From 091a4b744428ee7ca756001b48d8654c308fbbb1 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Sat, 22 Aug 2026 11:18:08 +0200 Subject: [PATCH] Correct the placement mis-framing, and file what we wrote down and never filed (R-368..R-375) Documentation and survey only. No code, no machine contacted. THE CORRECTION. The 40 catalogue templates without a configurable path are not missing a choice: 01-topology-and-trust.md:150-152 classes each volume hot (DB/config/cache -> fast storage, ENFORCED) or bulk (media/files), and the 40 are all-hot apps. The deploy page has been saying so to the customer all along (deploy.html:624-625). SPEC-app-data-placement and R-352 are corrected in place with the framing MARKED, not deleted; every measurement stands. R-356 was re-checked and survives, strengthened - an absent HDD_PATH is the normal state, so reading it as "not installed" misreads a correct configuration. The disk claim, precisely: since R-165 there is ONE guest data volume with two binds, not two volumes (build-golden.sh:29-40, 99). A physical-disk failure losing data and first-tier copy together is REAL and is what the other tiers exist for. A full data volume stopping the OS is NOT real and was the overstated one. THE SWEEP. 113 survey-class documents examined, 14 statements of "not filed", 2 already filed. Its positive control convicted the sweep itself twice before it convicted the corpus - markdown bold broke the strongest pattern, and the reporter re-searched a truncated line - both false zeros of the exact class being hunted, and together worth 2 of the 14. THE HEADLINE. The gap the 2026-08-21 drill rediscovered WAS filed - as R-107, ROADMAP.md:122, M/READY, 2026-07-28 - and is absent from OPEN-ITEMS.md, which calls itself the single source of truth. OPEN-ITEMS and that rule both landed 2026-07-27; R-107 went to ROADMAP alone the day after. 72 ids live only in ROADMAP, 29 not done, some of them findings. Filed as R-369 (HIGH). Five more still-open gaps filed with their ages: R-371 (17d), R-372 (38d, the oldest), R-373 (20d), R-374 (14d), R-375 (4d). R-368 corrects Part 4: the storage default IS applied at deploy time via deploy.html:612 - the earlier "the deploy route never reads it" came from grepping Go and never the templates. R-370 records the process failure and is closed by the template change. PROMPT-TEMPLATE gains the two rules it lacked: name the architecture document for the area and say what it says (with a file->area map and the test "is this something we chose?"), and an enumerated gap becomes a register row in the same session - a ROADMAP row alone does not count. Ceiling R-367 -> R-375. --- CONTEXT.md | 29 + REPORT.md | 608 ++++++++---------- documentation/PROMPT-TEMPLATE.md | 50 +- .../REPORT-v0.218.0-r354-r355-2026-08-22.md | 383 +++++++++++ documentation/backlog/OPEN-ITEMS.md | 12 +- .../SPEC-app-data-placement-2026-08-21.md | 86 +++ 6 files changed, 822 insertions(+), 346 deletions(-) create mode 100644 documentation/audits/REPORT-v0.218.0-r354-r355-2026-08-22.md diff --git a/CONTEXT.md b/CONTEXT.md index 0fa2641a..9b834ed7 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -14,6 +14,35 @@ > language, one screen, no identifiers in the prose. Same subjects, different readers; merging them > would make one of the two audiences stop reading. `STATUS.md` is also a **view of `OPEN-ITEMS.md`** > and holds nothing of its own; this file does hold its own content, namely the standing rulings below. +## Read the architecture folder BEFORE calling something a defect (2026-08-22, R-370 / R-369) + +**Between 19 and 22 August the reviewing side called a documented architectural decision a defect, in +four places.** The decision is in `architecture/01-topology-and-trust.md:150-152`: `.felhom.yml` +classes each volume **hot** (DB/config/cache → fast storage, **enforced**) or **bulk** (media/files → +may be slow). The 40 catalogue templates with no `HDD_PATH` are all-hot apps — their data is app +internals and belongs inside the guest, on its own volume so it cannot fill the OS +(`felhom-agent/configs/build-golden.sh:29-40`). The 13 with a path are the bulk apps. **There is no +choice being denied**, and the deploy page has been telling the customer exactly this all along: +*„A kiválasztott meghajtón az alkalmazás fájljai (média, dokumentumok) tárolódnak. Az adatbázis a +gyors belső SSD-n fut"* (`deploy.html:624-625`). + +**Why it happened, mechanically: the register and live source were read; `documentation/architecture/` +was not.** Nothing in `PROMPT-TEMPLATE.md` §4 required naming the architecture document for the area +being touched — item 4 named only the controller module map, and the S-1 rule governs *updating* a +design doc at the end, not *reading* one at the start. **Fixed in the same session:** §4 now carries +the file→area map, the ordering *architecture = reasoning, register = work, source = truth*, and the +test **"is what I am about to call a defect something we chose?"** + +**Corrected in place, not rewritten** — `SPEC-app-data-placement-2026-08-21.md` and R-352 carry +`[CORRECTED 2026-08-22]` blocks that say what they got wrong; a document that quietly changes its mind +teaches nobody. + +**And the sibling failure, R-369: there are two registers.** `OPEN-ITEMS.md` calls itself the single +source of truth; `ROADMAP.md` also holds open work. 72 `R-` ids live only in ROADMAP, 29 of them not +marked done. **R-107 — the off-site restore never unpacking its own volume tars — was filed there on +2026-07-28, one day after OPEN-ITEMS was created, and never entered the register. It was rediscovered +from scratch 25 days later by the 2026-08-21 drill and shipped as R-354.** The template now says +plainly that a ROADMAP row alone does not satisfy the filing rule. ## Box REACHABILITY is a separate signal from box FILL — and the cadence difference is deliberate (2026-08-18, R-339, hub v0.106.0) diff --git a/REPORT.md b/REPORT.md index e2dc9bf9..f0283998 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,383 +1,307 @@ -# REPORT — the database nobody backed up, and the restore that returned most apps nothing (2026-08-22) +# REPORT — correcting what we mis-called a defect, and finding what we wrote down and never filed (2026-08-22) -**Controller v0.217.0 → v0.218.0.** Two fixes, both found by watching a machine on the night of -2026-08-21, both confirmed the same way. **Part 1 first, because it is the only place in the product -where one customer action causes permanent total loss.** - -The drill that found them is preserved at -`documentation/audits/REPORT-DRILL-backup-truth-2026-08-21.md`; its evidence is in -`documentation/audits/DRILL-backup-truth-2026-08-21/evidence/`. +**Documentation and survey only. No code, no version bump, no bake, no deploy, no machine contacted.** +The previous report is preserved at `documentation/audits/REPORT-v0.218.0-r354-r355-2026-08-22.md`. --- -## 0. Baselines, re-established — not trusted from the sheet +## 1. §2's four claims — ALL FOUR HELD. No halt. -| item | expected | confirmed | +| # | claim | verdict | |---|---|---| -| controller | 0.217.0 → 0.218.0 | ✔ repo head `v0.217.0`; live on `demo-hp` `…:0.217.0` | -| agent | 0.130.0 | ✔ repo head and `felhom-agent --version` on the box | -| golden vouched | 0.217.0 | ✔ `