# VM101 M07 canonical change plan

The canonical workspace is based on exact private source copies from
the VM101 raw mirror.

No VM101 connection or production change occurred during this step.

## Current candidate state

The nine managed candidate files are exact copies of their locked
sources. One new common helper library has been added:

    /usr/local/lib/router-egress-vm101-runtime.sh

## Planned canonical replacements

1. Refresh-safe wrapper:
   storage preflight, surgical backup manifest and validated rollback.

2. HMN bootstrap scripts:
   select an actually healthy vpn1-vpn5 interface; table 200 is only
   an optional preferred candidate.

3. Planner:
   read current endpoints from AmneziaWG runtime.

4. Rebalance apply:
   use runtime current values, retry strict health and return nonzero
   for commit failure.

5. Emergency runner:
   require both a successful shell status and valid JSON fields.

6. Slots apply:
   tables 201-205 are authoritative; table 200 is optional.

## Installation policy

The next step will create complete replacement files in the private
canonical workspace. It will not install them.

A later installation step will require:

- live source hashes equal the private source locks;
- syntax checks;
- unified diffs;
- surgical backups;
- atomic replacement;
- automatic rollback;
- post-change strict 5/5 validation.
