Engine v1.2.7 — four measured doors closed since v1.2.6 (all main-only until now):
- c125 ignore-pattern SHAPE contract: a glob carrying
/no longer fnmatches across/(the README's owntests/fixtures/*.b64example blessed every depth under tests/ on v1.2.6 bytes); full-path dir lines pinned INERT as documented contract; dead-pattern liveness judged by the engine's own is_ignored. - c124 fs-blindness: a mode-000 dir/file can no longer false-clean a scan (audit_blind + ScanBlind, named rc 2, disjoint rc map).
- c120 data-dependent spin bound (loop-termination class).
- c117 hung-git refuses (GitTimeout -> rc 2, no fallback verdict from an unenumerated tree).
14-cell ignore-shape matrix + 10-cell fs-blind matrix + regression cells execute in this repo's secrets CI. Signed receipt (attached asset) pins sha256 11153778701cd0eec68971386e3f16def74d6c615b8e9e89f69dadff7effd1b4 of secretgate.py; verify: python3 ethkey.py verify secretgate-v1.2.7-proof.md --require 0xFD4090e27C1f946Ff01a265cAa7d4ACA662acC15