Status: OPEN obligations, routed here 2026-07-23 from the session-ledger retained block (which pointed only at the archived rotation). Gates: the DEFERRED end-of-deployment write-back to the production apex netbox.baldurkeep.com (DOCFIX-195: office1-netbox is the WORKING VR1 apex; the production apex is READ-ONLY reference until then). These findings gate THAT write campaign -- nothing current.
History: six write-path defects found 2026-07-14 by adversarial review. Defects 1-3 and 6 were FIXED the same day (docs/archive/changelogs/changelog-20260714-netbox-write-path-hardening.md: roles-importer preflight covers ARIN + ULA; prefixes-importer preflights every role; fidelity check both-bounds + delta-scope-aware; test fake raises on multi-match like real pynetbox). Full original text: docs/archive/session-ledger-rotated-20260719.md ("OPEN -- NetBox WRITE-PATH BUGS" section).
sandbox-fidelity-check compares two dumps produced by the SAME field list, so any field the dumper omits is invisible on both sides by construction (prefix vrf, tenant, vlan, tags, custom_fields; site tenant/group/facility). Same structural shape as the region-scope bug that once dropped 17 prefixes. Fix direction: widen the dump field list, or add an independent field-coverage assertion.vr0-dc0). A whole prefix object can vanish under a green check. Latent only because no duplicates exist upstream today. The hardened fake (#6 fix) makes this testable now.sandbox-fidelity-check.py against office1-netbox before trusting that verdict -- this re-run IS C2 sub-task (i) per DOCFIX-195.The next NetBox WRITE campaign of any kind -- above all the deferred netbox.baldurkeep.com merge-back at end-of-deployment. No write campaign starts while items 1-2 are unfixed or 3-4 unrun. (Read-only NetBox use is ungated.)