CONTEXT + REPORT: v0.289.0/v0.289.1 off-site lock (floored 0.289.1, golden 0.289.1 vouched)
gates / gates (push) Successful in 28s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-03 21:29:10 +02:00
parent 2a2af2018d
commit c4bf730637
2 changed files with 25 additions and 12 deletions
+11 -1
View File
@@ -7,7 +7,17 @@
>
> Ask Claude Code: "Please update CONTEXT.md with what we did today"
Last updated: 2026-10-02 afternoon (v0.288.0 — the remove dialog names the household's files, decision 67, R-800)
Last updated: 2026-10-03 evening (v0.289.1 — the off-site key cannot delete, decisions 68–69)
> **2026-10-03 (evening) — v0.289.0 + v0.289.1 (floored 0.289.1, golden 0.289.1 vouched, needs hub v0.127.0):** the
> hub-provisioned off-site tier is reached through an APPEND-ONLY key the hub's registrar pins
> (`offsiteapply.HubRegistrar`, `PinnedProber`); the box never receives the Storage Box password; transport `rclone:`
> over ssh 23 (`OffboxTarget.Transport = "rclone-pinned"`; the household NAS stays sftp). Retention only inside a hub
> window behind the fake-snapshot guard (`backup/offbox_window.go`) — weekly windows are OFF; the guard is too strict
> after manual runs (R-824, next). Move-aside is the hub's; abandonment deferred to the operator (R-823). v0.289.1: the
> provider rclone NOTICE line is stripped from restic output, and an unreadable snapshot count is never a measured 0
> (it caused one false `offsite_snapshots_dropped` mail, R-825). Both demo boxes migrated live with history kept.
> Evidence `felhom.eu/documentation/audits/offsite-lock-build-2026-10-03/`.
> **2026-10-02 (afternoon) — v0.288.0 (floored, golden 0.288.0 vouched):** `userdata_kept` in hdd-data and both remove
> results; the dialog says the household's files stay and names them (decision 67). Rule for later work: a remove NEVER