From 01d5dbd3e0325809147ccaf9fce4fa2efabf1c51 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Tue, 6 Oct 2026 14:03:28 +0200 Subject: [PATCH] Part C: R-644, R-763, R-764 closed (wger's fixes proven on 9202), R-762/R-717 stopped with reasons; STATUS, CONTEXT, REPORT (142 -> 137; 0 opened, 5 closed) Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- CONTEXT.md | 2 + REPORT.md | 179 ++++++++++++------ STATUS.md | 23 ++- .../r890-instructions-2026-10-06/C/wger.txt | 45 +++++ .../r890-instructions-2026-10-06/README.md | 6 + .../box/T1-repoint-live.txt | 11 ++ .../box/T2-drill-reset.txt | 1 + .../tools/wgerwalk.py | 62 ++++++ documentation/backlog/CLOSED-ITEMS.md | 9 + documentation/backlog/OPEN-ITEMS.md | 6 +- 10 files changed, 280 insertions(+), 64 deletions(-) create mode 100644 documentation/audits/r890-instructions-2026-10-06/C/wger.txt create mode 100644 documentation/audits/r890-instructions-2026-10-06/box/T1-repoint-live.txt create mode 100644 documentation/audits/r890-instructions-2026-10-06/box/T2-drill-reset.txt create mode 100644 documentation/audits/r890-instructions-2026-10-06/tools/wgerwalk.py diff --git a/CONTEXT.md b/CONTEXT.md index 63e5ff54..63fcd675 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -24,6 +24,8 @@ > five conditions; the invite runs inside the box, the token never leaves it); the Tester 1 box is allowed but the walk > has no route there. Vaultwarden's first ladder step 1.36.0-alpine → 1.37.4-alpine is live in the catalog (`ecb8552`). > R-469 re-read: NOT removable — the engine gate is now decision 35's permanent per-app check (operator: close or keep). +> Part C: R-644, R-763, R-764 closed (wger's two fixes proven on 9202; wger stays hidden for R-762); R-717 needs a lift +> command in `after_setup` first. Register 142 → 137 (0 opened, 5 closed). > **2026-10-06 (midday) — the operator's ten answers (`09` §3 139–148, „A" for all; CC's own pick differed on 140, 146, > 147).** Register 150 → 142 (2 opened: R-890 vaultwarden ladder, R-891 a stale CLAUDE.md line; 10 closed). Releases: diff --git a/REPORT.md b/REPORT.md index dea8f325..1e5b5ddf 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,82 +1,147 @@ -# REPORT — the operator's ten answers built (2026-10-06, rulings `09` §3 139–148) +# REPORT — instruction files kept true; vaultwarden on the ladder; the burn-down continued (2026-10-06 afternoon) | Part | Result | |---|---| -| **A** — the box changes (1, 4, 5) | **done** — R-444 weekly trim (measured on demo-hp first, then built, delivered, seen working by itself), R-645 version skip, R-856 crash-boot grace; agent v0.149.0 + bundle, controller v0.300.0 + golden 0.300.0, hub v0.139.0, all on demo-hp, demo-felhom, Tester 1 | -| **B** — the backup leftovers (2) | **done** — runbook written; read-only listing of ep0: **no leftover exists**, nothing deleted, real counts unchanged; the box's warning names the runbook | -| **C** — the page sentences (6, 10) | **done** — mealie and Karakeep, hu + en, live in the catalog | -| **D** — the test tools (3, 7, 8, 9) | **done** — R-618 closed by ruling; R-734 marker list; R-624 bench seed proven on a recreated bench; R-502 full-run gate, first real run green with its decoy convicted | +| **A** — the instruction-file rule (R-891, R-469, sweep) | **done** — rule in all four copies of `unprompted-work.md` §5 and `PROMPT-TEMPLATE.md` §9 rule 9; R-891 fixed and closed; R-469 re-read: NOT removable, narrowed (an operator question); sweep: 26 factual edits in four repos (list below). No permission prompt or refusal came up. | +| **B** — vaultwarden on the update ladder (R-890) | **done** — the test-box admin seed built (catalog `6b4877d`, red-proved); 1.36.0-alpine → 1.37.4-alpine proven on bench 9401 and on 9202; written by `--write-ladder` (catalog `ecb8552`); R-890 closed | +| **C** — the burn-down | **3 closed** (R-644, R-763, R-764), **2 stopped with the reason written** (R-762 medium, R-717 needs a design) | | Rows before | Rows after | Opened | Closed | |---|---|---|---| -| **150** | **142** | **2** (R-890, R-891) | **10** | - -Closed: R-444, R-99, R-618, R-645, R-856, R-747, R-734, R-624, R-502, R-774. +| **142** | **137** | **0** | **5** (R-890, R-891, R-644, R-763, R-764) | ## Baselines and rulings -Verified 11:07: felhom.eu `8f40b3ce26` (the operator's own „cleaned reports" commit on top of `fe998b8`), controller -`13bda270c3` (v0.299.0), agent `37e98f452b` (v0.148.0), catalog `d1a148408f`, register 150. The ten rulings were recorded -first (`09` §3 139–148, `8c65ff0c`), with the note that CC's own pick differed on 2, 8 and 9. - -**The operator's cleanup removed every `REPORT*.md`.** Two felhom.eu checks read `REPORT.md`: the decoy test now plants a -missing file and removes it again (`8c65ff0c`), and this file is the session's own report, as the repo rule says. +Verified at the start: felhom.eu `7d0dffcf34`, controller `36088fd82e` (v0.300.0), agent `cefdc731a4` (v0.149.0), +catalog `65130c6c03`; register 142. Read: every repo's `CLAUDE.md` and `.claude/rules/`, `REPORT.md`, R-890, R-891, +R-469. The two rulings were recorded first as `09` §3 decisions 149 and 150, with the reviewer's error recorded in 150. +Architecture read: `09-update-architecture.md` §3 (decisions 16, 35, 42, 146), §6.4 part 4 (the ladder writer), §6.5 +(the drill catalog). ## Part A -- **R-444, measured first** (demo-hp, 09:14Z, `audits/ten-answers-2026-10-06/r444-measure.txt`): `pct fstrim 9201` rc 0 in - 24.4 s; thin pool 65.53 % → 33.40 %; 18/18 app probes 200, slowest 1.1 s. **Built** (agent `ee71abd`): weekly, due - Wednesday from 10:00 host-local, starts only 10:00–20:59, under the one-heavy-op gate (backup, restore-test, OS steps), - 3 tries a week, persisted, reported as `guest_disk_trim`; ONE sudo rule `/usr/sbin/pct ^fstrim [0-9]+$`. Hub - (`a411cde7`): System page „Last disk trim". **Live:** `sudo -l` on demo-hp and demo-felhom allows the trim and refuses - `--ignore-mountpoints`, `;x`, a second vmid and `pct destroy`. The job's first catch-up try ran 2 minutes after the agent - update and failed (the bundle had not landed — expected); the hourly retry at 12:56 local logged - `fstrim: guest 9201 trimmed 2.1 GiB in 2.4s` and the hub page read „10 min ago · 2.1 GiB" (`r444-live.txt`). -- **R-645** (controller `2d63714`): every night leg skips an app whose pin is not what it runs; one amber line on the - backups page. Red-proved on the hand-lift shape. **Residual, stated:** once the boot reconciler starts the app on the - new version, pin = running again — a design question, not built. -- **R-856** (controller `c393d85` + agent route `GET /host/crash-guard`): after a crash boot, app mails wait 15 min. - Live through the real route: demo-hp logged the normal 90 s because its last crash boot (2026-10-05) was not this - start; demo-felhom logged a clean boot. **The crash branch was not shown live** (no crash allowed); tests cover it. +**The rule** — `.claude/rules/unprompted-work.md` §5 „Instruction files", the operator's text verbatim plus the +permission-check sentence; identical in felhom.eu, felhom-controller, app-catalog-felhom.eu and the workspace root's +unversioned copy (md5 `c1e6c881…` for all four). `documentation/PROMPT-TEMPLATE.md` §9, rule 9. felhom-agent has no copy +of the shared rule file (it never had one); adding one is a rule change, left for the operator. -## Part B — ep0, read only +**R-469 — not met.** R-463 closed (8 of 11 PostgreSQL apps converted by the box; zipline, adventurelog, immich stay on 16 +by decision 42), but the engine gate now enforces decision 35: a PostgreSQL major passes only with a two-venue ladder +entry carrying `engine_conversion`. Removing it would let an unproven major ship, and the image refuses to start on the +old datadir. That is a loosened fence. Nothing is left for CC to build; the row asks the operator to close it (CC's pick) +or keep it. -Every snapshot of datastore `felhom-offsite`, both from the server's API and from the directories: 9 snapshots in 5 -namespaces, all ≥ 369,808,250 B, all verification `ok`, every directory with its manifest. **No phantom; nothing deleted.** -Runbook `runbooks/pbs-phantom-cleanup.md` (the list command, the two-part test, one `api delete` per proven phantom, the -before/after count control) + `runbooks/pbs-phantom-list.py`; the agent's WARN now names the runbook (`be398f9`). +**Every instruction-file edit** (before → after, why). All factual; none loosens a rule. -## Part C and D +felhom.eu +1. `CLAUDE.md` „Gates — ONE entry point": a list of ten gates + „`--fast` … today that is all of them" → the `GATES` + table is the list (nineteen gates); `--fast` skips the full-run-only gates and names them (today `iso-bootstrap`). Why: + `repo_gates.py` imported: 19 gates, `iso-bootstrap` not fast. **R-891.** +2. `CLAUDE.md` design pointer `architecture/01..05-*.md` → `01..11-*.md` (00 = the capability map). Why: 06–11 exist. +3. `.claude/rules/docs.md` „the locked design" `01..05` → `01..11`. Same reason. +4. `.claude/rules/website.md`: the list of what `site_gates.py` asserts gains „no embedded `