diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 70fd259..1f7d08e 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -30,17 +30,19 @@ ## Machine-derived (re-seed from `scripts/ledger-scan.sh`; do not hand-edit) -_Re-seeded from the 2026-07-21 scan. Re-run `bash scripts/ledger-scan.sh` to refresh._ +_Re-seeded from the 2026-07-21 evening scan (post-stage-3-close). Re-run `bash scripts/ledger-scan.sh` to refresh._ - **PROPOSED / OPEN decisions:** D-068 (Vault substrate hardening, Roosevelt), D-071 (routine update cadence + Juju controller patch policy), D-129 (OPNsense edge plugin/add-on base profile -- OPEN / partially ruled, four sub-decisions), D-131 (node-facing DNS strategy for - rack-only controllers -- PROPOSED 2026-07-21; interim forwarder workaround operator-ruled and - live). Status lines in `docs/design-decisions.md` are the only ruling authority. -- **OPEN security rows:** 10 open per `bash scripts/ledger-scan.sh` (re-seeded 2026-07-21). The - SEC register of record is `docs/security-ledger.md`; row-level dispositions live THERE only - (GA-R4 amendment F3) -- this block carries pointer + count, never rows. -- **Next-free numbers:** D = **132**, DOCFIX = 197, BUNDLEFIX = 052. + rack-only controllers -- PARTIALLY RULED: sub-1 ruled + delivered 2026-07-21, sub-2..4 open; + now surfaced by the scan itself after the PARTIAL fix). Status lines in + `docs/design-decisions.md` are the only ruling authority. +- **OPEN security rows:** 10 open per `bash scripts/ledger-scan.sh` (re-verified at stage close; + SEC-013 surface NARROWED 2026-07-21, row still open for rotation). The SEC register of record + is `docs/security-ledger.md`; row-level dispositions live THERE only (GA-R4 amendment F3) -- + this block carries pointer + count, never rows. +- **Next-free numbers:** D = **132**, DOCFIX = **198**, BUNDLEFIX = 052. - **Standing numbering rule:** never write an identifier-shaped token (D-/DOCFIX-/BUNDLEFIX-NNN) ABOVE the real high-water mark anywhere in `docs/` or `runbooks/` prose -- historically a decoy token in prose inflated the next-free counter (hardened in DOCFIX-174); the authoring discipline @@ -154,4 +156,22 @@ - Post-disconnect: operator ran the netem-tc install interactively; successor VERIFIED read-only (0440 root:root, byte-identical, sudo -n -l grant checks exit 0 -- docs/audit/netem-sudo-install-20260721.txt). Step E is now UNBLOCKED (gated run pending). -- Details: docs/changelog-20260721-close-and-delivery.md. Status lives ONLY in CURRENT-STATE.md. +- Details: docs/archive/changelogs/changelog-20260721-close-and-delivery.md. Status lives ONLY in CURRENT-STATE.md. + +## SESSION CLOSE 2026-07-21 -- STAGE 3 CLOSED + MERGED (third session; bounded, GA-R4) + +- Bookend landed at stage close while the session may continue (two same-day disconnects argued + for durable-early); any further work appends a POST-CLOSE ADDENDUM (07-18 precedent). +- Step E netem DONE (targeted apply at an operator-ruled 1/1/0 STOP; placeholder live on virbr5) + -> G10 CLOSED. G16 opened for the office1 channels residual, then CLOSED same-day + (operator-ruled state surgery; outer plan back to ZERO DIFF). +- Ruling 1 retire-fully EXECUTED: vr1-dc0-maas removed, stale pod + SEC-013 key file + tfstate + deleted. INCIDENT: the pod delete cascaded to the 9 machine records (association check ran + post-delete -- owned); recovered same-hour via re-enlist/power/commission, 9/9 Ready, shapes + exact, NEW MAAS hostnames. Appendix-A entry shipped (check pod machine list BEFORE delete). +- Also: ledger-scan PARTIAL fix, DOCFIX-197, D-103/D-123 amendments, GA-R7 memory review. +- STAGE 3 CLOSED (operator-ruled): consolidation + skill sweep + gauntlet 76 ALL GREEN; merge + commit 8d0d155 on main; branch retired local+remote. Next stage branches off main. +- Open queue unchanged: D-131 sub-2..4, SEC-014 rotation, D-068/D-071/D-129, G12 (dc1), G15. +- Details: docs/changelog-20260721-netem-install-verify.md (top-level until this session ends). + Status lives ONLY in CURRENT-STATE.md.