# Core 3.3.0rc8 integration review This is a source/package compatibility review of the user-supplied AIM Core 3.3.0rc8 archive against AIM WebGUI 2.1.0rc9. Core remains separately deployed and unmodified. ## Public contract Core remains service/wire/event API 1.0 with the existing detail-progress, inventory-hierarchy, target-outcome and `aim_operation_result_v1` contracts. The nine shipped report schemas remain catalog-driven. WebGUI therefore does not add a private adapter or parse playbook output. The release changes the required native Windows collection baseline. Live Core capabilities now advertise: ```text ansible.windows >=3.8.0,<4.0.0 ``` WebGUI 2.1.0rc9 requires that capability declaration. The actual collection remains Core/operator managed and must be visible to the execution identity in the canonical Ansible collection path. Core readiness remains authoritative for the installed runtime. ## Report deltas `patch_summary_v1` is additive: rc8 adds optional `reboot_reasons_before`, a bounded array of `{source, description}` observations from `ansible.windows.win_reboot_info`. Existing required fields and the established patch continuation/reboot semantics remain. Historical reports continue to validate against their recorded result contracts. `filesystem_usage_v1` remains schema-compatible, but Windows semantics now describe attached local storage volumes through `community.windows.win_disk_facts`; mapped/network drives are intentionally excluded. WebGUI updates its explanatory note accordingly. Core's Checkmk script placement and Windows ACL hardening are runbook behavior, not a new add-on API. WebGUI does not reconstruct those paths, permissions or deployment rules from private source; it renders final structured reports supplied by Core. ## Patch behavior retained The rc4 patch-wave model remains: one native `win_updates` wave per selected categories, AIM-owned reviewed reboot message/delay, explicit opt-in for post-reboot continuation, no automatic replay, and `remaining_updates_known` governing whether a final pending list is authoritative. `install_not_allowed` alone is not treated as proof of a reboot need. ## Qualification boundary This review does not certify native Windows Update, Checkmk ACL changes, collection installation, WinRM/SSH, or the production systemd sandbox. Controller acceptance must use Core rc8's current SANITY/VALIDATION guidance under the actual executor identity.