Update arc: the undo and ladder spiked, the build plan for the 2026-09-23 rulings
gates / gates (push) Successful in 26s

- Part 1 (09 §6.1a, audit): the undo performed by hand on 9202 for docmost
  (PostgreSQL), romm (MariaDB) and vikunja (SQLite volume) - all three came
  back with data written before AND after the backup. The product's loader
  cannot do it: over a migrated PG database it fails on the new tables'
  foreign keys; over MariaDB it leaves them behind. A truncated PG copy loads
  rc 0 into an empty database. No-DB apps have no last-second copy.
- Part 2: one press jumps A -> C; the box's catalog clone is depth 1.
  Ladder format recommended: update_ladder in .felhom.yml, not git history.
- Part 3: memory watch red-proof results (harness change in the catalog repo).
- Part 4 (09 §6.4): ten parts, ~22 evenings; one open point (R-643).
- Rows R-637..R-644 opened; R-446/450/451/462/463 updated. STATUS, CONTEXT.

No product code. Live catalog untouched; 9202 back on it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-23 08:54:41 +02:00
parent 805ad1e962
commit 4c92beab8f
67 changed files with 5977 additions and 162 deletions
+23
View File
@@ -14,6 +14,29 @@
> language, one screen, no identifiers in the prose. Same subjects, different readers; merging them
> would make one of the two audiences stop reading. `STATUS.md` is also a **view of `OPEN-ITEMS.md`**
> and holds nothing of its own; this file does hold its own content, namely the standing rulings below.
## 2026-09-23 — the operator rules on automatic updates (`09` §3 decisions 11–18); two spikes say what the build needs
**Operator rulings, not CC decisions.** One window = a leg of the backup chain (11); automatic, per-box
switch on by default (12); **the test decides, not the tag** (13, replaces decision 3's "never across
a major"); the ladder, one tested step at a time (14); **the box undoes a failed update itself** (15,
replaces §6.1's no-auto-undo); PostgreSQL majors converted by the box (16); digests recorded by the
catalog and pulled exactly (17); fleet view later (18). §3b is kept, marked ANSWERED.
**The two mechanisms were spiked the same day, by hand, on 9202** (`audits/update-rulings-2026-09-23/`):
- **The undo works** — docmost and romm, whose OLD versions refuse migrated data, came back with data
written before AND after the backup, ≈16 s and ≈38 s. **But not with the loader the product has:**
`ImportDump` over a migrated PostgreSQL database FAILS on the new tables' foreign keys, and over
MariaDB leaves the new tables behind (R-638). A truncated PostgreSQL copy loads rc 0 into an EMPTY
database and `ValidateDump` would accept it (R-640). No-DB apps have no last-second copy (R-641).
Build list: R-637.
- **The ladder is absent**: one press jumped 2.3.0 → 2.5.0; the box's catalog clone is `--depth 1`
and cannot see steps. Recommended format: `update_ladder:` in `.felhom.yml`, each intermediate step
carrying its own definition — not the git history.
- **The harness watches memory** (`upgrade-test.py` v2): the RomM template as promoted fails at +76 s.
**Build order and costs:** `09` §6.4 (≈22 evenings). **One open point for the operator:** the chain as
ruled leaves the update leg ≤15 min a night (R-643).
## 2026-09-20 — localisation slice 5: the app catalog's copy model is MEASURED, not proposed (R-560)
`architecture/10-localisation.md` §7 was a proposal; it is now a fact, with the numbers it was