VM101 HMN downloader selector method Generated UTC: 20260713-192030 Source of code: - Published Machine Git baseline commit 0cdefcb9bd39e750d200c00f56a3d55c1d18b14a. - No broad live filesystem inventory was performed. Access: - router-ops -> ssh pve-mgts -> VM101 10.71.100.2. - Existing key on Proxmox: /root/.ssh/pve_to_openwrt_mgts_ed25519. Deployment: - raw stdin transport; - same-directory temporary file; - exact SHA-256 verification; - BusyBox ash syntax check; - root:root and mode 0700; - atomic mv; - timestamped rollback copy. Reused implementation: - /usr/local/lib/router-egress-vm101-runtime.sh - vm101_healthy_bootstrap_iface - vm101_strict_iface - existing Machine Git v2 publisher - existing router-machine-close workflow Verification: - selector-only harness exits before downloader creates run/config directories; - auto selection checked; - explicit caller override checked; - invalid eth0 request rejected; - downloader body from TS= onward retains SHA-256 40c52441d31cad02155102bf86fd6583eff605d10d6ae63568e8b67d7911dfa4; - full refresh and rebalance were not invoked. Limitations: - This STEP does not prove a full HideMyName pool download. - This STEP does not modify hmn-validate-current-pool.sh. - A controlled full refresh remains a later M07 action after validator alignment.