docs: controller v0.228.0 — R-399/R-400 closed, R-401/R-402 filed
gates / gates (push) Failing after 19s

STATUS.md: header said 2026-08-23 over a 2026-08-30 body, and two "Waiting on
you" items were both numbered 4 — both fixed. R-399 leaves that section (decided
and shipped); the depth change is stated in plain words and the remaining items
each say what happens if Viktor does nothing.

00-capability-map.md: the off-site verification row now carries its DEPTH, and
its live citation is the 2026-08-31 run at 100%. The weekly firing at the new
depth stays IMPLEMENTED, not PROVEN-LIVE.

07-backup-architecture.md §10.2: R-399 recorded closed, with the one sentence
that stops it being turned back down — the structure check PASSED a
size-preserving pack corruption. R-87 untouched and still OPEN.

Register: R-399 and R-400 compressed into CLOSED-ITEMS.md with their reasoning
kept and 300d7e8 named as the commit holding the originals. R-401 filed with a
TRIGGER (the slow-check WARN firing) rather than a date. R-402 filed: the
integrity verdict and its depth are on the wire and no hub surface reads either.
OPEN 166 -> 165, CLOSED 148 -> 150.

wire_contract_gate.py: offsite.last_integrity_depth allowlisted WITH ITS REASON
beside its sibling last_integrity_ok, both to be deleted together when a hub
surface is built (R-402).
This commit is contained in:
2026-08-31 10:39:05 +02:00
parent db0812b6f2
commit 77a5a1154b
6 changed files with 33 additions and 32 deletions
+9
View File
@@ -171,6 +171,15 @@ ALLOWLIST = {
"that card. The sibling `offsite.last_integrity_check` is NOT allowlisted and passes on its "
"own — the string already occurs hub-side. **When a hub surface is built, delete this entry.**"),
(_CH, "offsite.last_integrity_depth"): (
"R-399, controller v0.228.0: the DEPTH the verdict was reached at, published beside "
"last_integrity_ok above and unconsumed for the identical reason. It matters because 'checked, "
"OK' means two different things at structure depth and at 100%, so a hub surface that shows the "
"verdict without the depth shows the same words for a check that re-read every byte and one "
"that only read the index. Absent = the box cannot answer (a controller older than v0.228.0), "
"never 'structure'. **Delete this entry with its sibling when a hub surface is built** — filed "
"as R-402 in OPEN-ITEMS.md."),
(_AH, "wireguard.last_handshake_age_s"): (
"redundant: hub-side wgsync reconciles peers from its own state, and the OOB path's own "
"wg_handshake_age_s IS now decoded (into HostOOBRow, for the alert text)."),