Skip to content

CQ-SAT/GCC v0.20.0

Choose a tag to compare

@kabudu kabudu released this 17 Jul 21:59
f72de53

Machine-enforced external production gate

CQ-SAT/GCC v0.20.0 turns the fixed v0.19 external-evidence protocol into a fail-closed executable check.

The checker enforces:

  • canonical injection-resistant register syntax and SHA-256 evidence fields
  • at least seven security-review and three technical-review cases
  • at least two organisations, three real projects, two domains, two workers, and 30 partner configurations
  • minimum SAFE, UNSAFE, and expected-failure coverage
  • expected/CQ/oracle agreement and exact result/exit semantics
  • positive runtime/memory evidence, repeatability, validated bundles, witness replay, and partner triage
  • zero open high/critical findings and complete independent attestations
  • annotated release tags that peel to the exact attested Git commit

CI exercises a complete synthetic passing package and rejects disagreement, exit mismatch, missing replay, unresolved rows, spreadsheet injection, failed security assessment, invalid date, undersized cohorts, symlinks, lightweight tags, and tag/commit mismatch. Synthetic fixtures never enter the canonical register.

All product, Linux portability, RTL corpus, isolation, independent oracle, mutation, operations, and RustSec checks passed. The public register remains header-only, so CQ-SAT/GCC remains a research preview until real independent and partner evidence satisfies this gate.