# Evidence Task 5C report ## Delivered - Added `vector.retain_published_generations` (default `3`, validation minimum `1`). - Retention runs only after publication. It keeps ACTIVE, the newest configured generations, and generations referenced by running or resumable failed job checkpoints. - Cleanup deletes the exact Evidence generation from the vector store before removing its immutable filesystem directory. Vector failures retain filesystem metadata for retry and produce credential-free partial reports. - Added idempotent `tht preprocess evidence gc [--dry-run] --json` reconciliation with pristine JSON output. - Materialized document reads now open generation/documents components with directory file descriptors and `O_NOFOLLOW`, require a regular file owned by the process with one link, and hash the bytes read from the same descriptor against the canonical manifest. - HTTP generation deletion is pinned to `delete_vector_generation` with exact table/kind/generation arguments. Legacy 404 responses fail closed with an actionable, sanitized migration message. ## Evidence - Focused retention, safe-read, CLI, and HTTP contract tests: `51 passed` (Docker-backed direct parametrizations excluded from that focused invocation). - Real Docker pgvector adapter suites: `33 passed`. - Full harness suite, including Docker-backed tests: `668 passed, 5 deselected`. - Changed-file Ruff: clean. - `git diff --check`: clean. The five deselected tests are the repository's opt-in `l2` tests requiring external services; they are not local pgvector tests. Test output retains pre-existing Pydantic serialization and legacy-config deprecation warnings.