Add audit maintenance, verified recovery and reproducible verification

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
tegwick 2026-09-28 11:48:01 +02:00
parent 820f0ff7b5
commit 3166da1d2e
13 changed files with 413 additions and 5 deletions

View file

@ -0,0 +1,23 @@
# Acknowledgment operations closure — 2026-09-28
Existing RTEL-WP-0002-T04, no new task/workplan. Added private Prometheus metrics
for pending/blocked/delivered outbox counts and last completed drain. No event
or actor labels. Database failures in the drain are retried instead of killing
the worker. Idle receiver health is explicitly not inferred from a drain.
Local admin CLI provides counts, bounded blocked-event IDs, explicit requeue and
verified SQLite backup/restore to a new path. No overwrite or public admin API.
Existing acknowledgment/event bytes are preserved by retry and restore.
Full verification command: bash scripts/verify.sh. Hash-locked runtime packages
installed into .venv-verify, native Flex Auth built in .cache/verify. Native owner
checkouts required; missing dependencies fail rather than silently skip tests.
37 core + 8 runtime tests pass. Actual audit-core receiver accepted an event,
lost its response, then deduplicated replay after backup and restore. Snapshot
tests retain all delivery states, repeated confirmation identity and immutable
triggers; unsafe paths and overwrite are refused.
Tested audit-core 3e42ca8ffb2ead14fd52f9a6f9f42800f1dc2771 and Flex Auth
2dfee5782ec9010758af9ba5a6f72d9fa0fe6234. No new live acknowledgment activation;
remaining native identity/PDP/audit, scrape, off-host and recipient gates stay
in the existing blocked workplan. Package image updated separately.