CONTEXT + REPORT: the night shift of 2026-09-23 (test record, 12 steps)
gates / gates (push) Successful in 2s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-24 00:23:42 +02:00
parent 5d49a11b31
commit 585a7cba22
2 changed files with 20 additions and 15 deletions
+5
View File
@@ -2,6 +2,11 @@
> Created with the REUSE.md rollout (2026-07-03). History: `CHANGELOG.md`; format spec: `README.md`. > Created with the REUSE.md rollout (2026-07-03). History: `CHANGELOG.md`; format spec: `README.md`.
- **2026-09-24 (night 2026-09-23) — THE TEST RECORD.** An `image:` move needs a proven `update_ladder:` entry
(`scripts/ladder.py`; gates `check-test-record.py` + `check-test-record-move.py`; the only writer
`upgrade-test.py --write-ladder`). 21 older moves backfilled; 12 steps published tonight. Harness v3: box fixtures
on the bench (`upgrade_boxport.py`), anon memory (`09` decision 22), `files_may_change`. Open: R-652, R-653,
R-655 (adventurelog), R-656; the box does not read the ladder yet (`09` §6.4 part 5).
- **2026-07-12 — `:latest` banned from catalog — pin rule recorded.** 5 templates pinned (bentopdf v2.8.6, calibre-web v4.0.6 = running digest on 9201, papra 26.6.1-rootless, recipe-importer v0.9.11, termix 2.5.0; all digest-equal to that day's `:latest` — no-op for running apps). Standing rule in CLAUDE.md + gate `scripts/check-image-pins.py` (run after any compose change). Deployed apps pin to their RUNNING digest; pin ≠ upgrade. - **2026-07-12 — `:latest` banned from catalog — pin rule recorded.** 5 templates pinned (bentopdf v2.8.6, calibre-web v4.0.6 = running digest on 9201, papra 26.6.1-rootless, recipe-importer v0.9.11, termix 2.5.0; all digest-equal to that day's `:latest` — no-op for running apps). Standing rule in CLAUDE.md + gate `scripts/check-image-pins.py` (run after any compose change). Deployed apps pin to their RUNNING digest; pin ≠ upgrade.
- **2026-07-03 — CLAUDE.md expanded** (repo purpose, push-to-main deploy contract, pointers); still intentionally light. - **2026-07-03 — CLAUDE.md expanded** (repo purpose, push-to-main deploy contract, pointers); still intentionally light.
- **2026-07-03 — `REUSE.md` exists at the repo root** (catalog conventions, healthcheck families, canonical example app = paperless-ngx, traps); maintenance rule active: update it in the same commit that changes a catalog-wide convention. - **2026-07-03 — `REUSE.md` exists at the repo root** (catalog conventions, healthcheck families, canonical example app = paperless-ngx, traps); maintenance rule active: update it in the same commit that changes a catalog-wide convention.
+15 -15
View File
@@ -1,22 +1,22 @@
# REPORT — the test record and its gate (night 2026-09-23, Part B) # REPORT — the test record, and 12 steps published with it (night shift 2026-09-23)
`09-update-architecture.md` §3 decision 13, §6.4 part 4 and the catalog half of part 6. Night record: `09-update-architecture.md` §3 decisions 13, 21–23; §6.4 part 4 and the catalog half of part 6. Night record:
`felhom.eu/documentation/audits/DRILL-night-2026-09-23.md`; evidence `…/night-2026-09-23/B*`. `felhom.eu/documentation/audits/DRILL-night-2026-09-23.md`.
## Not done, or changed ## Not done, or changed
- The brief's "`check-image-resolvable.py` already resolves digests" is only half true: it asks `docker - adventurelog v0.13.0 NOT moved (R-655): our frontend healthcheck override names `/nodejs/bin/node`, gone in
manifest inspect` whether a ref EXISTS and discards the digest. The digest comes from the new v0.13.0; with it dropped, the backend's start-time `download-countries` crash-looped on a cut-short download.
`image_digest.py`, whose answer equals Docker's `RepoDigests` on a box (positive control). - gitea inconclusive (installer, R-624). Step files `steps/<to>.yml` (part 5) not written.
- The move gate uses the network in the hook — for moved refs only. Decided by CC unattended (it is the - `check-image-resolvable.py` does not keep digests; `image_digest.py` was written for that.
only way a push-time "digest matches the registry now" can be asked); operator may reverse.
- Backfilled digests are TODAY's registry answer, not a measurement of the image that was tested.
- Step definitions for intermediate steps (`steps/<to>.yml`, part 5) are not written — no app has two
steps yet.
## What shipped ## What shipped
Format + spike, two gates (16 decoys, 3 red-proofs), the writer (5 tests), harness v3 (box fixtures on - Gates + format + writer + backfill: `6db08a5` (CI 920). R-612 wishlist 512M, R-613 uptime-kuma
the bench; files_may_change), `image_digest.py`, the backfill (21 proven). `UPTIME_KUMA_DB_TYPE=sqlite`: `a5a729a`. Harness fixes: `1263773`, nextcloud fixture wait.
- Published with records: romm 5.3.1 (`7ff4e68`) and mariadb 11.8 (`431cdec`), ghost 6.65.0 (`e6afab9`),
wishlist v0.67.1 + opengist 1.15 (`657c83f`), navidrome 0.64.1 (`76cc1f5`), komga 1.27.1 + 768M (`fc1becc`),
n8n 2.41.1 (`04b63db`), emby 4.11.0.3 (`8d573ad`), kimai mariadb 11.8 (`376b2c3`), immich-ML v3.2.2
(`b82b7c6`), nextcloud 34.0.4 (`5d49a11`, files_may_change).
## Gates ## Gates
`catalog_gates.py --fast` all OK; `test_gate_decoys.py` 80 cases OK; `test_ladder_writer.py` OK; `catalog_gates.py --fast` OK on every push (the move gate judged each move on the registry); decoys 80 OK;
`test_catalog_gates.py` OK after this commit (its shallow-clone case needs the new scripts committed). `test_ladder_writer.py` OK; `test_catalog_gates.py` OK (its table test had been stale since two gates ago).