Family gate session close: B4 on demo-hp (real internet: member in, stranger 401; remove with data), REPORT-family-gate-2026-10-02, STATUS, R-800 (remove-with-data keeps userdata, operator), CONTEXT; register 436
gates / gates (push) Successful in 26s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-02 10:43:10 +02:00
parent e6d1ebd152
commit 2633dc1654
15 changed files with 319 additions and 43 deletions
+1 -1
View File
@@ -911,7 +911,7 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server`
| **R-797** | **[P3-LOW] `check-family-gate.py` rule 3 (a family_gate template needs a baked golden ≥ 0.287.0) is checked only where the felhom.eu sibling exists — CI's single clone cannot.** MEASURED 2026-10-02 (`audits/family-gate-2026-10-02/C-metube-bench/C3b-family-gate-with-sibling.txt`): without the sibling the gate printed NOT CHECKED and its summary read OK. The summary line now says "rule 3 … NOT CHECKED here". The pre-push hook (with the sibling) is where it bites. **Needs:** nothing more unless CI gets the sibling. | **WATCHING — rank P3-LOW; owner: CC** |
| **R-798** | **[P3-LOW] Grimmory's template sets `SWAGGER_ENABLED=false`, which v3.5.0 does not read (it reads `API_DOCS_ENABLED`, default false).** READ 2026-10-02 (`audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt`). Harmless today — the API docs are off by default. **Needs:** remove the dead line or set the right name, on the next Grimmory step. | **READY — rank P3-LOW; owner: CC** |
| **R-799** | **[P3-LOW] The MeTube fixture's `POST /add` leaves out `download_type`, which upstream's validator lists as required.** MEASURED 2026-10-02 (`audits/family-gate-2026-10-02/C-metube-bench/`): both 2026.09.28 and .29 answered 200 and downloaded anyway. Fragile if a later tag enforces it. **Needs:** add `download_type: video` to the fixture with the next MeTube step. | **READY — rank P3-LOW; owner: CC** |
| **R-800** | **[P3-LOW] Removing MeTube "keeping data" answers `hdd_paths_preserved: []` although its downloads stay on the drive.** MEASURED 2026-10-02 on 9202 (`audits/family-gate-2026-10-02/B/box/life.txt`, `audits/family-gate-2026-10-02/B/box/final.txt`): the remove parses MeTube's compose as "0 HDD mounts" — its only drive mount is `${USERDATA_PATH}`, not `${HDD_PATH}` — so the result lists nothing kept; the files WERE kept and the restore used them. Other userdata-only apps (jellyfin, komga, …) have the same shape. **Needs:** check what the household's remove dialog says for such an app; list userdata mounts as kept. | **READY — rank P3-LOW; owner: CC** |
| **R-800** | **[P2-MEDIUM] "Delete your data from the hard drive" keeps the app's files in the household's userdata folder — and neither the dialog nor the result says so.** MEASURED 2026-10-02. On demo-hp (live catalog, `audits/family-gate-2026-10-02/B4/grimmory-demo.txt`, `metube-demo.txt`): remove WITH data removed Grimmory's database volume, appdata and backups but KEPT the uploaded EPUB in `userdata/media/grimmory`; for MeTube the dialog offers no data checkbox at all and the result says "the app stored no data of its own on a drive" while the downloaded video stays in `userdata/media/metube`. On 9202 "keeping data" answers `hdd_paths_preserved: []` for the same reason (`audits/family-gate-2026-10-02/B/box/life.txt`): the remove reads `${HDD_PATH}` binds only. The model behind it may be right — userdata is the household's own files (a shared `media/` tree must never go with one app) — but then the dialog must say the files stay and where. **Needs (operator):** keep userdata on remove (and say so on the dialog), or delete an app's OWN userdata subfolder when the household ticks the box. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (the rule), CC (the dialog)** |
| **R-801** | **[P2-MEDIUM] The volume-persistence gate never sent a request to ANY app: it read the routed port from label VALUES while `docker compose config --format json` puts the port in the label NAME.** MEASURED 2026-10-02 on the bench (`audits/family-gate-2026-10-02/B/volume-persistence-metube-exerciser-diag.txt`: `"ports": []`, `"exercise": []` for MeTube; the label shape read on Compose 2.26.1). So every verdict since the gate exists came only from what an app writes at start by itself; the GET exercise and the deep second pass never ran. **Fixed in the catalog** (`routed_ports()`, key=value; unit tests, red-proofed: `audits/family-gate-2026-10-02/B/RP-R801-routed-ports.txt`). **Still owed:** a full re-sweep of all 58 templates on the bench with the fixed gate — an app whose data path is written only on a request may now read differently. | **READY — rank P2-MEDIUM; owner: CC (the re-sweep)** |
<!-- DUE-CHECKS-BEGIN — machine-readable. Parsed by scripts/due_checks_gate.py.