RUMBO R2 Dedicated Authorizer V3.4 — Observer V1.4 Pin

Status: PASS / MERGE_DISABLED / PRODUCTION_NO_GO

Implementation: DEDICATED_R2_AUTHORIZER_V3_4_OBSERVER_V1_4_PINNED.

Required observer implementation: R2_GITHUB_OBSERVER_V1_4_JIT_DERIVED_GITHUB_AUTHORITY. Required broker provenance: R2_GITHUB_APP_CUSTODY_BROKER_V1_1_EXACT_SCOPE.

V3.4 advances the anti-downgrade chain to the JIT-derived GitHub authority observer. Older observer implementations and older broker provenance are rejected before merge authority can be issued. Signed authorizer issuance, consumption and ledger schemas advance to v3.4.

Positive cryptographic chain test evaluation: 01a04bfd-c052-74a3-b539-7411a361d553 — PASS. A valid V1.4 observer ES256 receipt was accepted; V1.3 observer downgrade, broker downgrade, binding mismatch and signature tamper were rejected. The temporary diagnostic route and test file were removed before release.

Permanent selftest after cleanup: 01a04bfe-0ef7-71f4-a776-f0dfcbef40c4 — PASS.

TEST_ONLY receipt SHA-256: a147703866ae5e0108210f7f52083cdf33b7d56fb228cf94d8cf0d3b1df56137.

Static source audit: PASS. MERGE_PR remains disabled, native enforcement remains mandatory, evidence must equal the signed observer receipt SHA-256 for merge authority, and production_go=false.