clio-relay 1.4.17
Provider build-identity fix
clio-relay 1.4.17 completes the legacy-provider identity boundary exposed by the exact 1.4.16 Ares upgrade.
- Stages the installed provider's verified embedded build identity beside the candidate overlay so legacy receipt checks retain commit, tag, and clean-tree provenance.
- Keeps the incoming candidate sources and installed provider identity distinct: candidate code plans the upgrade, while the existing provider proves what is currently installed.
- Rejects missing, redirected, malformed, oversized, or changing provider build-identity files rather than weakening receipt matching.
- Adds executable legacy-provider and hostile-path regressions for the rendered bootstrap payload.
Bootstrap still refuses any full reconcile of retained JARVIS state and performs no scheduler cancellation.