v2026.7.19
Corrective publication for 2026.7.18. Knowledge Shard formats, exact
2.0.0/full-v1 evidence, supported platform cells, and consumer revisions are
unchanged.
Fixed
- Persist the Vault-managed mutsu CI public key in a root-owned,
boot-available OpenSSH authorization path. Sidecar publication validates the
pinned key fingerprint and effective sshd configuration so Linux arm64 and
macOS arm64 jobs do not depend on an interactive console login after reboot. - Apply the required free-space and inode guard to both
matric-builderjobs
in the supported-platform workflow. - Run the Linux arm64 contract builder and its isolated PostgreSQL service on
a private Docker network instead of mounting the mutsu Colima daemon socket
into the contract container.