diff --git a/documentation/architecture/07-backup-architecture.md b/documentation/architecture/07-backup-architecture.md index 3420df6..3f22c75 100644 --- a/documentation/architecture/07-backup-architecture.md +++ b/documentation/architecture/07-backup-architecture.md @@ -303,17 +303,17 @@ backups/secondary// The locked rulings are not re-litigated; these are **consequences the doc surfaced**: 1. **Blocked-enlargement semantics (§9):** when the quota gate blocks an app's enlarged push, its - unit-only push CONTINUES (no protection regression). Confirm. + unit-only push CONTINUES (no protection regression). Confirm. <--- Confirmed 2. **`.fab` optional default = pre-selected** (spike rec #2 wording; ruling #1 said "checkboxes" - without a default). Confirm pre-selected. + without a default). Confirm pre-selected. <-- Conrifmed 3. **Offsite restore default = unit-only; full (unit+userdata) is an explicit second action with - the size shown first (§7.2).** Confirm. -4. **Undeployed apps stay legacy unit-only offsite + WARN (§2.4).** Confirm. + the size shown first (§7.2).** Confirm. <-- Conrifmed +4. **Undeployed apps stay legacy unit-only offsite + WARN (§2.4).** Confirm. <-- Conrifmed 5. **Tier-2 v2 layout migration = delete-and-rebuild of the derived secondary copy (§8),** old - copies replaced on the first v2 run per app. Confirm. -6. **Quota accounting switches to raw-data bytes (§9), pending SP-1.** Confirm direction. + copies replaced on the first v2 run per app. Confirm. <-- Conrifmed +6. **Quota accounting switches to raw-data bytes (§9), pending SP-1.** Confirm direction. <-- Conrifmed 7. **SSD fallback becomes explicitly state-only (unit + mandatory-if-fits, never optional) - (§2.2).** Confirm. + (§2.2).** Confirm. <-- Conrifmed ## 11. Explicitly out of scope (noted, not decided here)