RUMBO R2 GitHub Observer V1.4 — JIT Derived GitHub Authority

Status: PASS / JIT_AUTHORITY_FIXED / BROKER_CUSTODY_PENDING / PRODUCTION_NO_GO

Implementation: R2_GITHUB_OBSERVER_V1_4_JIT_DERIVED_GITHUB_AUTHORITY.

V1.4 fixes a JIT activation defect found during reconciliation. The sealed bootstrap LIVE_STATE.json is schema rumbo-continuity-live-state/v2 and contains historical successor coordinates. Those coordinates are now explicitly non-authoritative for a fresh activation. Runtime PR/base/head/branch authority is read directly from GitHub and signed into the observer receipt.

Stable invariants from the sealed state remain blocking: exact repository identity, private visibility, exact package SHA-256, local artifact seal PASS, direct-main mutation forbidden, reviewed-PR requirement, runtime merge gate disabled, product production NO_GO, control-plane operational GO false, and production_go false.

Branch-only adversarial evaluation 01a04bf1-7dbb-75d6-9148-4a3f95890696 — PASS:

  • stale historical PR/base/branch coordinates accepted only as non-authoritative metadata;
  • wrong repository id rejected;
  • product GO rejected;
  • wrong state schema rejected.

Permanent selftest after removing the diagnostic route/file: 01a04bf1-c709-708d-802a-63f5dad4c8e3 — PASS.

Static audit: PASS. Direct GitHub token custody remains retired, broker implementation remains pinned to R2_GITHUB_APP_CUSTODY_BROKER_V1_1_EXACT_SCOPE, native enforcement remains mandatory for merge readiness, and production_go=false.