Changes touching this path
- the backup machinery gets its record: ADR 0046 is amended by what building it found, and the drill is run as far as a key can take it (#813)
The build lands in the `scripts` repo (6d31542). This is loot's half: the decision
doc corrected where it was wrong, and the evidence file told what was actually run.
Three amendments, each because building the thing falsified the text.
Section 5's lifecycle rule is PREFIX-SCOPED. Sections 4 and 5 together ask one
bucket for two opposite retentions, and a bucket-wide rule deletes the artifact
section 6 calls genuinely unrecoverable -- silently, a week later.
Section 3's burn record carries the burner and the timestamp, not the oid alone.
burn_tombstone declares two more NOT NULL columns, so an oid on its own cannot be
replayed at all. signed_tombstone stays out because it carries the burned PATH into
a file that is unencrypted and kept forever, and the cost of that -- a replayed
tombstone cannot be the audit record -- is now written down rather than discovered.
Section 2's five replay steps are three today. The blob delete and the CDN purge
belong to a durable job purge.rs says does not exist, and the blob tier is never
restored from backup anyway.
The evidence file gains sections 8.1 through 8.4, run 2026-08-16. The recipient
keypair is minted -- rage rather than the reference age, because age ships only
sigsum proofs nothing here can verify, and the act that mints the key protecting
every backup took the checksummed path. Custody is proved rather than asserted: a
probe round-tripped through the offline key and a freshly minted stranger identity
was refused. Then a runner-shaped artifact -- dump, TOC, row manifest, both
credentials files -- was encrypted, its plaintext deleted, decrypted with the
offline key alone, restored and replayed. The negative first, because it is what
makes the positive mean anything: without the replay all four assertions came back
true, with it all four false, and a second replay moved nothing.
What is still not proved is said plainly. Section 8.5 wants the superuser password
coming back out of a REAL artifact and actually authenticating against the SCRAM
verifier, and the artifact above carried a stand-in because nothing has deployed.
The age-to-rage interop is assumed on the spec and gets proved by the first real
run. Until setup-forge.js has run once, this forge has no backup and
/root/.postgres-credentials has no second copy.
c26f154c · dbf3dbe6…
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.