{
  "schema": "router-step-release-v1",
  "step_id": "STEP_050M07P26C2_R03_CONTROLLED_LIVE_EXTERNAL_WIREGUARD_PROOF",
  "revision": "R03",
  "workflow_contract_version": 2,
  "canonical_zip_required": true,
  "classification": "class_c_controlled_live_external_wireguard_test",
  "functional_stage": "p26c2_controlled_live_external_wireguard_proof",
  "source_changed": false,
  "live_database_written": true,
  "database_schema_changed": false,
  "runtime_impact": true,
  "snapshot_required": false,
  "reboot_required": false,
  "runtime_provisioning_active": false,
  "external_onboarding_active": false,
  "config_qr_implemented": true,
  "public_config_qr_active": false,
  "external_client_handshake_proven": false,
  "smtp_tls_delivery_active": false,
  "encrypted_database_backup_required": true,
  "backup_restore_proof_required": true,
  "worker_entry": "scripts/run-step.sh",
  "exact_worker_fixture": "tests/exact-worker.sh",
  "target_package_path": "payload/p26c2-controlled-live-package.tar.gz",
  "target_package_sha256": "187fa2996f3b1e00fc9decf12ba3ba64f06acc723de53d84eeacb5e01f5ddae0",
  "expected_installer_sha256": "151968648cae025eb15407ae1ce7993ce3056f5707a6f43d2cd02fadecd9c98f",
  "mandatory_fixture_count": 7,
  "target_environment_matrix": "reference/target-environment.tsv",
  "path_ownership_manifest": "reference/path-ownership.tsv",
  "vm100_base_commit": "8c5d11b7e4b119757ea16b46775b26e0ac903d7c",
  "vm100_base_tree": "f25aab0f1886647b52a11ccebe080894bd06542a",
  "vm100_expected_file_count": 34,
  "vm101_base_commit": "94a1c5627bacf9212d3fb2af1a77507ec57ff74b",
  "vm101_base_tree": "ee4dddf35e308096d6496a4ecc25268ebcb3058a",
  "vm101_expected_file_count": 59,
  "vm121_base_commit": "9bbb2aeacd669698055121a0f4fbaf5aa67720db",
  "vm121_base_tree": "f83f404ca097962b1d407ad5b3c32da96acd4ee4",
  "vm121_expected_file_count": 51,
  "alembic_target": "0004_profile_provisioning",
  "source_of_truth": "AFTER_P25 Project Sources plus exact P25/R02, P26/R03, P26C1/R03 evidence, current VM121 Machine Git 9bbb2aeacd66, current Access Map DDN path ssh home-vm100, and P26C2/R01-R02 STOP evidence. R03 changes no production source/schema; it only hardens the external DDN config-transfer boundary after R02 proved that the client config never reached home-vm100.",
  "next_action": "P26C3 production SMTP/TLS magic-link delivery and durable admin authorization boundary before first trusted-user P27 pilot",
  "continuation_of": "STEP_050M07P26C2_R02_CONTROLLED_LIVE_EXTERNAL_WIREGUARD_PROOF",
  "continuation_reason": "R02 again proved authenticated profile creation, VM100 lifecycle/selector activation and config delivery, but the DDN transfer wrapper depended on an undeclared install utility and did not explicitly stop on transfer failure. The remote config file was absent, so no handshake was attempted; cleanup PASS. R03 keeps product/runtime semantics unchanged and makes transfer fail-closed using only preflight-declared utilities.",
  "external_client_handshake_target": true,
  "external_client_host": "home-vm100"
}
