Files
app-catalog-felhom.eu/REPORT.md
T
admin 6db08a5eb3
gates / gates (push) Successful in 1s
test record: an image move must carry its proof (09 decision 13, part 4)
update_ladder: in .felhom.yml, one JSON entry per line (spiked live on
controller v0.266.0 and v0.267.0 first). Two gates: check-test-record.py
(static, CI too) and check-test-record-move.py (history + registry for
moved refs only). 16 decoys, 3 red-proofs. The ONLY writer is
upgrade-test.py --write-ladder (bench AND box proven, digests resolved).
Harness v3: box fixtures on the bench, files_may_change.
Backfill: the 21 moves of 2026-09-22, 21 proven from their records.
No image: line moved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-23 20:52:32 +02:00

23 lines
1.4 KiB
Markdown

# REPORT — the test record and its gate (night 2026-09-23, Part B)
`09-update-architecture.md` §3 decision 13, §6.4 part 4 and the catalog half of part 6. Night record:
`felhom.eu/documentation/audits/DRILL-night-2026-09-23.md`; evidence `…/night-2026-09-23/B*`.
## Not done, or changed
- The brief's "`check-image-resolvable.py` already resolves digests" is only half true: it asks `docker
manifest inspect` whether a ref EXISTS and discards the digest. The digest comes from the new
`image_digest.py`, whose answer equals Docker's `RepoDigests` on a box (positive control).
- The move gate uses the network in the hook — for moved refs only. Decided by CC unattended (it is the
only way a push-time "digest matches the registry now" can be asked); operator may reverse.
- Backfilled digests are TODAY's registry answer, not a measurement of the image that was tested.
- Step definitions for intermediate steps (`steps/<to>.yml`, part 5) are not written — no app has two
steps yet.
## What shipped
Format + spike, two gates (16 decoys, 3 red-proofs), the writer (5 tests), harness v3 (box fixtures on
the bench; files_may_change), `image_digest.py`, the backfill (21 proven).
## Gates
`catalog_gates.py --fast` all OK; `test_gate_decoys.py` 80 cases OK; `test_ladder_writer.py` OK;
`test_catalog_gates.py` OK after this commit (its shallow-clone case needs the new scripts committed).