{
  "schema": "task26-security-final-successor-v1",
  "task_id": "st_01a00434",
  "recorded_at_utc": "2026-08-15T06:55:32Z",
  "lane": "legitimate privacy, authorization, and data-isolation correctness",
  "verdict": "PASS",
  "decision": "SECURITY_LANE_GO",
  "candidate": {
    "full_candidate_digest": "653cc2f0b47873e95f985ea3eb32b8f2c044d6de64cd9e8fe37ebcec67c7a723",
    "core_candidate_digest": "a03f84f7db67afe0ace8d31541dd373852af052fbb1a23a8e70dd96c6263f5ef",
    "manifest_sha256": "23b72148af7412b292555107c6b29616d9436c437871787763667c9fb62fca26",
    "checkpoint_sha256": "6acc31bdf597dfb51151fb4c2cd76cb7da2ceb33579a8cd840490fbbfdbbd4be",
    "wheel_sha256": "af4a9d0a1ffffb6eb7551c1d6dc2b32853ca6d024332a4f8f5702bbf992f141b",
    "repository_status_sha256": "ca1ce2705c0c406f30461e5f05e8d09468dee33348960c3650b6b98758895478",
    "repository_status_entry_count": 1294,
    "immutable_verifier": "PASS",
    "candidate_root_mode": "0500",
    "candidate_artifact_mode": "0400",
    "candidate_symlink_count": 0
  },
  "archive_binding": {
    "status": "PASS",
    "archive_id": "2009ac177177839cefddb98f285e27fa",
    "archive_digest": "644d74b05bc8115f9e3aeeba035188da195a7de18f1bc737648931d64bf43bcf",
    "binding_sha256": "b6f459adaad944cd61bde7feb8bebcb6faa64b49c55a087117f74b3185bd3613",
    "scope_count": 23,
    "classification": "historical_compatibility_and_provenance_evidence_only",
    "historical_execution_retargeted_to_successor": false,
    "task22_25_indexes_sha256": "419511b6fadb7920e155dcd5b57d20661d750a989ef0912e9ddf1bfbc0cb0abe",
    "finding": "Task22-25 receipts remain historical and do not claim execution against the successor."
  },
  "candidate_bound_gates": {
    "gate18": {
      "status": "PASS",
      "receipt_sha256": "589223e0d391346939dccbb79351b3d408a07351bb9218c4496e28b851814e5a",
      "tests": 38,
      "source_wheel_mismatch_count": 0,
      "source_closure_mismatch_count": 0,
      "pid_regressions_per_lane": 3
    },
    "gate19": {
      "status": "PASS",
      "receipt_sha256": "00bdaf0186437e9b93ca9fe2badd3f6a4db5fd8c4cf5b69c66135bb7245fd688",
      "required_results": 120,
      "failed": 0,
      "skipped": 0,
      "coverage": [
        "cancel_restart",
        "cleanup_stale_false",
        "legacy_malformed_symlink_preservation",
        "lock_ownership",
        "misleading_status",
        "pid_reuse_live_identity",
        "validated_stale_cleanup"
      ]
    },
    "gate20": {
      "status": "PASS",
      "receipt_sha256": "643970f32ef2f1e841ff2a43b28270e8ec539033026f832303955209f392d541",
      "passed": 8138,
      "failed": 0,
      "skipped": 59,
      "pid_authority_regression": "PASS"
    }
  },
  "security_assessment": {
    "pid_authority_fix": {
      "status": "PASS",
      "source_sha256": "8641bae4540dcadec0f80a3d97b1a1013ab36f3cb1b4920027d70cae1d1d308c",
      "test_sha256": "1976b3530484b105704fdf2bcf1c6302ec7416fcec33f675e515177ef7447c5d",
      "finding": "Live non-gateway PIDs, foreign PIDs, start-time mismatches, and PID reuse fail closed; the predecessor is explicitly superseded."
    },
    "controller_phase_boundary": {
      "status": "PASS",
      "controller_sha256": "b303634599c17e2f35339f964b2277c1a236f42c0ad5f3e4be18d3f38e556e13",
      "test_sha256": "95300eb8243d88af01d0e1167390ab1c30d900fed34bad44f44f2e1aca65bcdf",
      "finding": "Arm and launch fail closed unless exactly one durable recoverable owner_review projection is bound to the awaiting-activation session."
    },
    "customer_dm_and_staff_routing": {
      "status": "PASS",
      "finding": "Customer delivery requires a canonical private Bot DM with topic 0; shared staff-chat/topic configurations and customer membership in staff review chats are rejected. Staff destinations remain role-typed and separate."
    },
    "sole_owner_authority": {
      "status": "PASS",
      "finding": "Approval callbacks require the owner role and exact actor, chat, topic, publication, message, update, and session authority. Operator review data cannot authorize owner approval or delivery."
    },
    "trainer_free_scope": {
      "status": "PASS",
      "finding": "All TFV1 field, method, prompt, route, projection, serializer, validator, closure, archive, fixture, and regression controls passed with zero forbidden production matches; historical trainer material is not promoted to active authority."
    },
    "callbacks_restart_exactly_once": {
      "status": "PASS",
      "finding": "The authenticated callback is durably recorded before owner transition; stale, wrong-role, wrong-destination, repeated, and conflicting callbacks fail closed. Restart recovery preserves pending/failed ingress and outbox state, while immutable receipts and claims prevent duplicate customer sends."
    },
    "secret_and_pii_handling": {
      "status": "PASS",
      "finding": "Candidate and gate bindings carry hashes, modes, counts, and redacted authority only. No credentials, invite URL/token, raw route identifiers, raw callback payload, customer text, or model output is reproduced in this receipt. Runtime diagnostics are bounded and content-free."
    },
    "file_integrity_symlink_and_mode_controls": {
      "status": "PASS",
      "finding": "The immutable candidate has no symlinks and is sealed 0500/0400. Sensitive runtime state uses lstat, O_NOFOLLOW, descriptor validation, atomic replacement, 0700 directories, and 0600 files. Active sensitive profile data contains no symlinks and all active files observed are 0600. Evidence roots and Task22-25 indexes are owner-private."
    }
  },
  "current_profile": {
    "profile_label": "dualcoachtest",
    "status": "PASS_CLEAN_INACTIVE_BASELINE",
    "customer_count": 0,
    "enabled_customer_count": 0,
    "customer_state_count": 0,
    "room_bootstrap_session_count": 0,
    "customer_bootstrap_session_count": 3,
    "customer_bootstrap_states": {
      "EXPIRED": 3
    },
    "publication_outbox_record_count": 0,
    "emergency_outbox_record_count": 0,
    "owner_review_count": 0,
    "activation_count": 0,
    "delivery_count": 0,
    "active_sensitive_symlink_count": 0,
    "runtime_evidence": "inactive/dead, MainPID=0, Telegram disconnected",
    "historical_archives_retained": true,
    "finding": "Expired bootstrap records and authenticated rehearsal archives are retained as terminal history only; there is no prepared invite, customer, activation, owner review, delivery, or live authorization window."
  },
  "prior_blocker_closure": [
    {
      "id": "T26-SEC-001",
      "status": "CLOSED",
      "resolution": "Trainer-scoped production fields, routes, methods, prompts, projections, and access paths were removed and all TFV1 controls passed."
    },
    {
      "id": "T26-EVID-001",
      "status": "CLOSED",
      "resolution": "The repaired controller/test and PID fix are bound into immutable digest 653cc2f0 with exact executable closure and candidate-bound Gates18-20."
    },
    {
      "id": "T26-EVID-002",
      "status": "CLOSED",
      "resolution": "The cleaned-profile fixture is authenticated by executable successor derivation and isolated integration evidence."
    },
    {
      "id": "T26-EVID-003",
      "status": "CLOSED",
      "resolution": "Canonical Task22 evidence permissions were repaired without byte changes; the repair receipt SHA-256 is 53f9ce837b4e45fc5ef5a08c40345ee70f6dd6c7bfed5e4c39ae6af3e194290a."
    },
    {
      "id": "UNBOUND_EXECUTABLE_INPUTS",
      "status": "CLOSED",
      "resolution": "Build executable, seal tooling, test inputs, source closure, wheel, and verifier are hash-bound."
    },
    {
      "id": "UNBOUND_RUNTIME_BYTECODE",
      "status": "CLOSED",
      "resolution": "Candidate cache leaves are zero and verification uses bytecode-disabled execution."
    },
    {
      "id": "SYNTHETIC_HANDLER_COUNTS_AND_UNBACKED_REAL_HANDLER_STATE",
      "status": "CLOSED",
      "resolution": "Durable handler state and events back generation, edit, callback, and terminal-card counts."
    },
    {
      "id": "FIXTURE_DERIVATION_NOT_EXECUTABLE",
      "status": "CLOSED",
      "resolution": "Authenticated executable fixture derivation and hash-chain verification passed."
    },
    {
      "id": "ACKNOWLEDGEMENT_DOES_NOT_PRECEDE_DELIVERY_WORK",
      "status": "CLOSED",
      "resolution": "Durable acknowledgement/receipt precedes transition and transport; crash/restart and failed-ack fences passed."
    },
    {
      "id": "CANDIDATE_DRIFT_DURING_AUTHENTICATION",
      "status": "CLOSED",
      "resolution": "The drifting 5e6f candidate is historical and invalidated; the repaired successor verifies identically before/after all candidate-bound gates."
    },
    {
      "id": "T26-AUTHORITY-POSTLAUNCH-001",
      "status": "CLOSED",
      "resolution": "The owner-review prerequisite repair is sealed in the successor and tested in source and wheel lanes."
    },
    {
      "id": "T26-CANDIDATE-DRIFT-001",
      "status": "CLOSED",
      "resolution": "The repaired controller/test are authenticated by the successor seal; source closure and source/wheel mismatch counts are zero."
    },
    {
      "id": "T26-WINDOW-001",
      "status": "CLOSED_SAFE_TERMINAL",
      "resolution": "All prior invite windows are expired, prepared count is zero, runtime is inactive, and no stale window can authorize launch or delivery. A future live window requires separate fresh owner authorization."
    },
    {
      "id": "PID_AUTHORITY_LIVE_NON_GATEWAY",
      "status": "CLOSED",
      "resolution": "The exact gateway/status.py fix is sealed and the focused, adversarial, and full gateway suites pass."
    }
  ],
  "evidence_hashes": {
    "owner_v1_security_v4": "2a7b6b380518a9bcd9e7e8296cd9f549744c60a82931af0c3f4cdc40b5325470",
    "predecessor_security_fail": "de7e8e6a8f0155e7a561704eefa1a46e31c7d024ebc8e980bb1f73a5b3f11fd7",
    "trainer_free_inventory": "31f1118c224285e7ddf82c2901c3885a2eda105d882f763ed8c113cd909eb56f",
    "task22_permission_repair": "53f9ce837b4e45fc5ef5a08c40345ee70f6dd6c7bfed5e4c39ae6af3e194290a",
    "task24_replay": "7e8d38820a94143a73778c8eaedd244a1e00f149ea4689c0483f5e76b37a2d42",
    "task25_revalidation": "20ef2be32388fa2c3e60943487b370f83458374d25ef01f32dc605a311da576d",
    "expiry_cleanup": "d0cb1afeadbbf8c321b97eae53f1a616f4cd493b1dd34f0964beaa517b05608d",
    "pid_supersession": "8805062af465e95e7ceb1eaa2c1b9bea02cf8d179b9af693c9dd18dc7ad401cd"
  },
  "offline_verification": {
    "network": "denied by bubblewrap --unshare-net for immutable verifier",
    "filesystem": "root read-only bind for immutable verifier",
    "bytecode": "disabled",
    "candidate_verifier_result": "PASS",
    "candidate_or_profile_drift": false,
    "missing_or_inconclusive_required_control_count": 0
  },
  "privacy": {
    "redacted": true,
    "contains_secrets": false,
    "contains_raw_customer_or_model_text": false,
    "contains_raw_callback_data": false,
    "contains_raw_route_identifiers": false,
    "contains_invite_url_or_plaintext_token": false
  },
  "authority_boundary": {
    "security_lane_pass_only": true,
    "task26_release_authority_claimed": false,
    "runtime_action_authorized": false,
    "future_live_action": "Requires a separately authorized fresh owner window; historical receipts and expired windows confer no authority."
  },
  "non_touch": {
    "source_or_test_edits": 0,
    "profile_mutations": 0,
    "runtime_or_service_actions": 0,
    "archive_actions": 0,
    "network_or_provider_actions": 0,
    "telegram_actions": 0,
    "git_actions": 0,
    "receipt_files_created": 1,
    "other_files_created_or_modified": 0
  }
}
