07-backup-architecture.md: three places said no offsite action unpacks the named-volume tars. R-107 closed in controller v0.218.0; all three corrected with a dated [FACT], the old sentence kept in the past tense. R-102 is NOT closed and the correction says so explicitly. New [DESIGN] paragraph in 6.3: the restore destination is resolved by the same rule as the capture destination, and the wrong-disk refusal applies to apps that have a drive to get wrong. Carries the 13/40 measurement. STATUS.md was internally contradictory - nothing waiting, and one decision waiting, for something the same page recorded as shipped. 218 -> 102 lines; the deciding section now says what happens if nothing is done. R-356 compressed into CLOSED-ITEMS.md; OPEN-ITEMS 327109 -> 325236 bytes. Drill record and 16 evidence files for the live walk on demo-hp.
4.0 KiB
REPORT — R-356 doc corrections, register housekeeping, and one gate fix (2026-08-22)
Companion to felhom-controller v0.219.0 (R-356). This repo carried the architecture correction, the
drill record, the register move and one genuine gate defect found on the way.
1. documentation/architecture/07-backup-architecture.md — R-107 was closed and the doc said otherwise
Three places, each corrected with a dated [FACT] citing offbox_reconstitute.go volReplay and
controller v0.218.0:
- §6.3, the Tier-3 row — was "no offsite action unpacks the named-volume tars it captures".
- §8, matrix row 4 — was "the volume tars in either copy are unreachable".
- The R-107 index row.
The old sentence's history is kept, not deleted: each correction says what was true, until when, and what closed it. A correction that erases what was believed leaves the next reader no way to tell a fixed gap from one that was never noticed.
R-102 — the Tier-2 half — is NOT closed, and the correction says so explicitly so it cannot be read as covering both. The Tier-2 row stands exactly as written.
2. §6.3 — the R-356 reasoning recorded as reasoning, not as a closed row
A new [DESIGN] paragraph: the restore destination is resolved by the same rule as the capture
destination (drive if the app has one, system data path otherwise); the refusal that protects a drive
app from being restored onto the wrong disk applies to apps that have a drive to get wrong. It
carries the 13/40 measurement and points at felhom-controller/CONTEXT.md.
3. STATUS.md — the contradiction is gone, and the page is one screen
It said nothing was waiting while also saying one decision was waiting — to publish agent 0.130.0 — which the same page recorded as already published (R-347, closed). 218 → 102 lines.
"Waiting on you" now lists four real items, and — per the exemption — each says what happens if the operator does nothing. The two new ones are this release's hand-off: vouch a golden carrying controller 0.219.0, then raise the floor last, in a separate save.
4. documentation/audits/DRILL-r356-hot-only-restore-2026-08-22/
The live walk on demo-hp: both classes, both messages verbatim with their byte counts, both accented
filenames as explicit hex, and 16 evidence files. Copied off at the end of each phase. Nothing was
reverted during this drill, so no intermediate teardown could have taken it.
5. Register housekeeping (N.7)
R-356 compressed out of OPEN-ITEMS.md into CLOSED-ITEMS.md, keeping its title, shipping version,
evidence path and every sentence stating a rule, plus the pointer
git show e18668f9e19f:documentation/backlog/OPEN-ITEMS.md for the full original text.
| file | before | after |
|---|---|---|
OPEN-ITEMS.md |
327 109 bytes | 325 236 bytes |
CLOSED-ITEMS.md |
61 580 bytes | 63 507 bytes |
6. A real gate defect, found by CI going red
CI run 387 (job 386) failed instructions_gate on commit 08eb1a6 while run 73 on its parent had
passed. The cause was not the push: ef6ac6f (this repo, the same day) compressed closed rows out of
OPEN-ITEMS.md into CLOSED-ITEMS.md, and register_state() read only OPEN-ITEMS.md and
ROADMAP.md. Every citation of a compressed item became "a reference to nothing", failing the
next push in a sibling repo for a rule file nobody had touched — and it would have fired again on this
task's own R-356 compression.
CLOSED-ITEMS.md is now the third source. It answers does this ID exist and answers closed for
the rows it owns; OPEN-ITEMS.md remains the sole authority on openness, so a row it claims as
open is not overridden. Both controls still convict: an ID present nowhere fails, and a citation
claiming a closed item is still open fails — each watched failing, then watched clearing.
Gate state
python3 scripts/repo_gates.py --fast — all green except golden-currency, which is correct and
is operator item 1: controller 0.219.0 is released and no golden carries it.