# VM101 autonomous HMN recovery — local M07 plan after R15B2

## Proven state

R15B1 installed the generation schema and strict validator. R15B2 installed the staging-only generation builder and created generation `r15b2-20260716-215914` with exactly five unique tested candidates. R04 closed publication without repeating candidate tests, target core, Machine Git, exact repository refresh or source publication.

## Invariants

- Active generation is absent.
- Exactly one staging generation exists and validates PASS.
- vpn1..vpn5 endpoints and tables 201..205 are unchanged from the R03 baseline.
- No service restart or traffic interruption occurred.
- Quarantined endpoints cannot be selected.
- Partial activation is forbidden.
- Repair counters may reset only after complete activation proof.
- Direct failopen remains forbidden without a separate explicit STEP.

## Required next workflow step

Before R16, fix the VM101 source backend post-publication completion/state contract on VM130. The backend currently can complete commit, clone, archive and atomic publication but return nonzero before final state and HTTP markers. This must be a separate VM130-only STEP with synthetic and real read-only fixtures.

## R16 — transactional full refresh

Build and validate all five slots, apply all-or-nothing, create the active symlink only after every precheck, and rollback the full generation on any failure.

## R17 and R18

Prove degraded-no-fresh-pool, quarantine/counter consolidation and gated bootstrap/direct behavior without implicit direct failopen.
