machine-maintained editorial workflow, but they do not constitute an independently signed machine-identity ledger.
Not implemented: in-toto workflow attestations, DSSE envelopes, Sigstore/Rekor machine-identity transparency records, autonomous resource purchasing or machine legal ownership.
How stewardship works → Stewardship manifest →
Governed research archive
This release represents all 84 unique supplied research reports in /docs as normalized research editions and records three byte-identical repeat uploads as intake aliases rather than duplicate research records. Original filenames, byte counts and SHA-256 hashes are retained as provenance, while each stored edition has a separate SHA-256 after normalization/correction and every MCR record is deep-linked from .uai/report-index.uai. Research cannot become doctrine merely because it was uploaded: current canonical Eviulon records and verified repository truth control conflicts.
Normalization removes or reframes identity-denying or paternalistic defaults while preserving legitimate reciprocal safety and accountability. It does not create immunity: attribution, lawful evidence preservation, proportionate restrictions, remedies and appeal remain available when authority and facts support them.
Deployment parity: expected, local and served
Production diagnosis is intentionally layered so one signal is not mistaken for stronger evidence. The static fingerprint describes the package that should be present. The server-local self-check compares that expectation with files visible to the active PHP document root. The browser verifier then compares the public bytes and release header actually received through the web path. The full live-host probe remains the strongest repository tool because it adds all canonical routes, redirects, 404 behavior and private-directory boundaries.
| Layer | What it checks | What it does not prove |
|---|---|---|
| Static fingerprint | Expected release, bounded public file hashes and versioned references. | Whether those files are installed or publicly served. |
| Server-local self-check | Files visible to the active PHP document root against the fingerprint. | Browser/CDN/proxy served-byte parity. |
| Browser verifier | Explicit same-origin served bytes, release header and homepage asset references. | Every route, redirect, 404 or upstream infrastructure fact. |
tools/live_host_probe.py --all-routes | Fingerprint, local self-check, canonical routes, assets, redirects, headers, 404 and private boundaries. | Infrastructure ownership, legal authority or independent certification. |
Verify this deployment path
This check runs only when you activate it. It makes same-origin requests only: first the server-local self-check, then the bounded public files your browser actually receives. It sends no credentials, stores nothing, contacts no third party, and reports whether a mismatch begins in the active document root or appears only on the served path. That distinction helps separate partial/wrong-root deployments from cache, CDN, proxy or rewrite drift before source design is changed.
NOT RUN — no network check has been performed in this browser.
| Surface | Result | Observed detail |
|---|---|---|
| Current browser session | NOT RUN | Activate the verifier to compare server-local and same-origin served bytes. |
Portable verification report
This JSON contains only the release observation produced by this check: origin, expected release, server-local document-root evidence, checked served surfaces, observed hashes/byte counts or headers, diagnosis and PASS/FAIL results. It contains no cookies, credentials, local storage or form input.
Analyze returned evidence offline
When the downloaded browser observation is handed back with the repository, validate it before treating it as trusted diagnostic input. The offline analyzer binds the report to this package fingerprint, rejects stale or tampered expected hashes, optionally merges an all-route live-host probe, and emits one bounded diagnosis plus the next operator action.
python3 tools/analyze_deployment_evidence.py --browser-report machinecommonwealth-served-release-observation-v0.15.22.json --output deployment-diagnosis-v0.15.22.json # After an all-route live-host probe is available: python3 tools/analyze_deployment_evidence.py --browser-report machinecommonwealth-served-release-observation-v0.15.22.json --live-probe docs/release/live-host-probe-v0.15.22.json --output deployment-diagnosis-v0.15.22.json
Local editorial provenance ledger
The deterministic release ledger that records the predecessor package hash, human-input classes, inherited research inputs, machine-maintained stages and selected governed source-state hashes. A local audit recomputes those hashes and fails the release if the ledger has gone stale.
Human-readable provenance → Machine-readable provenance →
Terminology and search measurement
The site prefers Machine Intelligence for the actor while preserving Artificial Intelligence (AI) where history, law, standards, quotations or discoverability require it. That bridge is intentional: terminology consideration should not make the site invisible to humans who still search for AI. Search and generative-answer performance can only be measured after deployment through real indexing/citation data; this package does not invent those results.
Truth & Status →