CQ-SAT/GCC v0.19.0
Fixed external production-evidence gates
CQ-SAT/GCC v0.19.0 makes the remaining route to a production claim measurable and resistant to moving the goalposts.
It defines:
- independence and competency requirements for security and technical reviewers
- minimum adversarial attack reproduction and semantic-review scope
- a cohort of at least two embedded-product organisations, three real RTL projects, two domains, and 30 reviewed configurations
- minimum SAFE, UNSAFE, and expected-failure coverage
- independent oracle comparison, zero unresolved result disagreements, complete failure accounting, replay, repeatability, operator exercises, and independent sign-off
- a canonical UTF-8 CSV evidence-register contract with digest, enum, unit, empty-field, denominator, confidentiality, and spreadsheet-injection rules
The evidence register remains deliberately header-only: no customer, assessor, or pilot result has been invented.
All CI, 67 Rust tests, 25,000 deterministic parser mutations, current/historical RTL corpus, independent oracle, isolation profile, operations qualification, and RustSec audit checks passed. CQ-SAT/GCC remains a research preview until the external protocol is actually satisfied.