- host class
- SHARED_PRODUCTION_PORTAL
- Portal source
- 9214f9f46baf…
- Portal listener
- 127.0.0.1:8100 · 1
- Controller files
- ABSENT · 0 / 8
- Controller runtime
- 0 process · 0 :8110
Qualify the host.
Separate the witness.
Keep production stopped.
The privileged installation packet is now executable in an isolated root namespace, but the current EC2 is correctly denied. A dedicated staging host, four-party change authority, argv-only executor, independent eight-artifact readback and reverse rollback must all agree before a live install can exist.
The shared Portal host fails before sudo is considered
Read-only observation found four independent blockers. Identity collisions make the Cut 79 fixed 991:991 descriptor unsafe here even if every file path is still absent.
/etc/reits-production-host makes the host class incompatible.“EC2 reachable” is not a host qualification
The target profile requires a dedicated non-production control-plane host with both markers absent, ports 8100 and 8110 closed, 991:991 free and all Controller state absent.
Current shared Portal EC2
NOT
CONVERGE
Required dedicated staging host
Scope, time and authority become one immutable ticket
The repository envelope is fixture-only. A production envelope must name the exact dedicated host, source commit, eight artifacts, thirty-minute window, rollback plan and four independent roles.
- source
- Cut 79 · 9214f9f46baf…
- window
- 06:00 → 06:30 UTC
- scope
- 8 install artifacts
- executor
- EXECVE_ARGV_ONLY_NO_SHELL
- activation
- false · false
cannot self-witnesscannot change targetcannot executeread-only · separateNo actor can qualify, install, witness and activate alone
Six operational lanes prevent one privileged process from manufacturing its own evidence. Listener authority remains deliberately absent.
NO INSTALLNO WITNESSNO VERDICTNO MUTATIONNO SCOPE EXPANSIONABSENT IN CUT 80The transaction is atomic at the identity + manifest + six-module boundary
Every target has a reviewed digest and a different independent readback requirement. No systemd unit, Secret value or production driver is included.
991:991 · nologin · no groups · no caps/etc/reits-runner-factory/controller-runtime.json · 0640346c…0332 · GetItem only2c87…f689 · GetItem onlyd0b8…10ff · Describe ×214fb…b566 · exact GET ×34b1e…0e57 · Query onlye7a7…861c · verify-onlyExecutable argv is data; generic shell strings are rejected
The future driver must invoke an allowlisted binary with an exact argument vector. No command substitution, pipe, wildcard, variable expansion or interactive shell exists in the interface.
[groupadd, --gid, 991, --system, reits-runner-factory]Requires GID 991 FREE[useradd, --uid, 991, --gid, 991, --shell, /sbin/nologin, …]Requires UID 991 FREE[install, -o, root, -g, reits-runner-factory, -m, 0640, …]Canonical bytes only[install, -o, root, -g, reits-runner-factory, -m, 0640, six files]Six digests exact[getent, passwd, reits-runner-factory]Independent witness lane[stat, --format, %u:%g:%a:%h:%i, eight paths]Never trust write return values[systemctl, is-active, reits-runner-factory-controller.service]Must be absent or inactive[ss, -ltnH, sport = :8110]Must return zero listenersEvery exit path closes the window
Qualification and authority happen before the window. Installation, witness and rollback live inside it. Success means “rolled back rehearsal and closed,” not “left installed.”
The rehearsal starts from an exact absent and stopped state
An unexpected identity, manifest, module root, unit, process or listener denies the transaction before the first artifact operation.
The write lane is only one segment of the proof chain
Cut 80 makes target qualification, authorization, independent evidence and rollback first-class transaction stages instead of post-hoc runbook notes.
The executor cannot sign its own success
Eight executor proofs are inputs to a separate read-only witness. The witness rereads identity and filesystem state, then seals a new digest without mutation authority.
↓
DIGEST SET
Write return values are never acceptance evidence
The stopped-state proof is additional: it verifies that no unit, process, Portal change or 8110 listener appeared during the rehearsal.
uid · gid · shell · groups · capsinode · owner · 0640 · digestpath · regular · owner · digest ×6unit=0 · process=0 · 8110=0Installation rehearsal grants no activation authority
Even a perfect artifact readback cannot install a unit, start a process, resolve a live Secret or open a listener.
Identity is created first and removed last
Partial failure reverts only completed stages. Full rehearsal removes readiness first, then five Readers, manifest and identity, restoring the exact prior absence.
Target, authority, executor, witness and rollback fail independently
A rollback or window-close failure is not hidden behind the original error. The terminal outcome remains denied and carries the containment failure.
Six repository gates are green; live installation is still red
These subgates qualify the packet, not a real host mutation. A production receipt must be sourced from a separately approved dedicated host.
Repository rehearsal, current EC2 and future dedicated host never share a status
The matrix prevents a fixture receipt or a reachable sudo account from being reported as production installation evidence.
| Boundary | Repository rehearsal | Current EC2 | Future dedicated host |
|---|---|---|---|
| Qualification | profile validated | requires signed claim | |
| Authority | fixture envelope | 0 production receipts | four-party receipt |
| Executor | exact surface tested | not invoked | argv-only live driver |
| Readback | 8/8 fixture proofs | 0 installed artifacts | independent live reread |
| Rollback | 18 rehearsals | not needed | live prior-state restoration |
| Activation | denied | 0 unit/process/8110 | still denied after install |
Interrogate the exact P45 failure model
Filter complete rehearsals, target/authority denials, executor surface violations, witness tampering, rollback containment and capability/replay fences.
The only red gate is live dedicated-host execution
All prior P44 gates and six new P45 packet subgates are repository-bound. No production change authority or qualified host is implied.
Six production fragments remain owned and explicit
Cut 81 may close only these stopped-state installation dependencies. Service activation, live data access and public routing remain separate gates.
Next: approved dedicated-host stopped-state installation—and nothing more
Cut 81 should consume an exact dedicated staging host claim and production change receipt, run the no-shell executor, obtain independent live readback, rehearse rollback, and leave the host in a verified stopped state. It must not touch the shared Portal EC2, install a systemd unit, resolve production references, start Controller or bind 8110.