# RUNBOOK — test waits for OS-update approvals, and how they end Design: `architecture/11-os-updates.md` §5.3, §5.3.1, §5.8. Row R-859. Hub v0.133.0. ## The ruled waits - Guest and host fast lane: every ring-0 box runs the set healthy for **24 h** and through **1** night run → the hub approves it automatically. - Docker engine set: every ring-0 box ran it in **2** healthy night Docker steps → the operator's "Approve Docker set" button works. ## A test wait (only for a test, never to ship) Set one of these env vars on the hub Deployment (via `manifests/hub.yaml`, synced), restart: `OS_APPROVE_AFTER=`, `OS_APPROVE_NIGHTS=`, `OS_DOCKER_APPROVE_NIGHTS=`. The hub logs `TEST CONFIGURATION` at start. **The rule (R-859): test approvals end with the test.** Every approval made while ANY of the three is set is stored with a `test` mark (amber "TEST approval" on the System page). At the next start WITHOUT the overrides, every test approval that no real approval has superseded is **cancelled**: no ring-1 box installs it from then on (ring-1 boxes are bumped), and the operator gets an `os_release_cancelled` mail. What boxes already installed stays. The same set is approved again by the ruled wait, as a real release. So: **remove the override and restart the hub as the last step of every test.** Leaving it set leaves the test approvals in force for real boxes. ## The 2026-10-04 fact On 2026-10-04 no release could pass the ruled 24 h + 1 night, so the guest and host sets were approved under the test wait (12:39 / 12:41 UTC, 1.5 h after first seen). **Tester 2** (bound 16:06 UTC) installed both on its first night run (16:24 / 16:25 UTC): 49 guest and 106 host packages. Why the risk was small: ring 0 (both demo boxes) had run the same sets healthy since 11:07 / 12:24 UTC and kept running them; the packages are Debian (Security) fixes only; Tester 2 reported both runs `applied, healthy`. Hub v0.133.0's one-time backfill marked those two automatic approvals as test approvals and cancelled them at its start (2026-10-04 18:20 UTC, with two older ones of the same day). The operator's own Docker button approval of that day stays in force (decided by CC unattended — operator may reverse).