Collected on affected host as uid 1000 (ubuntu), gid 982 (monolith-runtime), using the existing passwordless sudo rule and runuser. No account membership or service configuration changed.
The unmodified kit failed during warmup because .venv/bin/python points through the cpython-3.12-linux-aarch64-gnu alias, while the collector mounted only the resolved cpython-3.12.13-linux-aarch64-gnu installation.
The adjusted collector adds --python-install-alias, creates the corresponding restore-root directory, and mounts the resolved Python installation at that alias. Exact commands and collector source are included. The original warmup failure is archived separately beside this bundle.
Adjusted run: dump_exit=0, restore_exit=1. restore.log reports: Unable to apply root mount options: Operation not permitted.
This reproduces the reported error but is not a kernel-only comparison: the handoff development baseline uses CRIU 4.1 and bubblewrap 0.9.0; this host uses CRIU 4.2.1 and bubblewrap 0.11.1.
Checkpoint images remain in /tmp/criu-3127-jh0x18rt/workspace/.timbal/criu/images and are excluded from this archive.
Original kit SHA256: 2323336c94699e56ec299d6c1ee996fbb12ff6c8ddaf953ce50a1cdd5d4079f2
