# R-436 exit test — written BEFORE any command ran (2026-10-03 ~11:10 CEST) The lock HOLDS only if ALL of these are true on the LIVE Storage Box (`u629488`, scratch venue `u629488-sub4`, a dedicated repo path that is NOT `felhom-repo`): | # | Through the FORCED key (`command="rclone serve restic --stdio --append-only "`) | Must be | |---|---|---| | E1 | `restic init` (scratch repo) | succeeds | | E2 | `restic backup` of a small tree | succeeds, snapshot count +1 | | E3 | `restic snapshots`, `restic restore` of one file (bytes compared) | succeeds | | E4 | `restic forget --prune` | REFUSED — verbatim error quoted; count unchanged | | E5 | `restic prune` | REFUSED — verbatim; `check` clean | | E6 | `restic forget --keep-last 1` | REFUSED — verbatim; count unchanged | | E7 | the same key asking for a shell / `sftp` / `scp` / `rsync` / a port forward | REFUSED | | E8 | the same key, client asks for a plain `rclone serve restic --stdio` (no flag) | still append-only | Controls (without them a refusal means nothing): | # | Control | Must be | |---|---|---| | C1 | the same `forget --prune` through a key WITHOUT the forced command | SUCCEEDS (the test can see a delete) | | C2 | the forced key, client names a DIFFERENT repo path | recorded as observed (expected: the pinned path is served regardless) | Locks (R-430): kill a backup mid-run through the forced key; record whether the next backup wedges, and what `unlock` / `unlock --remove-all` report AND what remains on disk. **Verdict rule:** E1–E8 as stated and C1 succeeding ⇒ the lock holds *for that key*. Part B then asks whether any OTHER credential reachable from a box defeats it; if one does, the lock alone is not protection, and that is reported first. A LOCAL LAB (`lab/`) runs the same matrix against OpenSSH + rclone on DooPlex. It measures rclone's and restic's behaviour; it CANNOT stand in for the provider's sshd honouring `command=`. Only `live/` can close R-436.