docs(R-329/R-386/R-387): the severity contract, the intent ruling, and Part 5 recorded
gates / gates (push) Successful in 17s
gates / gates (push) Successful in 17s
The alarm ladder gains the severity contract (the hub's vocabulary is exact, it coerces silently, and three things now hold it) and the intent test with its three-way ruling on unknown. Both marked [DESIGN] with the live measurements. Part 5 is RECORDED AND NOT IMPLEMENTED: the operator's notification philosophy, verbatim, marked plainly as direction rather than current behaviour, with the 12 -> 15 toggle growth as the argument. Filed as R-388, a product decision. R-329 and R-386 compressed into CLOSED-ITEMS with their rules kept and the full-text commit named. R-387 filed closed - including WHY the dispatcher branch was kept rather than deleted, which is evidence (three monitor checkers call ProcessEvent directly) and not caution. The drill record names three things that had to be re-run: an inert red-proof mutation, Scenario G refused twice behind an HTTP 200, and the live Scenario A NOT proving the customer gate because demo-hp has no prefs row at all. Register: OPEN 328325 -> 328132 B, CLOSED 71441 -> 74642 B.
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
# STATUS — what works, what's broken, what's next
|
||||
|
||||
**Updated 2026-08-23 — an app whose database dies now raises an alarm. It did not before, and the
|
||||
watcher said "nothing is down" the whole time. Released and NOT yet delivered: step 1 is yours.**
|
||||
**Updated 2026-08-23 — the app-down alarm now actually reaches you by e-mail. It never has: 91 of
|
||||
them were filed and not one was ever sent. Released and NOT yet delivered: step 1 is yours.**
|
||||
|
||||
> **A view, not a source.** `documentation/backlog/OPEN-ITEMS.md` is the authority; this page restates
|
||||
> part of it in plain words, and **nothing may exist only here**. **Items, not paragraphs. One screen.**
|
||||
@@ -12,26 +12,21 @@ watcher said "nothing is down" the whole time. Released and NOT yet delivered: s
|
||||
*This section is allowed to be longer than one screen, and each item says what happens if you do
|
||||
nothing.*
|
||||
|
||||
1. **Vouch the golden carrying controller 0.222.0** — Hub → Configuration → Day-0 artifacts.
|
||||
1. **Vouch the golden carrying controller 0.223.0** — Hub → Configuration → Day-0 artifacts.
|
||||
**It is already baked, published and round-trip verified**
|
||||
(`documentation/tests/golden-0.222.0-2026-08-23/`); only the vouch is left, and only you can do it.
|
||||
**It is a THREE-field save:** `golden_version` → **0.222.0**, `agent_version` → **0.130.0**,
|
||||
`min_agent` → **0.129.0**. **Then** raise the floor to **0.222.0**, last, in its own save.
|
||||
**If you do nothing:** the fleet stays on 0.221.1, where an app whose database has died reports
|
||||
nothing at all — no banner, no event — and the watcher keeps printing "0 currently down". New
|
||||
machines still receive 0.221.1.
|
||||
*(Thank you — the 0.221.1 vouch from earlier today has landed; the hub reads golden 0.221.1 and
|
||||
floor 0.221.1. Nothing is owed on that one.)*
|
||||
(`documentation/tests/golden-0.223.0-2026-08-23/`); only the vouch is left, and only you can do it.
|
||||
**It is a THREE-field save:** `golden_version` → **0.223.0**, `agent_version` → **0.130.0**,
|
||||
`min_agent` → **0.129.0**. **Then** raise the floor to **0.223.0**, last, in its own save.
|
||||
**If you do nothing:** the fleet stays on 0.222.0, where the app-down alarm shows on the dashboard
|
||||
and e-mails nobody, and where an app stopped from outside is still reported as if you had stopped
|
||||
it yourself. New machines still receive 0.222.0.
|
||||
*(The hub half is already live — v0.107.0 deployed itself through the manifest. Nothing owed there.)*
|
||||
|
||||
2. **A new switch has appeared for your customers, and it is OFF** — „Alkalmazás nem fut". **You get
|
||||
the e-mail either way**; the switch only decides whether the customer also does. This is what you
|
||||
asked for and it needs nothing from you. Mentioned so it is not a surprise the first time you see
|
||||
the settings page.
|
||||
|
||||
2. **An app that is stopped from outside still reports nothing** (R-386) — and this one I found today
|
||||
and deliberately did **not** fix. If a single-container app is stopped by hand on the machine
|
||||
rather than through the product, nothing is said: no banner, no e-mail, no operator event. I
|
||||
measured it: nine checks ran over four minutes and every one stayed silent. A comment in our own
|
||||
code claims the opposite, which is why nobody noticed. **The reason I stopped rather than fixed it:**
|
||||
from the outside this looks exactly like a customer pressing Stop, and the obvious fix would start
|
||||
alarming every time somebody legitimately stops their own app. That trade is a decision, not a
|
||||
patch. **If you do nothing:** it stays as it is — this is not a new fault, it has always been so;
|
||||
it is newly *known*.
|
||||
3. **Whether to change the hub password** (R-350). I printed it into my own session log on 20 August.
|
||||
Not in git, not in any saved file — in the log on this machine. **If you do nothing:** it stays as
|
||||
it is, at the risk you accept by leaving it. I can change it without ever showing you the new one.
|
||||
|
||||
Reference in New Issue
Block a user