Record archive recovery lifecycle and validate receipt provenance
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-06 14:53:15 +02:00
parent 445f1361dc
commit a867ec269a
9 changed files with 203 additions and 11 deletions

View file

@ -106,3 +106,10 @@ live expiration or cron cutover performed. T04 remains in progress for durable
scheduled caller/dependency binding, canonical verified inventory, fresh quota
checks and owner retention activation. See
`history/2026-09-06-backup-tiers-implementation.md`.
Receipt follow-up, September 6: new archive transfer/decryption/restore runs now
record operation timestamps and provenance receipt hashes. Cleanup failure cannot
leave a successful restore status. Historical primary decryption receipts remain
accepted explicitly, while new decryption retains its own schema. No repeat
upload, expiry or scheduled caller change was made; T04 remains in progress for
the existing durable caller, inventory, quota and retention gates.