R-304 option C: operator mail when a household's code opens or may open an older package (once a day); R-298 side fix (no eject/format on a backup-target drive); R-717 comments
gates / gates (push) Successful in 59s

Unreleased; ships with tomorrow's release (needs the hub of the same day).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-08 10:07:03 +02:00
parent a0370b4ed8
commit a40729a698
10 changed files with 186 additions and 3 deletions
+4
View File
@@ -154,6 +154,10 @@ type Server struct {
// recoveryRetainedTrustedFn overrides the R-311 gate deciding whether a 422 may be read as "the
// code is correct and opens a RETAINED earlier package" (tests). INIT-ONLY.
recoveryRetainedTrustedFn func(context.Context) bool
// R-304 option C: the operator's older-package mail — the test seam, and the once-per-day record (recovery_older_mail.go).
recoveryOlderPushFn func(eventType, severity, message string, details map[string]string)
recoveryOlderMu sync.Mutex
recoveryOlderLastDay string
// recoveryNowFn is the unlock path's clock (tests inject; nil → time.Now). Observability and
// tests only — never a classifier.
recoveryNowFn func() time.Time