{"type":"transition_applied","payload":{"type":"transition_applied","status":"running","residency_state":"resident"}}
{"type":"assistant_message","payload":{"text":"I read this as a read-only cryptographic release-provenance audit of the exact v20 candidate - I’ll locate the release artifacts and audit machinery, independently recompute every requested hash and lifecycle check, rerun the specified hermetic/bootstrap/rehydration validations, and return PASS/FAIL/INCONCLUSIVE with residual risks."}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"assistant_message","payload":{"text":"The exact v20 release directory and its separate postfreeze receipts are located. I’m now auditing the declared hash graph against independently computed bytes, then I’ll execute the bundled verifiers in disposable temporary locations so the release tree remains untouched."}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"assistant_message","payload":{"text":"Static bindings are internally consistent so far, including the v20 line’s 64-character driver hashes (unlike v19’s corrected truncation). I’m starting the three requested live reruns now: frozen candidate verification plus sealed-runtime replay, isolated bare bootstrap, and hermetic Ty from the exact sealed Ty wheel."}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":true}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":true}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":true}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":true}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":true}}
{"type":"tool_execution","payload":{"tool":"read","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"assistant_message","payload":{"text":"All three live release gates have now passed through the real sealed surface: the bootstrap rerun invoked `rehydrate_and_verify`, rebuilt an offline venv from the sealed wheels, reran the source/installed verifier and hermetic Ty, compared portable runtime/RECORD projections, and scrubbed its temporary runtime. I’m doing the final residue and ledger-authority reconciliation before issuing the cryptographic verdict."}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"tool_execution","payload":{"tool":"bash","is_error":false}}
{"type":"assistant_message","payload":{"text":"I read this as the final read-only v20 provenance verdict - the exact candidate passes cryptographic and runtime verification, with bounded residual risks.\n\n## Verdict: **PASS**\n\nCandidate:\n\n`0c2d83b143aa0175e01916ce8c85149b415187aed5a13bbebe60c8ea060decd1`\n\n### Cryptographic results\n\n- Candidate manifest: `100012f199ff9c71f405afee20583e5d351c9bd878ea7ba53516d64c00a91dce`\n- Product derivation recomputed to the exact candidate digest.\n- Hermes wheel: `e8e3ee5c26fa2645d8b06cfac5d354d4b3722f15ecb44701bce410a5202e55e7`\n- Profile wheel: `62c508d3548ed5f5fe28c1a137bbc1b6af286d48419dc9e66fa4c7c8422b4121`\n- Corrected Ty wheel: `932d4552233cfbaa325ddc3db5982150a37f437cf94a332eb3869052148bfe4c`\n- Controller source: `0f7dacb7184035630f9313da73d72a68416dff4e1d8c3f476886c7ae789bd26a`\n- Telegram source: `81c18c144643868e4e38e6689f379d1e31bc94ef37a8aa57dfc4ba84e2415db5`\n- Bundle seal: `2437d3ec821ad95780074c3e2365bfccf9a7415817adb96c9bb9c153a90c2679`\n- Postfreeze seal: `95ddac25805ae32b92e4a32efd65767afae4c679d2057ffb76bd0ac5dee588be`\n\nAll 381 candidate inventory entries matched current bytes. Bundle remained frozen: zero writable paths and zero symlinks.\n\n### Lifecycle and authority\n\n- Source lifecycle hash: `c6f92bb650b8f62e3a3c54fd249fa1eb7335a7c069d263421bfbe9196b18e990`\n- Installed lifecycle hash: `40eb40d51b6cc7650b0cdabd03a40f58921b316ca1a1eb10e19986fde14c35bd`\n- Both prove protected controller capability-v2 issuance, active authority, and audited delivery.\n- Runtime snapshot self-hash and source/installed parity passed:\n  `70ed568fdbd4113d2dda1971b3509cce4c7706468520099a0b62feea142eb18c`\n- Independently recomputed all 29 paired authority-chain links.\n- v19 `b347efcd...c33661ff` is revoked.\n- v20 is the sole current qualified candidate and is not revoked.\n\n### Ty, RECORD, and runtime\n\n- Fresh hermetic Ty rerun passed:\n  - raw diagnostics: `f4a2265141525dc8005430e8afdf61145ff88c24a7fc00aad2d7609b3f2ce86a`\n  - 810 diagnostics total\n  - 0 capability-surface diagnostics\n  - 810 acknowledged outside-surface diagnostics\n- Raw wheel RECORD validation passed for all Hermes 992, profile 58, and Ty 11 members.\n- Portable projections recomputed:\n  - Hermes: `6fcb7a82f2a09c0af26255f785e20d229650a99af272d98850ab9d5b2c2bb410`\n  - Profile: `89f7425c2712a4e4916fc59d8a7e5492e4fd055961b041a0e49310203539197e`\n- Fresh bare bootstrap and full sealed-wheel rehydration passed with `ACTUAL_INSTALLED_GOLDEN_PATH_PASS`.\n- Terminal cleanup passed: no active, pending, orphaned, unknown, or temporary runtime residue.\n\n### Ledger line 165\n\n- All 52 digest-valued fields are complete 64-character lowercase SHA-256 values.\n- Every `evidence.*_sha256` resolves to actual v20 or postfreeze bytes.\n- No copied or truncated hashes were found.\n- Unlike v19 line 163, no correction record is required.\n\nHash-bound test receipts confirm: focused 450, expanded source/installed 579 each, parser 204 each, related 129, profile 749, and gateway 8,416 passed with zero failures.\n\n## Residual risks\n\n- Seals are self-hashes, not externally signed attestations. Compromised operator/admin or coherent repository-and-verifier replacement remains outside the declared trust boundary.\n- Ty does not establish whole-file cleanliness; 810 pre-existing outside-surface diagnostics remain.\n- Raw installed RECORD hashes are intentionally nonportable and changed on fresh rehydration; portable projections matched exactly.\n- The archived rehydration JSON contains stale absolute paths, so direct replay through `independent_verify_candidate.py` fails. Fresh sealed bootstrap/rehydration through the authoritative `task26_final_state` path passed.\n- Historical full-suite tests were hash-audited rather than all rerun; the explicitly requested Ty, bootstrap, and sealed rehydration gates were rerun live."}}
{"type":"transition_applied","payload":{"type":"transition_applied","status":"completed","residency_state":"resident"}}
{"type":"transition_applied","payload":{"type":"transition_applied","status":"completed","residency_state":"evicted"}}
{"type":"evicted","payload":{"cause":"evict"}}
