CHAT_OUTPUT_BEGIN
COMMAND_ID=SIGNALBOT-260908-PACKAGE-SEAL-RCA-043PKGFIX4
STATUS=FAIL
RC=3
HOST=pve01
MODE=read-only
COMPONENT=signalbot-cr0116-package-seal-rca
REFERENCE_REGISTER_CHECK=OK
REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66
ERROR_REGISTER_CHECK=OK
ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0
COMMAND_SHA256=9ced1576bd959feda816a33885905e1bed85156c58d9145f8a4027570dcfa64d
DUPLICATE_FAILED_COMMAND_BLOCKED=false
EXECUTION_STARTED=true
CHANGE_DECLARED=false
RESULT_CONTRACT_VALID=true
RESULT_CONTRACT_STATUS=NOT_APPLICABLE
RESULT_CONTRACT_ERROR=NONE
COMMAND_RC=3
CHANGES_MADE=false
ROLLBACK_STARTED=false
ROLLBACK_RESTORED=null
MUTATION_OUTCOME=NO_MUTATION
SANITIZED=yes
SECRETS_INCLUDED=no
PRIVATE_ADDRESSES_INCLUDED=no
RAW_EVIDENCE_SHA256=f6bfc5e0e811b34437723475517c13047e89a5cd17aa1cba4a3bd9e162dd0583
SANITIZED_OUTPUT_SHA256=f6bfc5e0e811b34437723475517c13047e89a5cd17aa1cba4a3bd9e162dd0583
OUTPUT_BEGIN
ERROR_REGISTER_CHECK=OK
REFERENCE_CHECK=OK
AUTHORITY_CHECK_SCOPE=READABILITY_ONLY_INCIDENTS_NOT_CLOSED
SB043KF4_PRESTATE={"active_env":{"APP_IMAGE":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","CODE_IDENTITY":"e32760c69a4311728db9066ee8bf2bf66b1e5a70","COLLECTION_START_AT":"2026-09-07T00:00:00+00:00","EXPERIMENT_ID":"ec477ea41ecbd5cfdef5afc259595aab20674a7d933f41a389329ff05098b338","RUNTIME_MANIFEST_ID":"58d3b59200bdc0eb8d448612679d667b194263586cb3198dfc08597935053a1a"},"services":[{"container_id":"a546a70c3e8c263d9b590cd78ee206bcda0cfcdb6662327e8415ca0e29ad1501","image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":15,"running":true,"service":"collector","started_at":"2026-09-08T08:18:12.235219419Z"},{"container_id":"d8023f4cbf91f9382e39eec0436c9cebc7665535b42b950e95408c03ff9bf30d","image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"relay","started_at":"2026-09-06T18:48:20.603414848Z"},{"container_id":"1feeca2d9428cd5a277c026bef34534db307657dcdcd63aff98ea66e44f8b9c5","image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"shadow","started_at":"2026-09-06T18:48:20.768190553Z"},{"container_id":"889be41d2cee9d327811da78388f834ba6eafe4c0eeae456867ed0df76832d01","image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"worker","started_at":"2026-09-06T18:48:20.586788319Z"}],"stage_result":{"active_env_unchanged":true,"build_context":"/opt/stacks/8020-demonov-shadow/.deploy/SIGNALBOT-260908-DEPLOY-STAGE-042FIX5","collector_source_sha256":"193dd0c7f9890fdb4026c24dbc5add825f1641d92097e881806705ca452812d5","copy_source":"/opt/stacks/8020-demonov-shadow/.deploy/SIGNALBOT-260908-DEPLOY-STAGE-042FIX5/demonov_forward_map","decision":"DEPLOY_STAGE_READY","dockerfile":"/opt/stacks/8020-demonov-shadow/.deploy/SIGNALBOT-260908-DEPLOY-STAGE-042FIX5/Dockerfile","helper_candidates":{"demonov_forward_map.live_prospective":[{"name":"_hash","pure_candidate":true,"signature":"(value: 'object') -> 'str'"}],"demonov_forward_map.runtime_integrity":[{"name":"canonical_hash","pure_candidate":true,"signature":"(payload: 'Any') -> 'str'"},{"name":"verify_experiment_seal_receipt","pure_candidate":true,"signature":"(*, bundle: 'FinalProspectiveSealBundle', receipt: 'ExperimentSealReceipt', collection_start_at: 'datetime', receipt_verifier: 'Callable[[ExperimentSealReceipt], bool]') -> 'None'"},{"name":"required_retained_hashes","pure_candidate":true,"signature":"(*, runtime_registry: 'RuntimeRegistry', model_registry: 'FinalModelRegistry', state_snapshots: 'Sequence[StateSnapshotManifest]' = (), predictor_runtime: 'PredictorRuntimeManifest | None' = None) -> 'Mapping[str, RetainedArtifactKind]'"}],"demonov_forward_map.runtime_manifest":[{"name":"canonical_hash","pure_candidate":true,"signature":"(payload: 'Any') -> 'str'"},{"name":"verify_runtime_manifest","pure_candidate":true,"signature":"(manifest: 'RuntimeDeploymentManifestV1', *, expected_code_identity: 'str', actual_image_id: 'str', actual_package_identity: 'str') -> 'None'"}]},"new_image":"8020-demonov-shadow:76e1f58baa544a0e208bba317f0150e5b6d74dbd","new_image_id":"sha256:341f71a906c91d3fa9c1d50bd89df2a849dfb0b168bb4551efb444bf61c4ab99","policy":{"close_timeout":5,"open_timeout":10,"ping_interval":20,"ping_timeout":60},"runtime_activated":false,"service_identity_unchanged":true,"stage_path":"/opt/stacks/8020-demonov-shadow/.deploy/SIGNALBOT-260908-DEPLOY-STAGE-042FIX5","websockets_version":"15.0.1"}}
SB043KF4_CANONICAL_VALIDATION={"computed":"ab8a8d8f361c0c86f709fe84f27ba4378f9978fb802cbfb2a542ea9833ad48df","expected":"58d3b59200bdc0eb8d448612679d667b194263586cb3198dfc08597935053a1a","ok":false,"spec":{"class_fields":["runtime_manifest_id","code_identity","package_identity","application_image_id","base_image_digest","compose_hash","finality_policy_id"],"kind":"dict","parts":[{"key":"schema","kind":"const","value":"CR0116_RUNTIME_DEPLOYMENT_MANIFEST_V1"},{"key":"code_identity","kind":"field","value":"code_identity"},{"key":"package_identity","kind":"field","value":"package_identity"},{"key":"application_image_id","kind":"field","value":"application_image_id"},{"key":"base_image_digest","kind":"field","value":"base_image_digest"},{"key":"compose_hash","kind":"field","value":"compose_hash"},{"key":"finality_policy_id","kind":"field","value":"finality_policy_id"}],"source":"def content_hash(self) -> str:\n        return canonical_hash(\n            {\n                \"schema\": \"CR0116_RUNTIME_DEPLOYMENT_MANIFEST_V1\",\n                \"code_identity\": self.code_identity,\n                \"package_identity\": self.package_identity,\n                \"application_image_id\": self.application_image_id,\n                \"base_image_digest\": self.base_image_digest,\n                \"compose_hash\": self.compose_hash,\n                \"finality_policy_id\": self.finality_policy_id,\n            }\n        )"}}
SB043KF4_ARTIFACT_SPEC={"class_fields":["artifact_id","source_tree_hash","dependency_lock_hash","build_recipe_hash","executable_artifact_hash","runtime_environment_hash"],"fields":["source_tree_hash","dependency_lock_hash","build_recipe_hash","executable_artifact_hash","runtime_environment_hash"],"kind":"dictcomp","source":"def content_hash(self) -> str:\n        return canonical_hash({k: getattr(self, k) for k in (\n            \"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"\n        )})"}
SB043KF4_CALLSITES=[{"name":"RuntimeArtifactManifest","node":"ClassDef","path":"runtime_integrity.py","score":5,"source":"class RuntimeArtifactManifest:\n    artifact_id: str\n    source_tree_hash: str\n    dependency_lock_hash: str\n    build_recipe_hash: str\n    executable_artifact_hash: str\n    runtime_environment_hash: str\n\n    def __post_init__(self) -> None:\n        for name in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"):\n            _hex64(getattr(self, name), name)\n        if self.artifact_id != self.content_hash:\n            raise DemonovError(\"runtime artifact id must be content-addressed\")\n\n    @property\n    def content_hash(self) -> str:\n        return canonical_hash({k: getattr(self, k) for k in (\n            \"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"\n        )})\n\n    @classmethod\n    def build(cls, **kwargs) -> \"RuntimeArtifactManifest\":\n        payload = {k: kwargs[k] for k in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\")}\n        return cls(artifact_id=canonical_hash(payload), **kwargs)","source_sha256":"8cd1ebf70c003cd4d7b91f18602841426b19c2f54f2d803309c53c22f38cd5c7"},{"name":"DeploymentAttestation","node":"ClassDef","path":"runtime_integrity.py","score":4,"source":"class DeploymentAttestation:\n    attestation_id: str\n    subject_kind: DeploymentSubjectKind\n    subject_id: str\n    actor_id: str\n    source_tree_hash: str\n    dependency_lock_hash: str\n    executable_artifact_hash: str\n    runtime_environment_hash: str\n    effective_config_hash: str\n    deployed_at: datetime\n    issued_at: datetime\n    authority_provider_id: str\n    authority_receipt_hash: str\n    feature_extractor_code_hash: str = \"\"\n\n    def __post_init__(self) -> None:\n        _aware(self.deployed_at, \"deployment deployed_at\"); _aware(self.issued_at, \"deployment issued_at\")\n        if self.issued_at < self.deployed_at:\n            raise DemonovError(\"deployment attestation cannot be issued before deployment\")\n        if not self.actor_id or not self.authority_provider_id:\n            raise DemonovError(\"deployment attestation identity fields are required\")\n        for n in (\"subject_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"executable_artifact_hash\",\n                  \"runtime_environment_hash\",\"effective_config_hash\",\"authority_receipt_hash\"):\n            _hex64(getattr(self,n),n)\n        if self.feature_extractor_code_hash: _hex64(self.feature_extractor_code_hash,\"feature_extractor_code_hash\")\n        if self.attestation_id != self.content_hash:\n            raise DemonovError(\"deployment attestation id must be content-addressed\")\n\n    @property\n    def content_hash(self) -> str:\n        payload={\"subject_kind\":self.subject_kind,\"subject_id\":self.subject_id,\"actor_id\":self.actor_id,\n                 \"source_tree_hash\":self.source_tree_hash,\"dependency_lock_hash\":self.dependency_lock_hash,\n                 \"executable_artifact_hash\":self.executable_artifact_hash,\"runtime_environment_hash\":self.runtime_environment_hash,\n                 \"effective_config_hash\":self.effective_config_hash,\"deployed_at\":self.deployed_at,\"issued_at\":self.issued_at,\n                 \"authority_provider_id\":self.authority_provider_id,\"authority_receipt_hash\":self.authority_receipt_hash}\n        if self.feature_extractor_code_hash: payload[\"feature_extractor_code_hash\"]=self.feature_extractor_code_hash\n        return canonical_hash(payload)\n\n    @classmethod\n    def build(cls, **kwargs) -> \"DeploymentAttestation\":\n        payload={k:kwargs[k] for k in (\"subject_kind\",\"subject_id\",\"actor_id\",\"source_tree_hash\",\"dependency_lock_hash\",\n            \"executable_artifact_hash\",\"runtime_environment_hash\",\"effective_config_hash\",\"deployed_at\",\"issued_at\",\n            \"authority_provider_id\",\"authority_receipt_hash\")}\n        if kwargs.get(\"feature_extractor_code_hash\"): payload[\"feature_extractor_code_hash\"]=kwargs[\"feature_extractor_code_hash\"]\n        return cls(attestation_id=canonical_hash(payload),**kwargs)","source_sha256":"1b0ca84bb035dfb7ff441ce73bbe8ee5f140a07b4a821f5a9f55770b585ffac7"},{"name":"verify_final_deployment_attestations","node":"FunctionDef","path":"runtime_integrity.py","score":4,"source":"def verify_final_deployment_attestations(*, runtime_registry: RuntimeRegistry, producer_id: str,\n                                         predictor_runtime: \"PredictorRuntimeManifest\",\n                                         attestations: Sequence[DeploymentAttestation],\n                                         policy: DeploymentAttestationPolicy,\n                                         collection_start_at: datetime,\n                                         receipt_verifier: Callable[[DeploymentAttestation], bool]) -> None:\n    _aware(collection_start_at,\"collection_start_at\")\n    relevant_epochs=[e for e in runtime_registry.epochs if e.producer_id==producer_id and e.contains(collection_start_at)]\n    if len(relevant_epochs)!=1:\n        raise DemonovError(\"collection start must resolve to exactly one producer runtime epoch for deployment proof\")\n    epoch=relevant_epochs[0]\n    artifact=next((a for a in runtime_registry.artifacts if a.artifact_id==epoch.artifact_id),None)\n    if artifact is None: raise DemonovError(\"producer deployment proof references missing runtime artifact\")\n    expected={\n        (DeploymentSubjectKind.PRODUCER_RUNTIME_EPOCH,epoch.epoch_id):(\n            producer_id,artifact.source_tree_hash,artifact.dependency_lock_hash,artifact.executable_artifact_hash,\n            artifact.runtime_environment_hash,epoch.config_id,\"\",epoch.started_at),\n        (DeploymentSubjectKind.PREDICTOR_RUNTIME,predictor_runtime.predictor_runtime_id):(\n            predictor_runtime.consumer_id,predictor_runtime.source_tree_hash,predictor_runtime.dependency_lock_hash,\n            predictor_runtime.executable_artifact_hash,predictor_runtime.runtime_environment_hash,predictor_runtime.effective_config_hash,\n            predictor_runtime.feature_extractor_code_hash,predictor_runtime.started_at),\n    }\n    amap={(a.subject_kind,a.subject_id):a for a in attestations}\n    if len(amap)!=len(attestations): raise DemonovError(\"duplicate deployment attestation subject\")\n    if set(amap)!=set(expected): raise DemonovError(\"deployment attestation set differs from exact producer/predictor subjects\")\n    for key,(actor,src,dep,exe,env,cfg,feature,start) in expected.items():\n        a=amap[key]\n        if a.authority_provider_id!=policy.authority_provider_id or not receipt_verifier(a):\n            raise DemonovError(\"deployment attestation authority verification failed\")\n        if (a.actor_id,a.source_tree_hash,a.dependency_lock_hash,a.executable_artifact_hash,a.runtime_environment_hash,a.effective_config_hash)!=(actor,src,dep,exe,env,cfg):\n            raise DemonovError(\"deployment attestation artifact/config identity mismatch\")\n        if key[0] is DeploymentSubjectKind.PREDICTOR_RUNTIME and a.feature_extractor_code_hash!=feature:\n            raise DemonovError(\"predictor deployment attestation feature extractor mismatch\")\n        if key[0] is DeploymentSubjectKind.PRODUCER_RUNTIME_EPOCH and a.feature_extractor_code_hash:\n            raise DemonovError(\"producer deployment attestation must not invent challenger feature extractor\")\n        if abs((a.deployed_at-start).total_seconds()) > policy.max_start_skew_seconds:\n            raise DemonovError(\"deployment attestation outside frozen runtime-start skew\")\n        if policy.require_precollection_attestation and a.issued_at >= collection_start_at:\n            raise DemonovError(\"deployment attestation must be externally issued strictly before collection start\")","source_sha256":"9fc5b8d032d6a7b31f6b4e21d15142fe20b1fde4fe30a06fb758ad264bdeac9d"},{"name":"PredictorRuntimeManifest","node":"ClassDef","path":"runtime_integrity.py","score":4,"source":"class PredictorRuntimeManifest:\n    predictor_runtime_id: str\n    consumer_id: str\n    source_tree_hash: str\n    dependency_lock_hash: str\n    runtime_environment_hash: str\n    executable_artifact_hash: str\n    effective_config_hash: str\n    final_model_registry_id: str\n    feature_extractor_code_hash: str\n    started_at: datetime\n    ended_at: datetime | None\n    deployment_receipt_hash: str\n\n    def __post_init__(self) -> None:\n        _aware(self.started_at, \"predictor runtime started_at\")\n        if self.ended_at is not None:\n            _aware(self.ended_at, \"predictor runtime ended_at\")\n            if self.ended_at <= self.started_at: raise DemonovError(\"predictor runtime ended_at must follow started_at\")\n        if not self.consumer_id or not self.final_model_registry_id:\n            raise DemonovError(\"predictor runtime identity fields required\")\n        for n in (\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\"feature_extractor_code_hash\",\"deployment_receipt_hash\"):\n            _hex64(getattr(self,n),n)\n        if self.predictor_runtime_id != self.content_hash:\n            raise DemonovError(\"predictor runtime id must be content-addressed\")\n\n    @property\n    def content_hash(self) -> str:\n        return canonical_hash({k:getattr(self,k) for k in (\n            \"consumer_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\n            \"final_model_registry_id\",\"feature_extractor_code_hash\",\"started_at\",\"ended_at\",\"deployment_receipt_hash\"\n        )})\n\n    @classmethod\n    def build(cls, **kwargs) -> \"PredictorRuntimeManifest\":\n        payload={k:kwargs.get(k) for k in (\n            \"consumer_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\n            \"final_model_registry_id\",\"feature_extractor_code_hash\",\"started_at\",\"ended_at\",\"deployment_receipt_hash\"\n        )}\n        return cls(predictor_runtime_id=canonical_hash(payload),**kwargs)\n\n    def contains(self,t:datetime)->bool:\n        _aware(t,\"predictor runtime time\")\n        return self.started_at <= t and (self.ended_at is None or t < self.ended_at)","source_sha256":"6514f10948abbeb0030fb06b509a8a75d796eea4d6ef4101b72e20f688985454"},{"name":"required_retained_hashes","node":"FunctionDef","path":"runtime_integrity.py","score":5,"source":"def required_retained_hashes(*, runtime_registry:RuntimeRegistry, model_registry:FinalModelRegistry,\n                             state_snapshots:Sequence[StateSnapshotManifest]=(), predictor_runtime:PredictorRuntimeManifest | None=None)->Mapping[str,RetainedArtifactKind]:\n    \"\"\"Build the minimum blob-level replay corpus required by final prospective proof.\n\n    Content-addressed policy objects remain in the handoff/registry.  This function\n    targets blobs that cannot be reconstructed from identifiers alone.\n    \"\"\"\n    out:dict[str,RetainedArtifactKind]={}\n    for a in runtime_registry.artifacts:\n        out[a.source_tree_hash]=RetainedArtifactKind.SOURCE_TREE\n        out[a.dependency_lock_hash]=RetainedArtifactKind.DEPENDENCY_LOCK\n        out[a.build_recipe_hash]=RetainedArtifactKind.BUILD_RECIPE\n        out[a.executable_artifact_hash]=RetainedArtifactKind.EXECUTABLE_ARTIFACT\n        out[a.runtime_environment_hash]=RetainedArtifactKind.RUNTIME_ENVIRONMENT\n    for a in model_registry.artifacts:\n        out[a.model_freeze_hash]=RetainedArtifactKind.MODEL\n        out[a.transformer_freeze_hash]=RetainedArtifactKind.TRANSFORMER\n        out[a.calibration_freeze_hash]=RetainedArtifactKind.CALIBRATOR\n        out[a.feature_schema_hash]=RetainedArtifactKind.FEATURE_SCHEMA\n        out[a.feature_contract_hash]=RetainedArtifactKind.FEATURE_CONTRACT\n        out[a.training_data_hash]=RetainedArtifactKind.TRAINING_DATA\n    for s in state_snapshots:\n        out[s.serialized_state_hash]=RetainedArtifactKind.STATE_SNAPSHOT\n    if predictor_runtime is not None:\n        out[predictor_runtime.source_tree_hash]=RetainedArtifactKind.SOURCE_TREE\n        out[predictor_runtime.dependency_lock_hash]=RetainedArtifactKind.DEPENDENCY_LOCK\n        out[predictor_runtime.executable_artifact_hash]=RetainedArtifactKind.EXECUTABLE_ARTIFACT\n        out[predictor_runtime.runtime_environment_hash]=RetainedArtifactKind.RUNTIME_ENVIRONMENT\n        out[predictor_runtime.feature_extractor_code_hash]=RetainedArtifactKind.FEATURE_EXTRACTOR_CODE\n        out[predictor_runtime.effective_config_hash]=RetainedArtifactKind.EFFECTIVE_CONFIG\n    return out","source_sha256":"ac6e18e76fcbd23144d1870ac03e3c2a4a1149dc4b5cf3f84fc0664228cdab1a"}]
SB043KF4_REPRODUCTION={"derived_new_package_identities":[],"fields":["source_tree_hash","dependency_lock_hash","build_recipe_hash","executable_artifact_hash","runtime_environment_hash"],"group_sizes":{"build_recipe_hash":10,"dependency_lock_hash":9,"executable_artifact_hash":14,"runtime_environment_hash":13,"source_tree_hash":71},"matches":[],"ok":false,"reason":"NO_MATCH","tested":1162980,"total":1162980}
SB043KF4_HOLDS=["CANONICAL_HASH_NOT_VALIDATED","OLD_PACKAGE_ID_EXACT_REPRODUCTION_FAILED"]
SB043KF4_DECISION=HOLD_CANONICAL_HASH_NOT_VALIDATED__OLD_PACKAGE_ID_EXACT_REPRODUCTION_FAILED
SB043KF4_MUTATION_SCOPE=NONE_READ_ONLY
SIGNALBOT043KF4_DECISION=HOLD_GUEST_PACKAGE_REPRODUCTION

OUTPUT_END
CHAT_OUTPUT_END
