Skip to content

docs: clarify Play physical evidence boundary - #557

Open
daniele21 wants to merge 2 commits into
devfrom
docs/play-physical-evidence-clarification
Open

docs: clarify Play physical evidence boundary#557
daniele21 wants to merge 2 commits into
devfrom
docs/play-physical-evidence-clarification

Conversation

@daniele21

Copy link
Copy Markdown
Owner

Outcome

Record the operator-confirmed Play Internal physical result without overstating what it proves.

Physical result on the current Play-distributed Harnex + RedactGuard pair:

  • RedactGuard installed first;
  • Harnex installed later;
  • no RedactGuard reinstall;
  • RedactGuard observed as PENDING;
  • explicit authorization succeeded;
  • Connect / Disconnect / Reconnect succeeded;
  • real Consumer SDK/Binder/local inference succeeded.

Evidence boundary

Separate Play signing metadata collected for this evidence reports the same current Play App Signing SHA-256 digest for both applications. Therefore this physical run proves install-order, authorization, connectivity and production runtime behavior for the actual current Play topology; it does not prove distinct-signer Play behavior.

Distinct-signer authorization remains covered by the dedicated deterministic release-identity lane.

Documentation corrected

  • docs/current-state.md now records the exact physical result and removes the incorrect statement that the operator confirmed independent Play signing identities.
  • ADR 0018 now distinguishes the intended signer-independent authorization architecture from the current same-signer Play Internal topology.
  • PR release: promote current Harnex dev baseline to main #546 release body is aligned to the same evidence boundary.

No runtime/product code changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant