{
  "schema": "dualcoach-task26-provenance-reseal-deferred-plan-v3",
  "recorded_at_utc": "2026-08-14T08:31:45Z",
  "verdict": "NO-GO",
  "state": "DEFERRED_C3B1_SUPERSEDED_SECURITY_FAIL",
  "predecessor": {
    "path": ".omo/evidence/task26/provenance-reseal-deferred-plan-v2.redacted.json",
    "classification": "retained immutable deferment and inventory record; this successor records the final security re-audit outcome without rewriting any prior plan or historical receipt"
  },
  "scope": "Task26 provenance hold only. No authoritative candidate graph, whole-worktree manifest, freeze receipt, release binding, Task27 action, service, profile, Telegram, provider, delivery, commit, push, reset, stash, or clean action was performed.",
  "superseded_candidate": {
    "digest": "c3b1ea6877bc1a2ecc510de70610552fd397e13a73719df4bb82a943f2373f95",
    "classification": "non-authoritative and superseded for Task26 release provenance",
    "readiness_checkpoint": ".omo/evidence/task26/task26-owner-v1-readiness-checkpoint.redacted.json",
    "security_reaudit": {
      "path": ".omo/evidence/task26/task26-owner-v1-final-security-privacy-reaudit.redacted.json",
      "sha256": "09caa96a9b9e832048b5c17ccc107951173cfc15d70537b1420007ec26221958",
      "mode": "0600",
      "status": "SECURITY_REPAIR_FAIL"
    },
    "observed_post_checkpoint_status_drift": {
      "checkpoint": {"sha256": "75143e9a12d16bc07d0d28e6552e7cc63238b182e75ccd502319bfbcbba2399f", "bytes": 10720, "entries": 212},
      "observed": {"sha256": "59a59ffa8349bfe8a97711622263ff67ffcb21f291e71b4bd09e53cc73c49891", "bytes": 10767, "entries": 213},
      "added_unbound_path": "owner_v1/fixtures/preclean/.state.json.lock",
      "handling": "preserved without deletion; any future candidate must explicitly exclude this runtime cache before execution or bind it as a verified input"
    }
  },
  "preserved_security_blockers": [
    {
      "code": "UNBOUND_EXECUTABLE_INPUTS",
      "paths": ["scripts/reproducible-wheel-build", "tests/test_owner_v1_candidate_seal.py"],
      "required_repair": "Bind every build executable and verification test to the next candidate graph and checkpoint."
    },
    {
      "code": "UNBOUND_RUNTIME_BYTECODE",
      "detail": "Four source-package bytecode cache leaves can participate in source-based bwrap execution without candidate binding.",
      "required_repair": "Eliminate cache participation from the execution path or include every executable cache under a deterministic sealed policy; verify this before the next snapshot."
    },
    {
      "code": "SYNTHETIC_HANDLER_COUNTS",
      "detail": "The bwrap card, acknowledgement, staff-send, draft, and review-card counts are test-local counters rather than production-handler outcomes.",
      "required_repair": "Run a candidate-bound real-handler matrix whose observed counts originate in production handler effects."
    },
    {
      "code": "FIXTURE_DERIVATION_NOT_EXECUTABLE",
      "detail": "The fixture embeds successor metadata but is not a deterministic projection of authenticated successor records.",
      "required_repair": "Make the fixture builder consume the authenticated successor records and retain a deterministic source-record to destination-record mapping."
    }
  ],
  "new_seal_preconditions": [
    "A new private security re-audit reports SECURITY_REPAIR_PASS after closing all four preserved blockers.",
    "Quality reports READY_FOR_CANDIDATE_RESEAL with a green exact input/build/test inventory.",
    "The trainer-free checkpoint reports READY_FOR_TASK26_SECURITY_READONLY_REAUDIT and every input it names is a private regular file with matching hash and mode.",
    "A new NUL-framed Git-status snapshot is stable before and after all candidate leaf, wheel, fixture, source/member, and evidence capture. No prior snapshot or candidate may be amended in place.",
    "Task22-25 and adverse Task24 records are retained by hash but classified historical unless the relevant behaviors are rerun on the new candidate."
  ],
  "fail_closed_rules": [
    "The c3b1 manifest and readiness checkpoint remain retained evidence only; neither may be promoted, re-signed, or used for Task27.",
    "Do not delete the observed fixture lock or use Git clean/reset to restore an old snapshot; source drift is evidence, not cleanup authorization.",
    "No authoritative candidate graph or final provenance PASS receipt exists for c3b1.",
    "Any failed checkpoint, unbound executable/cache, non-production counter, non-executable fixture derivation, source drift, missing reviewer receipt, or historical-only lifecycle proof remains NO-GO."
  ],
  "redaction": "No customer content, model output, credentials, raw route identifiers, or live profile payloads are included.",
  "mode_required": "0600"
}
