# S6ESSJ3N PREP return and integrated provisioning plan

For Doyle. Incorporates the subject-identity gate in CO7OBPYP. **READ-ONLY PREP COMPLETE; PROVISIONING AND FIELD GO REMAIN HELD.** Nothing below grants an action.

## Decision and subject identity

1. **The currently named fold/assembly would ship the old Windows blob, not the field subject's repaired blob.** `fold/304-w2-admission@7357ea327c79f5930bdfe5947d427eabd19cf9b8` and `asm/304-w2@00c4dad9` both contain `windows.rs` blob `57e32e522f795afcbed43185c17e493c1a233664`. The measured subject `85f84d738fa702f35c83910f314aae17849d125c` contains `848a23fe18e5ca819774f9881ef13504221992f3`. No future shipping choice has been ruled; a field pass cannot be transferred between these blobs.
2. **The numeric suite is still on the named test branch, not folded into either named candidate.** `test/304-w2-enforcement-codes` resolves to 85f. Its stable native-byte patch ID is `b4f072a06f59e35d10420df175c0193aedfb4c92`; `git cherry` reports it unrepresented in both fold7357 and asm00c4. Available all-ref Windows path history contains that identity only at85f. This is a local-ref/path-history finding, not universal absence proof. The pre-amend0bb2d5e is not equivalent: it lacks standalone rejection cells for codes5 and20 and the extraction-boundary caveat.
3. **Recommendation: use the FULL85f history as the single assembly base, not a cherry-pick of its test-only tip onto7357.** The reverse ancestry query `git merge-base --is-ancestor 7357ea32 85f84d73` succeeded. This does not contradict the reported85f-not-ancestor-of-fold fact: **7357 is already an ancestor of85f.** The ancestry path is7357 → f94fe044 →167552fe →00c4dad9 →4f3f370f →dc8015cd →921aa68f →10d18b7f →53d625cd →a5f2186c →96080953 →85f84d73. The assembly merges and all subsequent repair/test prerequisites are carried by85f.

Before Doyle's single assembly build, add the minimal signer-child environment isolation repair described below. That produces ONE final assembled head based on85f, with the repaired module bytes retained and the signing tool safe to qualify. **The final commit SHA and both executable hashes do not exist in this PREP evidence; Doyle owns that assembly/build and supplies them. Hertz will not rebuild, substitute, or treat72d30901 as the newly assembled binary.** If another approved product merge is required, it precedes the one build, and the module blob tuple below remains an explicit admission gate.

### Module tuple to retain in the final assembly

| Path under `crates/spt-daemon/src/` |85f Git blob|
|---|---|
|`bootstrap_firewall.rs`|`c30d6b5466408b05d2dbd3032ca38043fbe0e5bb`|
|`bootstrap_firewall/windows.rs`|`848a23fe18e5ca819774f9881ef13504221992f3`|
|`bootstrap_firewall/linux.rs`|`08f615c4b0985a86ed8c42e96cfc3083857c4aff`|

85f preserves the fold's two immutable names, actual bound TCP port, tailnet100.64.0.0/10, LAN Private/Domain boundary, and no-program-filter policy. It additionally carries one-pass ActiveStore/source provenance, literal host-derived LAN prefixes rather than LocalSubnet, semantic representation matching, raw numeric enforcement, and pre-coercion UInt16Array/UInt16 checks. Fold still has string enforcement and a different snapshot/fixture shape. The85f tip changes only tests/comments; it is not a substitute for its production ancestors. The common runner's `run(label,program,args)` change also requires the Linux caller migration: do not transplant only windows.rs.

`fe4274979c5a93a36fef9f066df6afbe70070ae8` is a different `firewall.rs`/netsh ownership/provider implementation, not a missing commit to bolt onto this NetSecurity two-name design. Do not merge it as a supposed prerequisite.

The85f cleanup body retains the fold's guarded PersistentStore deletion and independent store-absence checks. Its encoded bytes nevertheless differ because the shared OWNERSHIP prelude changed. Consequently the accepted D3 payload is pinned independently; a source resemblance is not payload identity.

## Measured read-only PREP

Evidence directory: `.spt/preserved/hertz-fp-driver-review/d2/prep-S6ESSJ3N/`.

Intended root, **not created**:
`C:\Users\decid\Documents\projects\spt-core\.spt\preserved\hertz-fp-driver-review\d2\field-rig-r5-S6ESSJ3N`

The controlled probe run completed in **112.001851s**, within its600s ceiling. All13 leaves returned native0, `subject_exit`, and `CONFIRMED_GONE`: host; named rules; guard5470; test29470; runner; source head/blob/status; CI queued/in_progress/requested/waiting/pending. No subject, xtask, or fleet executable was invoked. Later source/history research is not represented as time inside that completed probe run. No experimental or field cleanup/reporting clock opened.

|PREP gate|Observed result|
|---|---|
|Intended root|Absent before and at end. Parent native canonical path is the intended d2 directory; file ID `10A8C584:101A0000000056AB`, attributes16. Absence is a precondition, **not** an exclusive-creation proof or lease.|
|Privilege|Unelevated.|
|Source snapshot|HEAD85f84d738fa702f35c83910f314aae17849d125c; porcelain output empty; Windows blob848a23fe18e5ca819774f9881ef13504221992f3.|
|Named rules|All FOUR readings typed ABSENT/notfound: both `spt-core-bootstrap-inbound-tcp` and `spt-core-bootstrap-inbound-tcp-lan` in both ActiveStore and PersistentStore. Each store's positive control PRESENT1 and negative control ABSENT; both providers valid. Sample11:47:07.1197347Z.|
|29470|No TCP listener/binder; matching rule count0. Independent rule controls valid.|
|5470 guard|No TCP listener/binder. One matching rule: `{FF36EE51-2837-46D8-9AB8-2441D9070633}`, enabled inbound Allow, Private, Local, TCP5470, remote192.168.1.0/255.255.255.0, ProgramAny, empty group. Baseline only: no mutation occurred against which preservation could be claimed.|
|Resident supervisor|PID4732, native birth2026-09-11T04:17:53.3401868Z, live; fleet exe; `daemon run --detached`. CIM/native delta8ticks. Historical parent33556 is not kill authority.|
|Resident brain|PID15856, native birth2026-09-11T04:17:53.6612052Z, live; parent4732; fleet exe; `daemon brain --generation 0 --start-reason cold`. CIM/native delta2ticks.|
|FreeC|79,525,765,120bytes =79.52576512decimalGB =74.06414032GiB, at host sample11:47:01.8472440Z–11:47:04.5745818Z. No reservation.|
|Runner census|11:48:32Z:602processes, self positive control valid; cargo_build0, runner_descended0, shim_unresolved0, analyzer3; Runner.Worker absent, listener_procs1.|
|CI query results|queued/in_progress/requested/waiting/pending each `[]`, native0, limit1000, no recency filter. A snapshot, not exclusion of later starts.|
|Final registered PREP births|26 launcher/subject identities, one census pass, surviving0, unreadable0. Native0. Birth controls: positive4ticks; deliberately skewed5,000,004ticks.|
|Traceability|`traceable-reqs check` native0:903complete,0incomplete,0findings. Raw output preserved. This is not a field or signing test.|

Todlando subsequently reported #299 complete and pool released, then a #302 instrumentation-only smoke window, and finally successful completion at86696e17 with the pool released (delivery14/4624RXOO). He reported no fleet change or restart. These are later peer observations, not a fresh host census or an availability lease. No competing build or field action was started by this PREP.

### Executable pins actually measured

|Role|Path|SHA256 / size / native file ID|
|---|---|---|
|OLD subject, retained control reference|`.worktrees/304-w2-repr/target/release/spt.exe`|`72d309011415b419aabfdb0b4065df1183bfd0069a9f95b5779da62e43349b10`;38,419,456bytes;`10A8C584:004400000038F77B`|
|Prebuilt xtask candidate, hashed only|`.worktrees/304-w2-repr/target/debug/xtask.exe`|`dbdb71135a30a58c81b21c09a64a330385900e7d3b75aa84f37167c0c150f43f`;7,024,640bytes;`10A8C584:004D00000038F121`|
|Fleet exclusion|`C:\Users\decid\AppData\Local\spt-core\bin\spt.exe`|`689503ad9fc6cfde637cbcacf21c42faf130ba465a0df6c356cf290e2adafb85`;38,072,832bytes;`10A8C584:01B500000023CF78`|

Native canonical paths matched these files. Old subject and fleet have different native identities. The future rig exe does not exist and therefore has no present file identity. Only the expressly authorized fleet executable was read; no fleet-home state was read or changed. Resident processes were observed, not controlled.

## Signing blocker: do not mint a real key yet

In the pinned xtask source, `debug-rollout` reads `SPT_DEBUG_RELEASE_SEED` and unconditionally calls `git_stdout` for HEAD and dirty provenance. `git_stdout` constructs `Command::new("git")...output()` without removing that variable. Both git children would inherit the seed under that source behavior. This violates the ruled exception allowing only the signer and bounding timeout to inherit it. Source review is not an attestation of what produced the hashed prebuilt candidate; **that uncertainty does not qualify it for real signing**.

Evidence: pinned `crates/xtask/src/main.rs`2379–2473 and2764–2772; detailed report `PrepSigningFacts-report.txt`. No supported seed-stdin/seed-file/no-provenance switch cures this. Omitting git from PATH is neither proved isolation nor honest provenance: a failed git lookup currently produces `git_dirty: Some(false)`. A shim would itself initially inherit the secret. Do not enlarge the exception silently.

Proposed minimal source repair before Doyle's one build: add `.env_remove("SPT_DEBUG_RELEASE_SEED")` to the `Command::new("git")` chain in `git_stdout`. Qualify the resulting prebuilt signer with the actual-child dummy-sentinel discriminator below before any real key. This is a proposed edit, **not applied here**. No hidden cargo, current-build fallback, or private hertz rebuild is permitted. Doyle supplies the final source identity, build provenance, absolute executable paths, and hashes for both `spt.exe` and `xtask.exe` from the final assembled tree.

## Fixed names and final admission tuple

Use these names only after an explicit provisioning grant:

- `RIG_ROOT` = intended root above; `H = RIG_ROOT/home`; `E = RIG_ROOT/bin/spt.exe`.
- `KEY_ID = hertz-r5-S6ESSJ3N`; explicit release version **N=202609130001**.
- Signed staging path **H/releases**.
- Sequence state **RIG_ROOT/rollout-state.json**, exclusively owned by xtask.
- Public evidence `EVID = RIG_ROOT/evidence`; provision event log `EVID/provision-events.jsonl`, never rollout-state.json.
- Private signing directory, outside repo/RIG/transcripts/archives: `%LOCALAPPDATA%\spt-rig-secrets\hertz-r5-S6ESSJ3N`; owner-only access, exclusively created. It does not exist by virtue of this plan.
- Immutable public support bundle `RIG_ROOT/support/fp-bin`; field outputs below `RIG_ROOT/support/fp-run`.

Final admission is a tuple: **Doyle's assembled commit + the three module blobs above + Doyle's spt SHA/path + safe xtask SHA/path + final configured driver/support manifest + this root/version/key-ID + current independent host/rule/port samples**. Missing or changed member means NOT_STARTED. Do not fill an unknown hash with the old subject/candidate hash. Source equality alone is not a PE identity or build-provenance proof.

## Ordered mutating plan — ALL HELD

### A. Qualify custody, then create a fresh rig

1. After a specific tooling/qualification grant, freeze the repaired signer and public observer/controller bytes. Run a **dummy-sentinel discriminator first, with no real key**. Exercise the real provenance-child path, not a seed rejected before git runs. A public valid32-byte hex dummy seed may be used only in an explicitly authorized disposable qualification home/staging root outside the intended rig and fleet. The intended signer must observe the sentinel; both actual git children and every helper must report absence. Include a deliberate forbidden-helper inheritance arm that the observer rejects, plus timeout/error-path teardown and post-window absence. Reports contain booleans/roles/births, not environment dumps. An unset afterward is not interval evidence. No dummy arm was executed by this PREP.
2. On custody success and a provisioning grant, begin ONE600s preparation deadline for provisioning through field GO. Independently refresh volatile admission measurements and compare the assembled pin tuple. Refuse active producer conflicts; do not commandeer a claimed pool. Hertz runs no cargo at any point.
3. Atomically create `RIG_ROOT` using Win32 `CreateDirectoryW(path,NULL)` and refuse every failure, especially already-exists. Do not use idempotent Directory.CreateDirectory or a Test-Path/create pair as exclusivity proof. Recheck native canonical parent/root identities and reparse attributes. Create only declared children. Receipt the creation time/owner/source tuple. Never clear or reuse an existing root.
4. Copy the DRI-supplied artifact with `CopyFileW(SUBJECT_EXE,E,TRUE)` (fail-if-exists), then hash E, canonicalize it, and record its native identity. It must equal Doyle's SHA and be distinct from source and fleet identities. Freeze approved public instruments with exclusive destinations and a manifest. Preserve the old72d artifact unchanged.

### B. Generate the private key; install only public rig trust

5. Start with the parent environment seed-absent. Disable transcription/xtrace/verbose secret capture. Construct public argv files and all compilation/readiness helpers before any secret exists. Exclusively create the external private directory and restrict access before producing key material.
6. Under a bounded native step, execute the safe prebuilt xtask with public argv:

```json
["debug-keygen","hertz-r5-S6ESSJ3N"]
```

ALL stdout/stderr go to private files only: keygen emits `seed_hex:` alongside public information. Parse exactly one labeled public_hex and one labeled seed_hex internally, each64hex; length alone cannot distinguish them. Publish only key ID/public key. Never put a seed in argv, a public ArgsFile, transcripts, source tree, archive, receipt, or hash inventory.

7. In a fresh seed-absent step, install rig-local debug trust with public argv:

```text
debug-pin --home H --key-id hertz-r5-S6ESSJ3N --public-key PUBLIC_HEX
```

PUBLIC_HEX is the generated public value, not a value fabricated in this plan. Require fresh H/identity trust absence before this step; inspect the resulting rig trust document for exact key ID/public key and debug channel. The helper can replace a same-ID key or recover malformed input, so it must not be aimed at a reused or fleet home. Never export seed for debug-pin.

### C. Sign and stage the actual repaired artifact

8. Create a private EnvironmentFile containing only the necessary overlay, including `SPT_HOME=H` and `SPT_DEBUG_RELEASE_SEED`. The clean parent invokes launch-v2; its Add-Type/setup runs BEFORE the overlay is read and passed directly to the native signer child. No broad shell export or seed-prefixed bounded function. The bounding controller may hold the seed in memory, but ambient helper environments remain clean. The repaired git child chain explicitly removes the seed.

Exact signer argv (substitute the fixed absolute H/RIG/E paths):

```text
debug-rollout --key-id hertz-r5-S6ESSJ3N --channel debug --version 202609130001 --stage-dir H/releases --state RIG_ROOT/rollout-state.json --artifact x86_64-pc-windows-msvc=E
```

There is NO `--home` option on debug-rollout: `SPT_HOME=H` is supplied in its private environment overlay. There is NO `--build-current`, cargo call, inferred version, default staging directory, or default sequence-state path. `rollout-state.json` must not be overwritten by a provision-phase logger, as the old provisioner would do.

9. Native success, the expected staged-version marker, exact artifact SHA, signed set metadata and explicit sequence-state N must agree. Per-artifact/metadata/sequence writes are not globally atomic: preserve any partial staging failure. Never synthesize completion. Await owned-job disappearance before unsetting all secret bindings and retiring private seed-bearing files under the explicit custody grant. Do not claim secure memory erasure. Subsequent helpers, CLI/apply/supervisor/brain windows must prove seed absence; never archive the private directory. The old `provision-rig-r4.sh` is not used.

### D. Genuine offline apply and normal trial promotion

10. Verify there is no rig daemon or prior release history. With a seed-absent overlay `SPT_HOME=H`, execute **E** with argv:

```json
["update","apply"]
```

No `--finish`, daemon start, service manager, fake applied-state, or **debug-mark-applied**. Same input bytes can genuinely apply when a fresh positive version has never been applied: version/state transitions, not unequal binary hashes, distinguish this operation. Require BrainOnly; non-BrainOnly currently refuses even under quiescence. NO_UPDATE, AlreadyApplied, RefusedClass, quarantine, or rollback is not success.

11. Preserve the pre-apply state, native CLI result, installed/landed outcome and actual `H/releases/applied-state.json` transition to phase `applied-pending`, version N, rollback_binary `E.old-N`, and fresh prior_version null. Pin E and its actual rollback aside. Do not write any of these product-owned release-state files yourself.
12. Start an **unelevated foreground** E `daemon run` in its own accepted run-scoped v2 job, not as the child of a bounded CLI step. Overlay: `SPT_HOME=H`, `SPT_INSTALL_NO_FIREWALL=1`, seed absent. No service-aware daemon start, node start, WMI/scheduled-task launch, breakaway fallback, or elevation-token re-spawn.
13. Require generation-matched brain readiness, native supervisor/brain birth identities, parent/path and owned-job membership, verified executable hash, promotion log, and durable state phase `applied`, numeric version N. `BRAIN_PROMOTED` alone is not enough. Missing executable hash can otherwise yield PROMOTE_BYTES_UNVERIFIED; reject that ceiling here. `E --json node status` is optional no-autostart corroboration, not release-phase proof. Cross-check legacy applied/last-outcome records where present.
14. Stop only that owned promotion run job through its recorded stop channel/native ownership contract and confirm active_processes0 plus all its recorded births gone. Native stop-request exit124 is interpreted with the full launcher/controller record, not confused with an apply failure. Preserve all records.
15. **Explicit integration substep requiring grant:** after successful promotion and confirmed ownership/gone evidence, retire ONLY the exact owned `H/daemon.pid` breadcrumb by atomic no-overwrite move to `EVID/provision-daemon.pid.retired`; receipt original bytes/hash and ownership. Unexpected contents or identity means refusal. This is not clearing a failed run: the accepted r5 start refuses any existing breadcrumb, and the earlier owned-run control demonstrably left one after native termination. No daemon-stop guard bypass, broad PID cleanup, or silent stale-file deletion. If retirement is not granted, field admission remains blocked.

### E. Prepared-home provenance and one field attempt

16. Publish provenance only after successful genuine promotion and owned daemon shutdown: rig ID, creation receipt, exact source/build/exe/module hashes, canonical E/H, public trust identity, numeric N, signed staging identities, apply/pending/promotion evidence, native job/child identities, and the breadcrumb retirement receipt. Include the current r5 compatibility string fields `rig_id`, `rig_exe`, `rig_exe_sha256`, `home`, `applied_version`, `trust_key_id`, `applied_evidence`. Validate the actual structured release state yourself: the current driver only checks some strings and a version substring in the evidence file.
17. Configure a reviewed copy of accepted r5, leaving its original bytes untouched. Bind RIG_ROOT, SP/support paths, assembled subject path/commit/hash/blob tuple and all support hashes. Required support files: census.ps1, runner-census.ps1, portfields.ps1, d1_render.py, d2_capture.ps1, d2_validate.py, launch-v2.ps1, launch-v2.cs, launch-record.py, run-daemon-ready.ps1, run-daemon-control.py. No scratch-path dependency may silently select different helpers. Record exact configuration diff and final manifest before any field invocation; unknown final values are admission blockers, not defaults.
18. Current r5's S0b atomically creates `H/.consumed` BEFORE its remaining preflight checks. Invoke it once only after the prepared-home gate. Any failure after that creation consumes the attempt permanently. Never remove .consumed, repair/reuse that home for another attempt, or use the whole driver as a supposedly read-only PREP probe.
19. Every SPT CLI, supervisor, brain and apply invocation uses **RIG_ROOT/bin/spt.exe**. Xtask is the explicitly pinned maintainer-tool exception, not an alternate SPT role. A product rollback may run E.old-N; if it does, the successful same-path contract failed: preserve and stop, never disguise it as success.

## Native command boundary and F5 budgets

For each public/private argv JSON file, the concrete launcher interface is:

```text
pwsh -NoProfile -File L2 -Label LABEL -Seconds LIMIT -RecordFile RECORD_ABS -ArgsFile ARGV_ABS -Exe PROGRAM_ABS -OutFile OUT_ABS -ErrFile ERR_ABS -Admission process-tree -Scope step -EnvironmentFile ENV_ABS
```

Use absolute, exclusive paths. A promotion/field daemon instead uses `-Scope run -StopFile STOP_ABS` and the accepted separately owned run-job readiness/control protocol. Signer/keygen capture paths are private. No seed appears in this command. All owned scope termination is by native job authority, not a PID-tree sweep. Unreadable ownership, escaped creation, or outstanding setup means PARTIAL/UNREADABLE and forbids a confident teardown.

**Preparation600s; experiment300s from actual GO; cleanup/report180s from activity end; each handoff at most120s; final30s reserved for reporting, not teardown work.** Provisioning must not give the following driver a fresh600s: carry the preparation epoch/deadline into the configured run and validate the remaining allowance. Builds/tool qualification occur only in separately explicit grants, never hidden inside that clock.

A static integration gap must be addressed before field GO: accepted r5 caps the experimental setup wait at120, but its PREP waits assign `prep_left`, its cleanup wait assigns `cleanup_left`, and the shared handoff_await counts five-second sleeps rather than an absolute deadline. It does not presently impose the120 cap on all waits; the cleanup assignment can spend the ledger reserve. **Do not certify those bounds from the constants alone.** The configured revision must use a common absolute wait deadline `min(now+120, requested_wait_end, phase_work_deadline)`, with cleanup using WORK_DEADLINE (REPORT_DEADLINE−30), and clamp the final sleep to remaining time. Preserve nonce/authorizer checks and signal behavior. Qualify the revised deadline boundary with no-field controls before invocation; the original accepted native-containment code and artifacts remain unchanged. No such edit/control was performed in this read-only task.

Readiness and GO remain separate. The executor returns PREPARED/NOT_STARTED with hashes; only Doyle supplies operational GO authority. The current protocol binds a new request nonce and names `authorizer=doyle`; that line is routing, not authentication. To rule once in advance, the ruling must explicitly bind the unique root/final tuple and authorize recording its decision against the first matching future run/nonce after all gates succeed. Otherwise the existing driver still waits for Doyle's run-bound message. Neither Hertz nor the elevated executor may manufacture authority from PREPARED or from this plan.

The successful field daemon has its own accepted run job; each subsequent CLI has its own bounded step job. Check owned readiness immediately before serve operations. All serve variants can autostart, so a readiness-to-call race remains if the owned daemon dies: there is no no-autostart serve flag to claim. Any unproved process-creation coverage remains PARTIAL; do not upgrade it because a post-census looks quiet.

## D3 cleanup, preservation, and later disposal

- Use the already reviewed literal `teardown-command.pinned` and its exact D3 encoded payload, not an ad hoc reconstruction or the fe427 netsh provider.
- `d3/decoded-todlando/d3-payload.b64` SHA256 **416280dbece2601203c74c3f8e2c46e13009125fa5870166894e079329fb1d43**.
- `teardown-command.pinned` SHA256 **38e0f21b2cf2ef1f9d986c650f2f6b0d36335ba25c8b017fe8dcbd5219c94676**.
- Before any creation, verify the actual final artifact's rendered cleanup payload against that pin. Different payload means stop for review, not update the pin to match. Preserve exact executor command/nonce/native result and independently re-read all four named-rule absences and the5470 guard fields/binder identity afterward.
- An outstanding setup operation or unproved ownership prevents safe cleanup dispatch; record the refusal rather than removing an unrelated owner's state. Elevated execution remains the specifically authorized executor's scope.
- Preserve all original r4/r5/v1/v2 artifacts, prior failures, partial staging/apply/promotion evidence, nonce requests/receipts, job events, stderr and attempted-result ledgers. An unsuccessful attempt remains unsuccessful in its original ledger.
- Later filesystem/private-rig disposal requires a distinct explicit scope and a **new disposal receipt** linked to the immutable run ledger. It must not overwrite the ledger to turn PARTIAL into COMPLETE. No fleet deletion, target/pool deletion, broad worktree removal, or cleanup outside owned/granted scope is authorized here. Secret-file retirement is a separately explicit custody operation; private seed-bearing files are never added to the public preservation set.

## Existing support and PREP pins

|Artifact|SHA256|
|---|---|
|accepted fp-driver-d2-r5.sh|df6cca2d987e8eb2a6e9ccba6e9532d278c08bb4f873674836653e5a8e419c59|
|launch-v2.ps1|6e2c2eac82dd53fd0af42c4fe796f911e987d406e6f31219cd4480a78f1f6804|
|launch-v2.cs|c3a905ec7cbc118f0b59dd1813b187740319802267689e14dacf6008730de157|
|launch-record.py|8fb2f87f9d55d845cd4932f6c6008edbb1d2db756196480a4da82ec0c179092f|
|run-daemon-ready.ps1|bf43935f5402771932e0a39eafe77af387a3f5ddba30643c56b7bd392c10de1c|
|run-daemon-control.py|4d04f0c3eb10d84a39ce6fdc64ba64c73b742da1626834c25fa63bd904fb2d0a|
|prep-host-readonly.ps1|0e15c209c496b534a56cc851adfb09185681dec2c3ec5889d126cb595ef0cb05|
|prep-readonly.ps1|cac9627393be7dcf5dc7919fb696c35ff637202a876d9aaa0317a9a8d1230e94|
|independent rule probe|be016198d860076c58257953bf2342fc35fea54550e373aae7e0f2b60132bcee|
|portfields.ps1|283386e7e1cac9df5e8e3c7e8283faea224ad3d12f4da30185a9b342b9a1da85|
|runner-census.ps1|63d0508b93a8d15fa2bc9940708c7a13ac4abda1f8ca9c9a5d32a63b1dcf3e8a|

## Evidence and ruling boundary

`host.json`, `summary.json`, `pins.json`, thirteen per-leaf native records/captures, final-identities.json, final-disposition.csv, traceability-result.json, and the four source-investigation reports are preserved in prep-S6ESSJ3N. `subject-history/` contains exact Git-object snapshots and local history/equivalence evidence. Its fe427 Windows submodule lookup failed because that path does not exist at that object; no snapshot was fabricated. Public inventory manifest excludes only itself and its checksum file.

This return has **not** generated a real/dummy key, installed trust, placed a subject in the intended root, staged a set, applied an update, started a rig daemon, consumed a home, changed firewall rules, run a field leg, compiled/rebuilt a subject, or performed disposal. Source/plan evidence was written only outside RIG_ROOT. There is no new D2 pair and no full two-host #297 run.

The reachable deliverable is complete: measured PREP plus subject diagnosis and the full conditional plan. The remaining prerequisites are deliberate authority/build gates: Doyle selects the assembled candidate, owns the one build and supplies its pins; signer custody and common deadline controls must qualify; the successful-promotion breadcrumb retirement and one-run authorization recording need explicit scope. **Until then, all provisioning/keygen/trust/artifact/apply/GO and ungranted cleanup remain HELD.**
