# Reference-contract hardening evidence — 2026-08-23 `ZONE-WP-0002` closes the executable gaps without creating a zone-engine runtime. ## Revisions reviewed | Repository | Revision | Role | | --- | --- | --- | | zone-engine | `be29c28` | Reference resolver, profile/exception fixtures, lineage checker, and tests | | net-kingdom | `3491c29` checkout; canonical artifact last changed at `104d5c6` | Canon publication and lifecycle | | repo-manager | `7b9fdaa` | RMGR-ADR-004 v1 workload-reference authority | | flex-auth | `00a7bc4`; profile owner baseline `e521e7b` | Adopted declaration and pre-sign stance | | ops-warden | `c8fa02a`; profile/PEP baseline `7ce58ae` | Adopted declaration, failure modes, and consumer registry | No owner repository was changed by this workplan. ## Canon lineage `make canon-lineage CANON_ROOT=/home/worsch/net-kingdom` passed. Both the reviewed `104d5c6` artifact and current checkout hash to `32e71e9c0d6946bb14099eb66193822da26f199de0e11d8488464207f3bd9906` and report lifecycle `proposed`. A mutation fixture proves content drift fails; a separate fixture proves lifecycle drift fails. The local standard text is no longer a second normative copy. It is a pointer to canon with a machine-readable lineage record. ## Resolved-view replay `fixtures/manifests/adoption.yaml` resolved the two live declarations and one native catalog subject: | Subject | Result | Effective zone | Membership revision | | --- | --- | --- | --- | | flex-auth | `satisfied` | `z1-operational` | `sha256:841d3a251ca9f9fb5eb263b4fd90b557cb06de031ec3be06034c5e011039c16c` | | ops-warden | `satisfied` | `z1-operational` | `sha256:0407d7a90e7f259163a0e1ec0907551a06ad7023a100261b911dcde62899bd5b` | | human-operator | `not-applicable` | none | none | The reference manifest also proves the managed Repo Manager tuple `(rapp-fixture, fixture-workload, fixture-workload)`. Direct and managed bindings, source revisions, guarantees, `unknown`, `unsatisfied`, and `not-applicable` are explicit. Paths, repository ownership, reefs, actors, and lane names cannot manufacture membership. Snapshot tests prove deterministic additions, removals, changes, source revision sensitivity, and order insensitivity. A missing source revision emits no digest and no source-bound guarantee. ## Profile authority Core membership resolution emits no controls. Projection requires `profiles/netkingdom-build-v0.1.yaml`, whose version pins the previously accepted owner revisions. Every row includes policy owner, PEP owner, and policy reference, and the profile is total over all five zones plus `unknown`. Fixtures reject missing coverage, ownerless/unqualified controls, invalid stance/failure combinations, and unversioned profiles. Profile failure leaves the independently resolved membership record intact and marks the overall projection unsuccessful. ## Exception lifecycle The offline checker evaluates only a supplied document, owner policy, and explicit instant. It validates designated grant authority, exact workload and zone scope, maximum duration, exclusive `not_after`, strict relaxation, renewal ids, overlap, wildcard/unknown rejection, and durable-authority expiry. Invalid or unevaluable records are inactive. It stores nothing, grants nothing, reads no live clock, and is absent from every decision path. ## Verification - zone-engine: `make check` — 29 tests passed; reference and exception fixture commands passed, including expected rejection of the overlap fixture. - canon lineage: passed at net-kingdom `104d5c6` and current checkout. - flex-auth: `go test ./...` passed. - ops-warden: 390 tests passed, 4 integration tests deselected; Ruff passed. - net-kingdom tenancy validator: flex-auth and ops-warden declarations valid. - repository whitespace checks passed. ## Outcome The repository is safe to retain as a bounded reference and safe to archive after handoff. The selected non-destructive disposition is retain while canon v0.1 remains proposed, with only owner-driven conformance and lineage changes permitted. No runtime, live policy authority, or estate-migration backlog was created.