After an edge reads back, --soak seconds (default 600) of light load while the kernel's own oom_kill counter is read host-side from the container's cgroup. A kill or restart turns proven into failed; a peak over 80% of the limit adds the memory_tight mark. New Romm fixture; edges M1 / M1old. Red-proof on scratch 9202: M1old (template as promoted, 512M, 4 workers) OOM-killed at +76 s -> failed. M1 (current, 768M, 2 workers) proven, 0 kills in 608.5 s, peak 81% -> memory_tight. Test code only; no template changed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
1.6 KiB
REPORT — the upgrade harness watches memory (2026-09-23)
Test code only. No template was changed; no image: line moved; the diff touches exactly
scripts/upgrade-test.py, scripts/upgrade_fixtures.py, CHANGELOG.md and this file.
What was done
The RomM lesson (R-635): a walk proves "the update applied and the data survived", not "the new
version runs". upgrade-test.py v2 adds a memory watch after a successful readback — --soak
seconds (default 600) of light load, sampling the kernel's oom_kill counter host-side, the peak
against the compose limit, and restarts. Kill or restart → failed; peak > 80 % → mark
memory_tight. New Romm fixture and edges M1 / M1old.
Red-proof (scratch guest 9202, /opt/upg, removed afterwards)
| edge | template | verdict | memory |
|---|---|---|---|
| M1old | as promoted (15f9ebf): 512M, 4 workers |
failed | first OOM kill at +76 s, peak 100 % of 512 MiB, restarts 0 |
| M1 | current: 768M, 2 workers | proven + mark memory_tight |
608.5 s under 11 429 requests (5 712 × 200, 5 717 × 401): 0 kernel OOM kills, 0 restarts, peak 621 MiB = 81 % of 768 MiB — the watch passes the fix and still flags the thin headroom R-635 left open |
C3 (the standing negative control) was not run: its container_name: privatebin collides with the
privatebin the controller runs on 9202. The M1old/M1 pair is this step's own control.
Gates: python3 scripts/catalog_gates.py --fast → all OK.
Full session report: felhom.eu/REPORT.md; evidence felhom.eu/documentation/audits/update-rulings-2026-09-23/.