Cut 83 packages the identity descriptor, canonical root manifest and six production-client modules as real embedded bytes. A content-addressed P-256 seal binds target, source, authorization, TTL, nonce, argv-only execution and reverse rollback. Twenty-four full roundtrips decode into the real Cut 82 POSIX transaction; the shared Portal host stays denied.
Repository evidence closes the transferable execution-package boundary. Production still lacks every external fact required to consume it safely.
0 qualified hosts · 0 live permits · 0 production key resolvers · 0 installed privileged consumers · 0 root:991 observations · 0 live receipts
Cut 83 closes the first three only in repository and isolated POSIX contexts. It grants no production installation or activation capability.
No single actor can package, consume, witness and roll back the installation.
| Authority | Object | Control | Current evidence |
|---|---|---|---|
| Cut 81 auth broker | authorization receipt | 4-role approval digest | fixture bound |
| Source registry | 8 repository payloads | SHA-256 bytes | real bytes |
| Release packaging | canonical capsule | P-256 seal | 156 verifies |
| Offline custody | opaque package | TTL + nonce | one-use model |
| Privileged consumer | decoded argv plan | allowlist | not installed |
| Independent auditor | readback proof | separate key / handle | sandbox only |
| Rollback owner | prior-empty receipt | reverse unlink | sandbox only |
Hostname, instance, environment, class, markers, listeners, IDs and prior state must equal the signed authorization.
Shared Portal classes fail before packaging.
Both numeric identities must be unallocated.
Process and 8110 counts must also be zero.
Repository target is a signed fixture, not a live claim.
The Cut 81 receipt is fixture-only and explicitly says productionInstallAuthorized=false and livePermitIssued=false. Cut 83 preserves both values.
Platform SRE · Release · Security · Independent auditor
Target path, mode and source digest stay fixed.
No production install and no live permit.
The capsule keeps release policy lineage distinct from installation-source lineage.
41972658d4ad2c6a93fc26e4d660d1c5dad72dd2CUT 829214f9f46bafd5cd75276a44bbbe441a4449c177BOUNDsha256: authorization-bound exact 8-item setREHASHSelect an artifact to inspect target, mode, source, byte treatment and execution contract.
The signature covers the canonical core; payload bodies are inside that core, not fetched later.
Cannot increase inherited authority.
Exact authorization match.
Release and installation lineage.
Issued, expires, rollback 120 sec.
Packaging and witness separated.
No unit, secret, config or activation.
ID, path, mode, byte length and SHA-256 for every source.
One allowlisted program; no shell.
Terminal state ABSENT.
Verified before projection and again after transfer.
Each payload is capped at 128 KiB and the complete embedded byte set at 1 MiB. No NUL byte is admitted.
Enforced before canonicalization.
Enforced before signing and after decode.
Digest must equal the original source bytes.
Object keys are sorted recursively; arrays preserve fixed artifact and rollback order.
The implementation accepts only a one-method verification surface. No private key, secret resolver or network client exists in the candidate.
The capsule is self-contained. It needs no source checkout, package registry, object store or secret fetch.
No operation plan is projected until shape, digest, TTL, signature, nonce and all eight payloads pass.
All 192 planned operations use the same absolute allowlisted program. Shell evaluation, interpolation, service activation and dynamic owner values are structurally absent.
8 per signed roundtrip.
No sh, bash, eval or interpolation.
Absolute path only.
No unit, start or 8110.
This is an integration proof, not a serialization-only test: every complete package writes, rereads and deletes all eight decoded artifacts in a real temporary filesystem root.
P-256 sealedexact bytesreal POSIXstrict reverseCryptographic separation protects package custody; read-only filesystem separation protects the installed byte proof.
Package validation rejects equality.
No write method exists.
Before and after stat must be stable.
Production public key and receipt remain external.
The consumer cannot choose a different rollback sequence. Every item declares expected terminal state ABSENT.
ReadinessKeyClient → Journal → Runner → Worker → Capacity → ReservationREVERSEROOT_MANIFESTUNLINKDEDICATED_IDENTITYUNLINK120 seconds from admitted package windowBOUNDThese are structural zeroes in both capsule and receipt.
Not a payload.
No credentials or private keys.
Only references in source manifest.
Argv arrays only.
No spawn primitive.
Authority false.
Authority false.
Capability absent.
Each subgate is executable and represented in the machine-readable admission contract.
8 source bytes, paths, modes, sizes and digests.
Target, authorization, source, window, nonce and rollback.
Canonical content address and real P-256 verification.
Exact allowlisted argv-only operation plan.
One-use decode and independent witness separation.
Decoded bytes write, reread, reverse and restore.
Filter six real fixture families. Every case exposes zero production contacts, mutations, service starts and listeners.
Package bytes, P-256 seal, offline custody, argv-only consumer and decoded POSIX roundtrip are repository-bound.
None can be fabricated from this repository or the current shared EC2.
Cut 84 must turn the current in-process consumer model into exact installable port contracts without contacting a live host or widening stopped-state authority.