R20K R01 did not reach candidate testing because its fixed two-second service-stop proof was too strict. R20K R02 uses bounded procd polling and exact PID evidence. The diagnostic mutates only the technical vpn_test UCI/runtime definition and temporary host routes to three probe IPs. It does not inject a failure into vpn1..vpn5 and does not call production LOCAL_REPAIR or full refresh. PrivateKey and complete provider config contents are never copied into public artifacts. Only config paths, hashes and same/different field booleans are published. A successful full_config test proves the candidate tunnel works with its own binding; it does not by itself implement the production repair.