Files
felhom.eu/documentation/audits/more-night-apps-2026-09-30/tools/q4.sh
T
admin 42bf40bd2c
gates / gates (push) Successful in 29s
More apps update themselves at night (30+2 -> 35+3); the same-name security-fix gap measured (R-740, decision for the operator)
- Twelve steps published on both venues (catalog): first ladders for calibre-web, gitea, wger,
  crafty-controller, uptime-kuma, zipline (two steps); within-major emby, ghost, home-assistant,
  outline, rallly. immich's step v3.0.3 -> v3.2.2 re-proven at 768M (Part D).
- Part C: the night leg skips a digest-only change AND the catalog never records a same-tag re-test,
  so a same-name upstream fix reaches no box. Row R-740; the decision in STATUS; `09` decision 30
  carries a dated note (the decision itself unchanged).
- Rows: 369 -> 377. Opened R-735..R-742; closed R-735, R-738, R-742; narrowed R-462, R-624, R-446,
  R-440, R-734, R-732. The currency audit gains §1b (and corrects its 31+1 to 30+2).

Evidence: documentation/audits/more-night-apps-2026-09-30/. Report: REPORT-more-night-apps-2026-09-30.md.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-30 20:27:28 +02:00

49 lines
3.2 KiB
Bash
Executable File

#!/bin/bash
# q4.sh — after q3 ends: sync the bench to the committed harness, then outline, rallly (benchq), Part D
# (partd.py, immich step 0b82 at 768M), zipline (benchq), and calibre-web again with --soak 0 ONLY to name
# the files behind its files_may_change mark (not a ladder verdict). Evidence off the bench after each.
EV=/mnt/5_hdd/felhom.eu/git/felhom.eu/documentation/audits/more-night-apps-2026-09-30
SC=/tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/2930eec5-3257-446d-80bf-8921da206cd8/scratchpad
Q=$EV/bench/benchq-q4.txt
until grep -q "QUEUE q3 FINISHED" $EV/bench/benchq-q3.txt; do sleep 20; done
$EV/tools/benchsync.sh >> $Q 2>&1
cd $EV/tools
python3 benchq.py q4 outline outline=outlinewiki/outline:1.10.1 rallly rallly=lukevella/rallly:4.15.3
# --- Part D
tar czf $SC/pd.tgz -C $EV/D template-immich@0b82-768 -C $EV/tools partd.py
scp -q -o BatchMode=yes $SC/pd.tgz demo-hp:/tmp/pd.tgz
ssh -o BatchMode=yes demo-hp "pct push 9401 /tmp/pd.tgz /tmp/pd.tgz; rm -f /tmp/pd.tgz"
echo "$(date +%T) START partD (immich step 0b82 at 768M)" >> $Q
$SC/bench.sh > $EV/D/D3-bench-run.txt 2>&1 <<'B'
set -e
cd /opt/upg && mkdir -p /tmp/pdx && tar xzf /tmp/pd.tgz -C /tmp/pdx && rm -rf 'templates/immich@0b82-768' \
&& mv '/tmp/pdx/template-immich@0b82-768' 'templates/immich@0b82-768' && mv /tmp/pdx/partd.py /opt/upg/partd.py && rm -rf /tmp/pdx /tmp/pd.tgz
grep -n "memory:" 'templates/immich@0b82-768/docker-compose.yml'; swapon --show; echo "swap lines above (none = no swap)"
[ -d evidence/D-immich-0b82-768 ] && mv evidence/D-immich-0b82-768 evidence/D-immich-0b82-768-$(date +%s)
timeout 3000 python3 partd.py > /opt/upg/D-immich.log 2>&1; echo rc=$?
B
$SC/bench.sh <<'B' | base64 -d | tar xzf - -C $EV/D
cd /opt/upg && tar czf - D-immich.log evidence/D-immich-0b82-768 | base64 -w0
B
python3 - >> $Q <<'P'
import json
v=json.load(open("/mnt/5_hdd/felhom.eu/git/felhom.eu/documentation/audits/more-night-apps-2026-09-30/D/evidence/D-immich-0b82-768/verdict.json"))
m=v.get("memory") or {}
print("DONE partD verdict=%s read_before=%s read_after=%s abort=%s marks=%s containers=%s" % (v.get("verdict"), v.get("seed_read_before"), v.get("seed_read_after"), v.get("abort"), v.get("marks"),
{n:(c.get("anon_peak_pct"), c.get("oom_kill")) for n,c in (m.get("containers") or {}).items()}))
P
# --- zipline
python3 benchq.py q4 zipline zipline=ghcr.io/diced/zipline:4.8.0
# --- calibre-web names (soak 0) — a separate evidence folder, never a ladder input
echo "$(date +%T) START calibre-web names re-run (--soak 0)" >> $Q
$SC/bench.sh > $EV/A/calibre-names-run.txt 2>&1 <<'B'
cd /opt/upg && [ -d evidence/MV-calibre-web ] && mv evidence/MV-calibre-web evidence/MV-calibre-web-$(date +%s)
timeout 2000 python3 upgrade-test.py --soak 0 --move calibre-web calibre-web=crocodilestick/calibre-web-automated:v4.0.8 > /opt/upg/MV-calibre-names.log 2>&1; echo rc=$?
B
mkdir -p $EV/A/calibre-names
$SC/bench.sh <<'B' | base64 -d | tar xzf - -C $EV/A/calibre-names
cd /opt/upg && tar czf - MV-calibre-names.log evidence/MV-calibre-web | base64 -w0
B
python3 -c "import json;v=json.load(open('$EV/A/calibre-names/evidence/MV-calibre-web/verdict.json'));print('DONE calibre-names verdict',v.get('verdict'),'files_changed_detail',v.get('files_changed_detail'))" >> $Q
echo "$(date +%T) QUEUE q4 FINISHED" >> $Q