test record: an image move must carry its proof (09 decision 13, part 4)
gates / gates (push) Successful in 1s

update_ladder: in .felhom.yml, one JSON entry per line (spiked live on
controller v0.266.0 and v0.267.0 first). Two gates: check-test-record.py
(static, CI too) and check-test-record-move.py (history + registry for
moved refs only). 16 decoys, 3 red-proofs. The ONLY writer is
upgrade-test.py --write-ladder (bench AND box proven, digests resolved).
Harness v3: box fixtures on the bench, files_may_change.
Backfill: the 21 moves of 2026-09-22, 21 proven from their records.
No image: line moved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-23 20:52:32 +02:00
parent cfcfe52784
commit 6db08a5eb3
38 changed files with 2944 additions and 37 deletions
+25
View File
@@ -1,3 +1,28 @@
## The test record: an image move must carry its proof (2026-09-23 night, `09` §6.4 part 4 + the catalog half of part 6)
**No `image:` line moved in this commit.** 21 templates gain an `update_ladder:` (backfill); scripts only otherwise.
- **Format** (`scripts/ladder.py`): `update_ladder:` at the end of `.felhom.yml`, one JSON flow mapping
per line — `from`/`to` per service, `digest` per `to` ref, `verdict` (proven | unrecorded), `tested_at`,
`harness_version`, `evidence`, `memory_peak_pct`, `marks` {files_may_change, needs_person,
memory_tight}, optional `backfilled`. **Spiked live first:** controller v0.266.0 and v0.267.0 on scratch
guest 9202 synced, deployed, probed and badged navidrome with the block exactly as without it.
- **Gates** (rows 8 and 9 of `catalog_gates.py`, both in `--fast`): `check-test-record.py` (static, runs in
CI) and `check-test-record-move.py` (history; the registry is asked ONLY for refs a range moves — an
unreachable registry is INCONCLUSIVE, never a pass). 16 decoy cases in `test_gate_decoys.py` (both
directions); three red-proofs seen failing (bare move, a `failed` entry, a digest mismatch).
- **The writer**: `upgrade-test.py --write-ladder` (bench AND box `proven`, template at FROM, digests
resolved, memory peak as a percent) — `test_ladder_writer.py`. `--move <app> <svc>=<ref>` builds an edge
from the template. Harness v3: the box walk's fixtures run on the bench (`upgrade_boxport.py`,
`upgrade_fixtures_box*.py` ported verbatim — R-462), and a bind-mount tree hash sets `files_may_change`.
- **`scripts/image_digest.py`** resolves a ref's digest (stdlib only); positive control: it equals the
`RepoDigests` Docker recorded for `privatebin/pdo:2.0.6` on 9202.
- **Backfill** (`ladder_backfill.py`): the 21 moves of 2026-09-22, each from the record its commit cited —
**21 proven, 0 unrecorded** (nextcloud's commit cited none; its record `nextcloud-engine-mariadb` was
named and the entry says so). romm carries its memory watch (M1, 80.9 %, `memory_tight`). Digests are
what the registry serves TODAY, and each entry says that.
- `test_catalog_gates.py`: its table test had been stale (asserted 5 gates while there were 7); now 9.
## The upgrade harness watches memory after the readback — the RomM lesson (2026-09-23, R-635/R-462)
**Test code only. No template changed; no `image:` line moved.** `scripts/upgrade-test.py` (harness