measurements/graviton5-production-20260909/README.md

Production measured image and warm-up, 2026-09-09

Production source: 474083ea74d0df069275da613e62a985d6960056, with 43,768,124 iterations per segment, seven segments, and 86,400-second epochs.

Two native ARM builds produced identical PCR0, PCR1, and PCR2. The second used an independent empty BuildKit builder and --no-cache; its exact commands are in reproduce.sh. The pinned Rust image, Debian snapshot, source, and Nitro CLI 1.5.0 were unchanged. This establishes reproducibility of the measured image contents. The complete EIF files have different SHA256 values: their unmeasured metadata includes different build timestamps and Docker image names. Both full EIF descriptions and hashes are preserved for inspection.

PCR0: c743aa2259fa59575de56c0c1e11f8eb5c40e95af991d433af87dc4b04797fc77b73e1ac8777d2b1ba98c900ae1820aa

The production enclave started its hardware-verified warm-up at 2026-09-09 20:38:47 UTC, with 12 CPUs, 24,576 MiB, and Flags: NONE. A fresh client nonce, current AWS Nitro certificate chain/COSE signature, pinned PCR0, and actual inner-TLS peer SPKI authenticated the captured warming-evidence.json. Its signed policy reports the production iteration count, graviton5_verified=true, and state=warming. This is an operational observation and does not claim service readiness. A direct inner request returned HTTP 503, and the ordinary SDK rejected the enclave as not ready.

The first production launch failed closed while retrieving parent credentials immediately after reusing the diagnostic CID. No request was logged by the still-running credential bridge. Restarting that bridge and retrying the same EIF succeeded. The precise kernel/listener failure was not established; the release installer now refreshes the bridge before reusing a CID. Failed launch logs and every diagnostic build/artifact remain on the parent.

The 50,000-sample host calibration predicts roughly 25.14 hours to generate an epoch, so first publication is estimated around 2026-09-10 21:47 UTC. That time is an estimate, not a readiness claim. Full-duration completion and automatic rollover still need observation. The current code rejects requests if its active 24-hour epoch expires before a successor is published.

The Linux aarch64 native wheel was built from the same source, repaired with auditwheel for manylinux_2_34_aarch64, installed into a fresh environment, and tested in a container with --network none. It solved the separate eight-step diagnostic puzzle and decrypted both real Nitro diagnostic records to the exact 559-byte example.com response. Wheel SHA256 and offline test results accompany this file; publication is managed separately by the parent task.