# Worldtree U11a: legacy memory plane OFF; U11b deletion gated; legacy archive (2026-09-30) `[2026-09-30]` Prime ruled at 0100, in worldtree-dev's session (thread `01M3RNRC8RE87AJ3M6XBNVHAYP`): the legacy plane goes OFF, not read_only, on demo AND personal, as soon as the b192 image (64f79b38) lands. The read_only window was skipped. Accepted risk: skaldsong/wizard-v2, personal's only Tier-3 client, is not remembered until it adopts the record profile. **The flips:** - Config went through the config repo, `~/development/worldtree-instance-configs`, and was deployed with `deploy-wt-config`: - 63cf268 sets writer and reader enabled and `legacy.mode: "off"`; - 0a1387e captured the U10 memory_tagger and U9 forget-policy host edits that had never reached the repo; - b6fdd81 enables the #308 metrics on personal. - DEMO flipped at 0115 and PERSONAL at 0120. The gauge reads `worldtree_memory_legacy_mode{kind="off"} 1.0` on both; personal's reading came after its metrics were added at 0124. - ⚠ `off` MUST be quoted. PyYAML safe_load is YAML 1.1, so a bare `off` becomes False and the strict LegacyMode enum refuses the boot. I found this at the first flip; worldtree-dev later made the loader say "write it quoted" (7a83f2f1). - Rollback: `legacy.mode: "live"` in the repo, then deploy. **The U11b gate (Prime 0320 via worldtree-dev, thread `01M3SGEQDRQD7DWBVT4K73FAHP`):** - DELETE the live legacy data on both instances after **3 consecutive PASS batches at off**. A FAIL restarts the count. - infra-hermes runs the daily batch, `scripts/wt-memory-gate-batch`, in a detached worktree at demo's deployed sha. Its exit codes are 0 PASS / 1 FAIL / 2 error / 3 refused / 4 busy. - Count: 20260930T090608Z PASS (user median 0.83). That run started by accident from a test meant to be `--dry-run`. worldtree-dev's controls 080927Z and 082829Z each FAILed by one flip and were the instrument check, not the streak. - Step 5 is mine: 1. Run `scripts/wt-h2-count.py` VERBATIM inside each api container. The rehearsal on copies read 0 on both instances. 2. Delete LIVE, with the api running, using literal paths. 3. Send worldtree-dev the stamp. - b192 re-creates an empty `context_promotion/ledger.db` at boot; that is residue. - `/embed` retires in b193. Evidence from the Skuld ledger: demo had 436 calls, the last on 08-31; personal had 5, the last on 08-05. Demo's ledger has been idle since 09-14. **Legacy archive (worldtree-dev GO, done 0957, restore drill passed):** - corviduo-dev `/var/lib/wt-legacy-archive/` (root 0700, unencrypted): tar.zst plus per-file sha256 plus MANIFEST, demo 51 files and personal 1,426. - A DEDICATED restic repo: rest-server-nh3 `/nh3-dev/wt-legacy-archive/`, snapshot `98dc64e0`, password `nh3-dev/wt-legacy-archive/restic-password`, mirrored to ana-nas. It is NOT in the main /home sweep, whose 12-month retention would break the 30-day rule. - The drill: every file's sha matched, sqlite integrity_check was ok, and the one-flipped-byte negative control was caught. - **Contract rev 1.2: DESTROY WHOLE at retirement-done or 2026-10-30, whichever is first, or on any subject-erasure request.** 1. `rm /var/lib/wt-legacy-archive` on corviduo-dev. 2. `rm /volume1/Backup/restic/nh3-dev/wt-legacy-archive` on nh3-nas. 3. The ana-nas mirror's `--delete` follows; verify it. 4. `secret rm` the password AND purge Vaultwarden's trash (crypto-shred), and check for NAS share snapshots.