From 1de0f7c2941728adaf04d8cea9aeaa4598b36a93 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 30 Sep 2026 21:49:25 +0200 Subject: [PATCH] Rulings recorded before the work: 09 decisions 52 (R-740 A, tested same-tag fixes at night) and 53 (R-736 A, image retention) Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- CONTEXT.md | 7 +++++++ .../architecture/07-backup-architecture.md | 3 +++ .../architecture/09-update-architecture.md | 21 +++++++++++++++++++ 3 files changed, 31 insertions(+) diff --git a/CONTEXT.md b/CONTEXT.md index cfd8b793..604289ec 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -16,6 +16,13 @@ > and holds nothing of its own; this file does hold its own content, namely the standing rulings below. +> **Rulings 2026-09-30 (late evening, operator) — `09` §3 decisions 52 and 53, recorded before the work.** **52 (R-740 A):** +> a box takes a same-tag security fix at night only after the catalog re-tested that tag at the new digest on both venues +> and wrote it as a ladder step; database and redis lines first; one command, run monthly. **53 (R-736 A):** a box keeps, +> per app service, the running image and the one before it (the undo's); older images of the app are deleted; never an +> image any container or installed compose names; removing an app deletes its images under the same rule; kept data +> (decision 40) untouched. + > **2026-09-30 (evening) — more night-updatable apps; the same-name fix gap measured (R-740, operator decision).** > Catalog: first ladders for calibre-web, gitea (its installer form, R-624), wger, crafty-controller, uptime-kuma, zipline > (4.6.1 → 4.7.0 → 4.8.0 — 4.8.0 refuses a database that skipped 4.7.x, R-742; the box UNDID the direct jump by itself); diff --git a/documentation/architecture/07-backup-architecture.md b/documentation/architecture/07-backup-architecture.md index b2fc4f03..04f41fa2 100644 --- a/documentation/architecture/07-backup-architecture.md +++ b/documentation/architecture/07-backup-architecture.md @@ -672,6 +672,9 @@ requires a database dump written after the conversion whose recorded engine is t **[FACT] The limit — the image is not in the backup (R-698).** A unit stores image NAMES and digests; the image is re-pulled on restore. A version its maker has deleted cannot start. Measured 2026-09-26: the 42 ladder digests all resolve today (`audits/version-travel-2026-09-26/A7/`). Options are in R-698; nothing is decided. +**Since decision 53 (`09` §3, 2026-09-30 evening):** a box keeps only the image each app service runs and the one before +it; older images of the app are deleted. A restore that needs an older version re-pulls it — as before; the limit +above is unchanged, and kept data (decision 40) is not touched by the image clean-up. ## 7. The recovery chain (D3) — the reason this document exists diff --git a/documentation/architecture/09-update-architecture.md b/documentation/architecture/09-update-architecture.md index a88a587e..e9e4246e 100644 --- a/documentation/architecture/09-update-architecture.md +++ b/documentation/architecture/09-update-architecture.md @@ -375,6 +375,8 @@ R-636's louder repeated alarm. image), so a same-name upstream fix reaches no box by either route today. Measured, with the options, in R-740; the decision is the operator's (STATUS 2026-09-30). This decision's ruling — the sync never moves an installed app's digest — is unchanged. + *Note 2026-09-30 evening:* decided — decision 52 (option A): the automatic leg takes a same-tag fix once the + catalog has re-tested it and written it as a step. ### 2026-09-25 (night) — three decisions taken by CC unattended, building §6.4 part 7 @@ -575,6 +577,25 @@ R-636's louder repeated alarm. Same day, operator: the first real tester gets a NEW customer record (`Tester-2`, domain `sajatfelhom.hu`), not `tester-1`; and CC rewrites the volunteer guide as measured (R-722). +### 2026-09-30 (evening) — two operator rulings + +52. **A box takes, at night, a same-tag security fix of an image — only after the catalog has re-tested that tag at + the new digest** — *operator ruling 2026-09-30 evening (R-740, option A).* The re-test is the full method on both + venues (bench with the memory watch, box 9202 through the guarded Update, read-back, negative control) and is + written by the only writer as a ladder step like any other; the box then takes it like any other step. Start with + the database and redis lines. The re-test is ONE command, run monthly. **Why:** a same-name upstream fix otherwise + reached no box at all (R-740: the catalog never recorded a same-tag re-test, and the leg skips a digest-only + change); measured that the box's leg presses such an entry with no controller change. Decision 30's cost line + ("or the automatic leg") is corrected by the dated note there; decision 30's ruling is unchanged. +53. **A box keeps, per app service, the image it runs now and the image before it (the undo's); it deletes older images + of that app by itself** — *operator ruling 2026-09-30 evening (R-736, option A).* It never deletes an image that any + container (running or stopped) or any installed app's compose still names. Removing an app deletes that app's + images under the same rule. **Kept data (decision 40) is unaffected** — it is data, not images. **Why:** a remove + ran `compose down --rmi local`, which keeps every registry-pulled image, and no other code deleted any; on 9202 + that filled the Docker disk until the box refused an install (R-736). **Cost, stated:** a restore to a version + older than the previous one re-pulls it — as every restore already does (R-698: a backup stores the image's name, + not the image). + ### 2026-09-30 (day) — operator notes, recorded before the work - **The day brief runs by day.** Every backup and automatic-update test is started by hand — the night chain's debug