SAVEGAME SWEEP -- 2026-08-09 session: open-items review (D/SEC/DOCFIX/BUNDLEFIX) + live-free confirmation
=======================================================================================================

Session shape: READ-ONLY analysis + operator-authorized LIVE read-only discovery. No cloud
mutation. One durable deliverable committed+pushed this session: f4aee80
(docs/audit/open-items-review-20260809.md + a CURRENT-STATE pointer). This sweep proves the
session's substance is on a repo surface so a /clear loses nothing.

PRIMARY DURABLE SURFACE: docs/audit/open-items-review-20260809.md (committed f4aee80). Nearly
all session substance lives there. Items below are either (A) ALREADY ON SURFACE (where), or
(B) FIRST SURFACE (this file is the durable home). FIRST SURFACE items lead.


== FIRST SURFACE (transcript-only until this file) ==

FS1. THE REPEATABLE METHOD for the two completed re-IP live-free checks (the review appendix
     records the RESULTS; the exact commands were transcript-only). Fills the ruling-prep's
     noted tooling gap (reip-1013-...:268 "is-this-prefix-free checker") as a MANUAL procedure:
     - Check #2, live NetBox apex (from vcloud; token never printed):
         set -a; . ~/vr1-office1-creds/vr1-netbox-sandbox.env; set +a
         python3 netbox/office1-record-dump.py --out <tmp>.json     # tested tool, read-only
         # then check prefixes/aggregates/ranges/ips for 10.13.0.0/16 (10.12 = positive control)
       Result 2026-08-09: 10.13 = 0 objects; 10.12 = 149. office1-netbox reachable FROM vcloud
       (10.10.1.10:8000; the ruling-prep's "unreachable from vcloud" caveat was over-stated --
       the record env lives on vcloud and vcloud has L3 to 10.10.1.10).
     - Check #1, Headscale/tailnet routes (from the live office1-tailscale node, on the tailnet):
         ssh office1-tailscale 'tailscale status --json'   # extract per-peer AllowedIPs
         # subnet routes only (skip /32,/128); check overlap vs 10.13.0.0/16 (10.12 = control)
       Result 2026-08-09: no 10.13 overlap; positive control reproduced the exact 10.12
       collision (vopenstack-jesse-tailscale advertising 10.12.4.0/22 + 10.12.8.0/22).
     RECOMMENDATION (logged, not built -- hard rule 1): if the operator wants this repeatable,
     build the ruling-prep's "is-this-prefix-free" read-only checker wrapping these two probes.

FS2. ACCESS / ENVIRONMENT facts confirmed live this session (some partially in the review
     appendix; consolidated here so none is lost):
     - tailscale is NOT installed on vcloud (the D-107 workstation path is the human tailnet
       route; vcloud reaches the tailnet only via a tailnet node like office1-tailscale).
     - office1-tailscale (10.10.1.11) runs tailscale 1.98.9 and is the usable tailnet vantage.
     - The shared self-hosted tailnet (tailscale.baldurkeep.com) ALSO carries OTHER projects:
       Roosevelt (10.17.4.0/22, 10.17.8.0/22, 10.0.0.0/24), willamette (10.1.0.0/24,
       10.16.0.0/24), Office1 (10.10.0.0/22). 10.13.0.0/16 is clear of ALL of them -- so the
       re-IP does not collide with Roosevelt or willamette either, not just the live VR0 cloud.
     - VR0 (vopenstack, logxen's live cloud) is a SEPARATE TRUST DOMAIN: 10.12.64.1:22
       unreachable from vcloud; no VR0 juju/openrc/clouds.yaml on vcloud; juju not installed on
       vcloud. VR0 is reachable only over the tailnet (which vcloud is deliberately not joined
       to -- STOPPED tailscale workstream). => re-IP owed check #3 (VR0 internals) is an
       operator accept-or-run-from-workstation choice, NOT completable from the jumphost.

FS3. RAW CAPTURES ARE EPHEMERAL. The apex dump ($CLAUDE_JOB_DIR/tmp/apex-live-20260809.json)
     and tailnet json live in the job tmp dir and are CLEANED when the job is deleted. Their
     DERIVED findings are durable (review appendix + FS1), but the raw JSON is not retained.
     Not a loss (re-runnable via FS1); recorded so no one hunts for a missing capture path.


== ALREADY ON SURFACE (verified by grep) ==

OS1. The full open-items review + all recommendations R1-R16, the 28-SEC partition, the P5=11
     correction, the SEC bucketing, the two-pass advisor consensus:
     docs/audit/open-items-review-20260809.md (committed f4aee80).

OS2. re-IP 2/3 live-free checks PASS + check#3 accept-or-run + review pointer:
     docs/CURRENT-STATE.md (pointer block added under the reip-prep pointer, f4aee80).

OS3. Credential residency inventory (dc0 rack / region VM / voffice1 shadow stores):
     open-items-review-20260809.md Appendix item 5.

OS4. dc0 checkpoint state 66 machines / 162 units active: measured live and matches
     CURRENT-STATE section 1 (already recorded there pre-session).

OS5. The 10.13 naming-collision literals (netbox/README.md:49, test_logic.py:265):
     open-items-review-20260809.md R16 + they are the live files themselves.


== CONTRADICTION DETECTOR (measurement vs standing docs -- all logged as recommendations) ==

CD1. P5 acceptance recorded as "6 findings" (CURRENT-STATE / SEC-028) vs live authoritative 11
     on voffice1 -- but the delta is BY DESIGN (matrix grew 101->121 via SEC-027/028/029). Not
     a doc defect; a note owed when P5 is re-cited. Review Section 3f. NO ACTION here.

CD2. SEC-021(a) record text ("needs a decision between RE-MINT and locating an off-jumphost
     copy") is stale -- SEC-032 located+minted the copy; S2 still RED because the DERIVED
     manifest was not regenerated. Review R11. Recommendation only (hard rule 1).

CD3. SEC-ledger "CURRENT-STATE G14 reads 12 / reconciles at Stage 4 close" count-notes
     (SEC-017/020/023) are stale -- CURRENT-STATE now carries 28, Stage 4 long closed.
     Review R13. Recommendation only.

CD4. creds-matrix note n-dc0-edge-api-absent (creds-matrix.tsv:76 / notes:123) factually stale
     (the cred now exists). Review R12 + SEC-032 already flags it. Recommendation only.


== RULING FIDELITY ==

RF1. NO GA-R5 rulings this session (analysis only). The operator directives were operational,
     not rulings: (a) "Run as much discover as you need on the live environment ... full
     permission into any system for this entire session" (authorized live read-only discovery);
     (b) "Yes, run the savegame and present" (this bookend + present the re-IP ruling next).
     Neither mints a D-number.

RF2. The re-IP GA-R5 ruling (would be D-143) is NOT minted -- it is to be PRESENTED to the
     operator (the session's next action). Grep next-free again at ruling time.


== AS-EXECUTED LOG ==

AX1. run-logged.sh was NOT opened this session -- correctly, no cloud MUTATION occurred. All
     live access was read-only (NetBox dump, tailnet status, juju status, creds-matrix, ls of
     credential dirs by name only, tcp reachability probes). Recorded so the absence of an
     as-executed log for this window is explained, not a silent gap.


== OWNED (own-mistakes; all corrected before reaching the operator as fact) ==

OW1. Ran the HOST-DEPENDENT P5 gate (creds-matrix --tier2) on VCLOUD and framed the result as
     "P5 silently grew to 12, you now face 12" -- a manufactured decision. Authoritative host is
     voffice1 (11 findings); the count grew 101->121 BY DESIGN (SEC-027/028/029). Framing
     inverted. Caught by the fable advisor, not self-review. => instrument-currency memory #25.

OW2. Claimed SEC-021(a)'s creds-matrix E1 was "now CLEAN / effectively resolved" from the RECORD
     without measuring; live run showed S2 still RED (manifest regen owed). Corrected same pass.

OW3. Asserted the SEC categorization "sums to the 28 open rows" while it summed to 24
     (SEC-003/015/016/024 unplaced) -- a completeness claim that failed its own count, the exact
     "checker that cannot fail" class. Caught by the advisor; re-partitioned (10/8/3/3/3/1).

OW4. R15 first offered "declare OR shred" for opnsense-api-rebuild-20260807.txt, which is very
     likely the LIVE dc1 edge credential (2026-08-07 rebuild) -- shred was a hazard, not an
     alternative. Reframed to declare-only (shred only on a proven-dead live auth-test).

All four are recorded in open-items-review-20260809.md Section 8 (consensus, corrections
visible) and OW1/OW2 in memory instrument-currency-before-negatives.md #25.


== DELIBERATELY NOT DONE (hard rule 1 -- findings logged, not executed) ==

ND1. R7 teardown credential-revocation checklist NOT built (recommendation; build at re-IP).
ND2. No SEC-row edits, no manifest regeneration, no DOCFIX applied, no re-IP ruling minted --
     all are gated exchanges for the operator (the review is the decision package).
ND3. re-IP owed check #3 (VR0 internals) NOT run -- not reachable from the authorized vantage
     (FS2); it is an operator accept-or-run choice.

NEXT: present the re-IP GA-R5 ruling package (would be D-143) with the check#3 accept-or-run
choice. Body: docs/audit/open-items-review-20260809.md. Status ONLY in CURRENT-STATE.md.
