{
  "title": "Prune Data-Loss (four-gate isolation)",
  "slug": "prune-data-loss",
  "claim_ids": ["E2-C001", "E2-C002"],
  "evidence_level": "fleet_codified",
  "access": "sanitized_public_excerpt",
  "source_date": "2026-05-13",
  "build_date": "2026-08-02",
  "source_commit": "24ec65306",
  "original_internal_locations": [
    "system/_operator/scripts/close-session.mjs",
    "system/_operator/scripts/promote-session.mjs",
    "system/_operator/scripts/prune-session.mjs",
    "system/_operator/scripts/deploy-session.mjs",
    "system/_operator/docs/CLOSE_PROMOTE_DEPLOY_CONTRACT.md § 1 (four-gate doctrine, I75-I78)",
    "system/caliber/lib/c112-four-gate-prune-isolation.mjs",
    "system/caliber/docs/CRITERIA.md § Criterion 112 (~L4003)",
    "system/_operator/plans/2026-05-13-promote-session-resilience-push-before-prune.md",
    "apps/rentos-canary (submodule history) + monorepo root history — INTERNAL ONLY: destroyed commit cc1fc8a, recovery commit 202cec2, gitlink re-advance 7c3205f"
  ],
  "published_artifacts": [
    "artifacts/four-gate-contract.md",
    "artifacts/prune-exit-codes.md",
    "artifacts/c112-contract.md",
    "artifacts/incident-sequence.md"
  ],
  "redactions": [
    {
      "item": "raw incident git history (destroyed commit cc1fc8a, recovery 202cec2, gitlink re-advance 7c3205f / 11faae1 / cf2afd5)",
      "action": "not published",
      "reason": "lives in the apps/rentos-canary submodule and monorepo root history; classified Internal evidence only. The incident shape is reproduced from the owner plan's Objective + Defect D1 + failure narrative instead."
    },
    {
      "item": "apps/rentos-canary app name",
      "action": "retained",
      "reason": "internal canary app, not a customer tenant; load-bearing — it establishes that the destroyed commit was internal build-tooling data, not production customer data."
    },
    {
      "item": "commit SHAs cc1fc8a / 202cec2",
      "action": "retained",
      "reason": "internal git object identifiers with no sensitive content; load-bearing — they anchor the destroy-then-reconstruct sequence that motivates the control."
    },
    {
      "item": "secrets / keys / tokens / emails / connection-strings / private URLs",
      "action": "none required",
      "reason": "mental sweep performed across all four source files and the plan; none present. Sources are framework orchestration scripts, fleet contract/doctrine, scanner logic, and an internal engineering plan."
    }
  ],
  "limitations": [
    "The original data-loss event was a one-time close-out of the Cure v2 blind-benchmark work; it is recorded in the owner plan's failure narrative and is not reproducible from this package.",
    "This package evidences a discipline/enforcement outcome on internal build tooling, not any production customer-data impact — the destroyed commit was an internal canary commit.",
    "The raw incident git history (cc1fc8a / 202cec2 and the gitlink re-advance) is Internal evidence only; its shape is reproduced via the plan's Defect D1 + failure narrative."
  ],
  "reproduction_method": "Read the four gate-script headers under system/_operator/scripts/ and CLOSE_PROMOTE_DEPLOY_CONTRACT.md § 1 (I75-I78) for the four-gate separation; read system/_operator/scripts/prune-session.mjs (EXIT map ~L74-84; reachability HALTs ~L443-461 and ~L584-600) for the fail-closed exit codes and push-before-prune ordering; run node system/caliber/lib/c112-four-gate-prune-isolation.mjs --self-test for the enforcement (must exit PASS); read system/_operator/plans/2026-05-13-promote-session-resilience-push-before-prune.md for the incident and Defects D1-D3.",
  "reviewer": "FoundryOS operator",
  "review_date": "2026-08-02"
}
