{
  "schema": "router-step-release-v1",
  "step_id": "STEP_050M07P26C2_R01_CONTROLLED_LIVE_EXTERNAL_WIREGUARD_PROOF",
  "revision": "R01",
  "workflow_contract_version": 2,
  "canonical_zip_required": true,
  "classification": "class_c_controlled_live_external_wireguard_test",
  "functional_stage": "p26c2_controlled_live_external_wireguard_proof",
  "source_changed": false,
  "live_database_written": true,
  "database_schema_changed": false,
  "runtime_impact": true,
  "snapshot_required": false,
  "reboot_required": false,
  "runtime_provisioning_active": false,
  "external_onboarding_active": false,
  "config_qr_implemented": true,
  "public_config_qr_active": false,
  "external_client_handshake_proven": true,
  "smtp_tls_delivery_active": false,
  "encrypted_database_backup_required": true,
  "backup_restore_proof_required": true,
  "worker_entry": "scripts/run-step.sh",
  "exact_worker_fixture": "tests/exact-worker.sh",
  "target_package_path": "payload/p26c2-controlled-live-package.tar.gz",
  "target_package_sha256": "39acc4b573bd1aa46450e32e535616d0c7cf19509e4cc4906f6e02339cb817a1",
  "expected_installer_sha256": "07ccecea2b70fabcb52911af00f4ce3bd7cb6d99b228ef601918b0ae9ab27b6d",
  "mandatory_fixture_count": 7,
  "target_environment_matrix": "reference/target-environment.tsv",
  "path_ownership_manifest": "reference/path-ownership.tsv",
  "vm100_base_commit": "8c5d11b7e4b119757ea16b46775b26e0ac903d7c",
  "vm100_base_tree": "f25aab0f1886647b52a11ccebe080894bd06542a",
  "vm100_expected_file_count": 34,
  "vm101_base_commit": "94a1c5627bacf9212d3fb2af1a77507ec57ff74b",
  "vm101_base_tree": "ee4dddf35e308096d6496a4ecc25268ebcb3058a",
  "vm101_expected_file_count": 59,
  "vm121_base_commit": "9bbb2aeacd669698055121a0f4fbaf5aa67720db",
  "vm121_base_tree": "f83f404ca097962b1d407ad5b3c32da96acd4ee4",
  "vm121_expected_file_count": 51,
  "alembic_target": "0004_profile_provisioning",
  "source_of_truth": "AFTER_P25 Project Sources plus exact P25/R02, P26/R03, P26C1/R03 evidence and current VM121 Machine Git 9bbb2aeacd66. P26C2 changes no source/schema; it proves the authenticated P26C1 config surface against the real VM100 lifecycle and an isolated external WireGuard client.",
  "next_action": "P26C3 production SMTP/TLS magic-link delivery and durable admin authorization boundary before first trusted-user P27 pilot",
  "continuation_of": "STEP_050M07P26C1_R03_WIREGUARD_CONFIG_QR_REVOKE_REISSUE_SURFACE",
  "continuation_reason": "P26C1 installed and isolated-tested config/QR/revoke/reissue; P26C2 supplies the explicitly deferred controlled live external handshake/data-plane proof without expanding public onboarding."
}
