# Session-ledger summaries rotated 2026-07-29 (GA-R4 rule 3 / F1)

Moved VERBATIM out of `docs/session-ledger.md` to restore the 300-line cap when the
2026-07-29 close bookend was appended. Oldest-first, per GA-R4 rule 3. Nothing here is
status: `docs/CURRENT-STATE.md` is the only status authority (GA-R1), and each summary
below still points at its own archived full body.

---

## SESSION CLOSE 2026-07-26 -- D-137 build + committee audit + remediation (bounded, GA-R4)

- D-137 was ADOPTED-not-built at open; all THREE tiers now exist plus enforcement (preflight
  P5 blocking). 17 commits `af1b682..1696d08` pushed. Stage 4 stays OPEN; no stage closed.
- Six-lens committee audited the build; FOUR converged on one root cause -- tier 2 keyed
  existence on host-role alone, ignoring site-key, so one site's credential satisfied every
  site, MASKING SEC-021's dc0 on-disk absence. 8 false greens, all reproduced and fixed.
- Owned: ~21 inferred filenames (reported six); systemic sec-ref mis-attribution;
  CURRENT-STATE cited a verdict file for measurements it lacked. 2 claims WITHDRAWN.
- Five operator rulings (GA-R5, quoted on D-137): 12-column schema; tier 1 as blocking P5;
  tier 2 local-blocking + `stages-reached` coupled by new repo-lint L12; tier 3 probe
  boundary; SEC-024 chmod. Ruling 4 (SEC-009 -> pointer) executed.
- SEC-024 opened then remediated (mode), severity corrected first. SEC 19 -> 20. Ledger
  rotated twice (GA-R4 F1). Gauntlet 79 -> 81 GREEN; repo-lint 0-fail.
- NEXT: live mission has NOT moved -- resume the DC1 Stage-5 chain per CURRENT-STATE.
  Unbuilt/unruled advice: `creds-mint.sh` BEFORE Stage 5 (largest minting event).
- Full body: `docs/archive/session-20260726-d137-build.md`. Status ONLY in CURRENT-STATE.md.

## SESSION CLOSE 2026-07-27 -- creds consolidation + STAGE 4 CLOSE-OUT (bounded, GA-R4)

- Opened on a creds question; ended closing Stage 4. **STAGE 4 IS CLOSED AND MERGED** --
  operator-gated merge commit `6f5701d` on `main` (2 parents, not squashed, 77 commits),
  branch retired local + remote, post-merge gauntlet ALL GREEN (81) + repo-lint 0-fail on
  `main`, close recorded in CURRENT-STATE by `1023596`. Next stage branches off `main`.
- Creds: dc0 SEC-012 power key consolidated + `.pub` derived (SEC-021(b) as written -- measured
  first: it IS the dedicated key, and dc0 using the snap default is SEC-016's ruled design, so
  NO re-mint); NetBox GUI admin password consolidated (**SEC-025**, rows 20->21); dc1 svc `.pub`
  backfilled. Findings 13 -> 7. MAAS account set verified COMPLETE by enumeration.
- V2 taught the ruled-deferral state -- reissuing SEC-006's token would have CONTRAVENED a
  standing 2026-07-13 ruling; the register was what needed changing. `--ledger` added; V2 had
  shipped with ZERO harness cases.
- **Two false greens fixed, both in controls that had passed for days:** `dc-mirror.sh check`
  asserted last-sync EXISTED (dc0 `FAIL`, dc1 4-day-stale `RUNNING` both read OK); and
  `creds-audit` CLEAN x3 alongside 13 matrix findings. Lesson repo-carried in the skill.
- Rulings (GA-R5, all quoted): **G17** opened (node-side reachability split out -- powered-off
  nodes cannot be probed); SEC-024 retention "Keep both"; set-interface-v4 reload "a"; D-135
  AMENDED (dc0 tests full mirror / dc1 tests proxy -- dc1's 330G mirror REMOVED, not paused).
- DOCFIX-204: DoD bullet 6 was UNSATISFIABLE (D-129(iv) had ruled the opposite); 4 surfaces.
  Carve residue: 108 fabrics -> 17, cascade-checked. dc1 nginx purged.
- OWNED: first draft of the pf reload sat inside the reconfigure heredoc -- would have fixed
  nothing in the very drop case that caused the bug. Caught pre-ship.
- **FINDING for the next session (logged, not actioned):** `tests/creds-matrix` T24's
  finding-class baseline (`expected-findings.txt`) covers **TIER 1 ONLY** -- tier-2/3 classes
  (E1/E3/E4/V1/V2) have NO baselined red state, so a future false green there would not turn
  the gauntlet red. Same class as the two false greens this session fixed. Also still open from
  the D-137 close: `creds-mint.sh` is unbuilt/unruled advice and Stage 5 is the largest minting
  event, so it is worth ruling BEFORE the bundle deploy rather than after.
- POST-CLOSE DURABILITY SWEEP (operator-requested): 4 transcript-only items landed on surfaces
  -- worst was `dc-mirror.sh`'s dc1 row carrying NO warning that dc1 is proxy-only, so
  `install dc1` would silently rebuild the removed apparatus + enabled timer + ~950G pull.
  Also: a WRONG causal claim in the mirror-gate capture superseded by appended correction
  (reset-failed cannot re-arm an inactive timer; the vector was a REBOOT via Persistent=yes);
  platform-traps section 5 added; the two-net-units coexistence claim marked REASONED-NOT-
  MEASURED. Capture `docs/audit/queued-findings-20260727.txt`. QUEUED: a runtime install
  guard for a non-mirror site (a comment is strictly weaker and prose-only prevention has
  already failed twice here).
- Gauntlet ALL GREEN (81), repo-lint 0-fail. Full body: `docs/archive/changelogs/changelog-20260727-creds-consolidation.md`;
  stage record `docs/archive/stage-records/vr1-stage4-record.md`. Status ONLY in CURRENT-STATE.md.

