diff --git a/docs/archive/session-ledger-rotated-20260729.md b/docs/archive/session-ledger-rotated-20260729.md new file mode 100644 index 0000000..b56433f --- /dev/null +++ b/docs/archive/session-ledger-rotated-20260729.md @@ -0,0 +1,68 @@ +# Session-ledger summaries rotated 2026-07-29 (GA-R4 rule 3 / F1) + +Moved VERBATIM out of `docs/session-ledger.md` to restore the 300-line cap when the +2026-07-29 close bookend was appended. Oldest-first, per GA-R4 rule 3. Nothing here is +status: `docs/CURRENT-STATE.md` is the only status authority (GA-R1), and each summary +below still points at its own archived full body. + +--- + +## SESSION CLOSE 2026-07-26 -- D-137 build + committee audit + remediation (bounded, GA-R4) + +- D-137 was ADOPTED-not-built at open; all THREE tiers now exist plus enforcement (preflight + P5 blocking). 17 commits `af1b682..1696d08` pushed. Stage 4 stays OPEN; no stage closed. +- Six-lens committee audited the build; FOUR converged on one root cause -- tier 2 keyed + existence on host-role alone, ignoring site-key, so one site's credential satisfied every + site, MASKING SEC-021's dc0 on-disk absence. 8 false greens, all reproduced and fixed. +- Owned: ~21 inferred filenames (reported six); systemic sec-ref mis-attribution; + CURRENT-STATE cited a verdict file for measurements it lacked. 2 claims WITHDRAWN. +- Five operator rulings (GA-R5, quoted on D-137): 12-column schema; tier 1 as blocking P5; + tier 2 local-blocking + `stages-reached` coupled by new repo-lint L12; tier 3 probe + boundary; SEC-024 chmod. Ruling 4 (SEC-009 -> pointer) executed. +- SEC-024 opened then remediated (mode), severity corrected first. SEC 19 -> 20. Ledger + rotated twice (GA-R4 F1). Gauntlet 79 -> 81 GREEN; repo-lint 0-fail. +- NEXT: live mission has NOT moved -- resume the DC1 Stage-5 chain per CURRENT-STATE. + Unbuilt/unruled advice: `creds-mint.sh` BEFORE Stage 5 (largest minting event). +- Full body: `docs/archive/session-20260726-d137-build.md`. Status ONLY in CURRENT-STATE.md. + +## SESSION CLOSE 2026-07-27 -- creds consolidation + STAGE 4 CLOSE-OUT (bounded, GA-R4) + +- Opened on a creds question; ended closing Stage 4. **STAGE 4 IS CLOSED AND MERGED** -- + operator-gated merge commit `6f5701d` on `main` (2 parents, not squashed, 77 commits), + branch retired local + remote, post-merge gauntlet ALL GREEN (81) + repo-lint 0-fail on + `main`, close recorded in CURRENT-STATE by `1023596`. Next stage branches off `main`. +- Creds: dc0 SEC-012 power key consolidated + `.pub` derived (SEC-021(b) as written -- measured + first: it IS the dedicated key, and dc0 using the snap default is SEC-016's ruled design, so + NO re-mint); NetBox GUI admin password consolidated (**SEC-025**, rows 20->21); dc1 svc `.pub` + backfilled. Findings 13 -> 7. MAAS account set verified COMPLETE by enumeration. +- V2 taught the ruled-deferral state -- reissuing SEC-006's token would have CONTRAVENED a + standing 2026-07-13 ruling; the register was what needed changing. `--ledger` added; V2 had + shipped with ZERO harness cases. +- **Two false greens fixed, both in controls that had passed for days:** `dc-mirror.sh check` + asserted last-sync EXISTED (dc0 `FAIL`, dc1 4-day-stale `RUNNING` both read OK); and + `creds-audit` CLEAN x3 alongside 13 matrix findings. Lesson repo-carried in the skill. +- Rulings (GA-R5, all quoted): **G17** opened (node-side reachability split out -- powered-off + nodes cannot be probed); SEC-024 retention "Keep both"; set-interface-v4 reload "a"; D-135 + AMENDED (dc0 tests full mirror / dc1 tests proxy -- dc1's 330G mirror REMOVED, not paused). +- DOCFIX-204: DoD bullet 6 was UNSATISFIABLE (D-129(iv) had ruled the opposite); 4 surfaces. + Carve residue: 108 fabrics -> 17, cascade-checked. dc1 nginx purged. +- OWNED: first draft of the pf reload sat inside the reconfigure heredoc -- would have fixed + nothing in the very drop case that caused the bug. Caught pre-ship. +- **FINDING for the next session (logged, not actioned):** `tests/creds-matrix` T24's + finding-class baseline (`expected-findings.txt`) covers **TIER 1 ONLY** -- tier-2/3 classes + (E1/E3/E4/V1/V2) have NO baselined red state, so a future false green there would not turn + the gauntlet red. Same class as the two false greens this session fixed. Also still open from + the D-137 close: `creds-mint.sh` is unbuilt/unruled advice and Stage 5 is the largest minting + event, so it is worth ruling BEFORE the bundle deploy rather than after. +- POST-CLOSE DURABILITY SWEEP (operator-requested): 4 transcript-only items landed on surfaces + -- worst was `dc-mirror.sh`'s dc1 row carrying NO warning that dc1 is proxy-only, so + `install dc1` would silently rebuild the removed apparatus + enabled timer + ~950G pull. + Also: a WRONG causal claim in the mirror-gate capture superseded by appended correction + (reset-failed cannot re-arm an inactive timer; the vector was a REBOOT via Persistent=yes); + platform-traps section 5 added; the two-net-units coexistence claim marked REASONED-NOT- + MEASURED. Capture `docs/audit/queued-findings-20260727.txt`. QUEUED: a runtime install + guard for a non-mirror site (a comment is strictly weaker and prose-only prevention has + already failed twice here). +- Gauntlet ALL GREEN (81), repo-lint 0-fail. Full body: `docs/archive/changelogs/changelog-20260727-creds-consolidation.md`; + stage record `docs/archive/stage-records/vr1-stage4-record.md`. Status ONLY in CURRENT-STATE.md. + diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 45935f4..0b94f8f 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -30,8 +30,9 @@ ## Machine-derived (re-seed from `scripts/ledger-scan.sh`; do not hand-edit) -_Re-seeded from a 2026-07-27 scan at the STAGE 4 CLOSE (values verified against -`bash scripts/ledger-scan.sh` in that session). Re-run the scan to refresh._ +_Re-seeded from a 2026-07-27 scan at the STAGE 4 CLOSE. RE-VERIFIED 2026-07-29 against +`bash scripts/ledger-scan.sh` -- every value below unchanged, so this is a confirmation, +not a re-seed. Re-run the scan to refresh._ - **PROPOSED / OPEN decisions (3):** D-068 (Vault substrate hardening, Roosevelt -- sole remainder is Q2 path selection at Roosevelt Vault design time), D-131 (node-facing DNS for @@ -144,64 +145,13 @@ The oldest remaining live summary ("POST-CLOSE ADDENDUM 2026-07-26 -- D-137 ADOPTED (GA-R4; 07-18/07-21 addendum precedent)") moved VERBATIM to `docs/archive/session-ledger-rotated-20260727.md`. The live ledger was 316 lines against the 300-line cap. -## SESSION CLOSE 2026-07-26 -- D-137 build + committee audit + remediation (bounded, GA-R4) +## ROTATED 2026-07-29 (GA-R4 rule 3 / F1 -- oldest-first, cap restored at this close) -- D-137 was ADOPTED-not-built at open; all THREE tiers now exist plus enforcement (preflight - P5 blocking). 17 commits `af1b682..1696d08` pushed. Stage 4 stays OPEN; no stage closed. -- Six-lens committee audited the build; FOUR converged on one root cause -- tier 2 keyed - existence on host-role alone, ignoring site-key, so one site's credential satisfied every - site, MASKING SEC-021's dc0 on-disk absence. 8 false greens, all reproduced and fixed. -- Owned: ~21 inferred filenames (reported six); systemic sec-ref mis-attribution; - CURRENT-STATE cited a verdict file for measurements it lacked. 2 claims WITHDRAWN. -- Five operator rulings (GA-R5, quoted on D-137): 12-column schema; tier 1 as blocking P5; - tier 2 local-blocking + `stages-reached` coupled by new repo-lint L12; tier 3 probe - boundary; SEC-024 chmod. Ruling 4 (SEC-009 -> pointer) executed. -- SEC-024 opened then remediated (mode), severity corrected first. SEC 19 -> 20. Ledger - rotated twice (GA-R4 F1). Gauntlet 79 -> 81 GREEN; repo-lint 0-fail. -- NEXT: live mission has NOT moved -- resume the DC1 Stage-5 chain per CURRENT-STATE. - Unbuilt/unruled advice: `creds-mint.sh` BEFORE Stage 5 (largest minting event). -- Full body: `docs/archive/session-20260726-d137-build.md`. Status ONLY in CURRENT-STATE.md. - -## SESSION CLOSE 2026-07-27 -- creds consolidation + STAGE 4 CLOSE-OUT (bounded, GA-R4) - -- Opened on a creds question; ended closing Stage 4. **STAGE 4 IS CLOSED AND MERGED** -- - operator-gated merge commit `6f5701d` on `main` (2 parents, not squashed, 77 commits), - branch retired local + remote, post-merge gauntlet ALL GREEN (81) + repo-lint 0-fail on - `main`, close recorded in CURRENT-STATE by `1023596`. Next stage branches off `main`. -- Creds: dc0 SEC-012 power key consolidated + `.pub` derived (SEC-021(b) as written -- measured - first: it IS the dedicated key, and dc0 using the snap default is SEC-016's ruled design, so - NO re-mint); NetBox GUI admin password consolidated (**SEC-025**, rows 20->21); dc1 svc `.pub` - backfilled. Findings 13 -> 7. MAAS account set verified COMPLETE by enumeration. -- V2 taught the ruled-deferral state -- reissuing SEC-006's token would have CONTRAVENED a - standing 2026-07-13 ruling; the register was what needed changing. `--ledger` added; V2 had - shipped with ZERO harness cases. -- **Two false greens fixed, both in controls that had passed for days:** `dc-mirror.sh check` - asserted last-sync EXISTED (dc0 `FAIL`, dc1 4-day-stale `RUNNING` both read OK); and - `creds-audit` CLEAN x3 alongside 13 matrix findings. Lesson repo-carried in the skill. -- Rulings (GA-R5, all quoted): **G17** opened (node-side reachability split out -- powered-off - nodes cannot be probed); SEC-024 retention "Keep both"; set-interface-v4 reload "a"; D-135 - AMENDED (dc0 tests full mirror / dc1 tests proxy -- dc1's 330G mirror REMOVED, not paused). -- DOCFIX-204: DoD bullet 6 was UNSATISFIABLE (D-129(iv) had ruled the opposite); 4 surfaces. - Carve residue: 108 fabrics -> 17, cascade-checked. dc1 nginx purged. -- OWNED: first draft of the pf reload sat inside the reconfigure heredoc -- would have fixed - nothing in the very drop case that caused the bug. Caught pre-ship. -- **FINDING for the next session (logged, not actioned):** `tests/creds-matrix` T24's - finding-class baseline (`expected-findings.txt`) covers **TIER 1 ONLY** -- tier-2/3 classes - (E1/E3/E4/V1/V2) have NO baselined red state, so a future false green there would not turn - the gauntlet red. Same class as the two false greens this session fixed. Also still open from - the D-137 close: `creds-mint.sh` is unbuilt/unruled advice and Stage 5 is the largest minting - event, so it is worth ruling BEFORE the bundle deploy rather than after. -- POST-CLOSE DURABILITY SWEEP (operator-requested): 4 transcript-only items landed on surfaces - -- worst was `dc-mirror.sh`'s dc1 row carrying NO warning that dc1 is proxy-only, so - `install dc1` would silently rebuild the removed apparatus + enabled timer + ~950G pull. - Also: a WRONG causal claim in the mirror-gate capture superseded by appended correction - (reset-failed cannot re-arm an inactive timer; the vector was a REBOOT via Persistent=yes); - platform-traps section 5 added; the two-net-units coexistence claim marked REASONED-NOT- - MEASURED. Capture `docs/audit/queued-findings-20260727.txt`. QUEUED: a runtime install - guard for a non-mirror site (a comment is strictly weaker and prose-only prevention has - already failed twice here). -- Gauntlet ALL GREEN (81), repo-lint 0-fail. Full body: `docs/archive/changelogs/changelog-20260727-creds-consolidation.md`; - stage record `docs/archive/stage-records/vr1-stage4-record.md`. Status ONLY in CURRENT-STATE.md. +The TWO oldest live summaries -- 2026-07-26 (D-137 build + committee audit + remediation) +and 2026-07-27 (creds consolidation + the STAGE 4 CLOSE-OUT) -- moved VERBATIM to +`docs/archive/session-ledger-rotated-20260729.md`. The live ledger would otherwise have +been 321 lines against the 300-line cap once this session's bookend was appended. +Sessions from the 2026-07-27 grounding audit onward remain live below. ## SESSION CLOSE 2026-07-27 -- STAGE-5 GROUNDING AUDIT (bounded, GA-R4) @@ -294,3 +244,21 @@ the apex tool against a dump so it matched zero live. All corrected on-surface. - NEXT: gate host-authority; `provider-bundle-check` ARITY gap (imminent); **voffice1 back to `main` at merge**; then the renderer. Body: `changelog-20260727-stage5-phase0.md`. + +## SESSION CLOSE 2026-07-29 -- VIP arity gate, the renderer, ruling-3 commit 1 (bounded, GA-R4) + +- Branch `dc-dc-stage5-preconditions`, 6 commits `d2460d0..b952683`. NO stage opened/closed. + Scan re-verified: 3 decisions, SEC 21, D 138 / DOCFIX 205 / BUNDLEFIX 053 -- all unchanged. +- **ARITY GAP CLOSED** + R11's three ruled gate changes (band 50->99, `VIP_COUNT_EXPECT` 11->13, + `EXPECT_PUBLIC_VIP` STAYS 11, hacluster-principal-without-VIP now FAILS). Checker takes a v4 + triple OR a dual-family sextet; v6 legs validated against APEX-derived /64s; `prefer-ipv6` + COUPLED to arity BOTH ways -- the L3-9 order that drops the v6 legs is the one that exits 0. +- **RENDERER SHIPPED** (D-136 (D)): `derive`/`render` split where F2 froze the interface; + reproduces `overlays/vr1-dc1-vips.yaml` BYTE-FOR-BYTE, proven able to fail on 3 seeded faults. +- ORDER INVERTED BY MEASUREMENT -- renderer BEFORE the extraction, since the reproduction window + closes when the reconciliation lands. It then caught a real renderer bug within the hour: the + first dual-family v6 leg joined with ONE colon, malformed but plausible (T13/T13b). +- **RULING 3 COMMIT 1:** `bundle.yaml` VIP-FREE, dc0's VIPs a RENDERED overlay, neutrality proven + by identical checker output. phase-01's RUN block would have ABORTED THE DEPLOY (0/0/0 vs + 11/11/0); Octavia SAN KeyError -> empty VIP; CHECK 1 died on `IFS` splitting. +- NEXT: commit 2 (dual-stack + `.61`/`.62`). Gauntlet ALL GREEN (85) vcloud; lint 0 fail. Body: `docs/changelog-20260728-vip-arity-gate.md`.