Files
app-catalog-felhom.eu/REPORT.md
T
admin 6db08a5eb3
gates / gates (push) Successful in 1s
test record: an image move must carry its proof (09 decision 13, part 4)
update_ladder: in .felhom.yml, one JSON entry per line (spiked live on
controller v0.266.0 and v0.267.0 first). Two gates: check-test-record.py
(static, CI too) and check-test-record-move.py (history + registry for
moved refs only). 16 decoys, 3 red-proofs. The ONLY writer is
upgrade-test.py --write-ladder (bench AND box proven, digests resolved).
Harness v3: box fixtures on the bench, files_may_change.
Backfill: the 21 moves of 2026-09-22, 21 proven from their records.
No image: line moved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-23 20:52:32 +02:00

1.4 KiB

REPORT — the test record and its gate (night 2026-09-23, Part B)

09-update-architecture.md §3 decision 13, §6.4 part 4 and the catalog half of part 6. Night record: felhom.eu/documentation/audits/DRILL-night-2026-09-23.md; evidence …/night-2026-09-23/B*.

Not done, or changed

  • The brief's "check-image-resolvable.py already resolves digests" is only half true: it asks docker manifest inspect whether a ref EXISTS and discards the digest. The digest comes from the new image_digest.py, whose answer equals Docker's RepoDigests on a box (positive control).
  • The move gate uses the network in the hook — for moved refs only. Decided by CC unattended (it is the only way a push-time "digest matches the registry now" can be asked); operator may reverse.
  • Backfilled digests are TODAY's registry answer, not a measurement of the image that was tested.
  • Step definitions for intermediate steps (steps/<to>.yml, part 5) are not written — no app has two steps yet.

What shipped

Format + spike, two gates (16 decoys, 3 red-proofs), the writer (5 tests), harness v3 (box fixtures on the bench; files_may_change), image_digest.py, the backfill (21 proven).

Gates

catalog_gates.py --fast all OK; test_gate_decoys.py 80 cases OK; test_ladder_writer.py OK; test_catalog_gates.py OK after this commit (its shallow-clone case needs the new scripts committed).