MCP Verify 1.0.629 deployment verification
Date: 2026-08-14 UTC Release SHA: 195da923c22d248a7192c23b223a2851cedd90a1 Deployment target: IONOS production
Pre-deployment
- Verify suite: 808 passed
- Root unit suite: 194 passed, 111 deselected
make test-suites: 305 passed; line coverage 75.71%; branch coverage 60.85%- Read-only semantic invariants: all 29 passed
Deployment
- Explicit release SHA/version accepted: yes (
1.0.629) - Migration release command: completed through
sentinel-signal.service; no new migration was included - Complete Verify service restart/cache invalidation: completed at
2026-08-14T02:24:27Z /versionbuild and runtime configuration: version/package1.0.629, expected release SHA,trust-core-v2, 20-run/2-full-payload history, final detail HTML cache disabled- Recurring coherence timer: enabled and active on a five-minute interval
The first deployment invocation was halted before restart when the repository's automatic pre-commit version hook revealed a package/release-input mismatch. Production remained on 1.0.628. Release metadata was corrected in 195da923c22d248a7192c23b223a2851cedd90a1, re-synced, and verified as mcp-verify-1.0.629 before the successful restart.
The timer's first scheduled run exposed a synthetic-only false positive: its sequential requests crossed the two-decimal evidence-age rounding boundary (1.74h to 1.75h). The stable trust fields agreed and the warm pass was clean. The monitor now compares confidence score, label, evidence depth, live check count, and threshold while validating each response's age/freshness relationship independently. The corrected systemd run completed at 2026-08-14T02:32:22Z with Result=success and ExecMainStatus=0; the timer remained active with its next run scheduled for 02:37:29Z.
Cold/warm public evidence
The deployment smoke and an independent post-deploy run both completed two iterations without a mismatch across detail, trust-summary, report, policy, and compact compare.
| Server | Snapshot | Readiness | Confidence basis | Alerts | High/critical | Detail cache | Machine materialization | | --- | --- | --- | --- | --- | ---: | --- | --- | | Tracepass | trustsnap_9328fa0faf5f068a | safe_for_evaluation | 100.0; 20 evidence-bearing validations; 22 affirmative checks; 24h threshold | 2 low | 0 | uncached_current | partial, trust core complete | | Playwright | trustsnap_d2356f8c2c499ea3 | metadata_only | not assessed; 0 evidence-bearing validations; 0 affirmative checks | 2 medium | 0 | uncached_current | partial, trust core complete |
The Tracepass detail response at 2026-08-14T02:26:57Z carried:
HTTP/2 200
cache-control: no-store, max-age=0, must-revalidate, no-transform
x-mcp-verify-build: 195da923c22d248a7192c23b223a2851cedd90a1
x-mcp-verify-materialization-state: complete
x-mcp-verify-rendered-at: 2026-08-14T02:27:03.583081+00:00
x-mcp-verify-route-cache: uncached_current
x-mcp-verify-route-cache-age: 0.0
x-mcp-verify-snapshot-id: trustsnap_9328fa0faf5f068a
x-mcp-verify-trust-evaluated-at: 2026-08-14T02:26:57.744578+00:00
x-mcp-verify-version: 1.0.629
The same page rendered 1.8h old, Freshness: fresh, both low alert codes, and High/critical-severity alerts: 0. The homepage independently rendered Tracepass at score 75.0, age 1.7h, and safe for evaluation.
GET responses for trust-summary, report, policy, and compare all carried the same Tracepass snapshot ID and release SHA. None emitted an ETag. Their trust evaluation timestamps were request-current (02:29:11Z through 02:29:13Z), while partial trust-summary explicitly reported trust_core_complete: true and named only deep unavailable fields.
Tracepass technical profiles rendered Technically compatible while its publishability profiles rendered Policy blocked; the provenance probe rendered neutral Not assessed copy without an error/comparison table.
Status: passed