Crew State Integrity — cumulative execution record

One anchor per landed node. Each entry records the commit, the gate measure as executed, the tests, and anything negative found on the way. The evergreen plan holds the design; this record holds what actually happened.

Envelope write safety (locked writes, corrupt refusal, retry backoff)

Commit 22074d2ab1ba978d86050496b853a85ea88c9c58 (2026-08-16, worker codex-a, 479 s, 217 insertions / 27 deletions over reckon/_store.py, reckon/ledger.py, tests/test_store_concurrency.py, tests/test_ledger.py).

Tests: 4 added; focused run 78 passed; full suite 1869 passed, 0 failed (88 s). Logs: ~/.config/reckon/crew/runs/r-20260816T204725505930-envelope-write-safety/logs/.

Pointer lifecycle recovery (duplicate promotion, discard, locked pointer writes)

Commit bcc11e2b1d469fd3d798cbc152c6d5f4a0719c2a (2026-08-16, worker codex-a, 578 s, 368 insertions / 96 deletions over reckon/crew.py, reckon/cli.py, tests/test_crew.py; fast-forwarded).

Tests: 4 added; focused run 84 passed (9 s); full suite 1875 passed, 0 failed (81 s) on the tree that already contained both earlier landings — this run is the integrated-suite evidence for the plan gate. Logs: ~/.config/reckon/crew/runs/r-20260816T205950003711-pointer-lifecycle-recovery/logs/.