CHAT_OUTPUT_BEGIN
COMMAND_ID=SIGNALBOT-260908-PACKAGE-SEAL-RCA-043PKG
STATUS=FAIL
RC=3
HOST=pve01
MODE=read-only
COMPONENT=signalbot-cr0116-package-seal-rca
REFERENCE_REGISTER_CHECK=OK
REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66
ERROR_REGISTER_CHECK=OK
ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0
COMMAND_SHA256=08ece8490c12004f2f6511bfb5dbcef29ab38d4385dbb224a48ba5d4a3dbfbaf
DUPLICATE_FAILED_COMMAND_BLOCKED=false
EXECUTION_STARTED=true
CHANGE_DECLARED=false
RESULT_CONTRACT_VALID=true
RESULT_CONTRACT_STATUS=NOT_APPLICABLE
RESULT_CONTRACT_ERROR=NONE
COMMAND_RC=3
CHANGES_MADE=false
ROLLBACK_STARTED=false
ROLLBACK_RESTORED=null
MUTATION_OUTCOME=NO_MUTATION
SANITIZED=yes
SECRETS_INCLUDED=no
PRIVATE_ADDRESSES_INCLUDED=no
RAW_EVIDENCE_SHA256=5a54891c071a17faf298b6f4df768f618290aac210aadeb4e5117d67b35ab713
SANITIZED_OUTPUT_SHA256=5a54891c071a17faf298b6f4df768f618290aac210aadeb4e5117d67b35ab713
OUTPUT_BEGIN
ERROR_REGISTER_CHECK=OK
REFERENCE_CHECK=OK
AUTHORITY_CHECK_SCOPE=READABILITY_ONLY_INCIDENTS_NOT_CLOSED
SB043K_PRESTATE={"active_env":{"APP_IMAGE":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","CODE_IDENTITY":"e32760c69a4311728db9066ee8bf2bf66b1e5a70","COLLECTION_START_AT":"2026-09-07T00:00:00+00:00","EXPERIMENT_ID":"ec477ea41ecbd5cfdef5afc259595aab20674a7d933f41a389329ff05098b338","RUNTIME_MANIFEST_ID":"58d3b59200bdc0eb8d448612679d667b194263586cb3198dfc08597935053a1a"},"services":[{"container_id":"a546a70c3e8c263d9b590cd78ee206bcda0cfcdb6662327e8415ca0e29ad1501","image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":14,"running":true,"service":"collector","started_at":"2026-09-08T07:38:09.79483772Z"},{"container_id":"d8023f4cbf91f9382e39eec0436c9cebc7665535b42b950e95408c03ff9bf30d","image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"relay","started_at":"2026-09-06T18:48:20.603414848Z"},{"container_id":"1feeca2d9428cd5a277c026bef34534db307657dcdcd63aff98ea66e44f8b9c5","image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"shadow","started_at":"2026-09-06T18:48:20.768190553Z"},{"container_id":"889be41d2cee9d327811da78388f834ba6eafe4c0eeae456867ed0df76832d01","image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"worker","started_at":"2026-09-06T18:48:20.586788319Z"}],"stage_result":{"active_env_unchanged":true,"build_context":"/opt/stacks/8020-demonov-shadow/.deploy/SIGNALBOT-260908-DEPLOY-STAGE-042FIX5","collector_source_sha256":"193dd0c7f9890fdb4026c24dbc5add825f1641d92097e881806705ca452812d5","copy_source":"/opt/stacks/8020-demonov-shadow/.deploy/SIGNALBOT-260908-DEPLOY-STAGE-042FIX5/demonov_forward_map","decision":"DEPLOY_STAGE_READY","dockerfile":"/opt/stacks/8020-demonov-shadow/.deploy/SIGNALBOT-260908-DEPLOY-STAGE-042FIX5/Dockerfile","helper_candidates":{"demonov_forward_map.live_prospective":[{"name":"_hash","pure_candidate":true,"signature":"(value: 'object') -> 'str'"}],"demonov_forward_map.runtime_integrity":[{"name":"canonical_hash","pure_candidate":true,"signature":"(payload: 'Any') -> 'str'"},{"name":"verify_experiment_seal_receipt","pure_candidate":true,"signature":"(*, bundle: 'FinalProspectiveSealBundle', receipt: 'ExperimentSealReceipt', collection_start_at: 'datetime', receipt_verifier: 'Callable[[ExperimentSealReceipt], bool]') -> 'None'"},{"name":"required_retained_hashes","pure_candidate":true,"signature":"(*, runtime_registry: 'RuntimeRegistry', model_registry: 'FinalModelRegistry', state_snapshots: 'Sequence[StateSnapshotManifest]' = (), predictor_runtime: 'PredictorRuntimeManifest | None' = None) -> 'Mapping[str, RetainedArtifactKind]'"}],"demonov_forward_map.runtime_manifest":[{"name":"canonical_hash","pure_candidate":true,"signature":"(payload: 'Any') -> 'str'"},{"name":"verify_runtime_manifest","pure_candidate":true,"signature":"(manifest: 'RuntimeDeploymentManifestV1', *, expected_code_identity: 'str', actual_image_id: 'str', actual_package_identity: 'str') -> 'None'"}]},"new_image":"8020-demonov-shadow:76e1f58baa544a0e208bba317f0150e5b6d74dbd","new_image_id":"sha256:341f71a906c91d3fa9c1d50bd89df2a849dfb0b168bb4551efb444bf61c4ab99","policy":{"close_timeout":5,"open_timeout":10,"ping_interval":20,"ping_timeout":60},"runtime_activated":false,"service_identity_unchanged":true,"stage_path":"/opt/stacks/8020-demonov-shadow/.deploy/SIGNALBOT-260908-DEPLOY-STAGE-042FIX5","websockets_version":"15.0.1"}}
SB043K_ARTIFACT_CLASS={"constructors":[{"name":"RuntimeArtifactManifest","node":"ClassDef","path":"runtime_integrity.py","source":"class RuntimeArtifactManifest:\n    artifact_id: str\n    source_tree_hash: str\n    dependency_lock_hash: str\n    build_recipe_hash: str\n    executable_artifact_hash: str\n    runtime_environment_hash: str\n\n    def __post_init__(self) -> None:\n        for name in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"):\n            _hex64(getattr(self, name), name)\n        if self.artifact_id != self.content_hash:\n            raise DemonovError(\"runtime artifact id must be content-addressed\")\n\n    @property\n    def content_hash(self) -> str:\n        return canonical_hash({k: getattr(self, k) for k in (\n            \"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"\n        )})\n\n    @classmethod\n    def build(cls, **kwargs) -> \"RuntimeArtifactManifest\":\n        payload = {k: kwargs[k] for k in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\")}\n        return cls(artifact_id=canonical_hash(payload), **kwargs)","source_sha256":"8cd1ebf70c003cd4d7b91f18602841426b19c2f54f2d803309c53c22f38cd5c7"},{"name":"DeploymentAttestation","node":"ClassDef","path":"runtime_integrity.py","source":"class DeploymentAttestation:\n    attestation_id: str\n    subject_kind: DeploymentSubjectKind\n    subject_id: str\n    actor_id: str\n    source_tree_hash: str\n    dependency_lock_hash: str\n    executable_artifact_hash: str\n    runtime_environment_hash: str\n    effective_config_hash: str\n    deployed_at: datetime\n    issued_at: datetime\n    authority_provider_id: str\n    authority_receipt_hash: str\n    feature_extractor_code_hash: str = \"\"\n\n    def __post_init__(self) -> None:\n        _aware(self.deployed_at, \"deployment deployed_at\"); _aware(self.issued_at, \"deployment issued_at\")\n        if self.issued_at < self.deployed_at:\n            raise DemonovError(\"deployment attestation cannot be issued before deployment\")\n        if not self.actor_id or not self.authority_provider_id:\n            raise DemonovError(\"deployment attestation identity fields are required\")\n        for n in (\"subject_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"executable_artifact_hash\",\n                  \"runtime_environment_hash\",\"effective_config_hash\",\"authority_receipt_hash\"):\n            _hex64(getattr(self,n),n)\n        if self.feature_extractor_code_hash: _hex64(self.feature_extractor_code_hash,\"feature_extractor_code_hash\")\n        if self.attestation_id != self.content_hash:\n            raise DemonovError(\"deployment attestation id must be content-addressed\")\n\n    @property\n    def content_hash(self) -> str:\n        payload={\"subject_kind\":self.subject_kind,\"subject_id\":self.subject_id,\"actor_id\":self.actor_id,\n                 \"source_tree_hash\":self.source_tree_hash,\"dependency_lock_hash\":self.dependency_lock_hash,\n                 \"executable_artifact_hash\":self.executable_artifact_hash,\"runtime_environment_hash\":self.runtime_environment_hash,\n                 \"effective_config_hash\":self.effective_config_hash,\"deployed_at\":self.deployed_at,\"issued_at\":self.issued_at,\n                 \"authority_provider_id\":self.authority_provider_id,\"authority_receipt_hash\":self.authority_receipt_hash}\n        if self.feature_extractor_code_hash: payload[\"feature_extractor_code_hash\"]=self.feature_extractor_code_hash\n        return canonical_hash(payload)\n\n    @classmethod\n    def build(cls, **kwargs) -> \"DeploymentAttestation\":\n        payload={k:kwargs[k] for k in (\"subject_kind\",\"subject_id\",\"actor_id\",\"source_tree_hash\",\"dependency_lock_hash\",\n            \"executable_artifact_hash\",\"runtime_environment_hash\",\"effective_config_hash\",\"deployed_at\",\"issued_at\",\n            \"authority_provider_id\",\"authority_receipt_hash\")}\n        if kwargs.get(\"feature_extractor_code_hash\"): payload[\"feature_extractor_code_hash\"]=kwargs[\"feature_extractor_code_hash\"]\n        return cls(attestation_id=canonical_hash(payload),**kwargs)","source_sha256":"1b0ca84bb035dfb7ff441ce73bbe8ee5f140a07b4a821f5a9f55770b585ffac7"},{"name":"verify_final_deployment_attestations","node":"FunctionDef","path":"runtime_integrity.py","source":"def verify_final_deployment_attestations(*, runtime_registry: RuntimeRegistry, producer_id: str,\n                                         predictor_runtime: \"PredictorRuntimeManifest\",\n                                         attestations: Sequence[DeploymentAttestation],\n                                         policy: DeploymentAttestationPolicy,\n                                         collection_start_at: datetime,\n                                         receipt_verifier: Callable[[DeploymentAttestation], bool]) -> None:\n    _aware(collection_start_at,\"collection_start_at\")\n    relevant_epochs=[e for e in runtime_registry.epochs if e.producer_id==producer_id and e.contains(collection_start_at)]\n    if len(relevant_epochs)!=1:\n        raise DemonovError(\"collection start must resolve to exactly one producer runtime epoch for deployment proof\")\n    epoch=relevant_epochs[0]\n    artifact=next((a for a in runtime_registry.artifacts if a.artifact_id==epoch.artifact_id),None)\n    if artifact is None: raise DemonovError(\"producer deployment proof references missing runtime artifact\")\n    expected={\n        (DeploymentSubjectKind.PRODUCER_RUNTIME_EPOCH,epoch.epoch_id):(\n            producer_id,artifact.source_tree_hash,artifact.dependency_lock_hash,artifact.executable_artifact_hash,\n            artifact.runtime_environment_hash,epoch.config_id,\"\",epoch.started_at),\n        (DeploymentSubjectKind.PREDICTOR_RUNTIME,predictor_runtime.predictor_runtime_id):(\n            predictor_runtime.consumer_id,predictor_runtime.source_tree_hash,predictor_runtime.dependency_lock_hash,\n            predictor_runtime.executable_artifact_hash,predictor_runtime.runtime_environment_hash,predictor_runtime.effective_config_hash,\n            predictor_runtime.feature_extractor_code_hash,predictor_runtime.started_at),\n    }\n    amap={(a.subject_kind,a.subject_id):a for a in attestations}\n    if len(amap)!=len(attestations): raise DemonovError(\"duplicate deployment attestation subject\")\n    if set(amap)!=set(expected): raise DemonovError(\"deployment attestation set differs from exact producer/predictor subjects\")\n    for key,(actor,src,dep,exe,env,cfg,feature,start) in expected.items():\n        a=amap[key]\n        if a.authority_provider_id!=policy.authority_provider_id or not receipt_verifier(a):\n            raise DemonovError(\"deployment attestation authority verification failed\")\n        if (a.actor_id,a.source_tree_hash,a.dependency_lock_hash,a.executable_artifact_hash,a.runtime_environment_hash,a.effective_config_hash)!=(actor,src,dep,exe,env,cfg):\n            raise DemonovError(\"deployment attestation artifact/config identity mismatch\")\n        if key[0] is DeploymentSubjectKind.PREDICTOR_RUNTIME and a.feature_extractor_code_hash!=feature:\n            raise DemonovError(\"predictor deployment attestation feature extractor mismatch\")\n        if key[0] is DeploymentSubjectKind.PRODUCER_RUNTIME_EPOCH and a.feature_extractor_code_hash:\n            raise DemonovError(\"producer deployment attestation must not invent challenger feature extractor\")\n        if abs((a.deployed_at-start).total_seconds()) > policy.max_start_skew_seconds:\n            raise DemonovError(\"deployment attestation outside frozen runtime-start skew\")\n        if policy.require_precollection_attestation and a.issued_at >= collection_start_at:\n            raise DemonovError(\"deployment attestation must be externally issued strictly before collection start\")","source_sha256":"9fc5b8d032d6a7b31f6b4e21d15142fe20b1fde4fe30a06fb758ad264bdeac9d"},{"name":"PredictorRuntimeManifest","node":"ClassDef","path":"runtime_integrity.py","source":"class PredictorRuntimeManifest:\n    predictor_runtime_id: str\n    consumer_id: str\n    source_tree_hash: str\n    dependency_lock_hash: str\n    runtime_environment_hash: str\n    executable_artifact_hash: str\n    effective_config_hash: str\n    final_model_registry_id: str\n    feature_extractor_code_hash: str\n    started_at: datetime\n    ended_at: datetime | None\n    deployment_receipt_hash: str\n\n    def __post_init__(self) -> None:\n        _aware(self.started_at, \"predictor runtime started_at\")\n        if self.ended_at is not None:\n            _aware(self.ended_at, \"predictor runtime ended_at\")\n            if self.ended_at <= self.started_at: raise DemonovError(\"predictor runtime ended_at must follow started_at\")\n        if not self.consumer_id or not self.final_model_registry_id:\n            raise DemonovError(\"predictor runtime identity fields required\")\n        for n in (\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\"feature_extractor_code_hash\",\"deployment_receipt_hash\"):\n            _hex64(getattr(self,n),n)\n        if self.predictor_runtime_id != self.content_hash:\n            raise DemonovError(\"predictor runtime id must be content-addressed\")\n\n    @property\n    def content_hash(self) -> str:\n        return canonical_hash({k:getattr(self,k) for k in (\n            \"consumer_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\n            \"final_model_registry_id\",\"feature_extractor_code_hash\",\"started_at\",\"ended_at\",\"deployment_receipt_hash\"\n        )})\n\n    @classmethod\n    def build(cls, **kwargs) -> \"PredictorRuntimeManifest\":\n        payload={k:kwargs.get(k) for k in (\n            \"consumer_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\n            \"final_model_registry_id\",\"feature_extractor_code_hash\",\"started_at\",\"ended_at\",\"deployment_receipt_hash\"\n        )}\n        return cls(predictor_runtime_id=canonical_hash(payload),**kwargs)\n\n    def contains(self,t:datetime)->bool:\n        _aware(t,\"predictor runtime time\")\n        return self.started_at <= t and (self.ended_at is None or t < self.ended_at)","source_sha256":"6514f10948abbeb0030fb06b509a8a75d796eea4d6ef4101b72e20f688985454"},{"name":"required_retained_hashes","node":"FunctionDef","path":"runtime_integrity.py","source":"def required_retained_hashes(*, runtime_registry:RuntimeRegistry, model_registry:FinalModelRegistry,\n                             state_snapshots:Sequence[StateSnapshotManifest]=(), predictor_runtime:PredictorRuntimeManifest | None=None)->Mapping[str,RetainedArtifactKind]:\n    \"\"\"Build the minimum blob-level replay corpus required by final prospective proof.\n\n    Content-addressed policy objects remain in the handoff/registry.  This function\n    targets blobs that cannot be reconstructed from identifiers alone.\n    \"\"\"\n    out:dict[str,RetainedArtifactKind]={}\n    for a in runtime_registry.artifacts:\n        out[a.source_tree_hash]=RetainedArtifactKind.SOURCE_TREE\n        out[a.dependency_lock_hash]=RetainedArtifactKind.DEPENDENCY_LOCK\n        out[a.build_recipe_hash]=RetainedArtifactKind.BUILD_RECIPE\n        out[a.executable_artifact_hash]=RetainedArtifactKind.EXECUTABLE_ARTIFACT\n        out[a.runtime_environment_hash]=RetainedArtifactKind.RUNTIME_ENVIRONMENT\n    for a in model_registry.artifacts:\n        out[a.model_freeze_hash]=RetainedArtifactKind.MODEL\n        out[a.transformer_freeze_hash]=RetainedArtifactKind.TRANSFORMER\n        out[a.calibration_freeze_hash]=RetainedArtifactKind.CALIBRATOR\n        out[a.feature_schema_hash]=RetainedArtifactKind.FEATURE_SCHEMA\n        out[a.feature_contract_hash]=RetainedArtifactKind.FEATURE_CONTRACT\n        out[a.training_data_hash]=RetainedArtifactKind.TRAINING_DATA\n    for s in state_snapshots:\n        out[s.serialized_state_hash]=RetainedArtifactKind.STATE_SNAPSHOT\n    if predictor_runtime is not None:\n        out[predictor_runtime.source_tree_hash]=RetainedArtifactKind.SOURCE_TREE\n        out[predictor_runtime.dependency_lock_hash]=RetainedArtifactKind.DEPENDENCY_LOCK\n        out[predictor_runtime.executable_artifact_hash]=RetainedArtifactKind.EXECUTABLE_ARTIFACT\n        out[predictor_runtime.runtime_environment_hash]=RetainedArtifactKind.RUNTIME_ENVIRONMENT\n        out[predictor_runtime.feature_extractor_code_hash]=RetainedArtifactKind.FEATURE_EXTRACTOR_CODE\n        out[predictor_runtime.effective_config_hash]=RetainedArtifactKind.EFFECTIVE_CONFIG\n    return out","source_sha256":"ac6e18e76fcbd23144d1870ac03e3c2a4a1149dc4b5cf3f84fc0664228cdab1a"},{"name":"__post_init__","node":"FunctionDef","path":"runtime_integrity.py","source":"def __post_init__(self) -> None:\n        for name in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"):\n            _hex64(getattr(self, name), name)\n        if self.artifact_id != self.content_hash:\n            raise DemonovError(\"runtime artifact id must be content-addressed\")","source_sha256":"a7b5db332b3cd656bf1d8ec3b9fe7b0da2fcbddad84b529725384be99beea98a"},{"name":"content_hash","node":"FunctionDef","path":"runtime_integrity.py","source":"def content_hash(self) -> str:\n        return canonical_hash({k: getattr(self, k) for k in (\n            \"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"\n        )})","source_sha256":"265c6eede8cfd8f93a315ea20905befdfb4f66947538978ef6e6013872668d94"},{"name":"build","node":"FunctionDef","path":"runtime_integrity.py","source":"def build(cls, **kwargs) -> \"RuntimeArtifactManifest\":\n        payload = {k: kwargs[k] for k in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\")}\n        return cls(artifact_id=canonical_hash(payload), **kwargs)","source_sha256":"f4859325ffab449c366e56333f48078b1a221897653cdc2a348eea73fdd8ba28"},{"name":"__post_init__","node":"FunctionDef","path":"runtime_integrity.py","source":"def __post_init__(self) -> None:\n        _aware(self.deployed_at, \"deployment deployed_at\"); _aware(self.issued_at, \"deployment issued_at\")\n        if self.issued_at < self.deployed_at:\n            raise DemonovError(\"deployment attestation cannot be issued before deployment\")\n        if not self.actor_id or not self.authority_provider_id:\n            raise DemonovError(\"deployment attestation identity fields are required\")\n        for n in (\"subject_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"executable_artifact_hash\",\n                  \"runtime_environment_hash\",\"effective_config_hash\",\"authority_receipt_hash\"):\n            _hex64(getattr(self,n),n)\n        if self.feature_extractor_code_hash: _hex64(self.feature_extractor_code_hash,\"feature_extractor_code_hash\")\n        if self.attestation_id != self.content_hash:\n            raise DemonovError(\"deployment attestation id must be content-addressed\")","source_sha256":"a98af80953a22a18bb46c75e43b09921d13d2c60d952a2d111fdd663345f1b7a"},{"name":"content_hash","node":"FunctionDef","path":"runtime_integrity.py","source":"def content_hash(self) -> str:\n        payload={\"subject_kind\":self.subject_kind,\"subject_id\":self.subject_id,\"actor_id\":self.actor_id,\n                 \"source_tree_hash\":self.source_tree_hash,\"dependency_lock_hash\":self.dependency_lock_hash,\n                 \"executable_artifact_hash\":self.executable_artifact_hash,\"runtime_environment_hash\":self.runtime_environment_hash,\n                 \"effective_config_hash\":self.effective_config_hash,\"deployed_at\":self.deployed_at,\"issued_at\":self.issued_at,\n                 \"authority_provider_id\":self.authority_provider_id,\"authority_receipt_hash\":self.authority_receipt_hash}\n        if self.feature_extractor_code_hash: payload[\"feature_extractor_code_hash\"]=self.feature_extractor_code_hash\n        return canonical_hash(payload)","source_sha256":"544b46e605c9a988693451af639cce42e20f359ae9dd69baa47b3780e4525ed1"},{"name":"build","node":"FunctionDef","path":"runtime_integrity.py","source":"def build(cls, **kwargs) -> \"DeploymentAttestation\":\n        payload={k:kwargs[k] for k in (\"subject_kind\",\"subject_id\",\"actor_id\",\"source_tree_hash\",\"dependency_lock_hash\",\n            \"executable_artifact_hash\",\"runtime_environment_hash\",\"effective_config_hash\",\"deployed_at\",\"issued_at\",\n            \"authority_provider_id\",\"authority_receipt_hash\")}\n        if kwargs.get(\"feature_extractor_code_hash\"): payload[\"feature_extractor_code_hash\"]=kwargs[\"feature_extractor_code_hash\"]\n        return cls(attestation_id=canonical_hash(payload),**kwargs)","source_sha256":"58286208dcbf95fffbf6775c550cbb0e4cb2eee55a6e89610d3c55cf6a57183c"},{"name":"__post_init__","node":"FunctionDef","path":"runtime_integrity.py","source":"def __post_init__(self) -> None:\n        _aware(self.started_at, \"predictor runtime started_at\")\n        if self.ended_at is not None:\n            _aware(self.ended_at, \"predictor runtime ended_at\")\n            if self.ended_at <= self.started_at: raise DemonovError(\"predictor runtime ended_at must follow started_at\")\n        if not self.consumer_id or not self.final_model_registry_id:\n            raise DemonovError(\"predictor runtime identity fields required\")\n        for n in (\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\"feature_extractor_code_hash\",\"deployment_receipt_hash\"):\n            _hex64(getattr(self,n),n)\n        if self.predictor_runtime_id != self.content_hash:\n            raise DemonovError(\"predictor runtime id must be content-addressed\")","source_sha256":"6387ddecd12c2c2af99dd5d683b4e12d35b045cf938d3ee15f672f1b1a67795f"},{"name":"content_hash","node":"FunctionDef","path":"runtime_integrity.py","source":"def content_hash(self) -> str:\n        return canonical_hash({k:getattr(self,k) for k in (\n            \"consumer_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\n            \"final_model_registry_id\",\"feature_extractor_code_hash\",\"started_at\",\"ended_at\",\"deployment_receipt_hash\"\n        )})","source_sha256":"df6127715e3a641101bfec75454672d73e712342aa989fa0b674c865d3d4424d"},{"name":"build","node":"FunctionDef","path":"runtime_integrity.py","source":"def build(cls, **kwargs) -> \"PredictorRuntimeManifest\":\n        payload={k:kwargs.get(k) for k in (\n            \"consumer_id\",\"source_tree_hash\",\"dependency_lock_hash\",\"runtime_environment_hash\",\"executable_artifact_hash\",\"effective_config_hash\",\n            \"final_model_registry_id\",\"feature_extractor_code_hash\",\"started_at\",\"ended_at\",\"deployment_receipt_hash\"\n        )}\n        return cls(predictor_runtime_id=canonical_hash(payload),**kwargs)","source_sha256":"320b24f7f9b26161be45b818701ca5f9e0ec55be2b1ade043dbcd6c3df656f2b"}],"content_hash":"def content_hash(self) -> str:\n        return canonical_hash({k: getattr(self, k) for k in (\n            \"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"\n        )})","fields":["artifact_id","source_tree_hash","dependency_lock_hash","build_recipe_hash","executable_artifact_hash","runtime_environment_hash"],"formula":null,"post_init":"def __post_init__(self) -> None:\n        for name in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"):\n            _hex64(getattr(self, name), name)\n        if self.artifact_id != self.content_hash:\n            raise DemonovError(\"runtime artifact id must be content-addressed\")"}
SB043K_OLD_ARTIFACT_INPUTS={"base_image_id":"sha256:008ab480142056d1f0b628e6c17bb6b99b30b8b4f59f24e31d972a4a128a8602","base_image_ref":"8020-demonov-shadow:ac7094a76ddc06f376d71a76432af7c2dd10ec7d","candidate_pool":{"base_image_id":"008ab480142056d1f0b628e6c17bb6b99b30b8b4f59f24e31d972a4a128a8602","base_rootfs_layers_canonical":"caf591ce9164d30a1fa64b2ca25d9728b116468c9410a883543bf3d696f3ced1","compose_sha256":"6461532b0a04decc60fe1d1885990020e886d40de40c0523e34e2849600af061","dockerfile_sha256":"901951def73961f76d2c2a93c5428a0fbdcc50113d42b39da92983a5ce157cb8","file:runtime_integrity.py":"99859b63e23d10fc051672965123f49d6e79d2ff767871c019ff7bdae2e2e39e","file:runtime_manifest.py":"1064cfb74303fdc8e0bf50bae95b1e755556a5b1dfc28b2b062341becaba08f2","old_application_image_id":"403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","old_dir_canonical_list_full":"af83cb6b6b1b0f01f5453bd2dd6048c42b1f194bee6f6323b91e90efec30ef1f","old_dir_canonical_list_sha":"708d044de397034bcdde99398f1014aceee0e9f58a7870e459c6d57879e2b552","old_dir_canonical_path_sha":"d32002a8dd2b78e63ac30bef3f1c8b4c18373509c98c92173a9f82386f53afd4","old_dir_canonical_path_size_sha":"0c7eac692accfd22113cebffb7897863370052731578418a5103e4004b749c7c","old_dir_concat_path_sha":"3a0e01804936792ff9159b896d17b5bcd2b0b0d61eacb331fd93ccaceb5411df","old_dir_concat_sha":"b39e64671adfa8a6cfac27ff4bac745ee5dc5b0b90d28f1a9e24b48de307e6ae","old_image_config":"403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","old_image_config_canonical":"27884bcdb5825bb3f2207da59a46451dac4e65a34b6af18db04266607e151d0e","old_image_id":"403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","old_rootfs_layers_canonical":"624aba0d14a23d453be78b45a360bfa5c724ddd3d01946930f8a76a4341d17fa","old_tar_canonical_list_full":"43b6ae1658ff777a219266ce66f2de7d8f9f3d9b3c8428f5d11b0c90aff6a581","old_tar_canonical_list_sha":"c6a1b005a330a0e5a73658fcbf7557a0645b1fca9fa05fe87955c26c06d1e4ac","old_tar_canonical_path_sha":"3b7df8cf67359efaa32f20d35a23636fe24a2a0f0f74d465c234eb92c6496733","old_tar_canonical_path_size_sha":"0579c2e9c3cfbacf9db2c6d7b1a05705305e63e130a74f89ff42d01fc5802b0f","old_tar_concat_path_sha":"dc1843e1ada353efcb935031b5783a677d5656310700c83e885c688829406f91","old_tar_concat_sha":"b39e64671adfa8a6cfac27ff4bac745ee5dc5b0b90d28f1a9e24b48de307e6ae","old_tar_strip_canonical_list_full":"af83cb6b6b1b0f01f5453bd2dd6048c42b1f194bee6f6323b91e90efec30ef1f","old_tar_strip_canonical_list_sha":"708d044de397034bcdde99398f1014aceee0e9f58a7870e459c6d57879e2b552","old_tar_strip_canonical_path_sha":"d32002a8dd2b78e63ac30bef3f1c8b4c18373509c98c92173a9f82386f53afd4","old_tar_strip_canonical_path_size_sha":"0c7eac692accfd22113cebffb7897863370052731578418a5103e4004b749c7c","old_tar_strip_concat_path_sha":"3a0e01804936792ff9159b896d17b5bcd2b0b0d61eacb331fd93ccaceb5411df","old_tar_strip_concat_sha":"b39e64671adfa8a6cfac27ff4bac745ee5dc5b0b90d28f1a9e24b48de307e6ae","package_gzip_sha256":"389e7aabca8887ee3b48b6ff0b4affe1163216005a4888013d9ccc82ea360e32","package_tar_sha256":"431ddf9e8938d5e583553f05f9e3d019aff0b439c83b0b23c81808073b7d61a8"},"old_image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","old_manifest":{"application_image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","base_image_digest":"sha256:881d80734ee05dca6f7f42dcb080975652a53c7eda9ba1f03bb8da31aa6a6ec2","code_identity":"e32760c69a4311728db9066ee8bf2bf66b1e5a70","compose_hash":"6461532b0a04decc60fe1d1885990020e886d40de40c0523e34e2849600af061","finality_policy_id":"BITFINEX_SEQ_ALL_D1_V1","package_identity":"637acba19fb29c98408a8031dc9265a31dc36551c666fcf0b287e8af83d2b893","runtime_manifest_id":"58d3b59200bdc0eb8d448612679d667b194263586cb3198dfc08597935053a1a"},"old_package_identity":"637acba19fb29c98408a8031dc9265a31dc36551c666fcf0b287e8af83d2b893","tar_meta":{"gzip_bytes":208049,"gzip_sha256":"389e7aabca8887ee3b48b6ff0b4affe1163216005a4888013d9ccc82ea360e32","tar_bytes":1157120,"tar_sha256":"431ddf9e8938d5e583553f05f9e3d019aff0b439c83b0b23c81808073b7d61a8"}}
SB043K_REPRODUCTION=[]
SB043K_OLD_DEPLOY_REFERENCES=[{"path":"demonov_forward_map/__init__.py","snippets":["    ClockDomainKind, ClockDomainSpec, ClockDomainRegistry, ClockSynchronizationPolicy, ClockAttestation,","    verify_clock_synchronization, WindowClockClassification, classify_event_time_with_clock_guard,","    FrozenConfigMapping, EffectiveConfigSnapshot, RuntimeArtifactManifest, RuntimeEpoch, RuntimeRegistry,","    ProducerSessionDeclaration, ProducerSessionCatalog, CollectorTopologyPolicy, CollectorReceiptRecord,","    CollectorReceiptStore, AuthoritativeProducerWatermark, CaptureCompletenessPolicy, verify_capture_through_watermark,"]},{"path":"demonov_forward_map/runtime_integrity.py","snippets":["","@dataclass(frozen=True)","class RuntimeArtifactManifest:","    artifact_id: str","    source_tree_hash: str","class RuntimeArtifactManifest:","    artifact_id: str","    source_tree_hash: str","    dependency_lock_hash: str","    build_recipe_hash: str","    artifact_id: str","    source_tree_hash: str","    dependency_lock_hash: str","    build_recipe_hash: str","    executable_artifact_hash: str","    source_tree_hash: str","    dependency_lock_hash: str","    build_recipe_hash: str","    executable_artifact_hash: str","    runtime_environment_hash: str","    dependency_lock_hash: str","    build_recipe_hash: str","    executable_artifact_hash: str","    runtime_environment_hash: str","","","    def __post_init__(self) -> None:","        for name in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"):","            _hex64(getattr(self, name), name)","        if self.artifact_id != self.content_hash:","    def content_hash(self) -> str:","        return canonical_hash({k: getattr(self, k) for k in (","            \"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\"","        )})","","","    @classmethod","    def build(cls, **kwargs) -> \"RuntimeArtifactManifest\":","        payload = {k: kwargs[k] for k in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\")}","        return cls(artifact_id=canonical_hash(payload), **kwargs)","    @classmethod","    def build(cls, **kwargs) -> \"RuntimeArtifactManifest\":","        payload = {k: kwargs[k] for k in (\"source_tree_hash\", \"dependency_lock_hash\", \"build_recipe_hash\", \"executable_artifact_hash\", \"runtime_environment_hash\")}","        return cls(artifact_id=canonical_hash(payload), **kwargs)","","class RuntimeRegistry:","    registry_id: str","    artifacts: Tuple[RuntimeArtifactManifest, ...]","    configs: Tuple[EffectiveConfigSnapshot, ...]","    epochs: Tuple[RuntimeEpoch, ...]","        for e in self.epochs:","            if e.artifact_id not in amap or e.config_id not in cmap: raise DemonovError(\"runtime epoch references missing artifact/config\")","            if e.producer_code_hash != amap[e.artifact_id].source_tree_hash:","                raise DemonovError(\"runtime epoch producer_code_hash must equal frozen artifact source_tree_hash\")","        # No overlapping epochs per producer; otherwise event->runtime binding is ambiguous.","            if e.artifact_id not in amap or e.config_id not in cmap: raise DemonovError(\"runtime epoch references missing artifact/config\")","            if e.producer_code_hash != amap[e.artifact_id].source_tree_hash:","                raise DemonovError(\"runtime epoch producer_code_hash must equal frozen artifact source_tree_hash\")","        # No overlapping epochs per producer; otherwise event->runtime binding is ambiguous.","        for producer in {e.producer_id for e in self.epochs}:","","    @classmethod","    def build(cls, *, artifacts: Iterable[RuntimeArtifactManifest], configs: Iterable[EffectiveConfigSnapshot], epochs: Iterable[RuntimeEpoch]) -> \"RuntimeRegistry\":","        a, c, e = tuple(artifacts), tuple(configs), tuple(epochs)","        payload = {\"artifacts\": tuple(sorted(x.artifact_id for x in a)), \"configs\": tuple(sorted(x.config_id for x in c)), \"epochs\": tuple(sorted(x.epoch_id for x in e))}","    subject_id: str","    actor_id: str","    source_tree_hash: str","    dependency_lock_hash: str","    executable_artifact_hash: str","    actor_id: str","    source_tree_hash: str","    dependency_lock_hash: str","    executable_artifact_hash: str","    runtime_environment_hash: str","    source_tree_hash: str","    dependency_lock_hash: str","    executable_artifact_hash: str","    runtime_environment_hash: str","    effective_config_hash: str"]},{"path":"runtime_manifest.json","snippets":["  \"compose_hash\": \"6461532b0a04decc60fe1d1885990020e886d40de40c0523e34e2849600af061\",","  \"finality_policy_id\": \"BITFINEX_SEQ_ALL_D1_V1\",","  \"package_identity\": \"637acba19fb29c98408a8031dc9265a31dc36551c666fcf0b287e8af83d2b893\",","  \"runtime_manifest_id\": \"58d3b59200bdc0eb8d448612679d667b194263586cb3198dfc08597935053a1a\"","}"]}]
SB043K_SOURCE_COUNTS={"new_files":57,"old_files":57}
SB043K_HOLDS=["ARTIFACT_CONTENT_HASH_FORMULA_NOT_EXTRACTED","OLD_PACKAGE_ID_NOT_REPRODUCED"]
SB043K_DECISION=HOLD_ARTIFACT_CONTENT_HASH_FORMULA_NOT_EXTRACTED__OLD_PACKAGE_ID_NOT_REPRODUCED
SB043K_MUTATION_SCOPE=NONE_READ_ONLY
SIGNALBOT043K_DECISION=HOLD_GUEST_PACKAGE_RCA

OUTPUT_END
CHAT_OUTPUT_END
