{
  "schema": "nutricoach-telegram-checkin-stepper-task-10-r71b-maintenance-digest-addendum-v1",
  "task_id": "st_01a05bb0",
  "generated_at": "2026-09-01T16:59:50+09:00",
  "mode": "advisory_read_only_except_required_evidence",
  "status": "SOUND_NORMATIVE_ADDENDUM",
  "design_status": {
    "design_path": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-telegram-checkin-stepper/task-10-r71b-maintenance-design.json",
    "design_sha256": "d955c2b35e8547fec11d687c8c01464b43e93cc9c0af3a9f7d79ce9cfe3b2e8e",
    "prior_status_interpretation": "DECISION_COMPLETE_EXCEPT_CIRCULAR_DIGEST_DERIVATION",
    "amended_status": "DECISION_COMPLETE_AS_AMENDED",
    "sound": true,
    "normative_replacement": "Every package_digest field in Topic59MaintenanceAuthorityV1, Topic59MaintenanceHoldV1, and Topic59MaintenanceSkipAuditV1 is replaced by package_binding_digest. FINAL_PACKAGE_DIGEST appears only in package.json, sealed-target.json, package-supersession.json, package-manifest.json metadata, authorization receipts, and execution receipts; it never appears in hold or authority bytes.",
    "unchanged_design": "The publication-boundary gate, pre-claim ordering, one-use consuming marker, terminal skip audit, typed NOOP_MAINTENANCE propagation, rollback pause, inventory, testing, and observer-r71 decisions remain unchanged."
  },
  "decision": {
    "algorithm": "TWO_STAGE_PACKAGE_BINDING_THEN_FINAL_PACKAGE_DIGEST",
    "summary": "First hash a complete non-self-referential package-binding input document that contains every semantic package input and the maintenance scope but contains no hold, authority, final package digest, approval phrase, or derived hash. Put that PACKAGE_BINDING_DIGEST into the hold and authority, then hash their exact bytes. Finally hash a final package payload that includes the complete binding input document, PACKAGE_BINDING_DIGEST, and the exact authority/hold hashes. This yields a separate FINAL_PACKAGE_DIGEST with no cycle.",
    "runtime_digest": "PACKAGE_BINDING_DIGEST",
    "controller_and_approval_digest": "FINAL_PACKAGE_DIGEST",
    "reason_trust_is_preserved": "FINAL_PACKAGE_DIGEST binds PACKAGE_BINDING_DIGEST and MAINTENANCE_AUTHORITY_FILE_SHA256. The sealed controller verifies FINAL_PACKAGE_DIGEST before copying the exact authority bytes into the successor systemd credential. Runtime then compares PACKAGE_BINDING_DIGEST consistently across the trusted authority credential, profile hold, and terminal audit while independently matching candidate/config/route/customer/card-slot/day. Runtime does not need the later final digest to authenticate a credential whose exact bytes were already admitted by that final digest."
  },
  "canonical_encoding": {
    "function": "canonical_json(value) = json.dumps(value, ensure_ascii=False, sort_keys=True, separators=(',', ':'), allow_nan=False).encode('utf-8')",
    "document_bytes": "canonical_json(document) + b'\\n'",
    "digest_encoding": "Every digest is 64 lowercase hexadecimal characters. Domain-separated preimages use the exact ASCII domain, one NUL byte, then canonical_json(document), with no trailing newline unless the algorithm explicitly says file SHA-256.",
    "type_constraints": [
      "All models are strict, frozen, and extra=forbid.",
      "Digest preimages contain only objects, arrays, strings, integers, booleans, and null. Floats are forbidden even though the shared canonical helper can encode them.",
      "Timestamps are normalized aware ISO-8601 strings with explicit +09:00 offset and seconds; no alternate textual representation is accepted.",
      "Absolute paths and relative package paths are exact strings; no resolve-time alias, symlink, '..', duplicate slash, or environment substitution is accepted.",
      "A parsed document must reproduce the exact original document bytes when canonicalized; whitespace/key-order variants are rejected rather than normalized silently."
    ],
    "digest_domains": {
      "PACKAGE_BINDING_DIGEST": "nutricoach-r71b-package-binding-v1",
      "MAINTENANCE_SCOPE_DIGEST": "nutricoach-r71b-maintenance-scope-v1",
      "HOLD_ID": "nutricoach-r71b-maintenance-hold-id-v1",
      "FINAL_PACKAGE_DIGEST": "nutricoach-r71b-final-package-v1"
    },
    "plain_file_hashes": [
      "BINDING_INPUTS_FILE_SHA256",
      "MAINTENANCE_SCOPE_FILE_SHA256",
      "NO_SEND_ORACLE_FILE_SHA256",
      "HOLD_FILE_SHA256",
      "MAINTENANCE_AUTHORITY_FILE_SHA256",
      "PERMISSION_PACKAGE_FILE_SHA256",
      "SEALED_TARGET_FILE_SHA256",
      "candidate/wheel/RECORD/controller/protected-inventory/dependency hashes"
    ]
  },
  "exact_namespace": {
    "product_generation": "r71",
    "package_namespace": "r71b-maintenance",
    "candidate_root": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-v150-combined/task-v15r71b-maintenance-candidate",
    "preseal_root": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-transaction-preseal-v15-runtime-authority-r71b-maintenance",
    "preflight_root": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/preflight-v15-runtime-authority-r71b-maintenance",
    "authority_id": "nutricoach-v150-v15-runtime-authority-r71b-maintenance",
    "authorization_root": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-authorization-v15/nutricoach-v150-v15-runtime-authority-r71b-maintenance",
    "execution_root": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/live-executions-v15/nutricoach-v150-v15-runtime-authority-r71b-maintenance",
    "rehearsal_root": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-v150-combined/task-v15r71b-maintenance-rehearsal",
    "observer_root": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/observer-r71",
    "preseal_binding_inputs": "maintenance/package-binding-inputs.json",
    "preseal_scope": "maintenance/maintenance-scope.json",
    "preseal_no_send_oracle": "maintenance/no-send-oracle.json",
    "preseal_authority": "maintenance-authority/nutricoach-topic59-maintenance-r71b.json",
    "preflight_permission_package": "package.json",
    "sealed_target": "sealed-target.json",
    "credential_name": "nutricoach-topic59-maintenance-r71b.json",
    "successor_credential_source": "/home/cube/.hermes/profiles/dualcoachtest/.strict-runtime/<candidate-digest-prefix>-v150/runtime-authority/nutricoach-topic59-maintenance-r71b.json",
    "runtime_credential": "$CREDENTIALS_DIRECTORY/nutricoach-topic59-maintenance-r71b.json",
    "active_hold": "/home/cube/.hermes/profiles/dualcoachtest/data/topic59-maintenance-r71b/hold.json",
    "consuming_hold": "/home/cube/.hermes/profiles/dualcoachtest/data/topic59-maintenance-r71b/hold.consuming.json",
    "terminal_audit": "/home/cube/.hermes/profiles/dualcoachtest/data/topic59-maintenance-r71b/skip-audit.json",
    "lock": "/home/cube/.hermes/profiles/dualcoachtest/data/topic59-maintenance-r71b/maintenance.lock",
    "approval_phrase": "AUTHORIZE NUTRICOACH V1.5 R71B MAINTENANCE UPGRADE <FINAL_PACKAGE_DIGEST>",
    "forbidden_aliases": [
      "task-v15r71-candidate-r4",
      "live-transaction-preseal-v15-runtime-authority-r71",
      "preflight-v15-runtime-authority-r71",
      "nutricoach-v150-v15-runtime-authority-r71",
      "observer-r71b",
      "any r72 path"
    ]
  },
  "source_documents_before_binding": {
    "maintenance_scope_document": {
      "path": "<PRESEAL>/maintenance/maintenance-scope.json",
      "schema": "nutricoach-r71b-maintenance-scope-v1",
      "fields_in_exact_canonical_object": [
        "schema",
        "product_generation = 'r71'",
        "package_namespace = 'r71b-maintenance'",
        "authority_id",
        "credential_name",
        "purpose = 'r71_cron_health_recovery'",
        "max_consumptions = 1",
        "candidate_digest",
        "config_digest",
        "route_digest",
        "customer_identity_digest",
        "card_slot",
        "kst_day",
        "not_before",
        "expires_at",
        "active_hold_relative_path = 'data/topic59-maintenance-r71b/hold.json'",
        "consuming_hold_relative_path = 'data/topic59-maintenance-r71b/hold.consuming.json'",
        "terminal_audit_relative_path = 'data/topic59-maintenance-r71b/skip-audit.json'",
        "lock_relative_path = 'data/topic59-maintenance-r71b/maintenance.lock'"
      ],
      "explicitly_absent": [
        "package_binding_digest",
        "package_digest",
        "approval_phrase",
        "hold_id",
        "hold_sha256",
        "authority_sha256",
        "row_digest",
        "nonce or random bytes"
      ],
      "scope_digest_formula": "MAINTENANCE_SCOPE_DIGEST = SHA256(b'nutricoach-r71b-maintenance-scope-v1\\0' + canonical_json(MAINTENANCE_SCOPE_DOCUMENT))",
      "file_hash_formula": "MAINTENANCE_SCOPE_FILE_SHA256 = SHA256(document_bytes(MAINTENANCE_SCOPE_DOCUMENT))"
    },
    "no_send_oracle_document": {
      "path": "<PRESEAL>/maintenance/no-send-oracle.json",
      "schema": "nutricoach-r71b-no-send-oracle-v1",
      "fields_in_exact_canonical_object": [
        "schema",
        "observed_r70_candidate_digest",
        "cron_job semantic identity: id/name/schedule/inline_card/delivery/enabled/state",
        "accepted_known_error exact string and evidence SHA-256",
        "target kst_day",
        "target candidate_digest/config_digest/route_digest/customer_identity_digest/card_slot",
        "non_topic59_due_send_count = 0",
        "non_topic59_due_edit_count = 0",
        "activation_notice_due_count = 0",
        "owner_delivery_due_count = 0",
        "target_topic59_projection_count = 1",
        "historical_incident_slots: exact ordered card_slot/latest_entry_digest/state/message_id-null rows",
        "topic59_publication_ledger_sha256",
        "scheduled_deliveries_sha256 and current-day terminal summary",
        "observer readiness disposition and fixed-collector source SHA-256"
      ],
      "file_hash_formula": "NO_SEND_ORACLE_FILE_SHA256 = SHA256(document_bytes(NO_SEND_ORACLE_DOCUMENT))"
    }
  },
  "package_binding_preimage": {
    "path": "<PRESEAL>/maintenance/package-binding-inputs.json",
    "schema": "nutricoach-v150-r71b-package-binding-inputs-v1",
    "rule": "This document is the complete first-stage semantic package preimage. It is independently reconstructed by the verifier; trusting the copy embedded in package.json is insufficient.",
    "top_level_fields": {
      "schema": "Literal['nutricoach-v150-r71b-package-binding-inputs-v1']",
      "product_generation": "Literal['r71']",
      "package_namespace": "Literal['r71b-maintenance']",
      "authority_id": "exact authority id",
      "paths": "Exact absolute candidate/preseal/preflight/authorization/execution/successor-runtime/profile/unit/dropin/observer roots plus exact authority relative path and credential name",
      "candidate": "candidate_digest, absolute candidate_manifest path, candidate_manifest_sha256",
      "wheels": "Ordered two-row build-1 wheel list; each row has role, absolute path, wheel sha256, RECORD sha256. Reproducible build-2 equality is already candidate-bound and is reverified separately.",
      "controller": "controller_source_manifest relative path, complete sorted files map, controller_derivation_sha256 = SHA256(canonical_json(files map))",
      "protected_inventory": "absolute snapshot-before path, protected_inventory_sha256, classifier_source_sha256, exact explicit maintenance volatile path list",
      "dependency_snapshot": "absolute dependency root and deterministic dependency_snapshot_sha256",
      "authority_baseline": "authority_root, candidate_digest, candidate_path and file hash, pin_path and file hash, source_id, genesis_sha256, registry/ledger file and head hashes, event_count, historical_pass_digest",
      "target_binding_base": "profile_root, current_runtime, successor_runtime, service_name, unit, dropin, execution_root, global_approval_ledger, protected_inventory path/hash, dependency path/hash, registry_sha256",
      "service_preparation": "ActiveState, SubState, MainPID, ExecStart, NRestarts as captured by the preparer",
      "maintenance_scope": "Exact parsed MAINTENANCE_SCOPE_DOCUMENT",
      "maintenance_scope_path": "maintenance/maintenance-scope.json",
      "maintenance_scope_file_sha256": "MAINTENANCE_SCOPE_FILE_SHA256",
      "maintenance_scope_digest": "MAINTENANCE_SCOPE_DIGEST",
      "no_send_oracle": "Exact parsed NO_SEND_ORACLE_DOCUMENT",
      "no_send_oracle_path": "maintenance/no-send-oracle.json",
      "no_send_oracle_file_sha256": "NO_SEND_ORACLE_FILE_SHA256",
      "diagnosed_blocker_evidence": "Ordered exact path/SHA-256 rows for task-10-cron-no-send-recovery-analysis.json, task-10-debug-cron.json, task-10-debug-observer-r70.json, task-10-next-cron-no-send.json, and task-10-r70-health-recovery.json"
    },
    "excluded_derived_fields": [
      "package_binding_digest",
      "binding_inputs_file_sha256",
      "hold_id",
      "hold bytes or hold_sha256",
      "authority bytes or authority_sha256",
      "final package payload",
      "final package digest",
      "approval phrase",
      "permission package file sha256",
      "sealed target bytes or sha256",
      "package-supersession bytes or sha256",
      "package-manifest bytes or sha256",
      "authorization/execution receipts"
    ],
    "placeholder_rule": "No placeholder is used. In particular, no zero digest, empty package_digest, '<pending>', null self-field, or second-pass text replacement is permitted. Excluded derived fields are absent keys, not placeholder values.",
    "formula": "PACKAGE_BINDING_DIGEST = SHA256(b'nutricoach-r71b-package-binding-v1\\0' + canonical_json(PACKAGE_BINDING_INPUTS_DOCUMENT))",
    "file_hash_formula": "BINDING_INPUTS_FILE_SHA256 = SHA256(document_bytes(PACKAGE_BINDING_INPUTS_DOCUMENT))"
  },
  "hold_derivation": {
    "ordering": 1,
    "hold_id_preimage": {
      "schema": "nutricoach-r71b-maintenance-hold-id-preimage-v1",
      "package_binding_digest": "PACKAGE_BINDING_DIGEST",
      "maintenance_scope_digest": "MAINTENANCE_SCOPE_DIGEST"
    },
    "hold_id_formula": "HOLD_ID = SHA256(b'nutricoach-r71b-maintenance-hold-id-v1\\0' + canonical_json(HOLD_ID_PREIMAGE))",
    "nonce_rule": "There is no nonce. The fresh one-use authority namespace plus the complete package binding and exact maintenance scope make HOLD_ID deterministic and collision-resistant. This normatively replaces the design's earlier preseal-nonce wording.",
    "hold_document": {
      "schema": "nutricoach-topic59-maintenance-hold-v1",
      "hold_id": "HOLD_ID",
      "package_binding_digest": "PACKAGE_BINDING_DIGEST",
      "scope": "Exact MAINTENANCE_SCOPE_DOCUMENT"
    },
    "hold_bytes_formula": "HOLD_FILE_BYTES = canonical_json(HOLD_DOCUMENT) + b'\\n'",
    "hold_sha_formula": "HOLD_FILE_SHA256 = SHA256(HOLD_FILE_BYTES)",
    "forbidden_hold_fields": [
      "package_digest",
      "final_package_digest",
      "approval_phrase",
      "authority_sha256",
      "message_id",
      "provider receipt"
    ]
  },
  "authority_derivation": {
    "ordering": 2,
    "authority_document": {
      "schema": "nutricoach-topic59-maintenance-authority-v1",
      "authority_id": "nutricoach-v150-v15-runtime-authority-r71b-maintenance",
      "product_generation": "r71",
      "package_namespace": "r71b-maintenance",
      "package_binding_digest": "PACKAGE_BINDING_DIGEST",
      "hold_sha256": "HOLD_FILE_SHA256",
      "hold": "Exact HOLD_DOCUMENT"
    },
    "authority_bytes_formula": "MAINTENANCE_AUTHORITY_FILE_BYTES = canonical_json(AUTHORITY_DOCUMENT) + b'\\n'",
    "authority_sha_formula": "MAINTENANCE_AUTHORITY_FILE_SHA256 = SHA256(MAINTENANCE_AUTHORITY_FILE_BYTES)",
    "output_path": "<PRESEAL>/maintenance-authority/nutricoach-topic59-maintenance-r71b.json",
    "mode_after_freeze": "0444 in preseal; the successor credential copy is 0400",
    "forbidden_authority_fields": [
      "package_digest",
      "final_package_digest",
      "approval_phrase",
      "permission_package_sha256",
      "sealed_target_sha256"
    ]
  },
  "final_package_derivation": {
    "ordering": 3,
    "payload_schema": "nutricoach-v150-r71b-final-package-payload-v1",
    "final_payload_fields": {
      "schema": "Literal['nutricoach-v150-r71b-final-package-payload-v1']",
      "package_binding_inputs": "Exact PACKAGE_BINDING_INPUTS_DOCUMENT",
      "package_binding_inputs_path": "maintenance/package-binding-inputs.json",
      "package_binding_inputs_file_sha256": "BINDING_INPUTS_FILE_SHA256",
      "package_binding_digest": "PACKAGE_BINDING_DIGEST",
      "maintenance_authority_path": "maintenance-authority/nutricoach-topic59-maintenance-r71b.json",
      "maintenance_authority_sha256": "MAINTENANCE_AUTHORITY_FILE_SHA256",
      "maintenance_hold_id": "HOLD_ID",
      "maintenance_hold_sha256": "HOLD_FILE_SHA256"
    },
    "formula": "FINAL_PACKAGE_DIGEST = SHA256(b'nutricoach-r71b-final-package-v1\\0' + canonical_json(FINAL_PACKAGE_PAYLOAD))",
    "permission_package_document": {
      "schema": "nutricoach-v150-r71b-permission-package-v1",
      "package_digest": "FINAL_PACKAGE_DIGEST",
      "approval_phrase": "'AUTHORIZE NUTRICOACH V1.5 R71B MAINTENANCE UPGRADE ' + FINAL_PACKAGE_DIGEST",
      "payload": "Exact FINAL_PACKAGE_PAYLOAD"
    },
    "permission_package_path": "<PREFLIGHT>/package.json",
    "permission_package_file_sha_formula": "PERMISSION_PACKAGE_FILE_SHA256 = SHA256(canonical_json(PERMISSION_PACKAGE_DOCUMENT) + b'\\n')",
    "non_self_reference_rule": "package_digest and approval_phrase are outside FINAL_PACKAGE_PAYLOAD. FINAL_PACKAGE_DIGEST is computed only over FINAL_PACKAGE_PAYLOAD. The permission package file's ordinary SHA-256 is computed later and is allowed to differ from FINAL_PACKAGE_DIGEST.",
    "final_digest_not_in": [
      "PACKAGE_BINDING_INPUTS_DOCUMENT",
      "MAINTENANCE_SCOPE_DOCUMENT",
      "NO_SEND_ORACLE_DOCUMENT",
      "HOLD_ID_PREIMAGE",
      "HOLD_DOCUMENT",
      "AUTHORITY_DOCUMENT",
      "FINAL_PACKAGE_PAYLOAD"
    ]
  },
  "sealed_target_binding": {
    "ordering": 4,
    "required_fields": [
      "schema = 'nutricoach-v150-r71b-sealed-live-target-v1'",
      "all target_binding_base fields copied exactly from PACKAGE_BINDING_INPUTS_DOCUMENT",
      "candidate_digest/candidate_manifest/candidate_manifest_sha256",
      "controller_derivation_sha256",
      "authority_baseline",
      "ordered wheels",
      "package_binding_digest = PACKAGE_BINDING_DIGEST",
      "package_digest = FINAL_PACKAGE_DIGEST",
      "approval_phrase",
      "permission_package absolute path",
      "permission_package_sha256 = PERMISSION_PACKAGE_FILE_SHA256",
      "maintenance_authority absolute preseal path",
      "maintenance_authority_sha256 = MAINTENANCE_AUTHORITY_FILE_SHA256",
      "maintenance_credential_name",
      "maintenance_hold_id = HOLD_ID",
      "maintenance_hold_sha256 = HOLD_FILE_SHA256"
    ],
    "why_both_digests": "package_binding_digest is the identity shared with runtime artifacts. package_digest is the one-use approval/controller identity that additionally commits to the exact authority bytes. A sealed target that changes either independently is invalid.",
    "sealed_target_exclusion": "sealed-target.json is a derived output and is not included in FINAL_PACKAGE_PAYLOAD. Its exact bytes are bound by package-manifest.json, while verify_preseal independently compares every duplicated field to the permission package and recomputes both digests.",
    "sealed_target_file_sha_formula": "SEALED_TARGET_FILE_SHA256 = SHA256(canonical_json(SEALED_TARGET_DOCUMENT) + b'\\n')"
  },
  "physical_manifest_rules": {
    "package_manifest": "<PRESEAL>/package-manifest.json is written last. Its entries map contains every regular preseal file and SHA-256, including package-binding-inputs.json, maintenance-scope.json, no-send-oracle.json, the maintenance authority credential source, controller closure, dependencies, sealed-target.json, and package-supersession.json.",
    "sole_self_exclusion": "package-manifest.json only",
    "permission_package_binding": "package.json is outside PRESEAL under PREFLIGHT. sealed-target.json binds its absolute path and PERMISSION_PACKAGE_FILE_SHA256; verify_preseal reads and checks it.",
    "no_other_exclusion": "No maintenance input, authority, target, controller, dependency, or supersession file is omitted from the physical manifest."
  },
  "credential_generation_and_live_order": [
    "1. Candidate sealing completes first; CANDIDATE_DIGEST and exact wheel hashes are immutable inputs.",
    "2. The r71b preparer proves every fresh r71b root absent and all old r71 roots unchanged.",
    "3. It builds controller/dependency closure and a fresh protected inventory, derives the exact successor config/projection, then writes maintenance-scope.json and no-send-oracle.json.",
    "4. It writes package-binding-inputs.json and computes PACKAGE_BINDING_DIGEST. No authority or hold exists before this point.",
    "5. It computes HOLD_ID, constructs HOLD_FILE_BYTES, and computes HOLD_FILE_SHA256. HOLD_FILE_BYTES are held in memory; the profile is not touched.",
    "6. It constructs and writes the preseal authority source at maintenance-authority/nutricoach-topic59-maintenance-r71b.json and computes MAINTENANCE_AUTHORITY_FILE_SHA256.",
    "7. It constructs FINAL_PACKAGE_PAYLOAD, computes FINAL_PACKAGE_DIGEST, writes preflight/package.json, then writes sealed-target.json with both digests and both maintenance hashes.",
    "8. It writes package-supersession.json and package-manifest.json, verifies exact inventory, then freezes PRESEAL. There is no second digest pass and no text replacement.",
    "9. During the live transaction, after exact wheels are installed but before systemd switch/start, the controller re-verifies the preseal and permission package, reads the exact preseal authority bytes, and copies them byte-for-byte to <successor-root>/runtime-authority/nutricoach-topic59-maintenance-r71b.json mode 0400.",
    "10. The controller reads AUTHORITY_DOCUMENT.hold, reconstructs HOLD_FILE_BYTES, confirms HOLD_FILE_SHA256, and atomically writes those exact bytes to profile hold.json mode 0600 while the predecessor service is stopped.",
    "11. The systemd drop-in postimage adds exactly LoadCredential=nutricoach-topic59-maintenance-r71b.json:<successor credential source>. The service starts only after credential and hold readback verification.",
    "12. systemd materializes the credential under CREDENTIALS_DIRECTORY. Runtime opens only that exact credential name and never reads the preseal or preflight package directly."
  ],
  "runtime_comparison_contract": {
    "must_compare": [
      "AUTHORITY_DOCUMENT.package_binding_digest == HOLD_DOCUMENT.package_binding_digest",
      "AUTHORITY_DOCUMENT.hold_sha256 == SHA256(exact active or consuming hold file bytes)",
      "Exact parsed hold object == AUTHORITY_DOCUMENT.hold",
      "HOLD_DOCUMENT.hold_id == derived HOLD_ID from its package_binding_digest and scope digest",
      "projection.candidate_digest/config_digest/route_digest/customer_identity_digest/card_slot/kst_day == corresponding HOLD_DOCUMENT.scope fields",
      "active Task26 authorized candidate == HOLD_DOCUMENT.scope.candidate_digest",
      "terminal audit package_binding_digest/hold_id/hold_sha256 and all scope bindings == credential authority and projection",
      "terminal audit row_digest and false/null zero-call fields are valid"
    ],
    "must_not_compare": "Runtime must not expect or compare FINAL_PACKAGE_DIGEST. It is deliberately absent from the credential, hold, and audit. The live controller and preseal verifier own that comparison.",
    "audit_schema_amendment": "Topic59MaintenanceSkipAuditV1 contains package_binding_digest, not package_digest. Its row digest covers package_binding_digest and all audit fields except row_digest.",
    "missing_or_mixed_digest": "A hold/audit carrying package_digest, final_package_digest, an unknown digest field, or a PACKAGE_BINDING_DIGEST from another authority fails strict parsing or BINDING_MISMATCH before Topic59PublicationLedger.claim."
  },
  "verifier_recomputation": {
    "candidate_verifier": [
      "Verify fresh candidate physical inventory, source/wheel parity, and candidate digest normally.",
      "Require all r71b derivation code/tests in source inventory and overlay; reject any old r71 default-root selection."
    ],
    "preseal_verifier_exact_order": [
      "1. Verify package-manifest exact inventory, modes, owner/link/no-follow rules, and controller closure before imports.",
      "2. Read package-binding-inputs.json and require exact canonical bytes/schema/absence rules.",
      "3. Independently reconstruct every PACKAGE_BINDING_INPUTS_DOCUMENT field from candidate manifest, wheels/RECORD, controller files, fresh inventory/classifier, dependency tree, authority baseline, target roots, service preparation snapshot, maintenance-scope.json, no-send-oracle.json, and diagnosed evidence hashes. Require object equality, not merely digest equality.",
      "4. Recompute MAINTENANCE_SCOPE_DIGEST and both scope/oracle file SHA-256 values; compare to binding inputs.",
      "5. Recompute PACKAGE_BINDING_DIGEST with the domain-separated formula and compare to package payload, authority, hold, and sealed target.",
      "6. Recompute HOLD_ID from PACKAGE_BINDING_DIGEST plus MAINTENANCE_SCOPE_DIGEST; reconstruct HOLD_DOCUMENT/HOLD_FILE_BYTES and HOLD_FILE_SHA256.",
      "7. Reconstruct AUTHORITY_DOCUMENT/AUTHORITY_FILE_BYTES; require byte equality with the preseal authority file and compare MAINTENANCE_AUTHORITY_FILE_SHA256.",
      "8. Reconstruct FINAL_PACKAGE_PAYLOAD exactly; recompute FINAL_PACKAGE_DIGEST and require package.package_digest and approval phrase equality.",
      "9. Recompute PERMISSION_PACKAGE_FILE_SHA256 and compare to sealed target. Compare every sealed-target duplicated binding field, both digests, authority path/hash, hold id/hash, and exact fresh root.",
      "10. Verify package-supersession active digest/phrase and immutable old-r71 tombstone entries, then require authorization/execution/successor roots absent."
    ],
    "detached_bootstrap": "Bootstrap verifies physical preseal inventory first, then the imported verifier performs semantic recomputation above. Bootstrap never accepts package-manifest hashes as a substitute for two-stage derivation.",
    "live_controller": [
      "Run the exact preseal verifier before reservation and again immediately before credential/hold installation after stopped-state drift checks.",
      "Compare copied successor credential bytes to the sealed target authority SHA-256 and preseal source bytes.",
      "Compare active hold bytes to sealed target hold SHA-256 and AUTHORITY_DOCUMENT.hold before service start.",
      "Post-fence compares final package digest in authorization/execution receipts and package binding digest in credential/audit; it reports both separately."
    ]
  },
  "tamper_tests": [
    {
      "id": "T1",
      "attack": "Insert package_digest or a zero/pending placeholder into maintenance-scope, hold, or authority.",
      "expected": "Strict extra-field or exact-object rejection before any digest acceptance."
    },
    {
      "id": "T2",
      "attack": "Change any maintenance scope binding while leaving PACKAGE_BINDING_DIGEST unchanged.",
      "expected": "Scope file hash/scope digest and independently reconstructed binding inputs reject."
    },
    {
      "id": "T3",
      "attack": "Change scope and recompute scope digest plus PACKAGE_BINDING_DIGEST inside package files.",
      "expected": "Independent derivation from live/candidate inputs differs; FINAL_PACKAGE_DIGEST/approval and sealed target also reject."
    },
    {
      "id": "T4",
      "attack": "Change package-binding-inputs.json whitespace/key order only.",
      "expected": "Exact canonical document-byte check rejects despite equivalent parsed JSON."
    },
    {
      "id": "T5",
      "attack": "Change one candidate, wheel, RECORD, controller, inventory, dependency, authority-baseline, target-path, service, oracle, or diagnosed-evidence field.",
      "expected": "Independent PACKAGE_BINDING_INPUTS reconstruction or source hash verification rejects."
    },
    {
      "id": "T6",
      "attack": "Swap in authority bytes from another r71b package with the same candidate but different route/day/window.",
      "expected": "Authority file SHA and PACKAGE_BINDING_DIGEST mismatch; runtime also rejects projection binding."
    },
    {
      "id": "T7",
      "attack": "Modify HOLD_ID only and recompute hold file SHA/authority bytes.",
      "expected": "HOLD_ID formula fails; final payload authority hash and final digest fail unless all are recomputed, after which sealed approval/independent inputs still fail."
    },
    {
      "id": "T8",
      "attack": "Modify hold content and authority hold_sha256 consistently without changing final payload.",
      "expected": "MAINTENANCE_AUTHORITY_FILE_SHA256/final payload mismatch."
    },
    {
      "id": "T9",
      "attack": "Modify authority and update final payload authority_sha256 but retain FINAL_PACKAGE_DIGEST.",
      "expected": "FINAL_PACKAGE_DIGEST recomputation fails."
    },
    {
      "id": "T10",
      "attack": "Recompute FINAL_PACKAGE_DIGEST after authority tamper but retain approval phrase or sealed target.",
      "expected": "Approval, permission-package SHA, sealed-target duplicate fields, package supersession, or user-authorized phrase rejects before reservation."
    },
    {
      "id": "T11",
      "attack": "Change only sealed-target package_binding_digest or package_digest.",
      "expected": "Verifier comparison to permission package/recomputed values and package-manifest file hash rejects."
    },
    {
      "id": "T12",
      "attack": "Point authority path/credential name at old r71 or another file with equal-shaped JSON.",
      "expected": "Exact namespace/path field reconstruction and authority file hash reject."
    },
    {
      "id": "T13",
      "attack": "Omit authority, scope, oracle, binding inputs, or sealed target from package-manifest, or add an unlisted file.",
      "expected": "Exact physical inventory rejection in detached bootstrap."
    },
    {
      "id": "T14",
      "attack": "Replace successor credential after copy or alter its mode/owner/link/kind.",
      "expected": "Controller postimage/readback or runtime credential filesystem contract rejects; no claim/provider call."
    },
    {
      "id": "T15",
      "attack": "Use a valid hold with a terminal audit containing FINAL_PACKAGE_DIGEST instead of PACKAGE_BINDING_DIGEST.",
      "expected": "Strict audit schema rejects before claim."
    },
    {
      "id": "T16",
      "attack": "Mix valid authority/hold from one package with audit from another package that has the same day/card slot.",
      "expected": "package_binding_digest, hold_id, hold_sha256, and audit row digest comparison rejects."
    },
    {
      "id": "T17",
      "attack": "Attempt a second-pass algorithm that writes a placeholder package digest into authority and replaces it after final hashing.",
      "expected": "Test asserts placeholder strings are forbidden, authority bytes are generated exactly once before final payload, and recomputation from retained stage artifacts is byte-identical."
    },
    {
      "id": "T18",
      "attack": "Rename the fresh roots to candidate-r4, bare r71, r72, or observer-r71b.",
      "expected": "Binding input path reconstruction and occupied/tombstone checks reject without mutation."
    }
  ],
  "reproducibility_and_stage_receipt": {
    "required_retained_hashes": [
      "MAINTENANCE_SCOPE_DIGEST",
      "MAINTENANCE_SCOPE_FILE_SHA256",
      "NO_SEND_ORACLE_FILE_SHA256",
      "BINDING_INPUTS_FILE_SHA256",
      "PACKAGE_BINDING_DIGEST",
      "HOLD_ID",
      "HOLD_FILE_SHA256",
      "MAINTENANCE_AUTHORITY_FILE_SHA256",
      "FINAL_PACKAGE_DIGEST",
      "PERMISSION_PACKAGE_FILE_SHA256",
      "SEALED_TARGET_FILE_SHA256",
      "package-manifest SHA-256"
    ],
    "stage_replay": "A read-only derivation verifier receives the retained scope, oracle, binding-input, authority, package, and target files and reproduces every intermediate in the listed order. It must never need to guess, substitute a placeholder, mutate a file, or iterate to convergence.",
    "expected_result": "One pass produces one stable PACKAGE_BINDING_DIGEST and one stable FINAL_PACKAGE_DIGEST. Re-running from identical bytes produces identical intermediate/final values."
  },
  "implementation_norms": {
    "symbols_to_add_or_change": [
      "canonical_binding_digest(document) in prepare/verify shared code",
      "maintenance_scope_digest(document)",
      "derive_hold_id(package_binding_digest, maintenance_scope_digest)",
      "build_maintenance_hold(scope, package_binding_digest)",
      "build_maintenance_authority(hold, package_binding_digest)",
      "final_package_digest(payload)",
      "verify_r71b_package_derivation(...)"
    ],
    "single_source_rule": "The preparer and verifier may share canonical encoding and pure digest constructors from a sealed small module, but the verifier must independently collect/reconstruct input values. It must not call a preparer function that simply returns the preparer's stored document.",
    "schema_changes_from_design": [
      "Topic59MaintenanceAuthorityV1.package_digest -> package_binding_digest",
      "Topic59MaintenanceHoldV1.package_digest -> package_binding_digest",
      "Topic59MaintenanceSkipAuditV1.package_digest -> package_binding_digest",
      "Hold ID is deterministic from package binding plus scope digest; remove preseal nonce language.",
      "Sealed target and permission package retain separate package_digest = FINAL_PACKAGE_DIGEST and add package_binding_digest."
    ]
  },
  "soundness_argument": [
    "PACKAGE_BINDING_DIGEST has no dependency on hold, authority, final payload, final digest, or approval.",
    "HOLD_ID and HOLD_FILE_SHA256 depend only on PACKAGE_BINDING_DIGEST and maintenance scope.",
    "MAINTENANCE_AUTHORITY_FILE_SHA256 depends only on PACKAGE_BINDING_DIGEST and the already-derived hold.",
    "FINAL_PACKAGE_DIGEST depends on PACKAGE_BINDING_DIGEST and the already-derived authority/hold hashes, but no earlier object contains FINAL_PACKAGE_DIGEST.",
    "The approval phrase and permission-package file hash are derived only after FINAL_PACKAGE_DIGEST and are not part of its preimage.",
    "sealed-target.json is derived after the permission package and binds both digest layers; the physical package manifest binds sealed-target bytes.",
    "Therefore the derivation graph is acyclic: source inputs -> package binding -> hold -> authority -> final payload -> final digest -> permission package -> sealed target -> physical manifest."
  ],
  "forbidden_effects": {
    "source_edits": 0,
    "live_profile_or_state_edits": 0,
    "candidate_or_preseal_edits": 0,
    "service_or_cron_actions": 0,
    "authority_reservations_or_consumptions": 0,
    "observer_appends": 0,
    "git_or_github_actions": 0,
    "network_or_provider_actions": 0,
    "customer_messages_or_updates": 0
  },
  "only_persistent_artifact": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-telegram-checkin-stepper/task-10-r71b-maintenance-digest-addendum.json"
}
