Files
felhom.eu/documentation/tests/golden-0.236.0-2026-09-13/README.md
T
admin ae59c31a84 R-459 CLOSED (MariaDB converts itself, proven by harness + live), golden 0.236.0 (R-467), the golden waiver (R-468)
Operator rulings 2026-09-13, both shipped the same day:
- MariaDB finishes its own conversion (catalog eec1228/bd32830/3525e35). Harness E3/E3b `proven`
  with engine_state_after "already upgraded to 12.3.3-MariaDB [exit=1]", the skip line gone, C3
  still `failed`; landed on demo-hp through the real 15-min cycle, nothing recreated, one deliberate
  restart logged "MariaDB upgrade not required" with the app serving. Evidence:
  documentation/audits/r459-close-2026-09-13/. The engine-major rule + gate keep every engine
  inside its major until Slice 4 (R-448) — removal tracked as R-469.
- Goldens on a cadence, not per release. golden_currency_gate.py reads a dated waiver
  (documentation/tests/golden-waiver.yml, <= 14 days, row-bound): valid + BEHIND -> loud advisory,
  exit 0; expired -> red again naming the date; UNRECORDED (R-385) never covered; malformed -> 2,
  never 0. Tests cases 5-15 incl. the R-421 decoy; red-proof old-vs-new on the real behind tree.
  R-242's vouch half stays open. Cadence in RUNBOOK-manual-build.md §4.2 + the checklist.
- Golden 0.236.0 baked, round-tripped, vouched, floor raised 0.232.0 -> 0.236.0
  (documentation/tests/golden-0.236.0-2026-09-13/) — the last per-release bake; the waiver was
  issued AFTER it landed. No --no-verify anywhere in this session.

Rows: R-459 CLOSED, R-467 CLOSED, R-242 narrowed; R-468/R-469/R-470/R-471 opened. 09 §3 gains
decisions 5 and 6; STATUS items 11 and 12 closed; CONTEXT records the cadence ruling.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-13 10:14:37 +02:00

3.9 KiB

Golden bake 0.236.0 — 2026-09-13

Baked, published, round-trip verified, vouched, and the fleet floor raised 0.232.0 → 0.236.0. This bake carries FOUR releases: 0.233.0, 0.234.0, 0.235.0 and 0.236.0 were never baked (R-467). It is the last per-release bake: from today goldens are on a weekly cadence, and before any drill or fresh install (operator ruling 2026-09-13, R-468 — RUNBOOK-manual-build.md §4.2).

GOLDEN_SHA256 58a3cc24c61dc2271f2cb508ef5a269af97005f386b671f18011258df5f958bf
size 654 115 664 B
baked controller gitea.dooplex.hu/admin/felhom-controller:0.236.0
MinAgent 0.129.0 — the newest header that STATES one is v0.232.0's; v0.233.0…v0.236.0 carry no line (R-470)
script build-golden.sh v3.0.0, sha 7b0fb5cf…73b6a1, compared across the hop (02-template.txt)
template debian-13-standard_13.6-1_amd64.tar.zst, after pveam update
archive volid local:backup/vzdump-lxc-9100-2026_09_13-09_51_44.tar.zst

Acceptance markers — counted on the COMMITTED log (04-markers.txt)

docker OK (overlay2          : 1
including mount point rootfs : 1   (line 316)
including mount point mp0    : 1   (line 317)   <- no mp1 since v3.0.0 (R-165/R-233)
upload OK (HTTP 201)         : 1
--- must be ZERO ---
excluding                    : 0
FATAL                        : 0

Three independent readers agreed before anything was vouched

  1. The bake printed GOLDEN_SHA256=58a3cc24…958bf.
  2. The round trip (07-roundtrip.txt) — the published bytes downloaded back: HTTP 200, 654 115 664 B, sha 58a3cc24…958bf, hashed from the downloaded bytes.
  3. The hub's Day-0 dropdown (08-hub-before-vouch.txt), a different code path reading Gitea: 0.236.0 sha=58a3cc24c61dc2271f2cb508.

The delivered artifact names the controller it will start, read out of the downloaded archive: ./etc/felhom-controller-image → gitea.dooplex.hu/admin/felhom-controller:0.236.0, with 19 382 entries under var/lib/felhom/docker/.

Pre-gates, each proven able to see something first (01-preconditions.txt, 03-bake-launch.txt)

gate result the control that makes it believable
404 pre-gate HTTP 404 for 0.236.0 before the bake the 0.232.0 package returns HTTP 200 on the same URL shape
token-leak grep on the committed log 0 the token appended to a throwaway copy greps 1; the copy was shred -u'd
token off every command line unit properties grep 0 same seeded control returns 1

The vouch — three fields, and only one moved (09-vouch.txt, 11-vouch-verified.txt)

field before after why
golden_version 0.232.0 0.236.0 the new bake
agent_version 0.130.0 0.130.0 unchanged — already ≥ MinAgent
min_agent 0.129.0 0.129.0 unchanged — no header since v0.232.0 declares a change (R-470)

POST /configuration/artifacts → 303 flash=artifacts_set; the page was re-read (golden 0.236.0 selected, sha 58a3cc24…), the R-120 refusal banner absent. Floor POST /configuration/global-floor → 303 flash=floor_set, re-read 0.236.0.

The floor, and why no box moved

Both demo guests were already on 0.236.0 by hand (proven during R-442's live validation the same morning), so the floor raise changes nothing on the fleet today. It clears golden_currency_gate.py and makes a fresh install land on the current release — which the nightly drills need. The chain itself was exercised on 2026-09-01 (golden-0.232.0-2026-09-01/12-selfupdate.txt) and is not re-proven here; nothing about it changed.

Teardown (05-teardown.txt)

pct destroy 9100 --purge, shred -u of the token, runner, script and log after the log was copied out (leftovers in /root: 0), poweroff, qemu confirmed exited with ps -eo comm, and qemu-img snapshot -a virgin. The disk carries the single virgin snapshot.