Vault policy tree
2026-09-15 — affected-entry pages (Unreleased)
affectedEntries.observedAt is the application's UTC wall-clock observation when
that page read completes, not a Mongo cluster timestamp or a guarantee spanning
multiple pages. contextFingerprint identifies the policy/owner/tenant/key/schema
context also bound into continuation cursors. Equal fingerprints do not freeze
entry revisions between observations. All opt-in metadata probes have a 10-second
Mongo operation limit; ordinary preview timeout behavior is preserved.
Opt in on the existing read-only preview command:
affectedEntries.entries includes retained soft-deleted entries and lifecycle
metadata. It does not read values. Current policy is not ciphertext provenance;
a blocked proposal is null. Each page is a separate snapshot, not a frozen
inventory or permission to migrate. Epoch/key changes invalidate the cursor.
The command requests one page, never silently drains or retries it. An older
server that omits the requested page is refused. TUI p retains its ordinary
counts/blockers view; this addition does not implement cross-boundary moves.
Actual local HTTP/Mongo and source-client parity can be reproduced with
examples/vault-tree/affected-acceptance.py. Set VAULT_TREE_BACKEND to the
candidate dreamlake-server and VAULT_TREE_PYTHON_SOURCE to the paired Python
checkout. The fixture owns and removes its local database/process, uses synthetic
metadata, and requires no cloud credentials. Shared JSON vectors cover both client
projections. No package publication or hosted activation is claimed.
2026-09-15 — local candidate, not released. The owner-only vault list --tree view and Python vault.tree() consume the metadata contract in
workspace PR576.
Existing list JSON remains unchanged. Unknown policy/migration state remains
unknown; the current policy key is not a claim about historical ciphertext.
The runnable local guide uses actual HTTP/Mongo, CLI JSON, Python continuation and keyboard navigation in a real PTY. It verified owner denial, synthetic plaintext absence, zero crypto calls and owned fixture closure. Strict response schemas reject unexpected payload fields; terminal controls render as literal escapes. No hosted rollout or full TUI/retention closure is claimed. Affected-entry move/change preview remains outstanding.
Review follow-up
The initial PTY oracle proved next-page output, not every arrow action. A new receipt asserts each selection/collapse/expand frame and recovery from an explicitly injected first-page503. Failed reads preserve the cursor for a deliberate retry and clear the error after success. Optimized Python modes are rejected before fixture allocation. Unknown/unavailable policy never renders as managed fallback. The stronger local run recorded nine metadata requests and zero crypto calls; the original receipt remains preserved as historical evidence.
Root independently reviewed CLI d68909f and reran the stronger acceptance
against backend 94fb53e8 and Python 1ccae1f: exit0, all keyboard/retry checks
passed, nine metadata GETs, zero crypto calls and fixture closure verified.
Source review is approved; required CI and release/deployment remain separate.
2026-09-15 — Unreleased selected-prefix policy preview
The tree accepts an explicit --preview-key and p on a selected prefix. It
reuses the existing KMS preview endpoint and Python vault.kms.preview contract.
Counts/blockers are labelled as such, missing counts remain unknown, and no
activation/migration/move is requested. This does not implement an affected-entry
list or complete cross-boundary move preview. The runnable example includes
paired actual HTTP/Mongo and PTY checks; its authentication remains synthetic.