Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Resetting the Recovery-Backup Conformance No-Go

This procedure recovers the Linux installed-conformance attempt that passed the server phase and then stopped at recovery backup.verify. The failed adapter changed /var/lib/ahri-tre from root:ahri-tre:0750 to 0700 while recording its candidate binding. That prevented ahri-tre-runtime from traversing the directory, so Managed-secret verification reported NotInitialized.

Do not repair that installation with chmod and continue qualifying it. It is a valid no-go result for immutable candidate bytes. Use the guarded wizard to preserve the result, remove the disposable installation, activate the corrected candidate, and then prepare fresh Secrets. Neither wizard installs packages or invokes conformance.

Exact scope

Use this procedure only with:

  • failed candidate SHA-256 21a99920541e044000bba7134f685f8780ba1de44ab9637408d8ffd5c470b125;
  • corrected candidate SHA-256 de2400a3d050b71a6d97165b1785df2c512d830b063d261d7ec43dc05d4e9721;
  • corrected source revision f3d902775477564edd1fcc873e0e2e60565d2cb3;
  • fixed 0.3.12 predecessor SHA-256 6f5555c25d96274d7772d1b46d4409bd36a42205f21c4c715de8df5179ab18ed;
  • host svrltreapcc02 at 192.168.31.75;
  • Deployment f2ef37c5-7430-468a-a439-b3ba1b0527c1; and
  • Datastore ahri-tre-test.

The candidate filename remains ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz; the checksum identifies which immutable candidate it contains.

What remains and what is removed

The wizard retains the hostname, reserved address, /data mount, Docker installation and default bridge, hosts mappings, intended UFW policy, and declared service identities. It preserves the successful Linux-server record, the recovery no-go record, the candidate binding, and the checksummed predecessor rollback unit under the failed candidate’s protected record.

It removes the failed AHRI TRE package files, managed PostgreSQL container, disposable PostgreSQL data, Lake and scratch directories, configuration, Managed-secret store, Injected-secret authority, ephemeral projections, Runtime state, and the failed attempt’s separate root-identity backup. No previous AHRI TRE installation is reused.

1. Verify the corrected candidate

In the ordinary WSL2 Ubuntu shell:

cd /home/kobus/repos/ahri-tre-rs/dist/conformance-candidate-recovery-permissions-output-0.3.14
sha256sum --check --strict \
  ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256

The result must be OK and the checksum file must contain exactly:

de2400a3d050b71a6d97165b1785df2c512d830b063d261d7ec43dc05d4e9721  ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz

Keep the fixed predecessor archive and checksum in /home/kobus/ahri-tre-conformance/input. Do not regenerate it.

2. Run the guarded reset

Leave the MinisForum in the failed state. Do not reboot, change permissions, delete the container, or edit evidence first. Run:

cd /home/kobus/repos/ahri-tre-rs
./scripts/reset-failed-recovery-backup-conformance-wizard.sh

The five stages:

  1. verify WSL2 and the exact replacement inputs;
  2. verify all candidate checksums, source revision, and embedded fix;
  3. accept only the exact host, failed archive, successful server evidence, backup.verify no-go, 0700 failed state, candidate binding, managed PostgreSQL container, empty recovery output, and checksummed predecessor; then preserve evidence and remove only the verified failed installation;
  4. retire the failed local pair, activate the corrected pair, and remove the failed root-identity backup; and
  5. prove the retained clean foundation, display UFW for review, and stop at RESET READY.

Approve the firewall prompt only if UFW is active with default-deny incoming, default-allow outgoing, SSH allowed, LAN HTTPS on TCP 443 allowed, and PostgreSQL TCP 5432 denied.

If any guard refuses, stop. Do not bypass it by changing state manually.

3. Prepare fresh candidate-matching Secrets

After RESET READY, run:

cd /home/kobus/repos/ahri-tre-rs
./scripts/minisforum-conformance-preparation-wizard.sh

The preparation wizard must verify and transfer the corrected archive and checksum above plus the fixed predecessor inputs. It generates a fresh Deployment root identity and fresh candidate-matching Secret projections.

Stop when it prints:

HOST READY
The conformance harness has not been invoked.
Press Enter to finish at the host-ready boundary.

Do not reboot after HOST READY; the verified /run/secrets projections are ephemeral. Do not install packages or invoke conformance until the later HITL step explicitly begins.