09-update-architecture.md gains the fourth dated operator ruling (2026-09-06, Option 1) and its section 5 is rewritten from a proposed shape into the shipped one: the pin, the stored definition, the render table, the four writers, the startup ordering, and the trap this slice set for slice 2 - the live compose file is now the frozen one, so a badge comparing against it would answer Naprakesz on exactly the apps that are behind. 02-controller-module-map.md said 'copy compose + .felhom.yml'. That stopped being true today, so it is corrected, and the two sections describing the old seam now carry a banner saying they describe v0.234.0 and below - kept because every box under v0.235.0 still behaves that way and because they are the measured account of why it changed. R-447, R-441, R-438 and R-455 closed and compressed into CLOSED-ITEMS; R-458 opened for the .felhom.yml asymmetry, with what would settle it by measurement. Live evidence: two real catalog pushes travelling the real 15-minute cycle, both reverted, the tree byte-identical afterwards. The restart that used to take 18.3 seconds and pull a new image now takes 0.1 seconds and pulls nothing.
4.4 KiB
REPORT — update arc slice 3: the version freeze (2026-09-06)
Overwritten each session. Nothing durable lives only here.
What this session changed in THIS repo
| file | change |
|---|---|
documentation/architecture/09-update-architecture.md |
§3 gains the fourth dated operator ruling (2026-09-06, Option 1); §5 rewritten from a proposed shape into the shipped mechanism — the pin, the stored definition, the render table, the four writers, the startup ordering, and §5.6 the trap it set for slice 2; slice 3 moved to shipped; two limitations added (§8.4 frozen-whole, §8.5 the .felhom.yml asymmetry). |
documentation/architecture/02-controller-module-map.md |
its "copy compose + .felhom.yml" line stopped being true and is corrected; §1/§2 of the app-definition seam now carry a banner saying they describe ≤ v0.234.0 and why they are kept. |
documentation/tests/VALIDATION-update-slice3-2026-09-06.md |
CREATED — the live evidence. |
documentation/backlog/OPEN-ITEMS.md |
R-447, R-441, R-438 and R-455 closed and moved out; R-458 opened. |
documentation/backlog/CLOSED-ITEMS.md |
the four closed rows, compressed, each naming bc47dd4ef997 as the commit whose git show returns the original. |
documentation/backlog/ROADMAP.md |
the arc item collapsed to slices 1/1b/2/3 shipped; R-448 named as the new head of the arc. |
documentation/architecture/00-capability-map.md |
one new row, PROVEN-LIVE; the pre-v0.235.0 row relabelled rather than deleted, because every box below v0.235.0 still behaves that way. |
STATUS.md |
new lead + item 10; items 4 and R-455 closed. |
The ruling, recorded
2026-09-06, Option 1: freeze the version, keep the fixes flowing. The document records what the ruling looked at, not just its outcome: the old behaviour had two halves — a restart silently changing an app's VERSION (unwanted), and template corrections plus self-healing reaching a deployed app (worth keeping) — and the ruling keeps the second while removing the first.
Register — 203 open rows before, 203 after; closed 163 → 167
Four closed and moved, one opened. The count is level by coincidence, not by inaction.
| row | disposition |
|---|---|
| R-447 | CLOSED — slice 3 shipped, controller v0.235.0 |
| R-441 | CLOSED BY MEASUREMENT — the restore now pins to what the unit captured; the render obeys it. The live half is §3/§6b of the validation file, not a code reading |
| R-438 | CLOSED — both halves discharged: documented 2026-09-02, behaviour changed 2026-09-06 |
| R-455 | CLOSED — the operator added a Docker Hub PAT |
| R-458 | OPENED (P3-LOW, CC) — .felhom.yml keeps flowing to a frozen app, so it can receive a health check written for a newer version. False alarm, never data loss. The row states what would settle it by measurement rather than by code |
Live validation
Full evidence: documentation/tests/VALIDATION-update-slice3-2026-09-06.md. Two REAL catalog pushes
travelling the REAL 15-minute cycle, both reverted in the same session; the catalog tree is
byte-identical to 8220f8d afterwards.
- Scenario A — a non-image change reached the pinned app (08:01:51Z), container untouched.
- Scenario B — an image change did not (08:20:29Z), and the restart afterwards took 0.1 s, did not recreate the container, and never pulled the new image — against 18.3 s with a pull for the identical sequence measured before the change.
- Scenario D — the Update button still moved the version, with the pin advancing 17 s before the pull completed.
- Scenario G — the frozen app read „Frissítés elérhető — 56 napja" while the other eight read „Naprakész".
- Teardown — the container is back on the baseline digest
sha256:eaeea1e4…, byte for byte.
A real gap was found by the live run and fixed in it: the stored definition did not follow the fixes delivered after the pin, so the first freeze would have reverted them — silently undoing the half of the ruling that says fixes keep flowing. Section 6 of the validation file keeps the observation that proved it.
Sibling repos
felhom-controllerv0.235.0 —8a0e0a59adc7+2a56f557d048, deployed to demo-hp, healthy.app-catalog-felhom.eu—dc7e548,09b4ff5(live-test) and1798ce6,17cc784(reverts), plus7b9b9b3recording them as a measurement rather than a release.