Outcome
Turn the merged V0 baseline into a release-candidate identity/recovery boundary with a genuinely separated recovery quorum and an aggregator that never opens all holder keys. Reconcile the authoritative checkpoint documents with the merged baseline.
Baseline: e855148ffac5b2f4068ba56be6324d7b78fb430f (tree be24a07fd387c9fe10331b17507904f14f66ea71).
Blocked by
None. This card is limited to repository code, documentation, synthetic custody fixtures and disposable local/CI processes.
Acceptance
- each recovery and replacement-root holder operates one disjoint owner-only custody store;
- public, content-bound partial signatures can be produced independently;
- an aggregator validates exact bodies, roles, key IDs, thresholds, duplicates, expiry and revocation without receiving private keys;
- target authorization can also be assembled without reopening a combined root store;
- the old combined-store ceremony is removed from runtime CLI or explicitly renamed/restricted to synthetic fixtures;
- crash/retry, hostile share, missing holder and process-separation tests pass;
- RESUME.md, CURRENT-STATE.md and ROADMAP.md name the merged baseline and honest remaining gates;
- full package, conformance and supported-Python CI stay green.
Deployment: not deployed. This card authorizes no root ceremony, real key generation, external contact, host access or production effect.
Outcome
Turn the merged V0 baseline into a release-candidate identity/recovery boundary with a genuinely separated recovery quorum and an aggregator that never opens all holder keys. Reconcile the authoritative checkpoint documents with the merged baseline.
Baseline:
e855148ffac5b2f4068ba56be6324d7b78fb430f(treebe24a07fd387c9fe10331b17507904f14f66ea71).Blocked by
None. This card is limited to repository code, documentation, synthetic custody fixtures and disposable local/CI processes.
Acceptance
Deployment: not deployed. This card authorizes no root ceremony, real key generation, external contact, host access or production effect.