{
  "schema": "task26-security-privacy-review-v1",
  "recorded_at_utc": "2026-08-14T07:04:15Z",
  "verdict": "FAIL",
  "release_blocked": true,
  "scope": "Security/privacy Oracle review of the fixed-candidate claim and canonical Task22-25 evidence. No product, profile, service, Telegram, provider, delivery, git, archive, or release mutation was performed.",
  "findings": [
    {
      "id": "T26-SEC-001",
      "severity": "HIGH",
      "release_blocker": true,
      "title": "The current v1 candidate generates and persists trainer-scoped review data and retains trainer implementation scaffolding",
      "evidence": {
        "current_source_sha256": {
          "gateway/platforms/nutrition_coaching_proposal.py": "d36b8452e6a9f74fddc444f649a509af5c4ec720b5a657e63a82d059cb7087a9",
          "gateway/platforms/nutrition_coaching_proposal_validation.py": "ab454c2d2223ffc1aff22e973a19ac218c0bfbc53ee2bad8362ef0f4b9ca6985",
          "gateway/platforms/nutrition_coaching.py": "2d10de01391b02228eb17625b6cfd3c01ee0be0219d417b19b355af9f3e6eb09",
          "gateway/platforms/telegram.py": "7740711ba483e6cd7bada83893faa625ea7c43e7436a1168fc1acfb356ecd2c7"
        },
        "observed_contract": "ValidatedCoachProposal and CoachReview contain trainer_handoff; the strict review schema requires and serializes that field; validation generates it from recovery/adherence/safety state; the generation worker persists it. The loaded coordinator also exposes trainer-address, trainer-launcher, trainer-text, and trainer-callback methods, and TelegramAdapter retains a trainer-handoff sender method.",
        "archived_v1_draft_ledger_sha256": "509ba81dc6356134f61d31d33f664ca0531391c62abe7f785aeb51122a2fe4a1",
        "archived_v1_draft_ledger_mode": "0600",
        "archived_trainer_handoff_field_count": 3,
        "archived_nonempty_trainer_handoff_field_count": 3,
        "route_limit": "The active v1 registry constructor builds an empty trainer route map and ResolvedCustomer instances with no trainer bridges; no trainer delivery or unauthorized disclosure was observed. This limits impact but does not satisfy the explicit no-marker, no-review, no-safety-path, and no-scaffolding v1 invariant."
      },
      "remediation": "Remove or exclude trainer-specific fields, generators, sender methods, coordinator methods, and loaded route scaffolding from the v1 closure. Represent safety information only as owner/operator review notes, migrate any active v1 projection forward without rewriting historical receipts, and rerun the trainer-free source/route/data scan plus Tasks23-25 on the resealed candidate."
    },
    {
      "id": "T26-EVID-001",
      "severity": "HIGH",
      "release_blocker": true,
      "title": "No immutable evidence graph binds the exact current candidate",
      "evidence": {
        "execution_head": "0dc0f228dcec8fa54430882daf72e901d6a89f79",
        "git_status_porcelain_v1_z_sha256": "ae78c0f38c66cf104c9f71ba4acc845e6daf09b9edf5f31a858da14ac74e2ce0",
        "git_status_entry_count": 178,
        "full_candidate_manifest_sha256": "e9bc7dff8060425aa001f6a4501107bb9685be9248a7753f0969f89c2cf5d5c8",
        "full_candidate_manifest_candidate_digest": "c160085a64454c23f789464170b299543324c743a489bac68ed5430fab42d291",
        "current_security_surface_sha256": {
          "gateway/platforms/telegram.py": "7740711ba483e6cd7bada83893faa625ea7c43e7436a1168fc1acfb356ecd2c7",
          "gateway/platforms/nutrition_coaching.py": "2d10de01391b02228eb17625b6cfd3c01ee0be0219d417b19b355af9f3e6eb09",
          "gateway/platforms/nutrition_coaching_judgment_request.py": "b704b013e754df31698266bc7fd994459a68e52d78ee9fb8e2960ee7732c290b",
          "gateway/platforms/nutrition_coaching_proposal_validation.py": "ab454c2d2223ffc1aff22e973a19ac218c0bfbc53ee2bad8362ef0f4b9ca6985",
          "gateway/platforms/telegram_nutrition_onboarding_runtime_authority.py": "75bd8c9217c34874ed3788cab88ab2e098048bfe58c3e98c21bd9d7f5283a7ca",
          "gateway/platforms/telegram_nutrition_onboarding_runtime_callback.py": "5e13ff75efc63c4b326bc4c45b952aea11663f5aa765a4a3aa07a2f7f33eab8f",
          "gateway/platforms/task23_portable_coach_successor.py": "f0e94be81b48484d875b745324b31f9a4c3c09a5f31a484d2694c7ab59c498b6",
          "tests/gateway/test_task23_portable_coach_successor.py": "01abed6875765a6fd65b2470cc9a395758f61acd32d2a9b4803f4924ca0be7bf",
          "tests/gateway/task24_preflight_harness.py": "4097465158263dfba21810b03ab2038f1dc60a6cbf60ac9c460c602ce8dd7693",
          "tests/gateway/test_task24_preflight_integration.py": "f41b15345fa9510609683b0626b2ddb8db133c15c00d5a6c4a87c3ce6f369245"
        },
        "mismatched_lineage": [
          "Task23 publication-inclusive evidence pins successor 2fc972..., telegram 21fb3c..., and successor test 30c158..., all different from current bytes.",
          "Task24 preflight evidence pins the current telegram.py but pins harness f6a898... and integration test 2f1030..., both different from current bytes.",
          "Task24 lineage-repair evidence pins the current nutrition_coaching.py and integration test but pins harness 72aca6..., different from current bytes.",
          "No later complete manifest binds the current source/test set and the current 178-entry status snapshot."
        ]
      },
      "remediation": "Freeze one exact tree and issue one complete transitive manifest covering runtime source, scripts, harnesses, tests, package/wheel inputs, HEAD, and the NUL-framed status snapshot. Re-run all affected gates from that tree and make every Task23-25 receipt point to the same candidate digest."
    },
    {
      "id": "T26-EVID-002",
      "severity": "MEDIUM",
      "release_blocker": true,
      "title": "The current Task24 real-handler integration test is not reproducible from the cleaned profile",
      "evidence": {
        "focused_contract_run": "81 passed, 1 integration test deselected",
        "explicit_integration_run": "1 failed",
        "failure_boundary": "The network-disabled bubblewrap harness copied the current cleaned profile and failed before handler execution: expected one current regenerable draft, got 0.",
        "external_network": false,
        "live_profile_mutation": false
      },
      "remediation": "Create a candidate-bound immutable pre-clean Task24 fixture from authenticated archived inputs entirely inside a disposable sandbox, or make the harness construct that state through supported offline setup. Then run the exact current real-handler matrix once and retain its receipt under the unified candidate manifest."
    },
    {
      "id": "T26-EVID-003",
      "severity": "LOW",
      "release_blocker": false,
      "title": "Task22 canonical summary permissions are weaker than the later private-evidence convention",
      "evidence": {
        "task22_index_mode": "0664",
        "task22_markdown_mode": "0664",
        "parent_evidence_directory_mode": "0700",
        "task23_to_task25_canonical_modes": "0600"
      },
      "remediation": "Normalize canonical Task22 summaries to the documented private-evidence mode during the next authorized evidence reseal. The owner-only parent directory currently limits exposure."
    }
  ],
  "verified_controls": {
    "customer_dm_and_staff_isolation": "Provider membership evidence 4b7d6a7b6971a2d0a0cf706705e026acf5f6925a175e19d827e1179cc7ee3237 records a complete observation with the synthetic customer outside the sole scoped staff chat; the associated private-route attestation is mode 0600.",
    "owner_only_and_fail_closed_callbacks": "Current authority/callback code checks exact actor, chat, topic, membership evidence, callback binding, current generation, record digest, check-in revision, draft revision, and render identity before mutation. Canonical Task24 evidence records zero stale, repeat, or wrong-role durable mutations and one accepted send ingress.",
    "request_and_schema_seals": "Current request construction fences untrusted customer notes and binds customer/session/finalized check-in, targets, history, principles, evidence, and authority context. Proposal validation requires an exact response key set, customer and revision equality, offered IDs, valid targets, grounded numbers/claims, and safety checks.",
    "synthetic_only_delivery": "Task24 canonical evidence records exactly one synthetic delivery, one accepted send ingress, no extra provider generation for send, and no post-restart duplicate.",
    "cleanup": "Task25 canonical evidence records delivery disabled, customer disabled, no future jobs, no profile process, inactive/dead runtime, no orphan artifacts, and 23 archived scopes.",
    "archive_integrity": "Archive manifest ca4811444e114a06749620b9a44e05c8bd62bc3223ec80b1b5740c832c4a84c1 and receipt e81a84a8584400401f83aace36283dee18660144ede11e854758e725796e7fb3 match current bytes; archive directories are 0700 and files are 0600.",
    "canonical_index_integrity": "All referenced Task23, Task24, and Task25 canonical paths, SHA-256 values, and declared modes matched. Task22 child-artifact references checked during review also matched."
  },
  "privacy": {
    "receipt_redacted": true,
    "contains_secrets": false,
    "contains_raw_customer_or_model_text": false,
    "contains_raw_callback_data_or_route_identifiers": false
  },
  "review_actions": {
    "product_edits": 0,
    "profile_or_archive_mutations": 0,
    "service_actions": 0,
    "telegram_or_provider_actions": 0,
    "delivery_actions": 0,
    "git_actions": 0,
    "evidence_receipt_created": true
  }
}
