GAL-2 RC4 72-Hour Extended Holdover Official Run: PASS_WITH_DOCUMENTED_BOUNDARY_FAIL_CLOSED_ROW
收藏资源简介:
This archive contains the official GAL-2 RC4 72-Hour Extended Holdover Time Contract characterization package. This was a pre-registered 120-hour run designed to evaluate application-facing temporal governance under controlled upstream loss and recovery. The run included 6 hours of baseline LIVE operation, 72 hours of controlled upstream-disabled holdover, and 42 hours of post-rejoin observation. Final verifier result: PASS_WITH_DOCUMENTED_BOUNDARY_FAIL_CLOSED_ROW Final archive SHA256: dd90816c9082191ce8fafb2cd983ab55eeee8ac2d1ee6cbbc8fa1f63f916ba91 Key results: 14,279 contract samples 0 monotonic_sequence backward steps 0 gal2_time backward steps 72-hour controlled holdover window exercised 1 documented FAIL_CLOSED boundary row at the declared 72-hour holdover policy boundary safe_to_consume changed to false when the declared hard boundary was exceeded Clean LIVE_RESTORED recovery after upstream restoration Return to LIVE after rejoin Final public secret scan rerun PASS with findings_count=0 Embedded Mac B observer archive for cross-machine liveness and timeline corroboration Transition audit chain recomputed and validated Mac B NTP tail and hash authority note included Final archive includes SHA256 manifest and Mac B observer package The most important result is not that the run avoided every boundary condition. The important result is that the Time Contract enforced the declared boundary honestly: when the 72-hour holdover policy limit was exceeded, GAL-2 produced a documented FAIL_CLOSED sample instead of continuing to mark the output as safe. After upstream restoration, the system recovered through LIVE_RESTORED and returned to LIVE without observed backward movement in gal2_time or monotonic_sequence. This archive supports the claim that GAL-2 RC4 can expose application-facing Time Contract behavior across baseline operation, controlled extended holdover, fail-closed boundary enforcement, rejoin, and post-rejoin recovery under one official 120-hour characterization run. Mac B observer note: Mac B served as a coarse external observer and receiver for Mac A pushed heartbeat events. Mac B is not a metrological reference and does not validate UTC accuracy. Mac B continued collecting NTP sanity samples after the official Mac A run ended; those post-run samples are documented as tail samples and are not part of the official 120-hour characterization window. Final stop-and-seal hashes are authoritative for Mac B NTP logs. Scope boundary: This package is application-facing Time Contract behavior evidence from one official GAL-2 RC4 characterization run. It is not presented as UTC accuracy certification, metrology certification, production SLA evidence, physical oscillator control evidence, universal 72-hour holdover safety evidence, or a replacement for UTC, GNSS, PTP, NTP, chrony, grandmasters, hardware clocks, or existing timing infrastructure. This is N=1 characterization evidence.



