55274d5ef3
gates / gates (push) Successful in 17s
The gate failed only on `released > baked`, so it could catch a forgotten bake and nothing else. A golden AHEAD of the record passed silently - and that is how controller 0.221.1 was built, baked AND vouched while the newest CHANGELOG heading still read v0.221.0, with every gate green. Reproduced on the real history: newest released 0.221.0 / newest golden baked 0.221.1 -> exit 0. The gate now asks whether the version being shipped is WRITTEN DOWN: the baked version must have its own `## vX.Y.Z` heading anywhere in the CHANGELOG. Membership rather than `baked > released` deliberately - a comparison against the newest heading alone goes green the moment any later entry is written, leaving the unrecorded version permanently unrecorded. INCONCLUSIVE (exit 2) preserved; every refusal names a reason and a route. Red-proofed both directions: old gate/old record exit 0, new gate/old record exit 1, new gate/fixed record exit 0, absent clone exit 2, post-bake exit 0. 08-alarm-ladder.md is new, and its absence was itself the finding: no document owned "when does a broken app raise an alarm?". The rules lived as comments in four packages, each locally correct, with the ordering between them legible only by reading one function top to bottom - which is how R-384 survived review. R-383 and R-384 closed into CLOSED-ITEMS with their rules kept. R-385 filed closed. R-386 filed OPEN: a single-container app stopped out of band raises no alarm, and a comment claims the opposite - measured live, 9 scans, 0 events, against a positive control from the same box 17 minutes earlier. Not fixed here. Golden 0.222.0 baked and published; vouching is the operator's act.
98 lines
5.2 KiB
Markdown
98 lines
5.2 KiB
Markdown
# REPORT — felhom.eu: the golden-currency gate could not see an unrecorded golden (R-385)
|
|
|
|
**Session 2026-08-23.** Companion to `felhom-controller` v0.222.0 (R-384, R-383) — see that repo's
|
|
`REPORT.md` for the controller work and the full live walk.
|
|
|
|
## What was wrong here
|
|
|
|
`scripts/golden_currency_gate.py` asked ONE question — *is the golden BEHIND the record?* — and
|
|
therefore could only ever catch a forgotten bake. **It said nothing when the golden was AHEAD of the
|
|
record**, and that direction is not harmless: a golden ahead of every CHANGELOG heading was built
|
|
from something never written down.
|
|
|
|
That is not hypothetical. Controller **0.221.1** was built, baked **and vouched** on 2026-08-23 while
|
|
the newest heading in the controller CHANGELOG still read `v0.221.0`. Measured on the real history,
|
|
with the old gate:
|
|
|
|
```
|
|
newest released controller : 0.221.0 (## v0.221.0 — taking the undo copy destroyed …)
|
|
newest golden baked : 0.221.1 (documentation/tests/golden-0.221.1-2026-08-23)
|
|
golden currency gate OK …
|
|
EXIT=0
|
|
```
|
|
|
|
Every gate was green while the fleet ran a version the record did not name.
|
|
|
|
## The fix, and why it is membership and not a comparison
|
|
|
|
The gate now asks **"is the version we are shipping WRITTEN DOWN?"** — the baked version must have its
|
|
own `## vX.Y.Z` heading **anywhere** in the controller CHANGELOG, not merely at the top (an entry may
|
|
legitimately be overtaken by later ones; what may never happen is that it is absent).
|
|
|
|
**Membership, not `baked > released`, deliberately:** a comparison against the newest heading alone
|
|
goes green the moment ANY later entry is written — which would have left 0.221.1 permanently
|
|
unrecorded and the gate permanently silent about it.
|
|
|
|
Preserved unchanged: **INCONCLUSIVE (exit 2)** for an absent clone or an unparseable CHANGELOG — *not
|
|
knowing is never a pass, and never a conviction*. Every refusal names a reason **and** a route,
|
|
including what to do if a bake was a throwaway that must never be delivered.
|
|
|
|
## Red-proofs — both directions, against the real history
|
|
|
|
| Run | Gate | CHANGELOG | Golden baked | Exit | |
|
|
|---|---|---|---|---|---|
|
|
| `gate-01` | **old** | v0.221.0 | 0.221.1 | **0** | the blindness, reproduced |
|
|
| `gate-02` | **new** | v0.221.0 | 0.221.1 | **1** | convicted |
|
|
| `gate-03` | new | v0.221.1 | 0.221.1 | **0** | Part 0's heading makes it pass |
|
|
| `gate-04` | new | absent clone | — | **2** | INCONCLUSIVE preserved |
|
|
| `gate-05` | new | v0.222.0 | 0.222.0 | **0** | post-bake |
|
|
|
|
Transcripts: `documentation/audits/DRILL-r384-dead-db-alarm-2026-08-23/evidence/gate-0*.txt`.
|
|
|
|
## Files changed
|
|
|
|
| File | Change |
|
|
|---|---|
|
|
| `scripts/golden_currency_gate.py` | the unrecorded-golden conviction; `newest_released` → `released_versions` returning the whole set; docstring records the second blindness |
|
|
| `documentation/architecture/08-alarm-ladder.md` | **NEW.** The alarm ladder as a dated [DESIGN] |
|
|
| `documentation/architecture/00-capability-map.md` | R-384 marked closed with its live evidence; points at the new doc |
|
|
| `documentation/backlog/OPEN-ITEMS.md` | R-383/R-384 removed (closed); **R-385** (closed) and **R-386** (open) filed |
|
|
| `documentation/backlog/CLOSED-ITEMS.md` | R-383 + R-384 compressed, each keeping its rules and naming `git show 1eb64bec5183:…` for the full text |
|
|
| `documentation/tests/golden-0.222.0-2026-08-23/` | **NEW.** Bake evidence + log + the vouching instructions |
|
|
| `STATUS.md` | the 0.222.0 vouch replaces the (now completed) 0.221.1 one; R-386 added in plain words |
|
|
| `documentation/audits/DRILL-r384-dead-db-alarm-2026-08-23/` | **NEW.** The drill record and 29 evidence files |
|
|
|
|
## The alarm ladder had no owning document — that absence is a finding
|
|
|
|
Nothing in `documentation/architecture/` owned the question *"when does a customer's app being broken
|
|
raise an alarm?"* The rules lived as comments across four packages, each locally correct, with the
|
|
ordering between them legible only by reading `aggregateState` top to bottom. **That is precisely how
|
|
R-384 survived review**, and three separate defects in this ladder (R-51, C9-F2, R-384) were each
|
|
found on live hardware rather than by reading. `08-alarm-ladder.md` now owns it.
|
|
|
|
## Golden
|
|
|
|
**Baked and PUBLISHED: 0.222.0.** `GOLDEN_SHA256 = 19f5904f5379…`, `upload OK (HTTP 201)`, round-trip
|
|
`HTTP 206` from the package URL, all acceptance markers counted.
|
|
**VOUCHING IS THE OPERATOR'S ACT AND WAS NOT DONE HERE.**
|
|
|
|
**Deviation recorded:** the bake runbook's §4.1 is missing a `pveam update`. On the `virgin` snapshot
|
|
the template index is stale, so the listed template cannot be downloaded and the failure presents as
|
|
`400 Parameter verification failed. template: no such template` rather than as a stale index.
|
|
|
|
## Register size
|
|
|
|
| File | Before | After |
|
|
|---|---|---|
|
|
| `OPEN-ITEMS.md` | 327,266 B | **328,325 B** |
|
|
| `CLOSED-ITEMS.md` | 68,464 B | **71,441 B** |
|
|
|
|
OPEN grew ~1 KB despite two closures, because R-386 is a substantial new finding. Recorded rather
|
|
than smoothed over.
|
|
|
|
## Hub numbers as read at session start (live, `GET /configuration`)
|
|
|
|
`golden_version` **0.221.1** · `agent_version` **0.130.0** · `min_agent` **0.129.0** ·
|
|
controller floor **0.221.1**. The task expected 0.220.2/0.220.2; the operator had already vouched.
|
|
**The hub was READ ONLY this session** — nothing was written to it.
|