Skip to content

IDE Freeze Execution Report - 2026-08-21

Field Value
Status Engineering execution complete; Build 843 designated; evidence, residual-risk, cybersecurity, and final software-package approvals recorded
Owner BionicLoop engineering
Baseline tag ide-software-freeze-2026-08-21
Baseline commit 91c0e98a9bc9429a0486bebdebffc7d8dbbe300e
Last product-source commit in frozen baseline ae00e754
Execution date 2026-08-21
Updated 2026-09-08

1. Scope

The four primary IDE software verification lanes were executed against the frozen baseline. Remaining sponsor decisions and physical observations are identified below.

2. Controlled Inputs

Execution used an isolated detached checkout of the annotated freeze tag.

Input Identity
BionicLoop 91c0e98a9bc9429a0486bebdebffc7d8dbbe300e
Algo2015 nested source repository b855f871c80e95d6f9226f54b0e60168ff603e36
Algorithm_2015_10_13.cpp SHA-256 f2c61ddc46c45f40bd53712610e00060105d6fe4d912d25f61b34118dc10081e
AlgorithmInterface.h SHA-256 392970bd82f8cc5d978131e1118bb0288e95c57875e469092c8f6c9bcc80368f
ringbuffer.h SHA-256 869bacce22e01cb979bfeae4bf1f31c239b2f93689cc639d3cf305c46b6b8ab3
Base.xcconfig SHA-256 ed7d66f263f626e94e703538945ad63852b1792fbb739ee936c5e59ac38f9e2c
Debug.xcconfig SHA-256 df4c78aa7ea8c5e7f0d2a4981e17dcbf1bc856ddce5671f918767f384a12a792
Release.xcconfig SHA-256 8c83ecc3acd2c23a2fcde93b2aa4e83329e9811d96a31b58bb47149cc55fb942
CC-DEV.xcconfig SHA-256 9c50fa680863be12da1bd604695c6bfe0a2b6b79c5be44d519b077f777d34c80
Formal-run SwiftPM resolution CryptoSwift 1.10.0 / f2a627b84c1ff96f21ac2fcb623ab36142dd5512; SlideButton 5eacebba4d7deeb693592bc9a62ab2d2181e133b; SwiftCharts c354c1945bb35a1f01b665b22474f6db28cba4a2; captured manifest SHA-256 019b5768cfb4fc5c4c3c27106b7df9d60e0d7988eed34a3e75f4e523c625eded
Toolchain Xcode 26.6 (17F113), macOS 26.6.2 (25G83)

Algo2015, the Base/Debug configuration files, and app-workspace Package.resolved are local or ignored inputs in this repository. Their exact formal-run provenance and hashes are recorded rather than silently assumed. CYBER-DEV-001 covers the separate finding that archive 826 used a different CryptoSwift resolution.

3. Formal Lane Results

Lane Result Primary Evidence
STP-ALG-001 Behavioral pass; documentary deviation closed by companion STR-ALG-001 run
STP-AUTO-001 App target pass; three UI-harness deviations closed by companion STR-AUTO-001 run
STP-SIM-001 Pass STR-SIM-001 run
TV-SEC-001 Pass for all 68 local controls defined by TV-SEC-001 STR-SEC-001 run
CYBER-DEV-001 impact companion Pass with archive-matching CryptoSwift 1.9 dependency-impact run

Algorithm

  • All behavioral suites passed with zero failed assertions.
  • Coverage: Algo2015 96.12% line / 87.77% branch; bridge 90.27% line / 65.85% branch.
  • Total-insulin host regression: 1/1 pass.
  • Primary/safety framework identity report: pass.
  • The original SA-006 run could not exact-match the freeze SHA because the immutable review-log entry uses this commit. The freeze linkage companion passed 6/6 with the literal SHA and requirement linkage, closing ALG-DEV-SA-006.

Automated App And UI

  • App unit/integration target: 997 total, 996 passed, 1 intentional IFU reference-table generation helper skip gated by an export directory, 0 failed.
  • The skip was BionicLoopIFUReferenceExportTests.testExportWritesReferenceTablesWhenExportDirectoryIsSet. It is an IFU document-generation helper gated by IFU_EXPORT_DIR, which is supplied only during controlled IFU reference-table generation; it does not omit a dosing or runtime requirement.
  • UI target: 44 total, 41 passed, 3 failed.
  • All three UI failures reproduced in isolation. Two are caused by an inconsistent profile seed. One compares accessibility frames for one-line and wrapped labels even though the production controls share one HStack.

Simulation

  • Core, pod, alert, and real-engine simulation suites passed.
  • evaluation-summary.json reports all TV-SIM-001..005 and TV-SIM-POD-001..004 true.

Cybersecurity Local Controls

  • 68/68 focused tests passed.
  • Participant Files-sharing/open-in-place plist keys are absent.
  • Protected retention, export staging, backup exclusion, clinical share gate, and exact-session recovery archive behaviors passed all 68 tests defined by TV-SEC-001.
  • Deferred cloud/auth/provider controls and commercial cybersecurity closure are not claimed by this result.
  • The archive-matching companion passed 68/68 security tests defined by TV-SEC-001, 8/8 OmniBLE cryptographic/session vectors, 9/9 app unlock tests, and 19/19 core unlock vectors with no frozen product-source change.

4. Formal Deviations and Companion Status

ID Description Engineering Assessment Disposition / Closure
ALG-DEV-SA-006 Freeze review-log row is not literal-SHA machine-linkable Documentary/tool-linkage defect; behavioral results unaffected Closed 2026-08-25 by freeze 6/6 linkage companion
AUTO-DEV-001 UI015/UI016 start from a Pregnancy seed while asserting Standard Test-harness setup defect; production settings behavior not implicated Closed 2026-08-25 by corrected 44/44 serial UI companion
AUTO-DEV-002 UI004a compares wrapped label accessibility frames Test assertion does not measure the containing HStack Closed 2026-08-25 by corrected 44/44 serial UI companion
CYBER-DEV-001 Package.resolved is ignored; archive 826 used CryptoSwift 1.9.0 while the freeze run resolved 1.10.0 Build-input identity mismatch, not a demonstrated product defect; the archive-matching impact companion passes Closed 2026-09-03 by designation of Build 843 with controlled CryptoSwift 1.10.0 resolution; archive-826 history retained

The post-run composition review and evidence are in the freeze composition/manual-advisory companion. The matching-dependency verification is in the CryptoSwift 1.9 impact companion. The three closed non-product deviations are linked from the Formal Evidence Index. The original execution results remain unchanged.

5. Remaining Physical / Human Work

Status as of 2026-09-08

The numbered list below is retained as the original 2026-08-21 execution closeout record. Its actions now have these controlled dispositions:

Original item Current disposition
1 Closed 2026-08-27 by Appendix A16: no separate formal hardware-validation or supplemental-alert claim is retained.
2 Superseded by the item 1 claim-boundary decision; the retained Build 843 real-Pod record remains supporting evidence in Appendices A10A-B.
3 Closed 2026-09-03 by Build 843 designation in Appendices A10C and A18; CYBER-DEV-001 is closed.
4 Closed for submission under D06 and D07; the controlled multi-G7 exercise and final deployment disposition remain required before participant deployment.
5 Closed by the approved IFU 1.17 and synchronized device-labeling record in Appendix A18 and D14.
6 Superseded by the supportive-Scout decision in Appendix A14 and closed cybersecurity disposition under D09; no retained live Scout round-trip is required for the submission claim.
7 Closed by the evidence-acceptance record under D08; the execution status itself remains unchanged.

The maintained closeout status, owners, and completion evidence are recorded in IDE_Freeze_Remaining_Work_Checklist_2026-08-21.md.

Engineering prepared a combined hardware/alert operator worksheet, retained as an internal supporting record rather than a separate formal claim.

The remaining actions are:

  1. The sponsor chooses whether STP-HW-001 and supplemental STP-ALERT-001 remain claimed or are explicitly deferred.
  2. If retained, an operator executes/signs the packet on the exact frozen build and attaches device, build, time, and saline-Pod evidence.
  3. The sponsor representative dispositions CYBER-DEV-001; a passing archive-matching companion is available for review.
  4. Sponsor/clinical owners resolve the remaining residual items identified in the freeze disposition memo and any retained hardware-only claims.
  5. Complete controlled IFU review/approval and required signatures.
  6. Attach the live retained-sequence phone-to-Scout observation and record acceptance of the controlled manual advisory method, or approved scanner artifacts if a scanner run is required.
  7. The sponsor representative accepts the formal evidence bundles and dispositions the applicable RTM rows while preserving explicit deferrals.

6. Freeze Control

No product source was changed during formal execution. Any product/build-input change requires a new freeze identity and impact-based rerun. Documentation or test-harness companion changes must not be represented as results from the original immutable tag.