# M6 Backup, Verification, and Restore Evidence - Coverage: local full-snapshot staging; immutable SHA-256 blobs; canonical Ed25519-signed manifests; manifest/blob verification; publication markers and startup reconciliation; selected and dry-run restores; `fail`, `skip`, and `replace` root policies; destination containment; corruption handling; and restore recovery. - Focused acceptance: the M6 integration, publication-fault, and restore-path suites pass. - Full verification: `make check` passed with 68 unit/contract, 37 integration, 7 fault, and 17 security tests, plus Ruff, mypy, frontend typecheck, and frontend production build. - Scope: excludes M7 incremental baselines/exclusions and later scheduling, remote source, encryption, retention, and UI milestones.