Write the real files. Read them twice. Delete them in reverse.
Cut 82 moves the installation proof from an executor model into the real POSIX filesystem. Twenty-four isolated roots each receive the identity descriptor, canonical manifest and six client modules, then an independent witness verifies bytes, mode, inode and link count before strict rollback returns the root to empty.
Repository transaction is green; live root installation is not attempted
The only reachable host remains the shared production Portal. Its production marker, 8100 listener and UID/GID 991 collisions make it ineligible.
Three zones, one deliberately narrow write capability
Source bytes are read from the repository, written only beneath a newly created temporary root, and independently reread without write access. Production stays outside the capability graph.
Source registry
Isolated POSIX root
Production host
Inspect the exact stopped-state installation set
Select a material to see its fixed target, mode and repeated filesystem evidence. None is a systemd unit, secret, or production configuration value.
/var/lib/reits-runner-factory/.identity.jsonInstallation begins with repository bytes, not generated placeholders
Every payload is non-empty and SHA-256-bound before the writer receives it.
Every ancestor is proven before any byte crosses the boundary
The root is canonicalized, every target is fixed and absolute, relative escape is rejected, and each ancestor is lstat-checked as a real directory rather than a symbolic link.
A real six-step POSIX commit for every artifact
Temporary files are exclusive, synced and renamed atomically. The temporary path is removed on every terminal branch.
192 materialized files prove more than content
Every install proof binds its target to the filesystem object that was actually created.
The reader cannot write, rename or delete
A separately constructed witness receives only readback, stopped-state and empty-root verification methods.
writeAtomic()
rollback()
close()
network = 0 · spawn = 0 · listen = 0
readback()
stoppedState()
restoredEmpty()
write = absent · rename = absent · delete = absent
Before metadata, bytes, and after metadata must agree
The second handle performs lstat → read → stat. Inode, size and digest must remain stable across the read.
| Check | Mechanism | Actual sandbox evidence | Live evidence |
|---|---|---|---|
| Second lstat | regular · no symlink · nlink 1 | 192 PASS | 0 |
| Second read | actual filesystem bytes | 192 PASS | 0 |
| Stable inode | before.ino = after.ino | 192 PASS | 0 |
| Second digest | source = installed = reread | 192 PASS | 0 |
Authorization enters once; an empty root exits once
No stage can authorize activation, network access, secrets or production installation.
Deletion order is the exact inverse of installation
The witness observes the sandbox only after all eight unlinks and ancestor pruning complete.
Failure after any write still returns the root to empty
Thirty injected failures rotate through all eight write positions. Independent-readback tampering adds thirty more rollback paths.
The terminal assertion is directory entries = 0
This is a real readdir of the canonical temporary root—not a counter or mocked restoration claim.
TRANSACTION 8 writes → 8 independent reads → 8 reverse deletes
TERMINAL READ readdir(realpath(root)).length = 0
24 / 24 complete roots restored · all failure roots restored
Installation evidence is deliberately activation-free
The sandbox checks forbidden unit, socket and PID artifacts and exposes no process or listener capability.
Real filesystem I/O does not broaden production authority
Root ownership is explicitly false; the identity file is a virtual descriptor and cannot create a user or group.
| Capability | Sandbox | Production | Truth |
|---|---|---|---|
| File write | temporary root only | denied | JAILED |
| Identity | descriptor bytes | useradd denied | VIRTUAL ONLY |
| Ownership | current sandbox owner | root:991 absent | NOT OBSERVED |
| Activation | capability absent | unauthorized | ZERO |
Six repository gates now bind the real POSIX transaction
They close the sandbox engineering gap without changing the live production gate.
Evidence owners remain separate from production authority
The writer, witness, rollback owner and live installation owner are distinct roles.
| Boundary | May do | May not do | Status |
|---|---|---|---|
| Source registry | provide digest-bound bytes | choose host | BOUND |
| POSIX writer | write jailed temp root | read production or spawn | BOUND |
| Independent witness | lstat/read/stat | write or delete | BOUND |
| Production owner | nothing without live permit | use shared Portal EC2 | HELD |
Interrogate every filesystem failure family
Filter real transactions, path attacks, artifact drift, witness drift, rollback failures and capability abuse. Every case ends with zero production effects.
Only live root:991 installation remains red
Source bytes, path jail, POSIX commit, independent readback, stopped-state and rollback evidence are repository-bound.
Actual operations are counted separately from production effects
This distinction prevents a sandbox success from being mislabeled as a live installation.
Six live fragments remain explicitly owned
These are external evidence dependencies, not missing sandbox implementation.
Next: live stopped-state installation only when all external evidence exists
Cut 83 may claim a dedicated staging host, consume a live one-time permit, install the same eight bytes as root:991, obtain independent readback and rehearse rollback. It still may not install a unit, start Controller, resolve production secrets/data, or bind 8110.