GLMCHAT V2.2.1 — CURRENT ISSUE STATUS REGISTER RELEASE-BLOCKING EXTERNAL GATES — OPEN P0-001 Successful PHP backend path with all required extensions. P0-002 Live LiteSpeed domain-root deployment acceptance. P0-003 Live LiteSpeed nested-subdirectory acceptance. P0-004 Target-host .htaccess and private-path enforcement. P0-005 Live HTTPS, proxy and session-cookie behaviour. P0-006 Upgrade using a cloned real production database/storage directory. P0-007 Tested rollback after an intentionally failed upgrade. P0-008 Live Together API-key validation and error paths. P0-009 Live GLM-5.2 chat, reasoning, streaming and cancellation. P0-010 Live function calling and autonomous PHP-tool execution. P0-011 Live vision routing and image validation. P0-012 Live Together TTS voice generation and playback. P0-013 Streaming/SSE behaviour through the production LiteSpeed/proxy stack. P0-014 Physical Android Chrome acceptance. P0-015 Physical Samsung Internet acceptance. P0-016 Physical TalkBack acceptance. MATERIAL OPEN RISKS P1-002 Six-digit PIN remains a limited-entropy local secret; device-bound passkey/WebAuthn protection remains recommended for high-sensitivity use. P1-004 Offline revocation cannot be immediate while a device remains disconnected; the seven-day maximum age limits but does not remove this constraint. P1-010 Source build and test claims cannot be reproduced because the matching source repository, package files and suites are absent. P1-011 React 16.0.0 and ReactDOM 16.0.1 require a formal dependency-risk decision and controlled source-level upgrade plan. P1-013 Real long-running workflow, concurrency, lease and contention testing is outstanding. P1-014 IndexedDB quota, transaction failure and browser-eviction testing is outstanding. P1-015 Large file and hostile ZIP handling on the target host is outstanding. P1-016 Current Together model, voice and cost settings require live verification. IMPORTANT OPEN UX/ACCEPTANCE ITEMS P2-010 Mandatory security headers must be confirmed on the target host, not only the compatibility harness. P2-011 The install-before-setup product decision requires physical-browser acceptance and recovery testing. P2-012 Low-connectivity, packet-loss and captive-portal behaviour remains untested. P2-013 Downloads and Android storage handling remain untested on target browsers. P3-005 Physical screenshots/device evidence is not included. CONFIRMED CLOSED OR REMEDIATED P1-001 Offline sensitive-data encryption. P1-003 Offline credential maximum age. P1-005 Background replay description corrected to match actual behaviour. P1-006 Runtime helper cache policy. P1-007 Controlled service-worker updates. P1-008 Production mock-provider restriction. P1-009 SBOM regeneration and exact inventory. P1-012 Third-party notices. P2-001 Service-worker fallback response. P2-002 Service-worker registration diagnostics. P2-003 Production preview bypass. P2-004 Light-only interface alignment. P2-005 Direct-deploy documentation paths. P2-006 Conditional-staging release wording. P2-007 Public-root documentation duplication. P2-008 Offline-lock wording and encrypted-record behaviour. P2-009 Normal update-ready interface. P3-001 Unused Workbox asset. P3-002 New-chat PWA shortcut. P3-003 SBOM scope/inventory consistency. P3-004 Documentation duplication in the public deployable tree.