Conformance updates.
This commit is contained in:
+49
-2
@@ -4,9 +4,9 @@ Specification for a Mechanical Compiler instance.
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| Revision | 5.2 (2026-08-17) |
|
||||
| Revision | 5.3 (2026-08-18) |
|
||||
| Supersedes | Revisions 1 through 4 |
|
||||
| Basis | Revision 4, reconciled against the proven staging build, then work orders 002 and 003 |
|
||||
| Basis | Revision 4, reconciled against the proven staging build, work orders 002 and 003, and container standardisation |
|
||||
| Scope | **Host-agnostic.** Applies to any instance. |
|
||||
| Instance state | `STAGING-STATE.md`, and later `PRODUCTION-STATE.md` |
|
||||
| Failure evidence | `FAILURES.md` |
|
||||
@@ -769,6 +769,44 @@ wrong form reported a pass against containers that were not running.
|
||||
|
||||
---
|
||||
|
||||
## 14a. Conformance
|
||||
|
||||
**REQ** — An instance carries an executable **baseline check**: read-only,
|
||||
runnable at any time, exiting non-zero when any container diverges from the
|
||||
standard.
|
||||
|
||||
**REQ** — **A property not checked by it is not part of the standard.** This is
|
||||
what makes conformance terminate. Without it, divergence is discovered one
|
||||
property at a time whenever something behaves oddly, and the process never
|
||||
finishes because nothing states what "the same" means. A property that must be
|
||||
uniform belongs in the check, not in an operator's memory.
|
||||
|
||||
**REQ (F-031)** — The check must examine **the thing being standardised**. An
|
||||
assertion derived from a related observation is not a check. Postfix
|
||||
configuration on the host says what the host does; it says nothing about the
|
||||
containers, and a standard asserted that way was wrong on two of three.
|
||||
|
||||
**REQ** — Each failure names the failure-log entry that established the
|
||||
requirement, so the reason survives the person who found it.
|
||||
|
||||
**REQ (F-032)** — Host-level requirements belong to the host, not to whichever
|
||||
project discovered them first. Where several projects share a host, the check
|
||||
is host-level and covers every container regardless of owner. Two projects on
|
||||
this host independently rediscovered the same two defects before this was done.
|
||||
|
||||
### Mail
|
||||
|
||||
**REQ** — **Containers do not originate mail.** Only the host does, and only its
|
||||
own operational alerts. A container with a mail agent installed but SMTP egress
|
||||
blocked is worse than either alone: it queues indefinitely and delivers nothing,
|
||||
while appearing configured.
|
||||
|
||||
Application mail — participant notification and similar — is a separate design
|
||||
problem with its own delivery and inbound requirements. It is not solved by
|
||||
leaving a partially configured agent in a container.
|
||||
|
||||
---
|
||||
|
||||
## 15. Acceptance gates
|
||||
|
||||
**REQ** — Five independent gates. Revision 4 ran them as one list, which meant
|
||||
@@ -812,6 +850,15 @@ active. Reference toolchain image reproduces `ddd0f154…`. Scaffolding removed.
|
||||
|
||||
Undefined pending a strategy decision.
|
||||
|
||||
**REQ** — **Conformance is a precondition, not a companion.** Backup work does
|
||||
not begin until the baseline check (§14a) exits zero, and the check forms part
|
||||
of restore verification.
|
||||
|
||||
A backup of an unverified configuration does not preserve a system; it
|
||||
preserves a state of confusion, and a restore returns that state faithfully.
|
||||
This was not hypothetical: a backup taken before 2026-08-18 would have restored
|
||||
two containers that queue mail forever (F-031).
|
||||
|
||||
### Gate 5 — Production automation
|
||||
|
||||
Idempotent scripts derived from a proven manual procedure. Firewall posture
|
||||
|
||||
Reference in New Issue
Block a user