measurements/graviton5-mullvad-92bd475-20260910/README.md

Mullvad production deployment and evidence

Production source: 92bd47508d7ad48442c98148f6b4e09c6169ab5e. Non-debug Graviton5 launch: 2026-09-10 02:39:40 UTC, parent i-0de9795ee9d3ce090, enclave i-0de9795ee9d3ce090-enc1a0892f694bd5b0. The image includes the native AES-probe race, memory-erasure and page-permission fixes. Previous releases and artifacts are preserved.

What passed

Independent reproduction

GitHub run 34430163444 passed both fresh hosted ARM builds and the separate measurement/signing job. Both Docker image IDs and PCR0/1/2 equal the deployed build. Whole EIF bytes differ in unmeasured metadata. The signed report and an actual downloaded EIF verified locally against exact CI revision a0fad3334b501c610c20dbe27137edaa607c90b3. See github/ and verification instructions.

Public release contains both EIFs, the report, signature bundle and scanned frozen source. The source archive has 557 files, no ancestor Git history, account number or credential-pattern findings. Its SHA256 is recorded in source-archive.json.

Production PCR0:

fd164375c25cef773742877caa93d56ec4e170022dc100a16216002fdb80fea8baeb3407ad401bd6bd655d9fdec5c438

Limits and remaining readiness

The fresh production observation authenticates its signed timestamp and session; readers must obtain their own fresh Nitro/TLS verification. Full-duration warm-up, rollover and production key recovery remain pending. The prior calibration estimates about 25 hours of generation, so 24-hour rollover can have fail-closed gaps; the new image has not completed a full-duration calibration. The restart began a new warm-up. Public Cloudflare transport and stronger storage retention remain separate unfinished deployment work.

The conservative 180-second handshake-age gate renews idle tunnels, observed during the production warm-up. This can briefly report unavailable while reconnecting; it neither creates a device nor enables direct upstream fallback. Bootstrap AWS and Mullvad API traffic may go direct. Request/DNS traffic requires WireGuard; Mullvad and DNS resolvers still see destination metadata. No anonymity or exact seven-day lower-bound claim is made.

Raw private test state, account files and offline key/checkpoint files are kept outside this evidence directory. The diagnostic request contains only public data.