# REPORT — v0.276.0: a restore and a drive move keep the app's records (2026-09-27) Follow-up to the version-travel brief (v0.275.0). Architecture: `07-backup-architecture.md` §6.6. Evidence: `felhom.eu/documentation/audits/records-carried-2026-09-27/`. **Not done, or changed:** R-691 (2) (Load from the off-site copy) NOT built — a new restore path on household data with no box CC may prove it on; R-700 NOT proven live (no Tier-0 guest has two drives); R-697's carry not exercised by a real restore (it would spoil the night's release proof on 9202). **Baseline:** `main` `54bb4da`, v0.275.0, floor 0.275.0. **Commit:** `820e8ef`. **Released:** image `0.276.0`; floor 0.276.0 (MinAgent 0.131.0); both demo boxes on 0.276.0 within 10 s; 9202 by hand. - **R-697:** `PersistUnitRedeployConfig` now carries the life records from the `app.yaml` it replaces (`carryLifeRecords`, `internal/stacks/life_records.go`); `earlier_conversion_copies` keeps a superseded copy's record and `ReleaseConversionCopies` releases every kept copy by the same rule (`releaseOneConversionCopy`). - **R-700 (new):** `doFlipRedeploy` persisted through that same fresh write and dropped the pin; now `persistDriveFlip` (load-then-save, `HDD_PATH` only) + `upFromAppConfig` (the tail shared with `RedeployFromEnv`). **Tests:** `internal/stacks/r700_records_carried_test.go` (4). Full suite `go build/vet/test ./...` rc=0; controller gates OK. **Red-proofs** RP1–RP4 (`redproofs/`), each seen failing with the wrong value, tree restored. **Live:** 9202 paperless-ngx keeps its `conversion_copy` record and volume across the upgrade (`R/R3`). The night check (the release on a real 18 dump, through the rewritten loop) is in `N/`.