257c4d85c0
gates / gates (push) Successful in 7s
R-190 is a grant that worked at 04:44 on 2026-08-03 and was gone by 09:24, with a reinstall, logged pveum activity and cluster-log entries all ruled out. The cause is open; the resilience need not wait for it. Everything needed already existed and had only ever been called once: the root wrapper's `grant` verb, its sudoers vector (`grant *`, any storage id — confirmed, not assumed), and the exact command. The verb had only ever run at storage creation — the "built but never wired" shape in a verb rather than a seam. The probe now runs that wrapper on a missing grant and re-reads ONCE to confirm, the pbsdr R-22 shape including its restraint. The record is the half that matters. A repair leaving only "ok" behind destroys the only evidence a permission vanished, so a recurring loss becomes undetectable — worse than the fault. A confirmed repair therefore reports DEGRADED for exactly one cycle with the explanation in Feature, because that is the field the hub puts in the operator's email (Reason does not travel). Nothing new was built: the hub's existing ok->degraded->ok edge is the channel, so one loss produces one alert pair. No wire change, no hub change, no new event type. Bounded at one attempt per tier per hour: a storage can be unreadable for reasons an ACL cannot fix, and re-granting every cycle is a repair loop wearing a fix's clothes. A failed repair never masks the fault.