Files
app-catalog-felhom.eu/REPORT.md
T
admin bd22749e50
gates / gates (push) Successful in 1s
REPORT for the R-469 rule lift
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-21 12:59:35 +02:00

71 lines
4.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# REPORT — the engine-major rule, half lifted (R-469 + R-450)
**Base `18a6d2d8243e` → `5ff36d098cbc`.** No template moved. Architecture read first and named:
`felhom.eu/documentation/architecture/09-update-architecture.md` §3 decision 5 (the 2026-09-13 ruling
and its three precautions) and §6.1 (slice 4 as shipped).
## Why now
The rule of 2026-09-13 named its own expiry — *until the Update button takes a verified backup as its
precondition* — **precisely so it would be removed deliberately rather than forgotten.** That
condition was met the same day: update arc Slice 4 shipped (controller v0.237.0/v0.238.0; any backup
tier since v0.239.0). R-469 exists to make the removal a reviewed diff. This is it, and it removes
exactly half.
## What changed
- **LIFTED — MariaDB.** The four `mariadb:` sidecars (`bookstack-db`, `kimai-db`, `nextcloud-db`,
`romm-db`) may cross a major. They now have both halves: a verified backup in front of the Update,
and `MARIADB_AUTO_UPGRADE=1` (R-459) whose conversion the harness WATCHED run on the E3/E3b edges
with the seeded data read back after.
- **NOT LIFTED — PostgreSQL and MySQL.** Postgres performs no `pg_upgrade` and REFUSES to start on an
older major's datadir, across eleven templates (R-463). **A backup is a route BACK, not a
conversion** — the app would simply not come up. MySQL has nothing measured at all. The refusal
text now says this, instead of citing the shipped R-448.
- **NEW — one edge, one migration (R-450's second half, recorded 2026-09-02, enforced now).** A
MariaDB major must be the ONLY image move in its template in that commit. bookstack's `0b73e5e`
moved the application 25.02.2 → 26.05.2 **and** MariaDB 11.6 → 12.3 together: two migrations behind
one edge, and an unreadable failure when it breaks. The refusal names what it was bundled with.
**Within a major is unaffected** and may still ride with anything.
- **The gate PRINTS what it allowed**, by name and with the reason, rather than passing in silence. A
lifted rule that goes quiet is a lifted rule nobody can audit.
## Red-proofs — two, each SEEN to fail
| the mutation | what failed |
|---|---|
| drop the own-edge check (`others = []`) | *FACT: kimai-db 11.6 → 12.3 BUNDLED with the kimai app bump: rc=0 expected 1* — the bookstack shape passes |
| empty `LIFTED` | *GENUINE: kimai-db 11.6 → 12.3 ALONE (the R-469 lift): rc=1 expected 0* — the lift is undone |
Both reverted; **40 decoy cases green**. The old *"a lone MariaDB major is REFUSED"* case is now the
*"…is ALLOWED"* case — that inversion is the lift itself. A third case pins the bundled PostgreSQL
shape.
`catalog_gates.py --fast`: image-pins, engine-major, catalog-since, copy-i18n — **all OK**. The
pre-push hook ran and passed; no `--no-verify`.
## Measured while here, and it belongs in this repo's record
A read-only sweep of all 66 unique pins against the public registries, from DooPlex, never from a box
(`felhom.eu/documentation/audits/UPDATE-ARC-STATE-2026-09-21.md` §3):
- **46 of 58 exact pins are behind upstream today**; 39 within a major, 7 across one. The seven were
all pinned 2026-07-18: nextcloud 34→35, paperless-ngx 2.20→3.2, claper 2.5→3.0, gokapi 1.9→2.2,
homepage 1.13→2.4, sparkyfitness 0.17→1.7 (two images).
- **6 of the 7 measurable floating pins have been repushed upstream since the catalog set them** —
`postgres:16-alpine`, `postgres:15-alpine`, `redis:7-alpine`, `mariadb:11.4`, `mariadb:12.3`,
`postgis:16-3.5-alpine`. Only `mariadb:11.6` has not. This is R-446 measured rather than theorised,
and it is the case for recording digests at push time (put to the operator as `09` §3b Q6).
- **`msdeluise/plant-it:0.10.0` is gone upstream.** The repo's own gate says INCONCLUSIVE (it refuses
to read a `denied` stderr as "dead", correctly); two independent signals say it really is gone —
Docker Hub's catalog API answers `object not found` for the whole repository, and the upstream
GitHub repo 404s. The app is already `lifecycle: abandoned`, so this is the expected end state, not
an incident. A deployed plant-it survives; it can never be redeployed.
## Rows
**R-469 PARTLY CLOSED** (MariaDB lifted; the PostgreSQL half stands until R-463).
**R-450 half SHIPPED** (the own-edge clause; the automatic-within-a-major half is Slice 6 and awaits
`09` §3b Q1–Q4). **R-605 filed** — a catalog gate that refused to run and one that ran and could not
decide print the same word.