- UID / GID
- 991 / 991
- shell
- /sbin/nologin
- home
- /var/lib/reits-runner-factory
- host class
- DEDICATED_CONTROL_PLANE
Installable source.
Reversible transaction.
Zero host mutation.
The canonical root manifest, dedicated non-login identity and six independently loadable client modules now enter one eight-stage sandbox transaction. Every artifact is read back, the actual modules drive the Cut 78 joint dry boot, and rollback restores the prior absent state. No privileged host installation is claimed.
Repository evidence advanced; the host deliberately did not
The evidence probe now checks the one canonical runtime path. Repository artifacts are real; host installation remains absent and separately authorized.
/etc/reits-runner-factory/controller-runtime.jsonreits-runner-factoryOne path, one owner boundary, twelve references
The file holds typed references and assembly intent—not token values. Strict canonical bytes, single trailing LF and an assembly-contract digest remove serializer and path ambiguity.
path /etc/reits-runner-factory/controller-runtime.json
owner root:reits-runner-factory
mode 0640 · regular · nlink=1
encoding UTF-8 · canonical JSON · LF
size 1…65536 bytes
read O_NOFOLLOW · O_CLOEXEC
11 typed ConfigRefs
1 P-256 KeyRef · VERIFY_ONLY
5 strongly-consistent Reader declarations
1 loopback bind declaration
0 inline secrets / private keys
0 production resolutions
UID/GID is part of the manifest digest, not an ops convention
The candidate has no login, supplementary group or Linux capability path. The future installer must prove the same subject before and after writing any file.
Identity + manifest + six modules form one atomic set
No artifact can be promoted alone. The plan and terminal receipt bind all eight positions and their strict order.
reits-runner-factory · 991:991/etc/reits-runner-factory/controller-runtime.jsondynamodb:GetItemdynamodb:GetItemDescribeInstances + DescribeVolumesGitea GET ×2 + agent readdynamodb:Queryverify-only public keyEach module owns one exact scope and one injected driver port
These are real ESM modules, imported independently and hashed from source. Construction validates authority but does not invoke a data-source method.
Loadable client does not mean configured production SDK
The module freezes the contract around an injected read-only driver. AWS SDK, Gitea transport, Unix socket and trust-store implementations remain a separate P45 dependency.
EXACT
PORT
The Cut 78 graph now starts from real module exports
Eleven ConfigRefs and one KeyRef select six modules; the existing binder creates six Adapters; the existing composer creates five Readers and one verifier. Only the repository key fixture resolves once.
Every forward step has a deterministic inverse
The repository driver simulates root operations inside an isolated sandbox. It proves sequencing and rollback semantics without touching EC2 production paths.
No success from write return values alone
Eight independent proof digests are rebound into one readback-set digest, then joined with the Cut 78 receipt. P45 must reproduce this from the real host.
uid · gid · shell · groups · capspath · inode · mode · content SHAinstall path · source SHA × 6binding + composition + install planReadiness comes off first; identity comes off last
Partial failure reverts only completed steps. Terminal disposal reverts all eight and must prove the same prior-absent state.
Six repository gates close together
Manifest, identity, modules, transaction, joint boot and rollback/readback are all required. None is a production installation receipt.
Repository proof and host proof remain visibly separate
The table prevents “loadable,” “staged,” “resolved” and “installed” from collapsing into one misleading green state.
| Boundary | Repository evidence | Production evidence | Decision |
|---|---|---|---|
| Manifest | canonical bytes + assembly digest | no inode / owner / mode proof | HOLD |
| Identity | exact 991:991 descriptor | no passwd/group readback | HOLD |
| Modules | 6 imports + 6 source digests | 0 installed module proofs | HOLD |
| Drivers | exact injected interfaces | 0 production implementations | HOLD |
| Joint boot | 18 actual-module dry boots | 0 production refs / calls | P44 PASS |
| Listener | loopback declaration only | 0 process / 0 :8110 | DENY START |
Filter the actual failure model
Six suites cover complete transactions, manifest/identity/module fences, driver surfaces, rollback containment, capabilities, receipts and replay. Every row carries zero production effects.
Only privileged host installation stays red
All source, identity, module, ordering, readback, rollback, receipt and zero-effect gates are repository-bound. P45 has no production receipt.
Six owned production fragments remain
P45 must focus on a bounded privileged transaction and independent readback. Actual driver implementations and live references remain explicit prerequisites.
Installable is not installed
All fixture work stayed inside injected memory/sandbox boundaries. No production value, call, process or resource crossed the line.
Next: independently witnessed privileged installation—still without service activation
Cut 80 should bind explicit change authority, maintenance window, observed pre-state, root executor, production driver packages, readback auditor and rollback rehearsal into a non-starting host transaction. Installing does not authorize resolving secrets, calling data sources or listening on 8110.