# October 3 remediation evidence

See the [remediation report](../../../REVIEW_REMEDIATION_2026-10-03.md) for all
17 findings, additional candidates, recovery compatibility and coverage limits.
The [original audit evidence](../audit/README.md) remains historical evidence of
the pre-fix source at `b09e4d8`; its bug-asserting probes are not passing-fix tests.

## Final repository gates

| Gate | Result | Transcript |
| --- | --- | --- |
| Full Go tests, uncached | Pass | [go-test-all](go-test-all.txt) |
| Full Go race tests, uncached | Pass | [go-race-all](go-race-all.txt) |
| Vet + pinned Staticcheck correctness | Pass | [lint](lint.txt) |
| Pinned Staticcheck U1000 | Pass | [unused checks](staticcheck-u1000.txt) |
| Module tidiness | Pass, no diff | [module check](mod-tidy.txt) |
| Host + six supported platform builds | Pass | [builds](build-all.txt) |
| Frontend lockfile installation | Pass | [npm ci](npm-ci.txt) |
| Frontend unit tests | 22 files / 184 tests pass | [Vitest](frontend-tests.txt) |
| Actual Chromium/Alpine/htmx/SSE integration | 31 tests pass | [browser gate](browser-tests.txt) |
| Frontend generation and embedded vendor consistency | Pass | [frontend build](frontend-build.txt), [vendor check](vendor-check.txt) |
| npm security audit | Zero advisories | [audit JSON](npm-audit-final.json) |
| Govulncheck 1.7.0, six target configurations | All pass, no reachable vulnerabilities | [target results](vulnerability-results.json) and individual `govulncheck-*.txt` transcripts |
| Actual Tailwind watch mode | Source edit changes generated class | [watch script](tailwind-watch.mjs), [result](tailwind-watch.txt) |
| Final TUI shutdown fixture | Uncached race pass; rejects renderer-panic sentinel | [TUI check](tui-fixture-final.txt), native transcripts |

[Go check results](go-check-results.json) record commands, exit codes and UTC
start/finish times. [Source hashes](source-sha256.json) cover code, tests and npm/Go
inputs. No release artifacts, tags, signing or deployment are asserted here.

## Native execution

Both final native runs execute ten test suites: fileops, config, hotkeys,
uiconfig, platform, main command, version, installer, TUI and log. Each run has ten
package `PASS` outcomes and no test failures. OS-specific skips are visible in the
full transcripts and remain coverage limits.

| Host/scope | Result | Evidence |
| --- | --- | --- |
| `win-dev`, Windows amd64, dedicated `agent` account | Ten suites pass; actual private owner/DACL, write-through replacement, protected installer journals, cscript no-overwrite shortcut, quoted cmd execution and log truncation exercised | [native Windows](native-windows-final.txt), [host identity](windows-host.txt) |
| `mac-dev`, macOS arm64 | Ten suites pass; actual disposable DMG attachment/owned cleanup and private recovery in `/Applications` exercised | [native Mac](native-mac-final.txt), [host identity](mac-host.txt) |

[Native binary hashes](native-binaries.json) identify the uploaded test
executables. The [Windows runner](october-native-windows.ps1) and
[Mac runner](october-native-mac-final.sh) show isolated HOME/config directories.
QA directories and host evidence are retained. Native checks used
`C:\Users\agent\AppData\Local\Temp\mpv-october-final` and
`/tmp/mpv-october-remediation-1791046548298`. Mac disk-image tests create an empty
image and simulate a post-attach cancellation/deadline result; they do not claim
arbitrary mid-system-call interruption coverage. Existing player bundles were
not replaced by these tests.

The Windows updater suite skips POSIX-shell helper/crash and child-health
fixtures. F05/F15 replay runs on Linux and native Mac; native Windows covers real
replacement/restoration, trust/journal/key refusal, signed selection and outcome
persistence. Some existing config/permission/symlink tests also skip under their
platform or privilege conditions. This is not exhaustive Windows helper crash,
standard-user permission, Windows Default apps or complete player lifecycle QA.
Windows ARM64 beta hardware/GPU coverage and Intel Mac native execution remain
the owner-accepted gaps in AGENTS.md.

The SSH alias now resolves to `agent@10.0.7.77:22`, as supplied by the owner.
New endpoint keys were matched to the VM's existing trusted host keys before
trusting the new address. Static IP assignment remains with the owner.

## Review and initial failures

- [Installer handoff](installer-notes.md), [updater/config/TUI handoff](updater-notes.md), [Web/UI handoff](ui-notes.md), [root notes](root-notes.md).
- [Independent review](independent-review.md): mixed line endings, preset admission, literal backup directories and Windows owner binding corrected.
- [Native portability review](native-portability-review.md): real native commands, quoted paths, platform fixture contracts and Darwin device grammar.
- [All 71 common reachability dispositions](deadcode-dispositions.json): removed obsolete duplicates versus retained supported APIs/tool/test seams.

`*-initial.txt`, `*-interim.txt` and `native-mac.txt` preserve failed intermediate
runs. The final matrix above uses corrected runs. Initial failures included an
ignored test error caught by Staticcheck, a browser selector matching both a real
card and confirmation, mixed host fixture assumptions, NTFS replacement conflicts,
informational ACL-control comparison and Windows append-handle truncation rights.
These files must not be mistaken for unresolved failures or final passes.
Final transcript review strengthened a cancellation fixture that had accepted a
joined renderer panic; the corrected native runs contain no caught panic.

Verbatim diagnostic captures retain native CRLF and rendered-template whitespace.
Source and maintained-document whitespace checks exclude these raw captures;
all 69 original audit evidence hashes remain unchanged.

The workspace-home preset test incident and matching retained backup are recorded
in the report. No real config contents or private keys are included as evidence.

[Evidence hashes](evidence-sha256.json) cover this directory except the hash
inventory itself.
