{
  "schema": "task26-security-privacy-final-v1",
  "task_id": "st_01a0038d",
  "recorded_at_utc": "2026-08-15T03:53:34Z",
  "lane": "legitimate privacy, authorization, and data-isolation correctness",
  "verdict": "FAIL",
  "decision": "NO-GO",
  "severity": "HIGH",
  "release_blocked": true,
  "runtime_action_authorized": false,
  "candidate": {
    "full_candidate_digest": "5e6f2f2a01321ac89c2950e511e7346d23070c51146c14c22c04db54034b28f1",
    "provider_candidate_digest": "f9a46172386333a0067f43695fb1429a043a606f04baceb06e8c59b90c36235c",
    "manifest_sha256": "0422f192d187738dc5ff1faaf7dcfbc92c51b30c2d21b12c10438674d801dc08",
    "checkpoint_sha256": "3ec449df7fb12ce1cbe45f4808a26f5e463355b59415100f676c43046514fc76",
    "wheel_sha256": "6a3f5f04a2982658f1c334273b05ae958b0353470997fc8df143c5b1fe12cbeb",
    "repository_status_sha256": "ca1ce2705c0c406f30461e5f05e8d09468dee33348960c3650b6b98758895478",
    "checkpoint_status": "SEALED",
    "internal_full_digest_recomputation": "PASS",
    "candidate_root_symlinks": 0,
    "candidate_root_mode": "0500",
    "candidate_artifact_mode": "0400"
  },
  "decisive_blockers": [
    {
      "id": "T26-AUTHORITY-POSTLAUNCH-001",
      "severity": "HIGH",
      "status": "OPEN",
      "finding": "The sealed controller accepted arm/start without proving one durable recoverable owner_review state, then unconditionally reported a human-action state. The deterministic post-launch repair receipt explicitly records candidate_invalidated_by_repair=true and live_owner_review_recovery_ready=false.",
      "sealed_controller_sha256": "76212d9caae866d7c5ed451d247165c8eb352c1a3af8281690b0ca7b9ba40a49",
      "repaired_controller_sha256": "b303634599c17e2f35339f964b2277c1a236f42c0ad5f3e4be18d3f38e556e13",
      "repair_receipt_sha256": "17fd0654060371b75e1673cb634ffbbbc3630c24913ab8377962b78bb0818200",
      "consequence": "Gate18, Gate19, and Gate20 are historical for pre-repair bytes and cannot authorize this candidate. A new candidate seal and candidate-bound gate chain are required."
    },
    {
      "id": "T26-WINDOW-001",
      "severity": "HIGH",
      "status": "OPEN_BLOCKED",
      "finding": "Both canonical human invite windows are EXPIRED; recurrence_count=2, live_prepared_count=0, owner_review_count=0, activation_count=0, and delivery_count=0. No valid human action pointer exists.",
      "first_expiry_supersession_receipt_sha256": "361d093f4b5c49cf73d2f77c2835292bd35910c88a08b3202b06c247cf2458c1",
      "final_cleanup_receipt_sha256": "08fe1b6556e991c8f90fb4204fd63abe23d83917529c08e21b6da6d41930f414",
      "cleanup_status": "PASS_BLOCKED_NO_LIVE_INVITE",
      "consequence": "No launch, claim, callback, activation, delivery, provider, Telegram, or restart action is authorized from this review."
    },
    {
      "id": "T26-CANDIDATE-DRIFT-001",
      "severity": "HIGH",
      "status": "OPEN",
      "finding": "The NUL status SHA and 1294-entry count still match because the repaired paths were already untracked, but byte authentication found exactly two mismatches among 375 source entries. Status equality therefore does not close source drift.",
      "source_mismatches": [
        {
          "path": "gateway/platforms/dualcoach_tasks21_25_controller.py",
          "sealed_sha256": "76212d9caae866d7c5ed451d247165c8eb352c1a3af8281690b0ca7b9ba40a49",
          "observed_sha256": "b303634599c17e2f35339f964b2277c1a236f42c0ad5f3e4be18d3f38e556e13"
        },
        {
          "path": "tests/gateway/test_dualcoach_tasks21_25_controller.py",
          "sealed_sha256": "323bce7c875fcdfc3854ef40f81deea7687cc9ab771b41e891e5218e9ed598bd",
          "observed_sha256": "95300eb8243d88af01d0e1167390ab1c30d900fed34bad44f44f2e1aca65bcdf"
        }
      ]
    }
  ],
  "gate_review": {
    "gate18": {
      "historical_result": "PASS",
      "receipt_sha256": "6d65eb8556321a144e7805b3eede44a7c9514af07420335fd396cc60a060175f",
      "tests": 1,
      "scope": "golden path and source/wheel parity"
    },
    "gate19": {
      "historical_result": "PASS",
      "receipt_sha256": "acc64624b90bbffda9af77aa7712192c41de2bbfd73c0e9b4e45d43400ca102b",
      "tests": 23,
      "scope": "wrong destination, stale callback, owner route, restart, outbox and duplicate-send matrix",
      "network_namespace": "unshared"
    },
    "gate20": {
      "historical_result": "PASS",
      "receipt_sha256": "0398155a1d39e6292bf31c22bfbbb26a190aa0b11901a81f0d55a4292cc02a52",
      "tests_passed": 8136,
      "tests_skipped": 59
    },
    "adjudication": "All three predate and are invalidated for release authority by the post-launch source repair."
  },
  "prior_blocker_closure": [
    {
      "blocker": "T26-SEC-001 trainer-scoped fields, review data, routes, methods, prompts and scaffolding",
      "historical_closure": "CLOSED for the trainer-free owner/customer v1 candidate by all TFV1 scan gates and the v4 security re-audit; no trainer-bearing production gateway source match was observed in the final static scan.",
      "evidence_sha256": ["31f1118c224285e7ddf82c2901c3885a2eda105d882f763ed8c113cd909eb56f", "2a7b6b380518a9bcd9e7e8296cd9f549744c60a82931af0c3f4cdc40b5325470", "9eda57cc2330a5919f3702b014abdf8f06b996145fc42a2b3d96d749bae6c078"]
    },
    {
      "blocker": "T26-EVID-001 missing exact immutable evidence graph",
      "historical_closure": "CLOSED at the 5e6f seal and Gate18-20 chain, then REOPENED by the post-launch controller/test byte repair. This blocker is not closed for the requested candidate.",
      "status": "OPEN"
    },
    {
      "blocker": "T26-EVID-002 non-reproducible cleaned-profile Task24 fixture",
      "historical_closure": "CLOSED by authenticated successor derivation, network-unshared disposable integration, and v4 verification."
    },
    {
      "blocker": "T26-EVID-003 weak Task22 canonical permissions",
      "historical_closure": "CLOSED by chmod-only permission repair with unchanged bytes.",
      "evidence_sha256": "53f9ce837b4e45fc5ef5a08c40345ee70f6dd6c7bfed5e4c39ae6af3e194290a"
    },
    {
      "blocker": "UNBOUND_EXECUTABLE_INPUTS",
      "historical_closure": "CLOSED by binding the build executable and candidate-seal test."
    },
    {
      "blocker": "UNBOUND_RUNTIME_BYTECODE",
      "historical_closure": "CLOSED with zero candidate cache leaves and bytecode-disabled verification."
    },
    {
      "blocker": "SYNTHETIC_HANDLER_COUNTS and REAL_HANDLER_COUNTS_NOT_BACKED_BY_HANDLER_STATE",
      "historical_closure": "CLOSED by durable handler state counts in v4: two generated drafts, two draft-created events, one draft-edited event, and one terminal child card."
    },
    {
      "blocker": "FIXTURE_DERIVATION_NOT_EXECUTABLE",
      "historical_closure": "CLOSED by executable authenticated successor derivation and hash chain."
    },
    {
      "blocker": "ACKNOWLEDGEMENT_DOES_NOT_PRECEDE_DELIVERY_WORK",
      "historical_closure": "CLOSED by durable acknowledgement before customer transport plus crash/restart fence evidence."
    },
    {
      "blocker": "CANDIDATE_DRIFT_DURING_AUTHENTICATION on superseded owner-v1 candidate",
      "historical_closure": "CLOSED for the recovered immutable owner-v1 snapshot, but a distinct post-launch byte drift now exists on 5e6f and remains OPEN."
    },
    {
      "blocker": "post-launch owner-review prerequisite omission",
      "historical_closure": "NOT CLOSED for 5e6f; repaired source exists but was not resealed or rerun through Gate18-20.",
      "status": "OPEN"
    },
    {
      "blocker": "expired human authorization windows",
      "historical_closure": "NOT CLOSED; both sessions are expired and cleanup records no live invite.",
      "status": "OPEN_BLOCKED"
    }
  ],
  "control_assessment": {
    "customer_dm_and_staff_only_routing": "Historically PASS: provider membership evidence and Gate19 bind the synthetic customer outside staff chat and enforce canonical customer destination. Not sufficient to override current candidate invalidation.",
    "sole_owner_authority": "Historically PASS for callback actor/chat/topic/role and stale binding checks; FAIL for launch authority because sealed controller omitted the durable owner-review prerequisite.",
    "callback_restart_outbox": "Historically PASS for stale/wrong/repeat no-op, immutable callback receipt, restart recovery, and no duplicate send. Gate19 is network-unshared and cache-disabled.",
    "secret_and_pii_handling": "PASS for reviewed redacted outputs: provider secret values are not in the candidate manifest or this receipt; candidate baseline carries hashes/modes only. Private invite evidence contains sensitive routing/token material and remains owner-only; none is reproduced here.",
    "file_integrity_and_symlink_controls": "Candidate artifacts are regular owner-only files with no symlinks; source/outbox code uses lstat, non-following descriptor opens, private modes and integrity records. Overall candidate integrity FAILS because two source bytes differ from the seal.",
    "profile_cleanup_evidence": "Evidence-only PASS_BLOCKED_NO_LIVE_INVITE: two expired sessions, no live prepared invite, zero activation/owner-review/delivery, gateway and watcher recorded inactive/dead. The profile was not read by this lane.",
    "trainer_free_acceptance": "Historically PASS for all TFV1 gates in the v4 re-audit; the original inventory itself is a FAIL-state acceptance contract, not a release receipt."
  },
  "evidence_hashes": {
    "initial_security_review": "804869f3ef143760b84c545ac7229a2a64251197fd9c688156818be57003d092",
    "trainer_free_inventory": "31f1118c224285e7ddf82c2901c3885a2eda105d882f763ed8c113cd909eb56f",
    "owner_v1_security_v4": "2a7b6b380518a9bcd9e7e8296cd9f549744c60a82931af0c3f4cdc40b5325470",
    "task22_permission_repair": "53f9ce837b4e45fc5ef5a08c40345ee70f6dd6c7bfed5e4c39ae6af3e194290a",
    "owner_customer_v3_independent_verification": "9eda57cc2330a5919f3702b014abdf8f06b996145fc42a2b3d96d749bae6c078",
    "authoritative_rearm": "202d08a09942cc67d2a04b140b19e08fd529bbcec3ef0199160672130df7186b"
  },
  "offline_checks": {
    "policy": {
      "network": "denied with bubblewrap --unshare-net",
      "host_filesystem": "read-only bind",
      "bytecode": "disabled with PYTHONDONTWRITEBYTECODE=1 and python -B",
      "pytest_cache": "not used",
      "live_profile_reads": 0
    },
    "commands": [
      "bwrap --die-with-parent --unshare-net --ro-bind / / --tmpfs /tmp --dev /dev --proc /proc --setenv HOME /tmp --setenv TMPDIR /tmp --setenv PYTHONDONTWRITEBYTECODE 1 --chdir '/home/cube/projects/richard/traning coach' /usr/bin/python3 -B -c '<read-only manifest/source/wheel/repair/window hash audit>'",
      "bwrap --die-with-parent --unshare-net --ro-bind / / --tmpfs /tmp --dev /dev --proc /proc --setenv HOME /tmp --setenv TMPDIR /tmp --setenv PYTHONDONTWRITEBYTECODE 1 --chdir /home/cube/projects/richard/hermes-agent /usr/bin/python3 -B -c 'import hashlib,subprocess,json; b=subprocess.run([\"git\",\"status\",\"--porcelain=v1\",\"-z\",\"--untracked-files=all\"],check=True,capture_output=True).stdout; print(json.dumps({\"sha256\":hashlib.sha256(b).hexdigest(),\"entry_count\":b.count(bytes([0])),\"network\":\"unshared\",\"cache\":\"disabled\"},sort_keys=True))'",
      "sha256sum <enumerated candidate, Gate18/19/20, repair, supersession, cleanup, trainer-free, permission, and security receipts>"
    ],
    "results": {
      "manifest_full_digest": "PASS",
      "candidate_artifact_hashes": "PASS",
      "repository_status_hash": "PASS",
      "repository_status_entry_count": 1294,
      "source_entries_checked": 375,
      "source_mismatches": 2,
      "repair_invalidation": true,
      "window_recurrence_count": 2,
      "window_states": ["EXPIRED", "EXPIRED"]
    }
  },
  "drift": {
    "status_snapshot_drift": false,
    "source_byte_drift": true,
    "semantic_reason": "Untracked path contents changed without changing porcelain path/status records.",
    "candidate_reseal_after_repair": false,
    "post_repair_gate18_19_20_chain": false
  },
  "cleanup": {
    "evidence_status": "PASS_BLOCKED_NO_LIVE_INVITE",
    "expired_sessions": 2,
    "live_prepared_sessions": 0,
    "activations": 0,
    "owner_reviews": 0,
    "deliveries": 0,
    "runtime_observation_source": "immutable cleanup receipt only; no live runtime or profile inspection"
  },
  "privacy": {
    "receipt_redacted": true,
    "contains_secrets": false,
    "contains_raw_customer_or_model_text": false,
    "contains_raw_callback_data": false,
    "contains_raw_route_identifiers": false,
    "contains_invite_url_or_plaintext_token": false
  },
  "non_touch": {
    "product_edits": 0,
    "profile_reads": 0,
    "profile_mutations": 0,
    "runtime_or_service_actions": 0,
    "telegram_or_provider_access": 0,
    "network_calls": 0,
    "delivery_actions": 0,
    "git_mutations": 0,
    "git_commits_pushes_releases": 0,
    "receipt_files_created": 1,
    "other_files_created_or_modified": 0
  },
  "required_next_authority_boundary": "NO ACTION AUTHORIZED. A separately authorized repair/reseal workflow must bind the repaired controller and test into a new candidate, rerun candidate-bound Gates18/19/20, and establish a fresh canonical human window only when the authorized synthetic actor is ready. Historical 5e6f evidence must not be used as PASS authority."
}
