{
  "authorized_keys_mutated": false,
  "automatic_watcher_detection_expected": true,
  "bundle_revision": "R11_NFT_EXACT_ENDPOINT_DROP_AND_NATURAL_RECOVERY",
  "classification": "runtime_proof",
  "controlled_failure_configuration_mutation": false,
  "controlled_failure_interface": "vpn2",
  "controlled_failure_interface_restart": false,
  "controlled_failure_method": "nft_output_drop_exact_endpoint",
  "controlled_failure_selector": "cs5",
  "controlled_failure_slot": "egress2",
  "controlled_failure_tunnel_ip": "10.253.1.14",
  "direct_failopen_allowed": false,
  "endpoint_restore_policy": "delete_temporary_nft_drop_then_prove_receive_growth_and_strict_egress_on_unchanged_running_vpn2",
  "expected_installer_sha256": "46e673bda61eeb3439a13658e10b99692adc234b139181ce62606fb9b7585ab4",
  "functional_stage": "controlled_one_slot_failure_end_to_end",
  "live_slot_failure_injected": true,
  "managed_source_change_expected": true,
  "mutated_machines": [
    "vm100",
    "vm101"
  ],
  "next_step": "R20Q-I_RESTORATION_NO_MASS_RETURN_AND_GRADUAL_REBALANCE",
  "nft_test_rule": "exact_endpoint_udp_output_drop_with_counter",
  "nft_test_table": "inet r20qh_vpn2_failure",
  "private_key_material_exported": false,
  "r03_failure_analysis": "R03 stopped on watcher detection timeout after an unproven asynchronous service restart; R04 proves stop, new process start and one completed prime cycle before endpoint mutation, and emits stage diagnostics on any timeout.",
  "r04_failure_analysis": "R04 proved watcher start and failure detection. Bridge start/confirm repeatedly failed rc 75 because watcher topology sync held the fallback lock and invoked the mapper without its controlled lock-bypass environment, so the mapper attempted to reacquire the same lock and returned STOP_FALLBACK_MAPPER_LOCKED.",
  "r05_failure_analysis": "R05 stopped before live failure injection because the unquoted VM101 heredoc expanded the remote literal $MAPPER_APPLY in the local set -u shell. The inherited ERR trap then finalized the same STOP once in the pipeline subshell and once in the parent shell.",
  "r06_failure_analysis": "R06 proved watcher detection and local bridge activation, but generation 000000000002 remained pending because Dropbear refused the first SSH connection to VM100: host 10.71.100.1 was not in the trusted hosts file.",
  "r07_failure_analysis": "R07 proved watcher detection, local fallback, degraded generation delivery and VM100 evacuation. It stopped during endpoint restoration because the endpoint-only live reapply did not produce the required fresh vpn2 handshake within 90 seconds.",
  "r08_failure_analysis": "R08 stopped before snapshot or mutation because a single lost ICMP packet to 1.1.1.1 was treated as a hard vpn2 failure, despite the live peer, endpoint and table 202 route being present.",
  "r09_failure_analysis": "R09 proved watcher detection, local fallback, degraded generation delivery and VM100 evacuation. It stopped before vpn2 reactivation because vm101-restore-normal.sh queried the anonymous UCI peer section with literal quote characters around $SEC, so the endpoint verification read an invalid UCI path and exited silently.",
  "r10_failure_analysis": "R10 proved a healthy fresh vpn2 before mutation, watcher detection, local fallback, degraded generation delivery and VM100 evacuation. It stopped after restoring the original endpoint because the same remote endpoint returned no UDP traffic after the port-1 mutation sequence; UCI, live endpoint, route and interface were correct, but receive bytes and handshake remained zero.",
  "r11_design": "Use a temporary local nft output drop for only the exact current vpn2 endpoint. Do not change UCI, peer keys, endpoint, listening port or interface state. After degraded proof, delete the test table and prove receive-byte growth plus strict egress on the same running tunnel before clearing the bridge.",
  "runtime_impact": "controlled_vpn2_exact_endpoint_output_drop_generations_000000000002_and_000000000003_acked_vm100_selector_evacuated_vpn2_natural_recovery_proven_allocator_paused_for_r20qi",
  "snapshot_names": [
    "r20qh100-pre-e2e",
    "r20qh101-pre-e2e"
  ],
  "source_of_truth": "machine_git",
  "step_id": "STEP_050M07R20QH_CONTROLLED_ONE_SLOT_FAILURE_END_TO_END",
  "target_egress_preflight_policy": "three_packets_to_1_1_1_1_then_three_packets_to_8_8_8_8_require_either_target_and_absent_r20qh_test_table",
  "target_egress_preflight_proof_expected": true,
  "target_package_sha256": "9c29b8eaa744f29801d0e12b8c380eb26b57bdf7c008f54c90cf3cf14c1ede31",
  "title": "Prove controlled one-slot bridge-first continuity with exact endpoint nft drop and configuration-free natural vpn2 recovery",
  "topology_transport_hostkey_policy": "single_dropbear_y_accept_unknown_reject_mismatch",
  "vm100_baseline_commit": "8746d2803c61070f4c8e04f89b993a8d9725206c",
  "vm100_baseline_file_count": 27,
  "vm100_baseline_tree": "0dc733135177b75065497437e270777019c5337d",
  "vm100_public_url": "https://reports.secret-studio.ru/latest/20260726-191301_vm100_git_source_8746d2803c61/",
  "vm100_selector_source_update_expected": true,
  "vm101_baseline_commit": "567413db2a9ba33e1d25cd4812af2c92e0f5378f",
  "vm101_baseline_file_count": 48,
  "vm101_baseline_tree": "d352213e2943081e83d5b73bde529ce3d99d155c",
  "vm101_changed_paths": [
    "usr/local/sbin/router-wgpay-topology-transport.sh",
    "usr/local/sbin/router-wgpay-watcher-topology-sync.sh"
  ],
  "vm101_public_url": "https://reports.secret-studio.ru/latest/20260727-054606_vm101_git_source_567413db2a9b/",
  "vm101_source_change_expected": true,
  "vm101_topology_transport_sha256": "afd01c4d0d00cd8281330ac073a25f995ef1923d2bb28662e2ce0d67385f1c39",
  "vm101_watcher_sync_sha256": "4c884dcf90cbfa03d46445a7451379d86ae5cb915ccf6e963b0ad85fb006e142"
}
