diff --git a/documentation/audits/DRILL-the-28-2026-09-22-HEAD.md b/documentation/audits/DRILL-the-28-2026-09-22-HEAD.md index 68967730..611d982a 100644 --- a/documentation/audits/DRILL-the-28-2026-09-22-HEAD.md +++ b/documentation/audits/DRILL-the-28-2026-09-22-HEAD.md @@ -74,3 +74,21 @@ Evidence: `the-28-2026-09-22/`. What came before: `DRILL-update-night-2026-09-21 cost `ghost` and `rallly` their edge on the first pass, and they are implicated in two of R-634's three instances. The nine re-walks were serial for exactly this reason. + +### Corrected 2026-09-22 (evening), from the records rather than by re-running + +9. **`calibre-web`'s restore was `refused-with-a-sentence`, not `failed`.** The refusal is in this + app's own `log.txt` line 12 as a `flash_error` on the redirect, and its state stayed `running` + throughout. It was recorded `failed` because that walk ran **before** the refusal-capture code was + added later the same night — the document's own section *"A restore that is REFUSED"* already said + so while the table and the record disagreed with it. + +10. **`calcom`'s restore was `inconclusive`, not `failed` — and that was my harness, not the + product.** The restore was accepted (`flash=flash.restore.started`, no `flash_error`), the app + read `running` at +45 s with no hold and no phase, and the classifier looked once more and saw + **`starting`** — a settling state it did not list beside `running`/`unhealthy`, so it fell + through to `failed`. **The task brief supposed a different cause** — "a read-back of data that + was never seeded" — and that is wrong: the seed half is recorded separately and was already + `no route`. The record's own `restore_state_seen: "starting"` is the evidence. + + **Totals move with it:** restores correctly REFUSED go from 2 to **3**. diff --git a/documentation/audits/DRILL-the-28-2026-09-22.md b/documentation/audits/DRILL-the-28-2026-09-22.md index 36e24432..c1e37994 100644 --- a/documentation/audits/DRILL-the-28-2026-09-22.md +++ b/documentation/audits/DRILL-the-28-2026-09-22.md @@ -75,6 +75,24 @@ Evidence: `the-28-2026-09-22/`. What came before: `DRILL-update-night-2026-09-21 three instances. The nine re-walks were serial for exactly this reason. +### Corrected 2026-09-22 (evening), from the records rather than by re-running + +9. **`calibre-web`'s restore was `refused-with-a-sentence`, not `failed`.** The refusal is in this + app's own `log.txt` line 12 as a `flash_error` on the redirect, and its state stayed `running` + throughout. It was recorded `failed` because that walk ran **before** the refusal-capture code was + added later the same night — the document's own section *"A restore that is REFUSED"* already said + so while the table and the record disagreed with it. + +10. **`calcom`'s restore was `inconclusive`, not `failed` — and that was my harness, not the + product.** The restore was accepted (`flash=flash.restore.started`, no `flash_error`), the app + read `running` at +45 s with no hold and no phase, and the classifier looked once more and saw + **`starting`** — a settling state it did not list beside `running`/`unhealthy`, so it fell + through to `failed`. **The task brief supposed a different cause** — "a read-back of data that + was never seeded" — and that is wrong: the seed half is recorded separately and was already + `no route`. The record's own `restore_state_seen: "starting"` is the evidence. + + **Totals move with it:** restores correctly REFUSED go from 2 to **3**. + --- ## What this night is, in three lines @@ -179,8 +197,8 @@ Classes are `07-backup-architecture.md` §6.2's, not re-derived. | app | class | deployed | seeded | backup | edge | update | restore | removed clean | s | evidence | |---|---|---|---|---|---|---|---|---|---|---| -| `calcom` | B volumes-only + postgres | yes | no route | 1 copy | none upstream | — | failed | yes | 675.8 | `apps/calcom/` | -| `calibre-web` | A file-leg | yes | no route | 1 copy | none upstream | — | failed | yes | 187.5 | `apps/calibre-web/` | +| `calcom` | B volumes-only + postgres | yes | no route | 1 copy | none upstream | — | inconclusive | yes | 675.8 | `apps/calcom/` | +| `calibre-web` | A file-leg | yes | no route | 1 copy | none upstream | — | refused-with-a-sentence | yes | 187.5 | `apps/calibre-web/` | | `claper` | B volumes-only + postgres | yes | no route | 1 copy | none upstream | — | ok | yes | 255.3 | `apps/claper/` | | `code-server` | B volumes-only | yes | route failed | 1 copy | `4.129.0` → `4.138.0` | done | ok | yes | 299.9 | `apps/code-server/` | | `crafty-controller` | B volumes-only | yes | no route | 1 copy | `4.10.7` → `4.11.0` | done | ok | yes | 288.5 | `apps/crafty-controller/` | @@ -210,7 +228,7 @@ Classes are `07-backup-architecture.md` §6.2's, not re-derived. **Totals:** **14** no-edge · **6** proven · **5** inconclusive · **2** could-not-deploy · **1** failed — 28 of 28 recorded. -**Read across the walk rather than down one column:** **26 of 28 deployed**, **6** had a non-browser route that seeded AND read back, **21** restored from their own copy, **2** were correctly REFUSED a restore, **6 proven / 1 failed** on the apps that had an upstream edge, and **2** left a container behind (R-633). +**Read across the walk rather than down one column:** **26 of 28 deployed**, **6** had a non-browser route that seeded AND read back, **21** restored from their own copy, **3** were correctly REFUSED a restore, **6 proven / 1 failed** on the apps that had an upstream edge, and **2** left a container behind (R-633). --- diff --git a/documentation/audits/the-28-2026-09-22/TABLE.md b/documentation/audits/the-28-2026-09-22/TABLE.md index e0215fb0..ea8ae3e8 100644 --- a/documentation/audits/the-28-2026-09-22/TABLE.md +++ b/documentation/audits/the-28-2026-09-22/TABLE.md @@ -1,7 +1,7 @@ | app | class | deployed | seeded | backup | edge | update | restore | removed clean | s | evidence | |---|---|---|---|---|---|---|---|---|---|---| -| `calcom` | B volumes-only + postgres | yes | no route | 1 copy | none upstream | — | failed | yes | 675.8 | `apps/calcom/` | -| `calibre-web` | A file-leg | yes | no route | 1 copy | none upstream | — | failed | yes | 187.5 | `apps/calibre-web/` | +| `calcom` | B volumes-only + postgres | yes | no route | 1 copy | none upstream | — | inconclusive | yes | 675.8 | `apps/calcom/` | +| `calibre-web` | A file-leg | yes | no route | 1 copy | none upstream | — | refused-with-a-sentence | yes | 187.5 | `apps/calibre-web/` | | `claper` | B volumes-only + postgres | yes | no route | 1 copy | none upstream | — | ok | yes | 255.3 | `apps/claper/` | | `code-server` | B volumes-only | yes | route failed | 1 copy | `4.129.0` → `4.138.0` | done | ok | yes | 299.9 | `apps/code-server/` | | `crafty-controller` | B volumes-only | yes | no route | 1 copy | `4.10.7` → `4.11.0` | done | ok | yes | 288.5 | `apps/crafty-controller/` | diff --git a/documentation/audits/the-28-2026-09-22/apps/calcom/verdict.json b/documentation/audits/the-28-2026-09-22/apps/calcom/verdict.json index d5d02d99..c71de0ce 100644 --- a/documentation/audits/the-28-2026-09-22/apps/calcom/verdict.json +++ b/documentation/audits/the-28-2026-09-22/apps/calcom/verdict.json @@ -22,7 +22,7 @@ "drive_label": "Belső SSD (rendszer)" } }, - "restore_verdict": "failed", + "restore_verdict": "inconclusive", "seed_read_after_restore": false, "healthy_after": false, "migration_observed": null, @@ -41,5 +41,6 @@ "restore_raw": "{'ok': True, 'snapshot_id': 'helyi', 'snapshots': [{'time': '2026-09-22T13:32:12Z', 'short_id': 'helyi', 'tier': 1, 'drive_label': 'Belső SSD (rendszer)'}], 'http': 'HTTP/2 302', 'location': ['location: /backups/restore?flash=flash.restore.started'], 'seconds': 44.6, 'state_after': 'running', 'hold_after': None, 'observables_after': {'pinned_images': {'calcom': 'calcom/cal.com:v6.2.0', 'calcom-pos", "restore_refusal": null, "restore_state_seen": "starting", - "remove_leftovers": "" + "remove_leftovers": "", + "correction": "Recorded `failed`, and that was the HARNESS, not the product. The restore was accepted (`flash=flash.restore.started`, no `flash_error`), the app read `running` at +45 s with no hold and no phase, and the classifier then looked once more and saw **`starting`** — a settling state it did not list alongside `running`/`unhealthy`, so it fell through to `failed`. NOT, as the task brief supposed, a read-back of data that was never seeded: the seed half is recorded separately and was already `no route`. `inconclusive` is the honest verdict — the restore ran and nothing says it did not work, and nothing proves it did. Corrected 2026-09-22 from log.txt 15:32:13-15:33:17 and the record's own `restore_state_seen`, not re-run." } \ No newline at end of file diff --git a/documentation/audits/the-28-2026-09-22/apps/calibre-web/verdict.json b/documentation/audits/the-28-2026-09-22/apps/calibre-web/verdict.json index e4d779fd..3bacacbd 100644 --- a/documentation/audits/the-28-2026-09-22/apps/calibre-web/verdict.json +++ b/documentation/audits/the-28-2026-09-22/apps/calibre-web/verdict.json @@ -21,7 +21,7 @@ "drive_label": "calibre-web" } }, - "restore_verdict": "failed", + "restore_verdict": "refused-with-a-sentence", "seed_read_after_restore": false, "healthy_after": false, "migration_observed": null, @@ -38,5 +38,7 @@ "code": "302" }, "restore_raw": "{'ok': True, 'snapshot_id': 'helyi', 'snapshots': [{'time': '2026-09-22T11:33:53Z', 'short_id': 'helyi', 'tier': 1, 'drive_label': 'calibre-web'}], 'http': 'HTTP/2 302', 'location': ['location: /backups/restore?flash_error=Ez+a+ment%C3%A9s+nem+tartalmazza+az+alkalmaz%C3%A1s+f%C3%A1jljait%2C+ez%C3%A9rt+nem+%C3%A1ll%C3%ADtjuk+vissza+az+adatb%C3%A1zist+f%C3%B6l%C3%A9j%C3%BCk+%E2%80%94+a+f%C3%A1jlok+%", - "remove_leftovers": "" + "remove_leftovers": "", + "restore_refusal": "Ez a mentés nem tartalmazza az alkalmazás fájljait, ezért nem állítjuk vissza az adatbázist föléjük — a fájlok így a helyükön maradnak. A fájlok a távoli másolatból állíthatók vissza: Biztonsági mentés → Visszaállítás, „Teljes visszaállítás (fájlok + adatbázis)”.", + "correction": "Recorded `failed` by the first walk, whose classifier predated the refusal-capture code added later the same night. The refusal is in this app's own log.txt line 12 as a `flash_error` on the redirect, and the state stayed `running` throughout. Corrected 2026-09-22 from the log, not re-run." } \ No newline at end of file diff --git a/documentation/audits/the-28-2026-09-22/moves6.json b/documentation/audits/the-28-2026-09-22/moves6.json new file mode 100644 index 00000000..6961d0f3 --- /dev/null +++ b/documentation/audits/the-28-2026-09-22/moves6.json @@ -0,0 +1,36 @@ +{ + "moved": [ + [ + "emby", + "4.10.0.20 -> 4.11.0.1", + "7a6797b" + ], + [ + "ghost", + "6.53.0 -> 6.64.0", + "acbfafa" + ], + [ + "immich", + "v3.0.3 -> v3.2.2", + "12c1270" + ], + [ + "radarr", + "6.3.0 -> 6.4.4", + "b7b0479" + ], + [ + "sonarr", + "4.0.19 -> 4.0.20", + "0b283d2" + ], + [ + "termix", + "2.5.0 -> 2.8.0", + "8898b1d" + ] + ], + "dropped": [], + "catalog_since": "2026-09-22" +} \ No newline at end of file