RUMBO R2 Deployer Controller V3.4 — Authorizer V3.4 Pin

Status: PASS / DEPLOY_DISABLED / BROKER_CUSTODY_PENDING / PRODUCTION_NO_GO

Implementation: R2_DEPLOYER_CONTROLLER_V3_4_AUTHORIZER_V3_4_PINNED.

Required broker: R2_GITHUB_APP_CUSTODY_BROKER_V1_1_EXACT_SCOPE. Required authorizer: DEDICATED_R2_AUTHORIZER_V3_4_OBSERVER_V1_4_PINNED with signed consumption schema rumbo-r2-dedicated-authorizer-consumption/v3.4.

The deployer now rejects V3.3 and older authorizer receipts. Direct GitHub token custody remains retired; GitHub access is broker-issued JIT installation-token only.

Validation evaluation: 01a04bff-ff6f-717a-87c3-49b2b2abfcf1 — PASS. The V3.4 authorizer fixture verified cryptographically; authorizer downgrade, receipt tamper and forged merge failed; TEST_ONLY execution failed closed; broker-unready provider preflight returned 424; duplicate preparation failed; ledger projected no signature bytes; audit chain passed.

Fixture authorizer receipt SHA-256: 72ba564de3da05f44b4ff7951b6c3fc98420554b408ee851dd88e51360193705.

Static source audit: PASS across broker and authorizer anti-downgrade, exact repository/permission contract, no durable installation-token persistence, live-main/base binding, native enforcement, independent APPROVED review fulfillment, exact head merge, post-merge main readback and explicit deploy flag.

R2_ALLOW_DEPLOY remains false/absent; broker custody remains pending; production_go=false.