Skip to content

fix: verify storage-first final release recovery - #56

Merged
mellowcroc merged 1 commit into
mainfrom
fix/v4-release-signer-checkpoint
Sep 17, 2026
Merged

mellowcroc merged 1 commit into
mainfrom
fix/v4-release-signer-checkpoint

Conversation

@mellowcroc

Copy link
Copy Markdown
Collaborator

Summary

  • pin the corrected Proof-tool runtime and verify final release signing against the authenticated review checkpoint
  • make fresh storage-first inspection keep an explicit artifact root and its children in one read-only Docker mount
  • add live R2 final-state reconstruction and isolated S3 initial-state/grant-scope coverage
  • retain immutable-write, credential-isolation, and frozen-workflow recovery protections

Validation

  • go test ./... -count=1
  • go vet ./...
  • bash scripts/test-install-launcher.sh
  • live R2 minimal-role ceremony through both phases, coordinator replay, final release checkpoint, and fresh-workspace reconstruction
  • live S3 initial-state reconstruction and scoped temporary-grant test

Limit

A complete live S3 contribution-to-release rehearsal is still pending. Tessera-backed storage-first ceremonies remain disabled until the compatible setup-v3 grant/status contract is deployed; existing frozen ceremonies are unchanged.

@mellowcroc
mellowcroc merged commit b150bcc into main Sep 17, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant