=== ROUTER STEP FACTS CONTRACT VALIDATION === step=STEP_048G_HMN_RECOVERY_ADAPTER_DRYRUN_DESIGN decision=STOP all_ok=False structure_ok=True success_ok=False expected_absence_ok=True blockers_ok=True success_checks_count=22 expected_absence_count=0 false_success_checks: - dryrun_candidate_has_source_file - dryrun_candidate_selected - has_unused_hmn_candidates warnings: - Read-only/dry-run design only. - No ifdown/ifup, no uci set, no wg set, no route changes, no tunnel replacement. - Synthetic failure uses egress4/vpn4 only to prove candidate selection and slot stability.