# DualCoach v1.1.0 local release verdict

## Verdict

**GO for a locally frozen v1.1.0 artifact. Deployment and customer upgrade are
not authorized by this verdict.**

The successor remains restricted to the existing one-customer bounded-pilot
contract. A future deployment requires a separate stopped-gateway preflight,
explicit owner approval, migration/snapshot checks, and a fresh onboarding
link bound to this candidate.

## Product identity

- Candidate:
  `0e383539aea1b83205771772f1e8b417840defe60f5ea6ce184f80e3af8d25f9`
- Product binding:
  `178ce0ce9a2ea0b76af8e5ef7fcba2340c4a266388a23da5769642bc550f97f2`
- Source commit:
  `ae90902686a66fd6b66dfacba0f373a8011a594a`
- Source tree:
  `7a559fb85dc12a3918e9435e06d97834165ef79b`
- Hermes wheel:
  `ec160d3d0e29bc747f463923d31bfe736aefb5840a3d32fcb04842aa5139ddb0`
- Profile wheel:
  `a56da2417df0912f3fe407c0b78befd7362207d1c8a35271000af46701ba79d2`

The complete product candidate changes only the Hermes wheel derivation input.
Every other canonical input remains identical to v1.0.0.

## User-visible change

- An unclaimed onboarding invite remains valid for exactly 24 hours.
- It remains private-DM-only.
- It is valid immediately before the 24-hour boundary.
- It expires exactly at the boundary.
- A successful claim transitions to `REGISTERING`.
- Replay, wrong-chat use, malformed input, and post-expiry use fail closed.

The two Hermes wheels have the same ordered 992-member inventory. The only
changed members are the bootstrap TTL module and wheel `RECORD`.

## Qualification

- Two isolated detached source-root builds produced byte-identical
  8,511,601-byte wheels with the successor Hermes hash.
- TTL boundary tests: 2 passed.
- Bootstrap regressions: 6 passed.
- Focused Task26: 306 passed.
- Expanded Task26: 76 passed.
- Full Gateway reliable rerun: 8,552 passed, 0 failed.
- Serial timeout recheck: 225 passed.
- Ruff, Ty, and compile gates: PASS.
- Candidate verifier tests: 4 passed.
- Source Golden Path: `ACTUAL_SOURCE_GOLDEN_PATH_PASS`.
- Installed Golden Path: `ACTUAL_INSTALLED_GOLDEN_PATH_PASS`.
- A separately executable offline installed replay harness reproduced
  `ACTUAL_INSTALLED_GOLDEN_PATH_PASS`.

The initial 24-worker stress run encountered two internal timeouts and one
140-second file ceiling. The same files passed serially, and the full
8-worker rerun passed with a 600-second per-file ceiling. This remains
disclosed as a low residual timing risk.

## Authority and rollback

The append-only release authority resolves uniquely to the v1.1 candidate:

- Registry head:
  `b18f72e6773c2c6e16a188dfe6f6b8333c2e480c345c234a25b7e5fe8aabca23`
- Ledger head:
  `e4c2a6a84ecb23f92cdbbb493ba1e58a175acde72f950ba8157e71802466c4ba`

The v1 candidate remains qualified and non-revoked as the rollback artifact.
No v1 receipt was relabeled as v1.1 evidence.

## Independent reviews

- F1 objective and invariants: PASS.
- F2 privacy and authority: PASS.
- F3 reliability and exactly-once: PASS.
- F4 real surface:
  `PASS_PRESERVED_BASE_REAL_SURFACE_PLUS_V1_1_OFFLINE_PARITY`.
- F5 provenance and cleanup: `PASS_PENDING_FINAL_SEAL` before the terminal
  inventory/tag spot-check.

The inherited real Telegram proof belongs to immutable v1 base evidence only.
No external Telegram execution is claimed for v1.1. Fresh v1.1 evidence is
installed-wheel, offline, local-loopback parity.

## Live terminal state

- Gateway service: inactive/dead, PID 0.
- Pilot customer: disabled.
- AI-processing consent: withdrawn.
- Customer delivery: disabled.
- Customer, bootstrap, publication-outbox, and staff-membership operational
  roots: absent.

## Constraints and residual risks

- No push, PR, release publication, deployment, service start, Telegram or
  provider action, customer activation, delivery, or live-profile mutation
  occurred.
- The 24-hour TTL deliberately increases pre-claim bearer-token exposure and
  local pending-draft lifetime relative to v1.
- Evidence is locally hash- and Git-bound, not externally signed or WORM.
- Git stores an exact content mirror but does not claim the original sealed
  `0400/0500` filesystem modes.
