linux observer

close the audit gaps in stale-key recovery master

Restore cmd_setup to its original single whole-config write via the new save_config_with_identity, removing the two-write partial-failure window the audit found. All three config writers now funnel through one locked read-modify-write. This one-line API swap inside cmd_setup was unavoidable after save_config became identity-preserving; the function's behavior is unchanged. Correct test coverage that overstated what it proved. AC 8 now documents that the persist window is await-free and pins the only two exact reachable disk identities. AC 13 proves the single-attempt bound structurally by asserting exactly one register request during a stalled relay. AC 5 now asserts that the on-disk identity is byte-identical after a register-route 403, and AC 15 gains its missing one-rejection and zero-rejection silence cases. Reset dropped_events whether or not the outcome record is admitted, so a suppressed outcome cannot inflate a later record and the count remains the lower bound its caveat claims. Remove the write-only suppressed_records state. Align ensure_registered's guard-refusal record with the recovery guard record, while documenting that CLI one-shot setup deliberately does not consume the daemon telling window. Rename stale sync tests and repoint AC comments that collided with this arc's numbering. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>


+159 -44
4 changed files