# v0.8.0-beta.33 Release Notes

## Hermetic Observer Contract

This package-visible procedure and contract candidate advances the Consumer
Authority Beta acceptance record to `0.8.0-beta.33`. It retains the beta32
current-package and fixture-closure boundary, then replaces its live invalid-
bundle parser probe with a parser-only command help preflight. It changes no Persona
Harness authority, Fetch, Finish, artifact transport, workflow runtime,
registry channel, tag, release, or fixture behavior.

`0.8.0-beta.32` is terminal, non-reusable protected-Verify evidence. Its
authoritative source contract reached the external-attestation preflight, but
the invalid-bundle invocation entered GitHub CLI network and Sigstore setup
before bundle parsing, so its local timeout could not prove parser grammar.
`0.8.0-beta.31` remains earlier terminal, non-reusable package-contract
evidence. `0.8.0-beta.30` is earlier terminal, non-reusable procedure evidence. Its exact
primary `/usr/bin/gh` selection reached the documented completion sibling, but
classified that never-executed file as a competing executable solely because
the runner image gave it an execute bit. This package accepts only that known
completion when it is a no-follow regular non-symlink file, irrespective of
mode. Its absence stays inert; every other secondary `gh` record remains
fail-closed.

`0.8.0-beta.25` is likewise terminal, non-reusable procedure evidence. It
precedes the workflow-owned observer-tool selection boundary and establishes no
current package, authority, Finish, or final-observer acceptance claim.

The package-visible
[`consumer-authority-beta33-acceptance.json`](consumer-authority-beta33-acceptance.json)
binds reviewed V4 procedure record SHA-256
`5389c027b21f72f325a5d9e467ecd4d150f672e14da1d04f51774602a284c57d`.
No local absolute record path is a source of truth.

## Explicit Tool And Cleanliness Rules

Each CI, publish, and release package-contract job first uses the fixed
`/usr/bin/dpkg-query` path to require installed `gh` status `ii` and the current
supported architecture. It then parses the package record as a bounded Buffer:
valid UTF-8, LF-only with at most one final LF, and no NUL, CR, blank, duplicate,
nonabsolute, or noncanonical record. It requires exactly the policy primary
`/usr/bin/gh` as a no-follow regular non-symlink executable. The documented
completion sibling `/usr/share/bash-completion/completions/gh` is optional: its
absence is not a tool-selection input, and when present it must be a no-follow
regular non-symlink file but is never selected, copied, executed, or resolved
through `PATH`. Every other present secondary basename-`gh` record must still
be a no-follow regular non-symlink non-executable file; a listed-missing,
symlink, nonregular, alias, or executable secondary record blocks. The selected tool is copied into a
private runner directory and only that copy reaches source-built, fresh-tar,
supplied-bundle, and grammar-preflight paths. Its bounded direct `--version`
result must be compatible with `>=2.96.0 <3.0.0`. No shell, PATH lookup,
literal runner path, download/install, credential fallback, or artifact
invocation is permitted.

Each direct version assessment and parser-only help preflight run with the same
explicit token-free state environment rooted in the validated runner temporary
directory. `HOME`, `gh`, XDG, temporary, Git, and npm state variables never
inherit the package-contract checkout, so neither `gh --version` nor
`gh attestation verify <placeholder> <exact-plan> --help` can create
consumer-local `.local`, `.config`, or `.cache` state. The placeholder is fixed
and never materialized; the help invocation carries the rendered canonical plan
flags, has no artifact or network input, and has its own short parser bound.

The workflow selector produces one fixed nonreflective stage for environment,
package-list, package-record, source-assessment, private-reservation,
private-copy, private-assessment, or output-handoff; an unexpected internal
failure is `selector-internal`. Package-record blocks additionally carry only
one of `record-encoding`, `record-path`, `primary-missing`, `primary-unsafe`,
`ancillary-unsafe`, `executable-ambiguous`,
`lstat-failed`, or `canonical`. The source child maps only those allowlisted
stage and shape codes to the authoritative bundle parent. No raw executable
path, package record, stderr, token, URL, or artifact input is rendered into
the package contract.

The authoritative bundle exercise now binds
`clean-package-exercise-phase.1`. The source-built child emits the ordered
source phase vocabulary and the fresh-tar child emits its separate ordered
phase vocabulary from
[`consumer-authority-beta33-acceptance.json`](consumer-authority-beta33-acceptance.json).
Every phase record has only `schemaVersion`, `surface`, `phase`, `state`, and
the fixed bounded code. The ready `authority-discovery` phase must be followed
immediately by one matching-surface
`consumer-authority-discovery-exercise.1` result with
`trusted-unconsumed-persisted`; the clean-bundle parent accepts no other
result or placement. A marker-only, malformed, out-of-order, foreign, or
success-after-blocked transcript becomes a bounded phase-envelope block.
No raw child stdout or stderr, path, token, URL, or artifact content is
reflected.

The V4 final-observer procedure retains host-state isolation: all fifteen
external host-state roots stay outside the consumer realpath under `env -i` and
explicit tool requirements.
At baseline, source-bound preparation, credential handoff, observer child, and
immediately before push, it compares NUL-safe untracked and ignored Git status
with the stage-specific normalized `git clean -ndx` projection. Only the
reviewed runtime/build residues may exist. `.local`, `.config`, `.cache`, a
tracked modification, an unexpected residue, or an alias/replacement remains a
fail-closed block. Linux may add only `UV_USE_IO_URING=0` to the existing fixed
authority-fetch child environment; any other extra key or value remains
blocked.

## Deterministic Boundary And Residual

The source-built and fresh packed-installed contracts use the same primary,
mode-independent known-completion, and strict-secondary qualified
workflow-selected `COPYFILE_EXCL` observer-gh lifecycle, private-copy
reassessment, fixed-placeholder help preflight, V4 evaluator, no-token grammar
checks, fixed child diagnostics, package root binding, and no-source-fallback checks. They preserve
the public Java/Spring readiness route, privacy constraints, modeled
trusted/unconsumed authority, one Finish consumption, and replay block without
accessing a live artifact.

Current package authority is dynamic but strict: the live package metadata,
lock metadata, and beta33 acceptance record must contain one identical version.
Historical beta27 and beta31 records remain fixed historical schemas. The
source verifier stays a Git-bound bundle tool; the fresh installed contract
must load the observer stage and package-record modules from the tarball with
no `src`, `.git`, or verifier fallback.

After normal gates, the sole remaining action is one separately authorized V4
fixture commit and normal push. The already prepared same consumer must then
immediately acquire and verify current original bytes online before the leaf
certificate `notAfter`, fetch once, consume Finish once, and prove immediate
replay rejection. It must not reset, reinitialize, switch consumers, change
CWD/HEAD/source/profile, or replace its isolated home/store after fetch.
