Design stage: there is no released app yet. This site separates what exists in the repository from what is planned. See status

Status

What we ran, and what it does not prove

On 2026-10-04 we ran the four Rust test suites on commit f3f328d. All 460 tests passed. That is a statement about code, not about a product.

Reading note

We ran cargo test --locked in each workspace of a clean checkout of the repository, with build output kept outside it. We did not review the code line by line, run the planned stress scenarios, or test anything on Windows or on real shop hardware.

SuiteTests passedWhat it covers
Simca Packaging220Registry, resolver, package container, signing, delta plans, removal plans, retention, offline and hidden-door guards.
Simca core100Money, database, the seven elements, removal and retention, profile and hidden-door checks, a kill test.
Simca Logistics76Reputation math, jobs and bids, the waybill handshake, retention, a separate-process service.
Simca Launcher (library)64The opening request, staging, rollback, offline install, entitlements, the fork guard.

The repository's own stress records

The repository keeps an append-only record of stress-test runs. It now holds 45 records over 22 scenarios: 44 passed and one failed because a scenario named the wrong package; that failure is kept, the scenario was corrected and re-run, and it passed. The test counts match what we saw (220, 100, 76 and 64).

Planned and not run

Twelve scenarios are listed as planned and have no results: real power loss on a disk or virtual machine, a long kill loop, coverage-guided fuzzing of the package, signed-document and spec parsers, flipping every byte of a package, a full disk during an update, a clock set backwards, a two-key signing rehearsal, catalog-scale performance, Windows installer and antivirus checks, and concurrent writers.

What these results do not show

  • No real power-loss test: the kill test aborts a child process, nothing more.
  • No fuzzing: the opening-request test is a list of hand-written hostile inputs.
  • The two-key signing tests use throwaway keys, and no key ceremony has happened.
  • Nothing was tested on Windows, on old hardware, on phones or in a shop.
  • There is no user interface to test.

Status · What the app core does today · Packaging security model