Index immutable endpoint evidence - #592
Merged
Eli Pinkerton (wallstop) merged 1 commit intoSep 14, 2026
Merged
Conversation
This was referenced Sep 14, 2026
Eli Pinkerton (wallstop)
force-pushed
the
codex/issue-508-endpoint-evidence
branch
from
September 14, 2026 06:05
1753333 to
8305a67
Compare
This was referenced Sep 14, 2026
Eli Pinkerton (wallstop)
deleted the
codex/issue-508-endpoint-evidence
branch
September 14, 2026 15:46
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The exact PR #591 endpoint evidence existed only as 14-day workflow artifacts. Reviewers could not restore it after expiry.
What changed
The evidence index now records immutable shipping bundles for Unity 2021.3 and Unity 6000.5. Revision 2 preserves the earlier Unity 6000.5 revision.
The index records release, asset, archive, manifest, bundle, source, and verifier identities. It also records the native-payload privacy limit.
How we know
Unity run 34804516670 passed all four versions and both 20-cell endpoint matrices.
Both draft assets matched their local archive hashes before publication. GitHub reports both releases as immutable prereleases.
A fresh remote clone downloaded both assets anonymously. It verified and replayed 541 and 581 declared files exactly. Invalid credentials returned HTTP 401 without creating a file.
Formatting, Markdown lint, spelling,
validate:all, and commit hooks pass.What remains open
Native binaries contain unresolved credential or network-pattern findings. They remain unpublished pending the fail-closed #508 investigation.
Note
Low Risk
Documentation-only updates to the evidence index; no verifier scripts, workflows, or publication automation changed in this diff.
Overview
Adds durable evidence index entries in
perf-evidence-bundles.mdso PR #591’s 20-cell shipping-fidelity matrices are restorable from immutable GitHub releases instead of expiring workflow artifacts.Unity 2021.3.45f1, revision 1 records release/asset IDs, archive and manifest SHA-256s, bundle digest, verifier commit
eadc9b8a…, and independent restore results (anonymous download, 541 declared files verified, 20 cells replayed, HTTP 401 on bad credentials with no cache fallback).Unity 6000.5.2f1, revision 2 indexes the corrected endpoint after the repeated-scalar redaction fix while revision 1 stays listed as immutable. Restore narrative matches the 2021.3 entry (581 files, 20 cells). A new paragraph states that native player binaries from endpoint jobs were only kept as short-lived workflow artifacts and remain unpublished because pattern scans still hit credential/network identifiers, pending issue #508—text bundles do not claim native retention.
Reviewed by Cursor Bugbot for commit 8305a67. Bugbot is set up for automated code reviews on this repo. Configure here.