Labels a self-cite and bounds the window claim - #120
Merged
Merged
Conversation
ADR-0005 takes a dated foot Note giving the 2026-09-14 Note's self-cite of its "Not which tenant." paragraph the SHA it was read at, as that Note's own rule asks of a quotation of another record. No record line is removed. The rotation runbook's restart-window sentence now says every public entry point of the vault answers the not-started error, and names the exception: the gate's own read answers no error, passing an in-flight call under the default store and refusing it under a shared store. Refs: enc-c3o
johnnyt
force-pushed
the
enc-c3o-runbook-window-and-note-cite
branch
from
September 30, 2026 06:00
7e556ce to
0ed6a05
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Docs-only follow-up to three advisories on the rotation runbook and ADR-0005, and one convention question.
What changes
:1473-1482with no read-at SHA. The new Note gives it one: the paragraph is at those lines at encd237bf3(the commit that wrote that Note) and again at enc75906cf.git diff origin/main -- docs/adr/shows zero removed lines.{:vault_not_started, vault}. It now says every public entry point of the vault does, and names the exception: the gate's own read (Encryptor.Vault.Suspension.suspended?/2) answers no error, so a call that read the configuration before the crash passes the gate under the default store and is refused as suspended under a shared store.Not in this PR
Encryptor.Vault.ensure_started/2throughEncryptor.Vault.Config.fetch/1.Refstrailer convention question is a note on the bead for the operator; CLAUDE.md is not edited.Review (in-turn)
Checked against main at
75906cf, by anchor.Encryptor.Vault.suspend/2andreinstate/2open withensure_started(vault, :start), andready/2callsensure_started/2too, so the public entry points answer the not-started error whenConfig.fetch/1finds no frozen configuration.Lifecycle.terminate/2callsConfig.erase/1.Suspension.suspended?/2answersshared?(config)when:ets.whereis/1finds no table:falseunderStore.Ets,trueotherwise. Its one caller,allowed/3inlib/encryptor/vault/resolve.ex, turnstrueinto{:key_unavailable, selector}, the same term a suspension gives. The ADR-0005 paragraph starts at:1473and ends at:1482at both SHAs the Note names. No changelog fragment: documentation and ADRs are excluded bychangelog.d/README.md. This change touches no Elixir code, so under CLAUDE.md's authority table it commits on review of the diff alone and no local gate ran; CI runs the full gate.