Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
1.4 KiB
R-833 lab proof — 2026-10-04 (a lab repo on DooPlex scratch, not a demo box's)
restic 0.14.0 from the controller image felhom-controller:0.290.0 (docker run --rm --entrypoint sh), a local repo,
password lab-only-password (a lab value). 98 daily snapshots, --host demo-lab --tag felhom-offsite, dated 97..0 days
back — the shape of a box whose windows were off for three months.
The box's own guard (offsiteGuard, controller v0.290.0 source) was run on the repo's REAL snapshots --json and the
policy's REAL forget --dry-run --json by offbox_window_lab_test.go.txt (copy it into
controller/internal/backup/ and set OFFSITE_LAB_DIR to rerun; it skips without it, so it is not committed).
| Step | Result |
|---|---|
| Honest plan | 98 snapshots, the policy removes 85 |
Default cap (hub MaxRemove = half) |
49 → REFUSED: the plan would remove 85 snapshots, more than one week's retention may (49) |
| Operator-raised cap 90 (one window) | 85 ids, no refusal |
restic forget <those 85 ids> --prune |
rc 0; 98 → 13; restic check rc 0 |
| Next window, default cap again (6) | plan 0, no refusal — the cap only needed raising once |
The hub half (the grant is one-shot, the next window has the default cap, the close check uses the window's own cap, a
box cannot grant itself) is in hub-redproofs.txt and the hub suite.