Journal and Governance
Journal stages, stored governance descriptors and the limits of snapshots/rollback.
GovernanceType contains HumanRoot(String) and MultiHumanRoot { roots, threshold }. The constructor stores this descriptor, and governance() returns it. Core operations do not implement a signer collection, root rotation, or threshold-signature enforcement merely because this field is set.
JournalRecord::new(op) starts in Prepared. Supported JournalOp variants are CreateDir, WriteFile and Remove; there is no root-rotation journal variant. Mutations persist journal records in Lens as they proceed through stages. They are not a transaction over both metadata and blobs, and the core does not replay all unfinished journal operations automatically on open.
| API | Actual behavior |
|---|---|
snapshot(name).await | Writes an ID/name/time marker under /.locus/snapshots/; it does not capture a restorable filesystem tree. |
rollback(id).await | Ignores the supplied ID and writes a __rollback_marker journal record. It does not restore previous metadata or file bytes. |
fsck().await | Checks root existence and returns a missing array; it is not a comprehensive metadata/blob repair scan. |
For write authorization, inspect the feature-gated LocusPolicy call sites and enforce identity/capability checks in the application. Changing a governance descriptor is not proof that a policy transition was authorized.