reconcile provider-bundle-check harness to D-141 (sweep F1 CLOSED)
The 2026-08-03 deploy session reverted the dc0 VIP overlay to IPv4-only
under D-141 (3e691cd) but shipped it without the companion harness update,
leaving run-tests-all RED at 1/98 (provider-bundle-check, 4 dual-family
cases T19/T21/T25/T45 asserting a shape the deploy input no longer has).

Reconcile by re-pointing, never deleting (the checker's dual-family path is
still live code and D-141 rule-3 promotes v6 later):
- new synthetic dual.yaml fixture on the MEASURED all-GUA legs of the
  pre-revert deploy input (3e691cd^), present in the current apex -- NOT the
  stale DUAL6 ULA constant D-139 deprecated
- T19 assertion REPLACED with the v4-only invariant (0 dual-family)
- T21/T25/T45 re-pointed to dual.yaml (dual-family PASS + apex-refusal
  controls preserved)
- corrected the now-vacuous v4only.yaml comment

scripts/provider-bundle-check.py is UNCHANGED -- it is family-agnostic (a
vip is a v4 triple OR a dual-family sextet); this is a harness reconcile only.

Verified: provider-bundle-check 55/55 ALL PASS (count unchanged 55->55, pure
re-point); new T19 failing-direction proven; full gauntlet GAUNTLET: ALL
GREEN (98 harnesses) (was 1/98 FAIL); repo-lint 0 fail / 1 legacy warn.

CURRENT-STATE updated same commit (GA-R1 C1). Three follow-ons LOGGED to the
close sweep (FN1 stale DUAL6 ULA; FN2 generated overlay header; FN3 dual.yaml
builder can silently no-op at promotion).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent bd7a1d0 commit 5c9da9945cf4e6b4ed6575aeb34fdcf4c2f581c8
@JANeumatrix JANeumatrix authored 1 hour ago
Showing 4 changed files
View
docs/CURRENT-STATE.md
View
docs/audit/queued-findings-20260803-stage5-deploy-ovn.txt
View
docs/changelog-20260803-provider-bundle-check-d141-reconcile.md 0 → 100644
View
tests/provider-bundle-check/run-tests.sh