R-459 CLOSED (MariaDB converts itself, proven by harness + live), golden 0.236.0 (R-467), the golden waiver (R-468)

Operator rulings 2026-09-13, both shipped the same day:
- MariaDB finishes its own conversion (catalog eec1228/bd32830/3525e35). Harness E3/E3b `proven`
  with engine_state_after "already upgraded to 12.3.3-MariaDB [exit=1]", the skip line gone, C3
  still `failed`; landed on demo-hp through the real 15-min cycle, nothing recreated, one deliberate
  restart logged "MariaDB upgrade not required" with the app serving. Evidence:
  documentation/audits/r459-close-2026-09-13/. The engine-major rule + gate keep every engine
  inside its major until Slice 4 (R-448) — removal tracked as R-469.
- Goldens on a cadence, not per release. golden_currency_gate.py reads a dated waiver
  (documentation/tests/golden-waiver.yml, <= 14 days, row-bound): valid + BEHIND -> loud advisory,
  exit 0; expired -> red again naming the date; UNRECORDED (R-385) never covered; malformed -> 2,
  never 0. Tests cases 5-15 incl. the R-421 decoy; red-proof old-vs-new on the real behind tree.
  R-242's vouch half stays open. Cadence in RUNBOOK-manual-build.md §4.2 + the checklist.
- Golden 0.236.0 baked, round-tripped, vouched, floor raised 0.232.0 -> 0.236.0
  (documentation/tests/golden-0.236.0-2026-09-13/) — the last per-release bake; the waiver was
  issued AFTER it landed. No --no-verify anywhere in this session.

Rows: R-459 CLOSED, R-467 CLOSED, R-242 narrowed; R-468/R-469/R-470/R-471 opened. 09 §3 gains
decisions 5 and 6; STATUS items 11 and 12 closed; CONTEXT records the cadence ruling.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-13 10:14:37 +02:00
parent 4b2e5608c2
commit ae59c31a84
62 changed files with 2607 additions and 220 deletions
@@ -125,6 +125,35 @@ These are rulings, not proposals. Anything specced against a different assumptio
**It does NOT make the Update button safer.** That is slice 4 (R-448), and it is where the backup
precondition goes. Slice 3 only stops the other twelve paths from doing the update's job.
### 2026-09-13 — the database engine finishes its own conversion, and the upgrade test goes wide
5. **DBs should be updated when the app moves, with proper precautions, tests and backoff plans**
— the operator's own words, ruling on `SPIKE-r459-mariadb-upgrade-2026-09-06.md`. SHIPPED in the
catalog the same day: every `mariadb:` sidecar (`bookstack-db`, `kimai-db`, `nextcloud-db`,
`romm-db`) carries `MARIADB_AUTO_UPGRADE=1`; `MARIADB_DISABLE_UPGRADE_BACKUP` stays unset. **Not an
image change, so `catalog_since` does not move.** The three precautions, because they are the real
content of the ruling:
1. **Proven before it ships** — `upgrade-test.py` re-ran E3 and E3b on the changed template and the
engine-state field shows the conversion RAN (`mariadb_upgrade_info` reads the new version, the
engine's own check says nothing further is needed, the entrypoint no longer prints
`skipped due to $MARIADB_AUTO_UPGRADE`), with the seeded data reading back after. C3 still
returns `failed`. Evidence: `audits/r459-close-2026-09-13/`.
2. **Watched as it lands** — the change travelled the real 15-minute cycle to demo-hp: the live
compose gained the setting, the sync recreated nothing, and one deliberate restart logged
`MariaDB upgrade not required` with the app serving (same evidence directory).
3. **A rule until Slice 4 is built** — the Update button still takes no backup, so **no template
may move a database-engine image across a major version until R-448 ships.** Catalog
`CLAUDE.md` states it; `scripts/check-engine-major.py` enforces it in the pre-push hook (the
CI half cannot, R-452); its removal is tracked as **R-469** so it is a deliberate act.
The setting is inert until an engine major moves, and precaution 3 keeps it that way.
6. **The upgrade test goes as wide as possible, through the nightly unattended sessions** — the
ruling on `STATUS.md` item 11. Not "the ~25 database apps first": all of them, as the nightly
rotation reaches them, one fixture per app through the app's own interface. **Browser-only apps
become reachable when CC runs on the operator's Windows workstation with Chrome** — the
`claude-in-chrome` route that DooPlex does not have — so an app recorded `inconclusive` for want
of a headless seed route (bookstack's file half, R-460) is deferred to that venue, not faked.
---
## 4. The vocabulary ruling — "rollback" is struck
@@ -314,6 +343,10 @@ app-half edge cannot produce and which no amount of readability would have surfa
restarts, no degradation, and the engine says `Check required!` every time, forever). Converting
properly **succeeds**, costs **7 s**, takes its own system-database backup, and **does not** cost the
ability to abort. **The trade that was expected here does not exist.**
- **2026-09-13 — the setting is in the catalog.** All four `mariadb:` sidecars carry
`MARIADB_AUTO_UPGRADE=1` (operator ruling, §3 decision 5), and `upgrade-test.py`'s engine-state field
now shows the conversion RUNNING on the bookstack edges. **And a gate holds the engines inside their
major until Slice 4:** `app-catalog-felhom.eu/scripts/check-engine-major.py` (R-469).
**Two rules for anything this arc builds around a database engine:**
@@ -428,10 +461,12 @@ Version strings stay in the logs, the API and the hub.
6. **The Update button is still unguarded.** It takes no backup, has no rollback, and can still
attempt a multi-major jump the app will refuse (R-40). **Slice 3 did not change that and must not
be read as having done so** — the precondition is slice 4 (R-448).
7. **An engine major can be applied without its datadir upgrade, and nothing notices.** Measured
2026-09-06: the catalog's own bookstack transition starts MariaDB 12.3 on an 11.6 datadir, and the
image logs that the required upgrade was **skipped** because the template sets no
`MARIADB_AUTO_UPGRADE`. The app serves. Whether that ever breaks is **not** established. **R-459.**
7. ~~**An engine major can be applied without its datadir upgrade, and nothing notices.**~~ **CLOSED
2026-09-13 for MariaDB (R-459):** every `mariadb:` sidecar carries `MARIADB_AUTO_UPGRADE=1`, and the
harness shows the conversion running on the E3/E3b edges (§3 decision 5). **What stays true:** the
PostgreSQL half (R-463) has no equivalent — the image performs no `pg_upgrade` — and the
engine-major rule (§3 precaution 3, R-469) is what keeps both engines inside their major until
Slice 4 gives the Update button a backup.
8. **Only three of 53 apps have ever had an upgrade measured**, and one of them (bookstack) can only
be half-proven headlessly (**R-460**). The widening is **R-462**, costed with real numbers.
9. **The hub does not record image tags at all.** Its report's container payload carries name, state,