golden 0.229.0 baked, vouched, floor raised — R-242's sixth debt PAID the same day
gates / gates (push) Successful in 16s

GOLDEN_SHA256 39aa886df77b21757aef3b298a389343dc0df5134bb0f14e8f92a451d7bdae87, 656 864 331 B.

The evidence is the ROUND TRIP, not the build log: the published bytes were downloaded back and
match the bake on both size and sha, and ./etc/felhom-controller-image read OUT of the downloaded
archive says felhom-controller:0.229.0 - the delivered artifact naming the controller it will start.
A THIRD independent reader agreed before anything was vouched: the hub's own Day-0 dropdown read the
same sha straight from Gitea, a different code path.

Both pre-gates were proven able to see something before their negative results were believed - the
404 pre-gate against a 200 from 0.228.0, and the token-leak grep against a seeded throwaway copy.
Acceptance markers counted on the COMMITTED log: 1/1/1/1 present, 0/0/0 absent.

The vouch is a three-field change, checked rather than assumed: MinAgent 0.129.0 read from the
golden's controller CHANGELOG header, agent_version 0.130.0 >= min_agent 0.129.0 (not the R-216
shape), agent_sha256 and wrapper_sha256 carried through explicitly because the handler clears a
field it is not sent. Verified by re-reading the manifest, never by trusting the flash. The R-120
gate PASSED rather than being bypassed - fleet newest 0.229.0, golden 0.229.0.

The floor is proven ACTING, not merely set: demo-felhom self-updated 0.228.0 -> 0.229.0 and logged
settle-gate GO at/above floor 0.229.0. Nobody deployed to that box. Both demo machines now carry the
Tier-2 unit restore.

golden_currency_gate.py went red -> green; the --no-verify bypass declared on c2de785 is now
historical. R-242's other half is untouched and still open: nothing gates the VOUCH itself.

Teardown: build guest 9100 destroyed --purge, token/runner/script/log shredded AFTER the log was
copied out, VM powered off, qemu confirmed gone from ps -eo comm, disk reverted to virgin.
This commit is contained in:
2026-08-31 12:38:01 +02:00
parent c2de785bf2
commit 83ff9e8e38
4 changed files with 467 additions and 8 deletions
+9 -7
View File
@@ -13,13 +13,14 @@ delivered; both demo machines are on it and nothing is waiting on you about this
*This section is allowed to be longer than one screen, and each item says what happens if you do
nothing.*
1. **Nothing about delivery — the golden train is current.** Golden **0.228.0** was baked, published,
round-trip verified, vouched, and the fleet floor raised to 0.228.0 on 2026-08-31. Both demo
machines run it; **`demo-felhom` got there by itself** in under a minute and re-registered its
off-site check without anyone touching it. A machine installed today receives 0.228.0 and
everything shipped today. Evidence: `documentation/tests/golden-0.228.0-2026-08-31/`.
1. **Nothing about delivery — the golden train is current.** Golden **0.229.0** was baked, published,
round-trip verified, vouched, and the fleet floor raised to 0.229.0 on 2026-08-31 (the second bake
that day; 0.228.0 was the first). Both demo machines run it; **`demo-felhom` got there by itself**
and re-registered its jobs without anyone touching it. A machine installed today receives 0.229.0
and everything shipped today, **including the restore from the second drive**. Evidence:
`documentation/tests/golden-0.229.0-2026-08-31/`.
2. **Nothing else about this release.** Everything in 0.228.0 is a fix to code that ships in the
2. **Nothing else about this release.** Everything in 0.229.0 is a fix to code that ships in the
controller image; no customer action, no data migration, no credential change.
3. **Whether to change the hub password** (R-350). I printed it into my own session log on 20 August.
@@ -95,7 +96,8 @@ off. **`peti-felhom` is a real machine we have not heard from since 15 July** an
database), and the undo copies no longer pile up forever — three per app, and they were being copied
off-site permanently.
- **The copy on the second drive can now bring an app back** (R-102 + R-103, controller 0.229.0,
proven on `demo-hp`). Every night the box copied each app's whole recovery package onto the second
proven on `demo-hp`, **and delivered** — golden 0.229.0 is vouched and the fleet floor is raised, so
a machine installed today has it). Every night the box copied each app's whole recovery package onto the second
drive — its settings, its database and its data. It did that for months. **Nothing could open those
copies.** No button, no screen, no command. That mattered most in the one fault the second drive
exists for: if the first drive dies, the package on it dies too, and the copy that survived could