R11 Exact Single-Command Probe — Reconciliation Release

Status: PASS_LIVE / FAIL_CLOSED / REAL_WINDOWS_RUNTIME_NOT_PROVEN / PRODUCTION_NO_GO

Effective audit date: 2026-08-29 UTC.

Goal

Close the residual R10 acceptance gap where a valid local-read proof required at least one completed shell command but did not mechanically prove that Codex executed exactly one shell command, that the started/completed event referred to the same command item, or that collaboration tool events were absent.

Reconciled active contract

  • implementation: R11-EXACT-SINGLE-COMMAND-PROBE
  • acceptance lane: CODEX_REAL_RUNTIME_ACCEPTANCE_V6
  • challenge id: 1638b61d-86e0-470e-8f2c-138fd9db966c
  • challenge SHA-256: 45afab1a27f762accf1b045c91656ff1bddf5c97009b922f335da93c81b3b653
  • challenge payload SHA-256: 3ed092607f5996fdb97afd36d63f282372fb487ff13554a2e9dbd8d053c24a9e
  • challenge revision: 1
  • deadline: 2026-09-02T03:15:00Z
  • bootstrap metadata schema: rumbo-codex-device-bootstrap/v5

The V6 challenge already existed in the shared evidence database before R11 promotion work and remains unacknowledged. It was not synthesized by the branch tests.

Exact launcher identities

  • Python launcher v7.0: SHA-256 b91fdd981daafca2a74628b8e796fa8df718c076447a32faf6b6b45f39017f30, 28802 bytes.
  • Windows launcher: SHA-256 2eda8ee066e91cb22d794453241e26b9db279d6f9bdfe862949cf22392155d5f, 4852 bytes.
  • Environment probe: SHA-256 8dff8e38c986fabdea627183745fb643bfbcb8c9262e915f6d1f8447d90a2f72.
  • Canonical release remains GPT_CODEX_CONTEXT_BRIDGE_V1_6.
  • Canonical release SHA-256 remains cdbbb59d96a4a45d943f6d14a610e3cdbf451cc9480ed9300a170f60bef39e0b.
  • Canonical Skill ZIP SHA-256 remains 152dee3cf1bf86e81539e3f334f74d8bf630937d516b0a88a60463c9f0feb068.
  • Canonical SKILL.md SHA-256 remains 224197fb56be75ae395fb2e4e2eb48f3bd64d1e187df5799fd6d661e4d1ec09f.

R11 hardening

R11 preserves R10 isolation, secret-scrubbed shell environment, scoped/revocable device bearer, authenticated ACK/message provenance, exact pairing contract, device self-revocation and fail-closed production boundary.

It additionally requires:

  1. exactly one command_execution start event;
  2. exactly one command_execution completion event;
  3. the same non-empty command item id for start and completion;
  4. exact command text equal to the generated hash-pinned probe wrapper command;
  5. no second shell command;
  6. no file_change, web_search, mcp_tool_call or collab_tool_call item;
  7. successful nested command exit/status;
  8. environment-probe output bound to the hidden nonce, plugin manifest hash and canonical SKILL.md hash;
  9. response evidence for wrapper SHA, expected/observed command SHA, command item-id SHA and exact-single-command counters.

The runtime claim, if and only if the authentic host satisfies all checks, is: ACTUAL_CODEX_CLI_EXEC_ISOLATED_READ_ONLY_EXACT_SINGLE_COMMAND_PROVEN.

Verification receipts

  • branch reconciliation selftest: 01a04c90-0a1b-73de-b575-b96eb6888c89PASS.
  • branch adversarial/static endpoint audit: 01a04c93-18dc-76b6-983c-f2f8ec4f8bd6PASS.
  • post-promotion canonical acceptance selftest: 01a04c94-d54d-71a4-a0d6-a59bffc50773PASS.
  • post-promotion exact-command audit on stable main endpoint: 01a04c95-470c-73d6-91a3-c25d867c4c26PASS.
  • post-promotion dynamic watcher: 01a04c95-61c6-744b-940f-cbb8e61e8cbdPASS / no drift / not urgent.
  • negative pairing-contract request: HTTP 409 DEVICE_PAIRING_CONTRACT_MISMATCH; expected exact R11 launcher/lane/challenge returned; no valid pairing created.
  • independent expert Python review: 0 reported issues.
  • exact CPython compile receipt in an independent executable runtime: NOT_PROVEN. The available browser executor did not emit an execution receipt and the Val Town runtime does not grant subprocess permission. This does not substitute for authentic host preflight.

After the negative test, shared V6 evidence remained:

  • Codex ACKs: 0
  • Codex reverse responses: 0
  • active/pending V6 pairings: 0
  • active V6 device tokens: 0

Truth boundary

  • branch mechanics: PASS
  • live-main promotion: EXECUTED — branch merged to main@208
  • authentic Windows Codex runtime: NOT_PROVEN
  • V6 Codex ACK: NOT_PROVEN
  • V6 reverse response: NOT_PROVEN
  • final ChatGPT semantic ACK: NOT_PROVEN
  • full federated runtime: NO_GO
  • product production: NO_GO

No branch/selftest result is evidence of an authentic Windows Codex run.

Post-promotion snapshot

Observed by the dynamic watcher at 2026-08-29T08:14:13.835Z:

  • relay revision: R11-EXACT-SINGLE-COMMAND-PROBE
  • active lane: CODEX_REAL_RUNTIME_ACCEPTANCE_V6
  • acceptance: PENDING_CODEX_ACK
  • mechanical checks passed: false
  • V6 Codex ACKs: 0
  • V6 Codex responses: 0
  • active V6 device tokens: 0
  • pending V6 pairings: 0
  • approved-not-delivered pairings: 0
  • audit chain: PASS
  • audit tail SHA-256: c246ad55046e7854f1d5a7373f1d5bc463fa4fbe945b9167180324594e9a917c
  • contract drift: false
  • production: NO_GO

The next gate is an authentic Windows Codex run using the live R11 launcher. No synthetic or branch-only test may satisfy that gate.