Files
felhom.eu/documentation/audits/immich-first-start-2026-09-30/tools/boxmove.py
T
admin 2866f6a318
gates / gates (push) Successful in 27s
immich's first start: cause measured, fixed in the catalog (R-732 closed); ISO clean-tree gate (R-730 closed)
- R-732: the first-start geodata import runs up to 9 concurrent 5000-row INSERTs; the database needs
  ~400 MB anon + ~170 MB touched shared_buffers (the image's FIXED 512MB, not host-RAM sizing). 512M fits
  only with swap (bench swap 0: 61-104 kills; 9202 swap 512 MiB: survived by swapping). Controls: swap
  alone, limit alone flip it; shared_buffers 128MB alone does not. Catalog 56c4888: v3.2.4 + 768M,
  proven with swap off on both venues. audits/immich-first-start-2026-09-30/A-cause.md.
- R-730: scripts/iso/build-felhom-iso.sh refuses an uncommitted/untracked/unpushed tree (no bypass),
  records repo-commit from the gate and iso-v<version>; test iso/test/clean-tree.sh, red-proof run
  (status check removed -> 2 of 4 cases fail -> restored).
- R-731 narrowed (gitea 28.0.0 GA; mariadb 13.0 a short-term Rolling line). R-676 note.
- New rows R-733 (bench has no swap, boxes 512 MiB), R-734 (immich .immich markers -> files_may_change).
- STATUS: the golden line corrected (no bake is due; 0.283.1 is the newest release). Register 364 -> 366.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-30 16:18:17 +02:00

59 lines
3.9 KiB
Python

"""boxmove.py <phase> <app> <sub> [<svc> <from> <to> <fmj> <tmj>] — Part B's BOX venue on 9202 (drill catalog):
prep: deploy (reuse if installed), seed through the app's own route, read it back (C1)
move: drill commit with the mark → sync → the guarded Update → engine state + seed read back → box verdict JSON
Evidence: B/apps/<app>/box/."""
import json, os, sys, time, subprocess
import walk as w
sys.path.insert(0, '/mnt/5_hdd/felhom.eu/git/app-catalog-felhom.eu/scripts')
import upgrade_fixtures_box as fixtures, upgrade_fixtures_box28 as _f28
FX = dict(_f28.FIXTURES28); FX.update(fixtures.FIXTURES) # the box set wins, as upgrade_boxport.get() decides
phase, app, sub = sys.argv[1:4]
EVD = f"{w.EV}/box/{app}"; os.makedirs(EVD, exist_ok=True)
TOK = w.SC + "/seed-tokens-box.json"
log = open(f"{EVD}/{phase}.txt", "a", buffering=1)
def say(*a):
w.say(*a); log.write(" ".join(map(str, a)) + "\n")
w.login()
toks = json.load(open(TOK)) if os.path.exists(TOK) else {}
if phase == "prep":
say(f"deploy/reuse {app}: {w.deploy(app, sub)}")
toks[app] = FX[app].seed(w, sub, say)
if isinstance(toks[app], dict) and w.GENERATED.get(app):
# the deploy secrets THIS run generated (grafana's admin password): kept beside the seed, in the 0600 scratch
# file only, so a LATER process (boxstep/undocase) can read the app back. Found 2026-09-30: grafana's box step
# read back with the default password and got 401 — the instrument, not the product.
toks[app]["__generated"] = w.GENERATED[app]
json.dump(toks, open(TOK, "w"), default=str); os.chmod(TOK, 0o600)
say(f"C1 seed reads back BEFORE: {FX[app].verify(w, sub, toks[app], say)}")
else:
svc, frm, to, fmj, tmj = sys.argv[4:9]
st = w.stack(app); before = (st.get("app_config") or {}).get("pinned_images")
pg = lambda: w.guest(f"docker exec {svc} sh -c 'cat $PGDATA/PG_VERSION' 2>&1").strip()
say(f"before: pinned={before} PG_VERSION={pg()}")
if os.environ.get("SKIPDRILL"):
say("drill: SKIPPED — the drill commit was made by an earlier attempt")
else:
r = subprocess.run([sys.executable, os.path.join(os.path.dirname(__file__), "drillmove.py"), app, svc, frm, to, fmj, tmj], capture_output=True, text=True)
say("drill:", r.stdout.strip().splitlines()[0] if r.stdout else r.stderr[-300:])
w.sync_rescan(app, to)
since = w.guest("date -u +%Y-%m-%dT%H:%M:%SZ").strip()
res = w.press_update(app, poll=1, cap_s=1800)
for p in res.get("phases", []):
log.write(f" phase +{p['t']}s {p['phase']} | err={p['error']}\n")
time.sleep(10)
after_pg = pg(); read = FX[app].verify(w, sub, toks[app], say)
conv = w.guest(f"docker logs --since {since} felhom-controller 2>&1 | grep -E 'update {app}|CONVERT' | grep -v DEBUG | cut -c1-400")
log.write(conv + "\n")
line = next((l for l in conv.splitlines() if "CONVERTED" in l), "")
st = w.stack(app)
verdict = {"app": app, "venue": "box 9202 (drill catalog, controller 0.283.1), the product's guarded Update",
"from": before, "to": (st.get("app_config") or {}).get("pinned_images"),
"verdict": "proven" if (res.get("final_phase") == "done" and read and after_pg == str(tmj)) else "failed",
"seed_read_before": True, "seed_read_after": read, "healthy_after": st.get("state") == "running",
"engine_conversion": {"service": svc, "engine": "postgres", "from": int(fmj), "to": int(tmj),
"result": "converted" if line else "not-seen", "controller_line": line.split("] ", 2)[-1] if line else ""},
"duration_s": res.get("duration_s"), "measured_at": since,
"evidence": f"felhom.eu/documentation/audits/immich-first-start-2026-09-30/box/{app}/move.txt"}
json.dump(verdict, open(f"{EVD}/box-verdict-{app}.json", "w"), indent=2)
say(f"RESULT final_phase={res.get('final_phase')} PG_VERSION={after_pg} seed_after={read} verdict={verdict['verdict']}")