Files
felhom.eu/REPORT-backlog-triage-2026-10-03.md
T

78 lines
7.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# REPORT — backlog triage, 2026-10-03
Paperwork session. **No machine touched. No release. No golden.** Other repos read only.
Baseline: felhom.eu `main` `9305288` (verified). Commits: A `9e2786c` · B `71b8c8c` · C `9f77865` · D `33bbf8e` ·
E (this commit).
## The Part table
| Part | Done? | Changed from the brief, and why |
|---|---|---|
| **A** — four roadmap items | **Done.** R-808 (box OS security updates), R-809 (legal + business papers), R-810 (independence, spike), R-811 (second login step). Findings filed beside two: **R-812** (no box receives OS security updates), **R-813** (website: no privacy notice, terms or imprint). `00` gained three §E/§G gap rows and a new §H "Business & legal". CONTEXT records the request first. | R-810 and R-811 got no register finding: nothing about them is false today (one password is a stated limitation, `00` §E). |
| **B** — finished rows out + gate | **Done.** 125 rows with an id and 20 without moved to `CLOSED-ITEMS.md` (one dated section, each naming `git show 9e2786c:…`). Open rows normalised to one shape. Narratives (campaign write-ups, rulings, old ranking paragraphs) moved word for word to `documentation/archive/OPEN-ITEMS-narratives-2026-10-03.md`. `closed_register_gate.py` **RULE 3**. Workflow text in `PROMPT-TEMPLATE.md` §N.7/§N.5 and `CLAUDE.md`. Loose notes: verdict per file in `backlog/README.md`. | 14 rows with an OPEN verdict were found finished and moved — each checked by me against live source (list below). 11 rows with a finished verdict **stayed open**, narrowed, because they name work no other row carries (R-451, R-579, R-610, R-618, R-621, R-635, R-691, R-707, R-719, R-723, R-738). Two loose notes stay in place (other repos link to their path). There is no "Deliverables" line in the template; §N.5's "report which rows" line gained "closed (and moved), narrowed". |
| **C** — category + severity | **Done.** Columns `| ID | Category | Sev | What | State | Blocked on | Next action | Owner |`; one section per category, severity order inside. `register_shape_gate.py` RULES 5–8. Duplicates folded: R-248 → R-246, R-580 → R-132. | A **column**, not a title tag: the gates read cells by the header's column NAME (new helper `register_table.py`), which a tag in prose cannot give reliably. Not folded (judged not duplicates): R-287/R-291, R-450/R-469, R-123/R-369 (R-123 closed anyway). Operator-owned rows: listed in `RECOMMENDATION.md`, with one line and the count in STATUS — STATUS is one screen and holds no ids. |
| **D** — clean ROADMAP | **Done.** 161 → 124 lines, 81 → 42 KB. Intentions re-sorted P2/P3/P4, each names its `00` row. 33 items + the pre-invite checklist → `ROADMAP-HISTORY.md`. UPDATE-ARC collapsed. Pre-invite list → pointer to STATUS. | R-48 was SHIPPED (controller v0.154.0) though the roadmap still listed it as an idea. Fixing `one_register_gate.py` to read suffix ids found R-50b — a finding that lived only in the roadmap; moved to the register. |
| **E** — ranking + recommendation | **Done.** `documentation/audits/backlog-triage-2026-10-03/RECOMMENDATION.md` and one decision in STATUS. | The top list is 29 rows: every P2. No P1 exists, so severity alone fills the 20–30. |
## Headline numbers
- `OPEN-ITEMS.md`: **442 rows with an id + 22 without, 824 KB, 932 lines → 326 rows, all with an id, ≈540 KB.**
- Moved to `CLOSED-ITEMS.md`: **125 + 20**. Marked VERIFY: **11**. New rows: **11** (R-812..R-819, R-50b moved in).
- Category × severity (P2/P3/P4; **no P1**): Install 2/11/5 · Apps 0/15/21 · App updates 0/12/7 · Backup 12/24/20 ·
Storage 0/7/5 · Security 3/23/3 · Box system 3/11/3 · Monitoring 2/16/6 · Hub 1/7/13 · Business 4/0/3 ·
Process 0/4/83 — totals **27 / 130 / 169**.
## Claims in the brief that turned out wrong
1. **The row counts.** Measured at `9305288` with a split that skips pipes inside backticks: **442** id rows (not
444) plus **22 rows with no id** the count missed. By leading verdict: **113** finished (107 CLOSED + SHIPPED 2,
FIXED 1, RULED 1, EXECUTED 1, ANSWERED 1), plus 4 DECIDED and 1 "✅ CLOSED" — 118 for the new gate; **195**
READY (not ~129); OPEN 74 + NARROWED 10; WAITING-ON-OPERATOR 15; WATCHING 15. **"~125 unreadable" was wrong:**
in those six-column tables the state is the THIRD column — the script read the last one, which is the owner. Only
**18** rows needed a person: 5 because of a pipe in prose, 13 because their state word was undefined.
2. **"Nothing updates the host or guest OS" — TRUE for boxes**, with two nuances: the installer points the host at
the no-subscription repository "so the box can pull security updates" and then says "No upgrades are run"; the
guest's Docker engine is current only on the day the golden is baked. The one `apt full-upgrade` in the project is
a by-hand step for the off-site endpoint ep0.
3. **"The website has no legal pages" — TRUE.** Worse than stated: the contact form asks for data-processing
consent and links to no notice.
4. **"No document answers the independence question" — PARTLY WRONG.** The LOST-hub half is answered
(`architecture/_recovery-inventory-2026-07-28.md` §D2.4; `07` §8 row 11b), and `01` §7 rules that the customer
owns the domain. Leaving, export and hand-over are answered nowhere — R-810 keeps those.
5. **"No gate refuses a closed row in OPEN-ITEMS" — TRUE.** One more gate had the same blind spot in another shape:
`instructions_gate.py` read the state by position and would have misread the new layout; fixed.
## Rows found finished and moved (verified by me, evidence in each CLOSED entry)
R-123, R-131, R-202, R-229, R-272, R-295, R-343, R-369, R-398, R-500, R-506, R-572, R-590, R-800.
## Gates — new rules and decoys, each seen red
- `closed_register_gate.py` RULE 3 — red on the real register before the move (118 convicted). Decoy
`finished-row-in-open` **passed the old gate**; convicts now. Genuine article (READY, prose says "closed") passes.
- `register_shape_gate.py` RULES 5–8 — five decoys (old-shape row, near-miss category, `P3-LOW` as Sev, undefined
state word, pipe outside backticks): **all five passed the old gate**; all convict now.
- `one_register_gate.py` — suffix ids and backtick-aware split; decoy `suffix-id-row` **passed the old gate**.
- Suite: `test_gate_decoys.py` 29/29; `test_instructions_gate.py` 73/73; `repo_gates.py --fast` OK at every commit.
## Rules carried out of closed rows
21 sentences that stated a rule and had no other home → `CONTEXT.md` ("Rules carried out of rows closed
2026-10-03"); the three decisions among them (R-245, R-303, R-312) → `07` §11 as `[DESIGN]`.
## Observations
1. `scripts/check_stands.py` is red and runs in no runner (2 dangling ids before today, 3 more after rows closed).
FILED: R-819.
2. `09` decision 56 and R-745 disagree about the controller self-update's roll-back target. FILED: R-817.
3. Two changelogs cite R-330/R-331 for other findings. FILED: R-818.
4. F-DIAG's six off-site failure messages have never been seen on a real failure. FILED: R-816.
5. Two July watch rows had no id and no recorded outcome (a Storage Box deletion; the first GC on the off-site
datastore). FILED: R-814, R-815.
6. One stray duplicate owner word ("operator") in R-209a's broken extra cell was dropped in normalising; every other
word of every open row is kept (checked by a token diff). NOT-A-FINDING: a duplicated cell, not content.
## Teardown
Provisioned nothing.