storage_backup_capability.v1.json (1807B)
1 { 2 "schema": "radroots.storage-backup-capability.v1", 3 "status": "approved", 4 "scope": "Existing canonical owner capture, verification and finalization through StorageReliability and SDK Operations", 5 "source_boundary": "Only the SQLite owner performs snapshots and filesystem publication. The SPI exposes no filesystem paths, SQL or backend handles.", 6 "unsupported_backends": "Actual operations fail closed. Reliability metadata transitions do not prove that any snapshot exists.", 7 "compatibility": "Existing backup manifests, formats, member names, schemas and concrete-owner operations remain unchanged. Default unsupported methods preserve other backend implementations.", 8 "error_boundary": "Typed bounded errors omit filesystem paths, raw database details and nested I/O sources.", 9 "consistency": "The capability preserves existing per-member snapshot semantics. Application and media coordination, identity binding and cross-member consistency require explicit host orchestration; no global transaction is implied.", 10 "settling": "Before related inventory/capture, the host excludes new writes and requests settle_backup_writes. SQLite retains every runtime/protected pool permit and drains their worker handshakes, including asynchronous return after caller cancellation. The host retains its write exclusion after settling returns. Unsupported backends refuse. This is not an ongoing reservation or global transaction.", 11 "lifecycle": "Unpolled operations have no effects. Owner close refuses later capture, verification and finalization. Failed or interrupted capture may retain staging for explicit reconciliation.", 12 "excluded": ["application backup formats", "automatic recovery", "restore orchestration", "secret export consent", "new filesystem owner", "coverage exclusions"] 13 }