RUMBO R2 Dedicated Authorizer V3.5 — Observer V1.5 Pin

Status: PASS / MERGE_DISABLED / PRODUCTION_NO_GO

Implementation: DEDICATED_R2_AUTHORIZER_V3_5_OBSERVER_V1_5_PINNED.

V3.5 advances the trust chain to observer R2_GITHUB_OBSERVER_V1_5_BROKER_AUTOPILOT and broker provenance R2_GITHUB_APP_CUSTODY_BROKER_V1_2_POST_INSTALL_AUTOPILOT.

The signed observer receipt must now carry a valid invocation mode (ROOT or BROKER_AUTOPILOT). All previous controls remain: exact repository/PR/base/head/package binding, observer freshness, ES256 signature verification, native enforcement requirement, evidence SHA equal to observer receipt SHA for merge authority, one-time authorization tokens, replay protection, and global NO_GO.

Signed authorizer schemas advance to v3.5.

Basic selftest evaluation after cleanup: 01a04c4f-e5b6-75d4-afc1-b6d966894e26 — PASS.

Positive V1.5 observer-chain evaluation: 01a04c4e-f496-73eb-9036-52a0257a372f — PASS. Valid V1.5/Broker V1.2 signed receipt accepted; observer downgrade, broker downgrade, invalid invocation mode, binding mismatch and signature tamper rejected. Temporary diagnostic route/file were removed before release.

Static source audit: 12/12 PASS. MERGE_PR remains disabled and production_go=false.