diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index a7bef2f..052aab8 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -1930,7 +1930,31 @@ proxy rather than a full mirror rebuild"*. Under the proxy arm the origin block is DELETED, not fixed. Its stated trigger is a REBUILD of dc0's artifact service and the mirror currently stands, so whether this fires that trigger is the OPERATOR'S call. - **THE FORK IS OPEN AND UNRULED (GA-R5 shape).** (A) converge dc0 on the proxy now + **>>> RULED 2026-08-02 -- OPTION (A), CONVERGE. D-135 AMENDMENT 2026-08-02 (b). <<<** + **Operator, exact utterance: "Option A, converge. We have gathered the information we need + on the mirror buildout. It will be a future implementation but will not be used in + Roosevelt but much later so keep the information as informational only with no pin or + expectation on a future deployment date."** dc0's artifact strategy becomes the apt caching + proxy on the dc1 pattern; **both DCs now run ONE strategy**. The per-DC origin override is + **DELETED, not repaired** -- the proxy forwards whatever URL it is handed, so + `cloud:jammy-caracal` (the as-built value, defined once behind `bundle.yaml`'s anchors) + works unmodified and the `NO_PUBKEY` problem ceases to exist. This SUPERSEDES the trigger + clause of amendment (a), which had made convergence conditional on a rebuild. + **>>> THE MIRROR EXPERIMENT RESULT IS INFORMATIONAL ONLY: NO PIN, NO EXPECTED DEPLOYMENT + DATE, NOT A ROOSEVELT ITEM. <<<** A later session must NOT convert it into a pinned item, a + gap-register row, a trigger, or a forward commitment -- that would manufacture an + expectation the operator explicitly declined to create. `ledger-scan` and the forward-items + register stay clean of it. NOT ruled: whether the running mirror is torn down and when its + 953 GB is reclaimed -- a separate destructive action needing its own approval; the mirror + may stand indefinitely without affecting this ruling. + **PROCESS DEFECT, OWNED: the ruling commit `ea708d7` was pushed with repo-lint RED.** L10 + fired correctly (an audit-file change without a CURRENT-STATE update in the same commit) and + I did not see it, because I chained `repo-lint ; git commit` with a semicolon instead of + `&&`, masking the exit code. **This is the same mistake recorded in this repo's own + 2026-08-02 changelog ("I pushed a red lint once by masking the exit code"), repeated in the + session that cites it.** Corrected in the very next commit; the ruling text itself was + unaffected. + **THE FORK AS PRESENTED (now closed by the ruling above).** (A) converge dc0 on the proxy now (`dc-cache-proxy.sh`, built and proven on dc1), delete the origin block, return to the as-built config -- eliminates the key problem rather than working around it, at the cost of a build mid-deploy. (B) keep the mirror, restructure the armored key behind a single anchor,