Files
felhom.eu/documentation/audits/update-night-2026-09-21/phase2_redo.log
T
admin 9c69b3ff07
gates / gates (push) Successful in 27s
Update night: Phases 2-4 evidence — both engines, the unattended HOLD, and five new findings
Evidence off the machine at the end of the phases that produced it (R-320). Teardown follows.

PHASE 2 — the two database engines, through the REAL Update button:
- MariaDB 11.6 -> 12.3 on nextcloud: PROVEN, and pressed through the button for the first time.
  All four SPIKE-r459 observables: the datadir's own record moved 11.6.2 -> 12.3.3; the engine
  itself says "already upgraded ... no need to run mariadb-upgrade again"; the entrypoint says
  "Major version upgrade detected ... Check required!" and then STARTED and FINISHED it (not the
  `skipped due to $MARIADB_AUTO_UPGRADE` line R-459 feared); and the engine took its own
  pre-upgrade backup, 631 905 B. The seeded Nextcloud account read back.
- PostgreSQL 16 -> 17 on docmost: FAILED exactly as R-463 predicted and nobody had measured.
  5.1 s to held; the pin named 17 while nothing ran; the restore brought it back in 29.1 s.
  The engine's REFUSAL LINE was destroyed by failAndHold before any probe could read it, so it
  was REPRODUCED INDEPENDENTLY with a control on every step (R-320).

PHASE 3 — the bad days. B1 produced THE UNATTENDED HOLD, which this project has never had: the
caller pressed once with nobody watching, the app held after 312.9 s, and passes 2 and 3 pressed
nothing. B2 put the pin back on a pull failure in 1.0 s. B3 refused `busy` six times. B4 showed
there is NO single-flight — 5 of 5 updates ran at once and all ended honest. B5 cut the power in
`backing-up` and the box recovered itself and said so. B7 refused under the 2 GB floor. B9 found
R-458's risk narrower than the row states.

PHASE 4 — every badge on the box is TRUE, and the held app answers all four of Q4's questions.

FINDINGS, five new and three corrections to existing rows. The one that matters: R-618 is P1 —
two templates name a health probe the app does not answer, and because the guarded update waits
on that same probe, a SUCCESSFUL update ends by STOPPING a working app. Measured: tandoor served
HTTP 200 on the new version at four samples across five minutes and was then stopped.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-21 22:13:57 +02:00

63 lines
4.0 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
############################################## 22:09:32 R1 redeploy docmost fresh on postgres:16-alpine, and seed it
22:10:51 [sync] the badge NEVER caught up to postgres:16-alpine in 78.4s — catalog_images = None
22:10:51 [1] deploy -> 202 {'ok': True, 'message': 'Telepítés elindítva – az állapot a kártyán követhető'}
22:11:26 [1] deployed, controller state=running, pinned={'docmost': 'docmost/docmost:0.96.0', 'docmost-postgres': 'postgres:16-alpine', 'docmost-redis': 'redis:7-alpine'}
22:11:26 docmost: /api/auth/setup http=200 rc=0
22:11:26 seeded: True
22:11:27 docmost: login as the seeded user http=200 ok=True
22:11:27 C1 readback: True
############################################## 22:11:27 R2 reproduce the PostgreSQL refusal INDEPENDENTLY, with a control on every step
=== 0. find the live docmost 16 datadir, and PROVE it is 16 before touching anything
mounts of docmost-postgres:
volume docmost_docmost_postgres_data /var/lib/docker/volumes/docmost_docmost_postgres_data/_data /var/lib/postgresql/data
volume: docmost_docmost_postgres_data
PG_VERSION of the SOURCE: '16'
=== 1. copy it, and PROVE the copy is 16 too
copied
PG_VERSION of the COPY: '16'
size of the copy: 49.0M
=== 2. THE MEASUREMENT: postgres:17-alpine on that 16 datadir — the household's exact case
container: running=false exit=1 restarts=0
--- POSTGRESQL 17's OWN WORDS, VERBATIM:
PostgreSQL Database directory appears to contain a database; Skipping initialization
2026-09-21 22:11:32.601 CEST [1] FATAL: database files are incompatible with server
2026-09-21 22:11:32.601 CEST [1] DETAIL: The data directory was initialized by PostgreSQL version 16, which is not compatible with this version 17.11.
--- the copy's PG_VERSION AFTER 17 refused it (must still be 16 — nothing was migrated):
16
=== 3. POSITIVE CONTROL: the same copy under postgres:16-alpine must start AND hold the data
container: running=true exit=0
2026-09-21 22:11:43.497 CEST [33] LOG: checkpoint starting: end-of-recovery immediate wait
2026-09-21 22:11:43.583 CEST [33] LOG: checkpoint complete: wrote 600 buffers (3.7%); 0 WAL file(s) added, 0 removed, 0 recycled; write=0.014 s, sync=0.061 s, total=0.089 s; sync files=409, longest=0.025 s, average=0.001 s; distance=2838 kB, estimate=2838 kB; lsn=0/1BEB798, redo lsn=0/1BEB798
2026-09-21 22:11:43.592 CEST [1] LOG: database system is ready to accept connections
--- the DATA, asked of the engine itself:
tables in the public schema: 48
=== 4. teardown, BY NAME
removed: DRILL-pg17-refuse, DRILL-pg16-ok, volume DRILL-pg16-copy
############################################## 22:11:45 R3 Phase 2.3 — the conversion rehearsal, costed
22:11:46 ==== Phase 2.3: the PostgreSQL 16 -> 17 conversion rehearsal (Q5)
22:11:46 docmost: /api/auth/setup http=403 rc=0
22:11:46 docmost: setup refused: {"message":"Workspace setup already completed.","error":"Forbidden","statusCode":403}
############################################## 22:11:46 R4 B8 — the floating pin, on docmost's postgres
22:11:46 ==== B8: the floating pin docmost-postgres on docmost
22:11:46 installed docmost-postgres = postgres:16-alpine digest=sha256:721873c34ceb9f8d8fc265984940dc982404c105f19ad51be9fdc5970a6080ea
22:11:46 catalog docmost-postgres = None
22:11:46 badge HU []
22:11:46 badge EN []
22:11:48 docker says: postgres:16-alpine sha256:81bd698b4594e751a3269e4dcd3e03a4a0ec0daf7b72e7aa1abd43cce9887542 | postgres@sha256:721873c34ceb9f8d8fc265984940dc982404c105f19ad51be9fdc5970a6080ea
22:11:48 upstream digest for postgres:16-alpine (measured from DooPlex, never from the box) = sha256:721873c34ceb9f8d8fc265984940dc982404c105f19ad51be9fdc5970a6080ea
22:11:48 press Update anyway: http=202 reason=None ::
22:11:48 [6] Update -> 409 {'ok': False, 'data': {'reason': 'updating'}, 'error': 'A(z) docmost frissítése már folyamatban van.'}
22:11:51 installed docmost-postgres AFTER = {'ref': 'postgres:16-alpine', 'digest': 'sha256:721873c34ceb9f8d8fc265984940dc982404c105f19ad51be9fdc5970a6080ea', 'at': '2026-09-21T20:11:02Z'}
22:11:51 phase2_redo done