R-459 CLOSED (MariaDB converts itself, proven by harness + live), golden 0.236.0 (R-467), the golden waiver (R-468)
Operator rulings 2026-09-13, both shipped the same day: - MariaDB finishes its own conversion (catalog eec1228/bd32830/3525e35). Harness E3/E3b `proven` with engine_state_after "already upgraded to 12.3.3-MariaDB [exit=1]", the skip line gone, C3 still `failed`; landed on demo-hp through the real 15-min cycle, nothing recreated, one deliberate restart logged "MariaDB upgrade not required" with the app serving. Evidence: documentation/audits/r459-close-2026-09-13/. The engine-major rule + gate keep every engine inside its major until Slice 4 (R-448) — removal tracked as R-469. - Goldens on a cadence, not per release. golden_currency_gate.py reads a dated waiver (documentation/tests/golden-waiver.yml, <= 14 days, row-bound): valid + BEHIND -> loud advisory, exit 0; expired -> red again naming the date; UNRECORDED (R-385) never covered; malformed -> 2, never 0. Tests cases 5-15 incl. the R-421 decoy; red-proof old-vs-new on the real behind tree. R-242's vouch half stays open. Cadence in RUNBOOK-manual-build.md §4.2 + the checklist. - Golden 0.236.0 baked, round-tripped, vouched, floor raised 0.232.0 -> 0.236.0 (documentation/tests/golden-0.236.0-2026-09-13/) — the last per-release bake; the waiver was issued AFTER it landed. No --no-verify anywhere in this session. Rows: R-459 CLOSED, R-467 CLOSED, R-242 narrowed; R-468/R-469/R-470/R-471 opened. 09 §3 gains decisions 5 and 6; STATUS items 11 and 12 closed; CONTEXT records the cadence ruling. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -125,6 +125,35 @@ These are rulings, not proposals. Anything specced against a different assumptio
|
||||
**It does NOT make the Update button safer.** That is slice 4 (R-448), and it is where the backup
|
||||
precondition goes. Slice 3 only stops the other twelve paths from doing the update's job.
|
||||
|
||||
### 2026-09-13 — the database engine finishes its own conversion, and the upgrade test goes wide
|
||||
|
||||
5. **DBs should be updated when the app moves, with proper precautions, tests and backoff plans**
|
||||
— the operator's own words, ruling on `SPIKE-r459-mariadb-upgrade-2026-09-06.md`. SHIPPED in the
|
||||
catalog the same day: every `mariadb:` sidecar (`bookstack-db`, `kimai-db`, `nextcloud-db`,
|
||||
`romm-db`) carries `MARIADB_AUTO_UPGRADE=1`; `MARIADB_DISABLE_UPGRADE_BACKUP` stays unset. **Not an
|
||||
image change, so `catalog_since` does not move.** The three precautions, because they are the real
|
||||
content of the ruling:
|
||||
1. **Proven before it ships** — `upgrade-test.py` re-ran E3 and E3b on the changed template and the
|
||||
engine-state field shows the conversion RAN (`mariadb_upgrade_info` reads the new version, the
|
||||
engine's own check says nothing further is needed, the entrypoint no longer prints
|
||||
`skipped due to $MARIADB_AUTO_UPGRADE`), with the seeded data reading back after. C3 still
|
||||
returns `failed`. Evidence: `audits/r459-close-2026-09-13/`.
|
||||
2. **Watched as it lands** — the change travelled the real 15-minute cycle to demo-hp: the live
|
||||
compose gained the setting, the sync recreated nothing, and one deliberate restart logged
|
||||
`MariaDB upgrade not required` with the app serving (same evidence directory).
|
||||
3. **A rule until Slice 4 is built** — the Update button still takes no backup, so **no template
|
||||
may move a database-engine image across a major version until R-448 ships.** Catalog
|
||||
`CLAUDE.md` states it; `scripts/check-engine-major.py` enforces it in the pre-push hook (the
|
||||
CI half cannot, R-452); its removal is tracked as **R-469** so it is a deliberate act.
|
||||
The setting is inert until an engine major moves, and precaution 3 keeps it that way.
|
||||
|
||||
6. **The upgrade test goes as wide as possible, through the nightly unattended sessions** — the
|
||||
ruling on `STATUS.md` item 11. Not "the ~25 database apps first": all of them, as the nightly
|
||||
rotation reaches them, one fixture per app through the app's own interface. **Browser-only apps
|
||||
become reachable when CC runs on the operator's Windows workstation with Chrome** — the
|
||||
`claude-in-chrome` route that DooPlex does not have — so an app recorded `inconclusive` for want
|
||||
of a headless seed route (bookstack's file half, R-460) is deferred to that venue, not faked.
|
||||
|
||||
---
|
||||
|
||||
## 4. The vocabulary ruling — "rollback" is struck
|
||||
@@ -314,6 +343,10 @@ app-half edge cannot produce and which no amount of readability would have surfa
|
||||
restarts, no degradation, and the engine says `Check required!` every time, forever). Converting
|
||||
properly **succeeds**, costs **7 s**, takes its own system-database backup, and **does not** cost the
|
||||
ability to abort. **The trade that was expected here does not exist.**
|
||||
- **2026-09-13 — the setting is in the catalog.** All four `mariadb:` sidecars carry
|
||||
`MARIADB_AUTO_UPGRADE=1` (operator ruling, §3 decision 5), and `upgrade-test.py`'s engine-state field
|
||||
now shows the conversion RUNNING on the bookstack edges. **And a gate holds the engines inside their
|
||||
major until Slice 4:** `app-catalog-felhom.eu/scripts/check-engine-major.py` (R-469).
|
||||
|
||||
**Two rules for anything this arc builds around a database engine:**
|
||||
|
||||
@@ -428,10 +461,12 @@ Version strings stay in the logs, the API and the hub.
|
||||
6. **The Update button is still unguarded.** It takes no backup, has no rollback, and can still
|
||||
attempt a multi-major jump the app will refuse (R-40). **Slice 3 did not change that and must not
|
||||
be read as having done so** — the precondition is slice 4 (R-448).
|
||||
7. **An engine major can be applied without its datadir upgrade, and nothing notices.** Measured
|
||||
2026-09-06: the catalog's own bookstack transition starts MariaDB 12.3 on an 11.6 datadir, and the
|
||||
image logs that the required upgrade was **skipped** because the template sets no
|
||||
`MARIADB_AUTO_UPGRADE`. The app serves. Whether that ever breaks is **not** established. **R-459.**
|
||||
7. ~~**An engine major can be applied without its datadir upgrade, and nothing notices.**~~ **CLOSED
|
||||
2026-09-13 for MariaDB (R-459):** every `mariadb:` sidecar carries `MARIADB_AUTO_UPGRADE=1`, and the
|
||||
harness shows the conversion running on the E3/E3b edges (§3 decision 5). **What stays true:** the
|
||||
PostgreSQL half (R-463) has no equivalent — the image performs no `pg_upgrade` — and the
|
||||
engine-major rule (§3 precaution 3, R-469) is what keeps both engines inside their major until
|
||||
Slice 4 gives the Update button a backup.
|
||||
8. **Only three of 53 apps have ever had an upgrade measured**, and one of them (bookstack) can only
|
||||
be half-proven headlessly (**R-460**). The widening is **R-462**, costed with real numbers.
|
||||
9. **The hub does not record image tags at all.** Its report's container payload carries name, state,
|
||||
|
||||
Reference in New Issue
Block a user