GLMChat V2.2.1 Outstanding Production Gates
Generated: 22 July 2026 13:03 UTC

The V2.2.1 deployment package is hardened but is not represented as production-approved until these gates are completed:

1. Deploy at the intended LiteSpeed domain root and a representative nested path.
2. Confirm PHP 8.2+ extensions sqlite3, curl, mbstring, zip, fileinfo, openssl and json.
3. Verify .htaccess rewrites, private-path denials and every mandatory security header.
4. Perform an upgrade against a cloned real pre-V2.2.1 storage directory and verify all user data.
5. Test application and storage rollback after an intentionally failed upgrade.
6. Run live Together API text, vision, function/tool and TTS requests, including timeout, rate-limit and invalid-key paths.
7. Test streaming and cancellation through the production LiteSpeed/proxy stack.
8. Test concurrent and long-running workflows, leases, interruption recovery and SQLite contention.
9. Test storage quota pressure, IndexedDB transaction failure and browser eviction behaviour.
10. Test large project uploads, ZIP guards, downloads and interruption on the target host.
11. Test installation, offline restart, queued replay and controlled updates on physical Android Chrome and Samsung Internet.
12. Complete TalkBack, keyboard, reduced-motion and responsive acceptance on physical devices.
13. Obtain the matching complete-source release and reproduce its build, type-check, lint and automated test suites.
14. Review the retained React 16.0.0/ReactDOM 16.0.1 dependency risk and plan a source-level upgrade.
15. Decide whether a six-digit PIN plus PBKDF2 and a seven-day offline lifetime is sufficient for the intended threat model. Stronger device-bound WebAuthn/passkey protection requires source/UI work and remains recommended for high-sensitivity deployments.

Until these checks are evidenced, release status remains: CONDITIONAL STAGING CANDIDATE — NOT PRODUCTION-PROVEN.
