# Task27 bounded-pilot release verdict

## Verdict

**GO for one explicitly consenting bounded pilot customer only.**

This report authorizes a controlled handoff for candidate
`d1109d8f78aaccf949ec4f664d9e62584c3cca33032030518bc3e2d712239112`.
It does not itself activate a customer, start a service, contact Telegram or a provider,
send a message, change a profile, commit, push, or release code. Every customer-facing action
still requires its existing permission-sealed preflight and explicit owner/operator action.

Delivered artifact:

`/home/cube/projects/richard/traning coach/.omo/evidence/task26/task26-combined-v38-delivered-st_01a019d7`

The delivered root passes its sealed independent verifier and frozen bootstrap directly,
without regenerating or replacing its retained postfreeze seal.

## Exact candidate and seals

- Candidate: `d1109d8f78aaccf949ec4f664d9e62584c3cca33032030518bc3e2d712239112`
- Hermes wheel: `f8b3c779c58435dd33f8f9bbc89e9823bd09f81367a27366c6d678270c1860b1`
- Profile wheel: `a56da2417df0912f3fe407c0b78befd7362207d1c8a35271000af46701ba79d2`
- Corrected Ty wheel: `932d4552233cfbaa325ddc3db5982150a37f437cf94a332eb3869052148bfe4c`
- Prefreeze seal: `257498e6aa2db7107ee24223a29b09f2e26c3d493869dc21206688be24b037b9`
- Postfreeze seal: `3002d815d7523c2971c990544d92c1f0d16fd51781f83d9d636ef6336b5878f6`
- Delivered-bundle seal: `54be54cf89720057486596a21941ec5d456a1c54148f66dbde0475503a752f67`
- Receipt seal: `52b7de2d30d99f38db6f73ad70ebe9a21c99449348f069cf3d1f29f5cab745c8`
- Qualification ledger: `.omo/start-work/ledger.jsonl:169`
- Six-lane review: `.omo/start-work/ledger.jsonl:170`

## Privacy and authority architecture

- Customers and the owner/operator remain distinct private-DM identities. No shared customer
  group is part of the pilot.
- Trainer-free v1 is preserved: neither delivered runtime wheel exposes a trainer role, route,
  authority, or customer-data path.
- The protected controller is the only capability-issuance path. Capabilities bind the exact
  candidate, product, authority snapshot, owner, customer route, card, generation, and expiry.
- Activation, service startup, capability issue, complete Telegram update processing,
  background recovery, background generation, scheduled transport, and provider transport are
  externally authorized under shared leases. Revocation-first performs zero mutation/send;
  operation-first makes revocation wait until the authorized operation completes.
- The event-driven `dnotify_signalfd_v1` watcher performs eventual disconnect with one watched
  directory and zero inotify watches.
- Every live advisory completion path sets `store=false`.
- Source and installed local-socket receipts use a real PTB/HTTPX loopback connection, record
  zero external traffic, deliver one post-revocation update from the server, and show zero
  handler entries and mutations.

## Automated qualification

All results are sealed to this candidate:

| Gate | Result |
|---|---:|
| Actual isolated profile qualification | 749 passed |
| Focused Task26 | 306 passed |
| Expanded Task26 | 76 passed |
| Parser source | 204 passed |
| Parser installed | 204 passed |
| Related lifecycle | 131 passed |
| Full Gateway | 8,552 passed, 0 failed |
| Direct-URL attacks | 32 passed |
| Ty target attacks | 14 passed |
| Final-state/materializer focused suite | 119 passed |
| Background authority: nutrition/controller/Telegram | 324 passed |
| Runtime/Ty/startup authority | 53 passed |
| Golden/final-state authority | 116 passed |
| Delivered-bundle verifier suite | 106 passed |
| Hands-on profile/seal scenarios | 126 passed |
| Hands-on authority/Telegram scenarios | 50 passed |
| Hands-on controller scenarios | 19 passed |
| Ruff and scoped Ty | PASS |

Direct delivered-root commands also passed:

```text
python -I verification-tools/independent_verify_candidate.py <delivered-root>
=> TASK26_INDEPENDENT_CANDIDATE_PASS

python -I verification-tools/task26_frozen_bootstrap.py <delivered-root>
=> TASK26_FROZEN_BOOTSTRAP_PASS
=> ACTUAL_INSTALLED_GOLDEN_PATH_PASS
```

Hermetic Ty uses the sealed Python 3.12.9 interpreter and exactly one
`--python-version 3.12`. It reports 809 diagnostics outside the nine selected
transport/capability spans and zero diagnostics inside those spans.

## Real-surface evidence

The retained, authorized synthetic rehearsal used the intended Telegram surfaces:

- Synthetic customer Telegram user/chat `8527916639`, customer
  `task22_dm_rehearsal`, session `rb_f4L9siIlDP-R6IF27GwxdA`.
- Task24 recorded one customer-DM delivery with provider message ID `157`,
  one `sent_audited` receipt, and one synthetic customer DM.
- Task25 archive `2009ac177177839cefddb98f285e27fa`, digest
  `644d74b05bc8115f9e3aeeba035188da195a7de18f1bc737648931d64bf43bcf`,
  retains 23 verified scopes including customer/owner state, activation journals,
  the exactly-once receipt, and cleanup evidence.
- Evidence:
  - `.omo/evidence/dualcoach-task-24-live-terminal-evidence.json`
  - `.omo/evidence/dualcoach-task-25-evidence-index.json`
  - `.omo/evidence/dualcoach-task-25-evidence.json`
  - `.omo/evidence/dualcoach-task-25-live-terminal-evidence.json`

No new live Telegram or provider action was needed or performed during Task26.

## Exactly-once proof

- Golden source and installed lifecycles each contain one transport call, one
  `sent_audited` delivery, one customer-surface receipt, consumed capability state, and
  duplicate rejection.
- Unknown provider outcome consumes authority and is not retried.
- The historical Task24 receipt records exactly one synthetic customer-DM delivery.
- Capability claim is atomic and precedes provider I/O under the delivery lock.

## Recovery and adversarial scenarios

The sealed candidate covers:

- update-first and revocation-first ordering;
- background recovery, generation, scheduled transport, capability issue, and provider
  transport revocation races;
- cancellation and error cleanup;
- reconnect and Telegram polling-conflict reauthorization;
- authority tamper/unavailability;
- stale, duplicate, wrong-actor, expired, and unknown-outcome delivery paths;
- genuine parse ambiguity, later-field revision, and stale field-zero rejection;
- preview/production isolation;
- approved-card projection failure before capability issue;
- forward cleanup resumption from `copied_verified`;
- direct-URL external/VCS/editable/wrong-hash substitutions;
- Ty target omission, duplication, wrong version, and semantic drift;
- delivered-root missing, regenerated, substituted, extra-file, symlink, writable-mode,
  stale-path, and absent-receipt attacks.

## Cleanup state

- The rehearsal customer is disabled and nonconsenting.
- Delivery is disabled by default.
- Gateway is inactive/dead and no scheduled jobs remain.
- Delivered, receipt, and prefreeze roots are `0500`; files are `0400`.
- All three roots have zero writable paths and zero symlinks.
- Original, rehydrated, hostile-CWD, tamper, watcher, socket, authority, and review
  temporary runtimes were removed.
- Final scans show zero Task26 process, FD, watcher, socket, runtime, pending, unknown,
  or orphan residue.

## Independent reviewer verdicts

All six Task26 lanes passed on the same delivered candidate:

| Lane | Verdict |
|---|---|
| Objective and constraints | PASS |
| Code quality | PASS |
| Security and safety | PASS |
| Hands-on QA | PASS |
| Release provenance | PASS |
| Trainer-free privacy and authority | PASS |

Receipt: `.omo/evidence/task26/task26-v38-final-six-lane-review.json`

## Pilot scope

The initial rollout is limited to:

1. one explicitly consenting pilot customer;
2. private customer and owner/operator DMs only;
3. no shared customer group;
4. one candidate: `d1109d8f...39112`;
5. daily owner/operator review during the observation window;
6. no expansion until the observation window is clean.

No automatic customer activation, delivery, or service start is authorized by this report.

## Immediate disable and rollback criteria

Disable the pilot and stop further delivery immediately on any:

- candidate, wheel, authority, profile, delivered-seal, or receipt mismatch;
- owner/customer identity or private-route mismatch;
- missing, expired, reused, duplicate, or wrong-actor capability;
- unknown provider outcome, duplicate delivery, missing `sent_audited` row, or surface-receipt
  mismatch;
- revocation that does not fence ingress/background/transport work;
- watcher, socket, process, FD, pending, unknown, orphan, or writable residue;
- provider call without `store=false`;
- unexpected external network destination;
- profile source drift or qualification-test regression;
- capability-surface Ty diagnostic;
- failed daily owner/operator review.

Rollback is fail-closed: stop the gateway, disable delivery and the pilot customer, revoke the
candidate authority, archive the terminal receipts, and require a new immutable candidate plus
the full qualification and six-lane review before resuming.

## Residual risks

- Integrity is deterministic and owner-permission sealed, not externally signed or WORM against
  a privileged host administrator.
- The 809 Ty diagnostics outside the selected transport/capability spans remain technical debt;
  this report does not claim whole-module Ty cleanliness.
- Current real-network proof is the retained authorized synthetic Telegram rehearsal; Task26
  added real loopback PTB/HTTPX revocation evidence without contacting Telegram or providers.
- A bounded pilot still depends on explicit customer consent, daily owner review, trusted-host
  operation, and the existing permission-sealed preflight.

