=== part0-repo-gates.txt ===
captured: 2026-08-20T08:01:52+00:00 UTC
cmd: python3 scripts/repo_gates.py
--- stdout+stderr ---
repo_gates (felhom.eu) — 10 gate(s)

==============================================================================
== gate: site   (site_gates.py)
==============================================================================
site gates OK — BOM, emoji=0, nav/footer consistent, analytics present, no CDN, no legacy tokens, no <style>, cache-busted assets

==============================================================================
== gate: hostinstall   (hostinstall_gates.py)
==============================================================================
  ok: SCRIPT_VERSION=1.28.0
  ok: header has no version literal
  ok: hub carries no host-install version literal (241 .go/.html files scanned, 6 shapes checked)
  ok: age is in the installed package set
  ok: felhom-pbs-apply is fetched from the agent repo
  ok: felhom-pbs-apply installed 0755 to /usr/local/sbin
  ok: uninstall removes felhom-pbs-apply
  ok: rendered agent.json defaults wg_tunnel.enabled=true
  ok: byo assert no longer forbids wg_tunnel
  ok: PVE_STORAGES default contains felhom-pbs
  ok: no raw/branch/ ref in the installer — every run-time fetch is pinned
  ok: fetch_raw pins the agent configs to the vouched agent version
  ok: manifest: /scripts/ syncs from an installer tag
  ok: manifest: the website still tracks main (a copy edit must not need a release)
  ok: every arm that resolves the backup target also grants on it (2 resolution(s), 3 grant(s))
  ok: the offsite tier arms no client-side prune (keep_last=0; retention is ep0's prune jobs)

hostinstall gates: ALL PASS

==============================================================================
== gate: hub-confirm   (hub_confirm_gate.py)
==============================================================================
hub confirm gate OK — no native confirm()/prompt() in hub templates

==============================================================================
== gate: manifest-bearer   (manifest_bearer_gate.py)
==============================================================================
manifests/felhom.secret.yaml:39  KNOWN-BACKLOG committed secret 65cee3c4...7a86 (secrets.md de-git backlog; not this gate's failure)
manifest bearer gate OK - no bearer-shaped literals in manifests/

==============================================================================
== gate: reuse-refs   (reuse_refs_check.py /mnt/5_hdd/felhom.eu/git/felhom.eu)
==============================================================================
note [felhom.eu] line 75: api/handler.go  (resolved by suffix → hub/internal/api/handler.go)
OK   [felhom.eu]: 66 cited paths — exact 65, suffix 1, ambiguous 0, cross-repo 0, FAILED 0 (siblings searched: app-catalog-felhom.eu, felhom-agent, felhom-controller)

==============================================================================
== gate: instructions   (instructions_gate.py /mnt/5_hdd/felhom.eu/git/felhom.eu)
==============================================================================
instructions_gate: /mnt/5_hdd/felhom.eu/git/felhom.eu
  CLAUDE.md effective lines : 128 (ceiling 200)
  version literals          : 0
  TEMPORARY blocks          : 0
  rule files                : 4 (4 path-scoped)
  workspace file            : SYMLINK -> felhom.eu/documentation/runbooks/workspace-CLAUDE.md (resolves to the versioned copy)
  memory index             : 158 lines (ceiling 200), 20238 bytes (ceiling 25600)
  memory index content     : 33 version literal(s), 4 host address(es), 0 expired statement(s)  [WARN only]
  memory topic files       : 125 indexed, 0 orphaned, 40 archived
  register citations       : 10 cited, 342 register items known

WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:26: version literal '1.25.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [ISO train v1.25.0](iso-train-v1.25.0-2026-07-23.md) — R-71 build-gate (golden≥floor), r
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:47: version literal '1.2.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [Offsite pool-box aggregate](offsite-pool-box-aggregate-2026-07-17.md) — R-5 hub 0.64/0.
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:50: version literal '0.90.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [Guest RAM resize + fast-tick](guest-ram-resize-fasttick-2026-07-17.md) — R-24 controlle
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:50: version literal '0.143.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [Guest RAM resize + fast-tick](guest-ram-resize-fasttick-2026-07-17.md) — R-24 controlle
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:59: version literal '0.142.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [Offsite continuity](offsite-continuity-2026-07-17.md) — ctrl 0.142.0 orphan guard + hub
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:59: version literal '0.60.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [Offsite continuity](offsite-continuity-2026-07-17.md) — ctrl 0.142.0 orphan guard + hub
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md: ... and 27 more version literal(s) — full list from the tally counts above.
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:42: host address '192.168.0.0' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [Tailscale N100 location-independent](tailscale-n100-location-independent-2026-07-19.md)
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:46: host address '167.233.158.164' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [Offsite PBS box RAM ceiling](offsite-pbs-box-ram-ceiling-2026-07-27.md) — **root SSH = 
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:46: host address '10.77.0.1' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - [Offsite PBS box RAM ceiling](offsite-pbs-box-ram-ceiling-2026-07-27.md) — **root SSH = 
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:139: host address '192.168.0.180' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
      - **CC runs ON DooPlex** (192.168.0.180) — repos `/mnt/5_hdd/felhom.eu/git/felhom-*`, buil

instructions_gate: OK (11 warning(s))

==============================================================================
== gate: golden-currency   (golden_currency_gate.py)
==============================================================================
  newest released controller : 0.216.0   (## v0.216.0 — one physical disk, one verdict (2026-08-14, R-335))
  newest golden baked        : 0.216.0   (documentation/tests/golden-0.216.0-2026-08-18)
golden currency gate OK — the newest released controller has a golden (NOTE: this checks the BAKE, not the vouch — see the module docstring)

==============================================================================
== gate: wire-contract   (wire_contract_gate.py)
==============================================================================
wire-contract gate — 190 tag(s) checked across 4 declared wire(s); 80 skipped (generic / opaque / allowlisted)
wire-contract gate OK — every emitted field is at least decodable by its receiver
  (BLIND SPOTS: generic tag names skipped; name-reachability is not use; only the
   declared ROOTS are covered — hub desired-state and the agent local API are not.)

==============================================================================
== gate: hub-copy   (hub_copy_gate.py)
==============================================================================
hub-copy gate OK — 95 hub file(s) scanned for 2 retired name(s); 4 customer surface(s) scanned for 4 retrieval stem(s), 0 registered claim(s), none unregistered
  drift: controller gate's STEMS match the shared list (4 stem(s))
  (BLIND SPOT: this checks the WORDS in the four declared customer surfaces. It cannot
   tell whether a true-looking sentence is wired to a predicate that is actually true —
   that is what render tests are for. And it does not read the operator's screens.)

==============================================================================
== gate: due-checks   (due_checks_gate.py)
==============================================================================
DUE-CHECKS GATE FAILED: 1 dated check(s) are due or overdue as of 2026-08-20 (UTC).

  R-341    due 2026-08-19   1 day(s) OVERDUE
           measure: ep0 proxy fd count + ESTAB/CLOSE-WAIT split; PID must still be 551655
           the command and its preconditions are in the R-341 row of documentation/backlog/OPEN-ITEMS.md

Take the measurement, record the result in that R-row, then remove the row from the
DUE-CHECKS block. Moving the date instead is allowed — state the reason in the R-row.
NOTE: this gate fires on a PUSH, not on the date; it may be later than the date.

==============================================================================
== summary
==============================================================================
  site               OK            (exit 0)
  hostinstall        OK            (exit 0)
  hub-confirm        OK            (exit 0)
  manifest-bearer    OK            (exit 0)
  reuse-refs         OK            (exit 0)
  instructions       OK            (exit 0)
  golden-currency    OK            (exit 0)
  wire-contract      OK            (exit 0)
  hub-copy           OK            (exit 0)
  due-checks         FAILED        (exit 1)

CONVICTED: due-checks
rc=1
