Corrected in all four instruction files across all four repos. Found while confirming this session own push by run ID, which is precisely the check that catches it. In felhom-agent/CLAUDE.md the sentence contradicted the same file release section, which already said R-168 mails the failure -- a contradiction inside one instruction file, the exact class the R-229 work exists to find. REPORT.md deliberately NOT overwritten in the sibling repos: a one-line docs correction must not destroy the record of their last real implementation.
3.1 KiB
paths
| paths | ||||
|---|---|---|---|---|
|
Gates and logging — felhom-controller
The ONE entry point
Run python3 controller/scripts/controller_gates.py (from controller/) after ANY change in this
repo. It runs all seven local gates — template_id_gate, emoji_gate, native_confirm_gate,
offbox_rename_gate, app_row_dedup_gate, mojibake_gate, docker_run_volume_path_gate — plus
reuse_refs_check and instructions_gate on the repo root, streaming each gate's own output and
exiting non-zero if any fails.
--fastselects the gates that touch no network and no container runtime; today that is all of them.- A missing gate script is a FAILURE, never a skip.
- The shared
reuse_refs_check.pyandinstructions_gate.pylive infelhom.eu/scripts/and are never copied here — a copy would recreate the drift they detect; an absent sibling clone FAILS. - The pre-push hook (
.githooks/pre-push) runs it with--fastand refuses a failing push. It is per-clone — switch it on once withgit config core.hooksPath .githooks, and a manual run WARNS when this clone is unarmed.git push --no-verifybypasses it deliberately; say so in the session report when you use it — CI re-runs the same entry point on every push and emails the operator on failure, so a bypass is noticed even though it is not blocked (R-168, CLOSED 2026-08-02).
Logging
New leveled lines use internal/logx — DEBUG always reaches the debug ring; stdout respects
logging.level. English, keys-never-values, durations on outcomes. Full rules:
felhom.eu/documentation/runbooks/logging-conventions.md.
Health checks issue no block I/O
A probe that touches a wedged device enters uninterruptible sleep, survives SIGKILL, and cannot be
recovered until the device returns or the host reboots — so systemctl restart hangs too. A timeout
protects the caller's control flow and nothing else: the blocked thread remains. Liveness is decided
from /proc and kernel state, never by reading or writing the filesystem.