{
  "amendment": "r10-S2-ENA6WIMS",
  "authority": "Doyle ENA6WIMS, 2026-09-14T10:49:26Z",
  "status": "REBOUND; NO PROVISIONING OR FIELD EXECUTION AUTHORIZED BY THIS FILE ALONE",
  "packet_nonce": "S2-W6-ENA6WIMS-53b027cd95c94b4b8b1b0bcb7a4ecdec",
  "window": 6,
  "candidate_commit": "527cd8e8d7ef192892d5630fce10e69a6d811893",
  "subject": {
    "source_tree": "C:/Users/decid/Documents/projects/spt-core/.worktrees/release-S2-527cd8e8",
    "artifacts": [
      {
        "name": "spt.exe",
        "path": "C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\release-S2-527cd8e8\\target\\release\\spt.exe",
        "bytes": 38876672,
        "sha256": "d90954220c0e74594e4c3a78603365a0d1e1d742498d60e6bdbafac7c3dfe645"
      },
      {
        "name": "xtask.exe",
        "path": "C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\release-S2-527cd8e8\\target\\release\\xtask.exe",
        "bytes": 5217280,
        "sha256": "2d5a8c05e6c0f3ed7cbc0b3fce0914c4090efc33e7b33e50c925d9697ce1c523"
      }
    ],
    "version": {
      "exit": 0,
      "stdout": "spt 0.70.0\n",
      "stderr": ""
    },
    "provenance": "Cold build exit 0, 11m44s; artifact hashes independently verified by Doyle. Release receipt read by hertz; build/version/tests were not rerun for this amendment.",
    "receipt": ".spt/preserved/304-handoff/consumer-linux-S2-527cd8e8/windows-release/release-artifacts.json",
    "windows_changed_cells": "10/10 each at S2; hertz-phase-b-B2FGTAFA/s2-final-receipt.json",
    "linux_changed_cells": "20/20 across both cells, reported by Doyle ENA6WIMS",
    "source_blobs": {
      "crates/spt-daemon/src/bootstrap_firewall.rs": "6e6d102c9043881fc721c3e0e7840a07e2ed40e6",
      "crates/spt-daemon/src/bootstrap_firewall/windows.rs": "56ff917657e794a1649961bf4780a63409acadb9",
      "crates/spt-daemon/src/bootstrap_firewall/linux.rs": "8947958725008b5efc6ed55646869ffff53aa4ab",
      "crates/spt/src/serveverb.rs": "b7d57d39b902dfa277de4667e4d22bfaa31e43e6"
    }
  },
  "driver": {
    "frozen_template": ".spt/preserved/hertz-fp-driver-review/d2/fp-driver-d2-r10-P9RLK4VU.sh",
    "template_sha256": "b499cb07a045aed5707ce29dc0344dcd69d1e2e58d7883649c4b8252e2a89b39",
    "configuration_assignments": {
      "W": "C:/Users/decid/Documents/projects/spt-core/.worktrees/release-S2-527cd8e8",
      "SP": "C:/Users/decid/Documents/projects/spt-core/.spt/preserved/hertz-fp-driver-review/d2/field-rig-r10-w6-ENA6WIMS/support",
      "RIG_ROOT": "C:/Users/decid/Documents/projects/spt-core/.spt/preserved/hertz-fp-driver-review/d2/field-rig-r10-w6-ENA6WIMS",
      "EXE_SHA": "d90954220c0e74594e4c3a78603365a0d1e1d742498d60e6bdbafac7c3dfe645",
      "SUBJECT_SHA": "527cd8e8d7ef192892d5630fce10e69a6d811893",
      "SUBJECT_BLOB": "56ff917657e794a1649961bf4780a63409acadb9"
    },
    "derivation": "Read the hash-verified template as UTF-8 bytes. For each of the six keys above, replace only the single-quoted value of its unique line-start assignment; preserve quotes, trailing comments, whitespace, line endings and every other byte. Each key must match exactly once. No logic, clock, exit-reader or protocol changes.",
    "configured_sha256": "474f6efc4d4f1457c106086180c2213c4ceb3f5cbda4a0d171e1c7b602acf07a",
    "configured_bytes": 211293,
    "materialization": "Configured bytes were derived and Bash-parsed in memory only. Materialize as a new file in the fresh support preparation, never overwrite the frozen template; require this configured SHA in the support manifest before invocation. No fifth-run support or artifact is reused as a writable destination.",
    "qualification": {
      "changed_assignment_lines": 6,
      "bash_n_exit": 0,
      "standing_logic_controls": "P9RLK4VU 16/16; no field execution",
      "executable_invocations_during_rebind": 0
    }
  },
  "executor": {
    "name": "liam",
    "runner": "leg-runner-r10.frozen.sh",
    "runner_sha256": "ea2f38861725254c8c5f62c49275e5fe882f256c8028286752590fdb50ccabd5",
    "qualification_receipt": ".spt/preserved/hertz-fp-driver-review/d2/AQ23KKNI-consumer-XOL7W64Q.json",
    "required": "Liam measures the runner, rig-copy executable and capture hashes and dry-runs the exact newly emitted request before the leg. Readiness is PREPARED/NOT_STARTED, not GO. A stale tuple check or any hash/transport mismatch refuses; never patch the frozen runner to bypass it."
  },
  "isolation": {
    "fresh_rig_root": "C:/Users/decid/Documents/projects/spt-core/.spt/preserved/hertz-fp-driver-review/d2/field-rig-r10-w6-ENA6WIMS",
    "home": "C:/Users/decid/Documents/projects/spt-core/.spt/preserved/hertz-fp-driver-review/d2/field-rig-r10-w6-ENA6WIMS/home",
    "sole_product_executable": "C:/Users/decid/Documents/projects/spt-core/.spt/preserved/hertz-fp-driver-review/d2/field-rig-r10-w6-ENA6WIMS/bin/spt.exe",
    "source_executable_use": "CopyFileW fail-if-exists into the fresh rig; verify equality to d9095422... . Do not run update/apply against the cold worktree artifact or fleet installation.",
    "freshness": "Root observed absent during amendment preparation; atomic CreateDirectoryW exclusivity and canonical/reparse checks remain mandatory at provisioning. One consumed marker and first matching run only. Fifth root, node.key, evidence and expired clocks remain untouched.",
    "disposal": "No filesystem rig disposal or broad process killing granted."
  },
  "environment_precondition": {
    "applies_to": "Every provisioning/field child launcher and Liam elevated executor shell, without changing the live parent session.",
    "purge": "All ambient OWL_* and SPT_* names except explicitly declared per-leg settings. SPT_RELEASE_SEED must be absent. Record before/after key NAMES only, never values.",
    "allowed_by_design": "SPT_HOME is set only to the fresh rig home for the declared product command. SPT_TEST_EPHEMERAL_ADVISORY_PORTS may be set only where the pinned provisioning launcher declares it. SPT_INSTALL_NO_FIREWALL is absent for setup.",
    "signing": "SPT_DEBUG_RELEASE_SEED only in the private controlled signer EnvironmentFile; never ambient, argv, public receipt or inventory. Existing seed-custody and retirement gates remain.",
    "capture_environment_file": "Exactly {}; capture inherits the already scrubbed executor environment. PSModulePath is not repaired or normalized."
  },
  "capture": {
    "sha256": "69b8506ac932841223996e7d5ad5ab03a51662ce4eacc6da77dad458a03f620c",
    "powershell7": "C:/Program Files/PowerShell/7/pwsh.exe",
    "step_7_from_scrubbed_elevated_bash": "pwsh -NoProfile -Command \"<T1_LAUNCH from the setup request, verbatim>; exit \\$LASTEXITCODE\"",
    "shape": "Evaluating PowerShell 7 host -> request-pinned pwsh -NoProfile -File launch-v2.ps1 -> PowerShell 7 capture subject. Do not pass the PowerShell expression directly to Bash; no Windows PowerShell-from-Bash capture substitution.",
    "exit_contract": "The trailing exit $LASTEXITCODE preserves the launcher status. Write it to then_write_its_launcher_exit_to (d2-t1.exit). The capture subject native exit stays in d2-t1.native.json, separate from setup.exit.",
    "sequence": [
      "Run leg_clock_begin_powershell verbatim immediately before setup: one UTC observation, CreateNew setup-start.utc/elevated-leg-start.epoch/d2-t1.deadline; any existing file refuses.",
      "Run the request run_exactly command and declared redirections.",
      "Preserve setup exit immediately.",
      "Stamp setup-return.utc.",
      "Write preserved setup.exit before capture.",
      "Stamp d2-t1-start.utc.",
      "Run the exact step-7 shape above; preserve and write launcher exit separately.",
      "Stamp d2-t1-end.utc."
    ],
    "setup_argv_shape": "env -u SPT_INSTALL_NO_FIREWALL SPT_HOME=\"<fresh rig home>\" \"<fresh rig bin/spt.exe>\" serve lan --bootstrap --port 29470; use only the concrete run_exactly line and redirects emitted in the new request."
  },
  "clocks": {
    "preparation_seconds": 600,
    "preparation_origin": "One separately authorized fresh A2 observation, carried through GO without reset; no clock started by this amendment.",
    "activity_seconds": 630,
    "activity_origin": "Actual driver GO, after valid run-bound authorization and final preparation recheck.",
    "pre_dispatch_seconds": 74,
    "setup_request_to_receipt_seconds": 240,
    "setup_only_handoff_extension": true,
    "elevated_leg_seconds": 120,
    "elevated_leg_origin": "Step 1, not request emission; deadline = that single epoch +120, CreateNew, never reset.",
    "capture_native_seconds": "min(90, d2-t1.deadline - current UTC epoch -5); nonpositive remaining time refuses.",
    "post_receipt_probes_seconds": 200,
    "t2_allocation_seconds": 100,
    "transition_reserve_seconds": 16,
    "cleanup_report_seconds": 180,
    "ledger_reserve_in_cleanup_seconds": 30,
    "other_handoff_cap_seconds": 120,
    "policy": "Existing clamping, late-receipt reporting, timeouts and fail-closed cleanup gates stay unchanged."
  },
  "d3": {
    "literal_file": ".spt/preserved/hertz-fp-driver-review/d2/teardown-command.pinned",
    "literal_bytes": 8514,
    "literal_sha256": "38e0f21b2cf2ef1f9d986c650f2f6b0d36335ba25c8b017fe8dcbd5219c94676",
    "encoded_payload_sha256": "416280dbece2601203c74c3f8e2c46e13009125fa5870166894e079329fb1d43",
    "source_binding_proof": "Hertz compared b8482445 to S2: the entire Windows prefix through script()/encoded() is byte-identical, as is cleanup_command(). Standing 85f84d73 -> b8482445 proof and exact payload comparison therefore extend to S2. Common/Linux full blobs changed and are separately rebound above; they are NOT claimed unchanged.",
    "literal_rule": "Execute only the pinned literal, never reconstruct a cleanup command or broaden its scope. If the product emits a cleanup payload, require byte equality to the pinned payload before D3; mismatch stops. No runtime cleanup renderer was invoked here.",
    "scope": "Exact owned names spt-core-bootstrap-inbound-tcp and spt-core-bootstrap-inbound-tcp-lan, group spt-core bootstrap TCP. Guard port 5470 and its rule remain read-only; subject port 29470.",
    "preconditions": "Prove pre-existing owned pair absent, live guard intact, and this run owns any created pair. Pinned cleanup does not itself establish run identity or port ownership.",
    "postcondition": "Native cleanup success plus independent exact-name checks in PersistentStore and ActiveStore; partial failure requires fresh residual evidence, not blind retry. Nothing-to-remove is a measured outcome, not inferred from command silence."
  },
  "nonce_and_GO": {
    "packet_vs_request": "The fresh packet_nonce binds this amendment and root. It is NOT a substitute for driver-generated request nonces. Each request uses its fresh RUN_ID-sequence-pid nonce; never reuse the fifth run or an old receipt.",
    "operational_authorizer": "Doyle only; authorizer=doyle in a file is routing/consistency, not authentication.",
    "operational_GO_fields": [
      "This amendment path and exact SHA256",
      "candidate 527cd8e8d7ef192892d5630fce10e69a6d811893 and executable d90954220c0e74594e4c3a78603365a0d1e1d742498d60e6bdbafac7c3dfe645",
      "exact packet_nonce and fresh rig root",
      "fresh BOX CLEAR receipt including release-S2-527cd8e8/target plus all participating roots",
      "explicit authorization of ONE fresh A2/provisioning and ONE window6, Liam as elevated executor, first matching future run/nonce only after all gates succeed; no resets/disposal"
    ],
    "driver_receipt_shape": "GO_AUTHORIZED\nauthorizer=doyle\nnonce: <exact nonce from this run's go-authorization request>\n",
    "receipt_destination": "Exactly receipt_file from that new go-authorization request. Write only after the corresponding Doyle decision; never precreate a receipt or substitute packet_nonce for GO_ACK_NONCE.",
    "remaining_gates": "BOX CLEAR is a sample, not a lease. Driver CI/ancestry gates, separate executor PREPARED/NOT_STARTED hash acknowledgment, genuine staging/apply/promotion, consumed-state check, D3 pin, and final preparation deadline check must all pass. If cold build/test/merge-push activity intervenes, refresh admission.",
    "BOX_CLEAR_reference": ".spt/preserved/304-handoff/hertz-phase-b-B2FGTAFA/BOX-CLEAR-EQZRXXIJ.json",
    "required_additional_target": "C:/Users/decid/Documents/projects/spt-core/.worktrees/release-S2-527cd8e8/target"
  },
  "validation": {
    "traceable_reqs_version": "0.4.1",
    "traceable_reqs": {
      "requirementCount": 918,
      "completeCount": 918,
      "incompleteCount": 0,
      "findingCount": 0
    },
    "driver_template_hash_verified": true,
    "D3_literal_and_payload_hashes_verified": true,
    "D3_composition_prefix_equal": true,
    "D3_cleanup_function_equal": true,
    "configured_driver_bash_syntax_exit": 0,
    "scope": "Read-only artifact/source checks and in-memory configuration parsing only. No new rig, key, trust, update, daemon, firewall command or field window.",
    "step7_transport_control": {
      "result": "PASS",
      "native_exit": 0,
      "scope": "Bash function captures argv; no PowerShell, launcher or product is run. Literal trailing $LASTEXITCODE survives the documented quoting."
    }
  },
  "packet_identity": "This single amendment is the new packet. Its identity is the SHA256 of the exact saved file bytes, announced separately with GO; no old DJNQQ2RA packet or nonce carries forward."
}
