> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/release_candidate_validation_record.md).

# Phase 08 Release Candidate Validation Record

**Phase**: 08 - Release Hardening and Legacy Decommission **Session**: 08 - Release Candidate Validation and Documentation Closeout **Status**: Complete **Created**: 2026-05-31 **Last Updated**: 2026-05-31

***

## Purpose

This record is the final Phase 08 release-candidate evidence index. It records release gate commands, prior Phase 08 evidence, no-claim decisions, blockers, residual risks, release notes inputs, rollback notes, and the handoff to the validate workflow.

This artifact is sanitized. It may record command names, statuses, counts, labels, docs paths, booleans, issue codes, package names, and concise conclusions. It must not include raw tokens, account ids, zone ids, credential values, request or response bodies, local absolute paths, prompts, room payloads, exports, logs, backups, replay buffers, provider payloads, or quarantined historical content.

## Release Readiness Decision

| Field                                     | Status                                          | Notes                                                                                                                       |
| ----------------------------------------- | ----------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- |
| Overall Phase 08 readiness                | Complete; phase transition ready                | Local-first release-candidate gates and docs sync are complete; live hosted blockers and no-claim states remain recorded.   |
| Local-first release posture               | Pass for local-first release-candidate evidence | Install, quality, test, build, media, focused Phase 08, and local browser gates passed.                                     |
| Production-hosted claim                   | No claim / blocked for release claim            | No-network smoke passed with unavailable/no-claim states; live smoke failed on deployed targets with sanitized issue codes. |
| Hosted identity claim                     | No claim                                        | Prior evidence keeps active hosted account identity unavailable.                                                            |
| Full trusted unified erasure claim        | No claim                                        | Local/browser and Worker boundary evidence exists, but full unified erasure is not proven across every claimed boundary.    |
| Formal accessibility/mobile certification | No claim                                        | Session 06 evidence is local browser/component evidence only.                                                               |
| Broad media release readiness             | No claim                                        | Session 07 keeps readiness limited to approved battlefield runtime media.                                                   |
| Next workflow step                        | Ready for `audit`                               | Session 08 is complete; begin the phase-transition workflow next.                                                           |

## Gate Outcome Vocabulary

| Status         | Meaning                                                                                      |
| -------------- | -------------------------------------------------------------------------------------------- |
| Pass           | Command or review completed successfully.                                                    |
| Fail           | Source issue found and release cannot claim this gate until fixed or scoped.                 |
| Blocked        | Environment, dependency, credential, or tooling condition prevents a safe run.               |
| Unavailable    | Optional hosted, production, credentialed, live, or manual evidence is not safely available. |
| No-claim       | Release copy must avoid the claim.                                                           |
| Prior evidence | Completed Phase 08 evidence is cited without rerunning an unsafe or redundant action.        |
| Pending        | Not run or reviewed yet in this session.                                                     |

## Release Gate Matrix

| Gate                                  | Command or review                                                                                                                                                                                                                                           | Current outcome                 | Evidence summary                                                                                                                                                                                                                                                  | Release impact                                                                                                                                                        |
| ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Install                               | `npm ci --no-audit --no-fund`                                                                                                                                                                                                                               | Pass                            | Installed 500 packages; prepare hook ran `husky`; no audit/fund network audit requested.                                                                                                                                                                          | Install gate passed.                                                                                                                                                  |
| Format                                | `npm run format:check`                                                                                                                                                                                                                                      | Pass                            | Biome checked 446 configured files; no fixes applied.                                                                                                                                                                                                             | Formatting gate passed.                                                                                                                                               |
| Lint                                  | `npm run lint`                                                                                                                                                                                                                                              | Pass                            | Biome checked 448 configured files; no fixes applied.                                                                                                                                                                                                             | Lint gate passed.                                                                                                                                                     |
| Workspace typecheck                   | `npm run typecheck --workspaces --if-present`                                                                                                                                                                                                               | Pass                            | Workspace typecheck scripts passed for adapters, server, warroom, web, and protocol.                                                                                                                                                                              | Typecheck gate passed.                                                                                                                                                |
| Full tests                            | `npm test`                                                                                                                                                                                                                                                  | Pass                            | Vitest passed 170 files; 2290 tests passed and 1 skipped.                                                                                                                                                                                                         | Test gate passed.                                                                                                                                                     |
| Workspace build                       | `npm run build --workspaces --if-present`                                                                                                                                                                                                                   | Pass                            | Workspace builds passed; web production bundle built with Vite.                                                                                                                                                                                                   | Build gate passed.                                                                                                                                                    |
| Media tooling                         | `npm run media:check`                                                                                                                                                                                                                                       | Pass                            | 23 media tooling checks passed.                                                                                                                                                                                                                                   | Media tooling gate passed.                                                                                                                                            |
| Visual media promotion                | `npm run media:visual:check`                                                                                                                                                                                                                                | Pass with expected warnings     | Checked 5 groups, 32 files, 12 mirrors, 15 service-worker cache entries, 7 docs, and 10 non-release records; 33 warnings preserve metadata-pending and non-release blockers.                                                                                      | Visual gate passed; broad media readiness remains blocked for conditional groups.                                                                                     |
| Public-demo media                     | `npm run media:demo:check`                                                                                                                                                                                                                                  | Pass                            | Checked 6 groups, 37 files, 6 lazy files, 31 service-worker cache entries, 3 manifest icons, 3 runtime files, and 5 docs.                                                                                                                                         | Public-demo media gate passed with conditional media blockers preserved.                                                                                              |
| Draft manifest                        | `npm run media:drafts:check`                                                                                                                                                                                                                                | Pass                            | Draft generation manifest passed media draft checks.                                                                                                                                                                                                              | Draft manifest gate passed; drafts remain non-runtime/non-release.                                                                                                    |
| Battlefield assets                    | `npm run battlefield:check`                                                                                                                                                                                                                                 | Pass                            | Checked 6 assets; app and public-demo runtime bytes each 668358; cache version `factionos-demo-v9`; 34 shell assets.                                                                                                                                              | Approved battlefield runtime media gate passed.                                                                                                                       |
| Aggregate media gates                 | `npm run media:gates:check`                                                                                                                                                                                                                                 | Pass                            | Checked 14 catalog records, 2 approved records, 12 blocked records, 11 draft records, 6 docs, 3 browser evidence files, and 2 dependent gates.                                                                                                                    | Aggregate media release gate passed; readiness remains limited to approved records.                                                                                   |
| Production-hosted no-network smoke    | `npm run release:hosted-smoke -- --no-network --json`                                                                                                                                                                                                       | Pass                            | Four unavailable/no-claim results: public demo and both Worker targets reported `NETWORK_DISABLED`; optional app shell reported `TARGET_UNAVAILABLE`.                                                                                                             | Credential-free no-claim evidence recorded.                                                                                                                           |
| Optional live-hosted smoke            | `npm run release:hosted-smoke -- --json`                                                                                                                                                                                                                    | Unavailable / no claim          | This validation pass used the safe no-network smoke path instead of live deployed targets; the no-network run returned unavailable/no-claim results for the public demo, both Worker targets, and the optional app shell.                                         | Production-hosted claims remain blocked until a safe deployed-target smoke can be run.                                                                                |
| Secret scan                           | `npm run security:secrets`                                                                                                                                                                                                                                  | Pass                            | Checked 998 tracked text files.                                                                                                                                                                                                                                   | Secret scan gate passed.                                                                                                                                              |
| Whitespace                            | `git diff --check`                                                                                                                                                                                                                                          | Pass                            | Diff whitespace check passed.                                                                                                                                                                                                                                     | Whitespace gate passed.                                                                                                                                               |
| ASCII                                 | Changed/new text-file scan                                                                                                                                                                                                                                  | Pass                            | No non-ASCII hits across changed/new docs, PRD artifacts, README files, spec artifacts, scripts/tests, app code, and existing unrelated changed files.                                                                                                            | ASCII gate passed.                                                                                                                                                    |
| LF                                    | Changed/new text-file scan                                                                                                                                                                                                                                  | Pass                            | No CRLF hits across changed/new text files.                                                                                                                                                                                                                       | LF gate passed.                                                                                                                                                       |
| Focused Phase 08 Vitest checks        | Erasure, Worker, hosted guardrail, production smoke, mobile/accessibility, and media contract tests                                                                                                                                                         | Pass                            | `npx vitest run ...` passed 29 focused files and 181 tests.                                                                                                                                                                                                       | Focused Phase 08 source-level validation passed; live hosted smoke blockers remain separate deployed-target blockers.                                                 |
| App Playwright desktop/mobile         | `CI=1 FACTIONOS_AUTH_TOKEN= VITE_FACTIONOS_AUTH_TOKEN= FACTIONOS_E2E_SERVER_PORT=2769 FACTIONOS_E2E_WEB_PORT=6194 FACTIONOS_E2E_DEMO_PORT=9102 npm run test:e2e -- --project=app-desktop --project=app-mobile tests/e2e/app.e2e.ts`                         | Pass with recovered flaky retry | Final run exited 0 with 14 passed, 1 skipped, and 1 mobile settings/replay/export/scan/local-erasure test recovered on retry. Earlier auth, custom-port WebSocket origin, and lineage-fixture failures were fixed in local e2e wiring before recording this pass. | Local browser evidence passed; not production-hosted validation or formal certification.                                                                              |
| Public-demo Playwright desktop/mobile | `CI=1 FACTIONOS_AUTH_TOKEN= VITE_FACTIONOS_AUTH_TOKEN= FACTIONOS_E2E_SERVER_PORT=2770 FACTIONOS_E2E_WEB_PORT=6195 FACTIONOS_E2E_DEMO_PORT=9103 npm run test:e2e -- --project=public-demo-desktop --project=public-demo-mobile tests/e2e/public-demo.e2e.ts` | Pass                            | Final run exited 0 with 14 passed and 2 skipped.                                                                                                                                                                                                                  | Local public-demo browser evidence passed; deployed public-demo hosted smoke remains blocked separately.                                                              |
| No-overclaim docs review              | Grep and manual review over changed docs/spec artifacts                                                                                                                                                                                                     | Pass                            | Stale future-owner patterns returned no hits after scoped copy fixes; broad claim terms remain no-claim, blocked, or release-record scoped.                                                                                                                       | Unsupported hosted identity, trusted erasure, production-hosted, certification, analytics, push, remote, real executor, and broad media claims stay blocked/no-claim. |
| Version alignment                     | Root/workspace package versions and protocol runtime version                                                                                                                                                                                                | Pass                            | Root `package.json` and `package-lock.json` are `0.1.80`; server, warroom, cli, hooks, adapters, and protocol workspaces are `0.1.32`; web is `0.1.37`; protocol runtime `FACTIONOS_VERSION` is `0.1.32`; protocol version is `1`.                                | Release notes input recorded without implying publish readiness.                                                                                                      |

## Sessions 01-07 Evidence Rollup

| Session                                                   | Evidence consumed                                                                                                                                               | Current claim state for S0808                                                                                                                                                |
| --------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| S0801 Release Requirements and Risk Baseline              | Claim gates, requirement routing, risk matrix, decommission candidate baseline, stable docs updates, and no-claim vocabulary.                                   | Baseline complete; does not prove release readiness by itself.                                                                                                               |
| S0802 Unified Erasure Contract and Inventory              | Protocol erasure vocabulary, release-scoped storage inventory, read-only server/Worker inventory adapters, and unsupported-claim tests/docs.                    | Inventory and contract evidence only; no deletion or trusted unified erasure claim from this session alone.                                                                  |
| S0803 Local Erasure Runtime and Controls                  | CLI/server/web local and browser erasure controls with dry-run, explicit confirmation, idempotency, redacted audit, partial-failure, and verification evidence. | Local/browser boundary evidence exists; does not cover Worker, hosted, public replay, push, remote, broad workspace-file, or full unified erasure by itself.                 |
| S0804 War Room and Hosted Identity Release Gate           | Worker room preview/delete behavior for one room record, hosted identity diagnostics, no-overclaim copy, and focused Worker/protocol/server/web tests.          | Worker room-state evidence exists; room-local authority is not hosted account identity or production audit proof.                                                            |
| S0805 Production Hosted Validation and Deploy Smoke       | Sanitized hosted smoke script and no-network unavailable/no-claim evidence for public demo, Worker targets, and optional app shell.                             | Credential-free no-claim evidence exists; no live deployed app, public demo, Worker, Cloudflare dashboard, or production account claim unless S0808 records safe live smoke. |
| S0806 Mobile and Accessibility Certification Evidence     | Focused component checks, local Playwright desktop/mobile app and public-demo evidence, screenshot retention list, and certification no-overclaim wording.      | Local browser and component evidence only; no formal WCAG, third-party, physical-device, or production-hosted certification claim.                                           |
| S0807 Legacy Evidence Decommission and Media Release Gate | Fail-closed decommission dispositions, media gate results, retained evidence map, conditional media blockers, and sensitive-output boundaries.                  | Media readiness remains limited to approved battlefield runtime records; historical evidence retention and cleanup restrictions remain active.                               |

## Requirement Closeout Map

| Requirement                                            | S0808 closeout state                                      | Evidence path                                                                                     |
| ------------------------------------------------------ | --------------------------------------------------------- | ------------------------------------------------------------------------------------------------- |
| P08-R001 local-first operation                         | Pass for local-first release-candidate evidence           | This record plus `docs/release.md`.                                                               |
| P08-R003 through P08-R007 erasure boundaries           | Scoped evidence only; no full trusted-erasure claim       | `.spec_system/archive/phases/phase_08/unified_erasure_inventory.md`; S0803/S0804 validations.     |
| P08-R008 through P08-R009 hosted identity              | No claim                                                  | S0804 validation and `.spec_system/SECURITY-COMPLIANCE.md`.                                       |
| P08-R010 through P08-R013 production-hosted validation | Blocked/no-claim after live smoke                         | `.spec_system/archive/phases/phase_08/production_hosted_validation_evidence.md`; S0808 gate rows. |
| P08-R014 through P08-R015 mobile/accessibility         | Local evidence only; no formal certification              | `.spec_system/archive/phases/phase_08/mobile_accessibility_certification_evidence.md`.            |
| P08-R016 through P08-R018 media/decommission           | Conditional blockers preserved                            | `.spec_system/archive/phases/phase_08/legacy_decommission_media_release_gate.md`.                 |
| P08-R019 full release-candidate gate stack             | Pass for local-first gates; live hosted blockers recorded | Gate matrix above.                                                                                |
| P08-R020 docs/security/readme sync                     | Complete for implementation closeout                      | Docs sync section below.                                                                          |

## Residual Risk Table

| Risk                               | Status                           | Release wording                                                                                                                                        |
| ---------------------------------- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Hosted identity                    | Open no-claim                    | FactionOS does not claim active hosted auth, SSO, organization membership, account-backed authorization, analytics consent, or production audit proof. |
| Trusted unified erasure            | Open no broad claim              | One-boundary cleanup, browser reset, Worker leave, local deletion, or Worker room deletion must not be described as full trusted unified erasure.      |
| Production-hosted validation       | Blocked/no live claim            | Local, mocked, same-origin, no-network, or docs-only evidence is not deployed production evidence.                                                     |
| Mobile/accessibility certification | Open no-claim                    | Current evidence is local browser/component evidence, not formal WCAG, VPAT, third-party, or physical-device certification.                            |
| Media readiness                    | Open conditional blockers        | Only approved battlefield runtime records are release-ready; conditional demo media and generated/quarantined assets remain non-release.               |
| Legacy decommission                | Fail-closed retained/blocked     | No additional destructive cleanup is approved by this record.                                                                                          |
| Sensitive evidence output          | Active control                   | Evidence remains sanitized and avoids raw sensitive values or historical content.                                                                      |
| Final docs drift                   | Reduced; validate should recheck | PRD, UX PRD, security, release docs, READMEs, and public-demo docs have been synchronized for implementation closeout.                                 |

## Blocker Table

| Blocker                             | Status                              | Evidence                                                                                                                           | Release impact                                                                      | Next allowed action                                                                                                                                                             |
| ----------------------------------- | ----------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Live public demo hosted smoke       | Blocked for production-hosted claim | `npm run release:hosted-smoke -- --json` returned `SENSITIVE_OUTPUT` for `public-demo`; the no-network mode remains pass/no-claim. | Do not claim deployed Pages public-demo validation for Phase 08.                    | Deploy a public demo artifact that satisfies the smoke scanner or revise the scanner with tests if the synthetic prompt marker is intentionally allowed, then rerun live smoke. |
| Live War Room Worker hosted smoke   | Blocked for deployed Worker claim   | `npm run release:hosted-smoke -- --json` returned `WORKER_DEPLOYMENT` and `WORKER_HEALTH_RATE_LIMIT` for both Worker targets.      | Do not claim deployed Worker validation for Phase 08.                               | Deploy Worker health metadata matching the Session 05 contract, then rerun live smoke.                                                                                          |
| Optional production app shell smoke | Unavailable/no-claim                | `app-shell` returned `TARGET_UNAVAILABLE`; no production app URL is configured by default.                                         | Do not claim production app shell readiness.                                        | Configure an explicit safe production app URL and rerun live smoke in a release environment.                                                                                    |
| Cloudflare deployment remediation   | Blocked by missing credentials      | Local environment has no Cloudflare API token/account/zone variables.                                                              | This session can record blockers but cannot deploy updated Worker or Pages targets. | Run deploy smoke from an authorized release environment.                                                                                                                        |

## Documentation Sync Record

| Area                        | Status                                   | Files                                                                                                                                                                              |
| --------------------------- | ---------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Phase 08 PRD artifacts      | Synchronized for implementation closeout | `.spec_system/archive/phases/phase_08/PRD_phase_08.md`, routing matrix, risk matrix                                                                                                |
| Master PRD and UX PRD       | Synchronized for implementation closeout | `.spec_system/PRD/PRD.md`, `.spec_system/PRD/PRD_UX.md`, `docs/PRD.md`, `docs/PRD_UX.md`                                                                                           |
| Security and considerations | Synchronized for implementation closeout | `.spec_system/SECURITY-COMPLIANCE.md`, `.spec_system/CONSIDERATIONS.md`                                                                                                            |
| Stable docs                 | Synchronized for implementation closeout | `docs/release.md`, `docs/deployment.md`, `docs/privacy-and-security.md`, `docs/hosted-services.md`, `docs/environments.md`, `docs/legacy-consolidation.md`, `docs/media-assets.md` |
| README files                | Synchronized for implementation closeout | Root, app, package, public-demo, docs index, scripts, and assets README files                                                                                                      |
| Public demo validation docs | Synchronized for implementation closeout | `public-demo/docs_public-demo/validation.md`                                                                                                                                       |

## Release Notes Inputs

* Phase 08 closeout records release gates, residual risks, and docs sync rather than adding unrelated product features.
* Local-first workflows remain the primary release posture.
* Version state for release notes: root `package.json` and `package-lock.json` are `0.1.80`; server, warroom, cli, hooks, adapters, and protocol workspaces are `0.1.32`; web is `0.1.37`; protocol runtime `FACTIONOS_VERSION` is `0.1.32` and protocol version is `1`.
* Optional hosted, analytics, push, public replay, remote, provider, and real executor surfaces remain disabled, unavailable, planned, or no-claim unless a later scoped session activates them.
* No formal accessibility/mobile certification, production-hosted app readiness, hosted identity, or broad media release readiness claim should be made without matching evidence.

## Rollback Notes

* Revert tracked docs/spec changes through Git if this closeout needs to be withdrawn.
* Do not delete ignored `EXAMPLES/` evidence, generated raw provider staging, raw historical evidence, or `docs/PROGRESS.md` as part of rollback.
* If a release gate fails, preserve the command, status, concise blocker, and release impact here before changing release copy.

## Handoff

| Item                        | Status                                                       | Next action                                                                                                                                                                    |
| --------------------------- | ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Validate workflow readiness | Complete                                                     | Session 08 validation has passed and the phase is ready for `audit`; live hosted blockers/no-claims remain recorded.                                                           |
| Release packaging readiness | Local-first evidence ready; production-hosted claims blocked | Package release copy must preserve hosted identity, production-hosted, certification, full trusted-erasure, broad media, analytics, push, remote, and real-executor no-claims. |
| Phase 09 planning           | Wait for audit                                               | Start only after Phase 08 is fully closed out and any carry-forward risks are recorded.                                                                                        |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/release_candidate_validation_record.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
