Decision sheet D1-D10: hub CHANGELOG, architecture notes (01, 04, 05, 07, 08, 10), register (VERIFY states, R-912), STATUS, report; decoy suite runs in a git worktree
gates / gates (push) Successful in 4m32s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-08 15:17:02 +02:00
parent 87af859fc3
commit fe0dc0d03f
14 changed files with 241 additions and 16 deletions
@@ -95,6 +95,16 @@ Evolves the existing staleness checker (60s **cadence**, a **configured** thresh
than waiting for a guest report to go stale.
- **Guest-report recency = secondary** app-level signal.
**Box presence from the wait channel [DESIGN, R-30 — `09` §3 decision 186, hub main 2026-10-08, unreleased].** The
hub records, in memory, each controller wait (`GET /api/v1/wait`) per customer: **connected** (a hold is open, or one
started < 333 s ago = 243 s cadence + 90 s grace), **not connected since T**, or **unknown** (the hub started < 333 s
ago). The host page shows it. Alerting is NOT changed. **„Delete host" goes ahead at once** — instead of waiting for
the report clock — only when the host is online by its report, the operator ticked „I checked: the box is off", AND
presence has been „not connected" for ≥ 360 s, re-checked at the POST; unknown never permits it. The delete writes an
INFO line and one `host_deleted_box_off` event. Wrong case: a box whose controller crashed while its host runs — its
agent is locked out until re-enrolled; no household data is touched. `hub/internal/intent/presence.go`,
`hub/internal/web/r30_presence_delete_test.go`.
**Backup-deadline checker:** today it is *event-based* — it scans for `backup_completed`/`backup_failed`
events since local midnight and alerts if none. Two changes: (1) **mechanism** — move it to a field
check on `host_reports`' last-backup-per-target (cleaner now that backup state arrives in the host