"""boxstep.py = [...] — a WITHIN-A-MAJOR step's BOX venue on 9202 (drill catalog), Part F. prep is boxmove.py's (deploy, seed through the app's own route, C1); this presses the step: a DRILL-only commit moves the named services and adds a ladder entry (no conversion mark), sync, rescan, the product's guarded Update, the seed read back → box verdict JSON beside boxmove's. The live catalog's entry is written later ONLY by `upgrade-test.py --write-ladder` from both verdicts. Evidence: box//step.txt + box//box-verdict-.json.""" import json, os, re, subprocess, sys, time import walk as w sys.path.insert(0, "/mnt/5_hdd/felhom.eu/git/app-catalog-felhom.eu/scripts") import upgrade_fixtures_box as fixtures, upgrade_fixtures_box28 as _f28 FX = dict(_f28.FIXTURES28); FX.update(fixtures.FIXTURES) # the box set wins, as upgrade_boxport.get() decides app, sub = sys.argv[1:3] moves = dict(a.split("=", 1) for a in sys.argv[3:]) EVD = f"{w.EV}/box/{app}"; os.makedirs(EVD, exist_ok=True) TOK = w.SC + "/seed-tokens-box.json" log = open(f"{EVD}/step.txt", "a", buffering=1) def say(*a): w.say(*a); log.write(" ".join(map(str, a)) + "\n") D = "/mnt/5_hdd/felhom.eu/drill/app-catalog-drill" w.login() toks = json.load(open(TOK)) if isinstance(toks.get(app), dict) and toks[app].get("__generated"): w.GENERATED[app] = toks[app]["__generated"] st = w.stack(app); before = (st.get("app_config") or {}).get("pinned_images") say(f"before: pinned={before}") if not os.environ.get("SKIPDRILL"): subprocess.run(["git", "-C", D, "pull", "-q", "--rebase", "origin", "main"], check=True) comp = f"{D}/templates/{app}/docker-compose.yml"; fy = f"{D}/templates/{app}/.felhom.yml" s = open(comp).read(); pins, cur = {}, None for line in s.splitlines(): m = re.match(r"^ ([a-z0-9-]+):\s*$", line) if m: cur = m.group(1) m = re.match(r"^\s+image:\s*(\S+)", line) if m and cur: pins[cur] = m.group(1) out, cur = [], None for line in s.splitlines(): m = re.match(r"^ ([a-z0-9-]+):\s*$", line) if m: cur = m.group(1) mi = re.match(r"^(\s+image:\s*)(\S+)\s*$", line) if mi and cur in moves: line = mi.group(1) + moves[cur] out.append(line) open(comp, "w").write("\n".join(out) + "\n") top = dict(pins); top.update(moves) entry = {"from": pins, "to": top, "verdict": "proven", "tested_at": "DRILL", "harness_version": 4, "evidence": "DRILL (box proof in progress)", "marks": {"files_may_change": False, "needs_person": None, "memory_tight": False}} f = open(fy).read() f = f.rstrip("\n") + "\n - " + json.dumps(entry) + "\n" if "update_ladder:" in f else f.rstrip("\n") + "\nupdate_ladder:\n - " + json.dumps(entry) + "\n" open(fy, "w").write(f) subprocess.run(["git", "-C", D, "commit", "-q", "-am", f"DRILL {app}: {moves} (box proof)"], check=True) subprocess.run(["git", "-C", D, "push", "-q", "origin", "main"], check=True, capture_output=True) say("drill:", subprocess.run(["git", "-C", D, "log", "--oneline", "-1"], capture_output=True, text=True).stdout.strip()) w.sync_rescan(app, next(iter(moves.values()))) since = w.guest("date -u +%Y-%m-%dT%H:%M:%SZ").strip() res = w.press_update(app, poll=1, cap_s=1800) for p in res.get("phases", []): log.write(f" phase +{p['t']}s {p['phase']} | err={p['error']}\n") time.sleep(10) read = FX[app].verify(w, sub, toks[app], say) lines = w.guest(f"docker logs --since {since} felhom-controller 2>&1 | grep -E 'update {app}' | grep -v DEBUG | cut -c1-400") log.write(lines + "\n") st = w.stack(app); after = (st.get("app_config") or {}).get("pinned_images") verdict = {"app": app, "venue": "box 9202 (drill catalog, controller 0.285.0), the product's guarded Update", "from": before, "to": after, "verdict": "proven" if (res.get("final_phase") == "done" and read and all(after.get(k) == v for k, v in moves.items())) else "failed", "seed_read_before": True, "seed_read_after": read, "healthy_after": st.get("state") == "running", "duration_s": res.get("duration_s"), "final_phase": res.get("final_phase"), "measured_at": since, "evidence": f"felhom.eu/documentation/audits/new-apps-2026-10-01/box/{app}/step.txt"} json.dump(verdict, open(f"{EVD}/box-verdict-{app}.json", "w"), indent=2) say(f"RESULT final_phase={res.get('final_phase')} after={after} seed_after={read} verdict={verdict['verdict']} ({res.get('duration_s')} s)")