P47 detached stopped-state execution package

Seal the exact bytes. Transfer offline. Decode once. Never activate.

Cut 83 packages the identity descriptor, canonical root manifest and six production-client modules as real embedded bytes. A content-addressed P-256 seal binds target, source, authorization, TTL, nonce, argv-only execution and reverse rollback. Twenty-four full roundtrips decode into the real Cut 82 POSIX transaction; the shared Portal host stays denied.

83 / 104global cut
21cuts remaining
24signed roundtrips
192embedded / decoded
82 / 83quality gates
0production effects
01 · current external red gate

The package is real; the production consumer is not

Repository evidence closes the transferable execution-package boundary. Production still lacks every external fact required to consume it safely.

01
P47_LIVE_DEDICATED_HOST_PACKAGE_CONSUMPTION_ROOT_991_INSTALL_READBACK_ROLLBACK

0 qualified hosts · 0 live permits · 0 production key resolvers · 0 installed privileged consumers · 0 root:991 observations · 0 live receipts

decision = HOLD sharedPortalHost = DENY productionHostContacts = 0 productionHostMutations = 0
02 · package boundary

Packaging, transfer, consumption and activation are four separate authorities

Cut 83 closes the first three only in repository and isolated POSIX contexts. It grants no production installation or activation capability.

02
01 · PACKAGECanonical bytes8 exact payloads
02 · SEALP-256 verifyrelease authority
03 · TRANSFEROffline custodyTTL + nonce
04 · DECODEOne-use handledigest recheck
05 · INSTALLDedicated hostnot connected
06 · ACTIVATEsystemd / 8110explicitly forbidden
03 · trust chain

Every handoff has a distinct owner, object and control

No single actor can package, consume, witness and roll back the installation.

03
AuthorityObjectControlCurrent evidence
Cut 81 auth brokerauthorization receipt4-role approval digestfixture bound
Source registry8 repository payloadsSHA-256 bytesreal bytes
Release packagingcanonical capsuleP-256 seal156 verifies
Offline custodyopaque packageTTL + nonceone-use model
Privileged consumerdecoded argv planallowlistnot installed
Independent auditorreadback proofseparate key / handlesandbox only
Rollback ownerprior-empty receiptreverse unlinksandbox only
04 · target binding

The capsule names one dedicated stopped staging host

Hostname, instance, environment, class, markers, listeners, IDs and prior state must equal the signed authorization.

04
HOST CLASSDEDICATED_NON_PRODUCTION_CONTROL_PLANE

Shared Portal classes fail before packaging.

IDENTITYUID 991 = FREE · GID 991 = FREE

Both numeric identities must be unallocated.

PRIOR STATEidentity / manifest / modules / unit = ABSENT

Process and 8110 counts must also be zero.

LIVE INVENTORY0 qualified hosts

Repository target is a signed fixture, not a live claim.

05 · current shared EC2 denial

The Portal host fails four independent target predicates

Cut 83 rechecked the currently deployed EC2 before implementation. Controller artifacts remain absent.

05
ip-172-31-19-46.ap-southeast-2.compute.internalDENIED
Source commit
41972658…
Portal service
active
Production marker
PRESENT
Port 8100
1 listener
UID 991
redis6
GID 991
nginx
Controller artifacts
0
Port 8110
0
PRODUCTION_HOST_MARKER_PRESENT/etc/reits-production-hostBLOCK
PORTAL_LISTENER_8100_PRESENTshared live trafficBLOCK
UID_991_OWNED_BY_REDIS6identity collisionBLOCK
GID_991_OWNED_BY_NGINXidentity collisionBLOCK
06 · authorization binding

The package can only inherit the authority it was given

The Cut 81 receipt is fixture-only and explicitly says productionInstallAuthorized=false and livePermitIssued=false. Cut 83 preserves both values.

06
AUTHORITY APPROVALS4 / 4 digest-bound

Platform SRE · Release · Security · Independent auditor

ARTIFACT BINDINGS8 / 8 exact

Target path, mode and source digest stay fixed.

LIVE AUTHORITYfalse / false

No production install and no live permit.

07 · source lineage

Two commits and one artifact-set digest survive the transfer

The capsule keeps release policy lineage distinct from installation-source lineage.

07
Release source41972658d4ad2c6a93fc26e4d660d1c5dad72dd2CUT 82
Installation source9214f9f46bafd5cd75276a44bbbe441a4449c177BOUND
Artifact setsha256: authorization-bound exact 8-item setREHASH
08 · eight embedded payloads

Inspect the payload ledger that actually crosses the offline boundary

Select an artifact to inspect target, mode, source, byte treatment and execution contract.

08
SELECTED PAYLOAD

DEDICATED_IDENTITY

Target path
/var/lib/reits-runner-factory/.identity.json
Mode
0600
Encoding
base64url
Owner
991:991
Digest
SHA-256 recomputed after decode
Production state
NOT INSTALLED
write-atomic --target /var/lib/reits-runner-factory/.identity.json --mode 0600 --owner 991:991 --digest sha256:<exact-source-bytes>
09 · package anatomy

Ten sections form one content-addressed capsule

The signature covers the canonical core; payload bodies are inside that core, not fetched later.

09
AUTHORIZATIONReceipt + approvals

Cannot increase inherited authority.

TARGETHost + instance + stopped profile

Exact authorization match.

SOURCE2 commits

Release and installation lineage.

WINDOW≤ 300 sec

Issued, expires, rollback 120 sec.

CUSTODYNonce + 2 key IDs

Packaging and witness separated.

CONSTRAINTS991:991 · prior absent

No unit, secret, config or activation.

ARTIFACT PAYLOADS8 real base64url bodies

ID, path, mode, byte length and SHA-256 for every source.

EXECUTION PLAN8 argv operations

One allowlisted program; no shell.

ROLLBACK PLAN8 reverse unlinks

Terminal state ABSENT.

SEALPackage digest + P-256 signature

Verified before projection and again after transfer.

10 · byte budget

Payload size is a security boundary, not a dashboard metric

Each payload is capped at 128 KiB and the complete embedded byte set at 1 MiB. No NUL byte is admitted.

10
actual repository source set · within bounded envelopehard cap · 1,048,576 bytes
ARTIFACT CAP131,072 bytes

Enforced before canonicalization.

PACKAGE CAP1,048,576 bytes

Enforced before signing and after decode.

BYTE RULEnon-empty · no NUL

Digest must equal the original source bytes.

11 · canonical serialization

The same object always produces the same package digest

Object keys are sorted recursively; arrays preserve fixed artifact and rollback order.

11
canonical(core) → sort object keys recursively → preserve 8-artifact order → preserve 8-stage reverse rollback → SHA-256 exact UTF-8 bytes → packageDigest
sealed fields schemaVersion packageDigest keyId issuedAt / expiresAt nonce signature (outside digest payload)
12 · P-256 seal

A verify-only signer boundary seals package content and custody

The implementation accepts only a one-method verification surface. No private key, secret resolver or network client exists in the candidate.

12
P-256
PASS
Algorithm
ECDSA P-256 · SHA-256 · ieee-p1363
Verification calls
156 real repository calls
Package digest
sha256:<canonical capsule core>
Key separation
packagingKeyId ≠ witnessKeyId
Private keys in candidate
0
Production key resolvers
0 · external gap
13 · offline custody

Transfer does not mean trust: the receiver replays every proof

The capsule is self-contained. It needs no source checkout, package registry, object store or secret fetch.

13
PACKAGEREmbed bytessource checkout
SEALSign digestrelease key
CUSTODYOpaque transferTTL + nonce
RECEIVERRehash + verifypublic key
DECODEOne projectionexact bytes
LIVE INSTALLNot authorizedexternal gate
14 · consumer verification pipeline

Eleven fail-closed stages stand between receipt and decoded bytes

No operation plan is projected until shape, digest, TTL, signature, nonce and all eight payloads pass.

14
01RECEIVEopaque capsule
02SHAPEexact core + seal
03DIGESTcanonical rehash
04FRESHinside TTL
05P-256verify seal
06REPLAYconsume nonce
07DECODE8 base64url
08REHASH192 proofs
09ARGVallowlist
10ROLLBACKreverse order
11PROJECTone handle
15 · argv-only execution plan

The package carries operations, never a command string

All 192 planned operations use the same absolute allowlisted program. Shell evaluation, interpolation, service activation and dynamic owner values are structurally absent.

15
program = /usr/local/libexec/reits-runner-factory/install-stopped-state-artifact argv = [ "write-atomic", "--target", "/etc/reits-runner-factory/controller-runtime.json", "--mode", "0640", "--owner", "991:991", "--digest", "sha256:<bound>" ] stdin = PAYLOAD_BYTES
ARGV OPERATIONS192

8 per signed roundtrip.

SHELL STRINGS0

No sh, bash, eval or interpolation.

PROGRAMS1 allowlisted

Absolute path only.

ACTIVATIONforbidden

No unit, start or 8110.

16 · decoded POSIX roundtrip

Decoded package bytes drive the real Cut 82 transaction

This is an integration proof, not a serialization-only test: every complete package writes, rereads and deletes all eight decoded artifacts in a real temporary filesystem root.

16
SIGNED PACKAGES24P-256 sealed
EMBED / DECODE192 / 192exact bytes
WRITE / READBACK192 / 192real POSIX
DELETE / EMPTY ROOT192 / 24strict reverse
CAPSULEVerifydigest + P-256
PAYLOADSDecode8 exact bytes
FILESWritewx + fsync + rename
WITNESSRereadlstat/read/stat
ROLLBACKDeletereverse 8
TERMINALEmpty24 / 24 roots
17 · independent witness

The witness key and filesystem handle are both separated

Cryptographic separation protects package custody; read-only filesystem separation protects the installed byte proof.

17
KEYwitnessKeyId ≠ packagingKeyId

Package validation rejects equality.

SURFACEreadback · stoppedState · restoredEmpty

No write method exists.

PROOFinode · size · link · mode · digest

Before and after stat must be stable.

LIVE WITNESSnot bound

Production public key and receipt remain external.

18 · rollback contract

Rollback order is packaged, signed and verified before decode

The consumer cannot choose a different rollback sequence. Every item declares expected terminal state ABSENT.

18
01–06ReadinessKeyClient → Journal → Runner → Worker → Capacity → ReservationREVERSE
07ROOT_MANIFESTUNLINK
08DEDICATED_IDENTITYUNLINK
Deadline120 seconds from admitted package windowBOUND
19 · stopped-state firewall

The package excludes everything that could activate Controller

These are structural zeroes in both capsule and receipt.

19
SYSTEMD UNIT0

Not a payload.

SECRET VALUES0

No credentials or private keys.

PRODUCTION CONFIG0

Only references in source manifest.

SHELL0

Argv arrays only.

PROCESS0

No spawn primitive.

SERVICE START0

Authority false.

LISTENER0

Authority false.

PORT 8110 CALL0

Capability absent.

20 · P47A–F subgates

Six repository gates close; the live gate remains singular and visible

Each subgate is executable and represented in the machine-readable admission contract.

20
P47A · PAYLOAD

8 source bytes, paths, modes, sizes and digests.

P47B · CUSTODY

Target, authorization, source, window, nonce and rollback.

P47C · SEAL

Canonical content address and real P-256 verification.

P47D · EXECUTION

Exact allowlisted argv-only operation plan.

P47E · CONSUMER

One-use decode and independent witness separation.

P47F · ROUNDTRIP

Decoded bytes write, reread, reverse and restore.

21 · 180-case executable QA lab

Interrogate the package, seal, consumer and POSIX roundtrip

Filter six real fixture families. Every case exposes zero production contacts, mutations, service starts and listeners.

21
180 / 180
22 · 82 / 83 quality gates

Only live dedicated-host package consumption remains red

Package bytes, P-256 seal, offline custody, argv-only consumer and decoded POSIX roundtrip are repository-bound.

22
Q01–Q30Auth · target · windowbound
Q31–Q46Payload · digest · sealbound
Q47–Q63Argv · one-use · receiptbound
Q64–Q76POSIX · zero effectbound
Q77–Q82P47 package closurebound
LIVE P47Dedicated host consumptionnot observed
23 · visible integration debt

Six external facts still block live consumption

None can be fabricated from this repository or the current shared EC2.

23
TARGET_HOST_QUALIFIERDedicated host · 0Needs a reachable signed staging claim.
CUT81_AUTH_BROKERLive permit · 0Needs four-party one-time authorization.
SECURITY_REVIEWERProduction keys · 0Needs packaging and witness public-key resolvers.
PRIVILEGED_CONSUMER_OWNERConsumer install · 0Needs out-of-band installation, not this package.
INSTALLATION_OWNERroot:991 · not observedNeeds a collision-free target and ownership proof.
READBACK_AUDITORLive terminal receipt · 0Needs install, readback and restoration evidence.
24 · Cut 84 handoff

Next: qualify the detached consumer and external replay registry

Cut 84 must turn the current in-process consumer model into exact installable port contracts without contacting a live host or widening stopped-state authority.

24

CUT 84 · PRIVILEGED CONSUMER PORT & REPLAY REGISTRY PRE-ADMISSION

  • Define exact package input, public-key resolver, durable nonce registry and argv executor ports.
  • Bind consumer binary/source digest and out-of-band installation contract.
  • Prove crash recovery between nonce consumption, partial write and reverse rollback.
  • Keep systemd unit, service start, listener and 8110 outside the authority envelope.