Summary
The deployed Certification Forge release 795ca1a927b8af649c91bfe74b84f55dc2e5c852 was modified in place on the production host on 2026-09-24 (~11:44 UTC) by an autonomous build (build prompt #39297, "echo-certforge-dispatcher restart storm / giveup"). The change never went through this repository or a CertForge certification run.
What changed
deploy/deploy_forge.sh (dispatcher unit template), and the same line in the live dispatcher systemd unit:
[Unit]
Description=echo-certification-forge - durable subscriber run dispatcher
After=network.target $SERVICE.service
-Requires=$SERVICE.service
+Wants=$SERVICE.service
Assessment
Benign. With Requires=, every restart or crash of the API service was propagated to the dispatcher. That cascade pushed the dispatcher into start-limit-hit during the #39297 incident. With Wants=, the dispatcher keeps its ordering after the API service and still starts it, but a failure of the API service no longer takes the dispatcher down. No code, policy, signing or evidence paths were touched. The pre-change copy was kept next to the modified file, so we left the change in place instead of reverting it.
Why this needs follow-up
- The running release no longer matches its certified source tree. This is the kind of uncertified drift the platform is supposed to prevent.
/v1/status currently reports NOT_READY with product_readiness_report_missing. The signed exact-source readiness report for 795ca1a is no longer present on the host. scripts/master_acceptance.py cannot regenerate it from the committed artifacts/ alone, because the committed P4 evidence (artifacts/p4_forge_acceptance.json, source 8ccfa65) has no completed_phase_gate: "P4" field. P1-P3, P5 (adapter gate GO), P6 (p6_acceptance.summary.json, 12/12) and P7 validate. A fresh P4 hostile acceptance run is required. Hosted CI for 795ca1a is green (run 33543830708).
Recommended actions
- Upstream the
Requires= → Wants= change as a normal PR against main (with a test covering the unit template).
- Cut a new exact-SHA release from that PR's merge commit and re-run the full release pipeline: P4 hostile acceptance,
scripts/master_acceptance.py, and the deploy gate. This recertifies the product and restores a signed product-readiness report.
- Treat any future in-place edit of a deployed release as an incident. Autonomous builders are now gated on a CertForge verdict before any merge, but direct edits to live files bypass that gate.
Filed by the ECHO ops pass on 2026-09-24.
Summary
The deployed Certification Forge release
795ca1a927b8af649c91bfe74b84f55dc2e5c852was modified in place on the production host on 2026-09-24 (~11:44 UTC) by an autonomous build (build prompt #39297, "echo-certforge-dispatcher restart storm / giveup"). The change never went through this repository or a CertForge certification run.What changed
deploy/deploy_forge.sh(dispatcher unit template), and the same line in the live dispatcher systemd unit:Assessment
Benign. With
Requires=, every restart or crash of the API service was propagated to the dispatcher. That cascade pushed the dispatcher intostart-limit-hitduring the #39297 incident. WithWants=, the dispatcher keeps its ordering after the API service and still starts it, but a failure of the API service no longer takes the dispatcher down. No code, policy, signing or evidence paths were touched. The pre-change copy was kept next to the modified file, so we left the change in place instead of reverting it.Why this needs follow-up
/v1/statuscurrently reportsNOT_READYwithproduct_readiness_report_missing. The signed exact-source readiness report for795ca1ais no longer present on the host.scripts/master_acceptance.pycannot regenerate it from the committedartifacts/alone, because the committed P4 evidence (artifacts/p4_forge_acceptance.json, source8ccfa65) has nocompleted_phase_gate: "P4"field. P1-P3, P5 (adapter gate GO), P6 (p6_acceptance.summary.json, 12/12) and P7 validate. A fresh P4 hostile acceptance run is required. Hosted CI for795ca1ais green (run 33543830708).Recommended actions
Requires=→Wants=change as a normal PR againstmain(with a test covering the unit template).scripts/master_acceptance.py, and the deploy gate. This recertifies the product and restores a signed product-readiness report.Filed by the ECHO ops pass on 2026-09-24.