{"schemaVersion":"developer.reits.tech/runner-controller-release-evidence/v1","status":"G09_G10_DENIED_UNSIGNED_RELEASE_CHAIN_AND_NO_INTENTIONAL_ROLLBACK_DRILL","observedAt":"2026-07-21T09:44:51Z","observationMode":"READ_ONLY_DUAL_TARGET_RELEASE_AND_ROLLBACK_AUDIT_NO_PRODUCTION_SWITCH","program":{"acceptedKnives":4,"totalKnives":36,"currentKnife":"D05","closeoutCut":6,"remainingIncludingCurrent":32,"remainingAfterAcceptance":31,"d05Accepted":false},"gateSummary":{"targetedGates":2,"satisfiedGates":0,"positiveAcceptanceReceipts":0,"identityFieldsMatched":6,"identityFieldsRequired":6,"missingIndependentIdentityReceipts":4,"namedRollbackTargetsObserved":2,"executedRollbackSteps":0,"requiredRollbackSteps":8,"decision":"DENY_AND_ESCALATE_TO_SUPPLY_CHAIN_AND_RELEASE_ENGINEERING"},"gates":[{"id":"D05-G09","name":"EXACT_RELEASE_IDENTITY","owner":"SUPPLY_CHAIN","target":"signed exact source, artifact, SBOM, configuration, migration and runtime identity chain independently bound across EC2 and Sites","observed":"all six identity values match across the audited EC2 and Sites runtimes, but provenance is unsigned, the EC2 release tree is service-user writable and no independent build-to-runtime or archive-to-dist attestation exists","positiveReceiptsObserved":0,"decision":"DENIED_MATCHED_VALUES_ARE_UNSIGNED_SELF_ASSERTIONS"},{"id":"D05-G10","name":"INTENTIONAL_ROLLBACK_DRILL","owner":"RELEASE_ENGINEERING","target":"authorized intentional rollback to the named immutable predecessor, predecessor smoke, timed recovery to the current release and independent signed receipt","observed":"EC2 predecessor release and Sites version 135 both exist, but verifiedAt is null, no intentional production transition was executed and no rollback or recovery receipt was found","positiveReceiptsObserved":0,"decision":"DENIED_NAMED_TARGETS_EXIST_BUT_DRILL_NOT_EXECUTED"}],"identity":{"auditBaseline":{"releaseId":"developer-portal@2619505ae534-be4aefef59cd","sourceRevision":"2619505ae534f9293626cd757183af4e33d24e44","rollbackReleaseId":"developer-portal@7df4c8f73386-eaad97e745fd"},"fields":[{"id":"source","label":"exact source","ec2":"2619505ae534f9293626cd757183af4e33d24e44","sites":"2619505ae534f9293626cd757183af4e33d24e44","matches":true,"acceptanceStatus":"OBSERVED_UNSIGNED"},{"id":"artifact","label":"dist artifact","ec2":"sha256:be4aefef59cd70651512e8425d8b754b27486491d6d5557485178d1f21e81546","sites":"sha256:be4aefef59cd70651512e8425d8b754b27486491d6d5557485178d1f21e81546","matches":true,"acceptanceStatus":"OBSERVED_UNSIGNED"},{"id":"sbom","label":"CycloneDX SBOM","ec2":"sha256:601fae3f405c5f18d636f2e222f43b03def5b94ba8602ded68717aa526fc2ec2","sites":"sha256:601fae3f405c5f18d636f2e222f43b03def5b94ba8602ded68717aa526fc2ec2","matches":true,"acceptanceStatus":"OBSERVED_UNSIGNED"},{"id":"configuration","label":"public configuration","ec2":"sha256:2acb68789cd717dbd5104c8f4f15d45dc7148be2a1119961cae15838e9c18db8","sites":"sha256:2acb68789cd717dbd5104c8f4f15d45dc7148be2a1119961cae15838e9c18db8","matches":true,"acceptanceStatus":"OBSERVED_UNSIGNED"},{"id":"migration","label":"migration set","ec2":"sha256:dc6c9dd2ab96033d9dfd46da240fbf27c35c6cd4a260d96b19ef35c16a0cdfd7","sites":"sha256:dc6c9dd2ab96033d9dfd46da240fbf27c35c6cd4a260d96b19ef35c16a0cdfd7","matches":true,"acceptanceStatus":"OBSERVED_UNSIGNED"},{"id":"runtime","label":"runtime release ID","ec2":"developer-portal@2619505ae534-be4aefef59cd","sites":"developer-portal@2619505ae534-be4aefef59cd","matches":true,"acceptanceStatus":"OBSERVED_UNSIGNED"}],"targets":[{"id":"ec2-systemd","label":"developer.reits.tech / EC2 systemd","runtimeStatus":"BOUND","sourceStatus":"MATCHED","materialization":"/opt/reits-developer-portal/releases/2619505ae534f9293626cd757183af4e33d24e44","materializationOwner":"ec2-user:ec2-user","materializationMode":"0755","materializationWritableByServiceIdentity":true,"packagedReceiptMatchesRuntime":true,"receiptSigned":false,"independentAcceptanceReceipt":false},{"id":"sites-worker","label":"Sites owner-only production","runtimeStatus":"BOUND","sourceStatus":"MATCHED","materialization":"Sites version 136 / environment revision 16","materializationOwner":"SITES_MANAGED","materializationMode":"OWNER_ONLY_CUSTOM_ACCESS","materializationWritableByServiceIdentity":false,"packagedReceiptMatchesRuntime":false,"receiptSigned":false,"independentAcceptanceReceipt":false,"versionSource":"2619505ae534f9293626cd757183af4e33d24e44","archiveDigest":"sha256:1464514daeeaca1cb7a3f3f04bdcac3820f7ae1ae21834380a0daaa52e1cfd44","archiveToDistAttestation":false}],"acceptanceRequirements":[{"id":"signed-provenance","proof":"independently verifiable signature over release ID and all six identity fields","status":"MISSING"},{"id":"immutable-materialization","proof":"root-owned read-only EC2 release tree and separately identified immutable Sites artifact","status":"MISSING"},{"id":"build-runtime-binding","proof":"independent builder attestation binding reviewed source, dist tree, SBOM, configuration and migration to runtime","status":"MISSING"},{"id":"dual-target-witness","proof":"signed deployment witness proving EC2 and Sites serve the same exact reviewed release without self-assertion","status":"MISSING"}]},"rollback":{"currentReleaseId":"developer-portal@2619505ae534-be4aefef59cd","targetReleaseId":"developer-portal@7df4c8f73386-eaad97e745fd","targetMatchesCurrent":false,"namedTargetsObserved":2,"intentionalTransitionsObserved":0,"recoveryTransitionsObserved":0,"rollbackReceiptsObserved":0,"recoveryReceiptsObserved":0,"verifiedAt":null,"targets":[{"id":"ec2-predecessor","platform":"EC2_SYSTEMD","target":"/opt/reits-developer-portal/releases/7df4c8f733866b7ba18ccbb3b4ef69e35c10d2af","sourceRevision":"7df4c8f733866b7ba18ccbb3b4ef69e35c10d2af","artifactDigest":"sha256:eaad97e745fdef4108ef5da3ebb6d717052e4bc5c8b0dbc20f6d4d2e918df7b9","targetPresent":true,"targetPrepared":true,"drillExecuted":false,"recoveredToCurrent":false,"receiptStatus":"MISSING"},{"id":"sites-predecessor","platform":"SITES","target":"Sites version 135","sourceRevision":"7df4c8f733866b7ba18ccbb3b4ef69e35c10d2af","artifactDigest":"sha256:c978d1b513e72d210877df4670b285ed5e87100858fae4a82bc2e30017b89d3a","targetPresent":true,"targetPrepared":true,"drillExecuted":false,"recoveredToCurrent":false,"receiptStatus":"MISSING"}],"steps":[{"id":"RB-01","label":"maintenance authorization","evidence":"approved window, accountable operator, independent observer and rollback scope","status":"REQUIRED_NOT_AUTHORIZED"},{"id":"RB-02","label":"before-state freeze","evidence":"current release identity, health, traffic and data-safety snapshot","status":"NOT_EXECUTED"},{"id":"RB-03","label":"intentional predecessor switch","evidence":"atomic EC2 pointer and Sites production version transition to the named predecessor","status":"NOT_EXECUTED"},{"id":"RB-04","label":"predecessor verification","evidence":"exact predecessor identity, HTTP smoke and invariant checks","status":"NOT_EXECUTED"},{"id":"RB-05","label":"recovery to current","evidence":"atomic re-promotion of the exact original release on both targets","status":"NOT_EXECUTED"},{"id":"RB-06","label":"current-state verification","evidence":"exact current identity, HTTP smoke and invariant checks after recovery","status":"NOT_EXECUTED"},{"id":"RB-07","label":"bounded timing and loss proof","evidence":"measured durations, zero data loss, zero unexpected route and no 8110 listener","status":"NOT_EXECUTED"},{"id":"RB-08","label":"independent signed receipt","evidence":"operator and observer signatures over ordered events, timestamps, digests and final state","status":"NOT_EXECUTED"}]},"operatorPlan":{"nextAction":"Supply Chain must first provide an independently signed release attestation and immutable materialization evidence. Release Engineering may schedule the dual-target rollback drill only after explicit production authorization, a maintenance window, an independent observer, bounded health and identity checks, and an automatic recovery guard are approved.","forbiddenActions":["Do not count matching environment variables, a BOUND runtime response or an unsigned packaged receipt as independent release provenance.","Do not count an existing predecessor directory, saved Sites version or configured rollback ID as an executed rollback drill.","Do not perform a production rollback from this read-only evidence cut without explicit maintenance authorization and an accountable operator.","Do not update Sites environment variables during a predecessor drill without a transaction plan that restores the exact current revision.","Do not issue G09 or G10 receipts when verifiedAt is null, signatures are absent or either production target was not observed after recovery."]},"safetyTruth":{"readOnlyAuditPerformed":true,"credentialsRecorded":false,"productionSymlinkSwitches":0,"sitesProductionVersionChanges":0,"sitesEnvironmentUpdates":0,"serviceRestarts":0,"rollbackTransitionsExecuted":0,"recoveryTransitionsExecuted":0,"externalWritesExecuted":0,"paidResourcesCreated":false,"controllerListener8110Observed":false,"g09Satisfied":false,"g10Satisfied":false,"d05Accepted":false},"verification":{"status":"PASS_READ_ONLY_DUAL_TARGET_RELEASE_AND_ROLLBACK_OBSERVATION","targetedGates":2,"satisfiedGates":0,"identityFieldsMatched":6,"identityFieldsRequired":6,"independentIdentityReceiptsObserved":0,"namedRollbackTargetsObserved":2,"intentionalRollbackStepsExecuted":0,"requiredRollbackSteps":8,"rollbackReceiptsObserved":0,"recoveryReceiptsObserved":0,"productionSymlinkSwitches":0,"sitesProductionVersionChanges":0,"serviceRestarts":0,"externalWritesExecuted":0},"discovery":{"workbench":"/release-foundation#runner-controller-release-evidence","schema":"/schemas/runner-controller-release-evidence.v1.schema.json","runtimeIdentity":"/api/release-unit","releaseRegistry":"/api/release-units","activationEvidence":"/api/runner-controller/activation-evidence","installationEvidence":"/api/runner-controller/installation-evidence","d05Closure":"/api/runner-factory/controller/d05-acceptance-closure"}}