6db08a5eb3
gates / gates (push) Successful in 1s
update_ladder: in .felhom.yml, one JSON entry per line (spiked live on controller v0.266.0 and v0.267.0 first). Two gates: check-test-record.py (static, CI too) and check-test-record-move.py (history + registry for moved refs only). 16 decoys, 3 red-proofs. The ONLY writer is upgrade-test.py --write-ladder (bench AND box proven, digests resolved). Harness v3: box fixtures on the bench, files_may_change. Backfill: the 21 moves of 2026-09-22, 21 proven from their records. No image: line moved. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
1.4 KiB
1.4 KiB
REPORT — the test record and its gate (night 2026-09-23, Part B)
09-update-architecture.md §3 decision 13, §6.4 part 4 and the catalog half of part 6. Night record:
felhom.eu/documentation/audits/DRILL-night-2026-09-23.md; evidence …/night-2026-09-23/B*.
Not done, or changed
- The brief's "
check-image-resolvable.pyalready resolves digests" is only half true: it asksdocker manifest inspectwhether a ref EXISTS and discards the digest. The digest comes from the newimage_digest.py, whose answer equals Docker'sRepoDigestson a box (positive control). - The move gate uses the network in the hook — for moved refs only. Decided by CC unattended (it is the only way a push-time "digest matches the registry now" can be asked); operator may reverse.
- Backfilled digests are TODAY's registry answer, not a measurement of the image that was tested.
- Step definitions for intermediate steps (
steps/<to>.yml, part 5) are not written — no app has two steps yet.
What shipped
Format + spike, two gates (16 decoys, 3 red-proofs), the writer (5 tests), harness v3 (box fixtures on
the bench; files_may_change), image_digest.py, the backfill (21 proven).
Gates
catalog_gates.py --fast all OK; test_gate_decoys.py 80 cases OK; test_ladder_writer.py OK;
test_catalog_gates.py OK after this commit (its shallow-clone case needs the new scripts committed).