diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 74252af..ef725b1 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -1875,6 +1875,21 @@ independent of the refuted one, so **the ruling may well stand on them -- but that is the operator's call under GA-R5**, since they answered a question whose stated deciding reason no longer holds. Nothing of D-139 has been executed, so nothing is half-built either way. + **^ RECONSIDERED AND CONFIRMED 2026-08-01 (GA-R5) -- THE FLAG IS CLEARED. Operator answer, + exact utterance: "Deciding to hold to gua does not cost anything operationally and the case + for ULA over gua is not very strong. Let's stay with gua".** Recorded as + `### RULING NOTE 2026-08-01 -- D-139:` in `docs/design-decisions.md`. **D-139 ruling B + STANDS, unchanged in substance** -- the GUA carve table is confirmed, the ULA `/48` stays + RETIRED for VR1, and the D-101/D-111 amendments hold. **What changed is the RATIONALE OF + RECORD:** the RFC 6724 precedence argument is STRUCK in D-139's own text and must NOT be + re-cited; ruling B now rests on exactly two project-constraint arguments -- conformance with + Willamette and VR0 DC0 (both already full GUA, VR1 was the outlier) and MINIMIZE DELTA TO + ROOSEVELT -- plus the operator's recorded reasoning that holding to GUA costs nothing + operationally. **EXPLICIT CONSEQUENCE that was not visible before: on glibc 2.35, choosing + GUA buys NO address-selection advantage on the two dual-stack planes** (ULA would have won + equally at precedence 40); it buys conformance and Roosevelt fidelity, and nothing else. + A later session reasoning "GUA was chosen so v6 would beat v4" is reasoning from the struck + argument and is wrong. **Stage-2 execution of D-139 is therefore UNBLOCKED.** - Project: Omega Cloud, VR1 DC-DC rehearsal -- a two-DC + Office1-headend virtual rehearsal on KVM (vcloud host), rehearsing the future bare-metal Roosevelt deployment (D-100, `docs/design-decisions.md:1946`). diff --git a/docs/changelog-20260731-snap-proxy-apply-ipv6.md b/docs/changelog-20260731-snap-proxy-apply-ipv6.md index 06f423e..7cdb81f 100644 --- a/docs/changelog-20260731-snap-proxy-apply-ipv6.md +++ b/docs/changelog-20260731-snap-proxy-apply-ipv6.md @@ -428,3 +428,54 @@ **Revert.** `git rm docs/audit/gai-conf-rfc6724-verification-20260801.txt` and drop the CURRENT-STATE paragraph. Note that reverting does not un-refute the measurement. + +--- + +## Item 11 -- D-139 ruling B RECONSIDERED and CONFIRMED; the refuted rationale is STRUCK + +**What.** `docs/design-decisions.md` -- D-139's deciding-reason paragraph replaced by a STRUCK +block, plus a new `### RULING NOTE 2026-08-01 -- D-139:` at the end of the entry + +`docs/CURRENT-STATE.md` (flag cleared). No script, no cloud change. + +**Question as presented.** The RFC 6724 precedence argument given as ruling B's DECIDING +reason is refuted for this deployment (item 10); on jammy's glibc 2.35, ULA and GUA are +behaviourally EQUAL. Three reasons survive independently. Does ruling B stand on those alone? +Nothing of D-139 is executed, so reversal costs only the exchange. + +**Operator answer, exact utterance: "Deciding to hold to gua does not cost anything +operationally and the case for ULA over gua is not very strong. Let's stay with gua".** + +**RULED: ruling B STANDS, unchanged in substance.** The GUA carve table is confirmed, the ULA +`/48` stays RETIRED for VR1, the D-101/D-111 amendments hold, and Phase-2 execution is +UNBLOCKED. + +**The refuted argument is STRUCK IN PLACE rather than deleted.** D-139's original text is +quoted inside the strike block, with the measurement that kills it and a pointer to the +capture. Deleting it would have been the easier edit and the wrong one: a future session +would have no way to know the argument had been considered and refuted, and would be free to +re-derive it. The strike block says explicitly **DO NOT CITE IT**, and separately warns +against the near-miss rescue -- glibc 2.35 DOES carry `fc00::/7` in `default_labels[]` +(label 6), which drives SOURCE-selection rules 5/6 and is a DIFFERENT mechanism from +destination precedence. Someone finding that entry could easily conclude the struck argument +survives after all. It does not. + +**The rationale of record is now narrower, and that is recorded as a CONSEQUENCE rather than +buried.** Ruling B rests on two project-constraint arguments -- conformance (Willamette and +VR0 DC0 are already full GUA; VR1 was the outlier) and MINIMIZE DELTA TO ROOSEVELT -- plus the +operator's own reasoning that GUA costs nothing operationally. **Made explicit because it was +NOT visible before: on glibc 2.35, GUA buys no address-selection advantage on the two +dual-stack planes; ULA would have won equally at precedence 40.** A later session reasoning +"GUA was chosen so v6 would beat v4" is reasoning from the struck argument. + +**NEW STANDING RULE, added to D-139's note because it generalises past this decision.** The +repo's citation rule is "a citation is an EXISTENCE claim; only its CONTENT is evidence" -- +open it, check STATUS and DATES. That was FOLLOWED here and was NOT ENOUGH: the citation was +real, current, correctly quoted and correctly understood, and still wrong, because nobody +checked whether the IMPLEMENTATION follows the standard. **For a STANDARDS citation, add a +third check: confirm the deployed software implements it, at the deployed version. An RFC is +not a description of your system.** + +**Revert.** `git checkout -- docs/design-decisions.md docs/CURRENT-STATE.md` restores both +the original deciding-reason paragraph and the flag. Reverting does not un-refute the +measurement, and the ruling note quotes an operator utterance -- so a revert would DESTROY a +GA-R5 record and must not be done casually. diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 727bdc3..c374152 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -6931,14 +6931,23 @@ in the apex; it simply carries no VR1 plane. **This AMENDS D-101**, whose text names that ULA prefix as a literal, and D-111. -**Deciding reason, and it is measurable rather than aesthetic:** RFC 6724's default policy -table ranks IPv4-mapped (`::ffff:0:0/96`) at precedence **35** and ULA (`fc00::/7`) at **3**, -while GUA falls under `::/0` at **40**. On a DUAL-STACK plane a ULA leg therefore LOSES -address selection to IPv4 and is largely decorative, whereas GUA WINS -- so full GUA -delivers D-101's "IPv6 unless IPv4 is necessary" by default, with no per-host `gai.conf` -tuning. **UNVERIFIED and owed before the carve is executed: the deployed jammy image's own -`/etc/gai.conf`, which can override the default table.** Secondary reasons: conformance with -Willamette (a REAL site) and VR0, both full GUA; and Roosevelt holds a GUA `/48` with no ULA. +**>>> THE ORIGINAL DECIDING REASON IS STRUCK -- REFUTED BY MEASUREMENT 2026-08-01. DO NOT +CITE IT. <<<** It read: *"RFC 6724's default policy table ranks IPv4-mapped +(`::ffff:0:0/96`) at precedence 35 and ULA (`fc00::/7`) at 3, while GUA falls under `::/0` at +40. On a DUAL-STACK plane a ULA leg therefore LOSES address selection to IPv4 and is largely +decorative, whereas GUA WINS."* **That is true of the RFC and FALSE of the software this +cloud runs.** glibc 2.35 -- jammy's `libc-bin 2.35-0ubuntu3` -- implements the **RFC 3484** +table, as glibc's own in-source comment states, and it has **NO `fc00::/7` entry at all**: +ULA falls through to `::/0` = **40**, identical to GUA, while IPv4-mapped is **10**. So ULA +and GUA are EQUAL and BOTH outrank IPv4. The shipped `/etc/gai.conf` carries ZERO active +lines, so nothing overrides it. The `fc00::/7` entry that does exist is in `default_labels[]` +(label 6) and drives SOURCE-selection rules 5/6 -- a different mechanism; do not conflate the +two into a rescue of the struck argument. Method and full table: +`docs/audit/gai-conf-rfc6724-verification-20260801.txt`. + +**THE RULING STANDS on the reasons below -- see RULING NOTE 2026-08-01 at the end of this +entry.** Those reasons: conformance with Willamette (a REAL site) and VR0 DC0, both full GUA; +and MINIMIZE DELTA TO ROOSEVELT, which holds a GUA `/48` with no ULA and no plane carve yet. **Isolation is NOT weakened, and this was checked rather than assumed.** Containment lives at the FORWARDING layer -- SEC-010's transit drop, D-125's proven egress isolation, D-107's @@ -6998,3 +7007,56 @@ (`octavia-pki.sh reissue` -- the rotation tool this is exactly the case for); update `lib-net.sh`'s v6 arm and its harness; carve `lb-mgmt` a VLAN/space/subnet, which it has never had; remove the v4 subnets from the five v6-only planes LAST, after each is proven. + +### RULING NOTE 2026-08-01 -- D-139: ruling B RECONSIDERED after its deciding reason was refuted, and CONFIRMED + +**Why this note exists.** D-139 ruling B ("Full GUA on every plane") was recorded on +2026-07-31 WITH an explicitly-named unverified premise: the deployed jammy image's +`/etc/gai.conf`. Closing that owed item on 2026-08-01 **refuted the ruling's stated deciding +reason** -- glibc 2.35 implements RFC 3484, not RFC 6724, so ULA and GUA are EQUAL at +precedence 40 and both outrank IPv4 at 10 (capture +`docs/audit/gai-conf-rfc6724-verification-20260801.txt`; the struck text is marked above). + +Under GA-R5 a ruling is the operator's, so the refutation was put BACK to them rather than +the ruling being silently kept because the answer was still liked, or silently reversed. + +**Question as presented.** The RFC 6724 precedence argument -- the reason given as deciding +-- is refuted for this deployment; ULA and GUA are behaviourally equivalent for address +selection on jammy. Three reasons survive and are independent of it: conformance with +Willamette (a REAL site) and VR0 DC0, both full GUA; MINIMIZE DELTA TO ROOSEVELT, whose +`2602:f3e2:103::/48` is GUA with no ULA and no plane carve yet; and isolation being +unaffected either way, since containment lives at the forwarding layer. Does ruling B stand +on those alone, or is it revisited? Nothing of D-139 is executed, so reversal costs nothing +but the exchange. + +**Operator answer, exact utterance: "Deciding to hold to gua does not cost anything +operationally and the case for ULA over gua is not very strong. Let's stay with gua".** + +**RULED: D-139 ruling B STANDS, UNCHANGED IN SUBSTANCE.** The GUA carve in ruling B's table +is confirmed; the ULA `/48` `fd50:840e:74e2::/48` remains RETIRED for VR1; the D-101 and +D-111 amendments stand. + +**What changed is the RATIONALE OF RECORD, and this matters for anyone citing it later.** +Ruling B now rests on exactly two arguments, both of which are project-constraint arguments +rather than protocol ones: +1. **Conformance** -- Willamette and VR0 DC0 already carve GUA on every plane; VR1 was the + outlier. +2. **Minimize delta to Roosevelt** -- the governing design constraint. Roosevelt's carve does + not exist yet, so whatever VR1 proves it inherits. + +Plus the operator's own recorded reasoning: **holding to GUA costs nothing operationally, and +the case for ULA over GUA is not strong.** The refuted precedence argument must NOT be +re-cited in support of this or any successor decision. + +**A CONSEQUENCE THAT IS NOW EXPLICIT AND WAS NOT BEFORE:** because ULA and GUA are equal at +precedence 40 on glibc 2.35, choosing GUA buys **no address-selection advantage** on the two +dual-stack planes. It buys conformance and Roosevelt fidelity. Anyone later reasoning that +"GUA was chosen so v6 would win selection over v4" is reasoning from the struck argument and +is wrong -- on this glibc, ULA would have won equally. + +**GENERALISABLE, and it is a NEW variant of this repo's citation rule.** The standing rule is +"a citation is an EXISTENCE claim; only its CONTENT is evidence" -- open the source, check its +STATUS and DATES. Here the citation was real, current, correctly quoted AND correctly +understood, and still wrong, because **nobody checked whether the IMPLEMENTATION follows the +standard.** For a STANDARDS citation, add a third check: confirm the deployed software +implements it, at the deployed version. An RFC is not a description of your system.