Moved VERBATIM from docs/session-ledger.md to restore the 300-line cap at this close. These are HISTORY: they carry no status weight (status lives in docs/CURRENT-STATE.md).
dc-dc-stage5-preconditions, 22 commits pushed. NO stage opened/closed. Scan unchanged: 3 decisions, SEC 21, D 138 / DOCFIX 205 / BUNDLEFIX 053.prefer-ipv6 is coupled to arity BOTH ways, closing the L3-9 merge order in which dropping the v6 legs exited 0.bundle.yaml is VIP-FREE; both DCs dual-family, vault .61 / designate .62 BUILT.tests/render-drift, added 3 refusals, fixed 2 harness cases that could not fail.skip_networking=1, every diff EXACTLY the new device; MAC adoption applied (drift 0 across 20 nodes, both roots ZERO DIFF); both controllers commissioned; all ruled MAAS tags created. THE STAGE-5 ALLOCATION BLOCKER IS CLOSED.skip_networking=1 is the vendor control, and the MAC check sits BETWEEN apply and re-commission, which is what makes 2026-07-20 non-repeatable..5 AND the octet map is a STANDING CROSS-DC STANDARD (D-134 amendment) -- divergence between DCs at the same octet is now a DEFECT, not a local choice.options (charm v12.1.1 source), so octavia-pki cannot clobber the VIP; and nothing inside Octavia requires IPv4.docs/audit/queued-findings-20260729.txt.docs/changelog-20260728-vip-arity-gate.md. Status ONLY in CURRENT-STATE.md.dc-dc-stage5-preconditions, 25 commits pushed (ab4c842..). NO stage opened/closed. Scan unchanged: 3 decisions, SEC 21, D 138 / DOCFIX 205 / BUNDLEFIX 053.$DC in NO path, so generating dc1 would have DESTROYED dc0's CA and left one fixed-name overlay applying dc1's CA to dc0. Fixed end to end + REFUSE-IF-PRESENT.check-ignore self-assert, proven both ways. F2: register was blind to a missing 2nd CA set (was RULED work, R13 Part 1). F6: P5 was probing the WRONG HOST'S filesystem and reporting it as fact -- 34 findings vs the true 7.scripts/octavia-pki.sh verify NEW (harness 21/21): asserts the SAN set nothing asserted before (F8's SAN-less cert), and A12 ARMS ITSELF from os-public-hostname so F9 cannot be missed.vr1-dc1 is dc1 by TOKEN or dc2 by POSITION -- item 3.1's ambiguity inside a ruling, deciding cert identity. A12 REFUSES rather than picking. ^ WITHDRAWN 2026-07-30 (DOCFIX-205): NOT a ruling gap. D-117 ruled it 2026-07-13 (dc1/dc2 retired for dc0/dc1) and says so in its own Status line; D-106 read as open only because D-117's annotation half was never executed (zero of four) while its Status line claimed "FULLY EXECUTED". Also not blocking -- A12 measures INERT and passes. Now an assertion on the derived zone; status in CURRENT-STATE.md.opentofu-validate fmt walking gitignored tfvars). Fixed + scoped; both hosts now ALL GREEN (89), repo-lint 0 fail.br-ex onto the PXE NIC); the skill cites D-107 for a tailnet path it does not rule; office1-tailscale is labelled a subnet router and advertises none.| grep -q under pipefail, git pull -q &&); four consecutive cwd mistakes. All corrected on-surface.phase-04-network-* scripts.docs/audit/queued-findings-20260730.txt (F10-F13 + 2 ruling questions). Body: docs/changelog-20260729-stage5-preconditions.md. Status ONLY in CURRENT-STATE.md.