# Integrated review corrections — current evidence

18 September 2026. The four baseline reviews and technical corrections are recorded in [integrated dispositions](../reviews/INTEGRATED-DISPOSITIONS.md). Current complete checks pass **644 Python methods**, **206 native Node tests** and **57 fresh installed flows**. These are separate overlapping evidence counts, not a compliance score. All four technical findings have exact-source follow-ups; no external certification is claimed.

Current records: [Python](integrated-python-tests.txt), [Node](integrated-node-tests.txt), [installation](integrated-installed-checks.json), [wheel/source inventory](integrated-wheel-inventory.json), [environment](integrated-environment.json) and [47 requirements / 180 evidence links](integrated-specification-checks.json). Current schemas and structural fixture bytes are unchanged from the M6 structural checks below. The fresh wheel SHA-256 is `e9aa31ff3ad84ac78ee76df6c98aebb3dac133bf1997b82b9a7547a3a720342a`.

The unchanged original review inventory is preserved in [integrated-review-baseline-manifest.json](integrated-review-baseline-manifest.json). Earlier M6 logs below predate the four implementation corrections and must not be treated as the current source run. Release operations and final publication remain open in [the audit](../docs/RELEASE-AUDIT.md).

--- Earlier milestone evidence (historical status at each checkpoint) ---

# M6 consolidated review edition — current full-source evidence

18 September 2026. [Release audit](../docs/RELEASE-AUDIT.md) and [consolidated specification](../SPECIFICATION.md) now identify the exact current contracts, 47 numbered requirements and explicit source/result mappings. The requested integrated four-perspective review is still incomplete. A verified private security intake and final candidate publication remain operational gates. This checkpoint is not RC approval.

- [Complete Python run](m6-python-tests.txt): **625 methods passed** in 48.803 seconds, including current actual free/paid/storage/asset clients and the new asset acquisition-timing correction. Asset wire evidence now comprises ten methods and 24 fresh native processes in `m6-asset-wire-run/`; paid/free/storage outputs have their own `m6-*-wire-run/` directories.
- [Complete Node run](m6-node-tests.txt): **191 tests passed** across seven suites. Its counts overlap with processes invoked by the Python harness.
- [Current profiles](m6-profile-schemas.json): **268 structural cases** across 16 schemas (153 positive, 115 negative). [Native policy](m6-policy-schema.json): four actual example policies and three structural negatives. [Historical wire compatibility](m6-legacy-schemas.json): 17 schemas with 18 positive/22 negative actual reference-output cases. These structural checks do not certify semantics.
- [Fresh installed flow](m6-installed-checks.json): **57 checks passed**, 17 direct-free + 17 delegated-free + 23 synthetic-paid, outside the source tree with usersite/source/test-fixture imports excluded. [Wheel inventory](m6-wheel-inventory.json) checks every packaged source/schema/fixture against the current tree and installed bytes, not only the eight CLI modules. [Environment](m6-environment.json) retains exact dependency/TLS/SQLite versions. The fresh wheel SHA is `3bf9c4ddca8a286c362bbbd97d6deaa52a05392067903c3d6c5818e2a819941d`; it is an internal review build, not a public download.
- [Specification checks](m6-specification-checks.json): **47 requirements, 169 explicit evidence links, 17 current schema documents and 230 listed definitions**. The check confirms exact rendered prose, source methods and executed results. It is not an independent judgment that the mapped tests cover every possible implementation.

The asset client's earlier post-fetch timestamp was corrected to pre-acquisition time. Slow acquisition, cache age/warnings and stale history retention are now rejected; actual HTTPS tests reproduce these boundaries. Python operational code and wire schemas were unchanged. The final full-source run supersedes the earlier 571-method baseline for current validation; old milestone logs retain their historical meaning. Subsequent edits are editorial/verification inventory tools, not service behavior changes.

The [final source/evidence inventory](m6-release-checks.json) records exact hashes, link checks, source compatibility and remaining gates. The [prepared reviewer brief](../reviews/INTEGRATED-REVIEW-BRIEF.md) requests bounded technical/data/research/product assessment against this exact edition; none is represented as approved. The public draft-2 release and immutable r6 download remain untouched.

--- Earlier milestone evidence (historical status at each checkpoint) ---

# M5 independent native asset graph — current evidence

18 September 2026. The [native asset guide](../docs/INDEPENDENT-ASSET-CLIENT.md) records complete graph verification, actual Python HTTPS publication and independent persistent trust. M5 now has installed operator, independent paid-flow and independent native-asset evidence. M6 normative consolidation, complete integrated release validation, four-perspective review and publication remain required. No public release changes.

The [final standalone Node regression](asset-node-regressions.txt) passes **191 tests** across seven suites: 51 new asset cases plus the previous 140. The [final wire regression](asset-node-wire-regressions.txt) passes **21 Python harness methods**: nine new asset, eight existing paid and four existing free/storage methods. The new [asset harness](../tests/test_asset_node.py) executes **22 fresh native processes** across nine [saved scenario reports](asset-node-wire-run/direct-lifecycle.json). All nine scenarios use certificate-verified HTTPS without Authorization or Cookie headers. Counts overlap with preceding evidence and are not additive. `asset-node-wire-tests.txt` is an earlier eight-method intermediate run; the 21-method regression contains the final ninth method and additional same-revision mutation check.

The independent verifier checks closed syntax, original JWS payload bytes, exact publication scope/key/issuer/delegation, independent current and historical origin trust, every declared ancestor, immutable versions, representation identities and copy correlations. It rejects missing/extra/substituted dependencies and excessive depth without truncation. Current compromise remains disqualifying after key removal/alias and restart. Retirement preserves qualified historical evidence. Identity and explicitly decoded gzip bytes are compared independently; local matches grant no access and prove no remote receipt, model use or derivation computation.

Actual wire scenarios cover direct and delegated two-version graphs, a graph spanning two independently acquired publisher origins, separately provisioned historical pins, original-publication substitution, missing ancestor, same-revision byte change, retirement/rollback, compromise introduced during byte retrieval and retained after key alias, immutable-version redefinition after restart, redirects, origin outage and wrong decoded bytes. The cross-origin graph is also independently accepted by the Python verifier. The initial cross-origin fixture omitted required no-store headers; the fixture and client requirement were corrected before the final passing run.

[Source/evidence compatibility](asset-node-checks.json) records exact hashes, unchanged Python operational/schema/config bytes and the unchanged previously installed operator wheel. The shared Node authority-shape function adds an explicit historical mode; default callers retain current validity checks. The full seven-suite Node run and paid/free/storage wire regressions cover that shared change. No wire schema changed. The last complete Python suite remains the M2 571-method run, not a new aggregate count. The private Node journal is an operator trust store, not a portable evidence export; saved scenario reports contain only bounded outcomes. Requested final reviewer sign-off remains incomplete; root implementation evidence does not substitute for it.

--- Earlier milestone evidence (historical status at each checkpoint) ---

# M5 independent paid Node flow — current evidence

18 September 2026. The [independent paid-client guide](../docs/INDEPENDENT-PAID-CLIENT.md) records native Node implementation of quote/assent/payer/provider verification and actual paid access/reporting. **M5 now has its installed operator and independent paid-flow portions evidenced. The complete native-asset graph remains**, followed by M6 consolidation, full Python/schema/integrated validation, requested four-perspective review and publication. No public release changes in this checkpoint.

The [complete standalone Node regression](paid-node-regressions.txt) passes **140 tests**: the existing 91 plus **49 new paid semantic cases** in [native test source](test_paid_verifier.mjs). The new pure verifier checks exact price/fee/payee binding and bounded decimal arithmetic, role separation, current origin appointment, signatures and accepted context, immutable check identities, sequence/transaction history, late confirmation without extending access, original receipt recovery after offer expiry and stale new assertions versus historical exact replay. No Python code or validators are imported into the Node implementation.

The final [eight new wire/adapter harness methods](../tests/test_paid_node.py) pass in [the final paid run](paid-node-wire-tests.txt), with [74 native phase invocations](paid-node-wire-run/direct-lifecycle.json) across eight saved scenario reports. Each phase is a new Node process resuming its private journal. The two complete lifecycles each execute 29 phases over real certificate-verified HTTPS: a directly hosted agreement service with only its verifier delegated, and a delegated agreement service plus verifier. They include pending, mandate-only and failed denials, separately authenticated payer mandate, confirmation, actual protected bytes, exact signed reporting/retry, reversal/old-bearer denial, historical response replay without resurrection, status and revocation. Synthetic provider states move no money.

Other final wire scenarios reject valid-but-unapproved prices/payees before assent, a service-signed receipt inventing active access, provider amount/signer substitution, withdrawal between provider request/reply and origin rollback across restart, changed known compromise history and a compromised key alias. One method deliberately proves unsupported execution duties cause **no HTTP request**; it is not claimed as an executed TLS exchange. Seven methods do make real HTTPS requests. An earlier [10-method regression slice](paid-node-wire-regressions.txt) includes the original six paid methods and all four existing direct/delegated free/storage Node exchanges. Those existing paths passed. The final paid-only run adds two methods and reruns all eight paid scenarios after the final client-only guards; these overlapping counts must not be added.

The saved per-scenario JSON reports contain only outcomes and nonsecret synthetic identifiers. The private runtime journal contains original evidence and may contain a bearer token; it is temporary, locked, owner-only and not an evidence export. No journal, password, verifier authorization value or private JWK was copied to the report directory. The Node client only supports the demonstrated retrieval/attribution duty and fixed configured identities; it does not silently claim all Agent Core duties, storage execution, provider handover or paid-archive verification.

The [source/compatibility inventory](paid-node-checks.json) checks the current Node bytes, evidence files and prior runtime/schema files. The existing free-client source differs only by exports of unchanged native helper functions. All old Python operational modules, schemas, installed entry points and the last tested wheel remain unchanged. The last complete Python run remains M2 **571**; the newer focused suites do not imply a fresh aggregate run. Strict schema cases were not rerun because no wire schema changed. Root implementation assessment is not the pending final team sign-off.

--- Earlier milestone evidence (historical status at each checkpoint) ---

# M5 installed operator path — partial milestone evidence

17 September 2026. The [current installation guide](../docs/CURRENT-QUICKSTART.md) now uses a separately installed `odexa-current` command backed by eight new `odexa_runtime` modules. It leaves the legacy command and prior wire/runtime files unchanged. **M5 is not complete:** the independent native Node paid flow and complete native-asset-graph checks still remain; M6 still requires consolidation, full validation and the requested integrated review.

A wheel was built, installed with its dependencies into a fresh Python virtual environment, and invoked from an unrelated temporary working directory with source path/user-site imports disabled. The [installed runner](check_installed_runtime.py) imports only the standard library. It passes **57 command-flow checks**: 17 direct-free, 17 delegated-free and 23 delegated synthetic-paid. See [machine results](current-runtime-installed-checks.json) and [run output](current-runtime-installed-checks.txt). No third-party account or payment configuration is used by the free path. A successful local TLS download is compared with actual article bytes; restarting the process closes active handlers and recovers the persisted gateway report for authenticated collection.

The flow covers independent origin/public-registry trust provisioning, offer/assent/receipt, pending and mandate-only denial, separate payer mandate, synthetic confirmation/reversal, actual protected retrieval, durable restart/outbox, status/revocation, denied future access, closed export, inert archive import/retry and rejection of altered archives/missing independent client pins. The synthetic verifier moves no money. This is a Python operator client using current Python semantic validators; it is **not** independent Node evidence or proof of every storage/native-asset capability through this CLI.

**Eight focused adapter tests pass**, covering TLS trust rejection, the public route allowlist/private-path isolation, Host/duplicate/framing rejection, private configuration/nonoverwrite, origin withdrawal, free-only imports, public-key receipt verification without reading the issuer private key, and completed-prefix counts after partial transport failure. See [test source](../tests/test_current_runtime.py) and [results](current-runtime-tests.txt). A synthetic failed-send unit test establishes the prefix counter; the installed suite establishes actual successful HTTPS delivery. It does not claim that a real network fault occurred in the installed run.

The final [wheel inventory](current-runtime-wheel-inventory.json) checks all eight installed runtime files against their source and packaged bytes, records the wheel hash and both entry points, and confirms no `tests/` package ships. The [environment inventory](current-runtime-environment.json) records actual Python, TLS, SQLite and installed dependencies. The [build log](current-runtime-wheel-build.txt), [install log](current-runtime-install.txt) and [inventory checker](check_current_runtime_inventory.py) retain the reproduction details. The [compatibility/link record](current-runtime-checks.json) compares existing files against the pre-M5 manifest; only `pyproject.toml` changes among that prior runtime/schema/config selection.

Root implementation review corrected an invalid gateway boundary URI and replaced all-or-nothing body writes with counted local sends before recording a terminal gateway event. Failed completion journalling retains an unresolved admission rather than inventing success. The final wheel and tests include those corrections. The security inventory explicitly retains the unverified private security-report intake as a publication check; no mail monitoring or external certification is claimed.

The last complete Python suite remains the historical M2 571-test run. The later M3/M4/M5 focused checks do not constitute a new complete-suite count. Existing Node/schema evidence is unchanged. No new public package, immutable download, site deployment or release version was published by this checkpoint.

--- Earlier milestone evidence ---

# M4 observation coverage — focused evidence

17 September 2026. The [observation coverage contract](../docs/OBSERVATION-COVERAGE.md) now has a separate reference module, schema and corpus. **22 new methods pass**, including four certificate-verified local HTTPS methods. The **83-method regression slice passes** and includes the new methods plus existing storage-session, storage-contract, gateway-reporting and free-contract suites; these counts are not additive. The final isolated coverage rerun also passes after removing a test clock-boundary race. See [new-module results](observation-coverage-tests.txt), [regression results](observation-coverage-regressions.txt) and [tests](../tests/test_observation_coverage.py).

Strict independent AJV compilation accepts the 16 registered schemas and **23 new structural cases**: 17 structurally valid and six invalid. Python separately executes all semantic expectations, including structurally valid but semantically invalid origin, scope, time and binding cases. See [schema evidence](observation-schema-validation.json). The preceding complete 245-case corpus remains historical M2 evidence against unchanged prior schemas, not a claim that all 268 cases were rerun here.

The new runtime supports origin-only policy-bound HTTPS publication without credentials or a service/payment dependency; private monotonic registry history; explicit gateway/agent/collector/unobserved boundaries; known trusted expectation cohorts; and qualified reporting ratios. Real TLS cases fetch a static empty registry, correlate authenticated collector evidence with a durable admission, collect a client report through a free agreement without any token/gateway operation, and reject unavailable publication or changed policy bytes. The delivery-construction fixture supplies synthetic transport testimony; its new measurement test does not claim a new end-client delivery experiment beyond the previously executed gateway transport suite.

The reducer exposes interval gaps and overlaps, independent source categories, exact payload receipt, missing/pending/late/conflicted reports, unresolved admissions, unknown boundaries, wrong agreement/profile, and deterministic retries/conflicts. It never derives an all-traffic denominator from reports that arrived. A registry remains an origin declaration at observation time; accepted duty deadlines and verified intake provenance remain trusted external inputs. Both `global_capture_percent` and `global_traffic_denominator` are null. Retained historical registry data cannot silently replace failed current acquisition.

The [compatibility/link inventory](observation-coverage-checks.json) confirms existing runtime/schema/config files were unchanged. M4 adds its own module/schema/fixtures; it does not mutate service contracts, global signing types, client duties or older archives. The last complete Python run is still the M2 **571-test run** retained below, and standalone Node evidence still belongs to unchanged earlier JavaScript. No new full-suite count, wheel, ZIP, installed CLI or public release is claimed.

Commands from the working source (with the documented runtimes/dependencies):

```sh
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s tests -p 'test_observation_coverage.py' -v
PYTHONDONTWRITEBYTECODE=1 PYTHONPATH=tests:. python3 -m unittest -v test_observation_coverage test_storage_sessions test_storage_contracts test_gateway_reports test_free_contracts
PYTHONDONTWRITEBYTECODE=1 PYTHONPATH=tests:. python3 tests/test_observation_coverage.py --cases > profiles/fixtures/observation-cases.json
python3 verification/build_observation_schema.py
node verification/check_profiles.cjs /absolute/path/to/ajv profiles/fixtures/observation-cases.json
```

M4's bounded contract, implementation, deterministic examples and focused evidence are complete. This is root-authored work awaiting the final independent four-perspective assessment. M5 installed current tooling/independent paid and native-graph clients and M6 integrated normative edition, whole-source validation, review and publication remain open. The overall goal remains incomplete.

---

## Earlier M3 evidence (retained)

# M3 provider/key handover — focused evidence

17 September 2026. The [fresh-agreement handover contract](../docs/PROVIDER-HANDOVER.md) now has **six passing real TLS integration tests**, plus **three passing existing key-history cases**. These nine focused tests took 2–3 seconds per completed run. See the [exact final run](provider-handover-tests.txt), [source](../tests/test_provider_handover.py) and [compatibility/link record](provider-handover-checks.json).

The integration uses one origin and two distinct certificate-verified provider origins. It covers new service/issuer/key and credential namespaces, staging without authority, server rejection of old secrets/assent/agreement IDs, pre-send credential scope, fresh free/paid agreements, original exact receipts and inert archives, new-key signing, successor/origin outage denial, locally observed rollback after restart, and selected-storage report collection under an explicit access-free delegation before full withdrawal. Retirement of an old receipt key remains acceptable when a new active export key signs the archive; known compromise of the old receipt key causes fresh verification to fail. A prior import report remains historical testimony.

The paid case retains original confirmed payment evidence, requires an explicit new quote/mandate at the successor and proves that predecessor payment credentials cannot activate it. The verifier is synthetic/read-only. No debit, bank settlement, refund or legal assignment is claimed. The storage tail closes a known authenticated client session while retaining its original acquisition/retention context; it does not prove physical erasure or visibility of undisclosed copies.

M3 needed no changes to the service, gateway, archive, history, client or schema runtime. The compatibility inventory compares 89 runtime/schema/configuration files with the pre-M3 working manifest and finds no change. Six new test methods were added; the last complete Python run remains the **M2 571-test run below**, not a claimed whole-source 577-test result. Existing Node and schema evidence remains applicable to unchanged code. No wheel/ZIP or public protocol release was rebuilt. Full integrated validation belongs to M6.

Reproduce this focused evidence:

```sh
PYTHONDONTWRITEBYTECODE=1 PYTHONPATH=tests:. python3 -m unittest -v test_provider_handover test_portable_evidence.PortableEvidenceTests.test_known_compromise_rejects_historical_agent_and_service_signatures test_portable_evidence.PortableEvidenceTests.test_retired_historical_signer_survives_real_new_export_key_rotation test_authority_history.AuthorityHistoryTests.test_revoked_material_cannot_return_under_new_kid_after_removal_and_restart
```

The procedure and focused automated evidence satisfy the bounded M3 exit conditions. It is root-authored work, not final CTO/Data/Research/Product review. M4 observation coverage, M5 installed tooling/independent paid and native-graph client, and M6 integrated specification/review/publication remain open. The complete goal is not achieved.

---

## Earlier M2 integration evidence (retained)

# Verification — paid portability milestone M2

17 September 2026. **Working developer-preview source, not a release candidate or a new published snapshot.** The existing r6 download remains immutable. This milestone adds four explicit paid archive variants using the current shared archive implementation; it does not relabel the unfinished historical prototype as supported code.

| Check | Result | Evidence |
| --- | --- | --- |
| Complete Python suite, after final runtime/test changes | **571 passed**, 30.325 seconds | `paid-portability-python-tests.txt` |
| Focused new paid archive suite | **18 passed**, 4.199 seconds | `paid-portability-tests.txt`; the final whole-suite run additionally covers the later audit-order mutation |
| Relevant free/storage/asset/paid regression slice | **80 passed**, 8.125 seconds | `paid-portability-regressions.txt`; an earlier slice containing the first 14 new tests, not extra unique cases |
| New paid schema corpus | **56 cases passed**: 32 positive, 24 negative | `paid-portable-schema-validation.json` |
| Combined strict AJV corpus | **15 schemas, 245 cases passed**: 136 positive, 109 negative | `paid-portability-all-schemas.json` |
| Existing ordinary direct/delegated Node wire exchange | **12 checks each passed** | `paid-portability-free-wire-run/`, nested in the Python suite |
| Existing selected-storage direct/delegated Node wire exchange | **14 checks each passed**, plus enclosing archive checks | `paid-portability-storage-wire-run/`, nested in the Python suite |
| Existing JavaScript source | **13 files unchanged** against r6 | `paid-portability-compatibility.json`; the 91 standalone Node tests retain their r6 evidence and were not rerun |
| Historical implementation/schema/client tree | **36 inventoried files unchanged** against r6 | Same compatibility inventory; includes all files in those named directories, not the earlier narrower 35-file selection |
| Local Markdown path checks | **216 targets checked, none broken** | `paid-portability-final-checks.json`; excludes remote URL and anchor validation |

The Python count is the preceding 553 plus 18 new paid-archive methods. Nested Node checks and the earlier focused runs are not added again. No new wheel, installed CLI or immutable ZIP was produced at this checkpoint. Those packaging/deployment claims still require the M5/M6 work. The earlier [sixth-snapshot report](sixth-workbench-report.md) retains its original counts, wheel/integrity evidence and limits.

## Commands and boundaries

Python 3.12.14, cryptography 50.0.1, Node.js 24.19.0 and AJV 8.20.0. Commands from the working package root:

```sh
PYTHONDONTWRITEBYTECODE=1 ODEXA_NODE=node ODEXA_FREE_REPORT_DIR=verification/paid-portability-free-wire-run ODEXA_STORAGE_REPORT_DIR=verification/paid-portability-storage-wire-run python3 -m unittest discover -s tests -v
PYTHONDONTWRITEBYTECODE=1 PYTHONPATH=tests:. python3 tests/test_paid_evidence.py --cases > profiles/fixtures/paid-portable-cases.json
node verification/check_profiles.cjs /PATH_TO_AJV profiles/fixtures/*-cases.json
```

The new tests perform actual certificate-verified local HTTPS assent, payer submission, verifier calls, protected retrieval/reporting and archive import. The services use synthetic parties/keys/content and a read-only simulated payment verifier; they perform no debit. Selected storage archive cases authenticate client claims; actual managed Node storage has its existing separate execution evidence. The native graph and paid archive verifier remain Python implementations; these tests do not close the M5 independent Node paid/graph requirement.

## What the implementation now establishes

The paid bundle retains exact quote/accepted binding, original separately signed payer proof, independently pinned payer identity, original signed provider checks and their origin-authority context, ordered changing audit rows and final scalar state. The verifier replays every row and compares each state digest and the final bytes. It correlates indexed access/status/admission state without changing the original pending-payment receipt or reactivating terminal access.

Tests include pending without a mandate; failed/pending/confirmed recovery; exact read-only retry; reversal from pending/active; late confirmation and expiry; original signed manual revocation; real gateway delivery/intake; incorrect independent payer pins; valid provider signature with a wrong amount; tampered authority scope; omitted/reordered/changed audit entries, state and counts after outer re-signing; retired versus revoked verifier; source/archive restart; credential exclusion; and expiry after archive locking. Ordinary/storage paid variants and their asset variants preserve exact dependent report/manifest closure. Removing an asset parent and repairing the outer inventory still fails verification.

The first run exposed an invalid retirement test fixture: it changed a key's state without its required retirement timestamp. The existing authority validator correctly rejected it; the fixture now models a valid retirement and subsequent revocation. No live authority metadata was changed.

Historical recorded times remain exporter testimony correlated with independently retained origin material. A reconstructed audit proves consistency with retained evidence, not a universally complete payment history or honest recording of every event. Provider confirmation is authenticated assertion, not independent bank-settlement evidence. The [paid archive contract](../docs/PAID-PORTABILITY.md) specifies the exact limits and returned assurance fields.

## Release disposition

M2's implementation and automated evidence are complete for the four explicitly selected bounded reference profiles. Root authored/integrated the code against the actual current store/state machine. The original interrupted prototype stays historical/non-importable. A completed independent review of the latest integrated artifact remains an M6 requirement; no agent approval is implied by the tests.

M3 provider/key/credential migration, M4 declared observation coverage, M5 installed current tooling and independent paid/asset client, and M6 final normative consistency/four-perspective review/publication remain open. The [fixed plan](../docs/RELEASE-COMPLETION-PLAN.md) preserves the full objective. No public website, account setting, licence or release version changed in this milestone.
