R-224..R-228 CLOSED: registers, capability map, campaign annotation, STATUS
gates / gates (push) Successful in 7s

Five closed in controller v0.202.0 + agent v0.126.0, each with its live or
red-proof evidence in the row. Five explicitly still open and named as such
rather than left to inference: R-214, R-220, R-221, R-213, R-202 — and R-220 is
flagged as currently worked around BY HAND on the campaign venue, which is the
only reason an app could be deployed there.

The capability map's recovery row STAYS FAIL and says why: fixes are not a
re-walk, nothing walked a customer end to end, and the customer-facing messages
were NOT re-driven live because /recovery correctly retires itself once the old
data is set aside — restoring that state is the reconfiguration the task forbade.

The campaign document is ANNOTATED, not rewritten: it records what was true when
it ran, and that is its value.

workspace-CLAUDE.md gains comment-vs-code entry 9 — the escrow header said the
errors were 'DISTINCT on purpose' and named THREE situations while a fourth was
folded into one of them, and a green test named the defect and did not prevent
it because it asserted a STRING one layer below the merge.

ROADMAP needed no collapse — it carries no rows for these IDs.
This commit is contained in:
2026-08-06 08:34:04 +02:00
parent 453e4503a9
commit d30c2a51ed
5 changed files with 71 additions and 40 deletions
+35 -33
View File
@@ -1,6 +1,6 @@
# STATUS — what works, what's broken, what's next
**Updated 2026-08-05.**
**Updated 2026-08-06.**
> **A view, not a source.** `documentation/backlog/OPEN-ITEMS.md` is the authority on open work; this
> page restates part of it in plain words, and **nothing may exist only here**. **Not `CONTEXT.md`**,
@@ -24,11 +24,11 @@ code was wrong. *(CAMPAIGN 11)*
## What's broken
- **A machine installed today would tell its owner their correct recovery code is wrong.** The
recovery screen needs a newer in-house service than a new machine is given; when it asked and got
nothing, it blamed the customer's typing. **We fixed the lie today** — it now says plainly that the
*machine* cannot do this yet, and never accuses anyone. **It still needs one click from you to
actually work on new machines** (below). *(R-216, R-223)*
- **A machine installed today still gets the older in-house service, so it cannot open a recovery
package until you approve the newer one.** It is no longer *lied to* — it says plainly that the
machine cannot do this yet — but **approving the new service is one click from you**, and until then
such a machine also gets the cautious "we do not know why" wording rather than the helpful one.
*(R-216, R-223, R-224)*
- **Three things a rebuilt machine still cannot do by itself.** Its owner cannot re-attach their own
drives, so no app can be put back on its data; it cannot create a new recovery code at all; and the
screen at the machine itself never stops showing a stale pairing code. Each is understood, measured
@@ -37,40 +37,42 @@ code was wrong. *(CAMPAIGN 11)*
that encrypts its own off-site backups, and a rebuilt machine invents a new one. **The good news:
the old key really is kept now — we proved it on a real machine today, for the first time**, and a
changed key raises an alarm the same day. *(R-193, R-198)*
- **The kept older backups cannot be opened yet.** We keep the previous sealed package, and there is
no way to open it. A customer holding exactly the right code for it used to be told they had
mistyped; today the screen names the situation honestly instead — but it still cannot open it, and
it does not pretend otherwise. *(R-222, R-202)*
- **The kept older backups cannot be opened — by anyone.** We keep the previous sealed package and
there is no way to open it. The screens now say exactly that and stop. **One place still promises
otherwise**: the older-backups card says they "may be restorable later with the matching code",
which is not true today. *(R-222, R-202)*
- **The off-site copy can be erased by the machine that made it.** A daily snapshot is armed as a
stopgap. *(R-95, R-87)*
## What last night's stress test found (2026-08-05/06, unattended)
## What last night's stress test found — and what we fixed this morning
We spent the night trying to break the recovery journey with eleven deliberate faults, then left the
machine alone and watched it run on its own. **The good news is real and worth saying first: nothing
we did lost a single byte.** When the customer chose "I do not want the old data", the old backups
were **set aside and not deleted** — we checked the far end of the wire and the 12.5 MB was still
there, untouched, to the byte. A wrong code was refused three times with nothing written and no
lockout. The machine's own alarm fired when we switched it off and cleared itself when it came back.
We spent the night trying to break the recovery journey, then left the machine alone and watched it
run. **Nothing we did lost a byte.** When the customer chose "I do not want the old data", the old
backups were **set aside and not deleted** — we checked the far end of the wire and the 12.5 MB was
still there, to the byte. A wrong code was refused three times with nothing written and no lockout.
The machine's alarm fired when we switched it off and cleared itself when it came back. Overnight it
ran a full cycle on its own and made a fresh off-site copy without being asked.
**What we found is that the machine still tells people the wrong thing when something else is wrong.**
**What it found: the machine still blamed the customer for failures that were not theirs.** Pull the
plug on our own central system and the customer was told their recovery code was bad — in three
hundredths of a second, when actually checking a code takes about one. The machine had not even
tried. **All of that is fixed and deployed** *(R-224, R-226, R-225, R-227, R-228)*:
- **Pull the plug on our own central system, and the customer is told their recovery code is bad.**
Same if the machine's in-house service is stopped. In both cases the code was **perfect** — and the
machine had not even tried it (we can prove that: a real attempt takes about a second, these failed
in three hundredths). The machine knows the difference internally and throws it away before anyone
sees it. **This is the same lie we fixed yesterday, coming back through a different door.**
*(R-224)*
- **A customer who mistypes is no longer told to check their typing** — on any machine that has been
given a new recovery code, that message can no longer appear at all. *(R-226)*
- **The backups page says "0 snapshots · 0 GB" when it cannot read the store** — directly above a
paragraph saying the store contains backups. It really held one snapshot and 12.5 MB. The machine
does not know the number and shows a confident zero instead of "unknown". *(R-225)*
- **After "I do not want the old data", the set-aside backups become invisible.** They are kept, and
the machine writes down exactly where — and then shows that to nobody, ever. *(R-228)*
- **When something on our side is down, we say so** — and we say plainly that the code was **not**
used, so it is still good. Proven on the real machine: with our hub unreachable the answer changed
from "your code is wrong" to "we could not reach the central system".
- **A customer who mistypes is told to check their typing again.** That message had become
unreachable on any machine that had been given a new code — exactly the machine that just recovered.
- **When we do not know why something failed, we say that**, and never guess the customer.
- **"0 snapshots · 0 GB" is gone** where the truth is "we have not read it yet".
- **The set-aside backups are visible again** — the machine says they are kept and not deleted, and
does **not** pretend they can be reopened, because today they cannot be.
**Nothing was fixed last night, on purpose** — a campaign that fixes as it goes is measuring a moving
target. Everything above is written down and ready to work on.
**Still open, and worth knowing:** a rebuilt machine still cannot re-attach its own drives without us
*(R-220 — we are working around it by hand on the test machine right now)*, cannot create a new
recovery code *(R-221)*, and the screen at the machine still shows a stale pairing code *(R-214)*.
**The recovery journey is still recorded as FAILED** — these are fixes, not a re-walk, and it stays
failed until someone walks it end to end with no help from us.
## What shipped recently