Six packages. One candidate mode. One no-listener dry boot.
The exact Cut 77 ConfigRef→client→Adapter binder now drives the exact Cut 76 six-component composer. Every component preserves its fixture contract, adds a separate digest-bound candidate surface, and participates in one reversible joint transaction. This is executable integration evidence—not a live production install.
Repository integration is green; the host remains intentionally empty
These are separate truths. Candidate construction can pass without turning an absent manifest, identity or listener into production evidence.
Every reference lands on one least-authority Adapter and one reviewed component
The lane cards are the development directory: ownership, operation vocabulary, reference count and live-install status are visible without opening source.
Capacity read lane
Worker read lane
Runner composite lane
Journal read lane
Readiness trust lane
Two proven transactions are joined without broadening authority
The binder owns references and client lifetime. The composer owns component lifetime. The joint candidate owns ordering and cross-layer rollback.
Fixture and candidate surfaces are both exact—and intentionally different
A candidate Adapter is not accepted because its label looks right. It must add exactly one canonical binding digest and keep every prior permission, operation, reference and method fence.
kind · operation(s) · permission
configRefs · read method(s) · dispose
kind · operation(s) · permission
configRefs · bindingDigest · read method(s) · dispose
Runner operation vocabulary drift was caught before installation
Cut 77 emitted method-style labels while RunnerReader’s reviewed contract requires uppercase protocol constants. The joint boot failed closed, so the binder vocabulary was aligned without weakening either side.
GetRepositoryJob
GetRootAgentState
GET_REPOSITORY_JOB
GET_ROOT_AGENT_STATE
Six changed source trees received six new evidence chains
Each package binds source tree, artifact, SBOM, provenance and detached role review. The review explicitly states that candidate mode is repository-qualified and live binding remains forbidden.
| Package | Owner → reviewer | Evidence chain | Mode decision | Production |
|---|---|---|---|---|
| ReservationReader | Data → Security | source · artifact · SBOM · SLSA · review | REQUALIFIED | NOT BOUND |
| CapacityReader | SRE → Security | source · artifact · SBOM · SLSA · review | REQUALIFIED | NOT BOUND |
| WorkerReader | SRE → QA | source · artifact · SBOM · SLSA · review | REQUALIFIED | NOT BOUND |
| RunnerReader | DevEx → Security | source · artifact · SBOM · SLSA · review | REQUALIFIED | NOT BOUND |
| JournalReader | Audit → Security | source · artifact · SBOM · SLSA · review | REQUALIFIED | NOT BOUND |
| ReadinessVerifier | Security → Architect | source · artifact · SBOM · SLSA · review | REQUALIFIED | NOT BOUND |
Construction and rollback have one explicit layer order
Failure at any component closes the already-created components, then closes all bound Adapters. The readiness resolver is consumed exactly once during construction; the five source ports remain untouched.
Five repository gates close together
P43 closure says “the pieces fit under dry boot.” It does not say production services exist.
One receipt joins binding identity, composition identity and six mode proofs
No ConfigRef value, SecretRef payload, private key or callable reference is serialized into the receipt.
productionConfigRefsResolved = 0
productionClientsConstructed = 0
productionAdaptersConstructed = 0
productionExternalReads = 0
productionListenerStarts = 0
productionBindingObserved = false
What is proven, what is simulated, what is absent
The design keeps repository observations separate from EC2 state so developers and AI agents cannot mistake a green fixture for production.
| Boundary | Repository proof | Production observation | Owner |
|---|---|---|---|
| Component source contract | 6 / 6 REQUALIFIED | not applicable | Package owners + reviewers |
| Reference bundle | 12 / 12 injected fixtures | 0 / 12 | Configuration Root + Security |
| Client constructors | 6 closed fixture shapes | 0 / 6 | Runtime Adapter |
| Controller identity | contract only | ABSENT | Identity Owner |
| Listener | authority denied | 0 on :8110 | Platform SRE |
Six concrete production fragments remain
These are owned development items, not vague “future work.” P44 should tackle the first four as one still-no-listener installation transaction.
Filter the exact failure family instead of reading a green total
18 full transactions, 30 mode/surface fences, 24 failure-containment cases, 24 capability/receipt/disposal cases and 24 admission/replay/zero-effect cases.
The only red gate is an honest production-install boundary
All source, mode, surface, ordering, receipt, cleanup and zero-effect gates are repository-bound. P44 has no evidence and stays red.
Every production-effect counter remains zero
The only allowed candidate invocation is the injected repository public-key resolver, once per successful dry boot. It reports zero source reads, secret reads and network calls.
Next: atomic root manifest, six live clients and dedicated identity binding—still without starting 8110
Cut 79 should define installation inputs, file/UID/GID ownership, six client constructor modules, SecretRef custody, readback proofs, partial rollback and a no-listener installed-state receipt. Starting the Controller process belongs to a later, separately authorized gate.