# v0.8.0-beta.22 Release Notes

## Pre-Push Final Observer Procedure

This document records the `0.8.0-beta.22` Consumer Authority Beta
procedure-only source candidate. It makes no npm publication, tag, dist-tag
movement, GitHub release, original signed consumer artifact, promotion, Finish
authority, or issue closure claim.

`0.8.0-beta.21` is non-reusable temporal final-observer evidence. Its online
crypto and identity bindings passed only after the leaf certificate window
expired, so authenticated fetch, Finish consumption, and replay were not run.
That timing result is not a product defect and must not be retried.

Beta22 changes no product fetch, authority, Finish, transport, workflow, or CI
behavior. It binds the coordinator-governed immutable future final-observer
procedure record by SHA-256
`8b2537fa1ca4e8209790a3c9539666abbb0a5ffda13d6a82cb9e5c7e2635b863`.
No local absolute path is a source of truth.

The package-visible
[`consumer-authority-beta22-acceptance.json`](consumer-authority-beta22-acceptance.json)
record binds the procedure to the existing release and observer boundaries.

## Required Procedure

Use one exact Git-backed fixture clone and one isolated consumer HOME/store.
Complete source-bound bootstrap before the final fixture commit. The final
commit may contain only the immutable reusable workflow pin and declared
source-bound bootstrap outputs. Retain that same unpushed final fixture commit
as the installed consumer CWD/HEAD.

After that commit, slow preparation may modify only excluded runtime or build
state: the bootstrap-local `.persona/.ph-init-manifest.json`, `.persona/evidence`,
`.persona/workflow`, `.gradle`, `build`, and `node_modules`. It may not alter
the pin, source-bound bootstrap files, project source, root Gradle descriptors,
or the Git identity. Immediately before the one normal push, require the remote
parent, CWD, Git top-level, HEAD, and source identity to remain bound to that
final commit.

Before enrollment, live artifact work, or fetch, run public strict bootstrap,
the accepted plan/current loops, Gradle test/compileJava/clean,
README/profile/Java evidence reads, public implementation/review report ingress,
and plan status. A default Finish must then block only on
`trusted-authority-required`. Only that unchanged consumer may enroll, fetch
the one current artifact, recheck trusted/unconsumed status and explain with no
readiness blocker, consume Finish once, and check immediate replay rejection.
After fetch, do not bootstrap, reset/copy lifecycle state, change CWD/HEAD/
source/profile, replace HOME/store, or switch consumers. A prefetch failure
requires abandoning and recreating the consumer before any live fetch.

## Required Live Evidence

After protected integration and current-package installation, the sole hosted
residual is one separately authorized normal push of the prearmed final fixture
commit. The observer immediately performs original-artifact transport, online
verification inside the leaf window, authenticated fetch, one Finish consumption,
and replay rejection in that same unchanged consumer. It does not substitute
local modeled evidence for live crypto or authority.
