The retrieval-readiness runtime and its paid release proof now resolve to the same immutable source.
- No rewritten history: the unpublishable paid V5.0.1 tag remains intact, while V5.0.2 advances every active release surface.
- Source-bound distribution: paid packaging requires a fresh private manifest, eval ledger, proof commit, and exact release provenance before artifacts can exist.
- Fail-closed lanes: private launch evidence is required in private source and explicitly omitted from paid distribution; partial projections are rejected.