# October 3 2026 codebase audit evidence

This evidence accompanies [the audit report](../../../CODEBASE_AUDIT_2026-10-03.md)
at source commit `b09e4d8d6d583c6711e92ada119536c5b09e1e6e`. Product source was
unchanged. [Scope and tool versions](scope.json) and
[the starting worktree](initial-worktree.txt) establish provenance.

## Baseline validation

| Check | Evidence |
| --- | --- |
| Go normal and race tests, lint, module tidy, build | [Command receipts](go-checks.json), [normal](go-test.txt), [race](go-race.txt), [lint](lint.txt), [build](build.txt) |
| Locked frontend install, 183 unit tests, vendor check | [Command receipts](frontend-checks.json), [unit tests](npm-test.txt), [vendors](vendor-check.txt) |
| Existing real Chromium integration suite | [21 passing browser tests](browser-tests.txt) |
| Six direct application cross-builds | [Results](cross-builds.json) |
| Govulncheck 1.7.0 for six target configurations | [Host result](govulncheck.txt), [other targets](platform-vulnerability-results.json) |
| npm dependency advisory | [Complete JSON response](npm-audit.txt) |
| CSS freshness, coverage, Staticcheck U1000 | [Command receipts](extended-checks.json), [CSS](tailwind-check.txt), [coverage](go-coverage.txt), [unused check](unused.txt) |
| Go module checks and formatting | [Module verification](go-mod-verify.txt), [tidy diff](go-mod-tidy.txt), [gofmt output](gofmt.txt) |
| Production function reachability | [Common six-target inventory](deadcode-common.json), per-target `deadcode-*.json`, [all Linux command roots](deadcode-linux-all-commands.json) |

The scanner was built as a host executable before setting target GOOS/GOARCH.
Cross-builds and source vulnerability analysis do not establish native execution,
permission behavior, signing acceptance or actual GPU acceleration.

## Focused reproduction

On Linux amd64, from the repository root:

```sh
python3 docs/qa/2026-10-03/audit/run-probes.py
```

The runner creates private temporary files and a Go overlay, executes the shipped
implementations with disposable configurations and controlled inputs, and writes
[receipts](focused-results.json), [Go observations](focused-go-probes.txt),
[hotkey observations](hotkeys-probe.txt), [CPU selection](cpu-selection-probe.txt)
and [JavaScript observations](ui-javascript-probe.txt). Go probe sources use
`.go.txt` so they do not become repository Go packages. These probes **assert or
print existing faulty behavior**; their successful exit is reproduction evidence,
not a passing regression for corrected behavior.

Installer tests cover unrelated-sibling recovery deletion, shortcut executable
overwrite, FFmpeg scratch deletion, restore permissions, a Flatpak deadline and
tar preflight. Updater/editor tests cover backup-consumption replay, retained
committed journals, interrupted migration edits and public proof construction.
The hotkey program records quoted-command and permission changes. The CPU probe
masks FMA in a CPU feature snapshot without executing a selected player binary.

The Web probes use real Go handlers/templates. The saved
[rendered Config fragment](ui/rendered-custom-config.html) was examined in a
detached Chromium document, with [observed select values](ui/chromium-dom-result.txt)
preserved; it is a fragment, not a complete
application preview. The JavaScript program executes shipped job code with DOM
and EventSource adapters. It does not replace a real browser/SSE regression gate.
The existing 21-test browser gate is recorded separately above. Focused live T3
preview navigation was unavailable because its browser host could not reach the
fixture's loopback listener; no production bind/auth policy was weakened.

## Detailed review observations

[Installer notes](installer/review-notes.txt),
[updater and configuration notes](updater-config/review-notes.txt), and
[Web and TUI notes](ui/review-notes.txt) preserve the subsystem observations and
their limitations. Temporary paths in those original notes are historical; the
portable runner and copied sources above are the retained reproduction route.

No destructive native Windows/macOS installation, second-account attack,
production publication, real power loss or private signing-service access was
performed. All implementation findings remain open; this task wrote audit
documentation and evidence only.
