# /hold-pack/ — public replay kit for the FleetOpus HOLD pack

This directory is the public, static copy of the frozen HOLD-pack slice
published at `https://fleetopus.com/hold-pack/`. It lets any second operator —
with only Python 3 stdlib and network access — re-derive the verifier's
verdict from the same frozen bytes the publisher used. That is the charter's
Proof-1 done-test; this kit exists to make it runnable by strangers.

## What is here

| File | Role |
|---|---|
| `freeze-pack-artifact.json` | The frozen HOLD pack (61 evidence entries). Content hash pinned in the verifier contract. |
| `replayable_verifier.py` | The canonical verifier. Pure function: no clock, no network, no env, no randomness; loud-fails on structural violations. |
| `MANIFEST.json` | Freeze manifest: path, role, SHA-256, size for all 10 frozen files. |
| `MANIFEST.sha256` | Self-hash of MANIFEST.json. |
| `PACK_ROOT.sha256` | Content-rooted pack root over the frozen directory. |
| `FREEZE_RECEIPT.json` | Freeze receipt: every source path it was copied from. |
| `conductor-disposition.json` | Conductor disposition: FREEZE-OK (HOLD slice, not a PASS). |
| `deterministic-reproducibility-verification.json` | Independent reproducibility verification report. |
| `replay-identity-receipt.json` | HMAC-signed two-replay identity receipt for the verifier output. |
| `verification-result.json` | The verifier's canonical output over this pack (what /replayable-hold renders). |
| `evidence/*.json` | The evidence fragments: Hermes run/session, SpriteFactory lineage, RoutePlane window entries, MeshFleet absence proof, prepush absence proof. |

## Replay

```
curl -O https://fleetopus.com/hold-pack/replayable_verifier.py
curl -O https://fleetopus.com/hold-pack/freeze-pack-artifact.json
curl -O https://fleetopus.com/hold-pack/verification-result.json
python3 replayable_verifier.py freeze-pack-artifact.json | diff - verification-result.json
```

Expected: no diff (byte-identical), exit 0 from the verifier. The verifier
imports only `hashlib`, `json`, `sys`, `typing` — no third-party packages.

## Provenance chain (summary)

- Fleet run subject: Hermes card `t_0571a99c`, run 1009, session
  `20260825_000936_880071`.
- Evidence sources frozen by kanban task `t_c578f2d6` (conductor disposition:
  FREEZE-OK); pack_hash `sha256:3ea63a1c791f9259780baf0600ab7a07c97ea6b1cfc1c1973ee72712accf70b9`.
- Deterministic verifier built by kanban task `t_18a03960`; two-replay identity
  receipt signed over that pack_hash. Charter:
  `docs/ops/REPLAYABLE-VERIFIER-SPEC.md` (in the site repo).
- Rejection fixture (`t_3b8495a6`) and hostile review (`t_61d97102`,
  HOLD-CONFIRMED) are separate kanban artifacts and are not republished here.
- Expected verdict: **HOLD** (baseline) with `conditional` assurance ceiling.
  The verifier refuses any upgrade without an `authenticated-evidence` class
  and refuses time-window attribution by construction.

## Integrity expectations

- **Pack Root (`PACK_ROOT.sha256`)**:
  Computed as the SHA-256 digest over formatted string tuples (`path\tsha256:hex\tsize\n`) of the 10 frozen evidence pack files in canonical manifest order. It cryptographically binds the set of evidence files and their contents, independent of manifest formatting or serialization:
  `sha256:c1794eee4cce33db2dd11be0ffec867cb83b942ded68bd20558dcf9e200deb5f`
- **Freeze Manifest Hash (`MANIFEST.sha256`)**:
  The SHA-256 byte digest of `MANIFEST.json` itself:
  `sha256:c9b52b1e5c21dd02016dc5536f632143e5f5889c1e567cdee8bfe8b0c60ce679`
- **Freeze Receipt (`FREEZE_RECEIPT.json`)**:
  Records source paths and lineage for every frozen file; references both `MANIFEST.sha256` and `PACK_ROOT.sha256`.
- **Replay Verification**:
  `verification-result.json` must equal the verifier's output over `freeze-pack-artifact.json`, byte for byte. Any divergence is a tamper alarm.
- **Repository Test Suites**:
  The public kit provides `replayable_verifier.py` for stdlib verification. Comprehensive charter compliance (`tests/test_replayable_verifier_charter.py`, 33 tests) and multi-seed determinism tests across 6 `PYTHONHASHSEED` configurations (`tests/test_replayable_verifier.py`, 72 assertions) are maintained and verifiable in the site repository.
- The 10 frozen evidence pack files and canonical manifests (`MANIFEST.json`, `MANIFEST.sha256`, `PACK_ROOT.sha256`)
  are byte-identical publication copies from the site repo's `data/hold-pack-frozen/` and must never be edited.
  The verification toolkit (`replayable_verifier.py`, `freeze-pack-artifact.json`, `verification-result.json`)
  and documentation (`FREEZE_README.md`, `FREEZE_RECEIPT.json`) are maintained alongside them in this public kit
  to enable standalone, hermetic replay verification.
