Skip to content

R-15: record deletion transitions (DELETE_PENDING / TOMBSTONED) in the protected write path #948

Description

@qnbs

CONTROL-PLANE MIRROR — 2026-10-02

Linear mirror: QNB-182 · Project v1.30.0 — Complete Desktop At-Rest Encryption · M6 — Gate 7 production authority switch. QNB-182 blocks QNB-171/Gate 7.

This residual is not a Gate-3 blocker. Gate 3 is terminal via #949. Execute #948 before Gate 7 for any class whose current authority deletes records.

Part of #445. Recorded as a residual by the Gate 3 closure (#921).

Gate 3 implements the protected write and read paths for ordinary records: ABSENT -> PENDING -> ACTIVE, ACTIVE -> PENDING -> ACTIVE, rollback, and a root commit per marker transition. The marker codec admits DELETE_PENDING and TOMBSTONED (§8.5), but there is no protected delete operation yet, so:

  • no transition writes those markers or commits them through the root and catalog;
  • no tombstone retention is enforced.

Scope:

  • add a protected delete that follows §8.5 and §5.5's ordinary-write coherence rule (marker, catalog and root in one serialized commit);
  • add startup resolution of an interrupted delete;
  • add tombstone retention.

This is not part of Gate 3's definition (§20 item 3). It must land before Gate 7 for any class whose current authority deletes records.

PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions