{
  "schema": "task26-hands-on-final-pid-successor-v1",
  "status": "PASS",
  "task": "Task26 hands-on QA review",
  "candidate": {
    "full_digest": "653cc2f0b47873e95f985ea3eb32b8f2c044d6de64cd9e8fe37ebcec67c7a723",
    "core_digest": "a03f84f7db67afe0ace8d31541dd373852af052fbb1a23a8e70dd96c6263f5ef",
    "predecessor_full_digest": "3b42723d0e8256351defdf31958f9ade795f80a7be456529740949c87875d527",
    "manifest_sha256": "23b72148af7412b292555107c6b29616d9436c437871787763667c9fb62fca26",
    "checkpoint_sha256": "6acc31bdf597dfb51151fb4c2cd76cb7da2ceb33579a8cd840490fbbfdbbd4be",
    "wheel_sha256": "af4a9d0a1ffffb6eb7551c1d6dc2b32853ca6d024332a4f8f5702bbf992f141b",
    "pre_post_verifier_output_sha256": "fcc099ec0bb56f35af27f30e07c2d25fc1f1348cff8b0f7483ae8c7be6f0471c",
    "pre_post_identical": true,
    "immutable_verifier_status": "PASS"
  },
  "scope": {
    "current_executable_delta": {
      "path": "gateway/status.py",
      "before_sha256": "7a04d81facfd29360a096c1233d2afd015e1933c223adcbf7946c087ca9c5115",
      "after_sha256": "8641bae4540dcadec0f80a3d97b1a1013ab36f3cb1b4920027d70cae1d1d308c",
      "delta_sha256": "f3820c5f2dc5ec7170b53966bb3f84e71865f69252711128c98de92658a71355"
    },
    "production_handler_linkage": {
      "source_root": "/home/cube/projects/richard/hermes-agent",
      "executable_closure_entry_count": 2374,
      "gateway_status_source_and_wheel_sha256": "8641bae4540dcadec0f80a3d97b1a1013ab36f3cb1b4920027d70cae1d1d308c",
      "controller_source_and_wheel_sha256": "b303634599c17e2f35339f964b2277c1a236f42c0ad5f3e4be18d3f38e556e13",
      "status_test_source_sha256": "1976b3530484b105704fdf2bcf1c6302ec7416fcec33f675e515177ef7447c5d",
      "controller_test_source_sha256": "95300eb8243d88af01d0e1167390ab1c30d900fed34bad44f44f2e1aca65bcdf",
      "result": "PASS"
    }
  },
  "scenarios": [
    {
      "priority": "P0",
      "name": "untrusted live non-gateway PID is fail-closed",
      "production_surface": "gateway.status.get_running_pid",
      "coverage": "legacy PID record naming the test process is rejected and preserved; planned-stop fallback accepts only self when start time is unavailable, rejects a foreign PID, and rejects a known start-time mismatch",
      "result": "PASS in isolated source and sealed-wheel lanes"
    },
    {
      "priority": "P1",
      "name": "Tasks21-25 controller fails closed before operational work",
      "production_surface": "gateway.platforms.dualcoach_tasks21_25_controller",
      "coverage": "all controller tests cover arm prerequisites, repository binding, durable owner-review recovery, candidate deployment binding, and explicit-start behavior; installed sealed-wheel CLI with a private invalid receipt returned NO_GO/arm_receipt_invalid",
      "safe_cli": {
        "exit_code": 1,
        "stdout_sha256": "346acf44a62f7e0ffa77b5683f905fed614d4c3ff7d53bfea7e7b639329fc831",
        "stderr_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
      },
      "result": "PASS"
    },
    {
      "priority": "P2",
      "name": "runtime-health rendering and retained rehearsal provenance",
      "production_surface": "hermes_cli.gateway runtime-health plus retained Task22-25 evidence/archive bindings",
      "coverage": "four runtime-health/PID-status tests passed in each lane; Task22-25 index and referenced-evidence hashes/modes, terminal exactly-once evidence, Task25 terminal-cleanup evidence, and archive manifest/receipt/scope binding were recomputed read-only",
      "result": "PASS; historical provenance only"
    }
  ],
  "offline_execution": {
    "source_lane": {
      "command": "pytest -q -p no:cacheprovider selected controller, PID, planned-stop, and runtime-health nodes",
      "result": "19 passed in 0.20s",
      "tests": 19,
      "failures": 0,
      "errors": 0,
      "skipped": 0
    },
    "sealed_wheel_lane": {
      "install": "pip install --no-index --no-deps --no-cache-dir --ignore-installed --target <disposable> hermes_agent-0.17.0-py3-none-any.whl",
      "result": "19 passed in 0.20s",
      "tests": 19,
      "failures": 0,
      "errors": 0,
      "skipped": 0,
      "disposable_junit_sha256": "da6fd7b30d2c7707a70f88078f6810fb5a5de5614b1e4cf090ed82a8766fa7e8"
    },
    "isolation": {
      "network": "bwrap --unshare-net",
      "filesystem": "read-only host root; only disposable bind work tree writable",
      "home_and_profile": "private tmpfs",
      "bytecode": "disabled",
      "pytest_cache": "private tmpfs with cache provider disabled",
      "package_install": "offline, no index, no dependencies"
    },
    "setup_abort_note": "Four preparation/configuration aborts occurred before test collection or execution (sandbox path mount, hidden temp script, copied-test pytest configuration, and copied-test path); they performed no scenario action. The two recorded source/wheel lanes above are the sole substantive executions and are conclusive."
  },
  "historical_task22_25_validation": {
    "classification": "compatibility and provenance only; not execution against this successor",
    "historical_execution_retargeted_to_successor": false,
    "reconciliation_indexes_sha256": "419511b6fadb7920e155dcd5b57d20661d750a989ef0912e9ddf1bfbc0cb0abe",
    "indexes": {
      "task22": {
        "sha256": "cc4ac1264d947226f0e2ebfdd2f3845781d48ab298a71ae96c09517eecb26309",
        "mode": "0600",
        "referenced_hashed_artifacts_verified": 3
      },
      "task23": {
        "sha256": "86b72c4c21b9f1113cb34e81b293e93ed7df7ac1388d3d1b31d9dc01dca3987a",
        "mode": "0600",
        "referenced_hashed_artifacts_verified": 13,
        "evidence": "one owner authorization consumption, one provider call, zero duplicate child appends/provider calls, one owner-review card"
      },
      "task24": {
        "sha256": "4df0f8712887f2125e100ba8d7585914b7b8810a298c37f9a32584b31fabe04d",
        "mode": "0600",
        "referenced_hashed_artifacts_verified": 7,
        "evidence": "one synthetic customer send and audited receipt, one accepted owner ingress, zero duplicate customer delivery, zero terminal replay sends or durable mutations"
      },
      "task25": {
        "sha256": "c3c40ff9406dbb2609ee7ef89be2fdc20fa139064b5d65e494c6efc8b2a80ed2",
        "mode": "0600",
        "referenced_hashed_artifacts_verified": 5,
        "evidence": "delivery disabled, empty enabled-customer list, inactive/dead gateway, absent delivery ledger, zero profile processes/jobs, Task24 terminal receipt preserved"
      }
    },
    "archive": {
      "id": "2009ac177177839cefddb98f285e27fa",
      "manifest_sha256": "ca4811444e114a06749620b9a44e05c8bd62bc3223ec80b1b5740c832c4a84c1",
      "receipt_sha256": "e81a84a8584400401f83aace36283dee18660144ede11e854758e725796e7fb3",
      "canonical_digest": "644d74b05bc8115f9e3aeeba035188da195a7de18f1bc737648931d64bf43bcf",
      "scope_count": 23,
      "scope_digest_sha256": "86478968ecb0caee9f96f6814e8fd291be9397d49f403fcb2aafe8e92a6ff102"
    },
    "compatibility_assessment": "The successor's sole executable-source change is gateway/status.py. Task22-25 historical receipts are hash-bound to the immutable successor as retained provenance, but are explicitly not retargeted as successor execution. Therefore no live/profile/Telegram/provider/customer/archive rerun is required or authorized for this PID/controller-only QA scope."
  },
  "drift_and_cleanup": {
    "candidate_tree_drift": false,
    "candidate_verifier_pre_post_identical": true,
    "current_relevant_source_and_wheel_pin_drift": false,
    "historical_index_hash_or_mode_mismatches": 0,
    "disposable_roots_removed": true,
    "candidate_or_source_edits": 0,
    "live_profile_mutations": 0,
    "service_lifecycle_actions": 0,
    "archive_mutations": 0,
    "telegram_actions": 0,
    "provider_actions": 0,
    "customer_actions": 0,
    "git_mutations": 0
  },
  "verdict_scope": "Hands-on offline QA PASS only. This receipt grants no release, activation, service start, or live operational authority.",
  "privacy": "Redacted: no credentials, customer prose, raw model output, callback payloads, route identifiers, or live profile contents retained."
}
