docs(wake): #953 dead-letter retention recorded as load-bearing at the write site #968
@@ -488,6 +488,19 @@ _dlq_alarm_offhost() {
|
|||||||
# A dead-letter write failure is itself alarmed (both legs) but never aborts the
|
# A dead-letter write failure is itself alarmed (both legs) but never aborts the
|
||||||
# drain — the good entries MUST still deliver (availability is the whole point of
|
# drain — the good entries MUST still deliver (availability is the whole point of
|
||||||
# #920).
|
# #920).
|
||||||
|
#
|
||||||
|
# RETENTION IS LOAD-BEARING (#953) — read BEFORE adding rotation/pruning/caps:
|
||||||
|
# this ledger is append-only history AND the SOLE evidence base for
|
||||||
|
# store.sh quarantine-audit's conviction predicate (#946): a false
|
||||||
|
# consumed-hashes witness row is provable ONLY while its matching entry
|
||||||
|
# survives HERE. Any rotation, pruning, or size cap — however locally correct
|
||||||
|
# — silently converts provable rows into unprovable ones, and the audit's
|
||||||
|
# clean sweep reads IDENTICALLY before and after the evidence disappears (no
|
||||||
|
# signal at either end; the audit never guesses, by design). If retention
|
||||||
|
# limits ever become genuinely necessary, they MUST ship with (a) a loud
|
||||||
|
# signal at prune time naming what evidence is being given up, and (b) the
|
||||||
|
# audit's residual-class reporting updated IN THE SAME CHANGE. Until then:
|
||||||
|
# nothing prunes this file, and that is a recorded decision, not an omission.
|
||||||
_quarantine_entry() {
|
_quarantine_entry() {
|
||||||
local line="$1" seq="$2" dlq="$STATE_DIR/dead-letter.jsonl"
|
local line="$1" seq="$2" dlq="$STATE_DIR/dead-letter.jsonl"
|
||||||
if [ ! -f "$dlq" ] || ! grep -qxF "$line" "$dlq" 2>/dev/null; then
|
if [ ! -f "$dlq" ] || ! grep -qxF "$line" "$dlq" 2>/dev/null; then
|
||||||
|
|||||||
Reference in New Issue
Block a user