Skip to content

Refresh v0.7.1 analyzer pins and measurement evidence - #164

Merged
DavidBakerEffendi merged 33 commits into
mainfrom
dave/v071-measurement-evidence
Sep 8, 2026
Merged

Refresh v0.7.1 analyzer pins and measurement evidence#164
DavidBakerEffendi merged 33 commits into
mainfrom
dave/v071-measurement-evidence

Conversation

@DavidBakerEffendi

Copy link
Copy Markdown
Collaborator

Refresh analyzer pins and measurement evidence for the exact v0.7.0 population: 852 cases, 82 reports, and 3,480 results. This replaces the superseded pins-only PR #162 and integrates #163. The 22 later cases remain outside this measurement population. The published freeze and generated results remain unchanged; final inventory, freeze, and publication are separate work after this evidence is merged.

Key Changes:

  • Retain 148 invocation attempts with exact inputs, execution context, hashes, failures, and supersession history. Complete the native and modeling probes, two warm series, and nine overhead groups with three repeats each. Semgrep warm batches are prospectively corrected to 1, 2, 4, 8, and 12 because its existing identical-rule population has 12 cases; the rejected batch-16 attempt is retained.
  • Clarify Bifrost and OpenTaint native rationale without changing classifications. Bifrost native activation remains partial. OpenTaint full-product controls succeeded after two retained CLI failures; their contended functional timings are excluded from latency qualification. Preserve the initial sandboxed Bifrost context, five approved elevated repeats, and the limited scope of paired access controls.
  • Verify all 9,572 retained log/output references against committed Git blobs, retain the initial historical plan at its original hash, and preserve raw line endings. The normalized outcome comparison has four changes: Bifrost Java anonymous-implementation positive/negative move from inconclusive to reached/not-reached; OpenTaint Java callback-registration and map-iteration positives move from not-reached to reached. No other normalized outcome changes were observed.

Touch Points:

  • Analyzer pin/configuration files and src/native.rs
  • scripts/record-release-attempt.py, scripts/execute-release-stage.py, and probe/audit scripts
  • reports/*.json, reports/raw/, and reports/releases/v0.7.1/
  • .gitattributes

Validation: formatting; all 226 Rust tests; 874-case validation; both report-validation modes (82 reports, 66 configuration hashes, zero stale); 12 site tests, Astro check, and production build; unchanged published freeze/results byte guard; historical generate-results --check from exact published revision 61300f47. See reports/releases/v0.7.1/final-validation.json and completed-measurement-audit.json.

Measurement conditions and uncertainty remain explicit: desktop activity is recorded rather than described as an idle OS; initial sandbox/elevated contexts are not claimed equivalent; FlowDroid batching equivalence remains unresolved. Remote CI and independent publication audit are separate from these local results.

@DavidBakerEffendi
DavidBakerEffendi merged commit 2007f15 into main Sep 8, 2026
3 checks passed
@DavidBakerEffendi
DavidBakerEffendi deleted the dave/v071-measurement-evidence branch September 8, 2026 07:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant