Skip to content

Failure model ​

ConfigOps is designed to lose capability before it invents certainty. The host settings request must keep working even if observation fails; the resulting evidence is marked incomplete and unsafe whole-change actions disappear.

Fail-closed matrix ​

ConditionConfigOps behaviorOperator response
Evidence storage failsReports an internal observation error without breaking the host save; evidence becomes incompleteVerify the actual setting, database health, and logs; do not trust the observation as complete
Named-session stop summary cannot be verifiedThe Change Session stays active for safe retry or recovers to interruptedRetry stop after storage health is restored; inspect before any undo
Evidence finishes after a named-session stop boundaryThe observation is marked incompleteReview for investigation only; whole-change undo remains unavailable
Probable secret detectedStores a redacted marker, not plaintextRe-enter credentials manually if the setting must be changed back
Value exceeds safe shape or depthKeeps bounded, non-restorable evidenceUse plugin-native controls or a tested backup
Adapter absent or version outside rangePreserves generic evidence; disables adapter-dependent undoVerify against the exact plugin version or update the adapter contract
Experimental array target or structure changedRefuses the complete generic patch without writingRe-review the current plugin setting; use its native screen or a fresh capture
Current value changed after observationReturns a conflict and performs no target writeReview newer work and choose the intended state manually
Referenced local object missingRefuses the restoreRecreate/select a valid object, then use the native settings screen
Operation lock unavailableRefuses concurrent restore or maintenanceWait for the active operation; investigate a stale lock if it does not clear
Retention runs while restore owns the scopeRefuses cleanup and preserves the evidenceLet the restore finish; the next scheduled or manual retention run may retry
A later write in session undo failsAttempts compensation for earlier writes and records the outcomeVerify every affected setting; treat compensation failure as an incident
Unknown custom-table writeStores a value-free signal onlyUse the owning plugin’s tools or a database backup
ConfigOps is deactivated during a Change SessionCloses the session as interrupted and incompleteReactivate, verify site state, and start a new bounded Change Session

What ConfigOps protects ​

  • It does not allow observation failures to fail the original WordPress settings request.
  • It redacts before persistence and never treats browser intent as write authority.
  • It verifies current state before undo and serializes restore with evidence retention in the same site or network scope.
  • It records value-free restore outcomes before and after writes.
  • It does not call incomplete evidence complete.

What still needs operational controls ​

ConfigOps cannot guarantee availability, detect every possible secret name, or reverse external side effects. Production use still requires backups, least-privilege administration, database monitoring, staging for risky changes, and a recovery procedure independent of this plugin.

For concrete preflight and verification steps, see Undo safely and Operations.

Local evidence. Explicit limits. No account required.