# Task 1.3 Baseline Evidence ## Status This file records the best available historical baseline for task 1.3 and its reproducibility limits. It does not claim that a pre-change image was rerun during this change, and it does not convert current tests into pre-change evidence. An immutable rerun of the exact pre-change source and image is unavailable. On 2026-09-18, the reviewer explicitly accepted this documentary baseline and waived that rerun requirement. Task 1.3 therefore relies on the historical record below; current regression results remain separately identified as post-change evidence. ## Historical pre-change record The repository's [`DOCKER_MIGRATION.md`](../../../DOCKER_MIGRATION.md), under "Current Verified Evidence," records a final run on 2026-09-15. It reports: - The selected container regression suite completed with **578 passed** and **7 expected Windows-only tests skipped on Linux**, with no failures recorded. - The selected suite used test image `sha256:4ce11325728ba3e58e6643c1c8e800f317179d5c7c50e7e80568b58f62dbdfd0`. - The separate six-test `docker/test_verify.py` suite passed on Windows and WSL Linux; those six tests were not included in the 578 count. - The recorded offline E2E passed its result/check gates and removed its owned resources. This is contextual historical evidence, not a rerun for task 1.3. The `add-minimal-remote-scan-workers` OpenSpec change was created on 2026-09-17, after that recorded run. The preserved records contain no pre-existing failure for the cited 578-test selection to list separately. "No recorded failure" means only that no failure record was found; it is not proof that no unrecorded attempt failed. ## Reproducibility limits - The old test image is unavailable and was not retrieved, rebuilt, or executed. Current Docker runs use new, dedicated test image identities. - This workspace has no commit history. On 2026-09-18, `git status` reported `No commits yet on master` and every repository path as untracked; `git log` failed because the branch has no commits. - `WORKSPACE.md` names a source-side provenance commit, but also states that this source-only snapshot includes modified and selected untracked files and did not copy source Git history. It is not an immutable tree for either 2026-09-15 or the moment immediately before the 2026-09-17 OpenSpec change. - The image digest and prose result are therefore useful historical evidence but cannot independently reconstruct or rerun the claimed chronology from this repository. ## Current expanded selection The current reviewed allowlist is the `SELECTION` mapping in `tests/container_unit.py`. On 2026-09-18, its stdlib-only selection check reported **33 modules and 649 test definitions**, with no runner skips at declaration time; pytest parametrization may expand the executed count. The current mapping selects: ```text test_docker_foundation.py test_container_runtime.py test_owned_process.py test_owned_process_linux.py test_owned_process_boundary.py test_runtime_bootstrap_authority.py test_supervisor_foreground_shutdown.py test_supervisor_startup_rollback.py test_supervisor_managed_postgres_gate.py test_observer_only_coordinated_shutdown.py test_supervisor_safety.py test_postgres_runtime.py test_container_security.py test_runtime_security.py test_postgres_empty_initialization.py test_container_migration_paths.py test_container_provider_portability.py test_container_e2e_helpers.py test_container_import.py test_container_import_config.py test_container_projection_recovery.py test_result_bundle_v2.py test_pipeline_cutover_invariants.py test_custom_provider_detector_compatibility.py test_scan_execution.py test_synthetic_llm_pipeline.py test_worker_api.py test_worker_api_runtime.py test_worker_assignment.py test_worker_package.py test_remote_worker_db.py test_admin_api.py test_edge_deployment.py ``` The remote-worker, package, administration, edge, synthetic-pipeline, and bundle modules in this current selection postdate the historical baseline. Their presence demonstrates current review scope, not pre-change execution. ## Current post-change evidence The expanded selection and isolated end-to-end gates were rerun on 2026-09-19. They validate the completed implementation but do not replace the historical pre-change baseline: ```text python -I -S -B tests/container_unit.py --check-selection container-unit: AST OK; 33 modules, 650 test definitions, no runner skips (parametrizations expand in pytest) isolated Linux container selection 867 passed, 7 expected platform skips wsl.exe -d Ubuntu-24.04 -- python3 docker/verify.py E2E passed; project truf-worker-test-99b193a64f46a0002e34da9c5ff8029a; artifacts removed python -B docker/verify_packaged_workers.py ... Windows/Linux packaged-worker E2E passed; run 348d24046fb7b8d4; cleanup complete; foreign Docker state unchanged Windows package manifest sha256 f0bbbbf79d9f5f3f17440a60561b307fa7bafd312ab6110b14098ff90755f8e6 Linux worker image manifest list sha256 888bffc5519fd3a27cb52d20eaea1143f89ac9779bb2e4b0d998e450583c57a0 python -B docker/verify_edge_e2e.py --timeout-seconds 1200 Edge/fail2ban E2E passed; run 597b3ff7826055e1; cleanup complete; foreign Docker state unchanged openspec validate add-minimal-remote-scan-workers --strict --no-interactive Change 'add-minimal-remote-scan-workers' is valid ``` The current runs used only random or dedicated test-owned identities and verified that foreign container and volume metadata remained unchanged. No current result is represented as historical or pre-change evidence.