R-459 CLOSED (MariaDB converts itself, proven by harness + live), golden 0.236.0 (R-467), the golden waiver (R-468)
Operator rulings 2026-09-13, both shipped the same day: - MariaDB finishes its own conversion (catalog eec1228/bd32830/3525e35). Harness E3/E3b `proven` with engine_state_after "already upgraded to 12.3.3-MariaDB [exit=1]", the skip line gone, C3 still `failed`; landed on demo-hp through the real 15-min cycle, nothing recreated, one deliberate restart logged "MariaDB upgrade not required" with the app serving. Evidence: documentation/audits/r459-close-2026-09-13/. The engine-major rule + gate keep every engine inside its major until Slice 4 (R-448) — removal tracked as R-469. - Goldens on a cadence, not per release. golden_currency_gate.py reads a dated waiver (documentation/tests/golden-waiver.yml, <= 14 days, row-bound): valid + BEHIND -> loud advisory, exit 0; expired -> red again naming the date; UNRECORDED (R-385) never covered; malformed -> 2, never 0. Tests cases 5-15 incl. the R-421 decoy; red-proof old-vs-new on the real behind tree. R-242's vouch half stays open. Cadence in RUNBOOK-manual-build.md §4.2 + the checklist. - Golden 0.236.0 baked, round-tripped, vouched, floor raised 0.232.0 -> 0.236.0 (documentation/tests/golden-0.236.0-2026-09-13/) — the last per-release bake; the waiver was issued AFTER it landed. No --no-verify anywhere in this session. Rows: R-459 CLOSED, R-467 CLOSED, R-242 narrowed; R-468/R-469/R-470/R-471 opened. 09 §3 gains decisions 5 and 6; STATUS items 11 and 12 closed; CONTEXT records the cadence ruling. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,31 @@
|
||||
## the golden waiver — goldens on a cadence, not per release (2026-09-13, R-468 / R-242) — NOT A RELEASE
|
||||
|
||||
**No product code, no version bump, no image.** A scripts change is not a release.
|
||||
|
||||
`golden_currency_gate.py` now reads a dated waiver, `documentation/tests/golden-waiver.yml` (`issued`,
|
||||
`expires`, `reason`, `register_row`). Operator ruling 2026-09-13: **bake on a cadence — weekly, and
|
||||
always before any drill or fresh install — not per release.** The gate had tripped on every release
|
||||
by design and the only honest ways past it were a bake or a declared `--no-verify`; August measured
|
||||
25 goldens in 26 days and thirteen bypasses.
|
||||
|
||||
- **Valid waiver + golden BEHIND the record** → a loud ADVISORY naming the waiver, its expiry and how
|
||||
many releases the golden lags; exit 0. A waived conviction stays visible on every push.
|
||||
- **Expired waiver** → exit 1 exactly as before, and the message says it EXPIRED on `<date>`.
|
||||
- **Unrecorded golden (R-385)** → exit 1 regardless; the waiver is named and declared NOT to cover
|
||||
it. **The asymmetry is the design:** behind is a cadence choice, unrecorded is the fleet running
|
||||
something nobody wrote down.
|
||||
- **Malformed waiver** — more than 14 days, absent or unparseable date, empty reason, a row that does
|
||||
not exist in `OPEN-ITEMS.md` — → exit 2 INCONCLUSIVE, never 0, never silently ignored. The 14-day
|
||||
cap lives in the gate (`WAIVER_MAX_DAYS`), not in prose. The register is read for ONE fact (does
|
||||
the row exist), never for meaning (R-421).
|
||||
- `GOLDEN_GATE_*` environment variables are a **test seam**: they move where the gate reads, never
|
||||
what it decides. `test_golden_currency_gate.py` gains cases 5–15 (Scenarios E/F/G/H, each with its
|
||||
wrong direction; the R-421 decoy — a file saying only `expires` — returns 2). **Red-proof:** the
|
||||
old gate on the real tree with a valid waiver planted → exit 1 (it cannot read one); the new gate on
|
||||
synthetic "behind" trees → 0 with the advisory present.
|
||||
- The docstring's *"honest fix is a recorded waiver, never a habit of bypassing"* is now a mechanism.
|
||||
**R-242's OTHER half — nothing gates the VOUCH — is unchanged and still open.**
|
||||
|
||||
## the decoy sweep — can this gate be fooled by a label? (2026-09-01, R-421) — NOT A RELEASE
|
||||
|
||||
**No product code, no version bump, no image, no golden.** A scripts change is not a release.
|
||||
|
||||
Reference in New Issue
Block a user