Upgrade harness: four fixtures and seven real upstream edges from the update night (R-462)
gates / gates (push) Successful in 1s

Test code only — no template changed and no image: line moved.

The update night walked real within-a-major upstream edges on scratch guest 9202 through the
product's own guarded Update, against a PRIVATE DRILL CATALOG; the live catalog was never
touched. This brings the expensive half of that work — the seed routes — back into the harness
so the same edges can be run here WITH their ABORT step, which the box deliberately does not
offer (09 6.1: whether the old image starts on migrated data is per-app and unpredictable).

- upgrade_fixtures.py: ActualBudget, Navidrome, AudiobookShelf, Vikunja. Each seeds through the
  app's OWN interface (R-156); each carries a negative control run on every verify(), so a
  readback that has broken into always succeeding fails instead of passing everything.
- upgrade-test.py: edges U1..U7, all real upstream moves existing 2026-09-21 that this catalog
  has NOT made, each holding its database engine constant.
- Limitations kept: Navidrome and AudiobookShelf seed the DATABASE half only, and say so.

OWED, stated so it is not mistaken for done: the U1..U7 harness RUNS, and with them the per-app
ABORT answers. The code is in; the runs are not.

Gates: catalog_gates.py --fast — image-pins, engine-major, catalog-since, copy-i18n all OK.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-21 21:00:50 +02:00
parent f5f6a152b5
commit 4463243f2e
4 changed files with 320 additions and 61 deletions
+28
View File
@@ -1,3 +1,31 @@
## Upgrade harness: four new fixtures and seven real upstream EDGES (2026-09-21, R-462)
**Test code only. No template changed, and no `image:` line moved.** The update night
(`felhom.eu/documentation/audits/DRILL-update-night-2026-09-21.md`) walked real within-a-major
upstream edges on scratch guest 9202 **through the product's own guarded Update**, each app seeded
and read back through its own front door. This commit brings that work back into the harness so the
same edges can be run here **with their ABORT step**, which the box deliberately does not offer
(`09` §6.1: the box never puts the old version back by itself, because whether the old image starts
on migrated data is per-app and cannot be predicted).
- **`upgrade_fixtures.py` — four new fixtures**: `ActualBudget` (its own bootstrap + login),
`Navidrome` (`/auth/createAdmin` + `/auth/login`), `AudiobookShelf` (`/init` + `/login`) and
`Vikunja` (register → login → create project → authenticated readback). Every one goes in through
the app's OWN interface (R-156) and every one carries its own negative control, run on every
`verify()`: a wrong password, or an id that cannot exist, must NOT read back — so a readback that
has broken into always succeeding fails instead of passing everything.
- **`upgrade-test.py` — seven new edges, `U1`–`U7`**, all REAL upstream moves that existed on
2026-09-21 and that this catalog has NOT made: privatebin 2.0.5→2.0.6, docmost 0.95.0→0.96.0,
bookstack 26.05.2→26.05.5, actualbudget 26.7.0→26.9.0, navidrome 0.63.2→0.64.0,
audiobookshelf 2.35.1→2.36.1, vikunja 2.3.0→2.6.0. Each holds its database engine CONSTANT, per
the standing rule that an engine change gets its own edge.
- **Limitations kept rather than papered over.** `Navidrome` and `AudiobookShelf` seed the DATABASE
half only — the library on the drive is not populated — and both say so in their docstrings, as
`BookStack` already does for its file half (R-460).
**Owed, and stated so it is not mistaken for done: the harness RUNS.** The code is in; the U1–U7
runs, and with them the per-app ABORT answers, have not been performed.
## RULE LIFT: a MariaDB major may cross, as its OWN EDGE; PostgreSQL may not (2026-09-21, R-469 + R-450)
The engine-major rule of 2026-09-13 named its own expiry — *until the Update button takes a verified