docs: controller v0.228.0 — R-399/R-400 closed, R-401/R-402 filed
gates / gates (push) Failing after 19s
gates / gates (push) Failing after 19s
STATUS.md: header said 2026-08-23 over a 2026-08-30 body, and two "Waiting on you" items were both numbered 4 — both fixed. R-399 leaves that section (decided and shipped); the depth change is stated in plain words and the remaining items each say what happens if Viktor does nothing. 00-capability-map.md: the off-site verification row now carries its DEPTH, and its live citation is the 2026-08-31 run at 100%. The weekly firing at the new depth stays IMPLEMENTED, not PROVEN-LIVE. 07-backup-architecture.md §10.2: R-399 recorded closed, with the one sentence that stops it being turned back down — the structure check PASSED a size-preserving pack corruption. R-87 untouched and still OPEN. Register: R-399 and R-400 compressed into CLOSED-ITEMS.md with their reasoning kept and 300d7e8 named as the commit holding the originals. R-401 filed with a TRIGGER (the slow-check WARN firing) rather than a date. R-402 filed: the integrity verdict and its depth are on the wire and no hub surface reads either. OPEN 166 -> 165, CLOSED 148 -> 150. wire_contract_gate.py: offsite.last_integrity_depth allowlisted WITH ITS REASON beside its sibling last_integrity_ok, both to be deleted together when a hub surface is built (R-402).
This commit is contained in:
@@ -1,7 +1,8 @@
|
||||
# STATUS — what works, what's broken, what's next
|
||||
|
||||
**Updated 2026-08-23 — you now hear about EVERY broken app, not just the first one each hour. The
|
||||
hub deployed itself; nothing is waiting on you except the floor from the last release.**
|
||||
**Updated 2026-08-31 — the weekly off-site check now re-reads your actual data, not just the list of
|
||||
it. A third of the debug page did nothing and no longer exists. One thing is waiting on you: the
|
||||
golden and the floor for 0.228.0.**
|
||||
|
||||
> **A view, not a source.** `documentation/backlog/OPEN-ITEMS.md` is the authority; this page restates
|
||||
> part of it in plain words, and **nothing may exist only here**. **Items, not paragraphs. One screen.**
|
||||
@@ -12,29 +13,16 @@ hub deployed itself; nothing is waiting on you except the floor from the last re
|
||||
*This section is allowed to be longer than one screen, and each item says what happens if you do
|
||||
nothing.*
|
||||
|
||||
1. **How deep should the off-site check go?** (R-399). The box now checks its off-site store weekly.
|
||||
The check it runs today reads the catalogue — it catches a missing or unreadable backup, and it does
|
||||
**not** re-read the stored bytes, so it cannot see a file that has quietly rotted.
|
||||
**What it costs to go deeper, measured on your own machine today, not guessed:**
|
||||
the shallow check takes **35.0 s**; re-reading **all** the data takes **39.2 s**. Four seconds more.
|
||||
That is because the time goes on talking to the off-site box, not on moving data — and it will stop
|
||||
being true as the store grows, so this is worth re-measuring, not deciding once forever.
|
||||
**If you do nothing:** the catalogue is checked weekly and the stored bytes are never re-read.
|
||||
I can turn it on with one setting whenever you say.
|
||||
1. **Bake and vouch a golden that carries 0.228.0, and raise the floor.** The fleet is on **0.227.1**.
|
||||
Controller **0.228.0** is built, deployed to `demo-hp` and proven there, but a golden and the floor
|
||||
are yours to move. **If you do nothing:** a machine installed tomorrow gets 0.227.1, whose weekly
|
||||
check reads only the catalogue.
|
||||
|
||||
2. **Nothing about delivery — the golden train is current.** Golden **0.227.1** was baked, published,
|
||||
round-trip verified, vouched, and the fleet floor raised to 0.227.1 on 2026-08-30. Both demo
|
||||
machines run it; **`demo-felhom` got there by itself** and started the new off-site check on its own
|
||||
schedule without anyone touching it. A machine installed today receives 0.227.1 and everything
|
||||
shipped today. Evidence: `documentation/tests/golden-0.227.1-2026-08-30/`.
|
||||
|
||||
3. **Nothing else.** Everything in the releases of 2026-08-30 is a fix to code that ships in the
|
||||
controller image; no customer action, no data migration, no credential change.
|
||||
|
||||
4. **Whether to change the hub password** (R-350). I printed it into my own session log on 20 August.
|
||||
2. **Whether to change the hub password** (R-350). I printed it into my own session log on 20 August.
|
||||
Not in git, not in any saved file — in the log on this machine. **If you do nothing:** it stays as
|
||||
it is, at the risk you accept by leaving it. I can change it without ever showing you the new one.
|
||||
4. **`demo-hp`'s network setup does not match our own notes** (R-338) — the machine works, the page is
|
||||
|
||||
3. **`demo-hp`'s network setup does not match our own notes** (R-338) — the machine works, the page is
|
||||
wrong, or the other way round. **If you do nothing:** the page keeps misleading the next session,
|
||||
as it misled one by an hour.
|
||||
|
||||
@@ -131,12 +119,14 @@ off. **`peti-felhom` is a real machine we have not heard from since 15 July** an
|
||||
|
||||
## Broken, or knowingly incomplete
|
||||
|
||||
- **The off-site store is only checked SHALLOWLY, and the deep check is switched off** (R-399).
|
||||
This is the honest version of what shipped today. The box now checks its own off-site store about
|
||||
once a week (R-359, controller 0.227.0) — and the check it runs reads the *catalogue* of the backups,
|
||||
not the backups themselves. **We proved the difference:** a copy was damaged in a way that left its
|
||||
size unchanged, and the shallow check said „no errors were found". Only the deep check caught it.
|
||||
The deep check is built and **off**, waiting for your decision — see item 2 under „Waiting on you".
|
||||
- **We do not know what the deep check costs on a BIG store** (R-401). Since 0.228.0 the weekly check
|
||||
re-reads **all** your stored data, not just the list of it. We had to: a copy was damaged in a way
|
||||
that left its size unchanged, and the old shallow check said „no errors were found". Only the deep
|
||||
check caught it. **The cost we measured was four seconds** — 35.0 s before, 39.2 s after — but that
|
||||
was on a 134 MB store, and it will not stay four seconds. So the box now tells us: any check that
|
||||
takes longer than five minutes writes a warning naming this item. **If you do nothing:** every
|
||||
machine re-reads its whole store every week, however large it grows, and the first person to notice
|
||||
would be a customer whose upload is busy. The warning is there so that does not happen.
|
||||
- **We ask the off-site box a question about once a second** (R-336) — ~85,000 a day for a box we
|
||||
write to weekly. The leak that made this dangerous is fixed (R-344); the volume is not. The ceiling
|
||||
is **under a year** away on the corrected measurement, not two.
|
||||
|
||||
Reference in New Issue
Block a user