{
  "schema": "nutricoach-telegram-checkin-stepper-task-10-r70-safe-restore-analysis-v1",
  "task_id": "st_01a05d9e",
  "captured_at_kst": "2026-09-02T00:40:35+09:00",
  "mode": "independent_read_only_recovery_audit",
  "verdict": "RECOVERABLE",
  "verdict_scope": "Recoverable only by a newly authorized, one-use execution of the already authenticated original r71 package from the stopped r70 predecessor, with a temporary runtime Restart=no drop-in. There is no safe in-place r70 registration rewrite, no safe byte-for-byte r70 rollback from the available snapshot, and no authority to execute the sequence from this audit.",
  "done_claim": false,
  "authorization_guard": {
    "status": "NEW_EXPLICIT_OPERATOR_AUTHORIZATION_REQUIRED",
    "reason": "The Sep 2 operational window ended at 2026-09-02T00:40:00+09:00; this audit captured the final state at 00:40:35. The immutable r71 package remains internally valid through its weekly authority expiry, but the expired operational window does not authorize either the runtime systemd drop-in or the one-use launcher.",
    "new_package_required": false,
    "new_package_required_if": [
      "the immutable r71 preseal verifier no longer returns V15_RUNTIME_AUTHORITY_PRESEAL_VERIFIED",
      "any expected live hash or absence guard below changes",
      "the r71 package's weekly authority window expires at 2026-09-30T23:59:59+09:00",
      "a prior or concurrent process creates any r71 action root",
      "the one-use r71 launcher is invoked and does not commit"
    ]
  },
  "incident": {
    "failure": "gateway.platforms.nutrition_weekly_reminder_bootstrap_config.WeeklyReminderStartupAuthorityIncident: weekly reminder canonical registration is unavailable",
    "failure_site": "nutrition_weekly_reminder_bootstrap_customers.py:110-114",
    "restart_storm": {
      "operator_restart_count": 1,
      "automatic_restart_count": 26,
      "policy": "Restart=always, RestartSec=5, StartLimitIntervalSec=0",
      "protective_stop_completed": true
    },
    "root_cause": "Fresh startup reacquires a canonical customer binding from the current profile and requires the single immutable registration row in data/weekly-operations-authority-81a7a06ec2e7a159 to match both customer_identity_digest and binding_digest. Customer identity still matches 253243ad46f32f8d456514b1c8a8fda4f605dc04874b69b1e3ded72de49c877c, but the durable row binds 0ef1462c19bcb6dde3fb53b952e1a45b018f78d693672c7ee62a307b47be7397 while read-only reacquisition from the current signed registry/profile produces eb2cfb9340251f2477b7207341bfe0a0bfbfb321d76b5be08429711da0bf7eac. The one-time registry already contains this customer, so appending a replacement row is prohibited by CanonicalAuthorityAlreadyRegistered.",
    "durable_state_expected_by_r70_startup": {
      "config_sha256": "6a949de8c8a7c4caff4462f9c2821d49e5517a0f12defa93693e7f3bff97ed17",
      "registry_sha256": "176a7e3c55e5be95583c122dc535f13b35ef6fd13c1fbf9445f3cc2be95dd95e",
      "authority_root": "/home/cube/.hermes/profiles/dualcoachtest/data/weekly-operations-authority-81a7a06ec2e7a159",
      "authority_candidate_digest": "81a7a06ec2e7a1595784c92ab61df0df7e138d13a2620d9a917e94999e7f7a04",
      "registration_file": "canonical-authorities-v1.jsonl",
      "registration_row_digest": "25adce3c97d9a030ad5ada1d72472c4e158892e1555405bda12005c89972e4f7",
      "registered_binding_digest": "0ef1462c19bcb6dde3fb53b952e1a45b018f78d693672c7ee62a307b47be7397",
      "currently_reacquired_binding_digest": "eb2cfb9340251f2477b7207341bfe0a0bfbfb321d76b5be08429711da0bf7eac",
      "currently_reacquired_registered_binding_digest": "526041ed0056db55f9f88cffe70a9bfdc2efa27bad8ee7236048e6a82a227f6c",
      "pin_identities_still_match_row": {
        "customer_root": [66306, 44869149, 448, 1000, 5],
        "events": [66306, 45487465, 384, 1000, 1],
        "sequence": [66306, 44850005, 384, 1000, 1],
        "lock": [66306, 45487466, 384, 1000, 1]
      },
      "interpretation": "This is not a missing customer event and not evidence that customer bytes should be reverted. It is a stale one-time capability binding after legitimate durable profile evolution. Startup is correctly fail-closed."
    }
  },
  "r70_committed_receipts": {
    "authorization": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-authorization-v15/nutricoach-v150-v15-runtime-authority-r70/authorization-consumed.json",
    "authorization_value": {"candidate_digest": "81a7a06ec2e7a1595784c92ab61df0df7e138d13a2620d9a917e94999e7f7a04", "outcome": "SUCCEEDED", "status": "CONSUMED"},
    "execution_phase": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-executions-v15/nutricoach-v150-v15-runtime-authority-r70/phase.json",
    "execution_value": {"phase": "COMMITTED", "schema": "nutricoach-v150-phase-journal-v3"},
    "implication": "Do not replay r70 authorization, invoke its launcher, or treat its rollback snapshot as an uncommitted transaction recovery."
  },
  "snapshot_assessment": {
    "authenticated_snapshot_root": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-executions-v15/nutricoach-v150-v15-runtime-authority-r70/post-stop-snapshots",
    "manifest_sha256": "025d87aa1413a679322735387cd227fb49205c320334cdadd5d7f463ee610c0b",
    "manifest_mode": "0400",
    "manifest_entries": [
      {"live": "/home/cube/.hermes/profiles/dualcoachtest/config.yaml", "sha256": "5f6e2608ffaca91bfecef05aff2a7f9d0d291e6687787d2bd9460150c956249d"},
      {"live": "/home/cube/.hermes/profiles/dualcoachtest/customers/registry.json", "sha256": "413f75f296ca98aa451b6fb20825454baaaa398126c19bff71a3bcf52982fffd"},
      {"live": "/home/cube/.config/systemd/user/hermes-gateway-dualcoachtest.service", "sha256": "761c603ddea1ba1e233516b1444559ed7b8a7113f235377d73c8af62df985241"},
      {"live": "/home/cube/.config/systemd/user/hermes-gateway-dualcoachtest.service.d/task26-authority.conf", "sha256": "a591e892e7a3a1ede44163f53f6ddb0cd8314513ab041282ce1f1901367e4132"}
    ],
    "byte_for_byte_r70_restore_safe": false,
    "reason": "The snapshot is the pre-r70 rollback image, not a healthy post-r70 checkpoint. Restoring it would undo committed r70 config, registry, unit, and authority bindings while omitting the later customer canonical events/sequence and all other durable customer/delivery state. It cannot restore the exact state expected by current r70 startup and would create a mixed-generation profile.",
    "forbidden_command": "Do not call scripts.nutricoach_v150_sealed_authority.restore() on the r70 post-stop snapshot and do not copy any *.snapshot over live files."
  },
  "reconciliation_assessment": {
    "in_place_r70": "NO_SAFE_PATH",
    "reason": "canonical-authorities-v1.jsonl is append-only with unique customer identities; one_time_registration rejects a second row for the customer. Editing, truncating, replacing, or fabricating a row would destroy authenticated authority history. The committed r70 package has no signed in-place re-registration operation.",
    "fresh_r71_authority": "SAFE_IF_NEWLY_AUTHORIZED",
    "mechanism": "The original sealed r71 controller derives a fresh absent authority root data/weekly-operations-authority-a41c97c8a467b030 from the current signed registry and current canonical descriptors, registers the existing customer exactly once, runs installed weekly startup smoke before service activation, and commits only after the successor is active/running. It does not create customer events or delivery records.",
    "customer_input_required": false,
    "customer_or_delivery_state_fabrication_required": false
  },
  "live_final_state": {
    "service_probe_1": {"ActiveState": "inactive", "SubState": "dead", "MainPID": 0, "NRestarts": 26, "Restart": "always", "Result": "exit-code"},
    "service_probe_2_one_second_later": {"ActiveState": "inactive", "SubState": "dead", "MainPID": 0, "NRestarts": 26},
    "matching_gateway_or_launcher_processes": 0,
    "r71_roots": {
      "authorization": "ABSENT",
      "execution": "ABSENT",
      "successor_runtime_a41c97c8": "ABSENT",
      "observer_r71": "ABSENT"
    },
    "unchanged_hashes": {
      "config": "6a949de8c8a7c4caff4462f9c2821d49e5517a0f12defa93693e7f3bff97ed17",
      "registry": "176a7e3c55e5be95583c122dc535f13b35ef6fd13c1fbf9445f3cc2be95dd95e",
      "topic59": "92ef87536865b4d74c50f9715601de7870c5c3893839f2862dbaf62024e51af5",
      "scheduled_deliveries": "1000b155ccb56aa318ac098613f5808d2cb9633fc1178a0b49f280c3a23f72a1",
      "scheduled_deliveries_fence": "e647bdcdd1505e3d978c73d69934c9f04c20159bad4e12ac9d0c93b202442555",
      "customer_events": "4a718b95dc35f7219be2be54b402f19eb0af41dc35928206d19357a9d6f9053713",
      "customer_binding": "318d62644dc480dbe2be54b402f19eb0af41dc35928206d19357a9d6f9053713",
      "draft_235d": "69f6510e555b47984c6462b12da569b5bb67c051b1592ddb2ffb93898564b9c1",
      "draft_dc99": "d717125902230dc362c3e951ef0d6f656d0919dd0665f449f7056158b031dfab"
    }
  },
  "r71_package": {
    "preseal_root": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-transaction-preseal-v15-runtime-authority-r71",
    "candidate_root": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-v150-combined/task-v15r71-candidate-r3",
    "candidate_digest": "a41c97c8a467b0308b9f50ac072cc3adae1c2d47ca515b76f123e7c1debee9be",
    "package_digest": "4b032722f236dacc7f7e413cc37b31232000ce4f5d839bf0360fa8ac008ea6b1",
    "package_manifest_sha256": "66ede3f1995d644b9ce423c8e8846b50d823c57f76d892cef66694d7e1d3a793",
    "sealed_target_sha256": "b9f0cb2694ea0dcc49af7b0355fa491b3c74452c0f74ebc6c17f0b7c7b183c79",
    "controller_source_manifest_sha256": "0a4ad503db2f26aba4e050071fbc725f2ef0e6bd9216a6869d7123acf2047c8b",
    "preseal_verifier_expected": "V15_RUNTIME_AUTHORITY_PRESEAL_VERIFIED",
    "stopped_predecessor_supported": true,
    "stopped_predecessor_reason": "The controller has no active/running entry precondition. It captures protected bytes and authority, reserves once, calls stop idempotently, snapshots, performs stopped_probe, builds the fresh authority, runs smoke, switches, and starts r71. Its rollback assumes the predecessor can be restarted, so Restart=no must remain in force to bound a failed r70 restore to one failed start rather than another loop."
  },
  "exact_preconditions": [
    "Obtain a new explicit operator authorization naming package digest 4b032722f236dacc7f7e413cc37b31232000ce4f5d839bf0360fa8ac008ea6b1, one launcher invocation, creation/removal of one runtime Restart=no drop-in, daemon-reload, and protective stop on failure.",
    "Run the immutable preseal verifier before creating the runtime drop-in; require exit 0 and status V15_RUNTIME_AUTHORITY_PRESEAL_VERIFIED.",
    "Require service inactive/dead, MainPID=0, NRestarts=26 on two consecutive reads, and no matching gateway/controller/launcher PID.",
    "Require all four r71 effect roots absent with both -e and -L checks.",
    "Require every live hash listed above exact; any drift requires a new audit and no launcher call.",
    "Require /run/user/1000/systemd/user/hermes-gateway-dualcoachtest.service.d/00-safe-restore.conf absent before creation.",
    "After daemon-reload require Restart=no while ActiveState remains inactive and MainPID remains 0.",
    "Arm local file/journal observation before the launcher; no network, provider, customer, cron manual tick, observer, or authority side action is part of this sequence."
  ],
  "precondition_commands": [
    "set -euo pipefail; PRE=/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-transaction-preseal-v15-runtime-authority-r71; /usr/bin/python3 -B \"$PRE/controller-source/scripts/verify_nutricoach_v150_preseal_v15.py\" | tee /dev/stderr | grep -F 'V15_RUNTIME_AUTHORITY_PRESEAL_VERIFIED'",
    "set -euo pipefail; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p ActiveState --value)\" = inactive; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p SubState --value)\" = dead; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p MainPID --value)\" = 0; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p NRestarts --value)\" = 26; ! pgrep -f '[h]ermes_cli.main.*dualcoachtest.*gateway|[n]utricoach_v150_(controller|detached|execute)'",
    "set -euo pipefail; R=/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined; for p in \"$R/live-authorization-v15/nutricoach-v150-v15-runtime-authority-r71\" \"$R/live-executions-v15/nutricoach-v150-v15-runtime-authority-r71\" /home/cube/.hermes/profiles/dualcoachtest/.strict-runtime/a41c97c8-v150 \"$R/observer-r71\"; do test ! -e \"$p\"; test ! -L \"$p\"; done",
    "set -euo pipefail; printf '%s  %s\\n' 6a949de8c8a7c4caff4462f9c2821d49e5517a0f12defa93693e7f3bff97ed17 /home/cube/.hermes/profiles/dualcoachtest/config.yaml 176a7e3c55e5be95583c122dc535f13b35ef6fd13c1fbf9445f3cc2be95dd95e /home/cube/.hermes/profiles/dualcoachtest/customers/registry.json 92ef87536865b4d74c50f9715601de7870c5c3893839f2862dbaf62024e51af5 /home/cube/.hermes/profiles/dualcoachtest/data/weekly-operations-topic59.jsonl 1000b155ccb56aa318ac098613f5808d2cb9633fc1178a0b49f280c3a23f72a1 /home/cube/.hermes/profiles/dualcoachtest/data/scheduled-deliveries.jsonl e647bdcdd1505e3d978c73d69934c9f04c20159bad4e12ac9d0c93b202442555 /home/cube/.hermes/profiles/dualcoachtest/data/scheduled-deliveries-fence.json 4a718b95dc35f7219be2be54b402f19eb0af41dc35928206d19357a9d6f9053713 /home/cube/.hermes/profiles/dualcoachtest/data/customers/pilot_20260820_01/wizard/events.jsonl 318d62644dc480dbe2be54b402f19eb0af41dc35928206d19357a9d6f9053713 /home/cube/.hermes/profiles/dualcoachtest/data/customers/pilot_20260820_01/wizard/telegram-bindings.json 69f6510e555b47984c6462b12da569b5bb67c051b1592ddb2ffb93898564b9c1 /home/cube/.hermes/profiles/dualcoachtest/data/customers/pilot_20260820_01/wizard/drafts/235d1edf627bf3b9ba045b41a880b05a7.json d717125902230dc362c3e951ef0d6f656d0919dd0665f449f7056158b031dfab /home/cube/.hermes/profiles/dualcoachtest/data/customers/pilot_20260820_01/wizard/drafts/dc993802883dbb8ba045b41a880b05a7.json | sha256sum -c -"
  ],
  "safe_minimal_restoration_sequence_not_executed": [
    {
      "order": 1,
      "purpose": "Temporarily bound any failed predecessor/successor start to one attempt without modifying the persistent unit.",
      "command": "set -euo pipefail; D=/run/user/1000/systemd/user/hermes-gateway-dualcoachtest.service.d; F=\"$D/00-safe-restore.conf\"; test ! -e \"$F\"; test ! -L \"$F\"; umask 077; mkdir -p \"$D\"; printf '[Service]\\nRestart=no\\n' >\"$F\"; systemctl --user daemon-reload; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p Restart --value)\" = no; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p ActiveState --value)\" = inactive; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p MainPID --value)\" = 0"
    },
    {
      "order": 2,
      "purpose": "Invoke the original immutable r71 launcher exactly once in its network-unshared bubblewrap transaction.",
      "command": "set -euo pipefail; PRE=/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-transaction-preseal-v15-runtime-authority-r71; /usr/bin/python3 -B \"$PRE/controller-source/scripts/execute_nutricoach_v150_sealed_live.py\" --approval 'AUTHORIZE NUTRICOACH V1.5 LIVE UPGRADE 4b032722f236dacc7f7e413cc37b31232000ce4f5d839bf0360fa8ac008ea6b1'",
      "one_use": true
    },
    {
      "order": 3,
      "purpose": "Success fence before restoring normal restart policy.",
      "command": "set -euo pipefail; R=/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p ActiveState --value)\" = active; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p SubState --value)\" = running; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p MainPID --value)\" -gt 0; grep -Fq '\"phase\":\"COMMITTED\"' \"$R/live-executions-v15/nutricoach-v150-v15-runtime-authority-r71/phase.json\"; grep -Fq '\"outcome\":\"SUCCEEDED\"' \"$R/live-authorization-v15/nutricoach-v150-v15-runtime-authority-r71/authorization-consumed.json\"; grep -Fq a41c97c8a467b0308b9f50ac072cc3adae1c2d47ca515b76f123e7c1debee9be /home/cube/.config/systemd/user/hermes-gateway-dualcoachtest.service; test -d /home/cube/.hermes/profiles/dualcoachtest/data/weekly-operations-authority-a41c97c8a467b030"
    },
    {
      "order": 4,
      "purpose": "Remove only the temporary runtime override after r71 is committed and healthy, restoring the package's persistent Restart=always policy.",
      "command": "set -euo pipefail; F=/run/user/1000/systemd/user/hermes-gateway-dualcoachtest.service.d/00-safe-restore.conf; rm -- \"$F\"; rmdir --ignore-fail-on-non-empty \"$(dirname \"$F\")\"; systemctl --user daemon-reload; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p Restart --value)\" = always; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p ActiveState --value)\" = active"
    }
  ],
  "rollback_and_failure_handling": {
    "launcher_internal_rollback": "Before commit, the sealed RollbackGuard stops a running service, restores its authenticated transaction snapshot, removes only transaction-created successor/weekly roots, reloads systemd, and attempts predecessor start. With the runtime Restart=no override, an invalid r70 predecessor can fail only once and remains inactive instead of looping.",
    "failure_command": "set -euo pipefail; systemctl --user stop hermes-gateway-dualcoachtest.service; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p ActiveState --value)\" = inactive; test \"$(systemctl --user show hermes-gateway-dualcoachtest.service -p MainPID --value)\" = 0",
    "failure_policy": [
      "Leave 00-safe-restore.conf in place after any launcher or post-fence failure.",
      "Do not call the launcher again, even if authorization/execution files appear partial; preserve all roots as evidence.",
      "Do not manually invoke recover_pending or rollback_committed unless a new package-specific audit explicitly authorizes the exact observed phase.",
      "Do not restore the old r70 post-stop snapshots.",
      "A failed r71 one-use attempt requires a new independently sealed package/generation and new authorization."
    ]
  },
  "no_replay_constraints": [
    "Never replay r70: its authorization is CONSUMED/SUCCEEDED and execution is COMMITTED.",
    "Invoke original r71 at most once and only while authorization, execution, successor runtime, and observer-r71 roots are all absent.",
    "Never reuse the approval phrase after any launcher invocation, regardless of exit code or apparent absence of customer/provider effects.",
    "Do not manually tick cron, invoke observer-r70/r71, request customer input, send/update provider messages, or access network as part of recovery.",
    "Do not edit, truncate, replace, merge, or synthesize canonical-authorities-v1.jsonl or customer events/sequence/delivery ledgers.",
    "Do not copy a 2026-08-31 row from another weekly authority root.",
    "Do not remove or overwrite any failed/partial authority, execution, runtime, snapshot, candidate, or preseal root.",
    "Do not remove the temporary Restart=no override until r71 COMMITTED/SUCCEEDED and active/running are both proven."
  ],
  "audit_effects": {
    "git_commands": 0,
    "source_edits": 0,
    "service_start_restart_stop": 0,
    "network_customer_provider_authority_actions": 0,
    "live_profile_or_registration_writes": 0,
    "only_write": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-telegram-checkin-stepper/task-10-r70-safe-restore-analysis.json"
  }
}
