Rulings recorded before the work: 09 decisions 52 (R-740 A, tested same-tag fixes at night) and 53 (R-736 A, image retention)
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-30 21:49:25 +02:00
parent 42bf40bd2c
commit 1de0f7c294
3 changed files with 31 additions and 0 deletions
+7
View File
@@ -16,6 +16,13 @@
> and holds nothing of its own; this file does hold its own content, namely the standing rulings below.
> **Rulings 2026-09-30 (late evening, operator) — `09` §3 decisions 52 and 53, recorded before the work.** **52 (R-740 A):**
> a box takes a same-tag security fix at night only after the catalog re-tested that tag at the new digest on both venues
> and wrote it as a ladder step; database and redis lines first; one command, run monthly. **53 (R-736 A):** a box keeps,
> per app service, the running image and the one before it (the undo's); older images of the app are deleted; never an
> image any container or installed compose names; removing an app deletes its images under the same rule; kept data
> (decision 40) untouched.
> **2026-09-30 (evening) — more night-updatable apps; the same-name fix gap measured (R-740, operator decision).**
> Catalog: first ladders for calibre-web, gitea (its installer form, R-624), wger, crafty-controller, uptime-kuma, zipline
> (4.6.1 → 4.7.0 → 4.8.0 — 4.8.0 refuses a database that skipped 4.7.x, R-742; the box UNDID the direct jump by itself);
@@ -672,6 +672,9 @@ requires a database dump written after the conversion whose recorded engine is t
**[FACT] The limit — the image is not in the backup (R-698).** A unit stores image NAMES and digests; the
image is re-pulled on restore. A version its maker has deleted cannot start. Measured 2026-09-26: the 42 ladder
digests all resolve today (`audits/version-travel-2026-09-26/A7/`). Options are in R-698; nothing is decided.
**Since decision 53 (`09` §3, 2026-09-30 evening):** a box keeps only the image each app service runs and the one before
it; older images of the app are deleted. A restore that needs an older version re-pulls it — as before; the limit
above is unchanged, and kept data (decision 40) is not touched by the image clean-up.
## 7. The recovery chain (D3) — the reason this document exists
@@ -375,6 +375,8 @@ R-636's louder repeated alarm.
image), so a same-name upstream fix reaches no box by either route today. Measured, with the options, in
R-740; the decision is the operator's (STATUS 2026-09-30). This decision's ruling — the sync never moves
an installed app's digest — is unchanged.
*Note 2026-09-30 evening:* decided — decision 52 (option A): the automatic leg takes a same-tag fix once the
catalog has re-tested it and written it as a step.
### 2026-09-25 (night) — three decisions taken by CC unattended, building §6.4 part 7
@@ -575,6 +577,25 @@ R-636's louder repeated alarm.
Same day, operator: the first real tester gets a NEW customer record (`Tester-2`, domain `sajatfelhom.hu`), not
`tester-1`; and CC rewrites the volunteer guide as measured (R-722).
### 2026-09-30 (evening) — two operator rulings
52. **A box takes, at night, a same-tag security fix of an image — only after the catalog has re-tested that tag at
the new digest** — *operator ruling 2026-09-30 evening (R-740, option A).* The re-test is the full method on both
venues (bench with the memory watch, box 9202 through the guarded Update, read-back, negative control) and is
written by the only writer as a ladder step like any other; the box then takes it like any other step. Start with
the database and redis lines. The re-test is ONE command, run monthly. **Why:** a same-name upstream fix otherwise
reached no box at all (R-740: the catalog never recorded a same-tag re-test, and the leg skips a digest-only
change); measured that the box's leg presses such an entry with no controller change. Decision 30's cost line
("or the automatic leg") is corrected by the dated note there; decision 30's ruling is unchanged.
53. **A box keeps, per app service, the image it runs now and the image before it (the undo's); it deletes older images
of that app by itself** — *operator ruling 2026-09-30 evening (R-736, option A).* It never deletes an image that any
container (running or stopped) or any installed app's compose still names. Removing an app deletes that app's
images under the same rule. **Kept data (decision 40) is unaffected** — it is data, not images. **Why:** a remove
ran `compose down --rmi local`, which keeps every registry-pulled image, and no other code deleted any; on 9202
that filled the Docker disk until the box refused an install (R-736). **Cost, stated:** a restore to a version
older than the previous one re-pulls it — as every restore already does (R-698: a backup stores the image's name,
not the image).
### 2026-09-30 (day) — operator notes, recorded before the work
- **The day brief runs by day.** Every backup and automatic-update test is started by hand — the night chain's debug