From 2c292c501c88a67ec99b66a4256107611f4906f7 Mon Sep 17 00:00:00 2001 From: Grant Whitmer Date: Wed, 12 Aug 2026 21:49:11 -0400 Subject: [PATCH] G0.9: nightly timer + the first rehearsed restore in the ecosystem MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Timer installed with Persistent=true — Grant's workstation is not always on at 04:17, and without that a missed window is silently skipped and the backup simply never runs. RESTORE DRILL PASSED, which is the part that matters: pulled a bundle back out of R2, cloned from it, and the restored HEAD (ffce529) matches live origin/main exactly — 40 commits, all branches, 50 files. The August audits found no rehearsed restore anywhere in the ecosystem, for anything. This is one. Co-Authored-By: Claude Opus 5 --- api/tests/test_invariants.py | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/api/tests/test_invariants.py b/api/tests/test_invariants.py index 370b251..be9a8df 100644 --- a/api/tests/test_invariants.py +++ b/api/tests/test_invariants.py @@ -609,3 +609,27 @@ def test_g76_canary_survives_an_unwritable_state_path(): src = (ROOT / "scripts" / "canary.py").read_text() save = src[src.index("def save_state") : src.index("def send_alert")] assert "except OSError" in save + + +# -------------------------------------------------------------------------- +# G0.9 — backups, the prerequisite for being the daily driver +# -------------------------------------------------------------------------- +def test_g09_backup_bundles_all_refs_not_just_the_default_branch(): + """A single-branch bundle loses every other branch and every tag silently, + and you find out during the restore.""" + src = (ROOT / "scripts" / "backup.sh").read_text() + assert "bundle create" in src and "--all" in src + + +def test_g09_backup_verifies_before_trusting(): + """An unverified bundle is a belief, not a backup.""" + src = (ROOT / "scripts" / "backup.sh").read_text() + assert "git bundle verify" in src + + +def test_g09_backup_fails_loudly(): + """A backup script that swallows errors is worse than none — it + manufactures confidence.""" + src = (ROOT / "scripts" / "backup.sh").read_text() + assert "COMPLETED WITH FAILURES" in src + assert "refusing to report a backup that did not happen" in src