56c4888f5e
gates / gates (push) Successful in 2s
The ONLY image move in this commit; the limit rides it (09 decision 39's precedent), because the step itself re-runs immich's geodata import (228 294 -> 228 571 places) — the load that killed the database. Cause, measured on the bench (audits/immich-first-start-2026-09-30/A-cause.md): the first-start import runs up to 9 concurrent 5000-row INSERTs; the database then needs ~400 MB anon + ~170 MB touched shared_buffers (the image's own postgresql.conf fixes 512MB). At 512M with no swap: 61 kills; with 512 MB swap: 0 (swapped ~70 MB) — why 9202 passed; shared_buffers 128MB alone: still killed; 1024M: 0; 768M: 0. Proof at the new definition, fresh install from birth, no swap: bench x2 (anon 409/412 MB = 53 %, 0 kills, import 8.1 s) and box 9202 (anon 368 MB = 48 %, 0 kills, swap.peak 0). Step, written by upgrade-test.py --write-ladder: bench (harness v4) proven, 10-min watch 0 kills 0 restarts, anon peak 51.1 %; box 9202 through the guarded Update: done 58.5 s, album read back, the running database limit 805306368 after. The step carries `files_may_change` (the harness saw only immich's six 13-byte `.immich` folder markers rewritten at start) — the night leg takes it only with a whole copy. Per-box cost: +256 MB on immich-postgres; `mem_limit` 4096M -> 4480M (the old figure was already 128 MB under the sum of the four limits). Header comment corrected (it said postgres 256M). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS