diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index d16d609..fea9410 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -1418,6 +1418,33 @@ heading, which L5 reads as a second DEFINITION of D-101 (collision), and it was appended after D-136 instead of beside the other D-101 notes. Re-titled to the established `### RULING NOTE -- D-101:` form and moved to sit after note (a). + **RULING (b) BUILT AND APPLIED LIVE 2026-07-31.** Renderer emission DISABLED (not deleted -- + one line turns it back on when v6 is operational, and `PREFER_IPV6_CHARMS` is still the + right set to gate it by); both overlays re-rendered, **exactly 7 lines removed per DC and + nothing else -- all 13 apps keep 6-leg dual-family vips at both DCs**; invariant 9b + RE-POINTED from the coupling rule to "the option must be ABSENT from every application" and + mutation-proven; T20/T21 re-pointed and **three stale fixtures fixed (T22/T23/T30 each set + the option because the OLD coupling required it -- under the absence rule 9b fires FIRST and + short-circuits, so their v6-band assertions would never have been reached and they would + have passed for the wrong reason)**. Harness 55/55, gauntlet ALL GREEN (93), repo-lint 0 fail. + Applied live: the overlay re-staged on the rack hash-verified, the seven set to `false` and + each READ BACK, then every erroring unit resolved. **RESULT MEASURED: units in `error` went + 17 -> 4, and all seven prefer-ipv6 apps CLEARED.** + **>>> THE REMAINING BLOCKER IS ONE CLASS: SNAP ACCESS, AND IT IS THE ALREADY-RECORDED D-135 + ITEMS 2-3 GAP HITTING FOR REAL. <<<** All three remaining failures are snap installs from an + airgapped node: `mysql-innodb-cluster` -> `snap install mysql-shell` (`persistent network + error ... api.snapcraft.io ... network is unreachable`), `ovn-central` -> + `snap install prometheus-ovn-exporter`, `vault` -> `snap install core`. This document already + records the shape: **three artifact classes, only ONE of them local** -- apt packages to + `10.12.8.4` (local), MAAS boot images to `images.maas.io` (NOT local), juju agent stream and + snaps to `streams.canonical.com` / `api.snapcraft.io` (NOT local). **It will hit dc1 EQUALLY** + -- apt-cacher-ng proxies apt, not snaps -- so unlike the UCA finding this one is NOT a + full-mirror-only asymmetry. **LOGGED NOT FIXED: it is a D-107 (airgap posture) / D-135 + (items 2-3) decision, not an engineering choice**, and the options span a snap-store proxy, + narrowly-scoped controlled egress on the DC edge (which D-107 already contemplates for the + mirror's own upstream sync), or a model-level snap proxy setting. + **D2 (the upstream UCA) IS STILL UNFIXED AND STILL OWED** -- it stopped being the visible + error only because the units that hit it are now blocked earlier on snaps. **memcached SCALED to 3 in `overlays/dc-ha-scaleup.yaml`** (operator-directed 2026-07-31); its exclusion comment is RE-POINTED rather than left stale. **`ceph-rbd-mirror` is PINNED, NOT SETTLED** -- gap register **item 22** carries four options and the recommendation