# REPORT — felhom.eu: the golden-currency gate could not see an unrecorded golden (R-385) **Session 2026-08-23.** Companion to `felhom-controller` v0.222.0 (R-384, R-383) — see that repo's `REPORT.md` for the controller work and the full live walk. ## What was wrong here `scripts/golden_currency_gate.py` asked ONE question — *is the golden BEHIND the record?* — and therefore could only ever catch a forgotten bake. **It said nothing when the golden was AHEAD of the record**, and that direction is not harmless: a golden ahead of every CHANGELOG heading was built from something never written down. That is not hypothetical. Controller **0.221.1** was built, baked **and vouched** on 2026-08-23 while the newest heading in the controller CHANGELOG still read `v0.221.0`. Measured on the real history, with the old gate: ``` newest released controller : 0.221.0 (## v0.221.0 — taking the undo copy destroyed …) newest golden baked : 0.221.1 (documentation/tests/golden-0.221.1-2026-08-23) golden currency gate OK … EXIT=0 ``` Every gate was green while the fleet ran a version the record did not name. ## The fix, and why it is membership and not a comparison The gate now asks **"is the version we are shipping WRITTEN DOWN?"** — the baked version must have its own `## vX.Y.Z` heading **anywhere** in the controller CHANGELOG, not merely at the top (an entry may legitimately be overtaken by later ones; what may never happen is that it is absent). **Membership, not `baked > released`, deliberately:** a comparison against the newest heading alone goes green the moment ANY later entry is written — which would have left 0.221.1 permanently unrecorded and the gate permanently silent about it. Preserved unchanged: **INCONCLUSIVE (exit 2)** for an absent clone or an unparseable CHANGELOG — *not knowing is never a pass, and never a conviction*. Every refusal names a reason **and** a route, including what to do if a bake was a throwaway that must never be delivered. ## Red-proofs — both directions, against the real history | Run | Gate | CHANGELOG | Golden baked | Exit | | |---|---|---|---|---|---| | `gate-01` | **old** | v0.221.0 | 0.221.1 | **0** | the blindness, reproduced | | `gate-02` | **new** | v0.221.0 | 0.221.1 | **1** | convicted | | `gate-03` | new | v0.221.1 | 0.221.1 | **0** | Part 0's heading makes it pass | | `gate-04` | new | absent clone | — | **2** | INCONCLUSIVE preserved | | `gate-05` | new | v0.222.0 | 0.222.0 | **0** | post-bake | Transcripts: `documentation/audits/DRILL-r384-dead-db-alarm-2026-08-23/evidence/gate-0*.txt`. ## Files changed | File | Change | |---|---| | `scripts/golden_currency_gate.py` | the unrecorded-golden conviction; `newest_released` → `released_versions` returning the whole set; docstring records the second blindness | | `documentation/architecture/08-alarm-ladder.md` | **NEW.** The alarm ladder as a dated [DESIGN] | | `documentation/architecture/00-capability-map.md` | R-384 marked closed with its live evidence; points at the new doc | | `documentation/backlog/OPEN-ITEMS.md` | R-383/R-384 removed (closed); **R-385** (closed) and **R-386** (open) filed | | `documentation/backlog/CLOSED-ITEMS.md` | R-383 + R-384 compressed, each keeping its rules and naming `git show 1eb64bec5183:…` for the full text | | `documentation/tests/golden-0.222.0-2026-08-23/` | **NEW.** Bake evidence + log + the vouching instructions | | `STATUS.md` | the 0.222.0 vouch replaces the (now completed) 0.221.1 one; R-386 added in plain words | | `documentation/audits/DRILL-r384-dead-db-alarm-2026-08-23/` | **NEW.** The drill record and 29 evidence files | ## The alarm ladder had no owning document — that absence is a finding Nothing in `documentation/architecture/` owned the question *"when does a customer's app being broken raise an alarm?"* The rules lived as comments across four packages, each locally correct, with the ordering between them legible only by reading `aggregateState` top to bottom. **That is precisely how R-384 survived review**, and three separate defects in this ladder (R-51, C9-F2, R-384) were each found on live hardware rather than by reading. `08-alarm-ladder.md` now owns it. ## Golden **Baked and PUBLISHED: 0.222.0.** `GOLDEN_SHA256 = 19f5904f5379…`, `upload OK (HTTP 201)`, round-trip `HTTP 206` from the package URL, all acceptance markers counted. **VOUCHING IS THE OPERATOR'S ACT AND WAS NOT DONE HERE.** **Deviation recorded:** the bake runbook's §4.1 is missing a `pveam update`. On the `virgin` snapshot the template index is stale, so the listed template cannot be downloaded and the failure presents as `400 Parameter verification failed. template: no such template` rather than as a stale index. ## Register size | File | Before | After | |---|---|---| | `OPEN-ITEMS.md` | 327,266 B | **328,325 B** | | `CLOSED-ITEMS.md` | 68,464 B | **71,441 B** | OPEN grew ~1 KB despite two closures, because R-386 is a substantial new finding. Recorded rather than smoothed over. ## Hub numbers as read at session start (live, `GET /configuration`) `golden_version` **0.221.1** · `agent_version` **0.130.0** · `min_agent` **0.129.0** · controller floor **0.221.1**. The task expected 0.220.2/0.220.2; the operator had already vouched. **The hub was READ ONLY this session** — nothing was written to it.