# Software baseline for the containment evaluation

22 September 2026. Company-authored host regression checks; no independent review.

## Result and scope

The interpreter library suite passed 25 tests and the monitor library suite passed 21, with zero failures, ignored tests or filtered tests. Scope: host regression tests on a development computer against frozen copies of the current sources.

## Relevant coverage

| Existing test | Observation within the test fixture |
|---|---|
| `out_of_bounds_access_halts` | The attempted out-of-window memory access halted execution |
| `capability_index_outside_the_table_rejected_at_load` | The loader rejected an unavailable capability index |
| `unaffordable_capability_is_not_invoked` | The execution budget prevented the capability call |
| `backward_jump_admitted_and_bounded_by_fuel` | A looping program exhausted its execution budget |
| `steady_command_is_permitted` | The monitor permitted the fixture's ordinary command sequence |
| `rate_violation_refuses` | The monitor refused the fixture's excessive command step |
| `latched_refusal_is_terminal` | Later ticks did not clear the refusal; an explicit reset did |
| `independent_feedback_requires_fresh_tracking_state` | Repeated synthetic feedback sequence values triggered a stale verdict |
| `independent_feedback_detects_following_error` | Synthetic measured state outside the configured tracking tolerance was refused |

Feedback samples here are software fixtures. They do not establish independent physical sensing. An explicit reset API exists; the test does not establish who can access it in the integrated product.

## Reproduction and retention

Command in each retained crate directory:

```
cargo test --offline --lib -- --test-threads=1
```

Compiler: `rustc 1.91.0-nightly (7ad23f43a 2025-09-09)`. Native host, default test profile; formal model-checker proofs and hardware timing were not rerun.

Internal run ID: `2026-09-22-host-baseline-01`, under `evidence/software-containment/`. Source snapshots, source hashes, original dirty-tree status, compiler details, full logs and a manifest are retained locally for review. The interpreter is published through the [source page](https://endstop.systems/source). Monitor source is available under evaluation agreement; this public record alone is not a complete reproduction package.

- `endstop-vm` full-log SHA-256: `3b5ecdf879fc23a24e1103b4b397dfa530756bdcada21496e1cf3767499fa239`.
- `endstop-monitor` full-log SHA-256: `fb360173cc6719a51cd43b1bb4847cd47bac4d6ab272fde2e731b0aea4a9dd1e`.

## What remains

Complete mediation of machine commands, protection of configuration and reset authority, independent physical feedback, response and stopping behavior, useful task output, and engineering savings require the [evaluation protocol](ai-containment-evaluation-2026-09-22.md). No general AI or AGI containment claim follows from these tests.
