CHANGELOG + REPORT: slice-4 live-test commits, all reverted — no net catalog change
gates / gates (push) Successful in 1s

Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-13 12:29:59 +02:00
parent 6d8c7ab4bc
commit 48d2003b7e
2 changed files with 33 additions and 45 deletions
+15
View File
@@ -1,3 +1,18 @@
## Live-test commits for controller slice 4, all reverted the same day (2026-09-13) — NO NET CHANGE
**`templates/glance` and `templates/uptime-kuma` are byte-identical to `3525e35`** (checked with
`git diff 3525e35 HEAD -- templates/glance templates/uptime-kuma` → 0 lines). The commits moved image
tags so the controller's guarded update could be proven live on demo-hp with a throwaway app:
| commit | change | reverted by |
|---|---|---|
| `a1f1c38` | glance v0.8.5 → v0.8.4 | `045495f` — glance **abandoned**: it crash-loops on a fresh install (no `glance.yml` seeded), filed felhom.eu R-473 |
| `01c631d` | uptime-kuma 2.4.0 → 2.3.2 (install from) | `28ce33b` — that revert IS Scenario A's real tag change |
| `29a8cbe` | uptime-kuma → 2.4.999 (does not exist) | `41dd686` — Scenario E |
| `6ce3f65` | uptime-kuma → alpine:3.20 (exits at once) | `6d8c7ab` — Scenario F; **reverted early** (~2 min exposure) once the update had pinned it, after the commit security review flagged that a catalog push is a deploy. No other box had uptime-kuma |
Every commit moved `catalog_since` with the image line, per the catalog rule, and every revert restored it.
## MariaDB finishes its own conversion — `MARIADB_AUTO_UPGRADE=1` on four db services, and an engine-major gate (2026-09-13, R-459 / R-469)
**Templates changed: bookstack, kimai, nextcloud, romm — the db service's `environment:` list only.
+18 -45
View File
@@ -1,51 +1,24 @@
# REPORT — MariaDB finishes its own conversion, and the engine-major gate (2026-09-13)
# REPORT — live-test commits for controller slice 4 (2026-09-13)
*Overwritten each run. This records the most recent implementation only. The full run — golden bake,
the golden waiver, the live observation on demo-hp — is in `felhom.eu/REPORT.md`.*
*Overwritten each run. This records the most recent work only. The implementation report is
`felhom-controller/REPORT.md`.*
## What changed in this repo
**No net change to the catalog.** Four image-tag commits served the live validation of the controller's
guarded update on demo-hp, and each was reverted in the same phase. `templates/glance` and
`templates/uptime-kuma` are byte-identical to `3525e35` — `git diff 3525e35 HEAD` over both → 0 lines.
- `templates/{bookstack,kimai,nextcloud,romm}/docker-compose.yml` — `MARIADB_AUTO_UPGRADE=1` on the db
service, with a comment pointing at the spike. **No image line moved; `catalog_since` untouched.**
- `scripts/check-engine-major.py` (new) — refuses a `mariadb:`/`postgres:` pin that crosses a major
between the two ends of a push range. Exit 0 / 1 REFUSED / 2 INCONCLUSIVE.
- `scripts/catalog_gates.py` — fourth row, `--fast`, `--range=` passthrough, announced skip on a shallow
clone. `scripts/test_catalog_gates.py` pins the table and the skip (7 tests green).
- `scripts/test_gate_decoys.py` (new) — the `COVERS` literal for `felhom.eu`'s decoy-coverage gate and
seven cases (three facts refused / inconclusive, one genuine and three decoys passing).
- `.githooks/pre-push` — computes `--range=<remote sha>..<local sha>` from git's stdin refs.
- `CLAUDE.md` — the engine-major rule with its expiry condition (R-448 → remove, tracked as R-469).
- `REUSE.md` — one convention row for the MariaDB sidecar env; the gates row now lists four.
## Harness verdicts (Scenario A and B) — engine-state field quoted
| edge | verdict | `engine_state_after.bookstack-db.answer` |
| commit | purpose | revert |
|---|---|---|
| C3 | `failed` (negative control intact) | — |
| E3 | `proven` | `12.3.3-MariaDB \| This installation of MariaDB is already upgraded to 12.3.3-MariaDB. There is no need to run mariadb-upgrade again. [exit=1]` |
| E3b | `proven` | same |
| `a1f1c38` | glance v0.8.4 to install from | `045495f` (glance abandoned — R-473) |
| `01c631d` | uptime-kuma 2.3.2 to install from | `28ce33b` (Scenario A's upgrade) |
| `29a8cbe` | uptime-kuma 2.4.999, non-resolving | `41dd686` (Scenario E) |
| `6ce3f65` | uptime-kuma alpine:3.20 | `6d8c7ab` (Scenario F, reverted early) |
`skipped due to $MARIADB_AUTO_UPGRADE`: **0** lines in both TO logs. Conversion lines, verbatim:
`[Entrypoint]: Starting mariadb-upgrade` at 09:53:20 → `Finished mariadb-upgrade` at 09:53:26 (E3).
**Observations**
## Gate texts (Scenario D)
Refusal, verbatim (from the red-proof on a scratch clone):
```
ENGINE-MAJOR GATE FAILED: templates/kimai/docker-compose.yml service kimai-db moves mariadb 11 -> 12 (mariadb:11.6 -> mariadb:12.3).
RULE (app-catalog CLAUDE.md, operator ruling 2026-09-13): until the Update button takes a VERIFIED BACKUP as its precondition (Slice 4, felhom.eu OPEN-ITEMS.md R-448), no template may move a database-engine image across a MAJOR version.
EXPIRY: this rule is removed DELIBERATELY when R-448 ships — the removal is its own register row, not a silent edit. Until then, keep the engine within its major.
```
Pass, verbatim (this push's own range, 4 compose files, 4 engine pins compared):
```
engine-major gate OK — no database engine crosses a major version (rule: CLAUDE.md, until Slice 4 / R-448 ships)
```
## Honest limits
- **CI cannot run the engine-major gate yet** — `.gitea/workflows/gates.yml` fetches at `--depth 1`.
The runner announces the skip; enforcement is the pre-push hook. Same gap as R-452, not re-filed.
- The harness proves the DATABASE half of bookstack only (R-460); the file half needs a browser.
1. **The glance template crash-loops on every fresh install** — the image needs `/app/config/glance.yml`
and nothing seeds it. **FILED: R-473.**
2. **A catalog push is a deploy, so a live-test tag is exposed to every new install.** The alpine tag
was reverted about two minutes after it landed; neither demo box installed uptime-kuma in that
window. **NOT-A-FINDING: the exposure was bounded and measured, and the practice is recorded here
and in the controller report.**