Files
felhom.eu/REPORT.md
T
admin 55274d5ef3
gates / gates (push) Successful in 17s
R-385: make an UNRECORDED golden fail the currency gate; file R-386; own the alarm ladder
The gate failed only on `released > baked`, so it could catch a forgotten bake
and nothing else. A golden AHEAD of the record passed silently - and that is
how controller 0.221.1 was built, baked AND vouched while the newest CHANGELOG
heading still read v0.221.0, with every gate green. Reproduced on the real
history: newest released 0.221.0 / newest golden baked 0.221.1 -> exit 0.

The gate now asks whether the version being shipped is WRITTEN DOWN: the baked
version must have its own `## vX.Y.Z` heading anywhere in the CHANGELOG.
Membership rather than `baked > released` deliberately - a comparison against
the newest heading alone goes green the moment any later entry is written,
leaving the unrecorded version permanently unrecorded. INCONCLUSIVE (exit 2)
preserved; every refusal names a reason and a route.

Red-proofed both directions: old gate/old record exit 0, new gate/old record
exit 1, new gate/fixed record exit 0, absent clone exit 2, post-bake exit 0.

08-alarm-ladder.md is new, and its absence was itself the finding: no document
owned "when does a broken app raise an alarm?". The rules lived as comments in
four packages, each locally correct, with the ordering between them legible only
by reading one function top to bottom - which is how R-384 survived review.

R-383 and R-384 closed into CLOSED-ITEMS with their rules kept. R-385 filed
closed. R-386 filed OPEN: a single-container app stopped out of band raises no
alarm, and a comment claims the opposite - measured live, 9 scans, 0 events,
against a positive control from the same box 17 minutes earlier. Not fixed here.

Golden 0.222.0 baked and published; vouching is the operator's act.
2026-08-23 07:59:52 +02:00

98 lines
5.2 KiB
Markdown

# REPORT — felhom.eu: the golden-currency gate could not see an unrecorded golden (R-385)
**Session 2026-08-23.** Companion to `felhom-controller` v0.222.0 (R-384, R-383) — see that repo's
`REPORT.md` for the controller work and the full live walk.
## What was wrong here
`scripts/golden_currency_gate.py` asked ONE question — *is the golden BEHIND the record?* — and
therefore could only ever catch a forgotten bake. **It said nothing when the golden was AHEAD of the
record**, and that direction is not harmless: a golden ahead of every CHANGELOG heading was built
from something never written down.
That is not hypothetical. Controller **0.221.1** was built, baked **and vouched** on 2026-08-23 while
the newest heading in the controller CHANGELOG still read `v0.221.0`. Measured on the real history,
with the old gate:
```
newest released controller : 0.221.0 (## v0.221.0 — taking the undo copy destroyed …)
newest golden baked : 0.221.1 (documentation/tests/golden-0.221.1-2026-08-23)
golden currency gate OK …
EXIT=0
```
Every gate was green while the fleet ran a version the record did not name.
## The fix, and why it is membership and not a comparison
The gate now asks **"is the version we are shipping WRITTEN DOWN?"** — the baked version must have its
own `## vX.Y.Z` heading **anywhere** in the controller CHANGELOG, not merely at the top (an entry may
legitimately be overtaken by later ones; what may never happen is that it is absent).
**Membership, not `baked > released`, deliberately:** a comparison against the newest heading alone
goes green the moment ANY later entry is written — which would have left 0.221.1 permanently
unrecorded and the gate permanently silent about it.
Preserved unchanged: **INCONCLUSIVE (exit 2)** for an absent clone or an unparseable CHANGELOG — *not
knowing is never a pass, and never a conviction*. Every refusal names a reason **and** a route,
including what to do if a bake was a throwaway that must never be delivered.
## Red-proofs — both directions, against the real history
| Run | Gate | CHANGELOG | Golden baked | Exit | |
|---|---|---|---|---|---|
| `gate-01` | **old** | v0.221.0 | 0.221.1 | **0** | the blindness, reproduced |
| `gate-02` | **new** | v0.221.0 | 0.221.1 | **1** | convicted |
| `gate-03` | new | v0.221.1 | 0.221.1 | **0** | Part 0's heading makes it pass |
| `gate-04` | new | absent clone | — | **2** | INCONCLUSIVE preserved |
| `gate-05` | new | v0.222.0 | 0.222.0 | **0** | post-bake |
Transcripts: `documentation/audits/DRILL-r384-dead-db-alarm-2026-08-23/evidence/gate-0*.txt`.
## Files changed
| File | Change |
|---|---|
| `scripts/golden_currency_gate.py` | the unrecorded-golden conviction; `newest_released` → `released_versions` returning the whole set; docstring records the second blindness |
| `documentation/architecture/08-alarm-ladder.md` | **NEW.** The alarm ladder as a dated [DESIGN] |
| `documentation/architecture/00-capability-map.md` | R-384 marked closed with its live evidence; points at the new doc |
| `documentation/backlog/OPEN-ITEMS.md` | R-383/R-384 removed (closed); **R-385** (closed) and **R-386** (open) filed |
| `documentation/backlog/CLOSED-ITEMS.md` | R-383 + R-384 compressed, each keeping its rules and naming `git show 1eb64bec5183:…` for the full text |
| `documentation/tests/golden-0.222.0-2026-08-23/` | **NEW.** Bake evidence + log + the vouching instructions |
| `STATUS.md` | the 0.222.0 vouch replaces the (now completed) 0.221.1 one; R-386 added in plain words |
| `documentation/audits/DRILL-r384-dead-db-alarm-2026-08-23/` | **NEW.** The drill record and 29 evidence files |
## The alarm ladder had no owning document — that absence is a finding
Nothing in `documentation/architecture/` owned the question *"when does a customer's app being broken
raise an alarm?"* The rules lived as comments across four packages, each locally correct, with the
ordering between them legible only by reading `aggregateState` top to bottom. **That is precisely how
R-384 survived review**, and three separate defects in this ladder (R-51, C9-F2, R-384) were each
found on live hardware rather than by reading. `08-alarm-ladder.md` now owns it.
## Golden
**Baked and PUBLISHED: 0.222.0.** `GOLDEN_SHA256 = 19f5904f5379…`, `upload OK (HTTP 201)`, round-trip
`HTTP 206` from the package URL, all acceptance markers counted.
**VOUCHING IS THE OPERATOR'S ACT AND WAS NOT DONE HERE.**
**Deviation recorded:** the bake runbook's §4.1 is missing a `pveam update`. On the `virgin` snapshot
the template index is stale, so the listed template cannot be downloaded and the failure presents as
`400 Parameter verification failed. template: no such template` rather than as a stale index.
## Register size
| File | Before | After |
|---|---|---|
| `OPEN-ITEMS.md` | 327,266 B | **328,325 B** |
| `CLOSED-ITEMS.md` | 68,464 B | **71,441 B** |
OPEN grew ~1 KB despite two closures, because R-386 is a substantial new finding. Recorded rather
than smoothed over.
## Hub numbers as read at session start (live, `GET /configuration`)
`golden_version` **0.221.1** · `agent_version` **0.130.0** · `min_agent` **0.129.0** ·
controller floor **0.221.1**. The task expected 0.220.2/0.220.2; the operator had already vouched.
**The hub was READ ONLY this session** — nothing was written to it.