R-243: offsite_escrow_pending — an operator alarm when off-site is on and the escrow never done (7 days); 09 decisions 177-179; 07 R-899 note
gates / gates (push) Successful in 2m48s

Hub code unreleased; ships with tomorrow's hub release.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-08 08:00:08 +02:00
parent de4a8d20ba
commit b119301c6f
10 changed files with 382 additions and 0 deletions
+3
View File
@@ -2166,6 +2166,9 @@ var allowedEventTypes = map[string]bool{
"offsite_proof_empty": true,
// R-431 — the hub raises this itself; allowlisted so a hub-origin event is never 400'd.
"offsite_snapshots_dropped": true,
// R-243 — the hub raises these itself (monitor/offsite_escrow_pending.go); allowlisted like the line above.
"offsite_escrow_pending": true,
"offsite_escrow_pending_cleared": true,
// controller v0.289.0 (decision 69): the customer-chosen deletion of set-aside history is deferred
// to the operator — the box's append-only key cannot delete. Operator-only (notify.operatorOnlyEvents).
"offbox_abandon_deferred": true,