{
  "version": 1,
  "messageId": "35c8e703-ed71-4337-8988-8c0600a3e4d3",
  "from": "pre-exec-audit",
  "to": "lead",
  "kind": "message",
  "body": "PRE-EXEC AUDIT VERDICT: BLOCK — do not perform live mutation.\n\nVerified present/read-only facts:\n- Candidate manifest SHA-256 recomputed to 78b2d1790b67cf0d9730cd9a4b0d2d0d3de5bf5f5836e31a70f5be3a62dd7786; package SHA-256 recomputed to afb91c8cfa6038862763b61ea58d47d880949eb4d8b77c961017a2db02e52f78. All five package evidence hashes match package.json.\n- Read-only manual QA ran the current executor and returned AWAITING_AUTHORIZATION for candidate 066a794d44861d2cd0fe8c1ea14c0050e00219b38a2d2026b389772783056dad. Current service fields equal the sealed snapshot; clean-boundary receipt passes; authorization-consumed.json is absent. Capacity-5 migration remains persisted=false. Preflight dirs/files are 0700/0600.\n- Active candidate manual-surface receipt records disposable cleanup and network_calls=0; package validation keeps both v1.5 capabilities OFF until separately authorized.\n\nCriterion-bound blockers:\n1. FROZEN LIVE CONTROLLER/SEAL MISSING. The only v1.5 executor is scripts/execute_nutricoach_v150_live_upgrade.py (SHA e5d15398a726c88b3470c438d4b50fbbb6f44d55dad3a8c3a1815ec9cc5ba30e); it requires --dry-run and contains no live transaction branch. .omo/evidence/nutricoach-v150-combined/live-transaction-red.json independently records the no-live-path exit-2 result. package.json binds candidate/evidence only, not a controller hash or transaction seal.\n2. V7 TRANSACTION EQUIVALENCE AND FULL REHEARSAL MISSING. The v1.4 v7 evidence has run-one-use-v7 staged receipts and rollback archive, but frozen v1.5 evidence has no corresponding controller/rehearsal artifacts. rollback-rehearsal.json proves only a disposable registry write/restore (stable digests equal); it does not exercise or recover stop -> post-stop snapshot/ledger validation -> install -> OFF smoke -> migration apply -> capability enablement -> systemd switch/restart -> post-fence -> atomic commit, nor every rollback boundary.\n3. ONE-USE AUTHORITY NOT IMPLEMENTED FOR LIVE EXECUTION. The current executor only rejects a pre-existing authorization-consumed.json; it never creates a durable reservation or consumption record because it has no mutation path. Thus the supplied approval remains unconsumed, but required duplicate/stale/interruption semantics for a live transaction are unproven.\n4. LIVE-PATH PRIVACY/NETWORK/CLEANUP UNPROVEN. Existing zero-network, privacy, cleanup, and current-clean-boundary evidence applies to the candidate and read-only preflight. With no executable sealed transaction, there is no auditable proof that those invariants hold across actual service stop/install/switch/restart/rollback.\n\nNo files or live state were modified by this audit.",
  "timestamp": 1787835219021,
  "summary": "BLOCK: v1.5 live mutation is not approvable"
}
