Oracle review found 3 gaps. All fixed: 1. Recipe #TODO updated from 'Always-permit stub' to 'Real UID-based policy' 2. init.d/20_polkit.service created 3. redbear-full.toml already has 14_redbear-polkit via [[files]] — verified