{
  "schema": "nutricoach-telegram-checkin-stepper-task-11-day-status-migration-codemap-v1",
  "task_id": "st_01a05dd3",
  "captured_at_kst": "2026-09-02T01:39:00+09:00",
  "mode": "read_only_code_and_evidence_investigation_except_this_deliverable",
  "verdict": "NO_SUPPORTED_CROSS_AUTHORITY_MIGRATION_API_OR_COMMAND_MINIMAL_SEALED_IMPORT_REQUIRED",
  "done_claim": false,
  "summary": "Original committed r71 created a valid candidate-scoped weekly authority and canonical registration but did not migrate the predecessor sidecar history. The r70 authority contains one authenticated 2026-08-31 missed row; the r71 sidecar is a durable empty file. WeeklyOperationRow has no authority ID, authority binding, candidate digest, or migration provenance field, and an in-memory reconstruction through the current canonical row contract reproduced the r70 row digest and all 792 bytes exactly. Therefore the row is customer/canonical-history bound, not authority/candidate bound, and it does not need to be semantically reissued with a different candidate. Nevertheless raw cp/write_bytes is not a supported or safe migration: it bypasses verified authority capabilities, global history validation, the sidecar lock, append/replay conflict checks, inode checks, fsync, crash continuation, and authenticated predecessor provenance. No cross-authority migration API or CLI exists. The smallest correct repair is a newly sealed, one-use, offline successor repair package that adds a prefix-preserving history import primitive implemented on WeeklyOperationsStore.read/append, records predecessor provenance in a separate authenticated migration receipt, stops provider-capable runtime and observer scheduling during the transaction, and creates a new observer namespace. The existing observer-r71 chain cannot become a seven-day PASS because it already contains failed observations and final_verdict rejects any failed row and late coverage.",
  "live_state_read_only_snapshot": {
    "configured_original_r71": {
      "config_relative_authority_path": "data/weekly-operations-authority-a41c97c8a467b030",
      "candidate_digest": "a41c97c8a467b0308b9f50ac072cc3adae1c2d47ca515b76f123e7c1debee9be",
      "authority_root": "/home/cube/.hermes/profiles/dualcoachtest/data/weekly-operations-authority-a41c97c8a467b030",
      "root_mode": "0700",
      "marker_sha256": "dd5981f94300d1fa9269fac018c8c309badee2dd4096daab82237630d105c57f",
      "canonical_registration_sha256": "b7a5dde559c7de527a69a41037e95d2337579370bf22668b064a7295e7b19e20",
      "canonical_registration_rows": 1,
      "day_status_file": "93f977332e8ca6e15d229c7154154b373bd9c07259fb3940b4c07e1b4227e823.day-status-v1.jsonl",
      "day_status_mode": "0600",
      "day_status_rows": 0,
      "day_status_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
      "day_status_head": "0000000000000000000000000000000000000000000000000000000000000000"
    },
    "committed_predecessor_r70": {
      "candidate_digest": "81a7a06ec2e7a1595784c92ab61df0df7e138d13a2620d9a917e94999e7f7a04",
      "authority_root": "/home/cube/.hermes/profiles/dualcoachtest/data/weekly-operations-authority-81a7a06ec2e7a159",
      "root_mode": "0700",
      "marker_sha256": "39d786bef523af384252b1be17ae929b26435b70b759746eb3704072a9f11a8f",
      "canonical_registration_sha256": "542555cf4068012028711441ed220e6c80ab182462bbfd6eff95856bb0ba472f",
      "day_status_file": "93f977332e8ca6e15d229c7154154b373bd9c07259fb3940b4c07e1b4227e823.day-status-v1.jsonl",
      "day_status_mode": "0600",
      "day_status_rows": 1,
      "day_status_sha256": "7a8d7d6ecc66c863bc27793df6a5f3efd1ba0661cf3568095b6b9bcf4cb45208",
      "day_status_head": "405b519c7f0ae51d413d26e4ca5bb1fd69786c3eb11a5dbe1f00e2701bd90d26",
      "required_day": "2026-08-31",
      "row_state": "missed",
      "canonical_sequence": 0,
      "canonical_digest": "dd9cdc73c717380a6aa3e1d35edfcafc8ba949eaf7203029b159422330257cdf",
      "occurred_at_kst": "2026-08-31T23:00:00+09:00",
      "customer_identity_digest": "253243ad46f32f8d456514b1c8a8fda4f605dc04874b69b1e3ded72de49c877c",
      "predecessor_row_digest": "0000000000000000000000000000000000000000000000000000000000000000",
      "logical_key": "0fb4a3f228f7fd1c81ad6cdd21cf1be01316bbd405316986a14e49d327e23fa7",
      "reminder_reservation_id": "weekly-reminder-5beb9e3cfe7e156864a1c80e788db4c9c4c92c4e23c3e8790a3c42a5d1ba227a",
      "reminder_audit_id": "schedule-row-44"
    },
    "r71_transaction": {
      "authorization": "CONSUMED/SUCCEEDED",
      "authorization_sha256": "fc242dec4cab503922222377b047503529528c8aa666e38e0c34aaa77e297e19",
      "execution_phase": "COMMITTED",
      "phase_sha256": "4e5ff24c555205b9bfe7417cc02f70c375254065c70d6073a4025faf53b8ec9d",
      "implication": "Original r71 authorization and launcher are one-use and must never be replayed. Repair requires a fresh package digest, authorization root, execution root, and approval phrase."
    },
    "gateway_and_cron": {
      "gateway": "active/running",
      "main_pid": 3376522,
      "nrestarts": 0,
      "cron_job_id": "6e042d5dff68",
      "cron_enabled": true,
      "cron_state": "scheduled",
      "cron_last_run_at": "2026-09-02T01:38:27.117308+09:00",
      "cron_last_status": "ok",
      "cron_last_error": null
    },
    "delivery_zero_change_anchors": {
      "weekly_operations_topic59_sha256": "92ef87536865b4d74c50f9715601de7870c5c3893839f2862dbaf62024e51af5",
      "scheduled_deliveries_sha256": "1000b155ccb56aa318ac098613f5808d2cb9633fc1178a0b49f280c3a23f72a1",
      "scheduled_deliveries_fence_sha256": "e647bdcdd1505e3d978c73d69934c9f04c20159bad4e12ac9d0c93b202442555",
      "assessment": "These still equal the protected post-r71 anchors. This investigation did not run cron, service, observer, transport, or provider actions."
    }
  },
  "row_binding_adjudication": {
    "answer": "ROW_IS_NOT_AUTHORITY_OR_CANDIDATE_BOUND",
    "raw_bytes_semantically_valid_in_empty_r71_history": true,
    "raw_filesystem_copy_supported": false,
    "must_change_row_or_reissue_under_new_candidate": false,
    "must_authenticate_predecessor_provenance_outside_row": true,
    "contract_fields": [
      "schema_version",
      "customer_identity_digest",
      "kst_day",
      "state",
      "canonical_sequence",
      "canonical_digest",
      "source_event_id",
      "source_event_digest",
      "reminder_reservation_id",
      "reminder_audit_id",
      "predecessor_row_digest",
      "occurred_at_kst",
      "logical_key",
      "row_digest"
    ],
    "authority_or_candidate_fields_present": [],
    "pure_reconstruction_probe": {
      "interpreter": "/home/cube/.hermes/profiles/dualcoachtest/.strict-runtime/a41c97c8-v150/venv/bin/python",
      "validated_rows": 1,
      "complete_end": 792,
      "size": 792,
      "source_row_digest": "405b519c7f0ae51d413d26e4ca5bb1fd69786c3eb11a5dbe1f00e2701bd90d26",
      "rebuilt_row_digest": "405b519c7f0ae51d413d26e4ca5bb1fd69786c3eb11a5dbe1f00e2701bd90d26",
      "canonical_bytes_equal": true,
      "network_or_mutation": 0
    },
    "reason_raw_cp_is_rejected": [
      "It bypasses WeeklyOperationsAuthorityRoot.verify and the pinned root/inode capability.",
      "It bypasses locked_sidecar and global authority history validation.",
      "It bypasses append replay/conflict checks and expected FileIdentity replacement detection.",
      "It bypasses per-append fsync and the existing crash-continuation semantics.",
      "It creates no authenticated statement tying r70 authority marker/file hash/head to r71 candidate/root/result head."
    ]
  },
  "supported_surface": {
    "cross_authority_migration_api": null,
    "cross_authority_migration_cli": null,
    "direct_supported_command": null,
    "existing_nearest_primitives": [
      {
        "api": "WeeklyOperationsStore.read()",
        "role": "shared-lock complete validated source history read"
      },
      {
        "api": "WeeklyOperationsStore.append(WeeklyOperationInput)",
        "role": "exclusive-lock validated append or exact durable replay"
      },
      {
        "api": "validate_history_bytes(...) / validate_weekly_rows(...) ",
        "role": "customer filename, KST, canonical pin, logical key, predecessor hash, and row digest validation"
      }
    ],
    "why_append_alone_is_not_a_supported_operator_command": "It accepts an operation, not a verified predecessor authority/history capability; it does not emit a migration receipt; there is no CLI that safely opens both exact authority bindings and invokes it. Hand-written Python against live state would be an unauthenticated ad hoc mutation, not a supported migration."
  },
  "required_minimal_implementation": {
    "scope": "new sealed repair package; no change to row schema",
    "new_module": "dualcoach/profile/checkin_cli/weekly_operations_migration.py",
    "proposed_api": "migrate_predecessor_history(source: WeeklyOperationsStore, destination: WeeklyOperationsStore, *, expected_source_authority_id: AuthorityId, expected_destination_authority_id: AuthorityId) -> WeeklyOperationsMigrationResult",
    "algorithm": [
      "Verify both authority capabilities and exact authority IDs; reject repair-only authorities and same-root identities.",
      "Read and fully validate source through source.read(); read and fully validate destination through destination.read().",
      "Require destination rows to be an exact prefix of source rows. Empty r71 is valid; any divergent or longer destination fails closed without append.",
      "For every source suffix row, reconstruct WeeklyOperationInput from its customer/day/state/canonical/source/reminder/occurred fields and call destination.append().",
      "Require AppendResult.row == the source row for both replayed and newly appended rows. Because predecessor digest and logical key are deterministic, this proves byte-preserving import; fail if any row would be reissued differently.",
      "After all rows, require destination.read() == source rows and record source/destination heads and complete-file hashes.",
      "Write an authenticated migration receipt in the fresh repair execution root, not inside either authority root. Bind package digest, source/destination authority IDs, marker/binding digests, customer storage digest, source file SHA/head/count, destination before SHA/head/count, destination after SHA/head/count, and receipt predecessor/digest.",
      "Advance the fresh phase journal only after the receipt is fsynced. A retry after interruption repeats prefix checks, replays committed rows, appends only the missing suffix, and emits one terminal receipt."
    ],
    "integration_for_future_rotations": {
      "file": "scripts/nutricoach_v150_host_operations.py",
      "placement": "inside apply_migrations after build/register of the fresh weekly authority and before migration_apply returns",
      "controller_phase": "before journal.advance(\"MIGRATED\") and before weekly_startup_smoke",
      "reason": "The original r71 sequence registered a new authority at migration_apply, advanced MIGRATED, then startup smoke initialized an empty sidecar. Import must be part of the rollback-covered migration, not a postcommit repair."
    },
    "current_r71_repair_packaging": {
      "required": true,
      "reason": "r71 is already COMMITTED and its one-use authorization is consumed; immutable original controller/source cannot be edited or replayed.",
      "transaction_shape": [
        "fresh one-use authorization and phase journal",
        "preflight exact r70/r71 marker, registration, sidecar, config, receipt, observer-chain, and delivery-ledger hashes",
        "prevent provider-capable runtime and observer execution during import",
        "run importer in a network-unshared process",
        "verify imported target and unchanged source/protected delivery hashes",
        "restart only through an authorized zero-send startup/cron fence",
        "create a fresh observer namespace; preserve observer-r71 byte-for-byte"
      ]
    }
  },
  "append_only_idempotency_crash_and_one_use": {
    "append_only": "Destination uses O_APPEND, validates predecessor_row_digest and full history before every append, then fsyncs. Source r70 is read-only and never rewritten. No truncation, replacement, merge, chmod, or repair-tail operation is permitted.",
    "idempotency": "WeeklyOperationsStore.append returns appended=false for exact operation replay. The importer adds the stronger exact-prefix and returned-row-equality checks, so repeat invocation cannot duplicate or reinterpret history.",
    "crash_safety": "Each completed row is durable before the next. On restart, exact-prefix detection resumes from the first missing source row. Torn destination tails remain fail-closed and require the separately authorized repair capability; the importer must not auto-truncate.",
    "concurrency": "The store lock serializes destination writers, but observer code reads JSONL without taking that lock. Therefore the authorized repair must prevent observer execution during import and must not rely only on the sidecar lock.",
    "one_use": "Do not reuse original r71. A fresh GlobalLedger/package digest must reserve once, consume SUCCEEDED/FAILED once, and preserve partial roots after failure. A failed attempt requires a new generation, not approval replay.",
    "rollback": "Before terminal receipt/commit, rollback may remove only rows/root created by the new repair transaction if it can restore the exact authenticated preimage. Since r71 sidecar already exists empty and row appends are not safely truncatable under the normal API, the safer design is roll-forward prefix recovery under the one-use phase journal rather than raw rollback."
  },
  "required_tests": [
    "Empty destination imports the authenticated one-row source and produces byte-identical payload/head.",
    "Destination exact prefix resumes after an injected crash between rows; one rerun appends only the suffix and ends byte-identical.",
    "Fully imported destination rerun is a no-op and emits no duplicate row or duplicate terminal receipt.",
    "Divergent destination row, longer destination, wrong customer, wrong source/destination authority ID, swapped roots, tampered source row, torn source/destination tail, replaced inode, symlink, mode/link/owner drift all fail before mutation.",
    "Authority/candidate rotation does not alter imported WeeklyOperationRow bytes, while the separate receipt binds predecessor and successor authority provenance.",
    "Concurrent destination writer is serialized; exact source equality is rechecked after lock acquisition.",
    "SIGTERM/SIGINT and fsync/write fault matrix proves committed-prefix recovery without timing sleeps or polling.",
    "Sealed controller test proves import occurs before MIGRATED/startup smoke and rollback/recovery phases preserve one-use semantics.",
    "Installed-wheel, network-unshared test uses a socket guard and fake transport to prove AF_INET/AF_INET6 attempts=0, provider sends=0, provider updates=0, Topic59/scheduled-delivery hashes unchanged.",
    "Observer regression uses a new output namespace, imports before observer start, gets first manual/natural PASS from the configured r71 root, and preserves failed observer-r71 unchanged."
  ],
  "zero_send_proof_contract": {
    "static": "weekly_operations.py, weekly_operations_store.py, weekly_operations_history.py, and weekly_operations_fs.py import filesystem/validation primitives only and contain no Telegram/provider/network call. The proposed importer must depend only on those modules.",
    "runtime_required_for_authorization": [
      "gateway inactive with MainPID=0 and no provider-capable worker/controller process before import",
      "observer timer prevented from firing and observer service inactive before import",
      "import process launched with network namespace unshared plus AF_INET/AF_INET6 socket guard",
      "no cron run/tick or observer invocation used as the migration command",
      "pre/post exact hashes for weekly-operations-topic59.jsonl, scheduled-deliveries.jsonl, scheduled-deliveries-fence.json, customer events/bindings/drafts",
      "provider transport callback counters remain zero",
      "only expected target sidecar append and fresh execution/receipt artifacts differ"
    ],
    "current_investigation": {
      "service_actions": 0,
      "timer_actions": 0,
      "cron_actions": 0,
      "observer_actions": 0,
      "provider_sends": 0,
      "provider_updates": 0,
      "network_actions": 0,
      "live_profile_mutations": 0
    }
  },
  "observer_predicate_and_chain": {
    "predicate": "At or after 2026-08-31T23:05:00+09:00, first_day_status fails iff date(2026, 8, 31) is absent from day_status_days collected from config weekly_operations_authority_path.",
    "collector": "The fixed collector parses config.yaml, selects the configured authority root, and unions kst_day from *.day-status-v1.jsonl.",
    "current_chain": {
      "path": "/home/cube/.hermes/migrations/nutricoach-v1.5.0-combined/observer-r71/observations.jsonl",
      "mode": "0600",
      "rows": 2,
      "sha256": "8125016c922ae65f91096ef9471160eabb25f3f4fbaa5aeae344f9014d1186bc",
      "hash_chain_valid": true,
      "head": "11a627d5cb11656ad2960d0c6824a14cce3d06761ce1d6c430ac8c74176daef5",
      "row_1": "2026-09-02T01:27:33.948593+09:00 FAIL:first_day_status",
      "row_2": "2026-09-02T01:30:26.485430+09:00 FAIL:first_day_status"
    },
    "timer_read_only_snapshot": {
      "unit": "nutricoach-v15-seven-day-observer.timer",
      "active_state": "active",
      "sub_state": "waiting",
      "unit_file_state": "enabled",
      "last_trigger": "2026-09-02T01:30:26+09:00",
      "next_elapse_at_capture": "2026-09-02T01:40:00+09:00",
      "timer_sha256": "098fb18c1302d5e48df8b708954b8c4d5ed7b53425f19c371a44bb7f9eec8e0e",
      "service_sha256": "acdac5b18ab36a8e4a02c07f54694b82671e69c071a5e8338822d61fb9c9b97a",
      "checksum_manifest_sha256": "67b311f3bd139733f74f0669bea3656a7e4db43474d14848f6aa644941f3479b"
    },
    "irreversibility": "observer_final.final_verdict appends failed_observation if any in-window row is not PASS. It also requires first coverage no later than WINDOW_START plus 20 minutes; this chain began on Sep 2. Importing the row can make later predicate evaluations pass but cannot make observer-r71 a valid seven-day PASS. Preserve it; use a newly authorized observer namespace and explicitly adjudicated window."
  },
  "code_map": [
    {
      "path": "dualcoach/profile/checkin_cli/weekly_operations.py",
      "lines": "103-156,183-198",
      "symbols": ["WeeklyOperationInput", "WeeklyOperationRow", "operation_logical_key", "canonical_weekly_row", "weekly_row_digest"],
      "sha256": "a1119f4c692e78d99ede8307ed3b9a79b46295b4fcb5b67a03caf6ee53b172c3",
      "finding": "Row schema and hashes contain customer/canonical lineage but no authority/candidate binding."
    },
    {
      "path": "dualcoach/profile/checkin_cli/weekly_operations_store.py",
      "lines": "76-93,127-192,194-216,253-266",
      "symbols": ["_append_private", "WeeklyOperationsStore.append", "_append_locked", "read", "ensure_initialized", "_matches", "_logical_key"],
      "sha256": "18b88ea62552fc5e9e8f319b354c650002c9e722cd328f843b540fa098f60a3f",
      "finding": "Existing lock/append/fsync/replay primitive is sufficient as the import engine but does not authenticate a predecessor migration."
    },
    {
      "path": "dualcoach/profile/checkin_cli/weekly_operations_history.py",
      "lines": "66-114",
      "symbols": ["validate_weekly_rows", "validate_history_bytes"],
      "sha256": "7a04ec2d513b780c22964ecb482386bc676b24b961d74735e62c11e22e47eab4",
      "finding": "Validates filename/customer, KST, canonical monotonicity, logical keys, predecessor chain, and row digests independently of authority ID."
    },
    {
      "path": "dualcoach/profile/checkin_cli/weekly_operations_authority_access.py",
      "lines": "28-30,72-81",
      "symbols": ["WeeklyOperationsMigrationRequired", "discover_legacy_sidecars"],
      "sha256": "efba7692b048055e3223f428cf32a409598fda23cbbad8fc4da6d14ee1ef3a9b",
      "finding": "Only legacy discovery exists and deliberately raises migration_required; no implementation follows."
    },
    {
      "path": "scripts/nutricoach_v150_weekly_authority.py",
      "lines": "47-53,148-186,188-258",
      "symbols": ["weekly_authority_path", "_register_authority", "build_weekly_authority_postimage"],
      "sha256": "c5b39a441eca66d446efb5ea7620ad1967b30f90e40c46e6f9abbbad9d41ac2e",
      "finding": "Rotation intentionally selects a candidate-suffixed fresh root and registers customers, but never carries sidecar history."
    },
    {
      "path": "scripts/nutricoach_v150_host_operations.py",
      "lines": "73-112",
      "symbols": ["apply_migrations"],
      "sha256": "bb149748f71dd684bcae515b6c29a356b24d26248640272df0d06a83f4fa2528",
      "finding": "Migration applies registry/config/authority initialization only; this is the minimal future integration site."
    },
    {
      "path": "scripts/nutricoach_v150_concrete_host.py",
      "lines": "621-659",
      "symbols": ["migration_dry_run", "migration_apply", "weekly_startup_smoke"],
      "sha256": "537d4636124017703010a17cce7773b4f5aace25f5e207f7b41f02e8419a66fe",
      "finding": "Original r71 omitted state transfer between authority creation and startup smoke."
    },
    {
      "path": "scripts/nutricoach_v150_sealed_controller.py",
      "lines": "166-209,213-235",
      "symbols": ["_execute", "recover_pending"],
      "sha256": "91f282ebe2bfcd6d4986001f0f4fffea09cbc08ee8c8fa50eace936baf46e58e",
      "finding": "One-use ledger and rollback phases exist, but original immutable/consumed r71 cannot be extended postcommit."
    },
    {
      "path": "scripts/nutricoach_v150_observer_runtime.py",
      "lines": "152-171,206",
      "sha256": "fa9c29f271e0d0bcc3f51d76721b3370af25c456104db3da1c0d6c8fef734f2e",
      "finding": "Current deployed observer collector correctly selects the configured authority root."
    },
    {
      "path": "scripts/nutricoach_v150_observer_contract.py",
      "lines": "12,64-65",
      "sha256": "9cc44ea117490aa8cbd7eb8c3ff02b0dcff40dbaf9893d7de5ed80dad579bea5",
      "finding": "first_day_status is date-membership only; state/candidate are not inspected."
    },
    {
      "path": "scripts/nutricoach_v150_observer_final.py",
      "lines": "27-48",
      "sha256": "7f818e0b643155fc3705adba6dc2f2785f92d216f52e56b18276b0cec81b9475",
      "finding": "Any failed observation and missing start/end coverage permanently deny final PASS."
    }
  ],
  "existing_test_map": [
    {
      "path": "dualcoach/profile/tests/test_weekly_operations.py",
      "sha256": "36b2f59e887689ffbb6da8a726186d68732719c7bc2eb85735a282919d0a51c9",
      "coverage": "deterministic append/replay, durable empty initialization, concurrent serialization, torn-tail explicit repair, interior corruption fail-closed"
    },
    {
      "path": "dualcoach/profile/tests/test_weekly_operations_authority.py",
      "sha256": "56880c77b157b5f41be7e96421ba63406081339d123cc75d369f2f5ceea0f568",
      "coverage": "legacy migration-required sentinel, authority path/capability integrity, initialized-root refusal, digest/history mismatch"
    },
    {
      "path": "dualcoach/profile/tests/test_weekly_operations_commit_outcome.py",
      "sha256": "441bd0bd41159936a7bd64ba2f9fc22ccc9d072cdb349116efecd13565a333ff",
      "coverage": "signal and directory-fsync commit/handoff boundaries"
    },
    {
      "path": "dualcoach/profile/tests/test_weekly_operations_global_history.py",
      "sha256": "cb5719f7333fee6cb7aeb9baada85f14c9d97c8787c3a866b1169b236c17248c",
      "coverage": "forged logical/predecessor/canonical/source/filename history blocks mutation globally"
    },
    {
      "path": "tests/test_nutricoach_v150_weekly_authority.py",
      "coverage": "successor receives a fresh root and startup authority, but has no history-continuity assertion"
    },
    {
      "path": "tests/test_nutricoach_v150_seven_day_observer.py",
      "sha256": "466805e6c85fcd3bdb510a0af07d562360732da90c5853d38e65f24a5d6a0480",
      "coverage": "configured-root selection and first-day date predicate; lacks authority-rotation migration integration"
    }
  ],
  "evidence_anchors": {
    "task_11_observer_r71": {
      "path": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-telegram-checkin-stepper/task-11-observer-r71.json",
      "sha256": "64b3eeee5d3b1621b7cd5e258c1a2c8fcf28274b0d8aca41c0e459635e085f85"
    },
    "task_10_r71_production": {
      "path": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-telegram-checkin-stepper/task-10-r71-production.json",
      "sha256": "a34a44aca67772f894cfac6f081f28c5a1f5e8ef43974216702dc434c12f84eb"
    },
    "task_10_r71_adversarial_final": {
      "path": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-telegram-checkin-stepper/task-10-r71-production-adversarial-final.json",
      "sha256": "0b5ea436a4a6cfbc7a82ca8d4d4d524c54c82fb3e36aafcec633bfa90dbe1842"
    },
    "r71_package": {
      "candidate_digest": "a41c97c8a467b0308b9f50ac072cc3adae1c2d47ca515b76f123e7c1debee9be",
      "package_digest": "4b032722f236dacc7f7e413cc37b31232000ce4f5d839bf0360fa8ac008ea6b1",
      "package_manifest_sha256": "66ede3f1995d644b9ce423c8e8846b50d823c57f76d892cef66694d7e1d3a793",
      "sealed_target_sha256": "b9f0cb2694ea0dcc49af7b0355fa491b3c74452c0f74ebc6c17f0b7c7b183c79",
      "controller_source_manifest_sha256": "0a4ad503db2f26aba4e050071fbc725f2ef0e6bd9216a6869d7123acf2047c8b"
    }
  },
  "recommendation": {
    "decision": "IMPLEMENT_AND_SEAL_PREFIX_PRESERVING_PREDECESSOR_HISTORY_IMPORT; DO_NOT_COPY_RAW_BYTES LIVE; DO_NOT REPLAY R71",
    "priority": "block Todo11 completion until a fresh repair package and new observer window exist",
    "exact_next_engineering_change": "Add weekly_operations_migration.py and its tests, call it from the rollback-covered migration immediately after fresh authority registration and before MIGRATED/startup smoke, then package the already-committed r71 repair as a new one-use generation with an execution-root provenance receipt and zero-network stop/fence orchestration.",
    "not_required": [
      "customer input",
      "provider send/update",
      "new synthetic day-status state",
      "row schema change",
      "candidate-specific row digest",
      "mutation of predecessor r70 history"
    ],
    "forbidden": [
      "cp, install, dd, write_bytes, shell redirection, or manual JSON append into the live r71 sidecar",
      "editing/truncating/replacing either canonical-authorities-v1.jsonl",
      "changing the r70 source row or claiming it belongs to r71 without a provenance receipt",
      "reusing original r71 approval/launcher/authorization",
      "deleting or rewriting observer-r71 failed rows",
      "running the old observer chain after migration and calling the seven-day result PASS",
      "using cron, Telegram, customer input, or provider I/O to manufacture the missing historical day"
    ]
  },
  "effects": {
    "source_edits": 0,
    "live_profile_edits": 0,
    "service_actions": 0,
    "timer_actions": 0,
    "cron_actions": 0,
    "network_customer_provider_actions": 0,
    "git_actions": 0,
    "only_persistent_write": "/home/cube/projects/richard/traning coach/.omo/evidence/nutricoach-telegram-checkin-stepper/task-11-day-status-migration-codemap.json"
  }
}
