Skip to content

Labels a self-cite and bounds the window claim - #120

Merged
johnnyt merged 1 commit into
mainfrom
enc-c3o-runbook-window-and-note-cite
Sep 30, 2026
Merged

johnnyt merged 1 commit into
mainfrom
enc-c3o-runbook-window-and-note-cite

Conversation

@johnnyt

@johnnyt johnnyt commented Sep 30, 2026

Copy link
Copy Markdown
Member

Docs-only follow-up to three advisories on the rotation runbook and ADR-0005, and one convention question.

What changes

  • ADR-0005, a dated foot Note by addition. The 2026-09-14 Note cites this record's own paragraph by anchor "Not which tenant." at :1473-1482 with no read-at SHA. The new Note gives it one: the paragraph is at those lines at enc d237bf3 (the commit that wrote that Note) and again at enc 75906cf. git diff origin/main -- docs/adr/ shows zero removed lines.
  • Rotation runbook, in-place prose. The restart-window sentence said "every entry point" answers {:vault_not_started, vault}. It now says every public entry point of the vault does, and names the exception: the gate's own read (Encryptor.Vault.Suspension.suspended?/2) answers no error, so a call that read the configuration before the crash passes the gate under the default store and is refused as suspended under a shared store.

Not in this PR

  • The earlier advisory that the runbook attributed the window to the suspension module was already fixed on main: the sentence names Encryptor.Vault.ensure_started/2 through Encryptor.Vault.Config.fetch/1.
  • The commit-title and Refs trailer convention question is a note on the bead for the operator; CLAUDE.md is not edited.

Review (in-turn)

Checked against main at 75906cf, by anchor. Encryptor.Vault.suspend/2 and reinstate/2 open with ensure_started(vault, :start), and ready/2 calls ensure_started/2 too, so the public entry points answer the not-started error when Config.fetch/1 finds no frozen configuration. Lifecycle.terminate/2 calls Config.erase/1. Suspension.suspended?/2 answers shared?(config) when :ets.whereis/1 finds no table: false under Store.Ets, true otherwise. Its one caller, allowed/3 in lib/encryptor/vault/resolve.ex, turns true into {:key_unavailable, selector}, the same term a suspension gives. The ADR-0005 paragraph starts at :1473 and ends at :1482 at both SHAs the Note names. No changelog fragment: documentation and ADRs are excluded by changelog.d/README.md. This change touches no Elixir code, so under CLAUDE.md's authority table it commits on review of the diff alone and no local gate ran; CI runs the full gate.

ADR-0005 takes a dated foot Note giving the 2026-09-14 Note's self-cite
of its "Not which tenant." paragraph the SHA it was read at, as that
Note's own rule asks of a quotation of another record. No record line
is removed.

The rotation runbook's restart-window sentence now says every public
entry point of the vault answers the not-started error, and names the
exception: the gate's own read answers no error, passing an in-flight
call under the default store and refusing it under a shared store.

Refs: enc-c3o
@johnnyt
johnnyt force-pushed the enc-c3o-runbook-window-and-note-cite branch from 7e556ce to 0ed6a05 Compare September 30, 2026 06:00
@johnnyt
johnnyt merged commit 827c6d3 into main Sep 30, 2026
1 check passed
@johnnyt
johnnyt deleted the enc-c3o-runbook-window-and-note-cite branch September 30, 2026 06:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant