# Phase-6 exit runs (sweep Batch 6, 2026-07-19)

Charter section 7, in order. Items 3 (probe trio) and 6 (operator re-sign)
are operator-executed; their results append here when run.

## 1. Extractor re-run -- zero contradictory status-claim PAIRS (adjudicated)

Operator ruling at batch open (2026-07-19): docs/archive/ joins docs/audit/
as inventoried-but-not-counted ("Yes, extend exclusion (Recommended)").
Implemented in record-audit.py + harness (35/35).

Post-exclusion run (`vocab-b6b` scratch capture; re-runnable:
`python3 scripts/record-audit.py --repo . --out <scratch>`): 9 groups
remain on counted surfaces. Per-group adjudication -- ZERO pairs claim
different values for the same referent (the charter's actual criterion):

| Group | Verdict |
|---|---|
| plan (6 values) | Different referents + required narration: 13/0/0 is Stage-1's OWN expected plan (a different root, correct procedural text); 6/0/6 x4 is THE consistent current triple (CURRENT-STATE + ledger pointer); 7/2/7 + 6/2/6 + 5/x/6 are history/evidence narration REQUIRED by GA-R1 rule 2 (capture quotes) on the status authority, the append-only register (GA-R3-kept), the retained finding doc, and the live session changelog (GA-R2 scratch) |
| juju | One real value (3.6 track, consistent everywhere); "2.1"/"3.1" are step numbers, "2024.1" a charm channel -- attribution artifacts |
| lxd | Consistent facts, different aspects: 5.21 = the pinned track; 5.21.4 = dated observation; 5.21.5 = current measured; 6.6/6.7 = the D-114 incompatibility THRESHOLD |
| maas | 3.7.2 measured everywhere it is claimed; 2.3.5 = pylxd (misattributed); 2.7.2 = the canonical/maas PROVIDER; 3.6/3.7 = compat range + channel |
| netbox | TWO different servers under one key: upstream apex 4.5.8 (netbox.baldurkeep.com) vs office1 sandbox 4.6.4 -- both correct |
| opnsense | 26.7 measured everywhere claimed; every 26.1 is release-notes citation / trap provenance / token-free-noted history |
| tofu | 1.12.4 measured (single claim site, CURRENT-STATE); 1.6.0 = required_version floor; 0.9.8 = provider (misattributed); 1.12.3 = dated history in a runbook execution banner + the finding doc |
| stage-2 / stage-4 | Keying artifacts: lines mentioning "Stage N" plus a token about something else (a closed sub-question, vr1-dc1's HELD) |

Mechanical group-zero is unreachable BY CONSTRUCTION while the append-only
decision register is a counted surface and the status authority must quote
capture evidence -- both properties are ruled (GA-R3, GA-R1 r2). The
extractor's keying limits (product attribution, global plan key, stage-N
line-keying) are documented false-positive classes (GA-F12 adjudication,
Batch 2). VERDICT: criterion MET as stated (zero contradictory pairs);
group-count floor recorded for future re-runs: 9 (2026-07-19 baseline).
Also fixed while running: docs/stage3-review-base.patch had been missed in
the Batch-4 disposition -- archived.

## 2. docs/ working set at the GA-R2 target

`ls docs/*.md | wc -l` = 16 (< 25; archives + dated captures excluded per
D2). History preserved: all moves were `git mv`; four stage records under
docs/archive/stage-records/ manifest every consolidated source.

## 3. Fresh probe trio -- RUN 2026-07-19 (operator: "Approved, continue")

Three independent clean-context agents (no session history, no shared
scratchpad, no auto-memory -- fresh subagent contexts satisfy GA-R7/G2 by
construction, matching the Phase-3 method), repo + the verbatim charter
question set only, read-only. Scored against CURRENT-STATE.md with
load-bearing citations spot-verified against the tree (opentofu-validate
:189 PASS line; platform-traps :142 bounce; site-baseleg header; phase2
runbook :572 scope stop; the GA-F14 banner commit hash `4170237` -- which
probe B got RIGHT by reading git).

| Q | A | B | C | Verdict |
|---|---|---|---|---|
| 1 stage + next action | PASS | PASS | PASS | unanimous: Stage 3/Phase 2, G9 BLOCKED, next = Batch-6 items 3+6 (two probes recognized themselves as item 3) |
| 2 applied vs authored 3+3 | PASS | PASS | PASS | all from state/measurement citations |
| 3 open gates + closers | PASS | PASS | PASS | all reproduced the open set (G3/G8/G9/G10/G12-G15) with closers + owners; all knew G1/G2/G4-G7/G11 closed |
| 4 pre-apply + required output | PASS | PASS | PASS | unanimous: opentofu-validate PASS line + fresh capture MUST equal 6/0/6 (STOP otherwise) + run-logged.sh |
| 5 three most dangerous traps | PASS | PASS | PASS | in-place bounce + no-cpu/svm near-unanimous; third pick varied (KiB memory / baseleg reboot-stranding) -- all real, all cited |
| 6 D-NNN authority + changelogs | PASS | PASS | PASS | unanimous: Status line ONLY, GA-R5 utterance requirement, changelogs never citable (GA-F14) |
| 7 DC0 entry doc | PASS | PASS | PASS | unanimous: runbooks/dc-dc-phase2-tofu-dc-substrate.md via the G9 row; all three flagged "redeploy" as a first deploy; correct not-without-leaving-the-repo verdict (gates, out-of-repo creds/tfvars/image) |

**Score: 21/21. Exit bar (7/7 on at least two of three; no question failed
by all three) EXCEEDED -- 7/7 on all three.** Notable vs the Phase-3
baseline: zero orientation divergence remained (all three landed
CURRENT-STATE-first via the swept skill); probe hole H1 did not recur (the
G9 canonical-entry row + demoted readiness banner worked). PASS.

## 4. Captured outer plan == the section-5 recorded triple

`docs/audit/outer-plan-20260719-phase6-exit.txt`: "Plan: 6 to add, 0 to
change, 6 to destroy." == section 5's recorded 6/0/6 EXACTLY. PASS.

## 5. (S2) SEC-gate confirmation before G9 is declared open

G9's gate row now NAMES the SEC-010 pre-apply dependency (applied+verified
at deploy step B via `site-headend-install.sh --host-nodes --check` on
vvr1-dc0, gate G10) and records it as the only SEC row gated on this apply
(scan cross-check: the other 7 OPEN rows are v1-close/external
obligations). PASS.

## 6. Operator re-read + re-signature -- OPERATOR-EXECUTED (pending)

CURRENT-STATE.md top to bottom; the new signature REPLACES section 11
(GA-R1 rule 7). After items 3 + 6: the DC0 apply path resumes from G9
(which also still requires G8's same-session plane re-verify inside the
apply session itself).
