diff --git a/CONTEXT.md b/CONTEXT.md index 4654d8d..c9837d4 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -26,6 +26,14 @@ able to make a starting backup record a failure — F-A1), and the candidate picker skips archives failing `archivePlausiblyComplete` (a phantom would be due forever and fail forever). - New read-only `--selftest=restore-test-due` prints the per-tier verdict + its cost. + - **v0.121.1 — a quiet evaluation is AUDIBLE.** "Nothing is due" is now the NORMAL outcome, and at + DEBUG it was silent: an empty journal would have been equally consistent with a healthy loop and + a dead goroutine (standing rule 3 — the shape the R-88 watcher was retired for). A not-due + evaluation logs ONE INFO line naming every tier's verdict; an unlistable tier reads `UNKNOWN` + with its error in that same line. + - **PROVEN LIVE 2026-08-03 on demo-felhom:** due-triggered offsite restore-test of a 14.5 GB + encrypted PBS archive — restored, booted, verified, scratch destroyed, **635 s**; the state then + named that archive, a second evaluation ran nothing, and an agent restart ran nothing. - **R-185 (filed, NOT fixed here):** on demo-felhom the agent token has no ACL on `/storage/felhom-backup`, so its content listing comes back EMPTY (root sees 3 archives) — the host tier has never been restore-testable there, and the due-check cannot distinguish that from