Blind Vault와 MemChain 충돌 복구 경계
프로세스 중단 후 복구 가능한 범위, 테스트 범위, 전원 손실 내구성·키 복구·fleet 배포가 별도 주장인 이유를 설명합니다.
Blind Vault와 MemChain 충돌 복구 경계
소스 구현
Blind Vault는 제한된 SQLite WAL transaction으로 immutable ciphertext를 저장하며 commit된 record는 process restart 후 읽을 수 있습니다. MemChain AOF는 framing/semantic link를 검증하고 불완전한 physical tail만 truncate합니다. 완전한 corrupt record는 유지한 채 fail closed합니다. 만료된 processing task는 lease 후 pending으로 돌아갈 수 있지만 외부 model call의 정확한 재개나 중복 방지를 보장하지 않습니다.
자동화 테스트 검증
Blind Vault retry/pull, issuer restart continuity, AOF torn-tail repair, complete corruption no-truncate, stale-claim reset의 기초 5개 tests가 통과했습니다. 복구된 commander integration line에서는 replica-recovery store 6개 tests도 통과해 restart recovery, V1 compatibility, corruption, conflict/rollback fail-closed를 확인했습니다. 이는 fleet crash drill 증거가 아닙니다.
현재 fleet 검증
2026-08-31 snapshot은 local commitment history가 검증된 follower 3개를 보여주지만 active coordinator, strict checkpoint threshold, witness-certified tip은 없습니다. r6 crash/recovery drill은 미검증입니다.
SQLite synchronous=NORMAL과 fsync 없는 flush는 sudden power loss에서 zero-loss를 증명하지 않습니다. legacy AOF는 node-readable Fact를 포함할 수 있어 ciphertext history가 아닙니다. sealed storage는 별도 경로입니다. 잃어버린 identity/key, 완전 replica, consensus/finality는 복구하지 못합니다.