Ranex

Current limits

Read the boundaries before you rely on the result.

A verdict answers the policy and evidence it was given. These limits matter when deciding what to trust and what to keep under independent control.

The confinement controller is trusted infrastructure

Strict-local execution requires a qualified Linux host. The controller runs as the same user and remains part of the trusted infrastructure. A signed result is not proof that the entire host is outside an attacker’s reach.

Ordinary gate evaluation does not authenticate the approver

No self-approval compares the producer and approver. Ordinary gate evaluate --approver uses an unauthenticated name; signed approver verification exists only in the task-merge approval path. Use the signed task-merge path when approval identity must be verified, with independently controlled producer keys and principal catalog.

A hash chain needs an independent head to detect rollback

Journal verification checks the retained chain. A consistent earlier prefix can still verify. Keep an independent head outside that journal if you need to detect truncation or rollback.

The suite manifest freezes test IDs, not test bodies

Missing required IDs are refused. A test can keep its ID while its assertions change. Keep acceptance tests under independent control; an ID manifest alone cannot establish that the assertions are trustworthy.

The working evidence file can be replaced

Do not treat evidence.json as an append-only archive. Preserve the admitted records and journal you need for review, including an independent head where rollback detection matters.

Network behavior depends on the execution stage

Dependency provisioning needs network access. Qualified sealed test execution uses a narrower boundary. Read the operator setup for the mode you use instead of assuming the whole workflow is offline.

External-harness delegation remains a prototype

The source-run CLI and verification path are available. That does not establish a complete installed workflow for arbitrary agents, scenario compilation or every acceptance policy. Review current capabilities before connecting a worker.

Reviewed against the kernel documentation on 8 September 2026. The maintained operator guide describes current capabilities and limits.