# DualCoach Task 22 authoritative redacted evidence

## Verdict

- Task22 acceptance: `PASS`.
- Scope: owner/operator review, authenticated terminal callback, one controlled
  restart, and the exact automated branch matrices.
- Global completion criterion `no normal-path step used a recovery shortcut`: not
  claimed. The plan remains `NO-GO` until that final criterion is independently
  satisfied.
- Screenshots: unavailable. No customer or owner/operator screenshot artifact was
  captured by the child audits. Redacted immutable receipts and hashes are used.
- Customer `task22_dm_rehearsal` remains disabled. Activation, generation, draft
  delivery, scheduled delivery, and feature-epoch authorities are absent or zero.

## Authenticated live terminal

The read-only terminal audit from child `st_019ff55e` is retained at
`.omo/senpi-task/children/st_019ff55e/evidence/st_019ff55e-readonly-terminal-audit.redacted.json`.
Its SHA-256 is
`030c942906cac551d8e9574e5d0dde85f3ed3733bf127bb7be777b954288aae8`.

- Journal HMAC and phase chain: `PREPARED -> REVIEW_COMMITTED -> PUBLICATION_COMMITTED`.
- Callback update: `629525051`.
- Callback event integrity: `987cdde4e245b1d316ab5000271a755db148153b5207156b8082f97c2a1f5c18`.
- Callback count: `1`, HMAC valid, terminally bound to the owner review.
- Generation 27: message `122`, send count `1`, receipt integrity
  `85d05e0ee400850435a6a8b670c840772b62779b1ec3c1db64fcfbcca9514cb4`.
- Generation 28: message `123`, send count `1`, receipt integrity
  `07b8c5dd700b218bf8a315bc57192e54b2de692b0a5f4d3517afdd4e7b58b31e`.
- Emergency outbox records: `0`.
- Answers: `22`, digest
  `f1aced0350c473a01aa4e1382bc810e072fccfe84ccd3ea8780ee83c324dfe55`.
- Trainer authority: absent. Customer enabled: `false`. Downstream authority: zero.
- Active service: `hermes-gateway-dualcoachtest.service`, PID `675692`, active/running.

## Restart and recovery receipts

The controlled restart child `st_019ff50a` retained its redacted DoneClaim at
`.omo/senpi-task/children/st_019ff50a/evidence/task22-restart-done-claim.redacted.json`.
Its SHA-256 is
`72c6a604fa4a57acaff9940a720bc452bdb606aa57fe391e70a5b2c8ccd6bf4f`.
The restart count was `1`, old PID `621917` exited, and the replacement was
active/running. Static snapshots and generation 27 message `122` remained unchanged.

The incident recovery child `st_019ff472` retained authenticated replay evidence at
`.omo/senpi-task/children/st_019ff472/evidence/authorized-replay-evidence.json`.
Its SHA-256 is
`3194181dc1d672d718d16deeaba9ba80c7df3fa3802a7d36aec6c52cb59a11db`.
The committed receipt remained SHA-256
`47e6213a4fba725ba2f4c1d773a4f41261f7c6eafac89350071bb7502eb51e39`, inode
`33165814`. Replay exited `0`, remained `COMMITTED_CLEAN`, left all 14 locks free,
and kept downstream state at zero.

The recovery incident is recorded transparently. The Task22 loader held
`.adaptive-authority.lock` while a generic canonical loader reopened the same inode
through another descriptor and blocked on `flock(LOCK_EX)`. The repaired loader keeps
parse, receipt, and runtime validation but omits activation-journal repair while that
authority lock is already held. No rollback, manual durable-state edit, or hidden
fallback was used in the final authenticated chain.

## Automated branch evidence

Counts below are copied from exact child records, not inferred:

| Evidence | Result | Exact child source |
| --- | ---: | --- |
| Latest package-closure and recovery verification | `93 passed` | `st_019ff52e`, `.omo/senpi-task/tasks/st_019ff52e.json` and its child session transcript |
| Prior terminal review branches, including Revise, Reject, wrong actor, stale, duplicate, and replay | `11 passed` | `st_019ff526`, `.omo/senpi-task/tasks/st_019ff526.json` |
| Prior Task22 supplemental matrix | `70 passed` | `st_019ff526`, `.omo/senpi-task/tasks/st_019ff526.json` |
| Prior sealed supplemental successor gates | `225 passed` | `st_019ff4ae`, `.omo/senpi-task/tasks/st_019ff4ae.json` |

The branch evidence is automated and owner/operator scoped. It does not turn the
historical trainer branch into v1 evidence.

## Active code-only pins

- Candidate: `3ce5b95637211b0289529c35b452cf1771fe868a34777140388a8caa75e183cc`.
- Manifest: `e456cfc6c93d97989319818879a38237cd70c0d516ae5d2e33543a59962658e8`.
- Freeze: `5c98ffeb84961eb91ae33e184094f2382ceff14ad6110263ffdb6ca860f23b48`.
- Wheel: `f592abefa3deca172c9d0b8dcb8013e0e8a1fc97ff03db4054adb3f0b6f3abf2`.
- Canonical code-only verifier: `PASS`.

## Non-touch and residuals

- No product, profile, service, Telegram, delivery, git, commit, or push change was
  made by this synchronization.
- Boulder remains active with the existing root session.
- Task23 remains the next unchecked task.
- The evidence records Task22 acceptance only. It does not mark the plan-wide
  recovery-shortcut criterion as complete.
