Changes touching this path

  • the backup machinery gets its record: ADR 0046 is amended by what building it found, and the drill is run as far as a key can take it (#813) The build lands in the `scripts` repo (6d31542). This is loot's half: the decision doc corrected where it was wrong, and the evidence file told what was actually run. Three amendments, each because building the thing falsified the text. Section 5's lifecycle rule is PREFIX-SCOPED. Sections 4 and 5 together ask one bucket for two opposite retentions, and a bucket-wide rule deletes the artifact section 6 calls genuinely unrecoverable -- silently, a week later. Section 3's burn record carries the burner and the timestamp, not the oid alone. burn_tombstone declares two more NOT NULL columns, so an oid on its own cannot be replayed at all. signed_tombstone stays out because it carries the burned PATH into a file that is unencrypted and kept forever, and the cost of that -- a replayed tombstone cannot be the audit record -- is now written down rather than discovered. Section 2's five replay steps are three today. The blob delete and the CDN purge belong to a durable job purge.rs says does not exist, and the blob tier is never restored from backup anyway. The evidence file gains sections 8.1 through 8.4, run 2026-08-16. The recipient keypair is minted -- rage rather than the reference age, because age ships only sigsum proofs nothing here can verify, and the act that mints the key protecting every backup took the checksummed path. Custody is proved rather than asserted: a probe round-tripped through the offline key and a freshly minted stranger identity was refused. Then a runner-shaped artifact -- dump, TOC, row manifest, both credentials files -- was encrypted, its plaintext deleted, decrypted with the offline key alone, restored and replayed. The negative first, because it is what makes the positive mean anything: without the replay all four assertions came back true, with it all four false, and a second replay moved nothing. What is still not proved is said plainly. Section 8.5 wants the superuser password coming back out of a REAL artifact and actually authenticating against the SCRAM verifier, and the artifact above carried a stand-in because nothing has deployed. The age-to-rage interop is assumed on the spec and gets proved by the first real run. Until setup-forge.js has run once, this forge has no backup and /root/.postgres-credentials has no second copy. c26f154c · dbf3dbe6…

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.