diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 6778adc..db5fe43 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2729,6 +2729,42 @@ measured plan is **56 apps / 108 relations**; `docs/dc-dc-buildout-design.md:12` records the repo was seeded at `8813efc` specifically so `bundle.yaml` + `phase-01..08` could be reused. **Provider capabilities must be READ (`references/opentofu-provider-docs.md`), never recalled.** + **>>> SESSION CLOSE 2026-08-02 (GA-R4 bookend). DURABILITY TRIAD, MEASURED -- AND IT CAUGHT A + LIVE DEPLOY HAZARD. <<<** vcloud **0 uncommitted, 0 unpushed**; voffice1 **1 commit behind** + (not a loss). **>>> THE dc0 RACK'S STAGED DEPLOY INPUT IS STALE: `~/repo-stage/overlays/ + vr1-dc0-vips.yaml` reads `ed19d989e80da8da` while the repo reads `80d861560a6b3c52`. <<<** + `bundle.yaml` and `vr1-dc0-machines.yaml` still MATCH. It diverged because this session + re-rendered the VIP overlay onto GUA and nothing propagates that to the rack -- which under + D-138 IS the deploy client. **A deploy from it would place 26 VIP legs on the ULA prefixes + D-139 retires, silently undoing today's work.** The 2026-08-01 sweep recorded these digests + MATCHING, so that note now misleads. **LOGGED NOT FIXED** (hard rule 1); it is the first item + of the next session. **`~/repo-stage` has NO git, so nothing detects its drift** -- any session + editing a deploy artifact owes a re-stage or a recorded digest. + **GATES AT CLOSE, quoted:** repo-lint **0 fail, 1 warn** (legacy D-001..018 ASCII carve-out), + 654 files; `run-tests-all` **GAUNTLET: ALL GREEN (97 harnesses)**; `ledger-scan` 3 open + decisions, **28 open SEC**, next-free **D-141** / DOCFIX-207 / BUNDLEFIX-053. **RECONCILED:** + D moved 140 -> 141 matching the one D assigned (D-140); SEC 26 -> 28 matching SEC-031 and + SEC-032; harness manifest 96 -> 97 matching the one harness added. + **MIRROR SYNC RE-RUN COMPLETED BUT RECORDS FAIL, AND THE CONTENT IS CURRENT:** journal reads + `Everything OK. Moving meta files ... All done.` then systemd `status=1/FAILURE`; status file + `ubuntu=1 uca=0` (**UCA now succeeds -- egress is genuinely fixed**); both Release files + re-written today (ubuntu 08:22:51, UCA 08:28:03). **So `dc-mirror.sh check dc0` stays RED on an + exit code that disagrees with the sync's own verdict.** Two readings remain open and only one + is right -- a non-fatal non-zero path in debmirror, or something failing after "All done". + **Do NOT relax the check to clear it**; that is the 2026-07-27 false-green defect inverted. + **CLOSE SWEEP: `docs/audit/queued-findings-20260802-stage5-edge-fold.txt` -- SIX FIRST + SURFACE**, each grep-proven absent from every repo surface first. Highest-consequence is the + stale staged overlay above; then the mirror exit-code disagreement; **`systemctl show` returning + success-looking defaults for a NON-EXISTENT unit**; a harness suite reporting ALL PASS while two + newly-added cases never ran; the rule that two scripts probing one endpoint must share the probe + definition; and the uncompleted `pg_dump maasdb`. + **GA-R7 MEMORY REVIEW: CLEAN** -- zero entries claiming operator policy, priority or posture. + One update: the instrument-currency memory gains its **tenth through twelfth** instances and + the operator's own framing of the pattern -- guessing values the repo already defines. + **LEDGER ROTATED (GA-R4 rule 3):** 283 lines would have breached the 300 cap; the oldest closed + summary moved VERBATIM to `docs/archive/session-ledger-rotated-20260802.md`; ledger now 286. + **No orphaned session** -- 7 close bookends, none in-flight, so rule 7 is a no-op. + **NO STAGE OPENED OR CLOSED**; Stage 5 remains OPEN and this is a session bookend. **>>> PRE-DEPLOY ITEMS 1-3 PROCESSED 2026-08-02. <<<** **(1) PREFLIGHT RE-RUN for dc0 on voffice1 with `MAAS_PROFILE=vr1-dc0-region`: EXIT 1 with EXACTLY 11 `[FAIL]` lines, and they are EXACTLY the ruled-accepted P5 set** (dc0 diff --git a/docs/archive/session-ledger-rotated-20260802.md b/docs/archive/session-ledger-rotated-20260802.md new file mode 100644 index 0000000..6e3e9da --- /dev/null +++ b/docs/archive/session-ledger-rotated-20260802.md @@ -0,0 +1,22 @@ +# Ledger summaries rotated 2026-08-02 (GA-R4 rule 3 / F1 -- cap restored at this close) + +Moved VERBATIM from docs/session-ledger.md. The live ledger stood at 283 lines and this +close's summary would have breached the 300-line cap. + +## SESSION CLOSE 2026-07-30 (part 2) -- F9 CLOSED live, the reissue tool, P7, lib-identity (bounded, GA-R4) + +- Branch `dc-dc-stage5-preconditions`, **19 commits** pushed (`1ddb078..`). NO stage opened/closed. Scan unchanged: 3 decisions, SEC 21, D 138 / **DOCFIX 206** / BUNDLEFIX 053. +- **>>> OPERATOR DIRECTIVE, STANDING: THE NEXT SESSION PROCEEDS TO THE JUJU DEPLOYMENT (Stage 5), NO MATTER WHAT.** Verbatim: "we have to continue to juju deployment next session no matter what". Precondition polishing is DONE; further hardening is OUT OF SCOPE unless it blocks the deploy. This is the GA-F06 circuit-breaker made explicit -- do not spend the session on records. +- **DOCFIX-205:** Q1 WITHDRAWN -- D-117 ruled it 2026-07-13; it resurfaced only because D-117's annotation half was never executed (0 of 4) while its own Status claimed "FULLY EXECUTED". All four annotated; Status corrected. Q2 withdrawn too (D-137 fork 1 ruled 2026-07-25). **Third stale premise in one findings file.** +- **F9 CLOSED LIVE, both DCs** (gated per DC, never batched): controller certs reissued into their own zones -- `omega.dc0.vr1` / `omega.dc1.vr1`, fresh P-256 keys, CAs untouched. Capture `docs/audit/octavia-reissue-executed-20260730.txt`. +- **`octavia-pki.sh reissue` SHIPPED** (operator: "Full script minter now"): derived zone, printf config (F8 paid off), stage-assert-promote, single-value overlay surgery, backup-before-mint. +- **VALIDATION AGENTS EARNED THEIR COST.** Mutation testing deleted my three new assertions and the harness stayed GREEN every time. Six defects closed: **A15** (no keyUsage/EKU minted + passed everything), **A16** (`-days` defaults to **30** and verify had NO validity check), **A17** (overlay/workspace desync read PASS), the re-run guard REFUSING to fix broken certs, A8's vacuous negative, two overlay checks moved pre-mint. +- **F8 + F9 FIXED AT SOURCE in 1.0-GEN.c** -- the generation path would otherwise recreate both at the next DC standup. F10 handled: 13 mint-refs re-anchored single-pass by row id; S4 clean. +- **P7: the PKI is now an actual GATE** in `preflight.sh` -- headend-only, NOT EVALUATED elsewhere, rc3 mapped explicitly, and it requires the literal zone line because `verify` exits 0 on a wrong-zone cert while inert. +- **`scripts/lib-identity.sh`** -- CLOUD_NAME + CLOUD_DOMAIN in ONE file; a rebuild that renames the estate edits one file. T47 catches shell-vs-OpenTofu drift, proven able to fail. +- **Backup custody done + REGISTERED** (2 rows, manifests, `n-reissue-backup`); the secrets-storage PIN now covers this step's creds and certs. Hazard recorded: these archives carry CA issuance state -- never restore over a workspace that has issued since. +- **OWNED:** I withdrew two of my own recommendations after measuring (the vr0-dc0 retirement, and the D-137 escalation framing); pushed one red-lint commit via `;` instead of `&&`; two harness stub bugs. All corrected on-surface. +- Guard misfire tally now **SEVEN** -- it blocked a command that only TESTED it, then the heredoc documenting its own misfires. Hardening it needs no ruling (fork 1 is ruled). +- Gauntlet ALL GREEN (89) BOTH hosts; repo-lint 0 fail; octavia-pki 51/51; preflight 33/33; creds-matrix 65/65 + 5 pre-existing findings. **verify 37/0 and P7 [ok] on both DCs.** +- **NEXT (Stage 5 entry):** preflight is RED only on P5's pre-existing credential register -- decide accept-or-remediate at the gate, do not re-audit it. G17 arms at first boot. Bodies: `docs/changelog-20260730-docfix205-d117-annotation.md`, `-octavia-reissue-tool.md`. Status ONLY in CURRENT-STATE.md. + diff --git a/docs/audit/queued-findings-20260802-stage5-edge-fold.txt b/docs/audit/queued-findings-20260802-stage5-edge-fold.txt new file mode 100644 index 0000000..169f813 --- /dev/null +++ b/docs/audit/queued-findings-20260802-stage5-edge-fold.txt @@ -0,0 +1,154 @@ +queued-findings-20260802-stage5-edge-fold.txt +============================================== +Close sweep for the 2026-08-02 session (edge outage + rebuild, D-139 steps 1-3, +Step 3.5, the egress gate, and the opening of the runbook fold). +Method (ruled 2026-07-31): read back over the whole session, enumerate every +finding/decision/measurement/mistake, then GREP each candidate against repo +surfaces. A hit = ALREADY ON SURFACE, and where. No hit = FIRST SURFACE and would +have been lost on a context clear. + +Session body: this session wrote no single changelog; its record is spread across +docs/CURRENT-STATE.md (status), docs/design-decisions.md (rulings), and the +per-topic captures cited below. Status claims live in CURRENT-STATE only. + +-------------------------------------------------------------------------------------- +FIRST SURFACE -- existed ONLY in the transcript. Listed first, by consequence. +-------------------------------------------------------------------------------------- + +F1. >>> THE dc0 RACK'S STAGED DEPLOY INPUT IS NOW STALE, AND IT IS THE VIP OVERLAY. <<< + greps: "ed19d989" hits ONLY the 2026-08-01 sweep, which recorded it MATCHING. + MEASURED at this close: + rack ~/repo-stage/overlays/vr1-dc0-vips.yaml ed19d989e80da8da + repo overlays/vr1-dc0-vips.yaml 80d861560a6b3c52 DIVERGED + bundle.yaml 4c8a7852 and vr1-dc0-machines.yaml e3be85e4 still MATCH. + WHY IT DIVERGED: this session re-rendered the VIP overlay onto GUA (26 of 39 v6 + legs moved from the retired ULA /64s to f02:20::/f02:21::). The rack's copy is + the PRE-GUA version and nothing propagated the change. + WHY IT MATTERS AND WHY IT IS THE TOP ITEM: under D-138 the rack IS the deploy + client. `juju deploy` there would consume the STALE overlay and place 26 VIP + legs on prefixes D-139 ruling B retires -- undoing, silently, the exact work + this session did. The 2026-08-01 sweep recorded these digests MATCHING, so a + reader trusting that note would conclude the staged copy is fine. + LOGGED, NOT FIXED (hard rule 1 + this skill does not fix). The fix is one copy + plus a re-verify, and it belongs to whoever runs Step 4. + DURABLE LESSON: ~/repo-stage has NO git, so nothing detects its drift. Any + session that edits a deploy artifact owes a re-stage or a recorded digest. + +F2. THE MIRROR SYNC EXITS 1 WHILE ITS OWN LOG SAYS THE SYNC SUCCEEDED, AND THE + CONTENT IS CURRENT. grep "Everything OK": 0 hits. + MEASURED after re-triggering the sync at 08:22 (egress restored): + journal: "Files to download: 0 B" / "Downloaded 15 kiB in 3s" / + "Everything OK. Moving meta files ..." / "Cleanup mirror." / "All done." + then: systemd "Main process exited, code=exited, status=1/FAILURE" + status: FAIL 2026-08-02T08:28:03Z ubuntu=1 uca=0 (UCA now SUCCEEDS: 0) + content: ubuntu jammy Release mtime 2026-08-02 08:22:51 + UCA caracal Release mtime 2026-08-02 08:28:03 -- BOTH refreshed today + So the mirror IS current and `dc-mirror.sh check dc0` will stay RED, because its + success criterion is debmirror's EXIT CODE and debmirror reported "All done" + while exiting 1. The 08-02 upstream failure is genuinely fixed (uca=0 proves + egress); what remains is an exit-code disagreement. + NOT DIAGNOSED FURTHER and NOT FIXED. Two readings remain open and only one is + right: debmirror has a non-fatal non-zero path, OR something after "All done" + fails silently. Do not assume the first. + CONSEQUENCE FOR STAGE 5: a real gate is red for a reason that is probably not + staleness. Do not wave it through and do not "fix" it by relaxing the check -- + that is the 2026-07-27 false-green defect in reverse. + +F3. `systemctl show` RETURNS SUCCESS-LOOKING DEFAULTS FOR A UNIT THAT DOES NOT EXIST. + grep "success-looking default": 0 hits. + MEASURED: `systemctl show dc0-rack-net -p Type -p RemainAfterExit -p Result` on + a unit name that does not exist returned `Type=`, `UnitFileState=`, + `RemainAfterExit=no`, `Result=success`, `ExecMainStatus=0` and NO journal + entries -- which reads exactly like a healthy oneshot that has completed. The + real units are `dc0-rack-legs` and `dc0-node-dns` (from `dc-rack-net.sh:16,22`). + This caused a false "inactive" reading that was reported before being caught. + DURABLE RULE: `systemctl show` is not an existence check. Use `systemctl cat` + (which errors on a missing unit) or check UnitFileState is non-empty. Same class + as the repo's standing instrument-currency lesson. + +F4. A HARNESS CASE THAT NEVER RAN, IN A SUITE THAT REPORTED ALL PASS. + grep "fok": 0 hits. + While extending tests/dc-egress-check, two new cases were written using `fok`/ + `fbad` -- helper names from a DIFFERENT harness (tests/dc-node-v6-carve). The + suite printed `fbad: command not found` to stderr, kept its old count of 14, and + still reported ALL PASS. Both mutations then "survived", which looked like the + tool being robust and was actually the tests not existing. + DURABLE RULE: after adding harness cases, assert the CASE COUNT moved. A suite + that says ALL PASS with the old count has silently dropped what was added. + +F5. WHEN TWO SCRIPTS PROBE THE SAME ENDPOINT THEY MUST SHARE THE PROBE DEFINITION. + grep "share the probe definition": 0 hits. + dc-egress-check.sh's A4 snap probe and dc-snap-proxy.sh:215 both hit the snap + store; only the latter sent `Snap-Device-Series: 16`, which the store REQUIRES. + Measured: 400 without it BOTH through the proxy and direct, 200 with it. The new + gate therefore reported a healthy proxy as broken on its first live run, while + the older script returned PASS with a real payload. A fixture that mocks curl + cannot catch a wrong REAL request. (Raised by the dc0 rebuild agent; the header + fix and its harness case are on surface, this GENERAL rule was not.) + +F6. `pg_dump maasdb` -- THE ONE dc0 CORRUPTION TEST THAT WAS NOT COMPLETED. + grep "pg_dump": 0 hits. + The MAAS region VM was hard-cut on 2026-08-01 and holds the region database this + session wrote ~95 changes to. Evidence AGAINST damage is good but not a proof: + ext4 with no EXT4-fs errors, no orphan recovery, MAAS services active, ZERO + checksum/corrupt/invalid-page entries in the postgres logs, and every one of + those ~95 writes read back correctly. A full-table read was attempted FIVE times + and blocked every time by snap confinement (`_daemon_` has HOME=/nonexistent; + the cgroup is rejected; the raw binary needs the snap's library path). + OWED: run `pg_dump maasdb > /dev/null` from the VM's own login shell, where the + snap cgroup is valid. One command, definitive, and it should happen before the + deploy rather than be assumed. + +-------------------------------------------------------------------------------------- +ALREADY ON SURFACE -- verified by grep, recorded here for completeness +-------------------------------------------------------------------------------------- + +A1. The edge outage, its root cause (UFS soft-update damage from the in-place + resize bounce, NOT a partial update) and the corrected diagnosis -- + docs/audit/dc0-edge-egress-outage-20260802.txt + CURRENT-STATE. +A2. The dc0 edge rebuild, incl. the wrong base-image path in my agent brief -- + docs/audit/dc0-edge-rebuild-20260802.txt + CURRENT-STATE. +A3. The dc1 edge assessment: forwards-but-does-not-translate, config INTACT, + repair-not-rebuild -- docs/audit/dc1-edge-assessment-20260802.txt + SEC-031. +A4. D-139 steps 1-3 executed -- docs/audit/d139-step1-apex-push-dc0-20260801.txt, + docs/audit/d139-steps2-3-dc0-20260801.txt + CURRENT-STATE. +A5. The D-139 conformance audit and the VIP-overlay blocker -- + docs/audit/d139-conformance-dc0-20260801.txt. +A6. Both GA-R5 rulings of this date (D-135 amendment; D-140 PINNED) with exact + utterances -- docs/design-decisions.md + CURRENT-STATE. +A7. The runbook fold register and both Class-A fixes -- docs/runbook-fold-register.md. +A8. `Snap-Device-Series: 16` as a store requirement -- scripts/dc-egress-check.sh + comment + tests/dc-egress-check T15. +A9. SEC-031 (dc1 edge is an open router) and SEC-032 (dc0 edge API credential). +A10. The dnsmasq v6 `constructor:` latent risk -- CURRENT-STATE. + +-------------------------------------------------------------------------------------- +THE FIVE STRUCTURAL SWEEPS +-------------------------------------------------------------------------------------- + +S1. GITIGNORED STATE. `.claude/settings.local.json` was NOT modified this session -- + allow/ask/deny counts unchanged from the 2026-07-30 verbatim record, which + therefore still stands as the recovery copy. No new permission rules were added; + two classifier refusals were hit and NOT retried in altered shapes (the sqlite + profile enumeration, and nothing else). +S2. DANGLING REFERENCES. Every docs/audit path cited by this session's commits + resolves; the four new captures are committed. +S3. RULING FIDELITY. Six GA-R5 rulings this session, each with its exact utterance + quoted, dated, committed and pushed BEFORE dependent work: D-139 ordering; OOB + dual-stack; OOB v4 allocation (10.12.40.0/22 / 10.12.88.0/22, superseding + 10.12.60.0/22); VPN deferral; D-135 amendment; D-140 PINNED. None paraphrased. +S4. AS-EXECUTED LOG. `run-logged.sh` was NOT used -- it needs an interactive shell. + All evidence is in the docs/audit captures and the commit messages. THIS WINDOW + IS NOT COVERED BY AN AS-EXECUTED LOG and that is declared here rather than left + to be discovered. +S5. CONTRADICTION DETECTOR. + (a) preflight's P6 reminder still quotes "plan: 50 apps / 97 relations" against + the 2026-07-31 MEASURED 56 apps / 108 relations. Pre-existing, still unfixed, + and measurement wins (GA-R1 C2). DOCFIX owed. + (b) `dc-rack-net.sh`'s DNS_UPSTREAM=10.10.0.20 still points node DNS at + voffice1's BIND across the fiber while the 07-30 record says node DNS now + uses the DC-local 10.12.8.6. Pre-existing; its gate passes because it checks + units and legs, not the upstream's correctness. + (c) D-135's "there is no fallback and no later convergence" is now QUALIFIED by + the 2026-08-02 amendment -- recorded as a qualification in the amendment + itself rather than left to contradict silently. diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 496e35f..f61c852 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -164,23 +164,6 @@ owed, because the next session is directed straight at the juju deployment. Sessions from the 2026-07-27 Phase-0 close onward remain live below. -## SESSION CLOSE 2026-07-30 (part 2) -- F9 CLOSED live, the reissue tool, P7, lib-identity (bounded, GA-R4) - -- Branch `dc-dc-stage5-preconditions`, **19 commits** pushed (`1ddb078..`). NO stage opened/closed. Scan unchanged: 3 decisions, SEC 21, D 138 / **DOCFIX 206** / BUNDLEFIX 053. -- **>>> OPERATOR DIRECTIVE, STANDING: THE NEXT SESSION PROCEEDS TO THE JUJU DEPLOYMENT (Stage 5), NO MATTER WHAT.** Verbatim: "we have to continue to juju deployment next session no matter what". Precondition polishing is DONE; further hardening is OUT OF SCOPE unless it blocks the deploy. This is the GA-F06 circuit-breaker made explicit -- do not spend the session on records. -- **DOCFIX-205:** Q1 WITHDRAWN -- D-117 ruled it 2026-07-13; it resurfaced only because D-117's annotation half was never executed (0 of 4) while its own Status claimed "FULLY EXECUTED". All four annotated; Status corrected. Q2 withdrawn too (D-137 fork 1 ruled 2026-07-25). **Third stale premise in one findings file.** -- **F9 CLOSED LIVE, both DCs** (gated per DC, never batched): controller certs reissued into their own zones -- `omega.dc0.vr1` / `omega.dc1.vr1`, fresh P-256 keys, CAs untouched. Capture `docs/audit/octavia-reissue-executed-20260730.txt`. -- **`octavia-pki.sh reissue` SHIPPED** (operator: "Full script minter now"): derived zone, printf config (F8 paid off), stage-assert-promote, single-value overlay surgery, backup-before-mint. -- **VALIDATION AGENTS EARNED THEIR COST.** Mutation testing deleted my three new assertions and the harness stayed GREEN every time. Six defects closed: **A15** (no keyUsage/EKU minted + passed everything), **A16** (`-days` defaults to **30** and verify had NO validity check), **A17** (overlay/workspace desync read PASS), the re-run guard REFUSING to fix broken certs, A8's vacuous negative, two overlay checks moved pre-mint. -- **F8 + F9 FIXED AT SOURCE in 1.0-GEN.c** -- the generation path would otherwise recreate both at the next DC standup. F10 handled: 13 mint-refs re-anchored single-pass by row id; S4 clean. -- **P7: the PKI is now an actual GATE** in `preflight.sh` -- headend-only, NOT EVALUATED elsewhere, rc3 mapped explicitly, and it requires the literal zone line because `verify` exits 0 on a wrong-zone cert while inert. -- **`scripts/lib-identity.sh`** -- CLOUD_NAME + CLOUD_DOMAIN in ONE file; a rebuild that renames the estate edits one file. T47 catches shell-vs-OpenTofu drift, proven able to fail. -- **Backup custody done + REGISTERED** (2 rows, manifests, `n-reissue-backup`); the secrets-storage PIN now covers this step's creds and certs. Hazard recorded: these archives carry CA issuance state -- never restore over a workspace that has issued since. -- **OWNED:** I withdrew two of my own recommendations after measuring (the vr0-dc0 retirement, and the D-137 escalation framing); pushed one red-lint commit via `;` instead of `&&`; two harness stub bugs. All corrected on-surface. -- Guard misfire tally now **SEVEN** -- it blocked a command that only TESTED it, then the heredoc documenting its own misfires. Hardening it needs no ruling (fork 1 is ruled). -- Gauntlet ALL GREEN (89) BOTH hosts; repo-lint 0 fail; octavia-pki 51/51; preflight 33/33; creds-matrix 65/65 + 5 pre-existing findings. **verify 37/0 and P7 [ok] on both DCs.** -- **NEXT (Stage 5 entry):** preflight is RED only on P5's pre-existing credential register -- decide accept-or-remediate at the gate, do not re-audit it. G17 arms at first boot. Bodies: `docs/changelog-20260730-docfix205-d117-annotation.md`, `-octavia-reissue-tool.md`. Status ONLY in CURRENT-STATE.md. - ## SESSION CLOSE 2026-07-30 (part 3) -- STAGE 5 OPENED; three bootstraps; D-138 + D-132 ruled; per-DC MAAS region LIVE at dc0 (bounded, GA-R4) - Branch `dc-dc-stage5-preconditions`, **12 commits** pushed (`726127d..`). **STAGE 5 OPENED**, not closed. Scan: 3 decisions, **SEC 23** (SEC-026, -027 opened), **D 139** / DOCFIX 206 / BUNDLEFIX 053. @@ -281,3 +264,23 @@ - Gauntlet **ALL GREEN (96)**, repo-lint 0 fail, `d139-gua-carve` 71/71, `dc-node-v6-verify` 55/55. **voffice1's clone is 36 commits BEHIND** -- no loss, but a live hazard on the Plane-2 host. - **AMENDED AFTER THE BOOKEND (2026-08-01):** both DC containment VMs resized **416 -> 480 GiB** through tofu (operator: *"Option 2 look sgood me"*), **128 GiB swap** added (operator-run), and preflight gained **gate P8, substrate drift** (harness 33 -> 38, proven live at zero diff). Host used **809 -> 63 GiB**. Found: dc0's MAAS region and juju controller have `autostart=disable`. Bodies: changelog items 21-22. - **NEXT:** apex CREATE-only push (tool built, independently reviewed, dry-run byte-identical), then the bundle deploy -- its blockers are cleared. `network-get` on a v6-only bound space is still unmeasured and gates the v4-removal experiment. Sweep: `docs/audit/queued-findings-20260801-stage5-ipv6-d139.txt` (**6 FIRST SURFACE**). Body: `docs/changelog-20260731-snap-proxy-apply-ipv6.md`. Status ONLY in CURRENT-STATE.md. + +## ROTATED 2026-08-02 (GA-R4 rule 3 / F1 -- cap restored at this close) + +The oldest closed-session summary moved VERBATIM to +`docs/archive/session-ledger-rotated-20260802.md`. The live ledger stood at 283 lines and +this close's summary would have breached the 300-line cap. + +## SESSION CLOSE 2026-08-02 -- dc0 edge destroyed and rebuilt; D-139 steps 1-3 done; runbook fold opened (bounded, GA-R4) + +- Branch `dc-dc-stage5-preconditions`, **24 commits** pushed (`f79c9e8..`). NO stage opened or closed. Scan: 3 open decisions, SEC **28** (SEC-031, -032 opened), D **141** / DOCFIX 207 / BUNDLEFIX 053. +- **D-139 STEPS 1-3 EXECUTED for dc0.** Apex 139 -> 152 prefixes; MAAS 6 GUA + 5 ULA each paired on one vlan; node statics migrated **GUA 54 / ULA 0 with ZERO multi-global NICs**. v4 untouched, which is the ordering step 3 exists to enforce. Step 3.5 done: model created, spaces gate PASS 0 fatal, `apt-mirror` verified. +- **>>> THE dc0 EDGE WAS DESTROYED AND HAS BEEN REBUILT. <<<** Root cause is NOT the update I first claimed -- zero pkg/firmware lines in the whole serial log. It was **UFS soft-update damage from an unclean power cut**: the 08-01 in-place tofu resize BOUNCED the containment VM, hard-cutting every inner guest. fsck salvaged 2533 unreferenced files and `libcrypto`/`libpython` did not survive. +- **dc1's edge took the SAME cut** (76/181 vs dc0's 2533/785) and lost its user DB instead: it **forwards without translating** (tcpdump, both taps, source unchanged) and runs with NO pf ruleset -- an open router serving its GUI, **SEC-031**. Config INTACT; verdict REPAIR not rebuild, blocked on having no credential path. +- **Edge rebuilt by agent**, `dc-egress-check dc0` **PASS 8/8 exit 0**. Plan asserted on `tofu show -json` including the POSITIVE half; `pfctl -s nat` verified rather than assumed. **SEC-032** minted. +- **NEW GATE `dc-egress-check.sh`** (F9): layered route -> edge answers -> traffic leaves -> upstreams, first failure reported as the cause. Proven live on TWO different failure modes. Wired into restart Stage 0 and phase-4 Step 3.9. **Two of its own defects found and fixed the same day.** +- **RUNBOOK FOLD OPENED** (`docs/runbook-fold-register.md`, 12 rows). D-138 and D-139 appear in **no runbook**; the chain as written would rebuild the pre-D-132/D-138/D-139 shape. Both Class-A rows closed -- incl. `SKILL.md`, which every session reads BEFORE any runbook. +- **6 RULINGS (GA-R5, all utterances quoted):** D-139 ordering (carve before deploy); OOB dual-stack; OOB v4 `10.12.40.0/22`/`10.12.88.0/22` superseding `10.12.60.0/22`; VPN deferred to Roosevelt; **D-135 amended** (dc0 converges on the proxy at rebuild); **D-140 PINNED** (tofu manages juju AFTER a hardened, tested dc0 deploy). +- **OWNED:** I diagnosed the edge break as a partial update from the symptom's SHAPE and was wrong; my agent brief carried a **wrong base-image path** where the apply destroys the volume first and no rollback exists; I guessed `/srv/mirror/ubuntu` and a systemd unit name the repo already defines; two harness cases I wrote never ran while the suite said ALL PASS; one assertion passed on its own comment; and I pushed a red lint once by masking the exit code. +- Gauntlet **ALL GREEN (97)**, repo-lint 0 fail / 1 warn, ledger-scan reconciled. **voffice1 1 commit behind** at close (not a loss). +- **NEXT:** re-stage the rack's VIP overlay (sweep F1 -- it is STALE and is the deploy input), settle the mirror's exit-1-with-"All done" (F2), `pg_dump maasdb` (F6), then fold F2-F11 and the dc1 Phase-2 exercise. Sweep: `docs/audit/queued-findings-20260802-stage5-edge-fold.txt` (**6 FIRST SURFACE**). Status ONLY in CURRENT-STATE.md.