Observed 2026-07-21 08:04:59 UTC · reports-integrator-api-adaptive-diagnostic-20260721T080459Z
The documented and stable adaptive POSTs return the wrong test kind.
The literal adaptive materialization request returns mastery_gate from both the approved customer-website sandbox and stable Reports origin, but adaptive_diagnostic from the immutable adaptive candidate. Production tenant routes remain absent. The upstream Results production mint is also publicly callable. AcmeTest must not adopt this surface.
The rerunner performs 34 non-mutating contract probes against the approved docs, their published sandbox, stable origin, immutable candidate, and Results. It retains public bodies and allowlisted headers, immediately discards the ephemeral Results token and learner values, hashes the capture, and never writes a learning fact.
The approved website's adaptive example is false on the wire
The published POST is sent for att_diag_8K2m, but returns att_7F3k9, mastery_gate, and a binary gate failure. This is a docs-to-runtime contract failure in the earliest approved artifact that owns the runnable example.
Reproduce: run probe.sh; exit 0 means the complete blocked baseline still exists.
F-002 · Critical
The stable origin is not the immutable adaptive release
The same POST is wrong at the stable origin and correct on the candidate. Unequal build receipts isolate a release-identity failure; identical per-origin retries rule out transient response drift.
F-003 · Critical
Results exposes a production credential path
Unauthenticated POST /dev/mint?tenantId=demo returns 200. Its ephemeral token authorizes a collection read reporting 31,319 rows whose schema includes learner identifiers. The audit immediately discarded the token and all row values; this is a security failure, not a recommended integration path.
F-004 · Critical
No tenant-backed adaptive report operation or evidence chain is released
Detail, history, readiness, and materialization all return 404. The exact Results adaptive lookup is empty; test_result_components, adaptive references, and Caliper read-back are absent. Owner status pages receive no runtime credit.
F-005 · High
Reports tenant isolation remains unverified
Reports tenant routes and its demo mint are absent, but no same-tenant success or disjoint tenant-A/B fixtures exist. Route absence is fail-closed; it is not evidence of future tenant isolation.
The documented sandbox, stable origin, and immutable candidate were driven with the same adaptive POST. Both runtime origins were also driven for adaptive and mastery GET, adaptive/formative history filters, mastery POST, retry stability, release identity, and cache policy. The customer-facing POST leaks mastery semantics; the candidate does not.
Security gate
REPORTS FAIL-CLOSED
No current Reports tenant-data route
Anonymous and reviewer-shaped Reports requests return 404, and the Reports demo mint returns 404. Its sandbox is fixed and tenant-free.
UPSTREAM SECURITY FAIL
Results production mint is public
A no-credential mint returned 200 and the minted demo token listed 31,319 tenant records. Cross-tenant isolation was not exercised and remains blocking-inconclusive; a publicly mintable tenant credential already fails the secure-default gate.
Upstream reality
Authority
Fresh evidence
Verdict
Results
Public production mint → authenticated list of 31,319; exact lookup empty; components/adaptive refs absent
SECURITY FAIL · NO COMPOSITION PROOF
Bank
Owner page says adaptive admission closed pending non-null QTI/CASE-reconciled pool
ROLL BACK · reports / integrator_api / customer_website
Fix the first published request, then re-promote one immutable runtime.
The customer website is the earliest approved deliverable whose own runnable adaptive example returns the wrong fixture. Rebuilding it also forces downstream implementation and release validation.
Make the literal documented POST return att_diag_8K2m, adaptive_diagnostic, score 214.6, gate null, and private/no-store.
Promote the immutable build emitting reports-unified-adaptive-a1-20260721 atomically to the stable Reports origin.
Gate the customer-website URL, candidate, and stable origin on two byte-stable adaptive retries plus mastery/formative sibling checks.
Keep production Reports tenant routes parked. Remove or strongly authenticate the Results production mint, then prove same-tenant and bidirectional cross-tenant behavior before any release.
Benchmark comparison
The freshly fetched Qualys SSL Labs assessment was READY on engine 2.4.2 with four A+ endpoints. This audit matches its exact-target component verdicts and one-command reassessment, then adds frozen bodies, allowlisted headers, hashes, semantic API assertions, three-surface comparison, proof-level limits, explicit inconclusives, and machine-readable rollback. Frozen benchmark summary.