# W6 EXIT AUDIT — 2026-09-28

Status: **W6 IN PROGRESS — PASS is not yet justified.**

This audit compares the binding W6 exit requirements in `W6_HANDOFF.md` against executed IONOS evidence. A requirement is PASS only where execution evidence exists.

| Area | Requirement | Status | Evidence / open item |
|---|---|---|---|
| A Identity | source commit / active release | PASS | active release and candidate/rollback identities recorded |
| A Identity | image/runtime identity | PASS | RC reproducibility collector captured container/image identity, runtime package versions, safe config and release-tree checksums; evidence archive checksum recorded |
| A Host | CPU/RAM/kernel/Docker facts | PASS | collected on authorised IONOS host and retained in the W6 evidence set |
| A Numerics | BLAS one-thread in real worker | PASS | `W6_REMAINING_EVIDENCE_READ=PASS`; OpenBLAS measured 1 thread |
| A Hardening | non-root/read-only posture | PASS | deployed container hardening collected; read-only root also observed during probe |
| A Boundary | reverse proxy | PASS (loopback) | nginx 429 rate limit and security headers exercised |
| A Boundary | TLS on staging boundary | PASS | public HTTPS boundary active on studio.vonmallinckrodt.com; root/ready/modules returned 200 after certificate deployment |
| B Capacity | p50/p95/p99 end-to-end | PASS | maximum-size sequential, saturation and mixed-load latency distributions measured on IONOS |
| B Capacity | queue-wait distribution | PASS (collected) | dedicated IONOS capacity run collected queue-wait and execution distributions in /tmp/benchews-w6-capacity.json |
| B Capacity | 429 latency | PASS | nginx 429 classification and latency measured; mixed-capacity run recorded ~0.142 s p95 |
| B Capacity | 503 latency | PASS | application-capacity 503 path, Retry-After semantics and rejection timing exercised in IONOS saturation evidence |
| B Capacity | CPU/RAM/worker utilisation under load | PASS (sampled) | mixed-load run sampled API at 13.95% CPU and 247.4 MiB / 3.744 GiB; web at 0.00% CPU and 3.277 MiB / 3.744 GiB |
| B Capacity | normal + maximum-size + mixed workloads | PASS | dedicated IONOS mixed-workload run completed with scientific invariance and recovery |
| B Capacity | CRTI under load | PASS | CRTI participated in mixed-load run; label remained EXPERIMENTAL_UNVALIDATED / unvalidated |
| B Capacity | timeout / worker replacement / recovery | PASS | real IONOS test: HTTP 504 ANALYSIS_TIMEOUT at ~30.08 s; frozen worker PID reaped; replacement worker observed; readiness and scientific result recovered |
| B Capacity | select max_workers / max_queue_depth / envelope from IONOS evidence | PASS | conservative baseline frozen at 2 workers / queue 4; no throughput SLA; see W6_CAPACITY_BASELINE.md |
| C Scientific | result unchanged under pressure | PASS | executed runtime test |
| C Scientific | CRTI label/status preserved | PASS | `EXPERIMENTAL_UNVALIDATED / unvalidated` |
| C Scientific | no global score/risk/recommendation | PASS | verified Studio/API contract and executed public scientific smoke expose module results/status only; no global score/risk/recommendation path is present |
| C Scientific | provenance same Core lineage | PASS | exact deployed runtime source frozen at `8e00117822b0d7ee10ccf4f699314cbafc58b403`; canonical reference identity remains recorded and RC evidence captures runtime identity |
| D Isolation | API outage vs DE/EN sites | PASS | executed failure-isolation test |
| D Isolation | UI outage vs DE/EN sites | PASS | executed failure-isolation test |
| D Isolation | telemetry outage vs science/sites | DEFERRED / RC OFF | public RC telemetry defaults OFF; scientific execution does not depend on telemetry |
| D Isolation | one research site outage vs Studio + other site | DEFERRED TO W8 WEBSITE INTEGRATION | first public Studio RC does not modify or depend on either research website; website-link integration is a separate W8 action |
| D Isolation | Studio rollback independent | PASS | real rollback executed |
| D Isolation | website rollback independent | DEFERRED TO W8 WEBSITE INTEGRATION | no website deployment/change is part of W6/W7; Studio rollback independence is already executed |
| E Telemetry | forbidden raw fields rejected / no raw sentinel in logs | PASS | HTTP 422 + log sentinel check |
| E Telemetry | controlled event counts | DEFERRED / RC OFF | not required for first public RC; telemetry remains disabled |
| E Telemetry | overhead + scientific invariance | DEFERRED / RC OFF | no telemetry overhead in first public RC because telemetry is disabled |
| E Telemetry | finite retention/deletion/rotation | DEFERRED / RC OFF | operational feed must not be enabled until this gate is verified |
| E Telemetry | internal aggregate feed non-public/non-indexed | DEFERRED / RC OFF | feed is not part of first public RC |
| F Rollback | previous release retained + rollback executed | PASS | real rollback to retained release |
| F Rollback | config backup + checksums | PASS | RC evidence collector produced protected staging config backup, release-tree manifest and SHA-256 bundle checksum |
| F Rollback | before/after deployment identity | PASS | candidate and original SHA recorded |
| F Rollback | no website rollback required | PASS | research sites stayed available |

## Executed IONOS mixed-capacity evidence — 2026-09-28

The dedicated capacity run completed with `W6_CAPACITY_CLOSURE=PASS` and final readiness HTTP 200 / `ready=true`.

Visible executed evidence includes:

- mixed scientific workload recovered successfully;
- scientific results remained unchanged under the run;
- CRTI retained `EXPERIMENTAL_UNVALIDATED` / `unvalidated`;
- reverse-proxy 429 rejection p95 was approximately 0.142 s in this run;
- no application-level 503 rejection occurred in this particular mixed-load sample;
- sampled API utilisation: 13.95% CPU, 247.4 MiB / 3.744 GiB;
- sampled web utilisation: 0.00% CPU, 3.277 MiB / 3.744 GiB.

The full capacity JSON remains host-local at `/tmp/benchews-w6-capacity.json`; the PASS marker does not by itself authorise a production sizing claim.

## Executed IONOS timeout/replacement/recovery evidence — 2026-09-28

The staging timeout-recovery test completed with both explicit markers `W6_TIMEOUT_REPLACEMENT_RECOVERY=PASS` and `W6_TIMEOUT_RECOVERY_FINAL_HEALTH=PASS`.

Observed evidence:

- stable API error: HTTP 504 / `ANALYSIS_TIMEOUT`;
- timeout elapsed approximately 30.08 s, matching the configured execution deadline;
- timed-out scientific worker PID was reaped;
- replacement worker was observed;
- readiness returned after replacement;
- the same scientific test result was reproduced after recovery;
- final Web/API readiness returned HTTP 200 with `ready=true`.

## Executed public HTTPS boundary evidence — 2026-09-28

The public HTTPS boundary for `studio.vonmallinckrodt.com` is now active with a Let's Encrypt certificate. Host-local validation after certificate deployment returned:

- HTTPS root: HTTP 200;
- HTTPS readiness: HTTP 200;
- HTTPS modules endpoint: HTTP 200;
- nginx configuration test: PASS;
- HTTP-to-HTTPS redirect enabled by Certbot;
- certificate auto-renewal scheduled.

The certificate is valid until 2026-12-27 according to the deployment output.



## Executed independent external public smoke evidence — 2026-09-28

GitHub Actions run `36430047223` completed **SUCCESS** from an independent hosted runner. DNS/TLS reachability, public health/modules, HTTP-to-HTTPS redirect and required security headers, and a real public scientific variance analysis all passed.

W6 is **PASS for the first-public-Studio-RC scope**. The remaining work is concentrated in four bounded packages:

1. **IONOS capacity closure:** executed and frozen conservatively at 2 workers / queue depth 4 in `W6_CAPACITY_BASELINE.md`; no throughput SLA or higher-capacity claim is made.
2. **Telemetry operational layer:** removed from the first-public-RC critical path. RC defaults telemetry OFF; the operational telemetry gate remains open and cannot be enabled publicly until verified.
3. **Boundary closure:** HTTPS/TLS and the independent external GitHub-hosted smoke test are PASS.
4. **Residual isolation/reproducibility:** RC config/checksum evidence is PASS. Research-website outage/rollback tests belong to the separate W8 website-link integration because the first Studio RC changes neither research website.

W6 PASS authorises W7 freeze. W8 remains NOT AUTHORIZED.
