Golden 0.227.1 baked, vouched, floor raised — and the floor delivered the new job by itself
gates / gates (push) Successful in 16s

Second full delivery of the day. golden_currency_gate.py went red -> green on
the same command, so the --no-verify bypass declared on the previous push is now
historical rather than standing.

  GOLDEN_VERSION  0.227.1
  GOLDEN_SHA256   66754491dc9bd0130ef8ded9562f63c53a5ffdcfd91baa551141e55fa083ea32
  size            657 403 203 B
  baked           gitea.dooplex.hu/admin/felhom-controller:0.227.1
  MinAgent        0.129.0  (read from the controller CHANGELOG header, not assumed)

THE EVIDENCE IS THE ROUND TRIP. The published bytes were downloaded back -- size
and sha256 identical to what the bake reported -- and ./etc/felhom-controller-
image was read OUT of the downloaded archive: felhom-controller:0.227.1. That is
the delivered artifact naming the controller it will start, from the bytes a
customer's box would actually fetch.

Markers counted: docker OK (overlay2 = 1, mount point rootfs = 1, mp0 = 1,
upload OK (HTTP 201) = 1; excluding = 0, FATAL = 0, mp1 = 0. 404 pre-gate passed
before the run and the script's own pre-delete agreed, so nothing was
overwritten.

Three-field vouch, all three checked: agent_version 0.130.0 >= min_agent 0.129.0
(NOT the R-216 shape), wrapper_sha256 carried through explicitly because the
handler clears it when omitted. Verified by RE-READING the manifest rather than
trusting the flash. The R-120 gate on that POST passed on its own terms rather
than being worked around.

AND THE LINE WORTH KEEPING. demo-felhom self-updated 0.226.1 -> 0.227.1 in under
30 seconds and then logged:

  [INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-08-31 06:00 CEST

A box nobody deployed to now runs today's off-site integrity check on its own
schedule. That is a floor DELIVERING rather than merely recording, observed
instead of assumed -- and it is the strongest evidence R-242 has carried.

Token hygiene: file->file, read inside the VM by a runner script, never on a
command line (systemctl show ... grep -c -F token = 0). The leak grep on the
committed log was PROVEN TO WORK before its 0 was believed.

Teardown: guest 9100 destroyed --purge, secrets shredded AFTER the log was
copied out, VM powered off, disk reverted to virgin.

R-242 now records the cadence as MEASURED: five convictions and two full bakes
in one day. Every bypass declared, every debt paid -- and the pattern the row
exists to name is exactly that a release and its delivery are separate acts. Its
other half stays open: nothing gates the VOUCH itself.
This commit is contained in:
2026-08-30 21:48:15 +02:00
parent 99af997ab9
commit db0812b6f2
4 changed files with 439 additions and 14 deletions
+8 -13
View File
@@ -12,13 +12,7 @@ hub deployed itself; nothing is waiting on you except the floor from the last re
*This section is allowed to be longer than one screen, and each item says what happens if you do
nothing.*
1. **Nothing — the golden train is current again.** Golden **0.226.1** was baked, published,
round-trip verified, vouched, and the fleet floor raised to 0.226.1 on 2026-08-30. Both demo
machines run 0.226.1; `demo-felhom` reached it by self-update, not by hand. A machine installed
today receives 0.226.1 and every fix from the four releases of 2026-08-30.
Evidence: `documentation/tests/golden-0.226.1-2026-08-30/`.
2. **How deep should the off-site check go?** (R-399). The box now checks its off-site store weekly.
1. **How deep should the off-site check go?** (R-399). The box now checks its off-site store weekly.
The check it runs today reads the catalogue — it catches a missing or unreadable backup, and it does
**not** re-read the stored bytes, so it cannot see a file that has quietly rotted.
**What it costs to go deeper, measured on your own machine today, not guessed:**
@@ -28,15 +22,16 @@ nothing.*
**If you do nothing:** the catalogue is checked weekly and the stored bytes are never re-read.
I can turn it on with one setting whenever you say.
3. **Bake and vouch a golden carrying 0.227.1, then raise the floor** — the usual last step. `demo-hp`
runs 0.227.1; the fleet floor is 0.226.1 and the golden carries 0.226.1.
**If you do nothing:** a machine installed today gets 0.226.1 and none of today's off-site checking,
and `demo-felhom` stays where it is. Tracked on R-242.
2. **Nothing about delivery — the golden train is current.** Golden **0.227.1** was baked, published,
round-trip verified, vouched, and the fleet floor raised to 0.227.1 on 2026-08-30. Both demo
machines run it; **`demo-felhom` got there by itself** and started the new off-site check on its own
schedule without anyone touching it. A machine installed today receives 0.227.1 and everything
shipped today. Evidence: `documentation/tests/golden-0.227.1-2026-08-30/`.
4. **Nothing else.** Everything in the releases of 2026-08-30 is a fix to code that ships in the
3. **Nothing else.** Everything in the releases of 2026-08-30 is a fix to code that ships in the
controller image; no customer action, no data migration, no credential change.
5. **Whether to change the hub password** (R-350). I printed it into my own session log on 20 August.
4. **Whether to change the hub password** (R-350). I printed it into my own session log on 20 August.
Not in git, not in any saved file — in the log on this machine. **If you do nothing:** it stays as
it is, at the risk you accept by leaving it. I can change it without ever showing you the new one.
4. **`demo-hp`'s network setup does not match our own notes** (R-338) — the machine works, the page is