RUMBO R4 — PR #392 Final Head Binding

Status: TEST_ONLY_BINDING_PASS / MERGE_NOT_AUTHORIZED / PRODUCTION_NO_GO

This record binds the live external R2 guard to the exact current GitHub PR #392 head without granting merge or production authority.

GitHub binding

  • repository identity SHA-256: 59e28afe0dd67d61cdaaaa5d470a6470b6c1540f025d172f094fe3321857fc23
  • PR: 392
  • base SHA: fd66dc70415c2aefcd654b9f01ce5b3c4d115a7f
  • head SHA: bcfb38f46438535cd200d10a2cde3bcb4f7aafc2
  • control package SHA-256: afbdc77510286adc5721ada5a0ddfa75e10305cb5200d6fd37cd8438c9c6119f

The PR was observed OPEN, DRAFT, mergeable, with five changed files when the evidence object was constructed.

External runtime binding

Runtime: sebas1/rumbo-continuity-relay

Implementation observed before issuance:

R4-ACCEPTANCE-GUARD

Runtime guard state:

  • configured: true
  • merge authorization enabled: false
  • production_go: false

The Codex real-runtime acceptance verifier remained fail-closed at:

PENDING_CODEX_ACK

Challenge message SHA-256:

70d6702195fca8666fd31d15084993c8ce4a7e191bd692984c0b1429c92f5979

Evidence object

Canonical evidence SHA-256:

2abe5bb70059597092668a7c1d50534a069aacb6f84d92037e7db21a2bf14914

Scope:

TEST_ONLY_FINAL_PR_HEAD_BINDING_NO_MERGE_NO_PRODUCTION

One-time authorization transaction

A branch-scoped script used the encrypted R2_GUARD_TOKEN_V1 environment variable to call the live main runtime. The bearer and the raw one-time token were never logged.

Result:

  • authorize: PASS
  • consume: PASS
  • one-time authorization ID: 6c54a26a-4cf3-4893-87ff-233c5351cc3d
  • request SHA-256: 76629d5646aca94992c6248b24d1713d8ebf795214f5b2f8716265955c1bf196
  • consumption receipt SHA-256: 7a73164985f7f19e26fdd755f83387adc1bc2729aa193dbb15330df0c8cf8c15
  • merge_authorized: false
  • production_go: false

Val Town evaluation ID:

01a04b5b-0efc-7728-8cc1-a86bd8d43430

Safety audit

The runtime was independently re-audited before this transaction:

  • five guard routes present;
  • five guard routes require the dedicated guard bearer;
  • no raw guard bearer embedded in source;
  • merge authorization blocked at both issuance and consumption;
  • no public guard self-test route;
  • unauthenticated ledger access returns 401;
  • guard token hashes are not projected by ledger/status reads;
  • production_go=false remains invariant;
  • R4 acceptance verifier is read-only and currently reports PENDING_CODEX_ACK;
  • acceptance self-test returned PASS while preserving production_go=false.

The temporary PR-binding script was deleted from the release branch after its single successful execution.

Claim boundary

This record proves only that the external fail-closed authorizer could issue and atomically consume one TEST_ONLY authorization bound to the exact PR #392 head above.

It does not prove or authorize:

  • MERGE_PR
  • GITHUB_OBSERVER_VALIDATED
  • DEDICATED_GITHUB_APP_CUSTODY
  • EXTERNAL_DEPLOYER_LIVE
  • PRODUCT_GO
  • PRODUCTION_GO

PR #392 must remain draft while the private GitHub-hosted observer is unable to obtain a runner and until the remaining trust-root gates are satisfied.