v10.65 - Proof Reachability and Authenticated Evidence
v10.65 — Proof Reachability and Authenticated Evidence
This release makes governed Goals closable at their explicitly selected reachable proof layer without weakening an explicitly selected live terminal gate.
Highlights
- Evaluates proposed Goal/plan done points for actual closability before they become binding, then records required/current/successor proof layers and route prerequisites.
- Closes source/code Goals at appropriate reachable source/non-live proof unless the user or checked governed authority explicitly selected live acceptance.
- Prevents generic completion wording, operational capability names, or assistant inference from turning authenticated/deployed/installed/restarted Product proof into a current Goal blocker.
- Repairs an assistant-authored infeasible Goal/plan done point in place when it was never explicitly selected, preserving reached proof and moving the impossible operation to successor scope without a replacement Goal or retry loop.
- Reconciles the task list before closeout and immediately after boundary repair: satisfied implementation and source/non-live checks close first, while optional rendered/live observation becomes an unselected successor task.
- Stops explicitly required but unavailable live proof as a visible blocker with a resume condition and
NO_RETRY_UNTIL_CHANGE, rather than retrying in a loop. - Adds authenticated/private capability preflight before access attempts.
- Stops unchanged retries after one bounded evidence-backed correction when the mechanism still cannot authenticate.
- Clarifies that a guest/login response or
401means required authentication was not established, while403means refusal without identifying authentication versus authorization as the cause. - Defines bounded proof for screenshots, Rendered HTML, rendered text/semantic witnesses, sanitized exports, and authenticated harness results.
- Preserves the active Runtime Rule inventory at exactly 19.
Verification
- Focused doctrine, scenario, matrix, coverage, triad, governance, allowlist, protected-byte, mode, link, and README checks passed.
- Bash and PowerShell installer fixture suites passed.
- Patch timeline regression suite passed: 32/32.
- The governed P149 Patch inventories as compliant.
- Disposable installation passed with 19/19 byte-and-mode parity, identical second-pass state, and unrelated-file preservation.
- Independent doctrine and release/no-drift reviews passed.
The annotated v10.65 tag and this Release identify the same verified candidate commit. Earlier tags and Releases remain immutable.