3525e355a1
gates / gates (push) Successful in 0s
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
3.0 KiB
3.0 KiB
REPORT — MariaDB finishes its own conversion, and the engine-major gate (2026-09-13)
Overwritten each run. This records the most recent implementation only. The full run — golden bake,
the golden waiver, the live observation on demo-hp — is in felhom.eu/REPORT.md.
What changed in this repo
templates/{bookstack,kimai,nextcloud,romm}/docker-compose.yml—MARIADB_AUTO_UPGRADE=1on the db service, with a comment pointing at the spike. No image line moved;catalog_sinceuntouched.scripts/check-engine-major.py(new) — refuses amariadb:/postgres:pin that crosses a major between the two ends of a push range. Exit 0 / 1 REFUSED / 2 INCONCLUSIVE.scripts/catalog_gates.py— fourth row,--fast,--range=passthrough, announced skip on a shallow clone.scripts/test_catalog_gates.pypins the table and the skip (7 tests green).scripts/test_gate_decoys.py(new) — theCOVERSliteral forfelhom.eu's decoy-coverage gate and seven cases (three facts refused / inconclusive, one genuine and three decoys passing)..githooks/pre-push— computes--range=<remote sha>..<local sha>from git's stdin refs.CLAUDE.md— the engine-major rule with its expiry condition (R-448 → remove, tracked as R-469).REUSE.md— one convention row for the MariaDB sidecar env; the gates row now lists four.
Harness verdicts (Scenario A and B) — engine-state field quoted
| edge | verdict | engine_state_after.bookstack-db.answer |
|---|---|---|
| C3 | failed (negative control intact) |
— |
| E3 | proven |
12.3.3-MariaDB | This installation of MariaDB is already upgraded to 12.3.3-MariaDB. There is no need to run mariadb-upgrade again. [exit=1] |
| E3b | proven |
same |
skipped due to $MARIADB_AUTO_UPGRADE: 0 lines in both TO logs. Conversion lines, verbatim:
[Entrypoint]: Starting mariadb-upgrade at 09:53:20 → Finished mariadb-upgrade at 09:53:26 (E3).
Gate texts (Scenario D)
Refusal, verbatim (from the red-proof on a scratch clone):
ENGINE-MAJOR GATE FAILED: templates/kimai/docker-compose.yml service kimai-db moves mariadb 11 -> 12 (mariadb:11.6 -> mariadb:12.3).
RULE (app-catalog CLAUDE.md, operator ruling 2026-09-13): until the Update button takes a VERIFIED BACKUP as its precondition (Slice 4, felhom.eu OPEN-ITEMS.md R-448), no template may move a database-engine image across a MAJOR version.
EXPIRY: this rule is removed DELIBERATELY when R-448 ships — the removal is its own register row, not a silent edit. Until then, keep the engine within its major.
Pass, verbatim (this push's own range, 4 compose files, 4 engine pins compared):
engine-major gate OK — no database engine crosses a major version (rule: CLAUDE.md, until Slice 4 / R-448 ships)
Honest limits
- CI cannot run the engine-major gate yet —
.gitea/workflows/gates.ymlfetches at--depth 1. The runner announces the skip; enforcement is the pre-push hook. Same gap as R-452, not re-filed. - The harness proves the DATABASE half of bookstack only (R-460); the file half needs a browser.