Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
4.4 KiB
REPORT — the engine-major rule, half lifted (R-469 + R-450)
Base 18a6d2d8243e → 5ff36d098cbc. No template moved. Architecture read first and named:
felhom.eu/documentation/architecture/09-update-architecture.md §3 decision 5 (the 2026-09-13 ruling
and its three precautions) and §6.1 (slice 4 as shipped).
Why now
The rule of 2026-09-13 named its own expiry — until the Update button takes a verified backup as its precondition — precisely so it would be removed deliberately rather than forgotten. That condition was met the same day: update arc Slice 4 shipped (controller v0.237.0/v0.238.0; any backup tier since v0.239.0). R-469 exists to make the removal a reviewed diff. This is it, and it removes exactly half.
What changed
- LIFTED — MariaDB. The four
mariadb:sidecars (bookstack-db,kimai-db,nextcloud-db,romm-db) may cross a major. They now have both halves: a verified backup in front of the Update, andMARIADB_AUTO_UPGRADE=1(R-459) whose conversion the harness WATCHED run on the E3/E3b edges with the seeded data read back after. - NOT LIFTED — PostgreSQL and MySQL. Postgres performs no
pg_upgradeand REFUSES to start on an older major's datadir, across eleven templates (R-463). A backup is a route BACK, not a conversion — the app would simply not come up. MySQL has nothing measured at all. The refusal text now says this, instead of citing the shipped R-448. - NEW — one edge, one migration (R-450's second half, recorded 2026-09-02, enforced now). A
MariaDB major must be the ONLY image move in its template in that commit. bookstack's
0b73e5emoved the application 25.02.2 → 26.05.2 and MariaDB 11.6 → 12.3 together: two migrations behind one edge, and an unreadable failure when it breaks. The refusal names what it was bundled with. Within a major is unaffected and may still ride with anything. - The gate PRINTS what it allowed, by name and with the reason, rather than passing in silence. A lifted rule that goes quiet is a lifted rule nobody can audit.
Red-proofs — two, each SEEN to fail
| the mutation | what failed |
|---|---|
drop the own-edge check (others = []) |
FACT: kimai-db 11.6 → 12.3 BUNDLED with the kimai app bump: rc=0 expected 1 — the bookstack shape passes |
empty LIFTED |
GENUINE: kimai-db 11.6 → 12.3 ALONE (the R-469 lift): rc=1 expected 0 — the lift is undone |
Both reverted; 40 decoy cases green. The old "a lone MariaDB major is REFUSED" case is now the "…is ALLOWED" case — that inversion is the lift itself. A third case pins the bundled PostgreSQL shape.
catalog_gates.py --fast: image-pins, engine-major, catalog-since, copy-i18n — all OK. The
pre-push hook ran and passed; no --no-verify.
Measured while here, and it belongs in this repo's record
A read-only sweep of all 66 unique pins against the public registries, from DooPlex, never from a box
(felhom.eu/documentation/audits/UPDATE-ARC-STATE-2026-09-21.md §3):
- 46 of 58 exact pins are behind upstream today; 39 within a major, 7 across one. The seven were all pinned 2026-07-18: nextcloud 34→35, paperless-ngx 2.20→3.2, claper 2.5→3.0, gokapi 1.9→2.2, homepage 1.13→2.4, sparkyfitness 0.17→1.7 (two images).
- 6 of the 7 measurable floating pins have been repushed upstream since the catalog set them —
postgres:16-alpine,postgres:15-alpine,redis:7-alpine,mariadb:11.4,mariadb:12.3,postgis:16-3.5-alpine. Onlymariadb:11.6has not. This is R-446 measured rather than theorised, and it is the case for recording digests at push time (put to the operator as09§3b Q6). msdeluise/plant-it:0.10.0is gone upstream. The repo's own gate says INCONCLUSIVE (it refuses to read adeniedstderr as "dead", correctly); two independent signals say it really is gone — Docker Hub's catalog API answersobject not foundfor the whole repository, and the upstream GitHub repo 404s. The app is alreadylifecycle: abandoned, so this is the expected end state, not an incident. A deployed plant-it survives; it can never be redeployed.
Rows
R-469 PARTLY CLOSED (MariaDB lifted; the PostgreSQL half stands until R-463).
R-450 half SHIPPED (the own-edge clause; the automatic-within-a-major half is Slice 6 and awaits
09 §3b Q1–Q4). R-605 filed — a catalog gate that refused to run and one that ran and could not
decide print the same word.