# Verification - AIM WebGUI 2.1.0rc9 Date: 2026-09-22. Target: independently managed AIM Core **3.3.0rc8**, public service/wire/event **1.0**; WebGUI HTTP **v2**; SQLite **schema 5**. ## Scope This candidate reconciles the add-on release surface with the supplied Core 3.3.0rc8 archive and packages the result as 2.1.0rc9. It does not claim native Windows/Linux or production-systemd acceptance merely because local source/contract checks pass. The supplied Core ZIP SHA-256 observed during this build is: ```text 76733be206b14c8a822126dfdd67ee3ad3667cdb88d3db925dd57859dd322ea0 ``` No independent publisher sidecar was supplied, so this is an observed digest rather than a publisher-authentication claim. ZIP extraction/integrity succeeded. ## Contract findings checked - Core rc8 reports product version `3.3.0rc8` and service/wire/event API `1.0`. - Live capabilities advertise `collection_baselines.ansible.windows` as `>=3.8.0,<4.0.0`; WebGUI requires that declaration and does not manage collections. - Existing public detail-progress, inventory-hierarchy, target-outcome, staging and structured operation-result contracts remain the integration boundary. - `patch_summary_v1` accepts rc8's additive optional `reboot_reasons_before` data while historical report contracts remain independently validated. - No WebGUI database migration, Core mutation, new privilege bridge or private Core import is introduced by rc9. ## Automated evidence observed for rc9 - Python compilation of `src`, `tests` and `deploy`: **passed**. - `tests/test_deployment_v2.py`: **10 passed**. - `test_core_contract.py::test_real_core_capabilities_and_customers` against the supplied rc8 tree: **1 passed**. - Targeted rc8 patch checks completed before the bounded native-finalization fixture: public catalog/options and new-report-schema/old-Core-gate checks **passed**. - The full `test_core_rc8_patch.py` file and the release-wide bounded runner did not complete inside this execution environment's command window. Their interrupted runs are **not** counted as passes and no rc4/rc5 test totals are carried forward. The final extracted rc9 ZIP is verified with the release's own `deploy.verify_release` manifest checker before delivery. ## Not qualified here This build does **not** establish production installation of `ansible.windows >=3.8.0,<4.0.0`, native `win_reboot_info`, Windows Update, Checkmk ACL normalization/script placement, real WinRM/SSH, reboot behavior, production proxy/CSP/ HTMX/EventSource traffic, or the actual systemd sandbox. Core rc8's current SANITY/VALIDATION guidance remains the operator acceptance source. Use a low-risk reporting operation first, then qualify Windows patching and changed Checkmk workflows separately on approved disposable targets.