burn-down night: rulings §1 recorded (09 §3 decisions 128-130); R-888, R-337, R-375 closed by ruling; R-126/R-856 rulings in their rows; night log (199 -> 196)
gates / gates (push) Successful in 1m57s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 21:09:04 +02:00
parent 30650cad6e
commit c8da8e0439
5 changed files with 49 additions and 10 deletions
@@ -905,6 +905,19 @@ its length, and both fixes cost something the household would notice — operato
127. **The agent's three by-design abilities (`03` §3.1) stay for now**; revisited before the first paying customer.
*Operator ruling 2026-10-05.* (R-861)
### 2026-10-05 (~21:00) — three rulings, the reviewer's picks given to the operator (recorded before the work; the burn-down night)
128. **R-126 — a `.fab` export onto a network drive.** **Refuse an export WITHOUT a password to any network drive; with
a password it is allowed.** Rejected: the row's other option, filtering network drives out of the export
destination list. *Ruling 2026-10-05 ~21:00, the burn-down night brief §1.*
129. **R-856 — a crash restart reached the household twice.** **After a crash boot, the controller's app mails wait the
same grace period as after a normal start.** The hub's "restarted after an unexpected stop" line stays the one
message about the crash. *Ruling 2026-10-05 ~21:00, the burn-down night brief §1.* `08` §5.
130. **R-888, R-337, R-375 — closed.** R-888: the hub needs neither `stacks.deployed` nor `storage.decommissioned` today
(no hub page reads them; the fields stay on the wire and stay allow-listed in `scripts/wire_contract_gate.py`).
R-337: resolved by itself and never seen again. R-375: a note with no defect behind it (nothing in the product
reads a PBS target's size). *Ruling 2026-10-05 ~21:00, the burn-down night brief §1.*
### 2026-10-05 (06:49) — four operator rulings (recorded before the work; the night-fixes brief)
100. **Tester 1's Cloudflare tokens, shown in the 2026-10-04 night session's output, are NOT rotated** (option B) —
@@ -0,0 +1,21 @@
# Night log — the burn-down night, 2026-10-05 → 06
Brief: `drills/NIGHT-burndown-2026-10-05.md` (workspace root). One line per row touched:
row · result (fixed / closed-stale / failed / moved to A or D / needs-live) · minutes · commit.
**Baselines read from live source at 21:03 CEST:** felhom.eu `30650cad6e` · controller `6f1ba1fe43` (v0.297.0) · agent
`208fac8027` (v0.147.0) · catalog `4828dc754d` · hub v0.137.0 (CHANGELOG head) · register **199** (19 P2, 95 P3, 85 P4).
**How the night is worked:** six helper sessions, one per repo lane, each in its own git worktree and branch cut from
`origin/main` (controller ×2, hub, installer, agent, catalog). Helpers commit locally, never push. The lead reviews,
cherry-picks onto `main`, writes CHANGELOG, closes rows, pushes and watches CI.
## Rows
| Row | Result | Min | Commit |
|---|---|---|---|
| R-888 | closed — ruling (decision 130) | 5 | (this commit) |
| R-337 | closed — ruling (decision 130) | 2 | (this commit) |
| R-375 | closed — ruling (decision 130) | 2 | (this commit) |
| R-126 | ruling recorded (decision 128); build → helper ctrl-a | 2 | (this commit) |
| R-856 | ruling recorded (decision 129); build → helper ctrl-a | 2 | (this commit) |
+10
View File
@@ -26,6 +26,16 @@
---
## 2026-10-05 (night) — the burn-down night: rulings §1
The full text of every row below: `git show 30650cad:documentation/backlog/OPEN-ITEMS.md`.
| Row | What | Closed | Evidence |
|---|---|---|---|
| **R-375** | **A PBS datastore signal was noted and explicitly not filed.** (P4) | CLOSED 2026-10-05 — RULED (decision 130, the burn-down night §1): a note with no defect behind it | Nothing in the product reads a PBS target's Total/Used/Avail: the space preflight skips a PBS target (felhom-agent `internal/backup/runner.go:265`, burn-down round 2 check). `09` §3 decision 130. |
| **R-337** | **`/backup/status` lagged a completed backup by minutes on one box and not the other — and it RESOLVED ITSELF, which is why this is WATCHING and not a defect.** (P4) | CLOSED 2026-10-05 — RULED (decision 130, the burn-down night §1): resolved by itself, never seen again | The lag cleared on its own on 2026-08-18 (the row). The refresh path is the job goroutine after the runner returns (burn-down round 2 check: felhom-agent `internal/localapi/server.go:885`, `pickLatestBackup` `:1304-1318`). Not seen again since 2026-08-18. `09` §3 decision 130. |
| **R-888** | **Two fields the controller reports are never read by the hub: `stacks.deployed` and `storage.decommissioned`.** (P4) | CLOSED 2026-10-05 — RULED (decision 130, the burn-down night §1): the hub needs neither field today | No hub surface decodes `stacks.deployed` or `storage.decommissioned` (grep of `hub/internal`, 2026-10-05 21:40: no reader). The fields stay on the wire and stay allow-listed in `scripts/wire_contract_gate.py` with this reason; a surface that needs one later decodes it then. `09` §3 decision 130. |
## 2026-10-05 (late night) — burn-down round 2: the operator's answer (43 accepted), small rows fixed with releases
The full text of every row below: `git show e8c56c44:documentation/backlog/OPEN-ITEMS.md` (the commit before each closing commit; the burn-down evidence table is `audits/burndown-2026-10-05/`).
File diff suppressed because one or more lines are too long
+3 -3
View File
@@ -299,11 +299,11 @@ ALLOWLIST = {
"R-555 / R-331: no producer since slice 8C; the Backup card reads offsite.repo_size_bytes "
"instead (hub/internal/web/backup_card.go)."),
(_CH, "stacks.deployed"): (
"R-555: surfaced 2026-10-05 — the hub decodes no deployed-app list from the report; whether a hub "
"surface needs it is not decided. Filed as R-888 for the operator to decide."),
"R-555: surfaced 2026-10-05 — the hub decodes no deployed-app list from the report; no hub "
"surface needs it (R-888 closed by ruling, 09 §3 decision 130, 2026-10-05)."),
(_CH, "storage.decommissioned"): (
"R-555: surfaced 2026-10-05 — the hub decodes no per-drive decommissioned marker from the report; "
"whether a hub surface needs it is not decided. Filed as R-888 for the operator to decide."),
"no hub surface needs it (R-888 closed by ruling, 09 §3 decision 130, 2026-10-05)."),
}
# A node whose IMMEDIATE CHILDREN are still checked but whose DEEPER descendants are not, because the