docs: v0.72.0 ship report + live validation, CONTEXT rulings, DIAG-f10 R-70/R-71 status annotations

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NKSN3gSg4TKVBBqkwW2djR
This commit is contained in:
2026-07-23 13:05:03 +02:00
parent 92681bda6c
commit 527d81cf70
3 changed files with 105 additions and 50 deletions
@@ -119,10 +119,16 @@ now reflects the customer. Nightly offsite is scheduled (daily 04:15 guest-UTC).
- **R-70 (P2-HIGH)** — the pending/failed offsite last mile is invisible on BOTH surfaces; the hub
cannot distinguish staged/consumed/applied. Couple to R-31's async/status-card idiom and the
R-39 `consumed_at` honesty-gauge precedent.
**→ SHIPPED 2026-07-23 (hub v0.72.0 + controller v0.161.0):** detector `offsite.DeliveryStateFor`,
operator-card state line (static copy deleted), `offsite_delivery_stuck` warning, controller
truthful empty-state banner. See `felhom.eu/REPORT.md` (2026-07-23) + hub CHANGELOG v0.72.0.
- **R-71 (P1)** — the day-0 race itself: managed floor-update vs apply-bridge, consume-then-persist
not crash-safe. **This recurs on every fresh onboarding** whose ISO floor lags the managed floor
(the update fires minutes after first boot, exactly when the bridge runs). demo-felhom escaped by
timing only.
**→ PARTIAL 2026-07-23: (c) self-heal restage SHIPPED in hub v0.72.0** (R-39(a)-guarded, one
restage/customer/24 h, every firing a warning event; unit-proven + red-proofed, NOT live-fired —
arms on the next natural occurrence). (a) day-0 ordering stays open — its own spec.
- Audit F10 row annotated: **offsite leg RESOLVED** (this record); the PBS-DR-snapshot half of F10
**stays open** pending F13 (cadence ruling) and the deliberate DR ceremony R-moment on demo-hp.