Files
felhom.eu/REPORT-new-app-checklist-2026-10-01.md
admin 2d69c61556
gates / gates (push) Successful in 27s
New-app checklist: the pilot audit (wger as of 2026-09-29 and now, two 9202 walks), R-758..R-764 opened; STATUS, CONTEXT, report
The operator's request of 2026-10-01 recorded in CONTEXT with the reviewer's defaults (new apps only; the 53 get a
read-only gap page). The pilot: the draft caught R-752 and R-755, missed R-737 and (for a new app) R-738; the
sharpened and new rows then found R-762 (wger serves no static files or photos), R-763 (strangers sign up, guest
accounts), R-764 (no mail). Also R-758 (8 mem_limit under the sum), R-759 (wger's open record rows), R-760
(vikunja healthcheck), R-761 (logo comment). R-755 note. Register 392 -> 399.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-01 15:22:05 +02:00

61 lines
4.2 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# REPORT — the new-app checklist: in the catalog, a gate, piloted on wger (2026-10-01, evening)
Architecture read: `documentation/architecture/09-update-architecture.md` §3 (decisions 13, 22, 37, 42, 45–50, 61) and
§6.5. Evidence: `documentation/audits/new-app-checklist-2026-10-01/README.md` (the full write-up).
## The Part table
| part | result | changed from the brief, and why |
|---|---|---|
| A — checklist in the catalog | **done** — `NEW-APP-CHECKLIST.md` 60 rows / 10 groups; `onboarding/_TEMPLATE.md`; CLAUDE.md, REUSE.md §5, README point to it | 7 rows added, 16 sharpened, 9 wrong claims fixed (below). A `since` column per id (B's date rule) |
| B — the gate | **done** — `scripts/check-onboarding.py`, gate `onboarding` in `--fast` (hook + CI); 16 decoys, all judged right; 5 gate mutants each turn the suite red | the 53 are exempt **by name**, not "new since commit X": CI fetches at depth 1 and cannot diff (R-452). Evidence in `felhom.eu/` is checked where that repo sits beside the catalog (the hook) and printed as NOT CHECKED where it does not (CI). Rows inside an HTML comment do not count; an empty evidence directory does not count |
| C — wger pilot | **done** — both records filled; table below | the restore round trip (2.5) could not be measured: no per-app backup press exists outside an Update (R-648) — open, R-759 |
| D — gap page | **done** — `onboarding/EXISTING-APPS-GAPS.md` from `scripts/onboarding_gaps.py` | none |
**The date rule (B.1):** each checklist id carries `since`; a record answers every id with `since` ≤ its `opened:`.
`opened:` must be on or after 2026-10-01 and not in the future, so a later id binds only apps opened after it. Residual:
an author can date `opened:` back to the cut-off to skip ids added since — the gate cannot see that; review can.
## Claims in the draft that were wrong
3.3 "32 apps" (33 today) · 5.2 "romm OOM at +76 s (decision 22)" (no such figure anywhere; R-635) · 5.3 "gate" (no gate;
8 templates differ, R-758) · 6.2 "35 of 53 update at night" (not reproducible; 38 carry a ladder) · 8.3 logo address
(`.webp` vs the controller's `.svg`/`.png`, R-761) · 1.6's how could not show R-737 · 1.4's how has nothing to run for
an app at its newest tag · 0.4's packet capture is not in our kit · 2.6's R-756 is an unexplained venue case (R-442
added). Duplicates of gates now name the gate (1.1, 2.1, 3.3, 4.2, 6.2, 8.1, 9.4).
## The pilot — the four problems
| problem | caught by | the draft's how? |
|---|---|---|
| R-737 JWT key | 1.6, 3.9 (new), 0.7 | **missed** — web login worked |
| R-738 no migration | 1.4, 1.7 (new), 6.1 | **only if an update existed** — not for a new app |
| R-752 lock-out → everyone | 3.6 | **caught** |
| R-755 dev server | 1.5, 1.7 | **caught** |
**And three more, found by the new rows on the LIVE wger template (9202, drill catalog):** R-762 no CSS/JS and no
uploaded photo is ever served (404); R-763 a stranger signs up after the setup, and every anonymous dashboard visit
creates a guest account; R-764 mail goes to the console. Not fixed: this task changes no template.
## Gap page headline (of 53)
Fit 52 · images/DB 53 · storage 38 · accounts 39 · health 49 · resources 24 · updates 26 · mail — (6 mapped) · text 52.
## Rows
Opened **R-758** (8 `mem_limit` ≠ sum), **R-759** (wger's open record rows), **R-760** (vikunja healthcheck),
**R-761** (logo comment), **R-762** (P2, wger static + media), **R-763** (P2, wger strangers + guests), **R-764**
(wger mail). Narrowed: none. Note added to R-755 (same server question as R-762). Closed: none.
**Register 392 → 399.** STATUS updated.
## Live work and teardown
9202 only, drill catalog `e9f50b5` (repointed, then restored to live `6d72c09` — three controls each way). wger
installed and removed twice through the product. **Machine:** no wger container, volume or image left; sampler files
removed. **Host:** nothing. **Hub:** untouched. Secrets never printed; evidence scanned for their values.
## Gates
Catalog: `catalog_gates.py --fast` all OK (11 gates); `test_gate_decoys.py` 121 cases OK; `test_catalog_gates.py` OK;
`decoy_coverage_gate.py` 0 unaccounted. felhom.eu: `repo_gates.py --fast` — see the commit. No `--no-verify`.