P46 stopped-state filesystem transaction

Write the real files. Read them twice. Delete them in reverse.

Cut 82 moves the installation proof from an executor model into the real POSIX filesystem. Twenty-four isolated roots each receive the identity descriptor, canonical manifest and six client modules, then an independent witness verifies bytes, mode, inode and link count before strict rollback returns the root to empty.

82 / 104global cut
22cuts remaining
24real POSIX roots
192writes / reads / deletes
76 / 77quality gates
0production mutations
01 · Current external red gate

Repository transaction is green; live root installation is not attempted

The only reachable host remains the shared production Portal. Its production marker, 8100 listener and UID/GID 991 collisions make it ineligible.

01
Shared production PortalHost class is not dedicated staging.DENY
UID 991 = redis6Required service UID is not free.COLLISION
GID 991 = nginxRequired service GID is not free.COLLISION
Live permit = 0No four-party production authorization exists.HOLD
02 · Sandbox boundary

Three zones, one deliberately narrow write capability

Source bytes are read from the repository, written only beneath a newly created temporary root, and independently reread without write access. Production stays outside the capability graph.

02

Source registry

IdentityJSON bytes
Manifestcanonical bytes
6 modulesESM source bytes

Isolated POSIX root

Writerwx · fsync · rename
Witnesslstat · read · stat
Rollbackunlink reverse · rmdir

Production host

SSH / SSM0 contacts
root:991not observed
systemd / 8110not authorized
03 · Eight real artifacts

Inspect the exact stopped-state installation set

Select a material to see its fixed target, mode and repeated filesystem evidence. None is a systemd unit, secret, or production configuration value.

03
ARTIFACTDEDICATED_IDENTITY
TARGET/var/lib/reits-runner-factory/.identity.json
PROOF0600 · 24 writes · 24 reads · 24 deletes
04 · Source bytes

Installation begins with repository bytes, not generated placeholders

Every payload is non-empty and SHA-256-bound before the writer receives it.

04
Identity descriptorExact candidate JSON bytes; virtual identity only.
Runtime manifestExact canonical runtime manifest candidate.
Six ESM modulesActual production-client source files.
Digest gatePayload digest must match before any directory is created.
05 · Path jail

Every ancestor is proven before any byte crosses the boundary

The root is canonicalized, every target is fixed and absolute, relative escape is rejected, and each ancestor is lstat-checked as a real directory rather than a symbolic link.

05
01realpath(root)canonical boundary
02fixed target8 exact paths
03relative jailno .. escape
04ancestor lstatno symlink
05prior absentfail closed
06 · Atomic file write

A real six-step POSIX commit for every artifact

Temporary files are exclusive, synced and renamed atomically. The temporary path is removed on every terminal branch.

06
01mkdir 0750parents only
02open wxexclusive temp
03write bytesnon-empty source
04fsyncdurable file
05closehandle sealed
06renamefixed target
07lstat + digestcommit proof
07 · Mode & inode proof

192 materialized files prove more than content

Every install proof binds its target to the filesystem object that was actually created.

07
0600 / 0640 / 0440Exact mode by artifact class.
inode > 0Captured from real lstat metadata.
nlink = 1No unexpected hard-link alias.
regular fileNot symlink, socket, FIFO or device.
08 · Independent witness

The reader cannot write, rename or delete

A separately constructed witness receives only readback, stopped-state and empty-root verification methods.

08
WRITER SURFACE
writeAtomic()
rollback()
close()
network = 0 · spawn = 0 · listen = 0
WITNESS SURFACE
readback()
stoppedState()
restoredEmpty()
write = absent · rename = absent · delete = absent
09 · Actual readback ledger

Before metadata, bytes, and after metadata must agree

The second handle performs lstat → read → stat. Inode, size and digest must remain stable across the read.

09
CheckMechanismActual sandbox evidenceLive evidence
Second lstatregular · no symlink · nlink 1192 PASS0
Second readactual filesystem bytes192 PASS0
Stable inodebefore.ino = after.ino192 PASS0
Second digestsource = installed = reread192 PASS0
10 · Fourteen-stage transaction timeline

Authorization enters once; an empty root exits once

No stage can authorize activation, network access, secrets or production installation.

10
01Bind Cut 81fixture receipt
02–05Root + sourcesvalidate
06–07Write + prove8 files
08Readbacksecond handle
09Stoppedno activation
10–12Reverse + emptyrestore
13–14Seal + holdlive root red
11 · Strict rollback

Deletion order is the exact inverse of installation

The witness observes the sandbox only after all eight unlinks and ancestor pruning complete.

11
01ReadinessKeydelete
02Journaldelete
03Runnerdelete
04Workerdelete
05Capacitydelete
06Reservationdelete
07–08Manifest · identitydelete last
12 · Partial failure containment

Failure after any write still returns the root to empty

Thirty injected failures rotate through all eight write positions. Independent-readback tampering adds thirty more rollback paths.

12
30 write failuresEach installed prefix reversed.
30 readback driftsTampered bytes fail independently.
0 temp residueTerminal cleanup is unconditional.
0 root residueEvery injected failure restores empty.
13 · Prior-state restoration

The terminal assertion is directory entries = 0

This is a real readdir of the canonical temporary root—not a counter or mocked restoration claim.

13
PRIOR STATE empty root
TRANSACTION 8 writes → 8 independent reads → 8 reverse deletes
TERMINAL READ readdir(realpath(root)).length = 0
24 / 24 complete roots restored · all failure roots restored
14 · Stopped-state firewall

Installation evidence is deliberately activation-free

The sandbox checks forbidden unit, socket and PID artifacts and exposes no process or listener capability.

14
Service unit · 0Not part of artifact set.
Socket unit · 0No listener activation.
PID / process · 0No spawn capability.
8110 · 0No bind or request capability.
15 · Capability boundary

Real filesystem I/O does not broaden production authority

Root ownership is explicitly false; the identity file is a virtual descriptor and cannot create a user or group.

15
CapabilitySandboxProductionTruth
File writetemporary root onlydeniedJAILED
Identitydescriptor bytesuseradd deniedVIRTUAL ONLY
Ownershipcurrent sandbox ownerroot:991 absentNOT OBSERVED
Activationcapability absentunauthorizedZERO
16 · P46A–F subgates

Six repository gates now bind the real POSIX transaction

They close the sandbox engineering gap without changing the live production gate.

16
P46A · Path jailrealpath + no symlink.BOUND
P46B · Atomic byteseight exact writes.BOUND
P46C · File proofmode/inode/link/digest.BOUND
P46D · Readbacksecond-handle evidence.BOUND
P46E · Stoppedno unit/process/listener.BOUND
P46F · Restorestrict reverse to empty.BOUND
17 · Trust boundary matrix

Evidence owners remain separate from production authority

The writer, witness, rollback owner and live installation owner are distinct roles.

17
BoundaryMay doMay not doStatus
Source registryprovide digest-bound byteschoose hostBOUND
POSIX writerwrite jailed temp rootread production or spawnBOUND
Independent witnesslstat/read/statwrite or deleteBOUND
Production ownernothing without live permituse shared Portal EC2HELD
18 · 168-case executable QA lab

Interrogate every filesystem failure family

Filter real transactions, path attacks, artifact drift, witness drift, rollback failures and capability abuse. Every case ends with zero production effects.

18
168 / 168
19 · 76 / 77 quality gates

Only live root:991 installation remains red

Source bytes, path jail, POSIX commit, independent readback, stopped-state and rollback evidence are repository-bound.

19
Q01–Q21Auth · path · sourcebound
Q22–Q35Atomic file proofbound
Q36–Q49Witness · stoppedbound
Q50–Q61Rollback · receiptbound
Q62–Q76Truth · suitebound
LIVE P46root:991 host installnot observed
20 · Filesystem metrics

Actual operations are counted separately from production effects

This distinction prevents a sandbox success from being mislabeled as a live installation.

20
24 rootsComplete real transactions.
192 writes8 per complete transaction.
192 readbacksIndependent second handle.
192 deletesStrict inverse order.
168 / 168New QA cases.
1,544Cumulative regressions.
248Architecture invariants.
0 live installsTruthfully still held.
21 · Visible integration debt

Six live fragments remain explicitly owned

These are external evidence dependencies, not missing sandbox implementation.

21
01 · Dedicated hostSigned non-production instance with free 991:991.
02 · Live permitFour-party one-time authorization.
03 · root:991 ownershipReal live uid/gid and modes.
04 · Eight live filesStopped-state target installation.
05 · Live readbackSeparately credentialed witness.
06 · Live rollbackPrior-state restoration receipt.
22 · Cut 83 handoff

Next: live stopped-state installation only when all external evidence exists

Cut 83 may claim a dedicated staging host, consume a live one-time permit, install the same eight bytes as root:991, obtain independent readback and rehearse rollback. It still may not install a unit, start Controller, resolve production secrets/data, or bind 8110.

22
0qualified live hosts
0live permits
0host contacts
0host mutations
0service starts
08110 listeners