# VM101 methods — R16 transactional activation

R16 validates the immutable staging generation immediately before core. It builds a complete UCI network file off-line, atomically installs it, restarts vpn1..vpn5 sequentially under activation and local-repair locks, and verifies every endpoint, strict probe, table and rule.

The active symlink and repair counter reset occur only after all five slots pass. A single-use authorization bound to the generation manifest is consumed before runtime mutation. Automatic activation remains disabled. Any failure before the PASS boundary restores the previous network, recovery state, repair counter and absence of active generation. The Proxmox snapshot is retained as a manual safety point and is not automatically restored.

Late Machine Git/publication failures after target core PASS do not trigger runtime rollback. Continuation starts at the first incomplete R15D phase.
