IMPORTANT: This report was supplied with V2.2.0 and is retained as historical evidence. Its test suites are not included in the deployment-only bundle and were not independently rerun during V2.2.1 hardening. GLMChat V2.2.0 — HISTORICAL SUPPLIED VERIFICATION REPORT Date: 2026-07-22 Verdict: HISTORICAL SUPPLIED LOCAL/EMULATED EVIDENCE — PRODUCTION ACCEPTANCE REMAINS REQUIRED CLASSIFICATIONS - EXECUTED PASS: the command or browser check ran successfully. - STATIC PASS: source/configuration inspection met the requirement. - EXTERNAL NOT EXECUTED: requires the target host, device or provider. 1. SOURCE, ARCHITECTURE AND FEATURE LOCK EXECUTED PASS Maintainable React/PHP/Python syntax checks. EXECUTED PASS Feature lock: 85 protected files and 26 capability contracts. STATIC PASS Active frontend is source/frontend/react/*.js with local React/ReactDOM; the historical bundle is provenance only. STATIC PASS PHP 8.2+/SQLite/LiteSpeed remains the sole production backend/deployment architecture. STATIC PASS Versioned agents, teams, workflows, templates, immutable snapshots, workers, stages, events, checkpoints, approvals and interventions are mapped. STATIC PASS Tool execution remains server-allowlisted, schema-validated and project-confined. 2. AUTOMATED CONTRACT AND MIGRATION TESTS EXECUTED PASS Node contract tests: 24 passed, 0 failed. EXECUTED PASS PHP portable/static checks: 50 passed. EXECUTED PASS SQLite migration scenarios: 4 passed, including fresh, upgrade, concurrency and conflict/idempotency paths. EXECUTED PASS Bootstrap preflight/logger fallback under php -n. STATIC PASS Migrations 011 and 012 add typed orchestration, templates, project metadata and branch lineage without destructive downgrade behaviour. 3. BROWSER AND OFFLINE ACCEPTANCE EXECUTED PASS Offline-first runtime: unlock, persistence, sync, replay, conflict, service worker and credential scan. EXECUTED PASS PWA install gate: native prompt, dismissal, appinstalled, standalone bypass, display-mode transition and embedded-browser recovery. EXECUTED PASS Accessibility: four Android layouts, 200% text, named controls, minimum targets, visible focus, one controlled live region and modal restoration. SUPPLIED PASS Deferred reopen synchronisation: durable registration/fallback, exact attempts, auth pause, conflict, exhaustion, ordering, reload, profile restart, worker update, idempotency and private-cache exclusion. EXECUTED PASS Responsive UI: 320, 360, 390, 412, 480 and 600 CSS-pixel portrait widths, team wizard, short landscape, reduced motion and dominant chat viewport. EXECUTED PASS Full-spec UI evidence: 21 production screens/wizards at 390x844 with no horizontal overflow. STATIC PASS Offline chat and AI/tool actions are never silently submitted. 4. AGENTIC AND USER-FACING INTEGRATION STATIC PASS Wizard fields serialize as typed server-validated definitions rather than prompt-only prose. STATIC PASS Custom stages instantiate from the immutable workflow definition. STATIC PASS Workers, delegation, coordination, checkpoints and approval/intervention events are persistent execution records. STATIC PASS Pause/resume, cancellation, retry, optional-stage skip, reassignment, tool revocation and checkpoint branching have server routes/state transitions. STATIC PASS Together integration includes bounded function calls, structured output, preserved reasoning and separate vision routing. STATIC PASS Chat exposes visible file context, image attachments, preflight, Stop, regenerate, export, prompt saving and conversion to agent/workflow. STATIC PASS Projects, templates, history, prompts, costs, provider settings, TTS, privacy and conflict resolution are reachable. 5. BUILD, CACHE AND ADVERSARIAL CHECKS EXECUTED PASS Two clean builds produced an identical tree SHA-256 recorded in evidence/BUILD_ADVERSARIAL_RESULTS.txt. EXECUTED PASS A semantic source mutation changed the application asset filename. EXECUTED PASS A falsified content fingerprint was rejected. EXECUTED PASS Cross-release immutable-URL reuse with changed bytes was rejected. STATIC PASS HTML, precache metadata, service-worker cache version, build manifest and SBOM are coordinated by one build. STATIC PASS Private API/auth/setup responses are excluded before all Cache Storage branches. 6. SECURITY AND DATA INTEGRITY STATIC PASS CSP contains no unsafe-eval or inline event-handler allowance. STATIC PASS Direct access to server/storage/source/tests/scripts/logs/databases/keys/evidence/implementation-prompts is denied. STATIC PASS Session, CSRF, regeneration, rate limiting, PIN lockout and recent-PIN controls remain mapped. STATIC PASS Together credentials retain authenticated encryption and secret-free logging/export/error handling. STATIC PASS ZIP traversal, symlink, size and decompression protections remain mapped. STATIC PASS Tool arguments reject unknown fields/types; unregistered tools and path escapes are rejected; loops and retries are bounded. STATIC PASS IndexedDB and queued mutations survive shell-cache updates. 7. PACKAGING STATIC PASS Full-source profile excludes node_modules, nested release ZIPs, __pycache__, bytecode and transient build caches. STATIC PASS Deployment-only profile excludes source, tests, scripts, handovers, evidence, logs, databases, keys and temporary files. STATIC PASS ZIP member safety, manifest hashes, references, PHP/JavaScript syntax, JSON, CSP, protected storage and secret scans are mandatory clean-extraction gates. 8. EXTERNAL ACCEPTANCE EXTERNAL NOT EXECUTED Physical ARM64 Android Chrome and TalkBack. EXTERNAL NOT EXECUTED Physical Samsung Internet. EXTERNAL NOT EXECUTED Live LiteSpeed root and nested-subdirectory deployment, rewrites, headers and permissions. EXTERNAL NOT EXECUTED Live PHP SQLite/cURL/mbstring/ZIP success path in this container because those extensions are absent. EXTERNAL NOT EXECUTED Live Together key validation, GLM-5.1 inference, function calling, vision and TTS. FINAL ASSESSMENT No known source, contract, migration, browser-emulated, security-static, deterministic-build or packaging blocker remains. External checks are acceptance activities and are not represented as passes. 9. DOCUMENTATION COMPLETENESS STATIC PASS README, documentation index, user guide, installation/acceptance guide, administration/operations guide and release notes are present. STATIC PASS Documentation distinguishes deployment, full-source and documented-bundle profiles. STATIC PASS Upgrade and rollback guidance preserves storage, IndexedDB and queued mutations. STATIC PASS External live-host, physical-device and provider acceptance remains explicitly unexecuted.