# Evidence

EV-216 records promotion proof for implementation commit `13f29b7`:

- test-first regressions demonstrated host/session overwrite, missing Claude
  backfill, missing surface identity, and missing model/effort metadata;
- 139 focused Reason Guard, dispatcher, benchmark, UI, status, and cross-host
  tests passed;
- the full deterministic verification ran 1,289 tests with zero failures;
- old Claude and Codex sessions backfilled offline through allowlisted parsers
  without launching Claude or persisting prohibited content;
- fixtures distinguish Codex Desktop/CLI, Claude Desktop/CLI, OpenCode, explicit
  overrides, and honest unknown values;
- Codex turn-context, Claude assistant metadata, and OpenCode assistant events
  retain bounded model and effort without forwarding message content;
- source and skeleton Reason Guard/OpenCode hooks are byte-identical;
- the benchmark budget passed at 39.289 ms structured p95 and 7.147 ms p95
  delta, with no model or network dependency;
- state consistency reported zero errors and warnings;
- deterministic workflow CHML was 0 critical / 0 high / 0 medium / 0 low;
- code review WFR-447 found no material findings.

EV-217 records the release-boundary proof from WFR-451: the full local workflow,
release and version-gap hygiene, package contents for 0.16.60, Substrate
capability audit, state gate, and another zero-CHML audit all passed. The first
attempt encountered only a transient Windows denial while atomically saving the
workflow receipt; deterministic attempt 2 completed every step.

Limitation: no live Claude session was run, as explicitly requested. Historical
trusted transcripts and synthetic privacy/adversarial fixtures supplied the
Claude evidence.
