Activation method: immutable staged generation validation; Proxmox pre-snapshot without VM stop; global activation/local-repair locks; complete temporary UCI network build; atomic persistent network replacement; sequential vpn1..vpn5 restart; endpoint, strict ping, route and rule verification; active symlink and repair counter reset only after five-slot proof. Rollback boundary: before TARGET_CORE PASS every runtime mutation triggers all-five-slot rollback. State/source rollback is committed only after the previous runtime is independently proven restored; otherwise recovery code is retained and the STEP stops with TARGET_ROLLBACK_OK=false. After TARGET_CORE PASS later Machine Git/publication errors STOP without automatic runtime rollback. Snapshot is an additional manual safety point and is never automatically restored by this STEP. DIRECT_FAILOPEN_ENABLED=false.