Files
felhom.eu/REPORT-burndown-2026-10-05.md
T

8.3 KiB

REPORT — the burn-down: the open-items list gets shorter — 2026-10-05 (night)

Part Result
A — stale sweep, every P4 then every P3 row, oldest first done — 317 rows checked against main; 24 closed as fixed by later work, 2 closed as duplicates (facts merged); table documentation/audits/burndown-2026-10-05/partA-table.md
B — small fixes, batched done — 19 rows fixed and closed in four repos, each with a test (and a red-proof where a check changed); no release (see below)
C — the „not worth doing" list done — 45 rows in STATUS.md, one line each with my pick; none closed; 2 more (leaked tokens) listed as actions for the operator
D — stop the growth done — the size rule and the four-numbers rule, in the register, the rules file (4 copies) and the report template
Rows before Rows after Opened Closed
336 291 0 45

Counted by register_shape_gate.py's method (| **R-n** | lines in OPEN-ITEMS.md). Target was ≥ 40 fewer: 45.

Baselines (re-verified at the start)

felhom.eu 53d8131b20 (hub v0.136.0) · controller 7690c27f86 (v0.296.0) · agent e06ed97fa8 (v0.146.1) · catalog 917a779cca. Register 336: P2 19, P3 139, P4 178.

Why no release

The brief allowed one release per repo, but also said „DooPlex: no change". The hub runs on DooPlex, so a hub release could not be deployed; delivering a controller or agent release needs a floor raise or signed jobs through the hub. So Part B fixed only what needs no release: documents, comments, tests, gates, catalog tooling. Controller, agent and hub each carry an ## unreleased head in CHANGELOG.md for these; the next release folds it into its own entry. Code rows that need a release stay open (they are in the Part A table as STILL-TRUE-SMALL with their fix described).

Part A — the sweep

Eight read-only checker agents took 40 rows each (P4 then P3, oldest id first). No machine was reached. Groups over all 317: FIXED-BY-LATER-WORK 29, DUPLICATE 2, STILL-TRUE-SMALL 91, STILL-TRUE-NOT-SMALL 129, NOT-WORTH-IT 43, UNCHECKED 23.

Every FIXED and DUPLICATE verdict was re-checked before closing: 22 cited proof lines re-grepped (all present; one first missed by my own shell quoting). Of the 29 „fixed": 24 closed; R-274 kept (only one of its two halves was checked); R-700, R-704, R-706, R-723 moved to Part C — their code fix and tests exist, but each row waits for a live observation, and closing them would silently drop that. R-766 was additionally checked in the live hub image (read only): the new app logos are in /usr/share/felhom/assets-seed/.

Closed as fixed by later work: R-184, R-207, R-287, R-289, R-373, R-390, R-427, R-437, R-464, R-501, R-602, R-617, R-705, R-766, R-50b, R-121, R-200, R-450, R-489, R-573, R-622, R-635, R-235, R-282. Duplicates: R-755 → R-762, R-446 → R-440 (the unique fact of each moved into the survivor). Each closed row's evidence is in CLOSED-ITEMS.md.

Part B — the fixes, by repo

Repo (commit) Row Fix Test / red-proof
felhom.eu ab2b304 + 58ce696 R-885 gate script-tests runs every scripts/**/test_*.py per push (13 → 15 suites, ~20 s); a Python-sqlite3 stand-in when CI has no sqlite3 5 decoys; 2 red-proofs convict
felhom.eu f5a0aeb R-376 marker legend in 08, 09, 11 (all 11 numbered docs now) — (docs)
felhom.eu f5a0aeb R-817 dated clarification under 09 decision 56 — same image, seen before and after a swap (controllerswap.go:236-240, :289) — (docs)
felhom.eu f5a0aeb, controller e563733 R-818 correction notes under hub v0.109.0, controller v0.224.0/v0.225.0 — those findings never had rows — (docs)
catalog 29ac711 R-799 MeTube POST /add sends download_type test + red-proof
catalog 29ac711 R-761 logo name .svg then .png in template comment, REUSE, checklist — (comment)
catalog 29ac711 R-391 CLAUDE.md: no observations section by convention — (docs)
agent d833163 R-291 retention record names its source (R-267 prune, R-287); dead reader dropped reader still reads 10
agent d833163 R-348 restart comment says what a restart blanks — (comment)
controller 114ff27 R-263 „only writer that GRANTS"; AST scan of internal/ + cmd/ 2 red-proofs convict
controller 114ff27 R-368 IsDefault comment names the form as the one that applies it — (comment)
felhom.eu b26d292 R-418 gate list in the docstring = GATES test + red-proof
felhom.eu b26d292 R-345 no :latest in hub/Makefile and in the real release script build-hub.sh (found during the fix; nothing pulls it) test; 2 red-proofs
felhom.eu b26d292 R-416 closed_register_gate RULE 4 — duplicate id in CLOSED-ITEMS decoy + red-proof
felhom.eu b26d292 R-261 CountSelfBindTokens documented as a test accessor — (comment)
felhom.eu b26d292 R-262 hostRestoreTest is a deliberate subset; the test found a third unmodelled agent field, skipped (by design) test; 2 red-proofs
felhom.eu b26d292 R-286 standing rule 3: a control from a DIFFERENT channel (both CLAUDE.md copies) instructions gate
felhom.eu b26d292 R-588 one home for ISO release records; 1.28.0 pointer — (docs)
felhom.eu (final commit) R-423 site_gates fails on a page PAGES does not list; exemption dropped decoy + red-proof

Red-proof records: documentation/audits/burndown-2026-10-05/ (r885-, r263-, r262-, r423-red-proof.txt). The red-proofs of R-418, R-345, R-416 and R-799 were run in the session and each convicted, but their output was not saved to a file — re-run them by mutating as described in each CHANGELOG entry. Suites: hub go test ./... green; controller go build/vet/test ./... green; agent build + vet green; all four repos' gates green at each push.

Fixed without a row (the new rule, used once): the :latest push in build-hub.sh — folded into R-345's fix.

One slip, said plainly: R-885's gate commit (ab2b304) went out WITHOUT closing the row — my closing file had a JSON error. It was closed one commit later (58ce696). „Close in the same commit" was broken once.

Part C — in STATUS.md

45 rows, one line each: what it is, what fixing costs, what happens if never, my pick (close for all 45). Two more — R-831 and R-870, leaked tokens — are listed as actions for the operator (pick: keep until rotated).

Part D — the rule, where it lives, quoted

documentation/backlog/OPEN-ITEMS.md, „How a row is filed":

Fix small, do not file (the size rule — operator brief 2026-10-05, the burn-down). The register grew because every session closed a few rows and filed a few small new ones. So: a finding that is cosmetic or small — fixable in the session in about 30 minutes, in a repo the session may change — is FIXED in that session, with a test where it changes behaviour, and NOT filed. It is recorded in that repo's CHANGELOG.md and in the session report under „fixed without a row". Only a finding that needs a decision, a design, a larger build, or a change the session may not make (a protected machine, a repo out of scope, a release budget already spent) becomes a row. This narrows — it does not repeal — „an enumerated gap becomes a row": a small gap leaves the session fixed, which is a record too.

Every session report states four numbers: rows before, rows after, rows opened, rows closed — counted the way register_shape_gate.py counts (| **R-n** | lines in this file).

Carried, so no instruction contradicts it: .claude/rules/unprompted-work.md §1 and §3.7 (all four identical copies: workspace root, felhom.eu, controller, catalog — commits b018ca9, df85a07, 7a19491) and documentation/PROMPT-TEMPLATE.md §9.2 (the exception) and N.7.3 (four numbers). The morning-note line in the rules file already asked for opened/closed/before/after. No gate was weakened or bypassed.

Teardown

Provisioned nothing. No machine changed: the only reads were the hub pod's asset directory (R-766) and none on any box. Checker agents were read-only. Scratch: the batch files and results in the session scratchpad; the results are copied to the audit folder.