c-4a1touchesauth.c-9f2touchesexport.c-9f2answersx-mu-drain.- Whatever
k.relsigned answersx-mu-drain. - Whatever
k.opssigned answersx-mu-debug. - The change that landed in the
03:15window answersx-mu-debug. - The change that landed in the
04:35window answersx-mu-trace. - The path added to
ingestanswersx-mu-trace. - The path added to
authdoes not answerx-mu-replay. c-77bis not signedr.sato.c-2delanded early: not in the04:35window, and not in the05:10one.- Every one of the four commits passed review. Three reviewers, one of whom has left.
14 / above the line
The harness checks itself on startup. Andy had always found that funny in an abstract way, and now found it funny in a specific one.
harness-04:/hook.d/
00-env
10-mount
20-log
30-verify ← self-check: manifest, hashes, signatures
40-attest.post ← not in any manifest
Hooks run in numeric order. 30-verify walks the manifest, hashes every file it
knows about, checks every signature, and writes harness: sound to a log that
20-log configured ten steps earlier.
Then 40-attest.post runs.
[INFO ] harness-04 self-check: PASS (4,118 files)
[INFO ] harness-04: sound
[INFO ] hook.d: 5 hooks executed
Five hooks. Four thousand one hundred and eighteen files.
Andy pulled the repo history for the night the hook’s mtime pointed at. Four commits had touched module paths between two and six in the morning. All four were signed. All four had landed cleanly. One of them had added a route that would survive any restore the company knew how to perform, because you cannot restore a file back out of existence if your baseline has never heard of it.
> four commits that night. one of them is the door.
the harness self-check covers hooks 00 to 30
work out which module the fifth one belongs to and the rest falls out
— nix
harness-04:/hook.d/40-attest.post
Not a service and not a patch. A path on the harness host, decoded from a thumbnail job's retry timer.
open incident →maintainer_key=r.sato
Every maintainer field was scrubbed. The key survived in the legacy index.
open incident →a backdoor isn't a hole. a hole gets patched. this is a supported feature nobody documented.
columns are commits, keys, modules, windows. rows are triggers, windows, modules, keys.
find the harness commit. then tell me what header it answers to. commit, signed, module, window, answers.
fault
Unmanifested persistence
self-check
hooks 00–30
severity
unfiled
| c-4a1 | c-9f2 | c-2de | c-77b | k.ops | r.sato | k.bot | k.rel | auth | ingest | harness | export | 02:40 | 03:15 | 04:35 | 05:10 | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| x-mu-trace | ||||||||||||||||
| x-mu-replay | ||||||||||||||||
| x-mu-debug | ||||||||||||||||
| x-mu-drain | ||||||||||||||||
| 02:40 | ||||||||||||||||
| 03:15 | ||||||||||||||||
| 04:35 | ||||||||||||||||
| 05:10 | ||||||||||||||||
| auth | ||||||||||||||||
| ingest | ||||||||||||||||
| harness | ||||||||||||||||
| export | ||||||||||||||||
| k.ops | ||||||||||||||||
| r.sato | ||||||||||||||||
| k.bot | ||||||||||||||||
| k.rel |
Question: Which commit added the hook — signed by what, in which module and window, answering which header?