forked from heavy-duty/box
converged anything. This takes the checkpoint one step later: after the rig bootstrap hook has run and box has WATCHED IT SUCCEED, the box is converged and untouched. 'box restore <box> bootstrapped' keeps the tenant role and undoes only what happened after it, which is the undo an operator reaches for far more often and which otherwise costs a ~10-minute re-mint. The policy is #128's, shared rather than copied: snapshot_pristine and the new snapshot_bootstrapped are thin wrappers over one snapshot_mark, so the never-fatal contract and the 'dir' skip exist in exactly one place. What does not generalise is the prose — the two marks name different moments — so each wrapper owns its own narration. Deliberately conditional where 'pristine' is unconditional. 'pristine' marks a MOMENT every fresh mint has; 'bootstrapped' marks an EVENT, and a blank box has no such event, so it gets no mark rather than a byte-identical duplicate of 'pristine' at twice the disk cost. A FAILED hook gets none either: the failure message already sends the operator to 'box shell', which is a run box does not watch, so box hands over 'box snapshot <box> bootstrapped' instead of labelling a convergence it never saw. The label is therefore documented as one-directional on every surface: its presence means the hook converged untouched, its absence means nothing at all. Same durability caveats restated everywhere it appears — it dies with the box on 'box rm', and no filesystem rollback reaches off-box state (heavy-duty/rig#62). Closes #130 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| plans | ||
| box-design.md | ||
| box-recipe.md | ||