feat: ship native Haiku Causal Chat RC6 - #3
Conversation
|
Native baseline from the implementation environment (therefore not independent and not sufficient to close the external-user gate): An independent tester should produce the same package/application hashes and |
|
Clean external-runtime receipt from GitHub Actions run 29895628287. The action booted a fresh Haiku R1/beta5 VM, used no source checkout, and downloaded the public RC6 assets. This is independent infrastructure evidence, not an unaffiliated human receipt. The next qualifying witness is a person outside the implementation environment following the linked public instructions and posting stdout only. |
|
Latest-head replay: run 29895795213 repeated the clean Haiku VM public-release receipt at PR head |
Outcome
This ships a native Haiku
BApplicationchat client plus a reproducible, rootless NATS/JetStream operator bundle. RC6 adds a privacy-safe external install/round-trip receipt so an independent Haiku user can validate the release without exposing a hostname, username, IP address, message body, or local path.61d3c961749ff5ee4ea7a48a2b5a727804f5a0fbbcce94a5e651094b8a2123deIndependent Haiku validation requested
On an x86_64 Haiku host, follow the Independent public receipt instructions, then paste only the checker stdout into a PR comment and say whether you are independent of the implementation environment. Keep stderr and the retained local evidence directory private.
The expected receipt schema is
causal-haiku-external-v1; a pass binds the downloaded package digest, exact native application digest, Haiku release/architecture, public publish round trip, and exactly-once history observation. A fresh GitHub-hosted Haiku R1/beta5 VM has now produced that receipt without a source checkout. This proves a separate runtime, disk image, and network path; it is not independent human judgment.Security boundary
The public compatibility endpoint at
nonlocal.info:4222is plaintext and is used only for a fresh non-sensitive marker. Do not send credentials or private content. Authenticated TLS/JetStream deployment is included and tested, but the current secure endpoint remains tailnet-scoped until the tailnet owner enables Funnel.Validation
Known open gates
This PR is the public response surface for the first gate; the exact Funnel command has already been validated up to its owner-approval boundary.