{
  "schema": "vm101-canonical-public-edit-map-v1",
  "canonical_id": "20260712-085142_vm101_m07_canonical_v1a_editmap",
  "source_canonical_id": "20260712-084610_vm101_m07_canonical_v1",
  "reference_id": "20260712-083919_vm101_reference_v1c",
  "source_reference_id": "20260712-082027_vm101_reference_v1b",
  "target_count": 9,
  "edit_ready_target_count": 9,
  "region_count": 22,
  "public_excerpt_count": 9,
  "sanitization": {
    "performed": true,
    "total_redactions": 0,
    "private_exact_lines_published": false
  },
  "targets": [
    {
      "label": "refresh_pool_safe",
      "source_path": "/root/hmn/hmn-refresh-pool-safe.sh",
      "source_sha256": "bb047e820196c4c5cb263499ed890c782190293257a2033568015c6b19230682",
      "source_line_count": 308,
      "purpose": "storage preflight, backup manifest and rollback gate",
      "anchors": [
        {
          "type": "token",
          "name": "table_200",
          "line": 145
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 266
        },
        {
          "type": "token",
          "name": "tmp_backup_path",
          "line": 14
        },
        {
          "type": "token",
          "name": "tmp_backup_path",
          "line": 22
        },
        {
          "type": "function",
          "name": "restore_backup",
          "line": 58
        },
        {
          "type": "function",
          "name": "run_validate_current_pool",
          "line": 96
        },
        {
          "type": "function",
          "name": "run_body",
          "line": 115
        },
        {
          "type": "assignment",
          "name": "BACKUPDIR",
          "line": 8
        },
        {
          "type": "assignment",
          "name": "BACK",
          "line": 24
        },
        {
          "type": "assignment",
          "name": "BACK",
          "line": 150
        },
        {
          "type": "assignment",
          "name": "LOCK",
          "line": 14
        }
      ],
      "regions": [
        {
          "region_id": "refresh_pool_safe-r1",
          "start_line": 1,
          "end_line": 34,
          "sanitized_sha256": "7e75958ec6298619df5e62b425ab56d25ed3cca2e2bafe211a874515d7d908da",
          "redactions": 0
        },
        {
          "region_id": "refresh_pool_safe-r2",
          "start_line": 50,
          "end_line": 68,
          "sanitized_sha256": "2de96652395a9807c7422746babefeb1ada5eaedd9414ac8f2b4d46790d0b4f0",
          "redactions": 0
        },
        {
          "region_id": "refresh_pool_safe-r3",
          "start_line": 88,
          "end_line": 125,
          "sanitized_sha256": "dcad8b5e9d50f609f60a17d416a8b7400adbe97a5eca5e21bb0dcd85d4dbce7f",
          "redactions": 0
        },
        {
          "region_id": "refresh_pool_safe-r4",
          "start_line": 137,
          "end_line": 160,
          "sanitized_sha256": "de1e15a1740e62ac0fed278721d17bd80c667bb52f99a48e68ac8fa05ec3d183",
          "redactions": 0
        },
        {
          "region_id": "refresh_pool_safe-r5",
          "start_line": 258,
          "end_line": 276,
          "sanitized_sha256": "e7aa96557f438533f092ee4a71f3b902fc11bce9174e42f798be1fbe2e2810a0",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "calculate required backup bytes before mutation",
        "refuse operation when temporary storage is insufficient",
        "create surgical backup manifest",
        "validate every rollback artifact before download",
        "refuse rollback from incomplete backup"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/refresh_pool_safe.txt"
    },
    {
      "label": "code_test",
      "source_path": "/root/hmn/hmn-code-test.sh",
      "source_sha256": "3515205270211206a9f3a34bc5c62d94a9f14a54ad712d6fa7e9c7d50db1370a",
      "source_line_count": 66,
      "purpose": "replace table-200-only active interface detection",
      "anchors": [
        {
          "type": "token",
          "name": "table_200",
          "line": 21
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 28
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 29
        },
        {
          "type": "token",
          "name": "active_interface_error",
          "line": 28
        },
        {
          "type": "assignment",
          "name": "ACTIVE",
          "line": 21
        },
        {
          "type": "assignment",
          "name": "ACTIVE",
          "line": 24
        }
      ],
      "regions": [
        {
          "region_id": "code_test-r1",
          "start_line": 13,
          "end_line": 39,
          "sanitized_sha256": "637eeaee0dd437ccd2eeaaffd6a136d40b39c7381eab50bb82e944d8af922b6a",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "source canonical runtime library",
        "select first strict healthy vpn1-vpn5",
        "treat table 200 only as optional preferred candidate"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/code_test.txt"
    },
    {
      "label": "download_all_awg",
      "source_path": "/root/hmn/hmn-download-all-awg.sh",
      "source_sha256": "c20d8ff7feead493f2524c6da3c921bbf62cbdfb503a11a8ea75e4d15144e18f",
      "source_line_count": 308,
      "purpose": "replace table-200-only bootstrap detection",
      "anchors": [
        {
          "type": "token",
          "name": "table_200",
          "line": 32
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 40
        },
        {
          "type": "token",
          "name": "active_interface_error",
          "line": 38
        },
        {
          "type": "assignment",
          "name": "ACTIVE",
          "line": 32
        },
        {
          "type": "assignment",
          "name": "ACTIVE",
          "line": 34
        }
      ],
      "regions": [
        {
          "region_id": "download_all_awg-r1",
          "start_line": 24,
          "end_line": 50,
          "sanitized_sha256": "9d66c8b1efef40ca538868ad3016e0a0d9cdd93a2ba113e654fb12ebfc5365d6",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "source canonical runtime library",
        "select first strict healthy vpn1-vpn5",
        "retain failure when no healthy slot exists"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/download_all_awg.txt"
    },
    {
      "label": "refresh_awg",
      "source_path": "/root/hmn/hmn-refresh-awg.sh",
      "source_sha256": "f725224e1b766f85f1ccf4a934e44f3c240865081348ff6bed8f63d366678e17",
      "source_line_count": 213,
      "purpose": "replace active interface and table-200 contract",
      "anchors": [
        {
          "type": "token",
          "name": "table_200",
          "line": 65
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 109
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 110
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 113
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 147
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 183
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 184
        },
        {
          "type": "token",
          "name": "active_interface_error",
          "line": 128
        },
        {
          "type": "token",
          "name": "hmn_endpoint",
          "line": 190
        },
        {
          "type": "token",
          "name": "hmn_endpoint",
          "line": 194
        },
        {
          "type": "token",
          "name": "amneziawg",
          "line": 118
        },
        {
          "type": "function",
          "name": "get_table_default_dev",
          "line": 64
        },
        {
          "type": "assignment",
          "name": "ACTIVE",
          "line": 101
        },
        {
          "type": "assignment",
          "name": "TABLE_DEV",
          "line": 107
        }
      ],
      "regions": [
        {
          "region_id": "refresh_awg-r1",
          "start_line": 56,
          "end_line": 75,
          "sanitized_sha256": "16d7462937119a237b90b7b9477549f07163a76a328934e27ba573fe7435c860",
          "redactions": 0
        },
        {
          "region_id": "refresh_awg-r2",
          "start_line": 93,
          "end_line": 157,
          "sanitized_sha256": "9be803ea741164541e8a3cbabb979ecf7c6cebfa0bec2e72e7eb8498bbc8a19e",
          "redactions": 0
        },
        {
          "region_id": "refresh_awg-r3",
          "start_line": 175,
          "end_line": 204,
          "sanitized_sha256": "6ecbd45c4b33cc8b8f4ed95575ade6354b72a66d2afb9875d785dae391a606e2",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "source canonical runtime library",
        "use vm101_healthy_bootstrap_iface",
        "keep table 200 informational only"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/refresh_awg.txt"
    },
    {
      "label": "validate_current_pool",
      "source_path": "/root/hmn/hmn-validate-current-pool.sh",
      "source_sha256": "7cf24b674fff3a5077308f07f1202b70dd34979e50b835758f92e9bda92507ee",
      "source_line_count": 266,
      "purpose": "healthy bootstrap selection and runtime endpoint lookup",
      "anchors": [
        {
          "type": "token",
          "name": "table_200",
          "line": 92
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 232
        },
        {
          "type": "token",
          "name": "table_200",
          "line": 250
        },
        {
          "type": "token",
          "name": "hmn_endpoint",
          "line": 218
        },
        {
          "type": "assignment",
          "name": "ACTIVE",
          "line": 90
        },
        {
          "type": "assignment",
          "name": "ACTIVE",
          "line": 229
        }
      ],
      "regions": [
        {
          "region_id": "validate_current_pool-r1",
          "start_line": 82,
          "end_line": 102,
          "sanitized_sha256": "fd6b59e44fc116df4beb86cf137f39ac757a12954600e3b5c7f2a3a4271358ea",
          "redactions": 0
        },
        {
          "region_id": "validate_current_pool-r2",
          "start_line": 210,
          "end_line": 260,
          "sanitized_sha256": "75766dcc17724a6f657a5c75e1fbc46a2460b41d59cd826cbc1ff287010ab6c6",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "source canonical runtime library",
        "select a strict healthy bootstrap slot",
        "use runtime endpoint before UCI fallback"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/validate_current_pool.txt"
    },
    {
      "label": "planner",
      "source_path": "/usr/local/sbin/router-egress-hmn-plan-top5.sh",
      "source_sha256": "6ec99e157235d811d6f0f3ab92de7f3371dc813f2478a654358982cda7ce34ce",
      "source_line_count": 192,
      "purpose": "runtime endpoint as current source of truth",
      "anchors": [
        {
          "type": "token",
          "name": "hmn_endpoint",
          "line": 125
        },
        {
          "type": "assignment",
          "name": "CURRENT",
          "line": 85
        }
      ],
      "regions": [
        {
          "region_id": "planner-r1",
          "start_line": 77,
          "end_line": 95,
          "sanitized_sha256": "13f1de7a31628ff1189f4c190193eec1c6bbf134b348f382b24c7f18456394df",
          "redactions": 0
        },
        {
          "region_id": "planner-r2",
          "start_line": 117,
          "end_line": 135,
          "sanitized_sha256": "ef1d00a7007182b6cab15393d281a6e012b56eb66cda9d5884035f59fcb53e0c",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "source canonical runtime library",
        "read current endpoint from amneziawg runtime",
        "use UCI hmn_endpoint only as explicit fallback"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/planner.txt"
    },
    {
      "label": "rebalance_apply",
      "source_path": "/usr/local/sbin/router-egress-hmn-rebalance-top5-apply.sh",
      "source_sha256": "2fa6b725c5e123b7fdc3dd14747058a02415d025231054c7537d72b8edc2346f",
      "source_line_count": 213,
      "purpose": "runtime current, strict retry and shell/JSON exit agreement",
      "anchors": [
        {
          "type": "token",
          "name": "hmn_endpoint",
          "line": 85
        },
        {
          "type": "token",
          "name": "hmn_endpoint",
          "line": 153
        },
        {
          "type": "token",
          "name": "hmn_endpoint",
          "line": 163
        },
        {
          "type": "token",
          "name": "commit_failed",
          "line": 173
        },
        {
          "type": "token",
          "name": "apply_ok",
          "line": 127
        },
        {
          "type": "token",
          "name": "apply_ok",
          "line": 172
        },
        {
          "type": "token",
          "name": "apply_ok",
          "line": 199
        },
        {
          "type": "token",
          "name": "strict_ping",
          "line": 27
        },
        {
          "type": "token",
          "name": "strict_ping",
          "line": 171
        },
        {
          "type": "function",
          "name": "strict_ping",
          "line": 27
        }
      ],
      "regions": [
        {
          "region_id": "rebalance_apply-r1",
          "start_line": 19,
          "end_line": 37,
          "sanitized_sha256": "80d4e3afd21fb51f3c77dc68278beae09b7fb46515b3bf99607d2388972bc1e2",
          "redactions": 0
        },
        {
          "region_id": "rebalance_apply-r2",
          "start_line": 77,
          "end_line": 95,
          "sanitized_sha256": "a8bea701c3163783a488ddb03c0534229a5916cbc08fdbecea9441fbc100b41b",
          "redactions": 0
        },
        {
          "region_id": "rebalance_apply-r3",
          "start_line": 119,
          "end_line": 137,
          "sanitized_sha256": "f5f8a31d4868958b26fe36ab0c0c354e3a8409da8491ca508ebeea549b62cdac",
          "redactions": 0
        },
        {
          "region_id": "rebalance_apply-r4",
          "start_line": 145,
          "end_line": 183,
          "sanitized_sha256": "2365b81d00203ba70f2a1d98aa52d033ce0b664a12391e83c88c104bde6c93ad",
          "redactions": 0
        },
        {
          "region_id": "rebalance_apply-r5",
          "start_line": 191,
          "end_line": 209,
          "sanitized_sha256": "8fa53e8c61d287d82c7643c03181f891b2966750da57d4359e04b1081ba38a2a",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "source canonical runtime library",
        "read current endpoint from runtime",
        "retry strict health after ifup",
        "return nonzero for commit_failed",
        "return nonzero for commit refusal",
        "keep JSON decision consistent with shell status"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/rebalance_apply.txt"
    },
    {
      "label": "emergency_runner",
      "source_path": "/usr/local/sbin/router-egress-emergency-refresh.sh",
      "source_sha256": "PRIVATE_ONLY",
      "source_line_count": 304,
      "purpose": "validate rebalance shell status and JSON contract",
      "anchors": [
        {
          "type": "token",
          "name": "rebalance_rc",
          "line": 274
        },
        {
          "type": "token",
          "name": "rebalance_rc",
          "line": 275
        },
        {
          "type": "token",
          "name": "rebalance_rc",
          "line": 277
        },
        {
          "type": "token",
          "name": "rebalance_rc",
          "line": 278
        },
        {
          "type": "token",
          "name": "rebalance_rc",
          "line": 280
        },
        {
          "type": "function",
          "name": "emit_json",
          "line": 147
        }
      ],
      "regions": [
        {
          "region_id": "emergency_runner-r1",
          "start_line": 139,
          "end_line": 157,
          "sanitized_sha256": "29bd6699c8f476d26c3e17daf2dabd79134d7fb577afb7132e49c521061fa3da",
          "redactions": 0
        },
        {
          "region_id": "emergency_runner-r2",
          "start_line": 266,
          "end_line": 290,
          "sanitized_sha256": "49a306037f11ad6c20614c5c306df319266b1e12bc87c262c097eba19838daef",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "capture complete rebalance output",
        "require shell rc zero",
        "require JSON decision commit_ok or noop",
        "require JSON apply_ok true",
        "convert false-success JSON to nonzero result"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/emergency_runner.txt"
    },
    {
      "label": "slots_apply",
      "source_path": "/usr/local/sbin/router-egress-slots-apply.sh",
      "source_sha256": "6e5bfbcc2b216a234f5501d72f2319a74f5ae9f49ec931d10157e322eeb66bfc",
      "source_line_count": 83,
      "purpose": "make table 200 optional",
      "anchors": [
        {
          "type": "token",
          "name": "table_200",
          "line": 44
        }
      ],
      "regions": [
        {
          "region_id": "slots_apply-r1",
          "start_line": 36,
          "end_line": 54,
          "sanitized_sha256": "306e578e8c2682062f38e66443cc1fea9c3cdf44daaab22db29fac78eb117651",
          "redactions": 0
        }
      ],
      "required_transformations": [
        "remove legacy table-200 hard gate",
        "retain authoritative validation for tables 201-205"
      ],
      "edit_ready": true,
      "excerpt": "docs/source-excerpts/slots_apply.txt"
    }
  ]
}
