burn-down Part B: 14 small rows fixed and closed across four repos (306 -> 292); no :latest in the hub build; gate list pinned; closed-id duplicates refused; R-262 subset pinned
gates / gates (push) Failing after 1m40s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 17:10:38 +02:00
parent f5a0aeb0b8
commit b26d292a64
19 changed files with 220 additions and 35 deletions
@@ -0,0 +1,6 @@
### R262-a: drop skipped from knownUnmodelled
--- FAIL: TestR262_RestoreTestFieldsAreAKnownSubset (0.00s)
FAIL
### R262-b: the hub stops decoding source_tier
--- FAIL: TestR262_RestoreTestFieldsAreAKnownSubset (0.00s)
FAIL
@@ -0,0 +1,9 @@
### R263-a: ClearBackupTarget writes true
1700: s.StoragePaths[i].BackupTarget = true
--- FAIL: TestR263_OnlySetBackupTargetGrantsTheRole (0.24s)
r263_backup_target_writers_test.go:73: BackupTarget may be granted outside SetBackupTarget at: [../settings/settings.go:1700:3]
FAIL
### R263-b: a composite literal BackupTarget: true in another package
--- FAIL: TestR263_OnlySetBackupTargetGrantsTheRole (0.28s)
r263_backup_target_writers_test.go:73: BackupTarget may be granted outside SetBackupTarget at: [../web/zz_r263_decoy.go:5:50]
FAIL
+14
View File
@@ -62,6 +62,20 @@ The full text of every row below: `git show ab2b3049:documentation/backlog/OPEN-
| **R-818** | **Two changelogs cite register ids for other findings.** (P4) | CLOSED 2026-10-05 — CORRECTED | Dated correction notes under hub v0.109.0 (`hub/CHANGELOG.md`) and controller v0.224.0 + v0.225.0 (`felhom-controller/CHANGELOG.md`): those two findings never had register rows of their own — the triage's „the real ids are in CLOSED-ITEMS" was itself wrong (no closed row names hub v0.109.0 or controller v0.224.0/v0.225.0). Nothing renumbered. |
| **R-755** | **[P3-LOW] wger runs Django's DEVELOPMENT server in production: `manage.py runserver`, because the template does not set `WGER_USE_GUNICORN=True`.** (P3) | CLOSED 2026-10-05 — DUPLICATE of R-762 (its unique fact moved there) | Still true: templates/wger/docker-compose.yml has no WGER_USE_GUNICORN (grep empty). R-762 (open, read) states 'Owner decides together with R-755 (same server question)' and its fix names 'the gunicorn switch of R-755'. |
| **R-446** | **[P2-MEDIUM] „Naprakész" can be FALSE, and the badge that says it cannot tell.** (P3) | CLOSED 2026-10-05 — DUPLICATE of R-440 (its unique fact moved there) | felhom-controller/controller/internal/stacks/updateorder.go:96: `if len(s.CatalogDigests) == 0 // s.CatalogTestedAt.IsZero() { return false }` — blind only for apps with no ladder entry, i.e. the same 15 templates R-440 lists (app-catalog has no update_ladder for them). Both rows close by the same act: each app's first proven ladder step (R-462). |
| **R-799** | **[P3-LOW] The MeTube fixture's `POST /add` leaves out `download_type`, which upstream's validator lists as required.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | app-catalog `29ac711`: `MeTube.add_body()` sends `download_type: video`; `scripts/test_upgrade_fixtures_metube.py` (red-proof: the field removed → FAIL). Not exercised on a box (the next MeTube step will). |
| **R-761** | **[P3-LOW] The canonical example template tells a new app's author the logo is `<slug>-logo.webp`; the controller loads `<slug>-logo.svg`, then `.png`.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | app-catalog `29ac711`: the canonical template comment, `REUSE.md` and `NEW-APP-CHECKLIST.md` name `{slug}-logo.svg` then `.png` (controller `config.go` AppLogoURL/AppLogoPNGURL). Comment-only. |
| **R-391** | **Gate 11 (observations) is registered in three of the four runners; `app-catalog-felhom.eu` is the exception.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | app-catalog `29ac711`: `CLAUDE.md` states its `REPORT.md` carries no observations section by convention (the row's second option); the shared gate was not copied. |
| **R-291** | **CI's installability assertion is now BOUNDED by a retention number, and the narrowing is recorded here so it can be widened deliberately rather than discovered.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom-agent `d833163`: `scripts/retention-policy.json` names the source of its 10 — the R-267 newest-10 prune, established 2026-08-10 (R-287) — and drops the non-existent `registry-retention.md` reader; `check-published-versions.py` still reads 10 (checked). The min_agent-floor bound stays recorded in the file as the better bound. |
| **R-348** | **Every agent restart blanks the reported backup list for up to ~18 hours, and the comment that covers it says "unaffected".** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom-agent `d833163`: `internal/backup/store.go` says a restart blanks the reported backup list until the next run; only the hub's verdict (7-day look-back) is unaffected. Comment-only. |
| **R-263** | **C7 — „This is the ONLY writer of `StoragePath.BackupTarget`" is false, and nothing pins it.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom-controller `114ff27`: comment „the only writer that GRANTS"; `internal/settings/r263_backup_target_writers_test.go` scans every non-test file under internal/ and cmd/ (assignments and composite-literal keys). Red-proofs: ClearBackupTarget writing true; a `BackupTarget: true` literal in internal/web — both convict (`audits/burndown-2026-10-05/r263-red-proof.txt`). |
| **R-368** | **The storage default DOES apply at deploy time — the earlier claim that it never does was wrong, and the residual defect is smaller and different.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom-controller `114ff27`: the `IsDefault` comment says the deploy FORM pre-selects it and the deploy API applies no default (the row's second option; behaviour unchanged on purpose). |
| **R-418** | **`repo_gates.py`'s docstring listed ELEVEN gates while THIRTEEN were registered** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom.eu this commit: `repo_gates.py` docstring lists all 17 gates; `scripts/test_repo_gates_docstring.py` asserts list == GATES in order (red-proof: one line removed → FAIL), run on every push by the script-tests gate. |
| **R-345** | **`hub/Makefile` tags and pushes `:latest`, which the project's own rules forbid in two places.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom.eu this commit: `hub/Makefile` AND the real release script `scripts/build-hub.sh` (3 lines; the build dir links to it) no longer tag or push `felhom-hub:latest` — nothing pulls it (grep of all repos + homelab-manifests). `scripts/test_no_latest_push.py` (walk of hub/ + scripts/; red-proofs: the old Makefile and the old build-hub.sh each FAIL). Whether a stale `:latest` sits on the registry was not checked. |
| **R-416** | **`closed_register_gate.py` still has no within-register duplicate-id rule.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom.eu this commit: `closed_register_gate.py` RULE 4 refuses an id twice in CLOSED-ITEMS.md (OPEN duplicates were already `register_shape_gate.py` RULE 3); 0 duplicates existed, so it registered green. Decoy `closed-register/duplicate-closed-id` (red-proof: RULE 4 off → LIVE HOLE). |
| **R-261** | **C6 — `CountSelfBindTokens` exists so that callers can assert an invariant, and no production caller asserts it.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom.eu this commit: `hub/internal/store/selfbind.go` names `CountSelfBindTokens` a test accessor and the two tests that pin the auto-mint invariant. Comment-only; no hub release needed. |
| **R-262** | **C7 — a comment claims a cross-repo contract is mirrored „field-for-field" and „the key-set tests guard drift"; it is two fields short, AND THE FIXTURE THE TEST READS OMITS THE SAME TWO FIELDS.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom.eu this commit: the hub comment says hostRestoreTest is a deliberate SUBSET; `hub/internal/api/r262_restoretest_subset_test.go` pins the hub fields and the known-unmodelled agent fields and cross-checks the agent source beside it — which found a THIRD unmodelled field, `skipped` (agent v0.133.0, R-672; by design a skipped test reads as failed with its reason). Red-proofs: drop `skipped` from the list / stop decoding source_tier → FAIL. |
| **R-286** | **A control drawn from the same channel as the measurement cannot detect a defect in that channel — and this one passed while the measurement was wrong.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom.eu this commit: workspace standing rule 3 (both `CLAUDE.md` copies, identical) adds: a control must come from a DIFFERENT channel than the measurement; a hub-state check copies `hub.db-wal` or asks the running pod. |
| **R-588** | **[P3-LOW] ISO release records live in two different places, so "was the gate run for this image?" cannot be answered by looking.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down Part B) | felhom.eu this commit: `runbooks/iso-release-gate.md` names `documentation/tests/iso-release-<ver>-<date>/` as the one home; `tests/iso-release-1.28.0-2026-09-16/README.md` points at the 1.28.0 record inside the 2026-09-16 audit. |
---
File diff suppressed because one or more lines are too long
@@ -320,3 +320,8 @@ record.
Record each criterion as PASS/FAIL **with the observed value and what was scanned for**, in the
release report. A criterion with no recorded observation is a criterion that was not run.
**The ONE home for a release's record is `documentation/tests/iso-release-<version>-<date>/`** (R-588,
2026-10-05) — one directory per published ISO, so „was the gate run for this image?" is answered by looking,
not by a full-text search for a checksum. A record made elsewhere (inside an audit) gets a directory here
whose `README.md` points at it. Today: 1.27.0, 1.27.1, 1.28.0 (pointer), 1.29.0.
+7 -1
View File
@@ -54,7 +54,13 @@ roles. **A file being open in the editor is NOT an instruction. If no task is st
attempts.
3. **An absent log line is not evidence of correct behaviour.** Verify with a POSITIVE observable —
something that MUST appear when the system is healthy. An empty log is equally consistent with
"working" and "stopped entirely".
"working" and "stopped entirely". **And the control must come from a DIFFERENT channel than the measurement** (R-286):
same query, same snapshot, same API or same clock all share the defect they are meant to catch — a
stale hub snapshot once "confirmed" itself (2 events all day) while the operator's mailbox held eight
alarms. A hub-state check copies `hub.db-wal` too, or asks the running pod. **And the control must come from a DIFFERENT channel than the measurement** (R-286):
same query, same snapshot, same API or same clock all share the defect they are meant to catch — a
stale hub snapshot once "confirmed" itself (2 events all day) while the operator's mailbox held eight
alarms. A hub-state check copies `hub.db-wal` too, or asks the running pod.
4. **A recommendation that is not followed gets one line saying why.** Silence reads as agreement and
the disagreement is lost.
5. **Evidence is copied off the machine at the end of the phase that produced it — before any revert,
@@ -0,0 +1,9 @@
# ISO release 1.28.0 — 2026-09-16 (pointer)
The gate record for this image was made inside an audit about something else, before the one-home rule
(`runbooks/iso-release-gate.md` „Result recording", R-588):
- `documentation/audits/evidence-backup-promise-2026-09-16/phaseD-iso-gate.txt` — run 2026-09-16T15:07:32Z against
`felhom-installer-1.28.0-pve9.2-1.iso`, sha256 `a4cd9b6ddcb55bae3700ab307084d2b699330cc20710688d5816318f04f6d635`.
Nothing was re-run for this pointer; it only makes the record findable by looking.