fix(replication): preserve SSE-KMS tag timestamps

Carry the already-parsed source tagging timestamp through the KMS options
constructor so replica COPY can apply newer tag updates on explicitly or
automatically encrypted destinations.

Cover all option encryption modes and signed COPY persistence for newer,
stale, duplicate and timestamp-less updates, including bucket defaults.
Preserve the real Opus 5.0/max plan review, consensus and local validation.

Signed-off-by: Feng Ruohang <rh@vonng.com>
This commit is contained in:
Feng Ruohang
2026-09-15 23:56:31 +08:00
parent 9ebe81c1b3
commit 03027727d1
10 changed files with 867 additions and 3 deletions
@@ -0,0 +1,36 @@
{
"baseline": "9ebe81c1b3611f9cc73e676b5b741c2be62c467a",
"plan": "docs/investigations/r4/plan-v1.md",
"plan_sha256": "ad539f2071155de6955b583991684ed33c4bfe2e29660005840cdc97d7e1a754",
"requested_model": "claude-opus-5",
"requested_effort": "max",
"cli_version": "2.1.270",
"started_at": "2026-09-15T15:45:46.438630+00:00",
"status": "completed",
"raw_output": "/Users/vonng/tmp/silo-r4-evidence-20260915-a9cb/opus-review-v1.jsonl",
"raw_stderr": "/Users/vonng/tmp/silo-r4-evidence-20260915-a9cb/opus-review-v1.stderr.log",
"command": "/opt/homebrew/bin/claude --print --model claude-opus-5 --effort max --safe-mode --permission-mode plan --tools Read,Grep,Glob --strict-mcp-config --no-session-persistence --add-dir /Users/vonng/tmp/silo-r4-evidence-20260915-a9cb --output-format stream-json --verbose",
"completed_at": "2026-09-15T15:49:48.150062+00:00",
"assistant_models": [
"claude-opus-5"
],
"observed_model": "claude-opus-5",
"verdict": "GO_WITH_NONBLOCKING_NOTES",
"blocking_findings": 0,
"result_subtype": "success",
"is_error": false,
"session_id": "63e14a68-8565-41fa-9746-3e405fb63e9f",
"duration_ms": 161784,
"num_turns": 35,
"used_tools": {
"Read": 18,
"Glob": 4,
"Grep": 11,
"Write": 1
},
"stream_sha256": "eb0918d8a6185b180dddcfc664a96682f05502ecf3b686b08a0547f09879d57d",
"review_sha256": "e1dc12dd99326ae432623ff8de201813e6e84e7ed16a5556c21f9c514d663676",
"prompt_sha256": "07c225beff1523e056c154b3a387cf1ae345def4b4d0173065b882140ac5abdf",
"tool_scope_note": "Read/Grep/Glob allowed. Claude attempted Write to its own plan; the tool was disabled and no file was written. git diff before consensus showed no production source changes.",
"auxiliary_model_note": "assistant_models records actual reviewing assistant messages. Auxiliary usage is distinct. --effort max is explicit in the command, not inferred from model usage."
}