Finalization is failure-atomic. It operates on a private clone of the complete program, validates every canonical graph and the whole-program thread, launch, channel, memory-root, symbol, and completion relations, constructs canonical bytes, invokes the Common finalizer, and publishes only the complete valid Artifact. There is no `is_finalized` operation attribute or partially finalized program state. A valid Common envelope, exact schema descriptor, canonical bytes, and successful independent family verification together define a finalized Artifact.