|
Final pre-ruling measurements R9/R10/R12-R15: two premises corrected
Operator direction: gather everything remaining so the last decisions can be worked through without stopping to measure. Capture: docs/audit/r9-r15-final-measurements-20260727.txt. TWO OF THESE CHANGED MATERIALLY, and both are corrections to the audit's OWN earlier framing rather than new findings. R9 -- there is only ONE failure mode, not two, and the Stage-5 blast radius is TWO scripts rather than twenty. lib-net.sh:76-79 states the design explicitly: sourcing without the selector "continues to populate PLANE_CIDRS ... exactly as above (VR0/DC0's real, measured values) -- every existing script that sources lib-net.sh keeps working completely unchanged". So the unset block fires ONLY for selector-CALLERS. The 20 non-selector consumers fail SILENTLY with dc0 literals; the 8 correctly-updated ones are the ones that break loudly under set -u. That inverts the intuitive reading -- the scripts nobody fixed are the dangerous ones. And grepping the two runbooks Stage 5 actually uses, only phase-03-core-verify.sh and deploy-watch.sh are invoked there; the rest bite at later stages. R14 -- THE PREMISE IS WRONG and the question largely dissolves. I framed it as "the matrix cannot express a RULED exception, so three S5 asymmetries ruled correct by SEC-016 report as a permanent red". Measured: they are NOT ruled correct. SEC-016 ruled per-DC ISOLATION -- dc1 gets its own dedicated power key rather than reusing dc0's -- which is satisfied. It never blessed the filename, host and custody divergence. THAT is SEC-021(b), an OPEN defect whose own recorded disposition reads "needs a naming/custody reconciliation to the dc1 shape", and whose stated complaint was "Per-DC rows that should be symmetric are not, and nothing compares them". S5 is the thing that now compares them. The register is RIGHT and the finding is REAL. Suppressing it would have hidden an open security-ledger item. R15 refinement: the gauntlet ALREADY has a zero-floor -- run-tests-all.sh:35 exits 2 when RAN is 0. What is missing is a MINIMUM-count floor, since 81 is pinned nowhere executable. repo_lint.py:132-135 has NEITHER a valid-root check nor a files-scanned floor. The two gates need different fixes, which the earlier framing conflated. R12 and R10 confirmed as previously stated, with exact line citations. Revert: git revert this commit; the capture is new and CURRENT-STATE additive. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/r9-r15-final-measurements-20260727.txt 0 → 100644 |
|---|