The portable runtime, modular build, LEP encoding/validation, persistent spool, boot/update state, filters, diagnostics, dumps/redaction, C++ wrapper and Rust no-std bindings are implemented and host-tested. Authentication, replay protection, compression codecs, public vectors, atomic Flash adapters, property tests, bounded decoder fuzzing and transport adapters are included. The spool reserves capacity for Critical/Emergency evidence, drains highest-priority records first and exposes saturation/corruption/transport statistics.
The current runtime also implements a CRC-protected retained black-box recorder, mission/dive/node correlation, 128-bit incident IDs, synchronized time anchors, AUV pressure/depth/temperature/humidity/vibration/leak evidence, crash fingerprinting, RTOS/peripheral trace helpers and a health supervisor for watchdog/deadline, power/brownout, battery, heap, thermal, spool, boot-loop and environmental alarms. These are diagnostic/observability primitives; they are not control-law or safe-state actuators.
Provisioning now has activation/rotation/revocation/decommission lifecycle, optional secure-element attestation and fail-closed secure decommissioning. OTA provides a generic authenticated A/B orchestration boundary and persistent anti-rollback/confirm/rollback state. Named fault-injection points are wired through storage, spool and transport durability paths. Fleet tools add device namespaces, persistent replay state, crash clustering, build comparisons, canary promotion guardrails, deterministic support bundles with sensitive-file exclusion and symbol lookup.
The repository now gates production-source coverage (src/, arch/, ports/) at 93% lines / 80% branches (current local validation: 93.76% / 80.19%) and carries a deterministic critical mutation campaign with 40/40 mutants killed, zero survivors and zero invalid mutants; release gates fail on any survivor or invalid mutation site. Stable release tags invoke Required, Coverage, Quality, Mutation, Crypto Assurance and Project Readiness workflows and, for 1.x+, require a commit-matched, fresh physical-HIL qualification manifest. These are software/release controls, not a substitute for vehicle qualification.
Architecture sources are implementation-complete at their generic boundary, but real-hardware qualification remains required per target. The ESP32 fixture has qualified real flash persistence, ESP-IDF reset normalization, reboot recovery, UART stream framing and durable collector ACKs on one ESP32-D0WD-V3/ESP-IDF 5.5.0 configuration. A separate ESP-IDF 5.5 example now wraps the vendor panic handler, writes a v3 retained Xtensa snapshot and delegates immediately; its A0-A15/special-register conversion is host-tested and its firmware is compile-checked, but that new automatic path has not yet replaced the earlier physical HIL evidence. RV64 uses an optional CRC-protected wide-context sidecar rather than truncating registers into the RV32 schema; its trap entry is host-tested/cross-compiled only. Linux fatal signals are limited to an alternate-stack, one-write raw-record handoff and never call the ordinary Latch runtime in a signal handler; the fork/pipe test exercises the native x86_64 layout, while AArch64 still needs validation against the selected Linux kernel/libc ABI. Cortex-M vector/linker integration, FPU lazy stacking under the selected compiler, RISC-V mscratch ownership, TrustZone secure/non-secure placement and manufacturer reset masks still cannot be certified by host tests.
Production qualification still needs the selected product hardware, linker script, bootloader, Flash geometry and vendor networking stack. TLS, BLE GATT, LoRaWAN and CAN bus drivers intentionally remain callbacks owned by those platform stacks; Latch provides framing, fragmentation, prioritization, incident beacons and HTTPS/MQTT adapters around them. Long-running LEP, stream/ACK, compression and AEAD fuzz campaigns and hardware-in-the-loop matrices are configured as automation entry points but require GitHub runners or physical boards to execute.