Skip to content

M5.6: tamper-evident restore receipt hash chain - #32

Merged
pgousdal merged 5 commits into
mainfrom
work/m5.6-receipt-hash-chain
Sep 8, 2026
Merged

pgousdal merged 5 commits into
mainfrom
work/m5.6-receipt-hash-chain

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Adds SHA-256 hash chaining to persistent restore receipts. Each receipt now carries previous_hash and receipt_hash; appends verify the complete existing chain and refuse to extend a broken audit log. New read-only GET /api/recording-archive/receipts/verify reports validity, receipt count, chain head, and first failing receipt/index on corruption. Existing wholly unchained M5.5 receipt files are sealed once in append order during open, establishing tamper evidence from migration onward; partially hashed files are not treated as legacy. Includes chain-link, tamper-detection, append-gate, legacy-migration and verify-API tests plus README and M5.6 documentation. This is local tamper evidence, not external signing/timestamping.

@pgousdal
pgousdal merged commit 0a3eec3 into main Sep 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant