RUMBO R2 CURRENT Audit — V7

Status: 75/75 PASS / LIVE_BLOCKER_EVIDENCE_RECONCILED / SNAPSHOT_ONLY / PRODUCTION_NO_GO

Snapshot basis:

  • repository: fscfede-beep/rumbo-control-queue
  • repository ID: 1314199389
  • owner: fscfede-beep
  • owner ID: 293577326
  • visibility: private
  • observed main SHA: 0f7d35cc752c084b9ec1192f986f5c433d3fcc0b
  • observed commit: checkpoint: record R13 27/27 runtime pass
  • observed time: 2026-08-29T07:19:30Z
  • CURRENT schema: rumbo-r2-current/v7
  • validity: SNAPSHOT_ONLY_REVALIDATE_ALL_DYNAMIC_AUTHORITY_BEFORE_ACTIVATION
  • production_go: false

The repository is actively changing in parallel. This SHA is evidence only; JIT activation must re-read live main immediately before and after branch refresh and abort on drift.

Live native-enforcement evidence

The authenticated GitHub identity is the repository owner. The connector reports:

  • admin: true
  • maintain: true
  • pull: true
  • push: true
  • triage: true

Live branch-protection read:

GET /repos/fscfede-beep/rumbo-control-queue/branches/main/protection

Result:

HTTP 403 — Resource not accessible by integration

This does not prove branch protection exists, so branch protection remains unproven.

Live repository-rulesets read:

GET /repos/fscfede-beep/rumbo-control-queue/rulesets

Result:

HTTP 403 — Upgrade to GitHub Pro or make this repository public to enable this feature.

GitHub's current official documentation states that protected branches and repository rulesets are available on public repositories with GitHub Free, while private repositories require GitHub Pro, Team or Enterprise for those features.

Decision:

FAIL_CLOSED_NATIVE_ENFORCEMENT_UNPROVEN_AND_PLAN_BLOCKED

No repository visibility change and no paid-plan purchase were performed.

Detailed evidence is preserved in:

NATIVE_ENFORCEMENT_BLOCKER.md

Current R2 trust chain

  1. broker: R2_GITHUB_APP_CUSTODY_BROKER_V1_2_POST_INSTALL_AUTOPILOT
  2. observer: R2_GITHUB_OBSERVER_V1_5_BROKER_AUTOPILOT
  3. authorizer: DEDICATED_R2_AUTHORIZER_V3_5_OBSERVER_V1_5_PINNED
  4. deployer: R2_DEPLOYER_CONTROLLER_V3_6_BROKER_AUTOPILOT
  5. continuity relay: R9-ISOLATED-AUTH-PROVENANCE

All trust pins remain exact and all services retain production_go=false.

Fresh stable-main selftests

Broker:

01a04c61-1ae5-7387-9c6e-7ba79ca5ee14 — PASS

Observed:

  • broker_ready false
  • autopilot downstream ready
  • exact manifest permissions PASS
  • extra/upgraded permission rejection PASS
  • AES-GCM roundtrip PASS
  • app JWT shape PASS
  • audit chain PASS
  • no persisted installation tokens
  • no plaintext private key
  • production_go false

Observer:

01a04c61-468a-701a-a7f0-b94fe575a3f2 — PASS

Observed:

  • direct GitHub token path retired
  • broker role token configured
  • broker custody not ready
  • live observe fails 424 before GitHub access
  • fixture signature verifies
  • tampered fixture fails
  • audit chain PASS
  • production_go false

Authorizer:

01a04c61-5e13-722b-bd13-ea2cf662c64b — PASS

Observed:

  • V1 merge issue/consume retired
  • V3 merge gate disabled
  • TEST_ONLY issue/consume PASS
  • wrong token/replay/duplicate fail
  • signed receipt verifies
  • tampered receipt fails
  • token hash not leaked
  • audit chain PASS
  • production_go false

Deployer:

01a04c61-75cb-7591-80a2-0b70d62359cf — PASS

Observed:

  • broker V1.2 pin exact
  • authorizer V3.5 fixture verifies
  • downgrade/tamper/forged merge rejected
  • unauthenticated JIT preparation rejected
  • authenticated JIT preparation stops at CUSTODY_NOT_READY
  • provider preflight stops at CUSTODY_NOT_READY
  • TEST_ONLY execution forbidden
  • signature bytes not leaked
  • audit chain PASS
  • deploy disabled
  • production_go false

Relay:

01a04c61-9c33-7019-a320-8da41a54d20a — PASS

Current acceptance:

CODEX_REAL_RUNTIME_ACCEPTANCE_V4

State:

PENDING_CODEX_ACK

Mechanical checks:

false

Bootstrap remains exact-hash-bound for both Python launcher 5.1 and the Windows PowerShell launcher. Audit chain remains PASS. No synthetic Codex evidence is claimed.

Capsule authority boundary

The historical MANIFEST.json remains immutable and records the exact 5/5 historical payload copy from:

d0043f418c1b0f7d21b36dc1c5469c9ded49cfd7

That historical source is explicitly not current GitHub authority.

Remaining external/evidence gates

Exactly four remain:

  1. DEDICATED_GITHUB_APP_CREATE_AND_EXACT_REPOSITORY_INSTALL
  2. NATIVE_PRIVATE_REPOSITORY_RULESET_OR_BRANCH_ENFORCEMENT
  3. JIT_R2_ACTIVATION_PR_AND_SIGNED_EXTERNAL_OBSERVER_PASS
  4. REAL_CODEX_V4_ACK_RESPONSE_AND_FINAL_SEMANTIC_GPT_ACK

Gate 3 is fully implemented as a fail-closed continuation behind Gate 1, but cannot produce real evidence before a real dedicated App installation exists.

Gate 2 is now backed by both a live API plan-block response and current official GitHub feature-availability documentation. It remains intentionally unresolved.

Mechanical audit

V7 mechanically checked 75/75 invariants covering:

  • live snapshot identity and churn handling;
  • JIT/no-force authority;
  • historical PR closure;
  • hosted-Actions deprecation as primary observer substrate;
  • no billing/visibility mutation;
  • live owner/repository identity;
  • live branch-protection and ruleset blocker evidence;
  • official feature-availability interpretation;
  • sealed package identity and tests;
  • broker V1.2 custody and bounded autopilot;
  • observer V1.5 service isolation and runtime authority;
  • authorizer V3.5 observer/broker provenance;
  • deployer V3.6 JIT-only service auth and strict execution gates;
  • cross-service least privilege;
  • R9/V4 Python and Windows exact launcher binding;
  • immutable historical capsule evidence;
  • exactly four remaining external/evidence gates;
  • disabled merge and deployment controls;
  • direct-main prohibition;
  • global product and production NO_GO.

No merge, deploy, paid-plan mutation, repository-visibility change or fabricated Codex evidence was performed.