Atomically persist signing workflow records and SIGNING_OPERATION
content-owner edges through the transactional metadata store.
Use the canonical SigningSubmissionId directly as the MetadataKey,
remove the former current.bin and signing-specific .owners authority,
and recover pending signing operations only from consistent metadata
record/owner pairs.
Keep immutable staged payload and reference metadata external.
Validated:
- focused migration tests pass
- lib tests pass
- PMD and JavaDoc pass
- app compilation passes
- pki retains only the 31 independently classified credential and
revocation failures