hub (unreleased): R-922 option A — a household's clear deletes its notification address (email_cleared); MAIL-HOLD — a restored hub sends no mail until released; two log lines drop the address; runbooks: mail hold is restore step 1; 07 §6.4 R-921 pre-check; R-921/R-922 narrowed
gates / gates (push) Successful in 5m25s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-09 12:37:28 +02:00
parent 2c48feb325
commit d55c590c5a
35 changed files with 861 additions and 23 deletions
+4
View File
@@ -94,6 +94,10 @@ ROOTS = [
# ACK's operator_actions list. Named type for the same reason as R-311's root above.
("hub -> controller (report ACK, `operator_actions` entry)",
"hub", "internal/store", "OperatorActionDirective", "controller"),
# R-922 (2026-10-09): the notification-prefs push. Declared when the household's deliberate clear
# (`email_cleared`) joined it — a flag the hub cannot decode would leave the cleared address stored.
("controller -> hub (POST /preferences)",
"controller", "internal/notify", "preferencesRequest", "hub"),
]
# R-315: a root whose receiver decodes it into ONE NAMED MIRROR TYPE gets the stronger check —