Protect digest-pinned packages and refuse partial-inventory pruning
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
codex 2026-09-27 16:00:51 +02:00
parent 3f834b0556
commit 743def17be
5 changed files with 174 additions and 11 deletions

View file

@ -56,7 +56,7 @@ activating bounded routine promotion. Destructive pruning remains disabled.
```task
id: RPF-WP-0048-T03
status: todo
status: progress
priority: high
state_hub_task_id: "6c2650a2-5da8-5999-a6e7-b22eb7c655f4"
```
@ -86,3 +86,17 @@ starts 2026-09-27T13:38:21Z, earliest eligibility 2026-09-28T13:38:21Z subject t
healthy observation. T02 stays waiting for this window and authenticated narrowly
bound release-identity/rollback proof. Automation and pruning remain disabled.
Authorization decision: 78a4b859-dd00-4623-b95b-121b0e1c915d.
## Digest retention implementation — 2026-09-27
Implemented conservative package-wide protection for live/exported sha256 refs,
including tag@digest and retained rollback references. This avoids unsafe alias
mapping assumptions; storage retention increases for those packages. Malformed
references and incomplete cluster/package inventory refuse apply before deletion.
Sixteen focused tests pass. Live tool installation/readback remains required;
existing baseline aliases continue protecting production in the meantime.
Credential routing inspection found no ready scoped unattended ArgoCD/Forgejo
release lane. ACTIVITY-WP-0041-T03 remains the authority/admission owner; no broad
operator token was copied or delegated. Its concrete executor contract is in
`docs/activity-core-release-admission.md`.