DreamLake

Vault policy tree

2026-09-15 — affected-entry pages (Unreleased)

affectedEntries.observedAt is the application's UTC wall-clock observation when that page read completes, not a Mongo cluster timestamp or a guarantee spanning multiple pages. contextFingerprint identifies the policy/owner/tenant/key/schema context also bound into continuation cursors. Equal fingerprints do not freeze entry revisions between observations. All opt-in metadata probes have a 10-second Mongo operation limit; ordinary preview timeout behavior is preserved.

Opt in on the existing read-only preview command:

shell
dreamlake vault kms preview -p alice/project --key managed --affected-limit 100
# Continue only the same prefix/key observation with the returned cursor:
dreamlake vault kms preview -p alice/project --key managed --affected-limit 100 --affected-cursor "$cursor"

affectedEntries.entries includes retained soft-deleted entries and lifecycle metadata. It does not read values. Current policy is not ciphertext provenance; a blocked proposal is null. Each page is a separate snapshot, not a frozen inventory or permission to migrate. Epoch/key changes invalidate the cursor. The command requests one page, never silently drains or retries it. An older server that omits the requested page is refused. TUI p retains its ordinary counts/blockers view; this addition does not implement cross-boundary moves.

Actual local HTTP/Mongo and source-client parity can be reproduced with examples/vault-tree/affected-acceptance.py. Set VAULT_TREE_BACKEND to the candidate dreamlake-server and VAULT_TREE_PYTHON_SOURCE to the paired Python checkout. The fixture owns and removes its local database/process, uses synthetic metadata, and requires no cloud credentials. Shared JSON vectors cover both client projections. No package publication or hosted activation is claimed.

2026-09-15 — local candidate, not released. The owner-only vault list --tree view and Python vault.tree() consume the metadata contract in workspace PR576. Existing list JSON remains unchanged. Unknown policy/migration state remains unknown; the current policy key is not a claim about historical ciphertext.

shell
dreamlake vault list -p alice/research --tree
dreamlake vault list -p alice/research --tree --to-json --limit 100
python
page = vault.tree(prefix="alice/research", limit=100)

The runnable local guide uses actual HTTP/Mongo, CLI JSON, Python continuation and keyboard navigation in a real PTY. It verified owner denial, synthetic plaintext absence, zero crypto calls and owned fixture closure. Strict response schemas reject unexpected payload fields; terminal controls render as literal escapes. No hosted rollout or full TUI/retention closure is claimed. Affected-entry move/change preview remains outstanding.

Review follow-up

The initial PTY oracle proved next-page output, not every arrow action. A new receipt asserts each selection/collapse/expand frame and recovery from an explicitly injected first-page503. Failed reads preserve the cursor for a deliberate retry and clear the error after success. Optimized Python modes are rejected before fixture allocation. Unknown/unavailable policy never renders as managed fallback. The stronger local run recorded nine metadata requests and zero crypto calls; the original receipt remains preserved as historical evidence.

Root independently reviewed CLI d68909f and reran the stronger acceptance against backend 94fb53e8 and Python 1ccae1f: exit0, all keyboard/retry checks passed, nine metadata GETs, zero crypto calls and fixture closure verified. Source review is approved; required CI and release/deployment remain separate.

2026-09-15 — Unreleased selected-prefix policy preview

The tree accepts an explicit --preview-key and p on a selected prefix. It reuses the existing KMS preview endpoint and Python vault.kms.preview contract. Counts/blockers are labelled as such, missing counts remain unknown, and no activation/migration/move is requested. This does not implement an affected-entry list or complete cross-boundary move preview. The runnable example includes paired actual HTTP/Mongo and PTY checks; its authentication remains synthetic.