Files
felhom.eu/documentation/audits/update-arc-gaps-2026-09-21/05b-scenarioB-coordinator-capture.txt
T
admin c85262111c
gates / gates (push) Successful in 23s
The update arc's two missing measurements, the lock, and the floor to 0.260.0
Part 0 — floor raised to 0.260.0, MinAgent 0.131.0 declared. 3 boxes below, all
down or blocked; both demo boxes SERVED.

Part 1 (R-610) — the DANGEROUS power cut, measured three times with three apps and
two cut mechanisms. All ended honest: resumed, completed, and pinned/installed/live
compose/docker inspect all agreed. vikunja's 2.6.0 migration had ALREADY run 0.64 s
after the cut decision and the seeded data read back intact — so the branch that is
one step from old-binary-on-migrated-database is now evidence, not argument.
Instrument limit stated: `starting` lasts under a second; all three landed in
`verifying`, which RecoverUpdates handles in the same branch.

Part 3 (R-611) — the night the previous session skipped without saying so. An app
updated with nobody pressing anything; a terminally-refused app was pressed exactly
once and never again over three passes. The unattended HOLD was NOT produced: the
within-a-major rule correctly refused the broken edge before it was attempted, so
Q4 still rests on the attended hold from slice 4. Said plainly rather than implied.

Rows: closed R-608/609/610/611; opened R-612 (P1 wishlist unusable on a fresh
install, and its error is a lie), R-613 (uptime-kuma healthy on its setup wizard),
R-614 (stale update phase survives a redeploy). R-520's pointer corrected.

Catalog: two drill pairs, both reverted; every image line byte-identical to
ff9717d3. The alpine:3.20 negative control a security review flagged is cleared.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-21 15:00:09 +02:00

36 lines
2.3 KiB
Plaintext

# 05b — SCENARIO B (cut in `verifying`, uptime-kuma) — COORDINATOR capture
#
# PROVENANCE: written by the main session, read-only, live from guest 9202, after the measuring
# agent again went a long interval without writing evidence while the box already showed the
# scenario complete. If the agent's own `05-*` file lands it is the fuller record; this exists so
# the measurement could not be lost (R-320). Nothing below is inferred.
== THE RECOVERY, verbatim from the controller log ==
2026/09/21 12:33:21 update.go:909: [WARN] [stacks] update recovery: uptime-kuma was interrupted in verifying (started 2026-09-21T12:32:26Z) — the new version may have run; marking it Updating and RESUMING the health wait
2026/09/21 12:33:21 update.go:951: [INFO] [stacks] update uptime-kuma: resuming after a controller restart — `up -d` then the health wait
2026/09/21 12:33:21 update.go:858: [INFO] [stacks] update uptime-kuma: phase verifying
2026/09/21 12:33:26 update.go:652: [INFO] [stacks] update uptime-kuma: healthy after 5s (the app's health check passed)
2026/09/21 12:33:26 update.go:658: [INFO] [stacks] update uptime-kuma: DONE in 1m0s
== THE FOUR VERSION OBSERVABLES, SIDE BY SIDE ==
pinned_images : {"uptime-kuma": "louislam/uptime-kuma:2.5.0"}
installed_images : {"uptime-kuma": "louislam/uptime-kuma:2.5.0"}
live compose line: image: louislam/uptime-kuma:2.5.0
docker inspect : louislam/uptime-kuma:2.5.0 | running
-> ALL FOUR AGREE. (catalog_images also 2.5.0 — the drill bump was still in place.)
== END STATE ==
state=running updating=False update_phase=done label='Frissitve'
update_error=(none) hold_reason=(none) health_probe.healthy=True
Total time from interruption to done: 1m0s.
== NOT CAPTURED HERE ==
the timestamp table (phase at decision, cut latency), the seeded-monitor read-back through
uptime-kuma's own front door, and the page sentence in both languages. Those need the agent's
poller output and its seeded session. Recorded as GAPS, not as passes.
== VERDICT ON WHAT IS MEASURED ==
The `verifying` cut ends HONEST for a second app, with a different health-check shape (5s rather
than 0s to pass). Resumed, completed, all four observables agree, no hold, no stuck `Updating`.
None of the brief's STOP conditions appeared in what was captured.