diff --git a/documentation/audits/night-burndown-2026-10-06/NIGHT-LOG.md b/documentation/audits/night-burndown-2026-10-06/NIGHT-LOG.md index a641b684..9e36cb04 100644 --- a/documentation/audits/night-burndown-2026-10-06/NIGHT-LOG.md +++ b/documentation/audits/night-burndown-2026-10-06/NIGHT-LOG.md @@ -52,3 +52,4 @@ no reboot. | R-762 | **measured** on the bench (runserver 52 %, gunicorn 1w 43 %, 2w 41 % of 384M; no kills); the numbers pick gunicorn with 2 workers; template change not built. Bench back to stopped; no Docker on DooPlex | 25 | (this batch) | | R-516 | **22 Go-literal messages moved into the bundle** (14 formal → te-form; English added); a detached NAS attach failure follows the reader language; 2 red-proofs | 60 | controller `3d6ba28` | | R-330 | **wire half built** in three repos (agent sends 187/188/199, controller decodes, hub models; carried only — no verdict reads them); 5 red-proofs | 15 | hub/agent/controller (this batch) | +| (hub release) | **NOT DEPLOYED.** 00:10 the release commit (`hub/CHANGELOG.md` v0.141.0: R-366, R-31, R-330 wire) was pushed, green; at 00:12 the image build (`build/felhom-hub/build.sh 0.141.0 --push`) was **refused by the session's permission check** („Production Deploy"). Stopped there (brief Rules 3), no workaround; the manifest still names 0.140.0, nothing changed on the hub. The CHANGELOG says so. The day session builds and deploys 0.141.0 | 5 | (this batch) | diff --git a/hub/CHANGELOG.md b/hub/CHANGELOG.md index 61308d0c..af0405fb 100644 --- a/hub/CHANGELOG.md +++ b/hub/CHANGELOG.md @@ -1,6 +1,6 @@ ## v0.141.0 — a reinstall's new backup key no longer overwrites the old one in the escrow; a second off-site Save is refused, not raced; the SMART counters are modelled (R-366, R-31, R-330) (2026-10-07) -**Operator action on deploy: none.** Released in the night window (brief `drills/NIGHT-burndown-2026-10-06.md` §1.3). +**NOT BUILT, NOT DEPLOYED (2026-10-07 00:12):** the night session's permission check refused the image build, so the night window was not used. The day session builds and deploys it (`felhom-build-deploy` skill). **Operator action on deploy: none.** - hub (R-31): a second Save of a customer's off-site settings while the first is still provisioning is refused at once (409, „already running — wait about a minute, then reload; do not save again") instead of racing it: both used to see no sub-account and create one (for a dedicated box, a second bill). Per customer, in memory; another customer is never blocked. Tests `TestProvision_R31_*` (red-proved: `documentation/audits/night-burndown-2026-10-06/hub/R-31-red.txt`). The async save with a status card stays open. - hub: the current escrow row is kept (retained, operator-only) when the whole-guest backup key's fingerprint changes, not only when the restic password changes. A reinstall mints a new PBS key while R-241 keeps the restic password, so the old rule overwrote the only copy of the old key and every pre-reinstall whole-guest archive became unopenable. An empty fingerprint on either side is unknown, not a change. Tests `TestSaveHostEscrow_R366_*` (red-proved: `documentation/audits/night-burndown-2026-10-06/r366/`).