{
  "schemaVersion": "1.0",
  "title": "Cal.diy isolated-live qualification on 13 July 2026",
  "description": "Historical result: PASS. The retained artifact records qualification at 2026-07-13T12:05:20.671410Z and restart verification at 2026-07-13T12:05:26.883165Z.",
  "canonical": "https://getaip.org/docs/testing/cal-diy-isolated-live",
  "route": "/docs/testing/cal-diy-isolated-live",
  "source": "docs/testing/cal-diy-isolated-live.md",
  "protocol": "Agent Interoperability Protocol",
  "protocolVersion": "1.0",
  "section": "Qualification and Evidence",
  "documentType": "Qualification evidence",
  "language": "en",
  "revision": {
    "lastReviewedRevision": "97be86e9efedf07ecf1783b03800f683f107fb04",
    "documentationSourceRevision": "9192fef3695ad294994f2712f6d156241e5e92fb",
    "basis": "frontmatter"
  },
  "downloads": {
    "md": "/docs/download/testing/cal-diy-isolated-live.md",
    "txt": "/docs/download/testing/cal-diy-isolated-live.txt",
    "json": "/docs/download/testing/cal-diy-isolated-live.json",
    "pdf": "/docs/download/testing/cal-diy-isolated-live.pdf"
  },
  "content": {
    "format": "text/markdown",
    "markdown": "---\ntitle: Cal.diy isolated-live qualification on 13 July 2026\ndescription: Evaluate the exact historical Cal.diy result, its retained evidence, and its current limitations\nkind: qualification\naudience: evaluator\nappliesTo: \"1.x\"\nwritingStandard: \"aip-docs/1.0\"\nlastReviewedRevision: \"97be86e9efedf07ecf1783b03800f683f107fb04\"\n---\n\n# Cal.diy isolated-live qualification on 13 July 2026\n\n**Historical result: `PASS`.** The retained artifact records qualification at\n`2026-07-13T12:05:20.671410Z` and restart verification at\n`2026-07-13T12:05:26.883165Z`.\n\nThis result applies only to the AIP source digest, harness, images, Cal.diy\nrevision, topology, and assertions identified below. It does not qualify the\ncurrent documentation review revision\n`97be86e9efedf07ecf1783b03800f683f107fb04`, another Cal.diy deployment, or the\ncomplete AIP platform.\n\n## Understand the evidence level\n\nThe result is historical live-product evidence. Its strongest retained record\nis a redacted JSON artifact with exact identities and observations. The\noriginal narrative report adds procedure and control detail, while retained\nsource confirms the structure of the campaign. Neither source code nor a\nsuccessful historical status proves that the campaign passed again.\n\n| Evidence | What it supports | Limitation |\n| --- | --- | --- |\n| Retained JSON result | Exact artifact identities, UTC times, status, correlation values, product observations, webhook outcomes, and restart result | It does not contain raw logs, command exits, cleanup confirmation, or a checksum manifest of the full run |\n| Historical narrative | Declared scope, topology, security controls, procedure, assertions, and supplemental deterministic gates | These statements are not all independently represented in the JSON result |\n| Retained source | The Cal.diy commit and tree, historical AIP base commit, and current form of the qualification campaign | The run included uncommitted AIP material identified only by digest |\n\nThe retained JSON bytes have SHA-256 digest\n`507c2136aa695a5e34efddd6fe5dc6b50e46de7d898c5ad39c3d5f7ebbbb82b3`.\n\n## Identify the exact artifacts\n\n| Artifact | Recorded identity |\n| --- | --- |\n| AIP source base commit | `d1d1a79d030d16e12d2ec8b46201e29cdfbdce5e` |\n| AIP source digest used by the build | `07b500c9ac0ff8ac5becc6b77c5661587fbe08de97522e21fed0e98edd94cee0` |\n| Qualification harness digest | `605d580cb913ccf6673e6ca6465261b5593e71df806ca93f4b6d9def79950691` |\n| AIP qualification image | `sha256:60ace4f074ad7f790801c6171e3f1dc9b66e7bf0dea4ed7291233a5b107131fd` |\n| AIP builder image | `sha256:77237dd363a0b127bb5ef532c2d64c0deb380b738e43a9c4bdac73398d6d0a08` |\n| AIP runtime base image | `sha256:240c36104698159b16dd76db37a24d97d04487d7635a6bb1a6f60064141fc969` |\n| Cal.diy upstream commit | `f00434927386c9ecdcbd7e6c5f82d22044a245bc` |\n| Cal.diy source tree | `ae0db7000d0479c20af5c82de60863a34165e2e2` |\n| Cal.diy image | `sha256:52be5e3d24f65c4c42793702d93e68fa19ffa2c2fd45269e3ae60e6e81f0cc4a` |\n| Qualification runner image | `sha256:50ae7f4dda0ef887ff4259bcfb610a2d6d4ea78bf6440a49c0ae583050a3a01a` |\n\nThe Cal.diy commit is present in the retained official upstream checkout. Its\nGit tree is exactly the source-tree value in the artifact. The AIP base commit\nis retained in a historical source checkout, but the build's source digest is\nnot that commit's Git tree because the campaign included uncommitted material.\n\nThe digest makes that historical input distinguishable. It does not preserve\nthe changed files or make the exact source tree reconstructable. A new release\nclaim therefore requires a clean build and a new campaign.\n\n## Review the isolated topology\n\nThe historical report describes:\n\n- one AIP daemon and one pinned Cal.diy API deployment;\n- separate PostgreSQL databases for AIP and Cal.diy;\n- Redis and an OAuth 2.0 token-introspection service;\n- one non-agent qualification runner;\n- two internal container networks with no published qualification port.\n\nThe machine artifact records the dedicated project name\n`aip-cal-diy-qualification`, `external_network_access: false`, and an empty\n`agent_services` list. These values establish the recorded isolation boundary;\nthey do not describe a production network.\n\n## Review the reported security boundary\n\nThe historical procedure used separate OAuth bearer tokens and distinct\nrequester and approver principals. The retained artifact identifies the two\nprincipals and states `credential_material_in_protocol: false`.\n\nThe narrative further reports these controls:\n\n- trusted identity mapped the requester to one tenant, one external Cal.diy\n  account, and one opaque credential handle;\n- the host resolved protected credential material only at invocation time;\n- envelopes, MCP results, manifests, lifecycle state, evidence, and errors did\n  not contain credential material;\n- the native AIP endpoint used a separate owner-only bearer-token file;\n- webhook verification used the exact raw body, HMAC-SHA256, a signed-time\n  window, constant-time comparison, and durable duplicate suppression.\n\nThe JSON result retains the credential-boundary boolean and webhook outcomes,\nnot the secret files or raw signed requests. This is appropriate for\nredaction, but it prevents an independent byte-for-byte signature review from\nthis artifact alone.\n\n## Reconstruct the reported procedure\n\nThe historical campaign reported this sequence:\n\n1. Create owner-only runtime secrets and reset only the dedicated campaign\n   project and its volumes.\n2. Build the identified AIP image without registry access and inspect selected\n   source files in the identified Cal.diy image.\n3. Start the isolated product, databases, Redis, identity service, AIP daemon,\n   and qualification runner.\n4. Verify native AIP and MCP Streamable HTTP discovery.\n5. Read real availability, plan a booking without mutation, and submit a\n   commit that waits for independent approval.\n6. Approve the immutable request through a separately authenticated principal\n   and verify one correlated booking.\n7. Replay the same action and idempotency identity and verify no second booking.\n8. Exercise valid, duplicate, invalid-signature, and stale webhook deliveries.\n9. Restart the AIP namespace owner and bound processes, then verify durable\n   action, transaction, event, idempotency, and provider facts.\n\nThe historical report says the stack remained available for inspection after\nsuccess. It does not retain an independent cleanup observation.\n\n## Inspect the retained results\n\n| Observation | Retained value |\n| --- | --- |\n| Result schema | `aip.cal-diy.qualification.v1` |\n| Status | `passed` |\n| Native message type | `aip.core.v1.action_result` |\n| MCP transport | `streamable_http` |\n| Stable MCP tools verified | `true` |\n| Admitted Cal.diy capabilities | `81` |\n| Available slot capacity | `8` |\n| Booking count before | `0` |\n| Pending approval observed | `true` |\n| Authenticated decision observed | `true` |\n| Completed action state | `completed` |\n| Booking count after approval and replay | `1` |\n| Idempotent replay observed | `true` |\n| Valid webhook delivery | HTTP `204` |\n| Duplicate webhook delivery | HTTP `204`; retained event count `1` |\n| Invalid webhook HMAC | HTTP `401` |\n| Stale webhook timestamp | HTTP `400` |\n| Restart verified | `true` |\n\nThe artifact also retains action, plan, commit, approval, transaction, run,\nbooking, booking-seat, webhook-marker, and subscription correlation values.\nThose identifiers make the observations internally traceable without exposing\ncredentials.\n\n## Separate reported assertions from retained facts\n\nThe historical narrative reports eleven successful boundaries: native\ninvocation, independent MCP sessions, the 81-capability admission set, live\nslot discovery, non-mutating plan, approval-blocked commit, authenticated\napproval, one booking, idempotent replay, four webhook cases, and restart\nrecovery.\n\nThe JSON artifact retains a related observation for each group, but it does not\nprove every intermediate request, provider response, database query, or\nprocess log independently. Treat the page as a result record, not as a replay\nof the evidence-generation process.\n\n## Account for skipped and missing evidence\n\nThe result excludes:\n\n- every connector other than Cal.diy;\n- capacity, latency, backup, disaster recovery, and rollout qualification;\n- production credentials, traffic, data, topology, and failure modes;\n- operations outside the campaign's booking, approval, replay, webhook, and\n  restart scope;\n- independent evidence that the historically reported workspace format, lint,\n  unit, integration, and conformance commands passed;\n- raw logs, command exit records, a full-run checksum manifest, and cleanup\n  confirmation.\n\nThe current qualification standard makes verified cleanup part of `PASS`.\nBecause this historical artifact has no cleanup field and the narrative says\nthe stack remained available for inspection, it must not be accepted as a new\ncampaign result under the current standard. Its recorded historical status\nremains `PASS` under the scope used on 13 July 2026.\n\n## Reproduce only a new campaign\n\nThe current source retains a campaign entry point:\n\n```sh\nexamples/cal-diy-qualification/qualify.sh\n```\n\nRunning it would create a new result for the current source, harness, images,\nconfiguration, and time. It would not reproduce the historical run unless all\nrecorded inputs, including the unavailable uncommitted source material, were\nrestored exactly. Follow the current [live-product procedure](live-product-e2e.md)\nand record the new evidence independently.\n\n## Retained evidence\n\n- [Machine-readable Cal.diy result](evidence/cal-diy-qualification-2026-07-13.json)\n- [Testing and qualification index](README.md)\n- [Live-product qualification procedure](live-product-e2e.md)\n- [Connector upstream baselines](../connectors/upstream-baselines.md)\n- [Implementation status](../reference/implementation-status.md)\n- [Cal.diy connector](../connectors/cal-diy.md)\n",
    "text": "Cal.diy isolated-live qualification on 13 July 2026\n\nHistorical result: PASS. The retained artifact records qualification at\n2026-07-13T12:05:20.671410Z and restart verification at\n2026-07-13T12:05:26.883165Z.\n\nThis result applies only to the AIP source digest, harness, images, Cal.diy\nrevision, topology, and assertions identified below. It does not qualify the\ncurrent documentation review revision\n97be86e9efedf07ecf1783b03800f683f107fb04, another Cal.diy deployment, or the\ncomplete AIP platform.\n\nUnderstand the evidence level\n\nThe result is historical live-product evidence. Its strongest retained record\nis a redacted JSON artifact with exact identities and observations. The\noriginal narrative report adds procedure and control detail, while retained\nsource confirms the structure of the campaign. Neither source code nor a\nsuccessful historical status proves that the campaign passed again.\n\n| Evidence | What it supports | Limitation |\n\n| Retained JSON result | Exact artifact identities, UTC times, status, correlation values, product observations, webhook outcomes, and restart result | It does not contain raw logs, command exits, cleanup confirmation, or a checksum manifest of the full run |\n| Historical narrative | Declared scope, topology, security controls, procedure, assertions, and supplemental deterministic gates | These statements are not all independently represented in the JSON result |\n| Retained source | The Cal.diy commit and tree, historical AIP base commit, and current form of the qualification campaign | The run included uncommitted AIP material identified only by digest |\n\nThe retained JSON bytes have SHA-256 digest\n507c2136aa695a5e34efddd6fe5dc6b50e46de7d898c5ad39c3d5f7ebbbb82b3.\n\nIdentify the exact artifacts\n\n| Artifact | Recorded identity |\n\n| AIP source base commit | d1d1a79d030d16e12d2ec8b46201e29cdfbdce5e |\n| AIP source digest used by the build | 07b500c9ac0ff8ac5becc6b77c5661587fbe08de97522e21fed0e98edd94cee0 |\n| Qualification harness digest | 605d580cb913ccf6673e6ca6465261b5593e71df806ca93f4b6d9def79950691 |\n| AIP qualification image | sha256:60ace4f074ad7f790801c6171e3f1dc9b66e7bf0dea4ed7291233a5b107131fd |\n| AIP builder image | sha256:77237dd363a0b127bb5ef532c2d64c0deb380b738e43a9c4bdac73398d6d0a08 |\n| AIP runtime base image | sha256:240c36104698159b16dd76db37a24d97d04487d7635a6bb1a6f60064141fc969 |\n| Cal.diy upstream commit | f00434927386c9ecdcbd7e6c5f82d22044a245bc |\n| Cal.diy source tree | ae0db7000d0479c20af5c82de60863a34165e2e2 |\n| Cal.diy image | sha256:52be5e3d24f65c4c42793702d93e68fa19ffa2c2fd45269e3ae60e6e81f0cc4a |\n| Qualification runner image | sha256:50ae7f4dda0ef887ff4259bcfb610a2d6d4ea78bf6440a49c0ae583050a3a01a |\n\nThe Cal.diy commit is present in the retained official upstream checkout. Its\nGit tree is exactly the source-tree value in the artifact. The AIP base commit\nis retained in a historical source checkout, but the build's source digest is\nnot that commit's Git tree because the campaign included uncommitted material.\n\nThe digest makes that historical input distinguishable. It does not preserve\nthe changed files or make the exact source tree reconstructable. A new release\nclaim therefore requires a clean build and a new campaign.\n\nReview the isolated topology\n\nThe historical report describes:\n• one AIP daemon and one pinned Cal.diy API deployment;\n• separate PostgreSQL databases for AIP and Cal.diy;\n• Redis and an OAuth 2.0 token-introspection service;\n• one non-agent qualification runner;\n• two internal container networks with no published qualification port.\n\nThe machine artifact records the dedicated project name\naip-cal-diy-qualification, externalnetworkaccess: false, and an empty\nagentservices list. These values establish the recorded isolation boundary;\nthey do not describe a production network.\n\nReview the reported security boundary\n\nThe historical procedure used separate OAuth bearer tokens and distinct\nrequester and approver principals. The retained artifact identifies the two\nprincipals and states credentialmaterialinprotocol: false.\n\nThe narrative further reports these controls:\n• trusted identity mapped the requester to one tenant, one external Cal.diy\n  account, and one opaque credential handle;\n• the host resolved protected credential material only at invocation time;\n• envelopes, MCP results, manifests, lifecycle state, evidence, and errors did\n  not contain credential material;\n• the native AIP endpoint used a separate owner-only bearer-token file;\n• webhook verification used the exact raw body, HMAC-SHA256, a signed-time\n  window, constant-time comparison, and durable duplicate suppression.\n\nThe JSON result retains the credential-boundary boolean and webhook outcomes,\nnot the secret files or raw signed requests. This is appropriate for\nredaction, but it prevents an independent byte-for-byte signature review from\nthis artifact alone.\n\nReconstruct the reported procedure\n\nThe historical campaign reported this sequence:\n1. Create owner-only runtime secrets and reset only the dedicated campaign\n   project and its volumes.\n2. Build the identified AIP image without registry access and inspect selected\n   source files in the identified Cal.diy image.\n3. Start the isolated product, databases, Redis, identity service, AIP daemon,\n   and qualification runner.\n4. Verify native AIP and MCP Streamable HTTP discovery.\n5. Read real availability, plan a booking without mutation, and submit a\n   commit that waits for independent approval.\n6. Approve the immutable request through a separately authenticated principal\n   and verify one correlated booking.\n7. Replay the same action and idempotency identity and verify no second booking.\n8. Exercise valid, duplicate, invalid-signature, and stale webhook deliveries.\n9. Restart the AIP namespace owner and bound processes, then verify durable\n   action, transaction, event, idempotency, and provider facts.\n\nThe historical report says the stack remained available for inspection after\nsuccess. It does not retain an independent cleanup observation.\n\nInspect the retained results\n\n| Observation | Retained value |\n\n| Result schema | aip.cal-diy.qualification.v1 |\n| Status | passed |\n| Native message type | aip.core.v1.actionresult |\n| MCP transport | streamablehttp |\n| Stable MCP tools verified | true |\n| Admitted Cal.diy capabilities | 81 |\n| Available slot capacity | 8 |\n| Booking count before | 0 |\n| Pending approval observed | true |\n| Authenticated decision observed | true |\n| Completed action state | completed |\n| Booking count after approval and replay | 1 |\n| Idempotent replay observed | true |\n| Valid webhook delivery | HTTP 204 |\n| Duplicate webhook delivery | HTTP 204; retained event count 1 |\n| Invalid webhook HMAC | HTTP 401 |\n| Stale webhook timestamp | HTTP 400 |\n| Restart verified | true |\n\nThe artifact also retains action, plan, commit, approval, transaction, run,\nbooking, booking-seat, webhook-marker, and subscription correlation values.\nThose identifiers make the observations internally traceable without exposing\ncredentials.\n\nSeparate reported assertions from retained facts\n\nThe historical narrative reports eleven successful boundaries: native\ninvocation, independent MCP sessions, the 81-capability admission set, live\nslot discovery, non-mutating plan, approval-blocked commit, authenticated\napproval, one booking, idempotent replay, four webhook cases, and restart\nrecovery.\n\nThe JSON artifact retains a related observation for each group, but it does not\nprove every intermediate request, provider response, database query, or\nprocess log independently. Treat the page as a result record, not as a replay\nof the evidence-generation process.\n\nAccount for skipped and missing evidence\n\nThe result excludes:\n• every connector other than Cal.diy;\n• capacity, latency, backup, disaster recovery, and rollout qualification;\n• production credentials, traffic, data, topology, and failure modes;\n• operations outside the campaign's booking, approval, replay, webhook, and\n  restart scope;\n• independent evidence that the historically reported workspace format, lint,\n  unit, integration, and conformance commands passed;\n• raw logs, command exit records, a full-run checksum manifest, and cleanup\n  confirmation.\n\nThe current qualification standard makes verified cleanup part of PASS.\nBecause this historical artifact has no cleanup field and the narrative says\nthe stack remained available for inspection, it must not be accepted as a new\ncampaign result under the current standard. Its recorded historical status\nremains PASS under the scope used on 13 July 2026.\n\nReproduce only a new campaign\n\nThe current source retains a campaign entry point:\n\nexamples/cal-diy-qualification/qualify.sh\n\nRunning it would create a new result for the current source, harness, images,\nconfiguration, and time. It would not reproduce the historical run unless all\nrecorded inputs, including the unavailable uncommitted source material, were\nrestored exactly. Follow the current live-product procedure (live-product-e2e.md)\nand record the new evidence independently.\n\nRetained evidence\n• Machine-readable Cal.diy result (evidence/cal-diy-qualification-2026-07-13.json)\n• Testing and qualification index (README.md)\n• Live-product qualification procedure (live-product-e2e.md)\n• Connector upstream baselines (../connectors/upstream-baselines.md)\n• Implementation status (../reference/implementation-status.md)\n• Cal.diy connector (../connectors/cal-diy.md)\n"
  },
  "integrity": {
    "algorithm": "sha256",
    "sourceDigest": "105903f3e07295923376485fc0fef6627cfee07f2756ff87c1dece07b242e508"
  }
}
