=== 2026-07-27 close-out sweep: content that existed ONLY in the session transcript ===
repo HEAD: 93ce463689d6aff6b1a8d02734a29ba3040ed9e8 branch: main
Precedent: docs/audit/queued-findings-20260726.txt. Operator asked for a durability sweep
before clearing the session. NOTHING here is ruled or built; each item names its status.
--- PART A: FIXED BY THIS SWEEP (were transcript-only, now on a surface) ---
A1. dc-mirror.sh's dc1 site row carried NO warning that dc1 is no longer a mirror site.
THE MOST CONSEQUENTIAL MISS OF THE SWEEP: `dc-mirror.sh install dc1` would have
silently rebuilt everything the 2026-07-27 teardown removed -- units, nginx vhost,
sync helper, AND an ENABLED daily debmirror timer that would start a fresh ~950G pull
on a rack whose ruled artifact path is the proxy. Someone treating a failing
`check dc1` as a regression would reach for exactly that command. FIXED: the row now
states dc1 is proxy-only by the D-135 amendment, that `check dc1` FAILS BY DESIGN,
and that `install dc1` is a deliberate strategy change, never a repair. The row is
RETAINED so the measured values survive for a legitimate rebuild.
QUEUED (not built, hard rule 1): a RUNTIME guard in do_install for a site whose ruled
path is not the mirror -- today's own lesson is that prose-only prevention does not
fire (DoD item 8 existed and missed dc1; D-137's wiring sat as prose and missed BOTH
DC standups). A comment is strictly weaker than a guard and is an interim.
A2. docs/audit/stage4-mirror-gate-20260727.txt carried a WRONG causal claim -- that
`systemctl reset-failed` would re-arm the paused dc1 debmirror. Measured afterwards:
reset-failed on the SERVICE cannot start an INACTIVE TIMER. The real vector was a
REBOOT (enabled -> timer starts at boot; Persistent=yes -> fires immediately because
the window had passed). CORRECTION APPENDED to that capture rather than edited in
place -- it is dated evidence, so a wrong claim is superseded openly.
A3. The generalisable lesson behind A2 was unrecorded. Now platform-traps section 5:
'stopped is not dormant across a reboot' (5a) plus 'a oneshot with RemainAfterExit=yes
does not undo its work on stop, so stopping it proves NOTHING about dependents' (5b),
with three new rows in the verbatim-error index. 5b is the reason the dc1 teardown was
safe: the independence test deleted the live addr/route instead of stopping the unit.
STILL LIVE: dc0-mirror-sync.timer is enabled with Persistent=yes, so the 5a shape
applies to dc0 today -- benign while its syncs succeed, but it is the same shape.
A4. dc-cache-proxy.sh stated coexistence of the two net units on one host as FACT.
It is REASONED, not MEASURED (hard rule 2): the proxy has only ever been installed on
dc1, and the mirror net unit was removed there, so nobody has run both on one host.
The header now says so and tells a future session to verify rather than trust the
sentence if dc0 is ever given the proxy.
--- PART B: MEASURED THIS SESSION, recorded here because they had no other home ---
B1. The region MAAS snap's ssh config contains exactly ONE Host block (dc1's transit
172.31.0.6 -> id_dc1_power, IdentitiesOnly yes). dc0 has NO block, so dc0 power ops
use the snap's DEFAULT identity id_ed25519. This MATCHES SEC-016's stated design
('172.31.0.2/dc0 keeps SEC-012'), so it is confirmation, not drift -- but it is the
measured basis for SEC-016's snap-refresh fragility note: a refresh that wipes
/var/snap/maas/current/root/.ssh/ takes dc1's Host block with it, and dc0 would keep
working on the default identity while dc1 silently lost power control. Asymmetric
failure, so verify BOTH DCs after any snap refresh, not just one.
B2. MAAS fabric-3 holds 192.168.122.0/24 -- the libvirt DEFAULT network, discovered by
MAAS. Load-bearing for nothing in VR1 and outside the flagged carve residue, so it
was deliberately KEPT. Noted as a possible future cleanup, NOT proposed: it is a
MAAS-discovered fact about the host, and removing discovered state has no ruling.
B3. dc0's mirror sync logs 'cannot delete non-empty directory: project/trace' on every
run. Cosmetic debmirror cleanup noise, present on successful runs too (verified on the
2026-07-27 08:43 run that exited 0). NOT a failure signal -- recorded so a future
reader of the journal does not chase it.
--- PART C: DEFERRED BY RULING (recorded so they are not later read as oversights) ---
C1. SEC-024's two pre-* state-surgery snapshots: RETAINED by ruling 2026-07-27 ('Keep
both'). SEC-024 stays OPEN as a standing WATCH, not an open remediation; the umask
CAUSE is unfixed and preflight P5 is the detection.
C2. dc0 edge API credential re-mint (sole remaining SEC-021(a) item): deliberately
EXCLUDED from the consolidation batch as a live edge mutation. Accounts for 2 of the
7 residual credential-register findings.
C3. The 3 residual S5 power-key asymmetries are RULED BY SEC-016, not defects. The
register has no way to record a ruled exception; suppressing them silently would be
wrong and renaming live files to satisfy a checker would be worse. Needs an operator
decision on mechanism.
C4. tests/creds-matrix T24's finding-class baseline covers TIER 1 ONLY -- tier-2/3 classes
(E1/E3/E4/V1/V2) have no baselined red state. Also in the session-ledger bookend.
C5. scripts/creds-mint.sh: unbuilt, unruled advice from the D-137 close. Stage 5 is the
largest credential-minting event in the deployment, so ruling it BEFORE the bundle
deploy is worth more than after.
C6. allow-vs-ask permission precedence is UNVERIFIED here. A useful allow entry for
creds-matrix.py was deliberately SKIPPED rather than risk a broad prefix silently
downgrading the --privileged ask rule. Measuring it unblocks that entry.
--- PART D: verification run by this sweep ---
D1. Dangling-reference sweep over docs/*.md, runbooks/, scripts/, and the skill: every
path introduced or cited by this session RESOLVES. The pre-existing dangles are all
legitimate -- deliberately deleted files cited as history (the D-112 config.xml
renderers), not-yet-built planned files (overlays/vr1-dc0-vips.yaml, creds-mint.sh),
and the deliberately-absent overlays/octavia-pki.yaml that preflight P4 fails on.
D2. ledger-scan values reconciled against the machine-derived block: 21 open SEC rows,
D next-free 138, DOCFIX 205, BUNDLEFIX 053 -- all match.