Skip to content

docs: Vault snapshots restored; record the permanent gap - #608

Merged
swares merged 1 commit into
mainfrom
docs/vault-snapshot-restored
Sep 23, 2026
Merged

swares merged 1 commit into
mainfrom
docs/vault-snapshot-restored

Conversation

@swares

@swares swares commented Sep 23, 2026

Copy link
Copy Markdown
Owner

A snapshot landed on the cold tier - vault-snap-20260923-151859.snap, 74271 bytes. The token's properties were checked rather than just its existence: orphan true, period 768h. A fresh non-orphan token would have produced an identical successful snapshot today and died again in 26 days.

Records two near-misses in the verification. wc -c on the token file returns Permission denied as swares, which reads like a missing file when moving quickly; sudo head -c 4 discriminates hvs. from Erro, which is what tee writes when the create fails. And the first systemctl start never ran - swallowed by a paste - while systemctl is-active reported failed from the previous night's timer, so a latched failure is indistinguishable from a fresh one.

Records the permanent hole: retention resumed with the job and -mtime +30 had not run since Sep 8, so about seven old snapshots aged out in one pass. The restore timeline is Aug 24 to Sep 8, a 15-day gap, then Sep 23. Vault's mid-September state cannot be reconstructed. Ticks when the gap ages out naturally after 2026-10-23.

Heading deliberately says 'snapshot restored', not RESOLVED. Three of the four remaining items belong to other sections - token hygiene, alert delivery, journal retention - and calling the entry resolved would have made all four orphans, which is precisely how 7.y's twenty-five were manufactured.

A snapshot landed on the cold tier - vault-snap-20260923-151859.snap, 74271 bytes. The token's properties were checked rather than just its existence: orphan true, period 768h. A fresh non-orphan token would have produced an identical successful snapshot today and died again in 26 days.

Records two near-misses in the verification. wc -c on the token file returns Permission denied as swares, which reads like a missing file when moving quickly; sudo head -c 4 discriminates hvs. from Erro, which is what tee writes when the create fails. And the first systemctl start never ran - swallowed by a paste - while systemctl is-active reported failed from the previous night's timer, so a latched failure is indistinguishable from a fresh one.

Records the permanent hole: retention resumed with the job and -mtime +30 had not run since Sep 8, so about seven old snapshots aged out in one pass. The restore timeline is Aug 24 to Sep 8, a 15-day gap, then Sep 23. Vault's mid-September state cannot be reconstructed. Ticks when the gap ages out naturally after 2026-10-23.

Heading deliberately says 'snapshot restored', not RESOLVED. Three of the four remaining items belong to other sections - token hygiene, alert delivery, journal retention - and calling the entry resolved would have made all four orphans, which is precisely how 7.y's twenty-five were manufactured.
@swares
swares merged commit 6cb781f into main Sep 23, 2026
4 checks passed
@swares
swares deleted the docs/vault-snapshot-restored branch September 23, 2026 19:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant