# v0.8.0-beta.27 Release Notes

## Hermetic Observer Contract

This package-visible procedure and contract candidate advances the Consumer
Authority Beta acceptance record to `0.8.0-beta.27`. It changes no Persona
Harness authority, Fetch, Finish, artifact transport, workflow runtime,
registry channel, tag, release, or fixture behavior.

`0.8.0-beta.26` is terminal, non-reusable procedure evidence. Its protected
Ubuntu Verify read the normal GitHub CLI package record, which includes the
regular non-executable bash-completion sibling named `gh`, but counted all
basename matches before lstat qualification. That deterministic selector defect
blocked before tool assessment, private copy, package exercise, or authority
work.

`0.8.0-beta.25` is likewise terminal, non-reusable procedure evidence. It
precedes the workflow-owned observer-tool selection boundary and establishes no
current package, authority, Finish, or final-observer acceptance claim.

The package-visible
[`consumer-authority-beta27-acceptance.json`](consumer-authority-beta27-acceptance.json)
binds reviewed V4 procedure record SHA-256
`5389c027b21f72f325a5d9e467ecd4d150f672e14da1d04f51774602a284c57d`.
No local absolute record path is a source of truth.

## Explicit Tool And Cleanliness Rules

Each CI, publish, and release package-contract job reads the runner-owned
Ubuntu `gh` package record, lstat-checks every basename-`gh` entry without
following links, and selects exactly one absolute regular non-symlink executable.
It ignores only the documented regular non-executable
`/usr/share/bash-completion/completions/gh` ancillary record; missing, malformed,
symlinked, nonregular, unexpected ancillary, or ambiguous executable records
block. The selected tool is copied into a private runner directory and
only that copy reaches source-built, fresh-tar, supplied-bundle, and
grammar-preflight paths. Its bounded direct `--version` result must be
compatible with `>=2.96.0 <3.0.0`. No shell, PATH lookup, literal runner path,
download/install, credential fallback, or artifact invocation is permitted.

The source child returns only one allowlisted stage code to the authoritative
bundle parent: tool-invalid, tool-unavailable, tool-version-unsupported,
parser-rejected, or non-tool-stage. No raw executable path, stderr, token, or
artifact input is rendered into the package contract.

The V4 final-observer procedure retains host-state isolation: all fifteen
external host-state roots stay outside the consumer realpath under `env -i` and
explicit tool requirements.
At baseline, source-bound preparation, credential handoff, observer child, and
immediately before push, it compares NUL-safe untracked and ignored Git status
with the stage-specific normalized `git clean -ndx` projection. Only the
reviewed runtime/build residues may exist. `.local`, `.config`, `.cache`, a
tracked modification, an unexpected residue, or an alias/replacement remains a
fail-closed block. Linux may add only `UV_USE_IO_URING=0` to the existing fixed
authority-fetch child environment; any other extra key or value remains
blocked.

## Deterministic Boundary And Residual

The source-built and fresh packed-installed contracts use the same qualified
workflow-selected observer-gh validation, V4 evaluator, no-token grammar
preflight, fixed child diagnostics, package root binding, and no-source-fallback checks. They preserve
the public Java/Spring readiness route, privacy constraints, modeled
trusted/unconsumed authority, one Finish consumption, and replay block without
accessing a live artifact.

After normal gates, the sole remaining action is one separately authorized V4
fixture commit and normal push. The already prepared same consumer must then
immediately acquire and verify current original bytes online before the leaf
certificate `notAfter`, fetch once, consume Finish once, and prove immediate
replay rejection. It must not reset, reinitialize, switch consumers, change
CWD/HEAD/source/profile, or replace its isolated home/store after fetch.
