Skip to content

Evidence: cancellation boundaries and artifact continuity

Publication of this bilingual study and evidence was authorized on 2026-09-07. The experiments ran on 2026-09-06 at CodeFlowMu baseline c008d9db91a21136fc61a4f60314e22db395d5d2. This is not security certification, independent QA, or development authorization.

中文 · Download full evidence ZIP · Full English guide

Articles

Claim mapping

RecordsObservationsRequired qualification
A0–A3Replay rejected; pending request enters cancelled or expired state; approved execution at second 31The 30-second deadline governs review; A1 rejects an unissued credential, not an already approved token being revoked
A4–A6Cancellation rejected while waiting; a research abort check prevents writing; an existing effect remainsNot successful revocation followed by execution; the barrier is injected
Three adapter scenariosPer round: one normal reply, zero replies in either cancellation caseReal local adapter with fake process transport; not a real host's post-lock check
B0–B3Stable same-request digest; changed target rejects old approval; another workspace or task changes operation digestB2/B3 verify digest distinction; B1 additionally verifies execution rejection, not acceptance of every cross-workspace or cross-task path
B4New-process digest matches; historical success coexists with original-path absence after renameThree points for one file; no deletion, power loss, or business acceptance

Twelve service/workspace scenarios and three adapter scenarios each ran twice: 30 observations, not 30 distinct scenarios or an accuracy score. The baseline test set, comprising two existing test files, ran twice, with a total of 39 pass / 0 fail / 0 skip per round. Both original baseline logs are retained in redacted form.

The editorial revision on 2026-09-07 only refines these claim boundaries. Original observations, figures, probes, the download archive, and their hashes remain unchanged; no new experiment was added.

Verification and rerunning

Extract the complete ZIP, enter evidence, and run node check.mjs. It checks the 30 exported observations, two baseline logs, and file hashes. It verifies existing records rather than rerunning the product.

probe-boundaries.mjs and probe-adapter.mjs are configurable copies of the executed research scripts. Hardcoded source paths become CODEFLOWMU_SOURCE_ROOT; the adapter creates its fixture directory for standalone use. Execution still requires authorized access to the fixed CodeFlowMu source, dependencies, and a TypeScript loader. See the bilingual guide. Product source, real tokens, and operational ledgers are not distributed. Readers without source access can check public records but cannot claim a product rerun.

Integrity and redaction

All scenarios, rounds, outcomes, error codes, and effect counts are retained. Machine paths and child PIDs are removed. Original-record hashes and before/after checks for seven product source files are in provenance.json. Hashes identify records and detect changes relative to the manifest; they are not independent signatures or correctness proofs.

The normal adapter scenario ends in cancelled only during cleanup; kill_calls counts fake-process calls. B1's intervening bytes and B4's preserved bytes were reread during editorial review without inventing new original-observation fields. Raw local fixtures and operational configuration are withheld.

OpenHands #4866 and Paperclip #12901 versions/statuses are study-date snapshots. Neither upstream experiments nor the paid Daytona suite were independently rerun. Publication adds no real-host, authorization-revocation, remote-sync, power-loss, or PM/QA acceptance experiment.

Individual files

Last updated: