diff --git a/docs/changelog-20260719-dc0-deploy-stepB.md b/docs/changelog-20260719-dc0-deploy-stepB.md index 887458e..859f67e 100644 --- a/docs/changelog-20260719-dc0-deploy-stepB.md +++ b/docs/changelog-20260719-dc0-deploy-stepB.md @@ -226,6 +226,21 @@ alternative: `virsh destroy vvr1-dc0`, D-122); module fixes revert by commit. +## 8. STAGE-CLOSE QUEUE ITEM (operator directive, 2026-07-20): OPNsense 26.7 review + +- Operator directive (verbatim intent): at the proper time/place, review the + OPNsense 26.7 changelog + documentation for upgraded features and changes; + incorporate beneficial improvements (esp. hardening) into the next + deployment iteration, following project rules. +- Scheduled: STAGE-3 CLOSE (GA-R6 close-out pass, with this stage's queued + DOCFIXes). Deliverable: a findings doc citing the official 26.7 release + notes; actionable items route per GA-R3 -- hardening/profile deltas as + PROPOSED items anchored on D-129 (its 4 open sub-decisions are the likely + surface), operational items as runbook DOCFIXes. NO self-executing + incorporation: each finding is ruled per GA-R5 (one per exchange) before + touching any built surface. Target of incorporation: dc1 standup + + Roosevelt runbooks; live-edge retrofits individually gated. + ## 6. ledger-scan hardening: FAIL-OPEN is terminology, not a status - SEC-010's close surfaced a scanner false positive: the OPEN-row detector