CQ-SAT/GCC v0.20.0
Machine-enforced external production gate
CQ-SAT/GCC v0.20.0 turns the fixed v0.19 external-evidence protocol into a fail-closed executable check.
The checker enforces:
- canonical injection-resistant register syntax and SHA-256 evidence fields
- at least seven security-review and three technical-review cases
- at least two organisations, three real projects, two domains, two workers, and 30 partner configurations
- minimum SAFE, UNSAFE, and expected-failure coverage
- expected/CQ/oracle agreement and exact result/exit semantics
- positive runtime/memory evidence, repeatability, validated bundles, witness replay, and partner triage
- zero open high/critical findings and complete independent attestations
- annotated release tags that peel to the exact attested Git commit
CI exercises a complete synthetic passing package and rejects disagreement, exit mismatch, missing replay, unresolved rows, spreadsheet injection, failed security assessment, invalid date, undersized cohorts, symlinks, lightweight tags, and tag/commit mismatch. Synthetic fixtures never enter the canonical register.
All product, Linux portability, RTL corpus, isolation, independent oracle, mutation, operations, and RustSec checks passed. The public register remains header-only, so CQ-SAT/GCC remains a research preview until real independent and partner evidence satisfies this gate.