14 / above the line

The harness checks itself on startup. Andy had always found that funny in an abstract way, and now found it funny in a specific one.

harness-04:/hook.d/
  00-env
  10-mount
  20-log
  30-verify        ← self-check: manifest, hashes, signatures
  40-attest.post   ← not in any manifest

Hooks run in numeric order. 30-verify walks the manifest, hashes every file it knows about, checks every signature, and writes harness: sound to a log that 20-log configured ten steps earlier.

Then 40-attest.post runs.

[INFO ] harness-04 self-check: PASS (4,118 files)
[INFO ] harness-04: sound
[INFO ] hook.d: 5 hooks executed

Five hooks. Four thousand one hundred and eighteen files.

Andy pulled the repo history for the night the hook’s mtime pointed at. Four commits had touched module paths between two and six in the morning. All four were signed. All four had landed cleanly. One of them had added a route that would survive any restore the company knew how to perform, because you cannot restore a file back out of existence if your baseline has never heard of it.

> four commits that night. one of them is the door.

the harness self-check covers hooks 00 to 30
work out which module the fifth one belongs to and the rest falls out
— nix
evidence retained
  1. c-4a1 touches auth.
  2. c-9f2 touches export.
  3. c-9f2 answers x-mu-drain.
  4. Whatever k.rel signed answers x-mu-drain.
  5. Whatever k.ops signed answers x-mu-debug.
  6. The change that landed in the 03:15 window answers x-mu-debug.
  7. The change that landed in the 04:35 window answers x-mu-trace.
  8. The path added to ingest answers x-mu-trace.
  9. The path added to auth does not answer x-mu-replay.
  10. c-77b is not signed r.sato.
  11. c-2de landed early: not in the 04:35 window, and not in the 05:10 one.
  12. Every one of the four commits passed review. Three reviewers, one of whom has left.
case file andy — personal
INC-0013 decoded from ttl-jitter on j-thumb
harness-04:/hook.d/40-attest.post

Not a service and not a patch. A path on the harness host, decoded from a thumbnail job's retry timer.

open incident →
INC-0004 cache-diag — edge fleet (archived)
maintainer_key=r.sato

Every maintainer field was scrubbed. The key survived in the legacy index.

open incident →
messages ttl-jitter
nix 02:14

a backdoor isn't a hole. a hole gets patched. this is a supported feature nobody documented.

nix 02:16

columns are commits, keys, modules, windows. rows are triggers, windows, modules, keys.

nix 02:18

find the harness commit. then tell me what header it answers to. commit, signed, module, window, answers.

table harness repo — that night

fault

Unmanifested persistence

self-check

hooks 00–30

severity

unfiled

Skip the grid, go to the answer
c-4a1 c-9f2 c-2de c-77b k.ops r.sato k.bot k.rel auth ingest harness export 02:40 03:15 04:35 05:10
x-mu-trace
x-mu-replay
x-mu-debug
x-mu-drain
02:40
03:15
04:35
05:10
auth
ingest
harness
export
k.ops
r.sato
k.bot
k.rel
answer input not an incident

Question: Which commit added the hook — signed by what, in which module and window, answering which header?