test record: an image move must carry its proof (09 decision 13, part 4)
gates / gates (push) Successful in 1s

update_ladder: in .felhom.yml, one JSON entry per line (spiked live on
controller v0.266.0 and v0.267.0 first). Two gates: check-test-record.py
(static, CI too) and check-test-record-move.py (history + registry for
moved refs only). 16 decoys, 3 red-proofs. The ONLY writer is
upgrade-test.py --write-ladder (bench AND box proven, digests resolved).
Harness v3: box fixtures on the bench, files_may_change.
Backfill: the 21 moves of 2026-09-22, 21 proven from their records.
No image: line moved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-23 20:52:32 +02:00
parent cfcfe52784
commit 6db08a5eb3
38 changed files with 2944 additions and 37 deletions
+18 -21
View File
@@ -1,25 +1,22 @@
# REPORT — the upgrade harness watches memory (2026-09-23)
# REPORT — the test record and its gate (night 2026-09-23, Part B)
**Test code only.** No template was changed; no `image:` line moved; the diff touches exactly
`scripts/upgrade-test.py`, `scripts/upgrade_fixtures.py`, `CHANGELOG.md` and this file.
`09-update-architecture.md` §3 decision 13, §6.4 part 4 and the catalog half of part 6. Night record:
`felhom.eu/documentation/audits/DRILL-night-2026-09-23.md`; evidence `…/night-2026-09-23/B*`.
## What was done
## Not done, or changed
- The brief's "`check-image-resolvable.py` already resolves digests" is only half true: it asks `docker
manifest inspect` whether a ref EXISTS and discards the digest. The digest comes from the new
`image_digest.py`, whose answer equals Docker's `RepoDigests` on a box (positive control).
- The move gate uses the network in the hook — for moved refs only. Decided by CC unattended (it is the
only way a push-time "digest matches the registry now" can be asked); operator may reverse.
- Backfilled digests are TODAY's registry answer, not a measurement of the image that was tested.
- Step definitions for intermediate steps (`steps/<to>.yml`, part 5) are not written — no app has two
steps yet.
The RomM lesson (R-635): a walk proves "the update applied and the data survived", not "the new
version runs". `upgrade-test.py` v2 adds a **memory watch** after a successful readback — `--soak`
seconds (default 600) of light load, sampling the kernel's `oom_kill` counter host-side, the peak
against the compose limit, and restarts. Kill or restart → `failed`; peak > 80 % → mark
`memory_tight`. New `Romm` fixture and edges `M1` / `M1old`.
## What shipped
Format + spike, two gates (16 decoys, 3 red-proofs), the writer (5 tests), harness v3 (box fixtures on
the bench; files_may_change), `image_digest.py`, the backfill (21 proven).
## Red-proof (scratch guest 9202, `/opt/upg`, removed afterwards)
| edge | template | verdict | memory |
|---|---|---|---|
| **M1old** | as promoted (`15f9ebf`): 512M, 4 workers | **failed** | first OOM kill at **+76 s**, peak 100 % of 512 MiB, restarts 0 |
| **M1** | current: 768M, 2 workers | **proven** + mark `memory_tight` | 608.5 s under 11 429 requests (5 712 × 200, 5 717 × 401): **0 kernel OOM kills, 0 restarts**, peak 621 MiB = **81 %** of 768 MiB — the watch passes the fix and still flags the thin headroom R-635 left open |
`C3` (the standing negative control) was not run: its `container_name: privatebin` collides with the
privatebin the controller runs on 9202. The M1old/M1 pair is this step's own control.
Gates: `python3 scripts/catalog_gates.py --fast` → all OK.
Full session report: `felhom.eu/REPORT.md`; evidence `felhom.eu/documentation/audits/update-rulings-2026-09-23/`.
## Gates
`catalog_gates.py --fast` all OK; `test_gate_decoys.py` 80 cases OK; `test_ladder_writer.py` OK;
`test_catalog_gates.py` OK after this commit (its shallow-clone case needs the new scripts committed).