railiance-platform/history/2026-09-06-archive-receipt-review.md
codex a867ec269a
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record archive recovery lifecycle and validate receipt provenance
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-06 14:53:15 +02:00

35 lines
2.1 KiB
Markdown

# Repository review and archive receipt repair — 2026-09-06
The checkout was clean at 445f136. Inbox was empty. Source still has seven open
plans: WP-0038 active and six blocked on the explicit gates reviewed in
`2026-09-06-blocked-workplan-progress.md`. The dated generated brief includes
retired aliases; it is not evidence of additional actionable work.
Selected local work under WP-0036-T03 / WP-0038-T04 supports INTENT's tested,
observable recovery requirement. Review found three concrete defects:
1. Archive transfer and restore producers omitted operation times, preventing
reliable freshness checks. All four producers now record UTC start and
terminal finish times, including failed operations.
2. Primary decryption copied the whole transfer receipt over its own schema.
It now copies only needed provenance fields and keeps its own schema/times.
3. Failed scratch cleanup could return nonzero while retaining a successful
restore status. The receipt now records failure as well.
Restore/decryption bind the exact input receipt bytes by SHA-256. Restore
requires recognized provider receipt schemas, verified decryption/download
claims and matching plaintext hash before running Docker. Both the historical
primary schema and the corrected decryption schema remain supported. These
hashes bind local evidence; they are not signatures or independent attestations.
Validation: 31 tests passed across receipt lifecycle, offsite boundaries,
backup tiers, native recovery adapters and archive integrity. Tests exercise
failed validation before credentials/Docker, terminal timestamps, cleanup
failure, provenance mismatch, schema preservation, primary legacy/new receipts,
and both archive profiles. No live backup, credential retrieval, cleanup of
existing backups or scheduler mutation was required.
Remaining: historical receipts are not backdated, and no fresh end-to-end
archive proof was claimed. Automatic archive evidence adapters and durable
scheduled delivery/retention remain open. All existing whole-plan statuses
remain accurate; this implementation does not satisfy external approval gates.