Resetting the Recovery-Backup Conformance No-Go
This procedure recovers the Linux installed-conformance attempt that passed
the server phase and then stopped at recovery backup.verify. The failed
adapter changed /var/lib/ahri-tre from root:ahri-tre:0750 to 0700 while
recording its candidate binding. That prevented ahri-tre-runtime from
traversing the directory, so Managed-secret verification reported
NotInitialized.
Do not repair that installation with chmod and continue qualifying it. It is
a valid no-go result for immutable candidate bytes. Use the guarded wizard to
preserve the result, remove the disposable installation, activate the corrected
candidate, and then prepare fresh Secrets. Neither wizard installs packages or
invokes conformance.
Exact scope
Use this procedure only with:
- failed candidate SHA-256
21a99920541e044000bba7134f685f8780ba1de44ab9637408d8ffd5c470b125; - corrected candidate SHA-256
de2400a3d050b71a6d97165b1785df2c512d830b063d261d7ec43dc05d4e9721; - corrected source revision
f3d902775477564edd1fcc873e0e2e60565d2cb3; - fixed
0.3.12predecessor SHA-2566f5555c25d96274d7772d1b46d4409bd36a42205f21c4c715de8df5179ab18ed; - host
svrltreapcc02at192.168.31.75; - Deployment
f2ef37c5-7430-468a-a439-b3ba1b0527c1; and - Datastore
ahri-tre-test.
The candidate filename remains
ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz; the checksum identifies
which immutable candidate it contains.
What remains and what is removed
The wizard retains the hostname, reserved address, /data mount, Docker
installation and default bridge, hosts mappings, intended UFW policy, and
declared service identities. It preserves the successful Linux-server record,
the recovery no-go record, the candidate binding, and the checksummed
predecessor rollback unit under the failed candidate’s protected record.
It removes the failed AHRI TRE package files, managed PostgreSQL container, disposable PostgreSQL data, Lake and scratch directories, configuration, Managed-secret store, Injected-secret authority, ephemeral projections, Runtime state, and the failed attempt’s separate root-identity backup. No previous AHRI TRE installation is reused.
1. Verify the corrected candidate
In the ordinary WSL2 Ubuntu shell:
cd /home/kobus/repos/ahri-tre-rs/dist/conformance-candidate-recovery-permissions-output-0.3.14
sha256sum --check --strict \
ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256
The result must be OK and the checksum file must contain exactly:
de2400a3d050b71a6d97165b1785df2c512d830b063d261d7ec43dc05d4e9721 ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz
Keep the fixed predecessor archive and checksum in
/home/kobus/ahri-tre-conformance/input. Do not regenerate it.
2. Run the guarded reset
Leave the MinisForum in the failed state. Do not reboot, change permissions, delete the container, or edit evidence first. Run:
cd /home/kobus/repos/ahri-tre-rs
./scripts/reset-failed-recovery-backup-conformance-wizard.sh
The five stages:
- verify WSL2 and the exact replacement inputs;
- verify all candidate checksums, source revision, and embedded fix;
- accept only the exact host, failed archive, successful server evidence,
backup.verifyno-go,0700failed state, candidate binding, managed PostgreSQL container, empty recovery output, and checksummed predecessor; then preserve evidence and remove only the verified failed installation; - retire the failed local pair, activate the corrected pair, and remove the failed root-identity backup; and
- prove the retained clean foundation, display UFW for review, and stop at
RESET READY.
Approve the firewall prompt only if UFW is active with default-deny incoming, default-allow outgoing, SSH allowed, LAN HTTPS on TCP 443 allowed, and PostgreSQL TCP 5432 denied.
If any guard refuses, stop. Do not bypass it by changing state manually.
3. Prepare fresh candidate-matching Secrets
After RESET READY, run:
cd /home/kobus/repos/ahri-tre-rs
./scripts/minisforum-conformance-preparation-wizard.sh
The preparation wizard must verify and transfer the corrected archive and checksum above plus the fixed predecessor inputs. It generates a fresh Deployment root identity and fresh candidate-matching Secret projections.
Stop when it prints:
HOST READY
The conformance harness has not been invoked.
Press Enter to finish at the host-ready boundary.
Do not reboot after HOST READY; the verified /run/secrets projections are
ephemeral. Do not install packages or invoke conformance until the later HITL
step explicitly begins.