5. Produce and test an actual runtime
The service has an old serving pool, a separate two-instance candidate pool and an operator interface that can install an identified package, set configuration, start a process and read back actual runtime state. Its data use is the compatible state above. A release holder permits isolated deployment and a synthetic address write/read test, not general user exposure.
SYSE.41 constructs the procedure: preserve ordinary routing on observed h1/c1; prepare the candidate resources and connections; install verified h2 with c2; query what actually runs on each target; and exercise the permitted write/read test under the data correspondence.
In the normal constructed history, both candidate instances run h2/c2, their dependency is accessible and the bounded test succeeds. SYSE.11 can assess usability for that test use.
In the partial history, one instance reports h2/c2 while the second request times out. Readback finds h2 with c1 and a failing database connection. Keep ordinary service on the old pool, exclude the unqualified candidate, and reconcile the second instance to c2 or remove it from the candidate result. Unknown readback remains unknown, not “nothing changed.”
Repeat no data migration blindly. A return to h1/c1 is available only because the old data contract remains valid and the runtime restoration test succeeds. Wider release requires the release holder’s decision.