{"type":"message","id":"0ed702e4","parentId":"16a56c60","timestamp":"2026-09-13T15:12:43.715Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Preparing the command fixture**\n\n**Adding EnvironmentFile support**"},{"type":"toolCall","id":"call_x0jomwBGNd2dg12xXAaJ85XI|fc_0e1539855bae2fa9016aa6bd5175f087d1a2712b163c3fa162","name":"eval","arguments":{"language":"py","code":"djn_prep=(m_base/'prep-ZFZISUHJ.ps1').read_text()\ndjn_prep=djn_prep.replace('ZFZISUHJ','DJNQQ2RA').replace('[Parameter(Mandatory=$true)][string]$RigRoot)', '[Parameter(Mandatory=$true)][string]$RigRoot,\\n      [Parameter(Mandatory=$true)][long]$Deadline)')\ndjn_prep=djn_prep.replace('1789311857-[DateTimeOffset]', '$Deadline-[DateTimeOffset]')\ndjn_prep=djn_prep.replace(\"-Scope step -Admission process-tree -Exe $Exe\", \"-Scope step -Admission process-tree -EnvironmentFile (Join-Path $OutputRoot 'capture-environment.json') -Exe $Exe\")\ndjn_prep=djn_prep.replace(\"Save (Join-Path $OutputRoot 'invocation.json')\", \"Save (Join-Path $OutputRoot 'capture-environment.json') @{}\\nSave (Join-Path $OutputRoot 'invocation.json')\")\ndjn_prep=djn_prep.replace(\"budget_seconds=600;field_main_executed\", \"deadline=$Deadline;budget_seconds=600;field_main_executed\")\ndjn_fixture=b'OHABRPAJ native launcher Get-FileHash positive control\\n'\ndjn_fixture_hash=hashlib.sha256(djn_fixture).hexdigest()\ndjn_control=\"\"\"# OHABRPAJ: one no-field positive control in the exact capture launcher shape.\n$fixture=Join-Path $OutputRoot 'capture-fixture.txt'\n[IO.File]::WriteAllBytes($fixture,[Text.Encoding]::UTF8.GetBytes(\"OHABRPAJ native launcher Get-FileHash positive control`n\"))\n$fixtureLiteral=$fixture.Replace(\"'\",\"''\")\n$controlCode='$ErrorActionPreference=\"Stop\"; $resolved=Get-Command Get-FileHash -ErrorAction Stop; $hash=(Get-FileHash -LiteralPath ''{0}'' -Algorithm SHA256).Hash.ToLowerInvariant(); if($hash -cne ''{1}'') {{ throw \"FIXTURE_HASH_MISMATCH\" }}; [ordered]@{{command=$resolved.Name;module=$resolved.ModuleName;fixture_sha256=$hash;result=\"GET_FILEHASH_CONTROL_PASS\"}} | ConvertTo-Json -Compress; exit 0' -f $fixtureLiteral,'HASH'\nRunRead 'get-filehash-control' $pwsh @('-NoProfile','-Command',$controlCode) 30\nif($results[$results.Count-1].native_exit -ne 0) {throw 'GET_FILEHASH_CONTROL_REFUSED'}\n$controlRecord=Get-Content -Raw -LiteralPath (Join-Path $OutputRoot 'get-filehash-control/record.json') | ConvertFrom-Json\nif($controlRecord.coverage -ne 'COMPLETE' -or $controlRecord.subject.native_exit -ne 0 -or -not $controlRecord.job.assigned -or -not $controlRecord.job.membership_read -or -not $controlRecord.job.kill_on_close_read -or $controlRecord.job.active_processes -ne 0) {throw 'GET_FILEHASH_CONTROL_OWNERSHIP_REFUSED'}\n$controlValue=Get-Content -Raw -LiteralPath (Join-Path $OutputRoot 'get-filehash-control/stdout.txt') | ConvertFrom-Json\nif($controlValue.result -cne 'GET_FILEHASH_CONTROL_PASS' -or $controlValue.fixture_sha256 -cne 'HASH') {throw 'GET_FILEHASH_CONTROL_RESULT_REFUSED'}\n\"\"\".replace('HASH',djn_fixture_hash)\n# Replace only placeholder tokens: HASH substitution above must not rename the marker.\ndjn_control=djn_control.replace('GET_FILE'+djn_fixture_hash,'GET_FILEHASH').replace('FIXTURE_'+djn_fixture_hash,'FIXTURE_HASH')\ndjn_prep=djn_prep.replace(\"RunRead 'host'\",djn_control+\"RunRead 'host'\",1)\nassert '1789311857' not in djn_prep\n(m_base/'prep-DJNQQ2RA.ps1').write_bytes(djn_prep.encode())\ndisplay({'fixture_sha256':djn_fixture_hash,'script':str(m_base/'prep-DJNQQ2RA.ps1'),'sha256':hashlib.sha256((m_base/'prep-DJNQQ2RA.ps1').read_bytes()).hexdigest(),'executed':False})","title":"Preparing the single fresh admission with the pinned no-field hash control","timeout":20,"reset":null},"intent":"Preparing the single fresh admission with the pinned no-field hash control"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":14751,"output":1522,"cacheRead":59392,"cacheWrite":0,"totalTokens":75665,"reasoningTokens":516,"cost":{"input":0.14751,"output":0.0761,"cacheRead":0.059392,"cacheWrite":0,"total":0.283002}},"stopReason":"toolUse","timestamp":1789312316226,"responseId":"resp_0e1539855bae2fa9016aa6bd3c8c2887d1997792bcdbb8d584","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_0e1539855bae2fa9016aa6bd3de44c87d186e89c93abaf791e","type":"reasoning","content":[],"encrypted_content":"gAAAAABqpr1Rteu5spgBXyRcMSezPQGG2v9tzrUNAaVPJ7l2Wt8X1-XEA5uqxxQgkIDFzEiymSBv_oD85IRkuvZSBVACJvd4VRPrOYh8TUZLzzAl9G_9tzgCP9HZ27PZp5Z31UUYE9HqqvDRG3KUQtkddGvgMEfds0-YLf6F_3xrziv0zNbhd-KtCTJdEUoaIb7GWGFLTCUiH-hA9bewH35Flrk_vH22cYP0xsgGJSWsty4jw2RdKYX6Vp-_LBJ5AOWHum3ZWv6AtVL-IqFcEG8guyawDYe9b3R_BuCe7BLf676KPx3mQwkOEaMKQ617_2XtGRJgsDdxHpbADmFXItd61m46k5uLz558wuVlwYpislD7PPvkYBnF3DehsCMKn0CmudHpXGLor7uQHxeNC6nZRAjoz-EAtveEUHzQ2g1hJY-UHWiOeo5rzgpVvjhtaEQ6pGCxhLV7nVb7N_5rJR0266klZmT3W1A_hpqsbnTUh9bdmD9OcHX540fbZqgY2jLjCi8vT4wA_WM1EY-_CXVZlvlBNp0dnhR__tEO3bRVXw7jx_KRFFMsIrvd9efLBM-bmfLAclsi38eLZMZcyygzvf_WFk4hE9nGAbjxXjHIRSFMOnCML6pak4VcKJnrxPBTHMxid10pRWozunyzTaXePxw7Vq-DibX55ZyjpPFziZjfk-Tql7lwgyhYzo7X1GsOrbTHDeJGEHC6Y1hLVBLA3VRX4XLfW3xYX7Xw7iVnMrFAS79Z_quTFpYZWLGPw0A53Bv5YU0Y6P3Op6xnUZ659yBx4ZIm8dRsw6yhqeg8ebTUg8gWjwIAxpzG4juqgoKXlVpy1iEWvx7AKiassZ0o-YBHZhfd3Kh0AEar29lJFqXspwHNLo2zXfoCc5AhEhJ8V3ackfus-gEdXbWEKGUs_z-4S5PcMr-YGXZvEXoP49UxxSquw25nyVtKQEUQGsM7tfK8IN8HhdFdvECZ44hdu19_vbCJx-DeFPWCjE6BlPty0VSgSJR16zEXo_ICKk8kT2QDIu2U7y3D1367WucCHhgdt6ZSIfRVZwdEIYkvLGepXTilFs55oMeGEKQ9uWS6dbxpZ6biOlQgUz6T1bFfvjedH2es-SF-_rIv1PUKz0b45UYRkxf0diL1KMT6J60mb81LiZdlBG8vOdA4RhvGnrx6dymxnbepDsmNQJ8Oi1IQdVcE3kcOkA_F9anPdPWvhBZBKhs1tsPqaWt829tsB6LAGf0P72ngEc3Ud-BQlQbsrgjmjjgEMfEZsi_WJTipgVCBNDD9UTNjG4lmUav7oiScr5f7gzbZqxWBIUqYQ0FMZMbaQKvU4TpPH_BXsOI_8xdPl4SoA5A7V7O-3SrX0gNuv3JdPUv6zmAkD7pxNANh6UhAcCnzS8Eej6BovEIbOs33LwKoVy6jHQ7Zz6aXX37WshqAWkQaODVrk9qyt6XtWKMukwNw314zXdQ29u5vAOXByzomb9OHsoG1fyxfEdloDZbq_7LDrIFXmUPiB6neWLiPd_JJXLaTSfqY8sCzxmqbS6cgPHgtt-zfurBb2Jytj6UpYoif-4AYnEp-NQqW4Xl6BEvtLLKj-JnKtRoTpw6Z4BdSA9mVhoKLd5j1TyMUpQsBqbf6Ju0N7WGzXUuHM5564qlcZ6fk5W1EBFlTsuHVzf1FtLvHBVobbPkgmzzSPqJZ_c39D3QUkTtc3lBY0bEPAvddRAipEBHfmHIog3MToJ-ixn7z21c5_mRZVecKX4HFuaPnL-d0f3EOdxoM-nAUl3uhBDND1EN93vtggltYnlXM4lbvj1oRFNlsjEsifVO_F7iIbOxF9Kr1IZzBqgyHKYcajC2ozPF7sSPvaCYEC4KxOnOF6BA1PonsxDHLuVxkq2K2kUnCeMsxMxmk7NBsPpskC5yC4E32MRtBBuvx3e73_r16o4nwZUgjOwdWYBO6yr95-gpuK2F_nNRQNt__33noH0ge1MQ25AuO3jDsgJutoVnpBPwmrnrn8DaQiIYZaTz-AuyoUoZgk9vthJH3TKi3bu9k6dmGVLVWyLTd52QZZyKkoRbaNO_gNKXpH2gdbXd-ExGBph7mC-ce_rDFSbR_eE2co_Iq-AXkiHuNDIS1PSgYOhaDne_TrDB5Cr-rGMms4kGksQGSakYIY3Kxr8mCyjBHahe-iFHLDEoF1w-qWhFz2Jc9gP_8wUuRydLW9gkH_WS9bNc238W4IhsidOkawx4fmsGwUCuveIUrYhNV4mA8qrn6TiGHE6OmTwwUot7VbjLAhf2kgq4PEA1Cnagp57qLNo9iyhbwkI2J0X5iLissqeV0-kNkBPwt20uxxgVgogAYHvAf5uFF5H95YHkFbH2ys-dskAZiD3xcWrf7bVk8LHa7DBXhDA9XUE2YCd7JANik6lfNb0RjGsyadQO8UH7LA2Z5U1rfcxiPlVVIO-uKPLgYcsH66tMoZj-9YKYH7CyggPz5_SFrIx-HOrY2MekJvV2OUKXiXlf9D2OqX7gQefI5ee7cVOIsoMgtPhjb2v_8ilN2xBlNOgR8T3bcFEaFA4YmbA6tyuIW2-NyAuBqBdjfLPJKHctgSfayZhFJ8x0KqFrycvFP9eI1_Zzrpf-BFItKaCvcLNVzvdd6_I4o5Co89X-8LNyIzYubStWjvuZfZF6q7dXuvUCQHYbzVXN65jdUZg-IgjWLRziYkb5idzG3PVHNXT3GPVEHJS-8eOZymYYfvZTWp4AIz0Nk4e7sd6TXwZXb4eQkY-ZStVNBh1Z6-wBi7aYI4q1Ksgjw0DN2XlCAyNYxOyMUJ3-AO4-J5vZBrHOQWBZeX9FAjJjk1FBreCXjyJuldIpT-GtMPICUxlLTYVXsmTQp5oX4We4ANQ_rhaNkFf-lVMavdEVoBjrDQmXyGc0E56sOgGlkGcbiG5MUf3ael3yr5gUER7bhplOrLENt-7XSQlYr0KP6aZ7p6rL-qJk1-5sYhoxthsvDb7JeBx43IBphMgTuOYHhC90G326nlJljr_BWnDr46EJp212-lH3wUnjfuA5IA_ZhtcCPqD_Swca1EB3rdWsu-9pz4wHuBDS2l1w0hCKnPrX9tnxJcZ2WQOEFV2M0-vJmiV5evw4VvhKkKIJ4ogMkN9IOYc1HDVx3bdwmyKNpi8yhl76S5dVwoYxcFYOhUH12JVi8yij34FKQfagUaqumBlqum4_AoPf7j8JMLCj_7AoNKQj63vaqK5fvGZ4s5sXgxgVx-3o3OfWjlcBDhIA7qNb3mH6Cvyv3MrxJdQ2lQKVbcSPEzlL27V7b6xVDhE0gL0fJp5AdpW_pkXIrhUNdhk-4GlPflAOy7ugurIFY9j7KrNpRlBysFKEtzJyuBPQjXtx6VMczCCw7uSVqbY7DA3lHaB-c4EcvYcUhm9bWMuyVGmyLMteIZCF6YO3TYjy-MD6FbP9y98bZ0rerU9F4EgsSmQnrU00wELalH-BzIWZ_HcF_40xQFPs9sfly-hInOgC5gPjZHlTzF4XBwHGNEKD90zdcYElbK_NvJ0JumPw11nprQnl08UJaxqA_F0T8nO3395NFw-291UtS6u07QvhzuxDZosNMSsgHl0K9xCi2fro-pH9IVtyhOwwLvlfkIKq1ix-5RfiQnfl9Abb03PIa-wAqN6qEhlkNInqNkGxW3qKUk8Td0dt1gxM-l8LhVsbgUhyc-vbjkixrd4b3eHXSUmA87rkeEleGNCzeAG6KZTt8H1pGK8KJAeCeezdpRrri9INzctUhvO_lhmG03M_D8tUVA83iHF8UyMXu165ltb6mLAKQs8U4WSfzX4BYIZWmH6lohy3Xz2_AroT8ZYYG7sPUFcjBGRvcVe7C5kpPMJWjR8gtmSxhc-O_WjRyD2NxPyO5CAp_wokSI0Xk6SrStRy6wfgDDFX-Wz0lGSc67g9-qy1EIWsFZzQpEnzyXj_nQK-pCrGvOabNo9Ycwcnl8Gwe1330QA9HVNgv1n2g2cp159kYX4o7NCRHoNbZ2TDNI1v05CnLUSFdvPS0ZG415H_XYiz-yupORPBt4PP9KAsIuFr1Yh4NqEfvw-GaC-oyd-lWkDvyKC5B9cBcTSdaQgHESN1dmC080GPfBf9s7xq7OSdpGPis56d1sBfIjde0-YRAMG2rnOiBhfKg1uNbWT-m8_RoJx857oifDJLjuwx4dl-Vn2rIkISf-cR05_T2CmbaXu9xbDDCAaApkUi8Xelz7p4xr02H7zLHaB2JaBdJYcHhpegp02SL4bugn9VMNbPgrS1DuHeJ-Q3bi58qLOLxBgIygFSpo0NTLMY5EMR8OhIufPvS41e2EfDRi2nrE4yOczX7LmtRqKszHprydNsYN6pEeBkOLpyVZqaXoruhB34nxYGFQ7_EyVucnWy5xsS8mHju79RxaIYjtQST9AtjtGpmXwc7EP5T9zORO4nkvleeIo0CBdyfceelcXjKetz-9EC-wKWsVF0cUT6lM7X_tMKzBHkM6U2Wgen5RZFzFbDcWePaJPaI2gZ3a8gP7xI_dlfV9q4ejS5QyfOK_Gju1T5Aal1e0BF9a-4MUfEtuLjXUSpSyA==","internal_chat_message_metadata_passthrough":{"turn_id":"da295b09-34aa-488b-b72c-8a13bd10ec4f"},"summary":[{"type":"summary_text","text":"**Preparing the command fixture**"},{"type":"summary_text","text":"**Adding EnvironmentFile support**"}],"metadata":{"turn_id":"da295b09-34aa-488b-b72c-8a13bd10ec4f"}},{"id":"fc_0e1539855bae2fa9016aa6bd5175f087d1a2712b163c3fa162","type":"function_call","status":"completed","arguments":"{\"language\":\"py\",\"code\":\"djn_prep=(m_base/'prep-ZFZISUHJ.ps1').read_text()\\ndjn_prep=djn_prep.replace('ZFZISUHJ','DJNQQ2RA').replace('[Parameter(Mandatory=$true)][string]$RigRoot)', '[Parameter(Mandatory=$true)][string]$RigRoot,\\\\n      [Parameter(Mandatory=$true)][long]$Deadline)')\\ndjn_prep=djn_prep.replace('1789311857-[DateTimeOffset]', '$Deadline-[DateTimeOffset]')\\ndjn_prep=djn_prep.replace(\\\"-Scope step -Admission process-tree -Exe $Exe\\\", \\\"-Scope step -Admission process-tree -EnvironmentFile (Join-Path $OutputRoot 'capture-environment.json') -Exe $Exe\\\")\\ndjn_prep=djn_prep.replace(\\\"Save (Join-Path $OutputRoot 'invocation.json')\\\", \\\"Save (Join-Path $OutputRoot 'capture-environment.json') @{}\\\\nSave (Join-Path $OutputRoot 'invocation.json')\\\")\\ndjn_prep=djn_prep.replace(\\\"budget_seconds=600;field_main_executed\\\", \\\"deadline=$Deadline;budget_seconds=600;field_main_executed\\\")\\ndjn_fixture=b'OHABRPAJ native launcher Get-FileHash positive control\\\\n'\\ndjn_fixture_hash=hashlib.sha256(djn_fixture).hexdigest()\\ndjn_control=\\\"\\\"\\\"# OHABRPAJ: one no-field positive control in the exact capture launcher shape.\\n$fixture=Join-Path $OutputRoot 'capture-fixture.txt'\\n[IO.File]::WriteAllBytes($fixture,[Text.Encoding]::UTF8.GetBytes(\\\"OHABRPAJ native launcher Get-FileHash positive control`n\\\"))\\n$fixtureLiteral=$fixture.Replace(\\\"'\\\",\\\"''\\\")\\n$controlCode='$ErrorActionPreference=\\\"Stop\\\"; $resolved=Get-Command Get-FileHash -ErrorAction Stop; $hash=(Get-FileHash -LiteralPath ''{0}'' -Algorithm SHA256).Hash.ToLowerInvariant(); if($hash -cne ''{1}'') {{ throw \\\"FIXTURE_HASH_MISMATCH\\\" }}; [ordered]@{{command=$resolved.Name;module=$resolved.ModuleName;fixture_sha256=$hash;result=\\\"GET_FILEHASH_CONTROL_PASS\\\"}} | ConvertTo-Json -Compress; exit 0' -f $fixtureLiteral,'HASH'\\nRunRead 'get-filehash-control' $pwsh @('-NoProfile','-Command',$controlCode) 30\\nif($results[$results.Count-1].native_exit -ne 0) {throw 'GET_FILEHASH_CONTROL_REFUSED'}\\n$controlRecord=Get-Content -Raw -LiteralPath (Join-Path $OutputRoot 'get-filehash-control/record.json') | ConvertFrom-Json\\nif($controlRecord.coverage -ne 'COMPLETE' -or $controlRecord.subject.native_exit -ne 0 -or -not $controlRecord.job.assigned -or -not $controlRecord.job.membership_read -or -not $controlRecord.job.kill_on_close_read -or $controlRecord.job.active_processes -ne 0) {throw 'GET_FILEHASH_CONTROL_OWNERSHIP_REFUSED'}\\n$controlValue=Get-Content -Raw -LiteralPath (Join-Path $OutputRoot 'get-filehash-control/stdout.txt') | ConvertFrom-Json\\nif($controlValue.result -cne 'GET_FILEHASH_CONTROL_PASS' -or $controlValue.fixture_sha256 -cne 'HASH') {throw 'GET_FILEHASH_CONTROL_RESULT_REFUSED'}\\n\\\"\\\"\\\".replace('HASH',djn_fixture_hash)\\n# Replace only placeholder tokens: HASH substitution above must not rename the marker.\\ndjn_control=djn_control.replace('GET_FILE'+djn_fixture_hash,'GET_FILEHASH').replace('FIXTURE_'+djn_fixture_hash,'FIXTURE_HASH')\\ndjn_prep=djn_prep.replace(\\\"RunRead 'host'\\\",djn_control+\\\"RunRead 'host'\\\",1)\\nassert '1789311857' not in djn_prep\\n(m_base/'prep-DJNQQ2RA.ps1').write_bytes(djn_prep.encode())\\ndisplay({'fixture_sha256':djn_fixture_hash,'script':str(m_base/'prep-DJNQQ2RA.ps1'),'sha256':hashlib.sha256((m_base/'prep-DJNQQ2RA.ps1').read_bytes()).hexdigest(),'executed':False})\",\"title\":\"Preparing the single fresh admission with the pinned no-field hash control\",\"timeout\":20,\"reset\":null}","call_id":"call_x0jomwBGNd2dg12xXAaJ85XI","internal_chat_message_metadata_passthrough":{"create_time":1789312316.861198,"turn_id":"da295b09-34aa-488b-b72c-8a13bd10ec4f"},"name":"eval","metadata":{"turn_id":"da295b09-34aa-488b-b72c-8a13bd10ec4f"}}]},"duration":47476.45149999857,"ttft":1692.1499000005424,"completedAt":1789312363712,"contextSnapshot":{"promptTokens":74143,"nonMessageTokens":19884,"compactionEpoch":4}}}
{"type":"message","id":"9b7c4bca","parentId":"0ed702e4","timestamp":"2026-09-13T15:12:43.815Z","message":{"role":"toolResult","toolCallId":"call_x0jomwBGNd2dg12xXAaJ85XI|fc_0e1539855bae2fa9016aa6bd5175f087d1a2712b163c3fa162","toolName":"eval","content":[{"type":"text","text":"{'fixture_sha256': '73ea0563c09d9e1af91e29bd079328d63499123a80bc3aea7e3d26f3c1387c8f', 'script': '.spt\\\\preserved\\\\hertz-fp-driver-review\\\\d2\\\\prep-DJNQQ2RA.ps1', 'sha256': '98af1551b590bf6512a0e6ee6193a870a31b8e9d1675e236f54a53ef17ef6d64', 'executed': False}\n\ndisplay[1]:\n{\n  \"fixture_sha256\": \"73ea0563c09d9e1af91e29bd079328d63499123a80bc3aea7e3d26f3c1387c8f\",\n  \"script\": \".spt\\\\preserved\\\\hertz-fp-driver-review\\\\d2\\\\prep-DJNQQ2RA.ps1\",\n  \"sha256\": \"98af1551b590bf6512a0e6ee6193a870a31b8e9d1675e236f54a53ef17ef6d64\",\n  \"executed\": false\n}"}],"details":{"language":"python","languages":["python"],"cells":[{"index":0,"title":"Preparing the single fresh admission with the pinned no-field hash control","code":"djn_prep=(m_base/'prep-ZFZISUHJ.ps1').read_text()\ndjn_prep=djn_prep.replace('ZFZISUHJ','DJNQQ2RA').replace('[Parameter(Mandatory=$true)][string]$RigRoot)', '[Parameter(Mandatory=$true)][string]$RigRoot,\\n      [Parameter(Mandatory=$true)][long]$Deadline)')\ndjn_prep=djn_prep.replace('1789311857-[DateTimeOffset]', '$Deadline-[DateTimeOffset]')\ndjn_prep=djn_prep.replace(\"-Scope step -Admission process-tree -Exe $Exe\", \"-Scope step -Admission process-tree -EnvironmentFile (Join-Path $OutputRoot 'capture-environment.json') -Exe $Exe\")\ndjn_prep=djn_prep.replace(\"Save (Join-Path $OutputRoot 'invocation.json')\", \"Save (Join-Path $OutputRoot 'capture-environment.json') @{}\\nSave (Join-Path $OutputRoot 'invocation.json')\")\ndjn_prep=djn_prep.replace(\"budget_seconds=600;field_main_executed\", \"deadline=$Deadline;budget_seconds=600;field_main_executed\")\ndjn_fixture=b'OHABRPAJ native launcher Get-FileHash positive control\\n'\ndjn_fixture_hash=hashlib.sha256(djn_fixture).hexdigest()\ndjn_control=\"\"\"# OHABRPAJ: one no-field positive control in the exact capture launcher shape.\n$fixture=Join-Path $OutputRoot 'capture-fixture.txt'\n[IO.File]::WriteAllBytes($fixture,[Text.Encoding]::UTF8.GetBytes(\"OHABRPAJ native launcher Get-FileHash positive control`n\"))\n$fixtureLiteral=$fixture.Replace(\"'\",\"''\")\n$controlCode='$ErrorActionPreference=\"Stop\"; $resolved=Get-Command Get-FileHash -ErrorAction Stop; $hash=(Get-FileHash -LiteralPath ''{0}'' -Algorithm SHA256).Hash.ToLowerInvariant(); if($hash -cne ''{1}'') {{ throw \"FIXTURE_HASH_MISMATCH\" }}; [ordered]@{{command=$resolved.Name;module=$resolved.ModuleName;fixture_sha256=$hash;result=\"GET_FILEHASH_CONTROL_PASS\"}} | ConvertTo-Json -Compress; exit 0' -f $fixtureLiteral,'HASH'\nRunRead 'get-filehash-control' $pwsh @('-NoProfile','-Command',$controlCode) 30\nif($results[$results.Count-1].native_exit -ne 0) {throw 'GET_FILEHASH_CONTROL_REFUSED'}\n$controlRecord=Get-Content -Raw -LiteralPath (Join-Path $OutputRoot 'get-filehash-control/record.json') | ConvertFrom-Json\nif($controlRecord.coverage -ne 'COMPLETE' -or $controlRecord.subject.native_exit -ne 0 -or -not $controlRecord.job.assigned -or -not $controlRecord.job.membership_read -or -not $controlRecord.job.kill_on_close_read -or $controlRecord.job.active_processes -ne 0) {throw 'GET_FILEHASH_CONTROL_OWNERSHIP_REFUSED'}\n$controlValue=Get-Content -Raw -LiteralPath (Join-Path $OutputRoot 'get-filehash-control/stdout.txt') | ConvertFrom-Json\nif($controlValue.result -cne 'GET_FILEHASH_CONTROL_PASS' -or $controlValue.fixture_sha256 -cne 'HASH') {throw 'GET_FILEHASH_CONTROL_RESULT_REFUSED'}\n\"\"\".replace('HASH',djn_fixture_hash)\n# Replace only placeholder tokens: HASH substitution above must not rename the marker.\ndjn_control=djn_control.replace('GET_FILE'+djn_fixture_hash,'GET_FILEHASH').replace('FIXTURE_'+djn_fixture_hash,'FIXTURE_HASH')\ndjn_prep=djn_prep.replace(\"RunRead 'host'\",djn_control+\"RunRead 'host'\",1)\nassert '1789311857' not in djn_prep\n(m_base/'prep-DJNQQ2RA.ps1').write_bytes(djn_prep.encode())\ndisplay({'fixture_sha256':djn_fixture_hash,'script':str(m_base/'prep-DJNQQ2RA.ps1'),'sha256':hashlib.sha256((m_base/'prep-DJNQQ2RA.ps1').read_bytes()).hexdigest(),'executed':False})","language":"python","output":"{'fixture_sha256': '73ea0563c09d9e1af91e29bd079328d63499123a80bc3aea7e3d26f3c1387c8f', 'script': '.spt\\\\preserved\\\\hertz-fp-driver-review\\\\d2\\\\prep-DJNQQ2RA.ps1', 'sha256': '98af1551b590bf6512a0e6ee6193a870a31b8e9d1675e236f54a53ef17ef6d64', 'executed': False}\n\ndisplay[1]:\n{\n  \"fixture_sha256\": \"73ea0563c09d9e1af91e29bd079328d63499123a80bc3aea7e3d26f3c1387c8f\",\n  \"script\": \".spt\\\\preserved\\\\hertz-fp-driver-review\\\\d2\\\\prep-DJNQQ2RA.ps1\",\n  \"sha256\": \"98af1551b590bf6512a0e6ee6193a870a31b8e9d1675e236f54a53ef17ef6d64\",\n  \"executed\": false\n}","status":"complete","exitCode":0,"durationMs":99}],"jsonOutputs":[{"fixture_sha256":"73ea0563c09d9e1af91e29bd079328d63499123a80bc3aea7e3d26f3c1387c8f","script":".spt\\preserved\\hertz-fp-driver-review\\d2\\prep-DJNQQ2RA.ps1","sha256":"98af1551b590bf6512a0e6ee6193a870a31b8e9d1675e236f54a53ef17ef6d64","executed":false}]},"isError":false,"timestamp":1789312363814}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_gFMevowV0u9NwFNxil9lDS6S|fc_0882477797ee396e016aa6bd7966ec87d28a543bfcda76b5cb","toolName":"read","startedAt":"2026-09-13T15:12:57.584Z","args":{"path":".spt/preserved/hertz-fp-driver-review/d2/r6-support-6U2UZVXK/launch-record.py:1-75"},"intent":"Reading the existing exclusive argument-file writer"},"id":"4996df84","parentId":"9b7c4bca","timestamp":"2026-09-13T15:12:57.584Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_Vz2pnJaZJLn6ZC4g4gP0vivl|fc_0882477797ee396e016aa6bd79670487d2903a6a9661bfe2f3","toolName":"read","startedAt":"2026-09-13T15:12:57.584Z","args":{"path":".spt/preserved/hertz-fp-driver-review/d2/provision-stage-DJNQQ2RA.ps1:1-220"},"intent":"Reading the public staging instrument and native ownership checks"},"id":"943ddbf1","parentId":"4996df84","timestamp":"2026-09-13T15:12:57.584Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_nUY5Of7MY81XXUyWKFfP02y2|fc_0882477797ee396e016aa6bd79670c87d2835197b314531eb3","toolName":"read","startedAt":"2026-09-13T15:12:57.584Z","args":{"path":".spt/preserved/hertz-fp-driver-review/d2/binding-ZFZISUHJ/fp-driver-d2-r6-configured.sh:124-170"},"intent":"Reading final binding configuration definitions"},"id":"51a1aa2b","parentId":"943ddbf1","timestamp":"2026-09-13T15:12:57.584Z"}
{"type":"message","id":"15ea516d","parentId":"51a1aa2b","timestamp":"2026-09-13T15:12:57.586Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Preparing fresh DJN binding**"},{"type":"toolCall","id":"call_gFMevowV0u9NwFNxil9lDS6S|fc_0882477797ee396e016aa6bd7966ec87d28a543bfcda76b5cb","name":"read","arguments":{"i":"Reading the existing exclusive argument-file writer","path":".spt/preserved/hertz-fp-driver-review/d2/r6-support-6U2UZVXK/launch-record.py:1-75"},"intent":"Reading the existing exclusive argument-file writer"},{"type":"toolCall","id":"call_Vz2pnJaZJLn6ZC4g4gP0vivl|fc_0882477797ee396e016aa6bd79670487d2903a6a9661bfe2f3","name":"read","arguments":{"i":"Reading the public staging instrument and native ownership checks","path":".spt/preserved/hertz-fp-driver-review/d2/provision-stage-DJNQQ2RA.ps1:1-220"},"intent":"Reading the public staging instrument and native ownership checks"},{"type":"toolCall","id":"call_nUY5Of7MY81XXUyWKFfP02y2|fc_0882477797ee396e016aa6bd79670c87d2835197b314531eb3","name":"read","arguments":{"i":"Reading final binding configuration definitions","path":".spt/preserved/hertz-fp-driver-review/d2/binding-ZFZISUHJ/fp-driver-d2-r6-configured.sh:124-170"},"intent":"Reading final binding configuration definitions"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":16547,"output":376,"cacheRead":59392,"cacheWrite":0,"totalTokens":76315,"reasoningTokens":195,"cost":{"input":0.16547,"output":0.0188,"cacheRead":0.059392,"cacheWrite":0,"total":0.24366200000000002}},"stopReason":"toolUse","timestamp":1789312363952,"responseId":"resp_0882477797ee396e016aa6bd6c4dc487d2a5276bb206c4095c","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_0882477797ee396e016aa6bd6e1c9c87d29558d9f0a0f3e0bd","type":"reasoning","content":[],"encrypted_content":"gAAAAABqpr154k4ZezoI9DVF7Y6XDOBR3rLcCMmk-KtgAcbrowre97uJiefJCPPiVdVINuPmrEyIbQduruyvP7qRnkCcGUlwIX-M3GSYWhAt6bjEoutoZDGBojb23siARIWKmxx40cXSvmS-VzLvvTzNAPP7kcAZlv2A1lmpW-wDarQ88A1RgkNtj4rN-869grQ4KwezP2fYfGMwhIEOtTHihidFWtrUpIkIM4aO5EhXFU9R1MJsXgFJWlqXw7spkLvZQXRe9wU0sFP_h9-1gb3Q5pLY1d4l33T3qC4IaVs15Q4tBXW2kDb9oRiTh-GCkS1a2H1ymziCQdaaMv2DNxy6QcXdpy_-I9glLbG_5PC0cKuZVBXRreSmPSrdcMwvHg0XDI-gR6bMRg7h39ITjQaMouLRz7h5vDNWK6Nl-Ev-dr1fJTXR-XOlpb55YaKjQnangIWKuLLdx-AoWmLDGZtxj2ZVKtX_7l6IXX6dyFD2KlnZ7UJQ-VKcRsTux1c9CuERV_FNeFXtAeJYYII8waSEfowL7N3y4qJw8ytYZbU_LW46kxbAy3qKU15NHI9XssEVkTe7ft29dlkxrdRX975Af9j50Mk743Da-D1V958eXNoakUP0M3Cyo-jy8Q4AIgZEUP3iKl_8gUWvPj3zOuZ03rZVzHZm1tJOjFGwNqJPkVMBn-6o6MJ42V5RFSZvX0TiOxhVm7JAcBMyXdv0DxrTfcNcHTVuXgbOZTBBSeZ1xU0OmM9QFyJWmpKoJi_qGswlb582lWgPVzrBk-_NzqH4gZaVQvnVmamWJzb7G8_wWy-WXleN_ov8q7BbfSdrIjt1HLN9OHpltJC2VMjCsGmLAyhYG68WPcedYIWNUiKkHZdjqd0qzca1XhFlIKUlE3I9017hKt5bGMnUh4vRpvOz5_WHZWNbRNB9ox9dZ6P60BwXOp1ZJZR6E6tKCbcgR5y2V-v7hAmM9G9ofSbZcQoAbmajeuKHwO4h1EYhguhf9T6-H6KeGFSJN8bCqm6NJYtmxg4WZIMutvykv2zGTlFaQq5_FANxeeU6WBHS5Km9TVujXTwkqa7DkjQ4H80fvQ8kGCqViVcsYQ3MLxbVckzbgZrCHtEdxijvem-4LY7-z9VDec7UKN9MNdzTeioAW3Cp2Ay4_FsbNjJwai6Q4t7yZGMxc1WmCpxGLWMapxniltlnRXrKu_SJZD6jXGl0cBv17OLvcWtnVjWhzL-DEiwgp34m9E6Sxc3bkKBDCQlaxN_ySftsQy6Aa3EtYOz3Na5rm8ibDBMmz4HO1oUbicuGlhyIvxC8bqRVCcPaLzw_JzP43jrLigYd2V6bhwzbdojfQN1hBUAPvOuZTWjjdVqqtGqa_py7Ng4yTRDDrotyXXjZnHoARM_uk9q360LC19T1qRTpzLSxH1BJD2He2phUEA3LuZRel2gl_IF8vAMxH3Pw_ZYsmggtqtKvl-jvQflmXcZhD9YeZVwWLsqguKHjzdtK3tKkz8q79TnwQI5POujn7UZK8HATsNdrJa9HDKwQh1Qfe-bU0Gj5k5NBatjq8Z1SfJXszpCB7CqifGufMy8tOUJfxiNYN0ePfMZFmfp3bR0K-z-LI4_hC1Le7X3VObPGFJjQim7oD9wBitnrcAe9Y01nQ1hc1VlpJbjUQGiU8eTO22CvVfsd36b0XVEMzulpOLWYM8WLE53WmBta3guT-5UT8RWZzp-cQAMVrhOcWgwz9S3eM6JQaeVPDy5hFQquWoODtpHMb3dmljq4lnINr3gN48RYv7vnN7s9cUIQIAya_feryYnGuSZ3Q-ko0UyVQhqwTMPlKcpN98u2rgPTb8c4SczpFU1jXCXpU0eOpJlaydoJ8m10GHVN7QENSs0XXNM8l6r0ULttpXiYAj-2ctY03QmnQhH5Wrg_-a8l1ENuzxXvoux02WCmJCOCKFDJREdQOGbKvXXgi0peNFOJCvrhO-3wC5IXoUgE5qYUlpYeE3OkSKH725XkPLu5VDR9Uczj1JXc_y8mCVsR9gO9caAPGlqYUUyLnABEKhP5j1-4SZn7sdScTkd5q2ubYNJh0Advs9y7qZFqqcfPFn9YDabZFj8Wcyzsv8e3VSjrSr7H-FDSDlDzdrvXFFpWNJOnA6Ex4fp7ueUQrdaaYjNOJPmDRN7vriSFyCf-eHZa-q7z1mi_uKtdSa5P77rc7VoW7ANfhcRudYXFgUSHefs6sd61vhziSuvzEMTcPcKVS9XOoxswSc_YXUUoglrl8SHUCfUAndqN6bo2mFjyG6ZYM7VpCKjRrw8wGbiPnVzOq54TCxnOy7GV8Y5yntrFwK-wkBAKMTedVK_aCXQNetCCzlY4UVfquJ6q5QLxAo-fSqqV5C_7NHtq4NoOkbtRolvWT91zriFpoOLzh8bohAD6cBNE13AXjUI3pG_vK8OhllZMsTtfL15WJQU_hBMbgO2q-16aXoEuNQNq566L3tuVA8MX_cnAxg3n56QUiW4xe7bA_wju","internal_chat_message_metadata_passthrough":{"turn_id":"1b642448-5b81-46ee-9459-81b5152a2be2"},"summary":[{"type":"summary_text","text":"**Preparing fresh DJN binding**"}],"metadata":{"turn_id":"1b642448-5b81-46ee-9459-81b5152a2be2"}},{"id":"fc_0882477797ee396e016aa6bd7966ec87d28a543bfcda76b5cb","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading the existing exclusive argument-file writer\",\"path\":\".spt/preserved/hertz-fp-driver-review/d2/r6-support-6U2UZVXK/launch-record.py:1-75\"}","call_id":"call_gFMevowV0u9NwFNxil9lDS6S","internal_chat_message_metadata_passthrough":{"turn_id":"1b642448-5b81-46ee-9459-81b5152a2be2"},"name":"read","metadata":{"turn_id":"1b642448-5b81-46ee-9459-81b5152a2be2"}},{"id":"fc_0882477797ee396e016aa6bd79670487d2903a6a9661bfe2f3","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading the public staging instrument and native ownership checks\",\"path\":\".spt/preserved/hertz-fp-driver-review/d2/provision-stage-DJNQQ2RA.ps1:1-220\"}","call_id":"call_Vz2pnJaZJLn6ZC4g4gP0vivl","internal_chat_message_metadata_passthrough":{"turn_id":"1b642448-5b81-46ee-9459-81b5152a2be2"},"name":"read","metadata":{"turn_id":"1b642448-5b81-46ee-9459-81b5152a2be2"}},{"id":"fc_0882477797ee396e016aa6bd79670c87d2835197b314531eb3","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading final binding configuration definitions\",\"path\":\".spt/preserved/hertz-fp-driver-review/d2/binding-ZFZISUHJ/fp-driver-d2-r6-configured.sh:124-170\"}","call_id":"call_nUY5Of7MY81XXUyWKFfP02y2","internal_chat_message_metadata_passthrough":{"turn_id":"1b642448-5b81-46ee-9459-81b5152a2be2"},"name":"read","metadata":{"turn_id":"1b642448-5b81-46ee-9459-81b5152a2be2"}}]},"duration":13631.10319999978,"ttft":2175.3059000000358,"completedAt":1789312377583,"contextSnapshot":{"promptTokens":75939,"nonMessageTokens":19884,"compactionEpoch":4}}}
{"type":"message","id":"e1076d00","parentId":"15ea516d","timestamp":"2026-09-13T15:12:57.606Z","message":{"role":"toolResult","toolCallId":"call_Vz2pnJaZJLn6ZC4g4gP0vivl|fc_0882477797ee396e016aa6bd79670487d2903a6a9661bfe2f3","toolName":"read","content":[{"type":"text","text":"[.spt/preserved/hertz-fp-driver-review/d2/provision-stage-DJNQQ2RA.ps1#B5DD]\n1:# S6ESSJ3N authorized preparation A3-A4/B5-B7/C8-C9. No field authority.\n2:# Invoke in a fresh, unelevated PowerShell 7 process. Never dot-source.\n3:[CmdletBinding()]\n4:param(\n5:    [Parameter(Mandatory)][string]$RigRoot,\n6:    [Parameter(Mandatory)][long]$Deadline,\n7:    [Parameter(Mandatory)][string]$OutputRoot,\n8:    [Parameter(Mandatory)][string]$SupportRoot,\n9:    [Parameter(Mandatory)][string]$SubjectExe,\n10:    [Parameter(Mandatory)][ValidatePattern('^[0-9a-fA-F]{64}$')][string]$SubjectSha256,\n11:    [Parameter(Mandatory)][string]$XtaskExe,\n12:    [Parameter(Mandatory)][ValidatePattern('^[0-9a-fA-F]{64}$')][string]$XtaskSha256\n13:)\n14:$ErrorActionPreference = 'Stop'\n15:$VerbosePreference = 'SilentlyContinue'\n16:$DebugPreference = 'SilentlyContinue'\n17:$InformationPreference = 'SilentlyContinue'\n18:Set-PSDebug -Off\n19:Set-StrictMode -Version Latest\n20:$utf8 = [Text.UTF8Encoding]::new($false)\n21:$keyId = 'hertz-r5-S6ESSJ3N'\n22:$version = [long]202609130001\n23:$platform = 'x86_64-pc-windows-msvc'\n24:$phase = 'PREFLIGHT'\n25:$privateRoot = $null\n26:$privateOwned = $false\n27:$publicReady = $false\n28:$steps = [Collections.Generic.List[object]]::new()\n29:$attempts = [Collections.Generic.List[object]]::new()\n30:$privateFiles = [Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase)\n31:$seed = $null; $keyText = $null; $seedMatches = $null; $publicMatches = $null; $overlay = $null\n32:$moduleTuple = [ordered]@{\n33:    commit = 'b848244577d398600b59c7829fef9edbdb6315fa'\n34:    common = 'c30d6b5466408b05d2dbd3032ca38043fbe0e5bb'\n35:    windows = '31ef24c8b203581eb6579c253dcfdc65c362f596'\n36:    linux = '08f615c4b0985a86ed8c42e96cfc3083857c4aff'\n37:}\n38:function Check-Clock {\n39:    if ([DateTimeOffset]::UtcNow.ToUnixTimeSeconds() -ge ($Deadline - 5)) { throw 'PREP_DEADLINE_EXPIRED' }\n40:}\n41:function Assert-SeedAbsent {\n42:    foreach ($name in @('SPT_DEBUG_RELEASE_SEED','SPT_RELEASE_SEED','SPT_RELEASE_SEED_CMD')) {\n43:        if ([Environment]::GetEnvironmentVariable($name, 'Process') -ne $null) { throw 'AMBIENT_SIGNING_SECRET_REFUSED' }\n44:    }\n45:}\n46:function Full([string]$Path) {\n47:    if (-not [IO.Path]::IsPathFullyQualified($Path)) { throw 'ABSOLUTE_PATH_REQUIRED' }\n48:    $p = [IO.Path]::GetFullPath($Path).TrimEnd('\\')\n49:    if ($p -notmatch '^[A-Za-z]:\\\\' -or $p.Substring(2).Contains(':')) { throw 'LOCAL_NON_ADS_PATH_REQUIRED' }\n50:    if (-not $p.Equals($Path.TrimEnd('\\'), [StringComparison]::OrdinalIgnoreCase)) { throw 'NORMALIZED_PATH_REQUIRED' }\n51:    return $p\n52:}\n53:function Below([string]$Child, [string]$Parent) {\n54:    return $Child.Equals($Parent, [StringComparison]::OrdinalIgnoreCase) -or $Child.StartsWith($Parent.TrimEnd('\\') + '\\', [StringComparison]::OrdinalIgnoreCase)\n55:}\n56:function Identity([string]$Path) {\n57:    $id = [StageNative]::Identify($Path)\n58:    if (($id.attributes -band 0x400) -ne 0) { throw 'REPARSE_PATH_REFUSED' }\n59:    if (-not $id.canonical_path.TrimEnd('\\').Equals($Path.TrimEnd('\\'), [StringComparison]::OrdinalIgnoreCase)) { throw 'CANONICAL_PATH_MISMATCH' }\n60:    return $id\n61:}\n62:function No-Reparse([string]$Path) {\n63:    $p = $Path\n64:    while ($p) {\n65:        if ([IO.File]::Exists($p) -or [IO.Directory]::Exists($p)) { $null = Identity $p }\n66:        $p = [IO.Path]::GetDirectoryName($p)\n67:    }\n68:}\n69:function Pin([string]$Path, [string]$Expected = '') {\n70:    No-Reparse $Path\n71:    if (-not [IO.File]::Exists($Path)) { throw 'INPUT_FILE_REQUIRED' }\n72:    $before = Identity $Path\n73:    $hash = (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash.ToLowerInvariant()\n74:    $after = Identity $Path\n75:    if ($before.file_id -ne $after.file_id -or ($Expected -and $hash -cne $Expected.ToLowerInvariant())) { throw 'PIN_MISMATCH' }\n76:    return [ordered]@{path=$Path;sha256=$hash;identity=$after}\n77:}\n78:function New-Text([string]$Path, [string]$Text) {\n79:    $stream = [IO.FileStream]::new($Path,[IO.FileMode]::CreateNew,[IO.FileAccess]::Write,[IO.FileShare]::None)\n80:    try { $bytes = $utf8.GetBytes($Text); $stream.Write($bytes,0,$bytes.Length); $stream.Flush($true) }\n81:    finally { $stream.Dispose(); $bytes = $null }\n82:}\n83:function New-Json([string]$Path, $Value) { New-Text $Path (ConvertTo-Json -InputObject $Value -Depth 24) }\n84:function New-Directory([string]$Path) {\n85:    Check-Clock\n86:    [StageNative]::CreateExclusive($Path, $null)\n87:    No-Reparse $Path\n88:}\n89:function Assert-PrivateAcl([string]$Path) {\n90:    No-Reparse $Path\n91:    $acl = Get-Acl -LiteralPath $Path\n92:    if ($acl.GetOwner([Security.Principal.SecurityIdentifier]).Value -cne $ownerSid -or -not $acl.AreAccessRulesProtected) { throw 'PRIVATE_ACL_OWNER_OR_INHERITANCE_REFUSED' }\n93:    $rules = @($acl.GetAccessRules($true,$true,[Security.Principal.SecurityIdentifier]))\n94:    if ($rules.Count -ne 1 -or $rules[0].IdentityReference.Value -cne $ownerSid -or $rules[0].AccessControlType -ne 'Allow' -or $rules[0].FileSystemRights -ne [Security.AccessControl.FileSystemRights]::FullControl -or ($rules[0].InheritanceFlags -band 3) -ne 3) { throw 'PRIVATE_ACL_NOT_OWNER_ONLY' }\n95:}\n96:function Private-Path([string]$Name) {\n97:    $p = Join-Path $privateRoot $Name\n98:    $null = $privateFiles.Add($p)\n99:    return $p\n100:}\n101:function Read-Json([string]$Path) { return (ConvertFrom-Json -InputObject ([IO.File]::ReadAllText($Path)) -AsHashtable) }\n102:function Assert-Gone($Record) {\n103:    if ($Record.version -ne 2 -or $Record.scope -ne 'step' -or $Record.coverage -ne 'COMPLETE' -or $Record.termination -ne 'CONFIRMED_GONE' -or $Record.job.assigned -ne $true -or $Record.job.membership_read -ne $true -or $Record.job.kill_on_close_read -ne $true -or $null -eq $Record.job.active_processes -or $Record.job.active_processes -ne 0 -or $Record.subject.state -notin @('EXITED','TERMINATED')) { throw 'OWNED_JOB_GONE_UNCONFIRMED' }\n104:}\n105:function Invoke-Step([string]$Label,[int]$NamedCap,[string]$ArgsFile,[string]$EnvironmentFile,[bool]$SeedAbsent) {\n106:    Check-Clock; Assert-SeedAbsent; Assert-PrivateAcl $privateRoot\n107:    $null = Pin $XtaskExe $XtaskSha256\n108:    $null = Pin $launcher '6e2c2eac82dd53fd0af42c4fe796f911e987d406e6f31219cd4480a78f1f6804'\n109:    $null = Pin $native 'c3a905ec7cbc118f0b59dd1813b187740319802267689e14dacf6008730de157'\n110:    $seconds = [int][Math]::Min($NamedCap, $Deadline - [DateTimeOffset]::UtcNow.ToUnixTimeSeconds() - 5)\n111:    if ($seconds -lt 1) { throw 'STEP_DEADLINE_EXPIRED' }\n112:    $recordFile = Private-Path \"$Label.record.json\"\n113:    $outFile = Private-Path \"$Label.stdout\"\n114:    $errFile = Private-Path \"$Label.stderr\"\n115:    $eventFile = Private-Path \"$Label.record.json.events.jsonl\"\n116:    $launchOut = Private-Path \"$Label.launcher.stdout\"\n117:    $launchErr = Private-Path \"$Label.launcher.stderr\"\n118:    $attempt = [ordered]@{label=$Label;record_file=$recordFile;launcher_exited=$false;public_record=$null}\n119:    $attempts.Add($attempt)\n120:    $psi = [Diagnostics.ProcessStartInfo]::new($pwsh)\n121:    $psi.UseShellExecute=$false; $psi.CreateNoWindow=$true\n122:    $psi.RedirectStandardOutput=$true; $psi.RedirectStandardError=$true\n123:    foreach ($arg in @('-NoProfile','-NonInteractive','-File',$launcher,'-Label',$Label,'-Seconds',\"$seconds\",'-RecordFile',$recordFile,'-ArgsFile',$ArgsFile,'-Exe',$XtaskExe,'-OutFile',$outFile,'-ErrFile',$errFile,'-Admission','process-tree','-Scope','step')) { $psi.ArgumentList.Add($arg) }\n124:    if ($EnvironmentFile) { $psi.ArgumentList.Add('-EnvironmentFile'); $psi.ArgumentList.Add($EnvironmentFile) }\n125:    $proc = [Diagnostics.Process]::new(); $proc.StartInfo=$psi\n126:    try {\n127:        if (-not $proc.Start()) { throw 'LAUNCHER_NOT_STARTED' }\n128:        $stdoutTask=$proc.StandardOutput.ReadToEndAsync(); $stderrTask=$proc.StandardError.ReadToEndAsync()\n129:        # Never kill the bounding launcher: only its native job owns descendants.\n130:        $waitMs=[int][Math]::Max(1,[Math]::Min(2147483647,($Deadline-[DateTimeOffset]::UtcNow.ToUnixTimeSeconds())*1000))\n131:        if (-not $proc.WaitForExit($waitMs)) { throw 'LAUNCHER_EXIT_UNCONFIRMED' }\n132:        $attempt.launcher_exited=$true\n133:        New-Text $launchOut ($stdoutTask.GetAwaiter().GetResult())\n134:        New-Text $launchErr ($stderrTask.GetAwaiter().GetResult())\n135:        $r=Read-Json $recordFile\n136:        Assert-Gone $r\n137:        if ($proc.ExitCode -ne 0 -or $r.subject.native_exit -ne 0 -or $r.completion_reason -ne 'subject_exit' -or $null -ne $r.error) { throw 'NATIVE_STEP_FAILED' }\n138:        # Native records contain only identity/control fields, not capture bytes.\n139:        # Refuse any exceptional record rather than publishing exception content.\n140:        foreach ($line in [IO.File]::ReadLines($eventFile)) {\n141:            $event=ConvertFrom-Json -InputObject $line -AsHashtable\n142:            if ($null -ne $event.record.error) { throw 'NATIVE_EVENT_ERROR_REFUSED' }\n143:        }\n144:        $publicRecord=Join-Path $OutputRoot \"$Label.record.json\"\n145:        [StageNative]::CopyExclusive($recordFile,$publicRecord)\n146:        [StageNative]::CopyExclusive($eventFile,\"$publicRecord.events.jsonl\")\n147:        $attempt.public_record=$publicRecord\n148:        $steps.Add([ordered]@{label=$Label;record_file=$publicRecord;args_file=$ArgsFile;environment_seed_absent=$SeedAbsent;native_exit=0;termination='CONFIRMED_GONE';named_cap_seconds=$NamedCap;allocated_seconds=$seconds})\n149:        Assert-SeedAbsent; Check-Clock\n150:        return [ordered]@{stdout=$outFile;stderr=$errFile;record=$publicRecord}\n151:    } finally { $proc.Dispose(); $psi=$null; $stdoutTask=$null; $stderrTask=$null }\n152:}\n153:function Retire-PrivateFiles {\n154:    if (-not $privateOwned) { return $null }\n155:    foreach ($attempt in $attempts) {\n156:        if (-not $attempt.launcher_exited) { throw 'PRIVATE_RETIREMENT_BLOCKED_LAUNCHER' }\n157:        Assert-Gone (Read-Json $attempt.record_file)\n158:    }\n159:    Assert-PrivateAcl $privateRoot\n160:    # The exclusively owned directory is retained. Never archive or remove it.\n161:    # Only this invocation's exact declared files may be retired, never a glob.\n162:    foreach ($entry in [IO.Directory]::EnumerateFileSystemEntries($privateRoot)) {\n163:        if (-not $privateFiles.Contains($entry) -or [IO.Directory]::Exists($entry)) { throw 'UNEXPECTED_PRIVATE_ENTRY_RETAINED' }\n164:        $null=Identity $entry\n165:    }\n166:    $retired=[Collections.Generic.List[object]]::new()\n167:    foreach ($file in $privateFiles) {\n168:        if ([IO.File]::Exists($file)) { $null=Identity $file; [IO.File]::Delete($file) }\n169:        if ([IO.File]::Exists($file) -or [IO.Directory]::Exists($file)) { throw 'PRIVATE_RETIREMENT_FAILED' }\n170:        $retired.Add([ordered]@{path=$file;retired=$true})\n171:    }\n172:    return [ordered]@{completed=$true;all_owned_jobs_gone=$true;files=@($retired.ToArray());directory_retained=$true;memory_erasure_claimed=$false;completed_utc=[DateTime]::UtcNow.ToString('o')}\n173:}\n174:try {\n175:    if (-not $IsWindows -or $PSVersionTable.PSVersion.Major -lt 7 -or -not [Environment]::Is64BitProcess) { throw 'WINDOWS_PS7_X64_REQUIRED' }\n176:    Check-Clock; Assert-SeedAbsent\n177:    # Stop any inherited manual transcript before a seed can exist. Policy-forced\n178:    # transcription/script-block logging cannot safely host secret bindings.\n179:    Stop-Transcript -ErrorAction SilentlyContinue | Out-Null\n180:    foreach ($base in @('HKLM:\\SOFTWARE\\Policies\\Microsoft\\Windows\\PowerShell','HKCU:\\SOFTWARE\\Policies\\Microsoft\\Windows\\PowerShell','HKLM:\\SOFTWARE\\Policies\\Microsoft\\PowerShellCore','HKCU:\\SOFTWARE\\Policies\\Microsoft\\PowerShellCore')) {\n181:        foreach ($policy in @(@('Transcription','EnableTranscripting'),@('ScriptBlockLogging','EnableScriptBlockLogging'),@('ModuleLogging','EnableModuleLogging'))) {\n182:            $value=Get-ItemPropertyValue -LiteralPath (Join-Path $base $policy[0]) -Name $policy[1] -ErrorAction SilentlyContinue\n183:            if ($value -eq 1) { throw 'POLICY_SECRET_CAPTURE_REFUSED' }\n184:        }\n185:    }\n186:    $windowsIdentity=[Security.Principal.WindowsIdentity]::GetCurrent()\n187:    try {\n188:        if ([Security.Principal.WindowsPrincipal]::new($windowsIdentity).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { throw 'ELEVATED_HOST_REFUSED' }\n189:        $ownerSid=$windowsIdentity.User.Value\n190:    } finally { $windowsIdentity.Dispose() }\n191:    # All native helper compilation happens now, in a seed-absent host.\n192:    Add-Type -TypeDefinition @'\n193:using System;\n194:using System.Text;\n195:using System.ComponentModel;\n196:using System.Runtime.InteropServices;\n197:public static class StageNative {\n198: [StructLayout(LayoutKind.Sequential)] struct FT { public uint low,high; }\n199: [StructLayout(LayoutKind.Sequential)] struct FI { public uint attributes; public FT creation,access,write; public uint volume,sizeHigh,sizeLow,links,indexHigh,indexLow; }\n200: [StructLayout(LayoutKind.Sequential)] struct SA { public int length; public IntPtr descriptor; public int inherit; }\n201: public sealed class FileId { public string canonical_path {get;set;} public string file_id {get;set;} public uint attributes {get;set;} }\n202: [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern IntPtr CreateFileW(string p,uint access,uint share,IntPtr security,uint disposition,uint flags,IntPtr template);\n203: [DllImport(\"kernel32.dll\",SetLastError=true)] static extern bool GetFileInformationByHandle(IntPtr h,out FI info);\n204: [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern uint GetFinalPathNameByHandleW(IntPtr h,StringBuilder p,uint n,uint flags);\n205: [DllImport(\"kernel32.dll\",SetLastError=true)] static extern bool CloseHandle(IntPtr h);\n206: [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool CreateDirectoryW(string path,IntPtr security);\n207: [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool CopyFileW(string from,string to,bool failIfExists);\n208: [DllImport(\"advapi32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool ConvertStringSecurityDescriptorToSecurityDescriptorW(string sddl,uint revision,out IntPtr descriptor,out uint size);\n209: [DllImport(\"kernel32.dll\")] static extern IntPtr LocalFree(IntPtr p);\n210: public static FileId Identify(string path) {\n211:  // Sharing includes DELETE; no persistent handle can obstruct genuine apply.\n212:  IntPtr h=CreateFileW(path,0,7,IntPtr.Zero,3,0x02200000,IntPtr.Zero);\n213:  if(h==new IntPtr(-1))throw new Win32Exception(Marshal.GetLastWin32Error());\n214:  try { FI i; if(!GetFileInformationByHandle(h,out i))throw new Win32Exception(Marshal.GetLastWin32Error());\n215:   var b=new StringBuilder(32768); uint n=GetFinalPathNameByHandleW(h,b,(uint)b.Capacity,0);\n216:   if(n==0||n>=b.Capacity)throw new Win32Exception(Marshal.GetLastWin32Error());\n217:   string p=b.ToString(); if(p.StartsWith(@\"\\\\?\\\"))p=p.Substring(4);\n218:   return new FileId { canonical_path=p,file_id=i.volume.ToString(\"X8\")+\":\"+i.indexHigh.ToString(\"X8\")+i.indexLow.ToString(\"X8\"),attributes=i.attributes };\n219:  } finally { if(!CloseHandle(h))throw new Win32Exception(Marshal.GetLastWin32Error()); }\n220: }\n221: public static void CreateExclusive(string path,string sid) {\n222:  IntPtr sd=IntPtr.Zero,sa=IntPtr.Zero;\n223:  try { if(!String.IsNullOrEmpty(sid)) { uint size; if(!ConvertStringSecurityDescriptorToSecurityDescriptorW(\"O:\"+sid+\"D:P(A;OICI;FA;;;\"+sid+\")\",1,out sd,out size))throw new Win32Exception(Marshal.GetLastWin32Error());\n…\n231:'@\n…\n324:    exit 0\n325:} catch {\n…\n364:}\n\n[Showing lines 1-223 of 364. Use :224 to continue]"}],"details":{"truncation":{"content":"# S6ESSJ3N authorized preparation A3-A4/B5-B7/C8-C9. No field authority.\n# Invoke in a fresh, unelevated PowerShell 7 process. Never dot-source.\n[CmdletBinding()]\nparam(\n    [Parameter(Mandatory)][string]$RigRoot,\n    [Parameter(Mandatory)][long]$Deadline,\n    [Parameter(Mandatory)][string]$OutputRoot,\n    [Parameter(Mandatory)][string]$SupportRoot,\n    [Parameter(Mandatory)][string]$SubjectExe,\n    [Parameter(Mandatory)][ValidatePattern('^[0-9a-fA-F]{64}$')][string]$SubjectSha256,\n    [Parameter(Mandatory)][string]$XtaskExe,\n    [Parameter(Mandatory)][ValidatePattern('^[0-9a-fA-F]{64}$')][string]$XtaskSha256\n)\n$ErrorActionPreference = 'Stop'\n$VerbosePreference = 'SilentlyContinue'\n$DebugPreference = 'SilentlyContinue'\n$InformationPreference = 'SilentlyContinue'\nSet-PSDebug -Off\nSet-StrictMode -Version Latest\n$utf8 = [Text.UTF8Encoding]::new($false)\n$keyId = 'hertz-r5-S6ESSJ3N'\n$version = [long]202609130001\n$platform = 'x86_64-pc-windows-msvc'\n$phase = 'PREFLIGHT'\n$privateRoot = $null\n$privateOwned = $false\n$publicReady = $false\n$steps = [Collections.Generic.List[object]]::new()\n$attempts = [Collections.Generic.List[object]]::new()\n$privateFiles = [Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase)\n$seed = $null; $keyText = $null; $seedMatches = $null; $publicMatches = $null; $overlay = $null\n$moduleTuple = [ordered]@{\n    commit = 'b848244577d398600b59c7829fef9edbdb6315fa'\n    common = 'c30d6b5466408b05d2dbd3032ca38043fbe0e5bb'\n    windows = '31ef24c8b203581eb6579c253dcfdc65c362f596'\n    linux = '08f615c4b0985a86ed8c42e96cfc3083857c4aff'\n}\nfunction Check-Clock {\n    if ([DateTimeOffset]::UtcNow.ToUnixTimeSeconds() -ge ($Deadline - 5)) { throw 'PREP_DEADLINE_EXPIRED' }\n}\nfunction Assert-SeedAbsent {\n    foreach ($name in @('SPT_DEBUG_RELEASE_SEED','SPT_RELEASE_SEED','SPT_RELEASE_SEED_CMD')) {\n        if ([Environment]::GetEnvironmentVariable($name, 'Process') -ne $null) { throw 'AMBIENT_SIGNING_SECRET_REFUSED' }\n    }\n}\nfunction Full([string]$Path) {\n    if (-not [IO.Path]::IsPathFullyQualified($Path)) { throw 'ABSOLUTE_PATH_REQUIRED' }\n    $p = [IO.Path]::GetFullPath($Path).TrimEnd('\\')\n    if ($p -notmatch '^[A-Za-z]:\\\\' -or $p.Substring(2).Contains(':')) { throw 'LOCAL_NON_ADS_PATH_REQUIRED' }\n    if (-not $p.Equals($Path.TrimEnd('\\'), [StringComparison]::OrdinalIgnoreCase)) { throw 'NORMALIZED_PATH_REQUIRED' }\n    return $p\n}\nfunction Below([string]$Child, [string]$Parent) {\n    return $Child.Equals($Parent, [StringComparison]::OrdinalIgnoreCase) -or $Child.StartsWith($Parent.TrimEnd('\\') + '\\', [StringComparison]::OrdinalIgnoreCase)\n}\nfunction Identity([string]$Path) {\n    $id = [StageNative]::Identify($Path)\n    if (($id.attributes -band 0x400) -ne 0) { throw 'REPARSE_PATH_REFUSED' }\n    if (-not $id.canonical_path.TrimEnd('\\').Equals($Path.TrimEnd('\\'), [StringComparison]::OrdinalIgnoreCase)) { throw 'CANONICAL_PATH_MISMATCH' }\n    return $id\n}\nfunction No-Reparse([string]$Path) {\n    $p = $Path\n    while ($p) {\n        if ([IO.File]::Exists($p) -or [IO.Directory]::Exists($p)) { $null = Identity $p }\n        $p = [IO.Path]::GetDirectoryName($p)\n    }\n}\nfunction Pin([string]$Path, [string]$Expected = '') {\n    No-Reparse $Path\n    if (-not [IO.File]::Exists($Path)) { throw 'INPUT_FILE_REQUIRED' }\n    $before = Identity $Path\n    $hash = (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash.ToLowerInvariant()\n    $after = Identity $Path\n    if ($before.file_id -ne $after.file_id -or ($Expected -and $hash -cne $Expected.ToLowerInvariant())) { throw 'PIN_MISMATCH' }\n    return [ordered]@{path=$Path;sha256=$hash;identity=$after}\n}\nfunction New-Text([string]$Path, [string]$Text) {\n    $stream = [IO.FileStream]::new($Path,[IO.FileMode]::CreateNew,[IO.FileAccess]::Write,[IO.FileShare]::None)\n    try { $bytes = $utf8.GetBytes($Text); $stream.Write($bytes,0,$bytes.Length); $stream.Flush($true) }\n    finally { $stream.Dispose(); $bytes = $null }\n}\nfunction New-Json([string]$Path, $Value) { New-Text $Path (ConvertTo-Json -InputObject $Value -Depth 24) }\nfunction New-Directory([string]$Path) {\n    Check-Clock\n    [StageNative]::CreateExclusive($Path, $null)\n    No-Reparse $Path\n}\nfunction Assert-PrivateAcl([string]$Path) {\n    No-Reparse $Path\n    $acl = Get-Acl -LiteralPath $Path\n    if ($acl.GetOwner([Security.Principal.SecurityIdentifier]).Value -cne $ownerSid -or -not $acl.AreAccessRulesProtected) { throw 'PRIVATE_ACL_OWNER_OR_INHERITANCE_REFUSED' }\n    $rules = @($acl.GetAccessRules($true,$true,[Security.Principal.SecurityIdentifier]))\n    if ($rules.Count -ne 1 -or $rules[0].IdentityReference.Value -cne $ownerSid -or $rules[0].AccessControlType -ne 'Allow' -or $rules[0].FileSystemRights -ne [Security.AccessControl.FileSystemRights]::FullControl -or ($rules[0].InheritanceFlags -band 3) -ne 3) { throw 'PRIVATE_ACL_NOT_OWNER_ONLY' }\n}\nfunction Private-Path([string]$Name) {\n    $p = Join-Path $privateRoot $Name\n    $null = $privateFiles.Add($p)\n    return $p\n}\nfunction Read-Json([string]$Path) { return (ConvertFrom-Json -InputObject ([IO.File]::ReadAllText($Path)) -AsHashtable) }\nfunction Assert-Gone($Record) {\n    if ($Record.version -ne 2 -or $Record.scope -ne 'step' -or $Record.coverage -ne 'COMPLETE' -or $Record.termination -ne 'CONFIRMED_GONE' -or $Record.job.assigned -ne $true -or $Record.job.membership_read -ne $true -or $Record.job.kill_on_close_read -ne $true -or $null -eq $Record.job.active_processes -or $Record.job.active_processes -ne 0 -or $Record.subject.state -notin @('EXITED','TERMINATED')) { throw 'OWNED_JOB_GONE_UNCONFIRMED' }\n}\nfunction Invoke-Step([string]$Label,[int]$NamedCap,[string]$ArgsFile,[string]$EnvironmentFile,[bool]$SeedAbsent) {\n    Check-Clock; Assert-SeedAbsent; Assert-PrivateAcl $privateRoot\n    $null = Pin $XtaskExe $XtaskSha256\n    $null = Pin $launcher '6e2c2eac82dd53fd0af42c4fe796f911e987d406e6f31219cd4480a78f1f6804'\n    $null = Pin $native 'c3a905ec7cbc118f0b59dd1813b187740319802267689e14dacf6008730de157'\n    $seconds = [int][Math]::Min($NamedCap, $Deadline - [DateTimeOffset]::UtcNow.ToUnixTimeSeconds() - 5)\n    if ($seconds -lt 1) { throw 'STEP_DEADLINE_EXPIRED' }\n    $recordFile = Private-Path \"$Label.record.json\"\n    $outFile = Private-Path \"$Label.stdout\"\n    $errFile = Private-Path \"$Label.stderr\"\n    $eventFile = Private-Path \"$Label.record.json.events.jsonl\"\n    $launchOut = Private-Path \"$Label.launcher.stdout\"\n    $launchErr = Private-Path \"$Label.launcher.stderr\"\n    $attempt = [ordered]@{label=$Label;record_file=$recordFile;launcher_exited=$false;public_record=$null}\n    $attempts.Add($attempt)\n    $psi = [Diagnostics.ProcessStartInfo]::new($pwsh)\n    $psi.UseShellExecute=$false; $psi.CreateNoWindow=$true\n    $psi.RedirectStandardOutput=$true; $psi.RedirectStandardError=$true\n    foreach ($arg in @('-NoProfile','-NonInteractive','-File',$launcher,'-Label',$Label,'-Seconds',\"$seconds\",'-RecordFile',$recordFile,'-ArgsFile',$ArgsFile,'-Exe',$XtaskExe,'-OutFile',$outFile,'-ErrFile',$errFile,'-Admission','process-tree','-Scope','step')) { $psi.ArgumentList.Add($arg) }\n    if ($EnvironmentFile) { $psi.ArgumentList.Add('-EnvironmentFile'); $psi.ArgumentList.Add($EnvironmentFile) }\n    $proc = [Diagnostics.Process]::new(); $proc.StartInfo=$psi\n    try {\n        if (-not $proc.Start()) { throw 'LAUNCHER_NOT_STARTED' }\n        $stdoutTask=$proc.StandardOutput.ReadToEndAsync(); $stderrTask=$proc.StandardError.ReadToEndAsync()\n        # Never kill the bounding launcher: only its native job owns descendants.\n        $waitMs=[int][Math]::Max(1,[Math]::Min(2147483647,($Deadline-[DateTimeOffset]::UtcNow.ToUnixTimeSeconds())*1000))\n        if (-not $proc.WaitForExit($waitMs)) { throw 'LAUNCHER_EXIT_UNCONFIRMED' }\n        $attempt.launcher_exited=$true\n        New-Text $launchOut ($stdoutTask.GetAwaiter().GetResult())\n        New-Text $launchErr ($stderrTask.GetAwaiter().GetResult())\n        $r=Read-Json $recordFile\n        Assert-Gone $r\n        if ($proc.ExitCode -ne 0 -or $r.subject.native_exit -ne 0 -or $r.completion_reason -ne 'subject_exit' -or $null -ne $r.error) { throw 'NATIVE_STEP_FAILED' }\n        # Native records contain only identity/control fields, not capture bytes.\n        # Refuse any exceptional record rather than publishing exception content.\n        foreach ($line in [IO.File]::ReadLines($eventFile)) {\n            $event=ConvertFrom-Json -InputObject $line -AsHashtable\n            if ($null -ne $event.record.error) { throw 'NATIVE_EVENT_ERROR_REFUSED' }\n        }\n        $publicRecord=Join-Path $OutputRoot \"$Label.record.json\"\n        [StageNative]::CopyExclusive($recordFile,$publicRecord)\n        [StageNative]::CopyExclusive($eventFile,\"$publicRecord.events.jsonl\")\n        $attempt.public_record=$publicRecord\n        $steps.Add([ordered]@{label=$Label;record_file=$publicRecord;args_file=$ArgsFile;environment_seed_absent=$SeedAbsent;native_exit=0;termination='CONFIRMED_GONE';named_cap_seconds=$NamedCap;allocated_seconds=$seconds})\n        Assert-SeedAbsent; Check-Clock\n        return [ordered]@{stdout=$outFile;stderr=$errFile;record=$publicRecord}\n    } finally { $proc.Dispose(); $psi=$null; $stdoutTask=$null; $stderrTask=$null }\n}\nfunction Retire-PrivateFiles {\n    if (-not $privateOwned) { return $null }\n    foreach ($attempt in $attempts) {\n        if (-not $attempt.launcher_exited) { throw 'PRIVATE_RETIREMENT_BLOCKED_LAUNCHER' }\n        Assert-Gone (Read-Json $attempt.record_file)\n    }\n    Assert-PrivateAcl $privateRoot\n    # The exclusively owned directory is retained. Never archive or remove it.\n    # Only this invocation's exact declared files may be retired, never a glob.\n    foreach ($entry in [IO.Directory]::EnumerateFileSystemEntries($privateRoot)) {\n        if (-not $privateFiles.Contains($entry) -or [IO.Directory]::Exists($entry)) { throw 'UNEXPECTED_PRIVATE_ENTRY_RETAINED' }\n        $null=Identity $entry\n    }\n    $retired=[Collections.Generic.List[object]]::new()\n    foreach ($file in $privateFiles) {\n        if ([IO.File]::Exists($file)) { $null=Identity $file; [IO.File]::Delete($file) }\n        if ([IO.File]::Exists($file) -or [IO.Directory]::Exists($file)) { throw 'PRIVATE_RETIREMENT_FAILED' }\n        $retired.Add([ordered]@{path=$file;retired=$true})\n    }\n    return [ordered]@{completed=$true;all_owned_jobs_gone=$true;files=@($retired.ToArray());directory_retained=$true;memory_erasure_claimed=$false;completed_utc=[DateTime]::UtcNow.ToString('o')}\n}\ntry {\n    if (-not $IsWindows -or $PSVersionTable.PSVersion.Major -lt 7 -or -not [Environment]::Is64BitProcess) { throw 'WINDOWS_PS7_X64_REQUIRED' }\n    Check-Clock; Assert-SeedAbsent\n    # Stop any inherited manual transcript before a seed can exist. Policy-forced\n    # transcription/script-block logging cannot safely host secret bindings.\n    Stop-Transcript -ErrorAction SilentlyContinue | Out-Null\n    foreach ($base in @('HKLM:\\SOFTWARE\\Policies\\Microsoft\\Windows\\PowerShell','HKCU:\\SOFTWARE\\Policies\\Microsoft\\Windows\\PowerShell','HKLM:\\SOFTWARE\\Policies\\Microsoft\\PowerShellCore','HKCU:\\SOFTWARE\\Policies\\Microsoft\\PowerShellCore')) {\n        foreach ($policy in @(@('Transcription','EnableTranscripting'),@('ScriptBlockLogging','EnableScriptBlockLogging'),@('ModuleLogging','EnableModuleLogging'))) {\n            $value=Get-ItemPropertyValue -LiteralPath (Join-Path $base $policy[0]) -Name $policy[1] -ErrorAction SilentlyContinue\n            if ($value -eq 1) { throw 'POLICY_SECRET_CAPTURE_REFUSED' }\n        }\n    }\n    $windowsIdentity=[Security.Principal.WindowsIdentity]::GetCurrent()\n    try {\n        if ([Security.Principal.WindowsPrincipal]::new($windowsIdentity).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { throw 'ELEVATED_HOST_REFUSED' }\n        $ownerSid=$windowsIdentity.User.Value\n    } finally { $windowsIdentity.Dispose() }\n    # All native helper compilation happens now, in a seed-absent host.\n    Add-Type -TypeDefinition @'\nusing System;\nusing System.Text;\nusing System.ComponentModel;\nusing System.Runtime.InteropServices;\npublic static class StageNative {\n [StructLayout(LayoutKind.Sequential)] struct FT { public uint low,high; }\n [StructLayout(LayoutKind.Sequential)] struct FI { public uint attributes; public FT creation,access,write; public uint volume,sizeHigh,sizeLow,links,indexHigh,indexLow; }\n [StructLayout(LayoutKind.Sequential)] struct SA { public int length; public IntPtr descriptor; public int inherit; }\n public sealed class FileId { public string canonical_path {get;set;} public string file_id {get;set;} public uint attributes {get;set;} }\n [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern IntPtr CreateFileW(string p,uint access,uint share,IntPtr security,uint disposition,uint flags,IntPtr template);\n [DllImport(\"kernel32.dll\",SetLastError=true)] static extern bool GetFileInformationByHandle(IntPtr h,out FI info);\n [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern uint GetFinalPathNameByHandleW(IntPtr h,StringBuilder p,uint n,uint flags);\n [DllImport(\"kernel32.dll\",SetLastError=true)] static extern bool CloseHandle(IntPtr h);\n [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool CreateDirectoryW(string path,IntPtr security);\n [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool CopyFileW(string from,string to,bool failIfExists);\n [DllImport(\"advapi32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool ConvertStringSecurityDescriptorToSecurityDescriptorW(string sddl,uint revision,out IntPtr descriptor,out uint size);\n [DllImport(\"kernel32.dll\")] static extern IntPtr LocalFree(IntPtr p);\n public static FileId Identify(string path) {\n  // Sharing includes DELETE; no persistent handle can obstruct genuine apply.\n  IntPtr h=CreateFileW(path,0,7,IntPtr.Zero,3,0x02200000,IntPtr.Zero);\n  if(h==new IntPtr(-1))throw new Win32Exception(Marshal.GetLastWin32Error());\n  try { FI i; if(!GetFileInformationByHandle(h,out i))throw new Win32Exception(Marshal.GetLastWin32Error());\n   var b=new StringBuilder(32768); uint n=GetFinalPathNameByHandleW(h,b,(uint)b.Capacity,0);\n   if(n==0||n>=b.Capacity)throw new Win32Exception(Marshal.GetLastWin32Error());\n   string p=b.ToString(); if(p.StartsWith(@\"\\\\?\\\"))p=p.Substring(4);\n   return new FileId { canonical_path=p,file_id=i.volume.ToString(\"X8\")+\":\"+i.indexHigh.ToString(\"X8\")+i.indexLow.ToString(\"X8\"),attributes=i.attributes };\n  } finally { if(!CloseHandle(h))throw new Win32Exception(Marshal.GetLastWin32Error()); }\n }\n public static void CreateExclusive(string path,string sid) {\n  IntPtr sd=IntPtr.Zero,sa=IntPtr.Zero;\n  try { if(!String.IsNullOrEmpty(sid)) { uint size; if(!ConvertStringSecurityDescriptorToSecurityDescriptorW(\"O:\"+sid+\"D:P(A;OICI;FA;;;\"+sid+\")\",1,out sd,out size))throw new Win32Exception(Marshal.GetLastWin32Error());","truncated":true,"truncatedBy":"lines","totalLines":364,"totalBytes":14880,"outputLines":223,"outputBytes":14880,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":364,"displayContent":{"text":"# S6ESSJ3N authorized preparation A3-A4/B5-B7/C8-C9. No field authority.\n# Invoke in a fresh, unelevated PowerShell 7 process. Never dot-source.\n[CmdletBinding()]\nparam(\n    [Parameter(Mandatory)][string]$RigRoot,\n    [Parameter(Mandatory)][long]$Deadline,\n    [Parameter(Mandatory)][string]$OutputRoot,\n    [Parameter(Mandatory)][string]$SupportRoot,\n    [Parameter(Mandatory)][string]$SubjectExe,\n    [Parameter(Mandatory)][ValidatePattern('^[0-9a-fA-F]{64}$')][string]$SubjectSha256,\n    [Parameter(Mandatory)][string]$XtaskExe,\n    [Parameter(Mandatory)][ValidatePattern('^[0-9a-fA-F]{64}$')][string]$XtaskSha256\n)\n$ErrorActionPreference = 'Stop'\n$VerbosePreference = 'SilentlyContinue'\n$DebugPreference = 'SilentlyContinue'\n$InformationPreference = 'SilentlyContinue'\nSet-PSDebug -Off\nSet-StrictMode -Version Latest\n$utf8 = [Text.UTF8Encoding]::new($false)\n$keyId = 'hertz-r5-S6ESSJ3N'\n$version = [long]202609130001\n$platform = 'x86_64-pc-windows-msvc'\n$phase = 'PREFLIGHT'\n$privateRoot = $null\n$privateOwned = $false\n$publicReady = $false\n$steps = [Collections.Generic.List[object]]::new()\n$attempts = [Collections.Generic.List[object]]::new()\n$privateFiles = [Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase)\n$seed = $null; $keyText = $null; $seedMatches = $null; $publicMatches = $null; $overlay = $null\n$moduleTuple = [ordered]@{\n    commit = 'b848244577d398600b59c7829fef9edbdb6315fa'\n    common = 'c30d6b5466408b05d2dbd3032ca38043fbe0e5bb'\n    windows = '31ef24c8b203581eb6579c253dcfdc65c362f596'\n    linux = '08f615c4b0985a86ed8c42e96cfc3083857c4aff'\n}\nfunction Check-Clock {\n    if ([DateTimeOffset]::UtcNow.ToUnixTimeSeconds() -ge ($Deadline - 5)) { throw 'PREP_DEADLINE_EXPIRED' }\n}\nfunction Assert-SeedAbsent {\n    foreach ($name in @('SPT_DEBUG_RELEASE_SEED','SPT_RELEASE_SEED','SPT_RELEASE_SEED_CMD')) {\n        if ([Environment]::GetEnvironmentVariable($name, 'Process') -ne $null) { throw 'AMBIENT_SIGNING_SECRET_REFUSED' }\n    }\n}\nfunction Full([string]$Path) {\n    if (-not [IO.Path]::IsPathFullyQualified($Path)) { throw 'ABSOLUTE_PATH_REQUIRED' }\n    $p = [IO.Path]::GetFullPath($Path).TrimEnd('\\')\n    if ($p -notmatch '^[A-Za-z]:\\\\' -or $p.Substring(2).Contains(':')) { throw 'LOCAL_NON_ADS_PATH_REQUIRED' }\n    if (-not $p.Equals($Path.TrimEnd('\\'), [StringComparison]::OrdinalIgnoreCase)) { throw 'NORMALIZED_PATH_REQUIRED' }\n    return $p\n}\nfunction Below([string]$Child, [string]$Parent) {\n    return $Child.Equals($Parent, [StringComparison]::OrdinalIgnoreCase) -or $Child.StartsWith($Parent.TrimEnd('\\') + '\\', [StringComparison]::OrdinalIgnoreCase)\n}\nfunction Identity([string]$Path) {\n    $id = [StageNative]::Identify($Path)\n    if (($id.attributes -band 0x400) -ne 0) { throw 'REPARSE_PATH_REFUSED' }\n    if (-not $id.canonical_path.TrimEnd('\\').Equals($Path.TrimEnd('\\'), [StringComparison]::OrdinalIgnoreCase)) { throw 'CANONICAL_PATH_MISMATCH' }\n    return $id\n}\nfunction No-Reparse([string]$Path) {\n    $p = $Path\n    while ($p) {\n        if ([IO.File]::Exists($p) -or [IO.Directory]::Exists($p)) { $null = Identity $p }\n        $p = [IO.Path]::GetDirectoryName($p)\n    }\n}\nfunction Pin([string]$Path, [string]$Expected = '') {\n    No-Reparse $Path\n    if (-not [IO.File]::Exists($Path)) { throw 'INPUT_FILE_REQUIRED' }\n    $before = Identity $Path\n    $hash = (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash.ToLowerInvariant()\n    $after = Identity $Path\n    if ($before.file_id -ne $after.file_id -or ($Expected -and $hash -cne $Expected.ToLowerInvariant())) { throw 'PIN_MISMATCH' }\n    return [ordered]@{path=$Path;sha256=$hash;identity=$after}\n}\nfunction New-Text([string]$Path, [string]$Text) {\n    $stream = [IO.FileStream]::new($Path,[IO.FileMode]::CreateNew,[IO.FileAccess]::Write,[IO.FileShare]::None)\n    try { $bytes = $utf8.GetBytes($Text); $stream.Write($bytes,0,$bytes.Length); $stream.Flush($true) }\n    finally { $stream.Dispose(); $bytes = $null }\n}\nfunction New-Json([string]$Path, $Value) { New-Text $Path (ConvertTo-Json -InputObject $Value -Depth 24) }\nfunction New-Directory([string]$Path) {\n    Check-Clock\n    [StageNative]::CreateExclusive($Path, $null)\n    No-Reparse $Path\n}\nfunction Assert-PrivateAcl([string]$Path) {\n    No-Reparse $Path\n    $acl = Get-Acl -LiteralPath $Path\n    if ($acl.GetOwner([Security.Principal.SecurityIdentifier]).Value -cne $ownerSid -or -not $acl.AreAccessRulesProtected) { throw 'PRIVATE_ACL_OWNER_OR_INHERITANCE_REFUSED' }\n    $rules = @($acl.GetAccessRules($true,$true,[Security.Principal.SecurityIdentifier]))\n    if ($rules.Count -ne 1 -or $rules[0].IdentityReference.Value -cne $ownerSid -or $rules[0].AccessControlType -ne 'Allow' -or $rules[0].FileSystemRights -ne [Security.AccessControl.FileSystemRights]::FullControl -or ($rules[0].InheritanceFlags -band 3) -ne 3) { throw 'PRIVATE_ACL_NOT_OWNER_ONLY' }\n}\nfunction Private-Path([string]$Name) {\n    $p = Join-Path $privateRoot $Name\n    $null = $privateFiles.Add($p)\n    return $p\n}\nfunction Read-Json([string]$Path) { return (ConvertFrom-Json -InputObject ([IO.File]::ReadAllText($Path)) -AsHashtable) }\nfunction Assert-Gone($Record) {\n    if ($Record.version -ne 2 -or $Record.scope -ne 'step' -or $Record.coverage -ne 'COMPLETE' -or $Record.termination -ne 'CONFIRMED_GONE' -or $Record.job.assigned -ne $true -or $Record.job.membership_read -ne $true -or $Record.job.kill_on_close_read -ne $true -or $null -eq $Record.job.active_processes -or $Record.job.active_processes -ne 0 -or $Record.subject.state -notin @('EXITED','TERMINATED')) { throw 'OWNED_JOB_GONE_UNCONFIRMED' }\n}\nfunction Invoke-Step([string]$Label,[int]$NamedCap,[string]$ArgsFile,[string]$EnvironmentFile,[bool]$SeedAbsent) {\n    Check-Clock; Assert-SeedAbsent; Assert-PrivateAcl $privateRoot\n    $null = Pin $XtaskExe $XtaskSha256\n    $null = Pin $launcher '6e2c2eac82dd53fd0af42c4fe796f911e987d406e6f31219cd4480a78f1f6804'\n    $null = Pin $native 'c3a905ec7cbc118f0b59dd1813b187740319802267689e14dacf6008730de157'\n    $seconds = [int][Math]::Min($NamedCap, $Deadline - [DateTimeOffset]::UtcNow.ToUnixTimeSeconds() - 5)\n    if ($seconds -lt 1) { throw 'STEP_DEADLINE_EXPIRED' }\n    $recordFile = Private-Path \"$Label.record.json\"\n    $outFile = Private-Path \"$Label.stdout\"\n    $errFile = Private-Path \"$Label.stderr\"\n    $eventFile = Private-Path \"$Label.record.json.events.jsonl\"\n    $launchOut = Private-Path \"$Label.launcher.stdout\"\n    $launchErr = Private-Path \"$Label.launcher.stderr\"\n    $attempt = [ordered]@{label=$Label;record_file=$recordFile;launcher_exited=$false;public_record=$null}\n    $attempts.Add($attempt)\n    $psi = [Diagnostics.ProcessStartInfo]::new($pwsh)\n    $psi.UseShellExecute=$false; $psi.CreateNoWindow=$true\n    $psi.RedirectStandardOutput=$true; $psi.RedirectStandardError=$true\n    foreach ($arg in @('-NoProfile','-NonInteractive','-File',$launcher,'-Label',$Label,'-Seconds',\"$seconds\",'-RecordFile',$recordFile,'-ArgsFile',$ArgsFile,'-Exe',$XtaskExe,'-OutFile',$outFile,'-ErrFile',$errFile,'-Admission','process-tree','-Scope','step')) { $psi.ArgumentList.Add($arg) }\n    if ($EnvironmentFile) { $psi.ArgumentList.Add('-EnvironmentFile'); $psi.ArgumentList.Add($EnvironmentFile) }\n    $proc = [Diagnostics.Process]::new(); $proc.StartInfo=$psi\n    try {\n        if (-not $proc.Start()) { throw 'LAUNCHER_NOT_STARTED' }\n        $stdoutTask=$proc.StandardOutput.ReadToEndAsync(); $stderrTask=$proc.StandardError.ReadToEndAsync()\n        # Never kill the bounding launcher: only its native job owns descendants.\n        $waitMs=[int][Math]::Max(1,[Math]::Min(2147483647,($Deadline-[DateTimeOffset]::UtcNow.ToUnixTimeSeconds())*1000))\n        if (-not $proc.WaitForExit($waitMs)) { throw 'LAUNCHER_EXIT_UNCONFIRMED' }\n        $attempt.launcher_exited=$true\n        New-Text $launchOut ($stdoutTask.GetAwaiter().GetResult())\n        New-Text $launchErr ($stderrTask.GetAwaiter().GetResult())\n        $r=Read-Json $recordFile\n        Assert-Gone $r\n        if ($proc.ExitCode -ne 0 -or $r.subject.native_exit -ne 0 -or $r.completion_reason -ne 'subject_exit' -or $null -ne $r.error) { throw 'NATIVE_STEP_FAILED' }\n        # Native records contain only identity/control fields, not capture bytes.\n        # Refuse any exceptional record rather than publishing exception content.\n        foreach ($line in [IO.File]::ReadLines($eventFile)) {\n            $event=ConvertFrom-Json -InputObject $line -AsHashtable\n            if ($null -ne $event.record.error) { throw 'NATIVE_EVENT_ERROR_REFUSED' }\n        }\n        $publicRecord=Join-Path $OutputRoot \"$Label.record.json\"\n        [StageNative]::CopyExclusive($recordFile,$publicRecord)\n        [StageNative]::CopyExclusive($eventFile,\"$publicRecord.events.jsonl\")\n        $attempt.public_record=$publicRecord\n        $steps.Add([ordered]@{label=$Label;record_file=$publicRecord;args_file=$ArgsFile;environment_seed_absent=$SeedAbsent;native_exit=0;termination='CONFIRMED_GONE';named_cap_seconds=$NamedCap;allocated_seconds=$seconds})\n        Assert-SeedAbsent; Check-Clock\n        return [ordered]@{stdout=$outFile;stderr=$errFile;record=$publicRecord}\n    } finally { $proc.Dispose(); $psi=$null; $stdoutTask=$null; $stderrTask=$null }\n}\nfunction Retire-PrivateFiles {\n    if (-not $privateOwned) { return $null }\n    foreach ($attempt in $attempts) {\n        if (-not $attempt.launcher_exited) { throw 'PRIVATE_RETIREMENT_BLOCKED_LAUNCHER' }\n        Assert-Gone (Read-Json $attempt.record_file)\n    }\n    Assert-PrivateAcl $privateRoot\n    # The exclusively owned directory is retained. Never archive or remove it.\n    # Only this invocation's exact declared files may be retired, never a glob.\n    foreach ($entry in [IO.Directory]::EnumerateFileSystemEntries($privateRoot)) {\n        if (-not $privateFiles.Contains($entry) -or [IO.Directory]::Exists($entry)) { throw 'UNEXPECTED_PRIVATE_ENTRY_RETAINED' }\n        $null=Identity $entry\n    }\n    $retired=[Collections.Generic.List[object]]::new()\n    foreach ($file in $privateFiles) {\n        if ([IO.File]::Exists($file)) { $null=Identity $file; [IO.File]::Delete($file) }\n        if ([IO.File]::Exists($file) -or [IO.Directory]::Exists($file)) { throw 'PRIVATE_RETIREMENT_FAILED' }\n        $retired.Add([ordered]@{path=$file;retired=$true})\n    }\n    return [ordered]@{completed=$true;all_owned_jobs_gone=$true;files=@($retired.ToArray());directory_retained=$true;memory_erasure_claimed=$false;completed_utc=[DateTime]::UtcNow.ToString('o')}\n}\ntry {\n    if (-not $IsWindows -or $PSVersionTable.PSVersion.Major -lt 7 -or -not [Environment]::Is64BitProcess) { throw 'WINDOWS_PS7_X64_REQUIRED' }\n    Check-Clock; Assert-SeedAbsent\n    # Stop any inherited manual transcript before a seed can exist. Policy-forced\n    # transcription/script-block logging cannot safely host secret bindings.\n    Stop-Transcript -ErrorAction SilentlyContinue | Out-Null\n    foreach ($base in @('HKLM:\\SOFTWARE\\Policies\\Microsoft\\Windows\\PowerShell','HKCU:\\SOFTWARE\\Policies\\Microsoft\\Windows\\PowerShell','HKLM:\\SOFTWARE\\Policies\\Microsoft\\PowerShellCore','HKCU:\\SOFTWARE\\Policies\\Microsoft\\PowerShellCore')) {\n        foreach ($policy in @(@('Transcription','EnableTranscripting'),@('ScriptBlockLogging','EnableScriptBlockLogging'),@('ModuleLogging','EnableModuleLogging'))) {\n            $value=Get-ItemPropertyValue -LiteralPath (Join-Path $base $policy[0]) -Name $policy[1] -ErrorAction SilentlyContinue\n            if ($value -eq 1) { throw 'POLICY_SECRET_CAPTURE_REFUSED' }\n        }\n    }\n    $windowsIdentity=[Security.Principal.WindowsIdentity]::GetCurrent()\n    try {\n        if ([Security.Principal.WindowsPrincipal]::new($windowsIdentity).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { throw 'ELEVATED_HOST_REFUSED' }\n        $ownerSid=$windowsIdentity.User.Value\n    } finally { $windowsIdentity.Dispose() }\n    # All native helper compilation happens now, in a seed-absent host.\n    Add-Type -TypeDefinition @'\nusing System;\nusing System.Text;\nusing System.ComponentModel;\nusing System.Runtime.InteropServices;\npublic static class StageNative {\n [StructLayout(LayoutKind.Sequential)] struct FT { public uint low,high; }\n [StructLayout(LayoutKind.Sequential)] struct FI { public uint attributes; public FT creation,access,write; public uint volume,sizeHigh,sizeLow,links,indexHigh,indexLow; }\n [StructLayout(LayoutKind.Sequential)] struct SA { public int length; public IntPtr descriptor; public int inherit; }\n public sealed class FileId { public string canonical_path {get;set;} public string file_id {get;set;} public uint attributes {get;set;} }\n [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern IntPtr CreateFileW(string p,uint access,uint share,IntPtr security,uint disposition,uint flags,IntPtr template);\n [DllImport(\"kernel32.dll\",SetLastError=true)] static extern bool GetFileInformationByHandle(IntPtr h,out FI info);\n [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern uint GetFinalPathNameByHandleW(IntPtr h,StringBuilder p,uint n,uint flags);\n [DllImport(\"kernel32.dll\",SetLastError=true)] static extern bool CloseHandle(IntPtr h);\n [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool CreateDirectoryW(string path,IntPtr security);\n [DllImport(\"kernel32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool CopyFileW(string from,string to,bool failIfExists);\n [DllImport(\"advapi32.dll\",CharSet=CharSet.Unicode,SetLastError=true)] static extern bool ConvertStringSecurityDescriptorToSecurityDescriptorW(string sddl,uint revision,out IntPtr descriptor,out uint size);\n [DllImport(\"kernel32.dll\")] static extern IntPtr LocalFree(IntPtr p);\n public static FileId Identify(string path) {\n  // Sharing includes DELETE; no persistent handle can obstruct genuine apply.\n  IntPtr h=CreateFileW(path,0,7,IntPtr.Zero,3,0x02200000,IntPtr.Zero);\n  if(h==new IntPtr(-1))throw new Win32Exception(Marshal.GetLastWin32Error());\n  try { FI i; if(!GetFileInformationByHandle(h,out i))throw new Win32Exception(Marshal.GetLastWin32Error());\n   var b=new StringBuilder(32768); uint n=GetFinalPathNameByHandleW(h,b,(uint)b.Capacity,0);\n   if(n==0||n>=b.Capacity)throw new Win32Exception(Marshal.GetLastWin32Error());\n   string p=b.ToString(); if(p.StartsWith(@\"\\\\?\\\"))p=p.Substring(4);\n   return new FileId { canonical_path=p,file_id=i.volume.ToString(\"X8\")+\":\"+i.indexHigh.ToString(\"X8\")+i.indexLow.ToString(\"X8\"),attributes=i.attributes };\n  } finally { if(!CloseHandle(h))throw new Win32Exception(Marshal.GetLastWin32Error()); }\n }\n public static void CreateExclusive(string path,string sid) {\n  IntPtr sd=IntPtr.Zero,sa=IntPtr.Zero;\n  try { if(!String.IsNullOrEmpty(sid)) { uint size; if(!ConvertStringSecurityDescriptorToSecurityDescriptorW(\"O:\"+sid+\"D:P(A;OICI;FA;;;\"+sid+\")\",1,out sd,out size))throw new Win32Exception(Marshal.GetLastWin32Error());\n…\n'@\n…\n    exit 0\n} catch {\n…\n}","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,null,231,null,324,325,null,364]},"fileSize":27933,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\hertz-fp-driver-review\\d2\\provision-stage-DJNQQ2RA.ps1"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":364,"totalBytes":14880,"outputLines":223,"outputBytes":14880,"shownRange":{"start":1,"end":223},"nextOffset":224}}},"isError":false,"timestamp":1789312377606}}