The gate failed only on `released > baked`, so it could catch a forgotten bake and nothing else. A golden AHEAD of the record passed silently - and that is how controller 0.221.1 was built, baked AND vouched while the newest CHANGELOG heading still read v0.221.0, with every gate green. Reproduced on the real history: newest released 0.221.0 / newest golden baked 0.221.1 -> exit 0. The gate now asks whether the version being shipped is WRITTEN DOWN: the baked version must have its own `## vX.Y.Z` heading anywhere in the CHANGELOG. Membership rather than `baked > released` deliberately - a comparison against the newest heading alone goes green the moment any later entry is written, leaving the unrecorded version permanently unrecorded. INCONCLUSIVE (exit 2) preserved; every refusal names a reason and a route. Red-proofed both directions: old gate/old record exit 0, new gate/old record exit 1, new gate/fixed record exit 0, absent clone exit 2, post-bake exit 0. 08-alarm-ladder.md is new, and its absence was itself the finding: no document owned "when does a broken app raise an alarm?". The rules lived as comments in four packages, each locally correct, with the ordering between them legible only by reading one function top to bottom - which is how R-384 survived review. R-383 and R-384 closed into CLOSED-ITEMS with their rules kept. R-385 filed closed. R-386 filed OPEN: a single-container app stopped out of band raises no alarm, and a comment claims the opposite - measured live, 9 scans, 0 events, against a positive control from the same box 17 minutes earlier. Not fixed here. Golden 0.222.0 baked and published; vouching is the operator's act.
5.2 KiB
REPORT — felhom.eu: the golden-currency gate could not see an unrecorded golden (R-385)
Session 2026-08-23. Companion to felhom-controller v0.222.0 (R-384, R-383) — see that repo's
REPORT.md for the controller work and the full live walk.
What was wrong here
scripts/golden_currency_gate.py asked ONE question — is the golden BEHIND the record? — and
therefore could only ever catch a forgotten bake. It said nothing when the golden was AHEAD of the
record, and that direction is not harmless: a golden ahead of every CHANGELOG heading was built
from something never written down.
That is not hypothetical. Controller 0.221.1 was built, baked and vouched on 2026-08-23 while
the newest heading in the controller CHANGELOG still read v0.221.0. Measured on the real history,
with the old gate:
newest released controller : 0.221.0 (## v0.221.0 — taking the undo copy destroyed …)
newest golden baked : 0.221.1 (documentation/tests/golden-0.221.1-2026-08-23)
golden currency gate OK …
EXIT=0
Every gate was green while the fleet ran a version the record did not name.
The fix, and why it is membership and not a comparison
The gate now asks "is the version we are shipping WRITTEN DOWN?" — the baked version must have its
own ## vX.Y.Z heading anywhere in the controller CHANGELOG, not merely at the top (an entry may
legitimately be overtaken by later ones; what may never happen is that it is absent).
Membership, not baked > released, deliberately: a comparison against the newest heading alone
goes green the moment ANY later entry is written — which would have left 0.221.1 permanently
unrecorded and the gate permanently silent about it.
Preserved unchanged: INCONCLUSIVE (exit 2) for an absent clone or an unparseable CHANGELOG — not knowing is never a pass, and never a conviction. Every refusal names a reason and a route, including what to do if a bake was a throwaway that must never be delivered.
Red-proofs — both directions, against the real history
| Run | Gate | CHANGELOG | Golden baked | Exit | |
|---|---|---|---|---|---|
gate-01 |
old | v0.221.0 | 0.221.1 | 0 | the blindness, reproduced |
gate-02 |
new | v0.221.0 | 0.221.1 | 1 | convicted |
gate-03 |
new | v0.221.1 | 0.221.1 | 0 | Part 0's heading makes it pass |
gate-04 |
new | absent clone | — | 2 | INCONCLUSIVE preserved |
gate-05 |
new | v0.222.0 | 0.222.0 | 0 | post-bake |
Transcripts: documentation/audits/DRILL-r384-dead-db-alarm-2026-08-23/evidence/gate-0*.txt.
Files changed
| File | Change |
|---|---|
scripts/golden_currency_gate.py |
the unrecorded-golden conviction; newest_released → released_versions returning the whole set; docstring records the second blindness |
documentation/architecture/08-alarm-ladder.md |
NEW. The alarm ladder as a dated [DESIGN] |
documentation/architecture/00-capability-map.md |
R-384 marked closed with its live evidence; points at the new doc |
documentation/backlog/OPEN-ITEMS.md |
R-383/R-384 removed (closed); R-385 (closed) and R-386 (open) filed |
documentation/backlog/CLOSED-ITEMS.md |
R-383 + R-384 compressed, each keeping its rules and naming git show 1eb64bec5183:… for the full text |
documentation/tests/golden-0.222.0-2026-08-23/ |
NEW. Bake evidence + log + the vouching instructions |
STATUS.md |
the 0.222.0 vouch replaces the (now completed) 0.221.1 one; R-386 added in plain words |
documentation/audits/DRILL-r384-dead-db-alarm-2026-08-23/ |
NEW. The drill record and 29 evidence files |
The alarm ladder had no owning document — that absence is a finding
Nothing in documentation/architecture/ owned the question "when does a customer's app being broken
raise an alarm?" The rules lived as comments across four packages, each locally correct, with the
ordering between them legible only by reading aggregateState top to bottom. That is precisely how
R-384 survived review, and three separate defects in this ladder (R-51, C9-F2, R-384) were each
found on live hardware rather than by reading. 08-alarm-ladder.md now owns it.
Golden
Baked and PUBLISHED: 0.222.0. GOLDEN_SHA256 = 19f5904f5379…, upload OK (HTTP 201), round-trip
HTTP 206 from the package URL, all acceptance markers counted.
VOUCHING IS THE OPERATOR'S ACT AND WAS NOT DONE HERE.
Deviation recorded: the bake runbook's §4.1 is missing a pveam update. On the virgin snapshot
the template index is stale, so the listed template cannot be downloaded and the failure presents as
400 Parameter verification failed. template: no such template rather than as a stale index.
Register size
| File | Before | After |
|---|---|---|
OPEN-ITEMS.md |
327,266 B | 328,325 B |
CLOSED-ITEMS.md |
68,464 B | 71,441 B |
OPEN grew ~1 KB despite two closures, because R-386 is a substantial new finding. Recorded rather than smoothed over.
Hub numbers as read at session start (live, GET /configuration)
golden_version 0.221.1 · agent_version 0.130.0 · min_agent 0.129.0 ·
controller floor 0.221.1. The task expected 0.220.2/0.220.2; the operator had already vouched.
The hub was READ ONLY this session — nothing was written to it.