# Stage 0 Acceptance Evidence ## Static Verification - Contract package is dependency-free from Redis, JPA, Controller, Agent state and existing Hook classes. - Repository secret scan covers tracked worktree files and reports no known plaintext credential matches. - `scripts/query_mysql.py` requires `SUPERBIZ_MYSQL_PASSWORD` and exits before connecting when it is absent. - Spring AI 1.1.7 `SpringAiRetryProperties` bytecode shows a default `maxAttempts` value of 10; stage 2 must set underlying retries to one attempt and keep retry ownership in Harness. ## Script Verification - `mvn -q '-Dtest=HarnessContractTest' test` - passed. - `mvn -q '-Dtest=ToolInvocationRecorderTest,ExecutorGatekeeperServiceTest,ChatControllerTest' test` - passed. - `mvn -q '-Dtest=HarnessContractTest,ToolInvocationRecorderTest,ExecutorGatekeeperServiceTest,ChatControllerTest' test` - passed. - `openspec validate single-react-design-freeze --strict` - passed. - `git diff --check` - passed; only existing Windows line-ending warnings were reported. - Secret scan for known committed key/password patterns - zero matches. - `python scripts/query_mysql.py "SELECT 1"` without `SUPERBIZ_MYSQL_PASSWORD` - exited before connecting with the expected missing-variable error. ## Runtime Behavior - Public Chat runtime was not switched in stage zero. - No live model, Redis, MySQL or Milvus E2E was run; full live E2E remains stage 7 scope. ## External Security Prerequisite - Plaintext credentials previously present in the repository must be rotated in their respective MySQL, Redis, DeepSeek, SiliconFlow and Milvus systems by the credential owner. - Repository changes can prove removal but cannot prove provider-side rotation. - Stage 3C and stage 7 must not claim live security/E2E acceptance until required environment variables contain rotated credentials.