{
  "schema": "task26-runbook-binding-receipt-v1",
  "recorded_at_utc": "2026-08-15T13:05:00Z",
  "task_id": "st_01a0054e",
  "task": "Task26 runbook rebind: Golden Path and Recovery Runbook supersession for candidate 2e0894ea",
  "binding": {
    "candidate_full_digest": "2e0894eac92bc396cc4723bf1f18ebc653b95018dd41574df435941c235da925",
    "wheel_sha256": "af4a9d0a1ffffb6eb7551c1d6dc2b32853ca6d024332a4f8f5702bbf992f141b",
    "amended_plan_sha256": "7ace03c6dad33d2fc3ef223621cbca68a150fde8429932138e252fb8498ac582",
    "amended_plan_path": ".omo/plans/dualcoach-production-readiness.md",
    "rehearsal_actor_user_id": "8527916639",
    "owner_operator_user_id": "8693203710",
    "service": "hermes-gateway-dualcoachtest.service",
    "profile_root": "/home/cube/.hermes/profiles/dualcoachtest",
    "ledger_authority": "same-actor-live-rehearsal-authorized (2026-08-15T11:55:24Z)"
  },
  "supersedes": {
    "candidate": "19ed0e9232e240553b9a96a2e6a33d10f1096be49e5ebafc019287d75984e45c",
    "documents": [
      {
        "path": ".omo/evidence/dualcoach-golden-path-contract.md",
        "sha256": "32a379d855c6e5af978bd9886e3bf49c616c7c20f1c1d5f100c19d8adfc5eb4a",
        "disposition": "preserved byte-identical; void for this rehearsal"
      },
      {
        "path": ".omo/evidence/dualcoach-recovery-runbook.md",
        "sha256": "ae2f5f9046c06f8f0b42693be5aa0d9c31cada8024ae1e5ab8ba19a3cf10f6fc",
        "disposition": "preserved byte-identical; void for this rehearsal"
      }
    ],
    "note": "The old files' dualcoach_admin planned interfaces (process-state, generation reconcile, callback inspect, card rebuild, updates reconcile, outbox reconcile, customer disable) do not exist in candidate 2e0894ea; the only shipped subcommand is provider-auth check. Verified against the installed argparse source."
  },
  "artifacts": {
    "directory": ".omo/evidence/task26/task26-runbook-rebind-2e0894ea-st_01a0054e",
    "golden_path": "task26-golden-path-2e0894ea.md",
    "recovery_runbook": "task26-recovery-runbook-2e0894ea.md",
    "linter": "lint_runbooks.py",
    "lint_results": "lint-results.json",
    "modes": "directory 0700; files 0600",
    "sha256_recorded_in": "artifact_sha256 below"
  },
  "artifact_sha256": {
    "task26-golden-path-2e0894ea.md": "1f55b8f967c6564113574d41bf1c15ce977d35c38b5687f1623ba37f235a7bdb",
    "task26-recovery-runbook-2e0894ea.md": "f4f2d2347b4b68a080b9c437a813accbef8c4bcc471cbf21d67ffff31e56f89b",
    "lint_runbooks.py": "8df077ea1444ecf381abd4438bd887fb3044b7b390d661da5586d8a702cb0c6d",
    "lint-results.json": "3448c564d9a977dfac467c381f7911536166889dbbf8437c38670f9b2a791011"
  },
  "lint": {
    "overall": "PASS",
    "check_count": 40,
    "failures": [],
    "method": "mechanical lint of both runbooks against the amended plan's Task26 amendment (authorized and forbidden action lists, all-new IDs/states, invalidation of candidate-19ed0e evidence), Spec 2 golden-path content and must-not-contain list, Spec 3 procedure families and per-procedure fields, Task 25 archive-first reset requirements, plan invariants (exactly-once, idempotency, append-only, no silent failure), and execution constraints (no git mutations). Includes recomputed preservation hashes of the superseded runbooks and the amended plan hash."
  },
  "coverage_matrix": {
    "amendment: boundary reuse actor 8527916639, same DM/identity/history/consent/memory, new logical lifecycle": "GP 0 binding, GP 6 all-new IDs table",
    "amendment: authenticated archive-first pre-reset": "GP 1 gates G8/G10/G11, GP 2",
    "amendment: exact-candidate wheel deployment and service rebind": "GP 3 (pip force-reinstall, direct_url, nine-module loaded-byte proof)",
    "amendment: exactly one new canonical bootstrap invite": "GP 5 step 1 (sealed harness, canonical API, one invocation)",
    "amendment: one private-DM Start by 8527916639": "GP 5 step 3 (handset, exact claim regex)",
    "amendment: synthetic lifecycle actions": "GP 7-11",
    "amendment: exactly one delivery after explicit send": "GP 11 (idempotency key, sent_audited)",
    "amendment: final disable": "GP 12",
    "amendment: authenticated archive-first cleanup reset": "GP 13",
    "amendment: forbidden actions (restore/prepopulation, direct mutation, raw listener/cursor edits, replay, forced publication, recovery shortcuts, real-customer activation, retargeting, unrelated profile changes, git mutations)": "GP 0 authority, GP 15, RC 2; lint E/H",
    "amendment: all-new IDs and states": "GP 6 (forbidden reused values enumerated); lint F",
    "amendment: invalidation of prior candidate evidence/runbooks": "GP 0 supersession, RC 0; lint B/C",
    "amendment: runtime proof (lease, lifecycle journal, consumed-update journals, ingress guard, registry/authority, publication, outbox, delivery receipt)": "GP 4 observer set, GP 5 expected evidence, GP 11; RC R1/R7/R9/R11",
    "spec2: golden path covers plan 21-25 surfaces with actor/action/expected state/evidence": "GP 5-14; lint G",
    "spec2: must not contain getUpdates harness, drop_pending_updates, direct mutation, raw listener, replay, forced publication": "GP 15, RC 1/2; lint H",
    "spec3: recovery procedures for invite/link, Start payload, consent card, claim collision, revision conflict, safety hold, card publish/edit conflict, owner rejection, failed/stale callback, provider failure, delivery duplicate, restart before/after send": "RC R1-R15; lint I",
    "spec3: per-procedure fields (trigger, commands, expected state, rollback, evidence)": "RC R1-R15 structure; lint I-procedure-fields",
    "task25: archive-first reset, no restore, cleanup, stopped truthful service": "GP 2, GP 13, RC 4; lint M",
    "invariant: exactly-once and idempotency": "GP 11; lint R",
    "invariant: append-only evidence, 0600": "GP 14, RC 5; lint O/P/T",
    "invariant: no silent failure": "GP 15; lint R",
    "constraint: no commit/push/release/publish/register/tag": "GP 0/15, RC 2; lint E"
  },
  "unresolved_issues": [
    {
      "id": "B1",
      "summary": "stale gateway.lock (dead PID 4091167)",
      "owner": "sealed reset scope (st_01a0054d) or canonical startup classification",
      "runbook_gate": "GP gate G8, RC R2"
    },
    {
      "id": "B2",
      "summary": "no sealed reset artifact compatible with candidate 2e (sibling lane in progress, not yet sealed; dry-run/verify receipts absent)",
      "owner": "st_01a0054d",
      "runbook_gate": "GP gate G10, GP 2/13 blocked until sealed"
    },
    {
      "id": "B3",
      "summary": "openai-codex provider readiness not provable read-only; billable active probe needs explicit human authorization at rehearsal time",
      "owner": "human + operator at run time",
      "runbook_gate": "GP gate G7, RC R10"
    },
    {
      "id": "B5",
      "summary": "no sealed verifier covering all five predecessor archive schemas",
      "owner": "reset/archive lane",
      "runbook_gate": "GP gate G11"
    },
    {
      "id": "G12",
      "summary": "no sealed candidate-bound one-use invite preparation harness yet (arm lane holds commands.invite: null until blockers close)",
      "owner": "st_01a00547",
      "runbook_gate": "GP gate G12, GP 5"
    }
  ],
  "non_actions": "This task performed no product, profile, runtime, archive, service, network, Telegram, provider, or Git actions. All reconnaissance was read-only (file reads, hashes, zip inspection, systemctl status/is-active, argparse help). Writes were confined to this evidence directory.",
  "verdict": {
    "task_verdict": "PASS",
    "b4_runbook_rebind": "CLOSED",
    "executable_today": false,
    "decision_complete": true,
    "ready_for_rehearsal_preflight": false,
    "reason_not_ready": "Decision-complete (every step cites an evidenced command or a named fail-closed gate), but not executable end-to-end while B1, B2, B3, B5 and the invite-harness gate G12 remain open in other lanes. The token READY_FOR_REHEARSAL_PREFLIGHT is withheld per the issuance rule. Re-run the fail-closed preflight (GP Section 1) after the reset controller seals with passing dry-run/verify receipts, the archive verifier lands, the lock is reconciled inside the sealed reset scope, and the billable provider probe is authorized and passes."
  }
}
