R-224..R-228 CLOSED: registers, capability map, campaign annotation, STATUS
gates / gates (push) Successful in 7s
gates / gates (push) Successful in 7s
Five closed in controller v0.202.0 + agent v0.126.0, each with its live or red-proof evidence in the row. Five explicitly still open and named as such rather than left to inference: R-214, R-220, R-221, R-213, R-202 — and R-220 is flagged as currently worked around BY HAND on the campaign venue, which is the only reason an app could be deployed there. The capability map's recovery row STAYS FAIL and says why: fixes are not a re-walk, nothing walked a customer end to end, and the customer-facing messages were NOT re-driven live because /recovery correctly retires itself once the old data is set aside — restoring that state is the reconfiguration the task forbade. The campaign document is ANNOTATED, not rewritten: it records what was true when it ran, and that is its value. workspace-CLAUDE.md gains comment-vs-code entry 9 — the escrow header said the errors were 'DISTINCT on purpose' and named THREE situations while a fourth was folded into one of them, and a green test named the defect and did not prevent it because it asserted a STRING one layer below the merge. ROADMAP needed no collapse — it carries no rows for these IDs.
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
# STATUS — what works, what's broken, what's next
|
||||
|
||||
**Updated 2026-08-05.**
|
||||
**Updated 2026-08-06.**
|
||||
|
||||
> **A view, not a source.** `documentation/backlog/OPEN-ITEMS.md` is the authority on open work; this
|
||||
> page restates part of it in plain words, and **nothing may exist only here**. **Not `CONTEXT.md`**,
|
||||
@@ -24,11 +24,11 @@ code was wrong. *(CAMPAIGN 11)*
|
||||
|
||||
## What's broken
|
||||
|
||||
- **A machine installed today would tell its owner their correct recovery code is wrong.** The
|
||||
recovery screen needs a newer in-house service than a new machine is given; when it asked and got
|
||||
nothing, it blamed the customer's typing. **We fixed the lie today** — it now says plainly that the
|
||||
*machine* cannot do this yet, and never accuses anyone. **It still needs one click from you to
|
||||
actually work on new machines** (below). *(R-216, R-223)*
|
||||
- **A machine installed today still gets the older in-house service, so it cannot open a recovery
|
||||
package until you approve the newer one.** It is no longer *lied to* — it says plainly that the
|
||||
machine cannot do this yet — but **approving the new service is one click from you**, and until then
|
||||
such a machine also gets the cautious "we do not know why" wording rather than the helpful one.
|
||||
*(R-216, R-223, R-224)*
|
||||
- **Three things a rebuilt machine still cannot do by itself.** Its owner cannot re-attach their own
|
||||
drives, so no app can be put back on its data; it cannot create a new recovery code at all; and the
|
||||
screen at the machine itself never stops showing a stale pairing code. Each is understood, measured
|
||||
@@ -37,40 +37,42 @@ code was wrong. *(CAMPAIGN 11)*
|
||||
that encrypts its own off-site backups, and a rebuilt machine invents a new one. **The good news:
|
||||
the old key really is kept now — we proved it on a real machine today, for the first time**, and a
|
||||
changed key raises an alarm the same day. *(R-193, R-198)*
|
||||
- **The kept older backups cannot be opened yet.** We keep the previous sealed package, and there is
|
||||
no way to open it. A customer holding exactly the right code for it used to be told they had
|
||||
mistyped; today the screen names the situation honestly instead — but it still cannot open it, and
|
||||
it does not pretend otherwise. *(R-222, R-202)*
|
||||
- **The kept older backups cannot be opened — by anyone.** We keep the previous sealed package and
|
||||
there is no way to open it. The screens now say exactly that and stop. **One place still promises
|
||||
otherwise**: the older-backups card says they "may be restorable later with the matching code",
|
||||
which is not true today. *(R-222, R-202)*
|
||||
- **The off-site copy can be erased by the machine that made it.** A daily snapshot is armed as a
|
||||
stopgap. *(R-95, R-87)*
|
||||
|
||||
## What last night's stress test found (2026-08-05/06, unattended)
|
||||
## What last night's stress test found — and what we fixed this morning
|
||||
|
||||
We spent the night trying to break the recovery journey with eleven deliberate faults, then left the
|
||||
machine alone and watched it run on its own. **The good news is real and worth saying first: nothing
|
||||
we did lost a single byte.** When the customer chose "I do not want the old data", the old backups
|
||||
were **set aside and not deleted** — we checked the far end of the wire and the 12.5 MB was still
|
||||
there, untouched, to the byte. A wrong code was refused three times with nothing written and no
|
||||
lockout. The machine's own alarm fired when we switched it off and cleared itself when it came back.
|
||||
We spent the night trying to break the recovery journey, then left the machine alone and watched it
|
||||
run. **Nothing we did lost a byte.** When the customer chose "I do not want the old data", the old
|
||||
backups were **set aside and not deleted** — we checked the far end of the wire and the 12.5 MB was
|
||||
still there, to the byte. A wrong code was refused three times with nothing written and no lockout.
|
||||
The machine's alarm fired when we switched it off and cleared itself when it came back. Overnight it
|
||||
ran a full cycle on its own and made a fresh off-site copy without being asked.
|
||||
|
||||
**What we found is that the machine still tells people the wrong thing when something else is wrong.**
|
||||
**What it found: the machine still blamed the customer for failures that were not theirs.** Pull the
|
||||
plug on our own central system and the customer was told their recovery code was bad — in three
|
||||
hundredths of a second, when actually checking a code takes about one. The machine had not even
|
||||
tried. **All of that is fixed and deployed** *(R-224, R-226, R-225, R-227, R-228)*:
|
||||
|
||||
- **Pull the plug on our own central system, and the customer is told their recovery code is bad.**
|
||||
Same if the machine's in-house service is stopped. In both cases the code was **perfect** — and the
|
||||
machine had not even tried it (we can prove that: a real attempt takes about a second, these failed
|
||||
in three hundredths). The machine knows the difference internally and throws it away before anyone
|
||||
sees it. **This is the same lie we fixed yesterday, coming back through a different door.**
|
||||
*(R-224)*
|
||||
- **A customer who mistypes is no longer told to check their typing** — on any machine that has been
|
||||
given a new recovery code, that message can no longer appear at all. *(R-226)*
|
||||
- **The backups page says "0 snapshots · 0 GB" when it cannot read the store** — directly above a
|
||||
paragraph saying the store contains backups. It really held one snapshot and 12.5 MB. The machine
|
||||
does not know the number and shows a confident zero instead of "unknown". *(R-225)*
|
||||
- **After "I do not want the old data", the set-aside backups become invisible.** They are kept, and
|
||||
the machine writes down exactly where — and then shows that to nobody, ever. *(R-228)*
|
||||
- **When something on our side is down, we say so** — and we say plainly that the code was **not**
|
||||
used, so it is still good. Proven on the real machine: with our hub unreachable the answer changed
|
||||
from "your code is wrong" to "we could not reach the central system".
|
||||
- **A customer who mistypes is told to check their typing again.** That message had become
|
||||
unreachable on any machine that had been given a new code — exactly the machine that just recovered.
|
||||
- **When we do not know why something failed, we say that**, and never guess the customer.
|
||||
- **"0 snapshots · 0 GB" is gone** where the truth is "we have not read it yet".
|
||||
- **The set-aside backups are visible again** — the machine says they are kept and not deleted, and
|
||||
does **not** pretend they can be reopened, because today they cannot be.
|
||||
|
||||
**Nothing was fixed last night, on purpose** — a campaign that fixes as it goes is measuring a moving
|
||||
target. Everything above is written down and ready to work on.
|
||||
**Still open, and worth knowing:** a rebuilt machine still cannot re-attach its own drives without us
|
||||
*(R-220 — we are working around it by hand on the test machine right now)*, cannot create a new
|
||||
recovery code *(R-221)*, and the screen at the machine still shows a stale pairing code *(R-214)*.
|
||||
**The recovery journey is still recorded as FAILED** — these are fixes, not a re-walk, and it stays
|
||||
failed until someone walks it end to end with no help from us.
|
||||
|
||||
## What shipped recently
|
||||
|
||||
|
||||
Reference in New Issue
Block a user