{
 "schema": "task26-runbook-binding-receipt-v2",
 "recorded_at": "2026-08-15T12:50:00Z",
 "version": "v2",
 "bindings": {
  "candidate_full_digest": "2e0894eac92bc396cc4723bf1f18ebc653b95018dd41574df435941c235da925",
  "wheel_sha256": "af4a9d0a1ffffb6eb7551c1d6dc2b32853ca6d024332a4f8f5702bbf992f141b",
  "amended_plan_sha256": "7ace03c6dad33d2fc3ef223621cbca68a150fde8429932138e252fb8498ac582",
  "actor_id": "8527916639"
 },
 "supersedes": {
  "v1_runbooks": [
   {"path": ".omo/evidence/task26/task26-runbook-rebind-2e0894ea-st_01a0054e/task26-golden-path-2e0894ea.md", "sha256": "1f55b8f967c6564113574d41bf1c15ce977d35c38b5687f1623ba37f235a7bdb"},
   {"path": ".omo/evidence/task26/task26-runbook-rebind-2e0894ea-st_01a0054e/task26-recovery-runbook-2e0894ea.md", "sha256": "f4f2d2347b4b68a080b9c437a813accbef8c4bcc471cbf21d67ffff31e56f89b"}
  ],
  "original_runbooks": [
   {"path": ".omo/evidence/dualcoach-golden-path-contract.md", "sha256": "32a379d855c6e5af978bd9886e3bf49c616c7c20f1c1d5f100c19d8adfc5eb4a"},
   {"path": ".omo/evidence/dualcoach-recovery-runbook.md", "sha256": "ae2f5f9046c06f8f0b42693be5aa0d9c31cada8024ae1e5ab8ba19a3cf10f6fc"}
  ],
  "prior_binding_receipt": {"path": ".omo/evidence/task26/task26-runbook-rebind-2e0894ea-st_01a0054e/runbook-binding-receipt.json", "note": "v1 receipt preserved byte-identical; this v2 receipt is the current binding"},
  "policy": "append-only; all four prior runbook files and the v1 receipt remain byte-identical (recomputed and lint-verified)"
 },
 "v2_fixes": {
  "G8_section2_deadlock": "fixed: pre-reset G8 requires no active lock holder and schedules the authenticated stale gateway.lock for disposal inside the sealed reset approved_clear_scopes; post-reset G15 requires gateway.lock absent; hand removal forbidden everywhere",
  "ledger_authority_path": "fixed: same-actor-live-rehearsal-authorized is cited from .omo/start-work/ledger.jsonl (the plan/authorization ledger), not the profile customer-bootstrap ledger",
  "reset_interface": "fixed: exact sealed command from reset-controller-st_01a0054d (controller bd051dda, contract 4128cece, permission 8a290b11, dry-run 2fc323f8, readiness 776e9030); actual --archive-root semantics (new archive at data/profile-reset-archives/<run-id> via .pending rename; prior archives read from data/rehearsal-reset-archives and the archive root); --approval is the literal phrase; mode order dry-run then execute then verify; execute preconditions enumerated from source",
  "candidate_verifier_invocation": "fixed: verify_candidate.py takes the sealed verifier-input.json (cd9e080a) as its positional argument; exit 0 with status PASS; the v1 exit-2 claim was wrong",
  "B2": "closed",
  "B5": "closed (verifier 12b97aa7, inventory 29db87f2, seal 28ff72fd, receipt 597a37e4 PASS over 5 archives / 4 schemas; sealed tests 1b92ac72 pass 14/14; LSP diagnostics clean)",
  "B3": "open (billable active provider probe still awaits written human authorization)",
  "G12": "open (no sealed candidate-bound invite-preparation harness yet; arm manifest holds commands.invite null)",
  "bounded_deadlines": "added: 120 s watch windows, 90 s service-connect, 300 s consent-to-review, 600 s generation, 300 s send-to-DM, 60 s CLI exits",
  "stale_statements_removed": ["reset mode order dry-run/verify/execute", "approval-as-receipt-path", "candidate verifier exit-2 claim", "profile bootstrap ledger as authorization source", "sessions/state.db in preserved scope (both are cleared scopes in the sealed contract)", "reset controller and archive verifier described as not yet sealed"]
 },
 "artifacts": {
  "golden_path_v2": {"path": "task26-golden-path-2e0894ea-v2.md", "sha256": "633d5c25ce70cb9ab5d19c434122b14b46fb7108962ab6e453ce6ab3ede1848f"},
  "recovery_runbook_v2": {"path": "task26-recovery-runbook-2e0894ea-v2.md", "sha256": "6024c26ccae3cad7fcf46a77bca8607d73293a92ddb3dcf8fa5a278361869f1d"},
  "linter_v2": {"path": "lint_runbooks_v2.py", "sha256": "7cb505b12e2a392231afee4390636537f6965af1b4b1fc4573a605fe3623fc32"},
  "lint_results_v2": {"path": "lint-results-v2.json", "sha256": "0c8277f4e3a7d22ff4cc5ded6b098f2cd5ba0eea9cce148a228b41f88226dea5", "summary": {"total": 91, "passed": 91, "failed": 0, "status": "PASS"}}
 },
 "independent_verification": [
  "all twelve sealed pins recomputed from the live artifacts and matched (controller, contract, permission, dry-run receipt, readiness receipt, archive verifier, inventory, seal, verification receipt, test file, verifier-input, candidate verifier)",
  "sealed dry-run manifest digests match the current live profile files exactly (registry 9eb1b5ae empty, bootstrap ledger 7004dac9 with three EXPIRED claim-free sessions, sessions.json 0bd0afb9, state.db 68de185a mode 600, gateway.lock 28420d4a unheld)",
  "flock -n probe on the live gateway.lock succeeded: no active lock holder at 2026-08-15T12:42Z",
  "verify_candidate.py argparse and exit semantics read from source: positional verifier-input file, exit 0 on PASS",
  "reset_controller.py argparse, execute preconditions, rollback boundary, and verify-is-post-execute semantics read from source",
  "bootstrap terminal-state gap read from candidate wheel source: transition() allows only REGISTERING to AWAITING_CONSENT to AWAITING_ACTIVATION to ACTIVE; CANCELLED/FAILED never assigned; no COMPLETED state exists",
  "archive verifier test suite executed: 14/14 passed; LSP diagnostics clean; default-config ruff reports EXE001 (sealed 0400 test file carries a shebang) and UP035 (typing import style), both benign sealing/style artifacts, not functional defects",
  "preservation of all four prior runbook files verified by sha256 recompute"
 ],
 "coverage_matrix": {
  "fail_closed_preflight": "G1-G16 with PASS/OPEN status; UNKNOWN equals FAIL",
  "wheel_deployment_rebind_loaded_byte_proof": "GP section 3 (direct_url plus nine-module sha256)",
  "archive_first_pre_post_reset": "GP sections 2 and 12 with the exact sealed command and gate G15/G16",
  "one_invite_one_start": "GP section 5 with sealed-harness rule and expiry precedent",
  "subscriptions_before_actions": "GP section 4",
  "all_new_ids_states": "GP section 5 forbidden-value list",
  "handset_steps": "GP sections 5-9",
  "no_recovery_shortcuts": "RC hard rule plus every R procedure",
  "exactly_once_delivery": "GP section 10 and RC R12/R13",
  "disable_cleanup": "GP sections 11-12",
  "rollback_abort_matrix": "RC section 4, 15 rows",
  "other_profile_non_touch": "RC section 5 with pins and controller tree-digest abort",
  "secrets_redaction": "RC section 6",
  "evidence_receipts": "GP section 13 and RC section 7"
 },
 "unresolved_issues": [
  {"id": "B3", "severity": "blocker", "detail": "billable active provider probe for openai-codex awaits written human authorization; cheap read-only auth check only until then"},
  {"id": "G12", "severity": "blocker", "detail": "no sealed candidate-bound invite-preparation harness exists; arm manifest holds commands.invite null"},
  {"id": "B6", "severity": "blocker", "detail": "cleanup reset cannot pass the sealed contract terminal-authority check after a successful lifecycle: candidate 2e0894ea has no ACTIVE-to-terminal bootstrap transition and the claimed session retains role_claims; resolution needs a superseding sealed contract/permission revision or candidate support; rehearsal itself is unaffected", "new_in_v2": true},
  {"id": "note:ruff", "severity": "informational", "detail": "default-config ruff flags EXE001/UP035 on the sealed verifier test/verifier files; sealed artifacts are byte-pinned and functionally verified (14/14 tests), so they are left untouched"}
 ],
 "closed_blockers": {
  "B1": "closed as a preflight blocker: lock probe proves no active holder; the stale lock is inside the sealed reset approved_clear_scopes and is disposed of by execute; G15 verifies absence after reset",
  "B2": "closed: reset controller sealed with passing dry-run and readiness receipts",
  "B5": "closed: retained-archive verifier sealed with PASS receipt over all five archives"
 },
 "non_actions": ["no profile state mutations", "no service actions", "no network or Telegram actions", "no provider calls", "no git mutations", "no edits to any prior artifact", "no lock file removal", "writes confined to this evidence directory"],
 "verdict": {
  "task_verdict": "PASS",
  "executable_today": false,
  "decision_complete": true,
  "ready_for_rehearsal_preflight": false,
  "reason": "v2 runbooks are exact, internally consistent, deadlock-free, and fully pinned to sealed evidence; B3, G12, and B6 remain open external gates, so the READY_FOR_REHEARSAL_PREFLIGHT token is withheld"
 }
}
