golden 0.230.0 baked, vouched, floor raised - demo-felhom moved itself off the R-403 build (R-410 filed)
gates / gates (push) Successful in 17s

GOLDEN_SHA256 9287f7cef5f13166276e8406005e3f28004004510c5184f1c1c7377f7aafad2e,
657 873 700 B. Evidence documentation/tests/golden-0.230.0-2026-08-31/.

WHY IT WAS OWED: the newest golden was 0.229.0, which IS the build R-403 says deletes a
good copy. Every fresh install and the whole fleet floor still carried it.
golden_currency_gate.py had been red across dddcc80, 6e550ae, 130f7a6 and 32a4c35.

THREE INDEPENDENT READERS agreed before anything was vouched: the bake's own print, the
round trip of the PUBLISHED bytes (HTTP 200, 657873700 B, same sha), and the hub's Day-0
dropdown reading Gitea on a different code path. And the delivered artifact names the
controller it will start - ./etc/felhom-controller-image read OUT of the downloaded
archive says felhom-controller:0.230.0, with 19382 entries under var/lib/felhom/docker/.

BOTH PRE-GATES were shown able to see something before their zeroes were believed: the
404 pre-gate, and the token-leak grep which returns 0 on the committed log and 1 on a
seeded throwaway copy. The transient unit's own properties were grepped for the token
too - 0, with the same seeded positive control returning 1. Acceptance markers counted on
the COMMITTED log: 1/1/1/1 present, 0/0 absent, and the zeroes are believable because the
same including-mount-point pattern returns two real lines on that file.

THE VOUCH IS A THREE-FIELD CHANGE and only one field moved, which is stated rather than
left to look careless: golden_version 0.229.0 -> 0.230.0; agent_version 0.130.0 and
min_agent 0.129.0 UNCHANGED because v0.230.0's CHANGELOG header says MinAgent 0.129.0 and
0.129.0 <= 0.130.0, so this is not the R-216 shape. The 303 flash was not treated as
proof - the page was re-read and golden_behind_fleet confirmed absent.

THE FLOOR is a separate setting and was raised on the operator's explicit answer:
min_controller_version 0.229.0 -> 0.230.0. THE POSITIVE OBSERVABLE, from the agent's own
journal on demo-felhom, which was still running the defective 0.229.0:
  16:21:30 controller-swap: image file written, restarting bootstrap  target=...0.230.0
  16:21:40 controller-swap: new controller healthy                    target=...0.230.0
Both boxes now 0.230.0 healthy. Honest note: the polling loop's first read already said
0.230.0, so the transition was not seen by the loop - the journal is the evidence.

R-410 FILED, found while the gate went green: golden_currency_gate.py is satisfied by a
DIRECTORY NAME (EVIDENCE_RE against os.listdir, :89,:123). I created the evidence
directory before the bake finished and the gate would have passed at that moment. It
already declares that it does not check the vouch; it does not declare that the bake
check is a filename check. Fix: read the GOLDEN_SHA256= line out of the directory's
bake.log, with a red-proof on an empty directory.

R-242 updated - seventh debt, paid the same day, twice in one day.

Teardown: pct destroy 9100 --purge, shred -u AFTER the log was copied out, poweroff,
qemu confirmed exited with ps -eo comm (not pgrep -f, which self-matches), disk reverted
to virgin.

All 13 gates green - the first push this session that needed no --no-verify.

Ceiling R-409 -> R-410.
This commit is contained in:
2026-08-31 16:25:35 +02:00
parent 32a4c35c9c
commit 2263245cf2
22 changed files with 1851 additions and 19 deletions
+39 -5
View File
@@ -149,13 +149,47 @@ Ceiling **R-404 → R-409**.
`python3 scripts/unproven.py --summary`: 55 claims, walked 20 / partial 17 / built 14 / missing 4,
**NOT WALKED 35 of 55 — unchanged by this session**, which shipped no product claim.
## 7b. Golden 0.230.0 — baked, vouched, delivered (second half of the session, on request)
**This was NOT part of the spike and is reported separately so the two are not confused.** Asked for
after the spike closed; the spike itself still changed no product code.
| | |
|---|---|
| `GOLDEN_SHA256` | `9287f7cef5f13166276e8406005e3f28004004510c5184f1c1c7377f7aafad2e`, 657 873 700 B |
| markers | `docker OK (overlay2` 1 · `including mount point` rootfs 1 + mp0 1 · `upload OK (HTTP 201)` 1 · `excluding` 0 · `FATAL` 0 — counted on the **committed** log |
| three readers agreed | the bake's own print, the **round trip** of the published bytes, and the hub's Day-0 dropdown reading Gitea on a different code path |
| the artifact names its own controller | `tar --zstd -xOf golden.tar.zst ./etc/felhom-controller-image` → `felhom-controller:0.230.0`, with 19 382 entries under `var/lib/felhom/docker/` |
| vouch | `golden_version` 0.229.0 → **0.230.0**; `agent_version` 0.130.0 and `min_agent` 0.129.0 **unchanged** — v0.230.0's `MinAgent` is 0.129.0, and 0.129.0 ≤ 0.130.0 so this is not the R-216 shape. Re-read from the page; `golden_behind_fleet` confirmed absent |
| floor | `min_controller_version` 0.229.0 → **0.230.0**, a separate setting, done on the operator's explicit answer |
| **the unattended proof** | `demo-felhom` was on **0.229.0 — the R-403 build** — and moved itself: `controller-swap: image file written` 16:21:30 → `controller-swap: new controller healthy` 16:21:40 CEST. Both boxes now 0.230.0, healthy |
| pre-gates | 404 pre-gate passed; token-leak grep **0** on the committed log **and 1** on a seeded throwaway copy, so the zero is earned. Unit properties grepped for the token: **0**, positive control **1** |
| teardown | `pct destroy 9100 --purge`, `shred -u` after the log was copied out, `poweroff`, qemu confirmed exited with `ps -eo comm` (not `pgrep -f`, which self-matches), disk back to `virgin` |
Full record: `documentation/tests/golden-0.230.0-2026-08-31/README.md`.
**One honest gap vs. the 0.229.0 precedent:** the bake script's sha256 was **not** compared across
the hop, only recorded on DooPlex (`7b0fb5cf…73b6a1`). A corrupted `scp` would have failed the bake
rather than produced a wrong golden — but that is an argument, not a measurement.
**And the gate that flagged all this has a hole, found while it went green:** `golden_currency_gate.py`
matches a **directory name** (`scripts/golden_currency_gate.py:89,123`). I created
`documentation/tests/golden-0.230.0-2026-08-31/` before the bake finished, and the gate would have
passed at that moment. Filed as **R-410**.
## 8. Controller code, and the golden debt as it now stands
**The spike changed no controller code**, and that remains true — the golden bake ships the image
that was already released as v0.230.0, unchanged.
## 8. No controller code changed and no golden is owed
`felhom-controller` and `felhom-agent` were **read only**. No version bump, no build, no deploy, no
golden. The fleet stays on v0.230.0. **The one golden debt that exists — v0.230.0 released with the
newest bake at 0.229.0 — was already red at `dddcc80` before this session started** and belongs to
that release, not to this task; `golden_currency_gate.py` was the only failing gate at every point in
this session, before and after.
`felhom-controller` and `felhom-agent` were **read only** for the spike. No version bump, no build,
no deploy. **The golden debt — v0.230.0 released with the newest bake at 0.229.0 — was already red at
`dddcc80` before this session started** and belonged to that release, not to the spike;
`golden_currency_gate.py` was the only failing gate throughout the spike. **It was then PAID on
request** (§7b): the gate now exits 0, and the two register-only pushes below were the last that
needed a bypass.
**`git push --no-verify` was used, twice, for exactly that reason** — records-only pushes meeting the
golden gate. That is R-404's subject and the count is updated in its row.