--- type: limitation title: Reboot with the clock wound forward ends a block tags: [deadline, clocks] --- A block stores two anchors: a `CLOCK_REALTIME` deadline and a `CLOCK_BOOTTIME` deadline, plus the boot id the boottime anchor was taken under. Remaining time is the maximum of the two, so a block ends only when both agree it has. That closes both single-clock attacks. Winding the clock forward expires the realtime anchor while boottime keeps running. Winding it back leaves realtime running. It does not close the pair. `CLOCK_BOOTTIME` resets on boot, so after a reboot its anchor describes a clock that no longer exists and realtime is all that survives. Reboot with the clock wound forward and the block ends. Closing it would mean trusting a monotonic value across boots, and the box has no such value that a root user cannot also write. The hole is pinned by a test in `tests/deadline.test.sh` so it stays a decision rather than becoming a regression.